AI · AI at work
The EU AI Act in Practice: What Actually Applies from August 2026
For years, 2 August 2026 was billed as the AI Act's big high-risk deadline – but the deadlines have moved, and what starts now is enforcement of duties that already apply. The new deadline map, the transparency rules and a roadmap without panic. As of August 2026.
By Boaz Lichtenstein Prefer us on Google

For years, 2 August 2026 sat in every AI Act presentation as the big deadline: the day the high-risk duties for candidate selection, credit scoring and critical infrastructure were supposed to kick in. That date is history – the EU moved the high-risk deadlines in spring 2026 via the Digital Omnibus. What actually happens on 2 August is something else, and easily overlooked in the noise: enforcement begins. Fining powers go live, supervisory authorities become operational, and the transparency duties for chatbots and AI-generated content take effect. Anyone who merely uses AI rather than developing it is still affected: the AI Act explicitly places duties on deployers, not just providers. This piece sorts out the new state of play. As of August 2026. (This is not legal advice – binding guidance for individual cases requires proper legal counsel.)
Key takeaways
- 2 August 2026 brings hardly any new duties – it makes existing ones enforceable: the Commission and the AI Office can now sanction GPAI breaches with up to €15 million or 3 per cent of worldwide turnover, and the national market surveillance authorities start work.
- The Article 50 transparency duties apply: chatbots have to identify themselves as AI, and AI-generated or AI-manipulated content has to be labelled – with a transition period until 2 December 2026 for machine-readable marking by systems already on the market.
- The high-risk deadlines have moved: Annex III systems (candidate selection, credit scoring, education, critical services) to 2 December 2027, Annex I systems (AI in regulated products) to 2 August 2028 – fixed dates, not conditional triggers.
- New on the list of prohibitions: AI systems that generate non-consensual intimate imagery or child sexual abuse material are banned from 2 December 2026.
- Unchanged since February 2025: the bans on unacceptable practices and the duty of AI literacy (Article 4).
- Germany is ready to act: since late July 2026, the Federal Network Agency (Bundesnetzagentur) has been the central supervisory authority under the national AI implementation act.
What actually happens on 2 August
The popular narrative went: on 2 August, the big duties arrive. The accurate one goes: on 2 August, the authorities arrive.
First, GPAI supervision goes live. The duties for providers of general-purpose models – technical documentation, a copyright policy, a summary of training data – have applied since August 2025. What is new is that the Commission and its AI Office can now enforce them: with information requests, model access and fines of up to €15 million or 3 per cent of worldwide turnover. For a year this was a duty without teeth; anyone who waited to see whether the EU meant it is now getting the answer.
Second, the Article 50 transparency duties take effect. They touch far more businesses than the high-risk rules: chatbots and other systems that interact directly with people have to identify themselves as AI. AI-generated or AI-manipulated images, audio and video have to be labelled as such – deepfakes explicitly. Providers additionally have to mark synthetic content in a machine-readable way, for instance via metadata or watermarks. For systems already on the market before 2 August 2026, a transition period for that technical marking runs until 2 December 2026; the remaining transparency duties apply without delay. How manipulated content gives itself away even without a label is covered in spotting deepfakes.
Third, the national supervisory authorities become operational. By this date, member states had to designate and equip their market surveillance – from now on, complaints and inspections have a real addressee (for Germany: more below).
The new deadline map
The postponement came with the Digital Omnibus: politically agreed in spring 2026, confirmed by Parliament and Council in June, and published in the Official Journal and in force since late July 2026 as Regulation (EU) 2026/1744. That leaves the timeline of the AI Act looking like this:
- Since February 2025: bans on unacceptable practices (social scoring, manipulative systems), duty of AI literacy (Article 4).
- Since August 2025: duties for general-purpose AI models (provider side).
- 2 August 2026: enforcement powers for the Commission and national authorities; transparency duties under Article 50.
- 2 December 2026: end of the transition period for machine-readable marking; the new ban on systems for non-consensual intimate imagery and abuse material takes effect.
- 2 December 2027: high-risk duties for Annex III systems – candidate selection, credit scoring, education, critical services (previously: 2 August 2026).
- 2 August 2028: high-risk duties for Annex I systems – AI in regulated products such as medical devices or machinery (previously: 2 August 2027).
Two things about this map are worth noting. First, the new high-risk dates are fixed – earlier drafts had tied the deadlines to the availability of standards and guidance, which would have made planning impossible. Second, the reprieve is not a gift without strings: for businesses with high-risk use cases, the sixteen months are exactly the time that conformity assessment, data quality and human oversight realistically take. Anyone reading the postponement as an all-clear will be standing in the same spot at the end of 2027 as this summer – just without another grace period.
Duties hinge on risk, not on size
The Omnibus has not touched the AI Act’s core logic: the regulation sorts AI applications by their risk to people – not by industry, technology or company size. Four tiers determine how strict the duties are:
| Risk tier | Examples | Key duties |
|---|---|---|
| Prohibited | Social scoring, manipulative systems, nudifier apps | Use is banned |
| High risk | Candidate selection, credit decisions, critical infrastructure | Data quality, documentation, human oversight |
| Limited risk | Chatbots, AI-generated content | Labelling and transparency duty |
| Minimal risk | Spellcheckers, internal draft text | Largely unrestricted, but AI literacy remains mandatory |
The classification is not always obvious: an AI feature in HR software looks harmless at first glance, but falls under high risk as soon as it actually intervenes in candidate selection – say, through automatic shortlisting or scoring. What matters is not the tool but the specific purpose it is used for: one and the same model can end up in two different risk tiers depending on the application. New in the top row is the prohibition added by the Omnibus: systems that generate realistic non-consensual intimate imagery of identifiable people or child sexual abuse material – aimed at so-called nudifier apps, it applies from 2 December 2026 and also covers systems where such output is foreseeably possible without effective safeguards.
What deployers should do now
For the large majority of businesses – the ones using AI without operating high-risk systems – the task consists of four manageable blocks that can be implemented without outside consultants:
- Build and maintain an AI inventory. List all systems with AI components – including the hidden features in off-the-shelf software. Without this overview, no risk class can be determined and no duty assigned; it is the first question in any audit. Assign one person or role to keep the list current rather than ticking it off once.
- Implement AI literacy (Article 4). The training duty has applied since February 2025 and covers practically every business with AI tools – documented, with genuine practical relevance, not as a box-ticking session. That includes knowing which data may go into which tools – the trade-offs behind that are sorted out in ChatGPT and privacy.
- Tick off the transparency cases. Identify customer-facing chatbots as AI, label AI-generated images, audio and video wherever the regulation requires it – since 2 August 2026 this is no longer optional polish but an enforceable duty.
- Review supplier contracts. Anyone buying in AI features remains a deployer with their own duties – “the provider handles that” only holds if it is contractually guaranteed. The territorial scope is deliberately broad here: US providers fall under the AI Act as soon as their systems or their output are used in the EU – so the compliance question belongs in every tool selection, not just in European contracts.
Anyone operating high-risk systems, or planning to, faces the same four blocks – plus conformity assessment, technical documentation and human oversight by the end of 2027 or mid-2028 respectively. This is where outside legal support pays off, and it pays off now: the moved deadline is comfortable as long as you treat it as a project timeline, not a delayed start. How these governance building blocks fit into an AI rollout that does not suffocate under compliance is shown in the practical guide to AI adoption.
Germany: the supervisor is in place
For a long time it was unclear who would even enforce the AI Act in Germany. Since late July 2026 that is settled: the national act implementing the AI regulation passed the Bundestag in June and the Bundesrat on 10 July, and entered into force on 29 July 2026. The Federal Network Agency (Bundesnetzagentur) is now the central market surveillance authority and the single point of contact for complaints – under a hybrid model in which existing sectoral supervisors (for financial services or medical devices, say) remain responsible in their fields. Information services and at least one AI regulatory sandbox for controlled experimentation are planned as well.
For practice, that means two things. Supervisory routine is only just being built – nobody should expect a wave of inspections on 3 August. But the argument “there is no competent authority anyway” has been off the table since this summer: complaints from competitors, affected individuals or consumer groups now have a letterbox.
The bottom line
2 August 2026 is not the day new duties crash down on most businesses – it is the day existing duties become enforceable. That is more reassuring than it sounds, and more binding at the same time: the basics – inventory, training, labelling, clean contracts – were never part of the postponement and cover most of it for businesses that just use AI. It gets serious with high-risk use cases; anyone operating there has gained time until the end of 2027, not a free pass. Everyone else should treat the AI Act the way they once treated GDPR: set it up properly early on, and it becomes routine rather than a crisis – a good starting point for that is our roadmap for AI adoption at SMEs.
The concrete next step can be done within an hour: draw up a list of every AI feature in use across the business – including the ones built into off-the-shelf software that nobody had on their radar as an “AI project”. That list is the foundation for everything that follows, and turns an abstract piece of legislation into a concrete, actionable task.