Kimi K3 vs ChatGPT (GPT-5.6): Which AI Actually Wins in 2026?
A Chinese open-weight model just went toe to toe with OpenAI's best, and the internet noticed. Kimi K3, from Moonshot...
A pan-EU guide to the transparency rules, penalties, and postponed obligations taking effect this summer, and the five actions to take before the deadline.
Note on this article: dates, figures, and article numbers below reflect the AI Act (Regulation EU 2024/1689) and the Digital Omnibus text as adopted in June 2026. This is a fast-moving area of EU law, so verify current figures against the Official Journal of the EU or your national competent authority before relying on them for a compliance decision.
For two years, 2 August 2026 was billed as the "big bang" of the AI Act: the date the regulation's full weight would land on businesses across the Union. The reality, as of July 2026, is more nuanced, and that nuance is exactly what's causing confusion in compliance teams from Dublin to Warsaw.
The Digital Omnibus package, adopted by the European Parliament on 16 June and given final green light by the Council on 29 June 2026, postponed the heaviest obligations, those covering high-risk AI systems, to December 2027. But 2 August 2026 is still a real deadline. Transparency obligations, the activation of penalties, and the end of the transition period for general-purpose AI models all take effect that day, across every member state.
The one-sentence version: on 2 August 2026, it isn't the "high-risk" rules that arrive, it's Article 50 transparency, enforcement powers, and mandatory compliance for large AI models. That combination touches far more businesses than most people assume.
The AI Act entered into force on 1 August 2024 with a phased rollout. Two milestones are already behind every business in the EU:
Since 2 February 2025: AI practices with unacceptable risk (social scoring, manipulative techniques, certain biometric surveillance) have been banned, and the AI literacy obligation under Article 4 already applies to staff working with AI systems.
Since 2 August 2025: providers of general-purpose AI models (GPT, Claude, Gemini, Mistral, and others) have been subject to their own documentation and transparency duties.
2 August 2026 is the third wave, the general application date that switches on the institutional machinery and the penalty regime across all member states.
This is where most confusion sits right now. The Digital Omnibus postpones application of the high-risk obligations under Annex III (recruitment, credit scoring, education, biometrics, and similar uses) from 2 August 2026 to 2 December 2027, and those for AI embedded in regulated products (Annex I, e.g. medical devices, machinery) to 2 August 2028.
The reasoning was pragmatic: the harmonized standards and notified bodies needed for certification weren't ready in time. Forcing compliance without the tools to achieve it would have created legal uncertainty. But the postponement is narrow. According to Gibson Dunn's analysis, the Article 50 transparency obligations for AI systems largely remain on the original schedule, and businesses subject to those obligations must stay ready for 2 August 2026 regardless of the Omnibus.
Here's what is unchanged on 2 August 2026, EU-wide:
Article 50 transparency obligations (chatbots, deepfakes, AI-generated content) apply on schedule
The penalty regime and national governance structures become fully operational
GPAI models placed on the market before August 2025 must be in full compliance
The Article 5 prohibitions and the training obligation, in force since February 2025, continue to apply
Businesses that ease off on inventorying and classifying their AI systems this year will find themselves in December 2027 with weeks to do work that should take months.
One more addition worth flagging: the European Parliament confirmed that the Digital Omnibus introduces a new prohibited practice targeting systems that generate non-consensual intimate imagery ("nudifiers") and child sexual abuse material, applicable from 2 December 2026.
If your business takes away one thing from this piece, make it this. Article 50, applicable 2 August 2026, imposes transparency obligations that reach far beyond AI vendors. They apply to any business deploying generative or interactive AI, in any member state.
Concretely, from that date:
Chatbots and virtual assistants: anyone interacting with an AI system must be clearly told (a simple visible notice, such as "You are chatting with an AI assistant," is enough)
AI-generated or manipulated content: deepfakes and synthetic content distributed to the public must be labeled
Emotion recognition and biometric categorization: exposed individuals must be informed
Machine-readable marking (Article 50(2)): providers of generative systems must embed machine-readable markers, with a grace period until 2 December 2026 for systems already on the market before August 2026, per the Digital Omnibus final text
Take a typical example: a business running a customer-service chatbot built on Shopify, WooCommerce, Intercom, or Zendesk, anywhere in the EU, is a "deployer" under the regulation. The obligation isn't onerous: display the AI notice, confirm your chatbot vendor handles the technical marking, and document that check in an internal register. The cost is marginal; the absence of the notice is what becomes sanctionable.
Until now, the AI Act has largely lacked enforcement muscle at national level. 2 August 2026 activates the penalty regime under Article 99, calibrated on the GDPR model but stricter, and applied uniformly across the Union:
Up to €35 million or 7% of worldwide turnover for prohibited practices
Up to €15 million or 3% of worldwide turnover for other breaches, including Article 50 transparency
Up to €7.5 million or 1% of worldwide turnover for supplying incorrect information to authorities
A protective mechanism exists for SMEs and startups: Article 99(6) sets the fine at the lower of the percentage and the fixed amount for them, while large companies face the higher of the two. This asymmetry makes compliance proportionate, but not optional.
Master the EU AI Act
Stay ahead of the latest EU AI Act requirements with expert-led, self-paced training. Learn how the regulation impacts businesses, understand AI risk classifications, compliance obligations, governance frameworks, and practical implementation strategies. Earn a recognized PDF certificate at no extra cost. Build the knowledge and confidence to help your organization achieve AI Act compliance and responsibly deploy AI systems.
Enroll Now →This is the one area where a single, tidy answer doesn't exist, and any article that gives you one is oversimplifying.
The AI Act requires each member state to designate its own national competent authorities and a market surveillance authority, coordinated at EU level by the AI Office (based in the European Commission) and the European Artificial Intelligence Board, both established under the Regulation itself. What that looks like on the ground varies by country, and several member states were still finalizing their designations as of mid-2026.
A pattern that's common, but not universal: data protection authorities tend to take a lead role wherever an AI system processes personal data, such as biometrics, employment screening, or profiling, with separate bodies typically covering media/content authenticity, financial services, and cybersecurity. This roughly mirrors how GDPR enforcement is already split nationally in most countries.
If you operate in more than one member state, don't assume one authority covers you everywhere. Check each country's designation directly, starting with your national ministry of digital affairs or economy, rather than relying on a general EU-level summary, including this one.
For a DPO or compliance officer, the practical takeaway is that the GDPR playbook transfers directly: inventory, lawful basis, documented oversight. Where an AI system touches personal data, GDPR and the AI Act apply simultaneously; they stack rather than replace one another.
Map all your AI systems. Inventory every tool that embeds AI: chatbots, scoring, CV screening, content generation, predictive CRM, including employees' unsanctioned use of tools like ChatGPT or Copilot ("shadow AI"). Without an inventory, classification is impossible; treat it like a GDPR record of processing activities.
Classify each system by risk level. The regulation has four tiers: unacceptable (banned), high risk (Annex III, obligations postponed to December 2027 but worth anticipating), limited risk (transparency mandatory from August 2026), and minimal risk (no specific obligation). Most everyday business uses fall into limited or minimal risk.
Deploy transparency notices before 2 August. Add AI disclosures to chatbots, label AI-generated public-facing content, and confirm contractually that vendors handle technical marking. This is the most urgent and least costly step in the whole process.
Formalize staff training. The Article 4 AI literacy obligation has applied since February 2025. Document who uses which tools, train them on the risks, and keep records.
Prepare for high risk without waiting for December 2027. If you use AI in recruitment, employee evaluation, or credit decisions, start your gap analysis now: technical documentation, human oversight, traceability, data governance. The postponement buys time; it doesn't lower any substantive requirement.
Operating in multiple member states? Repeat steps 1 and 2 per country if your AI deployments differ locally (e.g. a recruitment tool used only in your German office), and add a step 0: identify the competent authority in each country where you have entities or users, since a single group-level compliance file may still need country-specific contacts and notifications.
AI Act compliance is tracking the same curve GDPR did in 2018: businesses that started a year ahead of the deadline experienced it as a project; those that waited experienced it as a crisis.
A Chinese open-weight model just went toe to toe with OpenAI's best, and the internet noticed. Kimi K3, from Moonshot...
Quick Answer: Kimi K3 is Moonshot AI's flagship open-weight AI model, released July 16, 2026. It has roughly 2.8 trillion...
Ai Governance
As AI spreads through business and daily life, so do the moments when it goes wrong, and those moments now...