AccuroAI
Products
What We Do
Solutions
Company
Resources
Book demo
← Blog·AI Compliance9 read

EU AI Act: What Actually Applies on August 2, 2026 (and What Doesn't)

Three weeks out, here is the answer that fits in a breath: August 2 is the day enforcement powers switch on, not the day new obligations land on most enterprises. Three things still happen on schedule — and one of them almost certainly applies to you.

S
Sofia Reyes
Head of Compliance
2026-07-11

Three weeks from now, on August 2, 2026, the EU AI Act crosses its most misunderstood milestone. If you have been getting contradictory answers — from vendors, from LinkedIn, from your own outside counsel — here is the short version, and it fits in a breath: August 2 is the day enforcement powers switch on, not the day new compliance obligations land on most enterprises. The high-risk obligations everyone spent 2025 preparing for moved to December 2, 2027. Three things still happen on schedule, and one of them almost certainly applies to you.

What On August 2, 2026 Who feels it
GPAI enforcement powers (Arts. 53/55 obligations) Commission and AI Office can investigate and fine — up to €15M or 3% of global turnover Model providers first; enterprises that fine-tune or resell GPAI models should check their exposure
Article 50 transparency Applies — chatbots must disclose they are AI; deepfakes and AI-generated content must be labeled Almost every enterprise with a customer-facing assistant or AI-generated content
Penalty framework (Arts. 99/101) Operative — national market-surveillance authorities can act Anyone violating the provisions already in force
High-risk Annex III (HR screening, credit, education…) Does not apply — moved to Dec 2, 2027 Nobody, yet
High-risk Annex I (embedded in regulated products) Does not apply — moved to Aug 2, 2028 Nobody, yet

Last verified: July 11, 2026, against the Council's June 29 final approval of the Digital Omnibus and the Commission's AI Act framework page.

Why is everyone confused about August 2, 2026?

Because three true stories collided and the headlines merged them into one false one.

First: the original Act made August 2, 2026 the big date — the day high-risk obligations became enforceable. Every compliance roadmap written in 2024 and 2025 was built around it. Then the Digital Omnibus moved those obligations to December 2, 2027, and half the market read that as "the AI Act is delayed." It isn't. Only one track moved.

Second: GPAI obligations have technically applied since August 2, 2025 — but with no enforcement teeth. The Commission's power to investigate and fine arrives August 2, 2026. So a rule that already existed suddenly starts to matter, which reads like a new deadline even though it isn't one.

Third: the omnibus itself was in limbo for months. Anything written before the Parliament's June 16 vote and the Council's June 29 sign-off had to hedge. That hedging is why so much advice you have read sounds uncertain. It no longer needs to: the text is final.

What actually starts on August 2

1. The Commission can now fine GPAI providers

The obligations themselves — technical documentation, copyright policy, training-data summaries for all GPAI models; adversarial testing, incident reporting, and cybersecurity for models with systemic risk — have applied since August 2025. What changes is that the AI Office can now compel documentation, run evaluations, and issue fines up to €15M or 3% of worldwide turnover, whichever is higher.

Expect the first actions to be documentation requests aimed at the large model providers, not dawn raids on enterprises. But if your company fine-tunes an open model and places it on the EU market, or ships a product with a model you have substantially modified, you may qualify as a GPAI provider yourself — that classification question is worth an hour with counsel before August, not after a letter arrives.

2. Your chatbots have to say they're chatbots

Article 50 is the one obligation in this wave that reaches ordinary enterprises, and it has had a fraction of the attention high-risk got. From August 2:

  • People interacting with an AI system (a support chatbot, a voice agent) must be told they are dealing with AI, unless it is obvious from context.
  • AI-generated or manipulated content — deepfakes especially — must be disclosed as such.
  • AI-generated text published to inform the public on matters of public interest must be labeled, unless a human editor took responsibility.

One nuance the headlines missed: the omnibus gave a grace period, until December 2, 2026, for the machine-readable marking requirement — the watermarking and provenance-metadata layer — because the tooling standards are not ready. The human-facing disclosure duties still start August 2. In practice: your chatbot needs its disclosure now; your content pipeline needs watermarking by December.

3. The penalty machinery is live — unevenly

The framework of national penalties (Article 99) and GPAI fines (Article 101) becomes operative. The honest caveat: several member states have not yet stood up their market-surveillance authorities, so enforcement capacity will be patchy through 2026. Do not build a compliance posture on that gap — documentation requests are cheap for a regulator to send, and they are the first move. The question that decides how an inquiry goes is simple: can you produce an inventory of the AI in use at your company, with owners and purposes, inside a week? Most organizations cannot, and it is rarely because they lack policy — it is because a meaningful share of their AI usage is invisible to them. That is a discovery problem before it is a legal one; it is also the problem we built AccuroAI to solve first.

What does not happen on August 2

To say it plainly, because this is the question in every inbox:

  • High-risk Annex III obligations do not apply. Recruitment screening, credit scoring, education, essential services, law enforcement — the conformity assessments, FRIAs, registration, logging, and human-oversight duties for these now land December 2, 2027.
  • High-risk Annex I obligations do not apply. AI safety components in regulated products moved to August 2, 2028.
  • Nothing new for prohibitions or AI literacy — Article 5 and Article 4 have been in force since February 2025. The omnibus added two prohibitions (non-consensual intimate imagery and CSAM generation) to the list.

The 17 months of runway on high-risk is real, but it is runway for work with long lead times — Annex IV documentation packs, fundamental-rights impact assessments, vendor requalification. Teams that stopped when the delay was announced are spending their runway standing still.

The three-week checklist

If you do only five things before August 2, make them these:

  1. Get a real AI inventory. Not the sanctioned list — the actual one, including the tools employees adopted without asking and the agents engineering wired up last quarter. Every obligation downstream assumes you know what is running.
  2. Find your Article 50 touchpoints. Every customer-facing chatbot, voice agent, and AI-content pipeline. Add the disclosure line where it is missing. It is the cheapest compliance fix in the entire Act.
  3. Answer the provider question. If you fine-tune, substantially modify, or white-label GPAI models for the EU market, get a written opinion on whether you cross into provider territory.
  4. Assign owners. Article 50 usually lands between legal, marketing, and product — which means it lands on nobody. Name a person.
  5. Start the evidence trail. A dated record of what you inventoried, decided, and fixed is worth more in an inquiry than a perfect policy PDF. Regulators forgive gaps; they do not forgive blindness.

FAQ

Is August 2, 2026 still a deadline at all?

Yes — for GPAI enforcement and Article 50 transparency. It stopped being the high-risk deadline when the Digital Omnibus became final in June 2026. If a vendor or consultant is still pitching August 2 as your high-risk compliance cliff, they are working from a pre-June script.

We're a deployer, not a model provider. Can we be fined on August 2?

For high-risk obligations, no — those start December 2027. But Article 50 applies to deployers of chatbots and content-generating systems, prohibitions have applied since 2025, and national authorities can act on both from August 2. "Deployer" is not a safe harbor; it just changes which articles reach you first.

Does Article 50 cover internal-only chatbots?

The disclosure duty covers people interacting with the system. For purely internal tools where employees plainly know they are using AI, the obvious-from-context exemption usually carries it — but the moment a bot faces customers, applicants, or the public, disclose. When in doubt, the disclosure line costs you nothing.

What is due December 2, 2026?

The machine-readable marking layer of Article 50 — watermarking and provenance metadata for AI-generated content. The omnibus granted that grace period because the technical standards lag. Human-facing disclosure is not covered by the grace period.

Should we slow down because high-risk moved to 2027?

Slow down the panic, not the program. The high-risk work has 6–12 month lead times, your customers' procurement questionnaires will not wait for the regulator, and the AI inventory you need for December 2027 is the same one you need for a GPAI documentation request this year. Sequencing changed; the work did not.

Sources: Council of the EU — final approval of the Digital Omnibus (June 29, 2026) · European Commission — AI Act regulatory framework · Commission guidelines for GPAI providers · EU AI Act implementation timeline · Regulation (EU) 2024/1689 on EUR-Lex.

Related: EU AI Act August 2, 2026: What's Enforced, What's Delayed · The EU AI Act Delay Is Final: High-Risk Rules Move to December 2, 2027 · EU AI Act Compliance Checklist: CISO Action Plan · The NIST × ISO × EU AI Act Compliance Crosswalk.

See AccuroAI in action.
30-minute demo tailored to your top AI risk.
Book a demo
More from the blog
See AccuroAI in action.

Book a 30-minute demo and see how security teams use AccuroAI to discover, govern, and protect every AI asset across their organization.

Book a demoTalk to security