sakutto
Generative AI

EU AI Act: What Actually Starts on August 2, 2026 | GPAI Enforcement and the High-Risk Delay

EU AI ActAI RegulationCompliance
EU AI Act: What Actually Starts on August 2, 2026 | GPAI Enforcement and the High-Risk Delay

What August 2, 2026 means for the EU AI Act

The EU AI Act is the EU's comprehensive AI regulation, which entered into force on August 1, 2024. It sorts AI into four levels of risk and attaches different obligations to each level. August 2, 2026 was set from the outset as the date the law becomes applicable in principle. But as the European Commission itself writes, it comes "with some exceptions" — not everything starts on this date.

One thing shifted right before the deadline. The "AI Omnibus" regulation, which simplifies the AI Act, entered into force just six days earlier on July 27, 2026, and rewrote some of the dates.

The AI Act's application schedule (as published by the European Commission)

WhenWhat appliesStatus
August 1, 2024The law itself enters into forceApplied
February 2, 2025Prohibitions 1–8 and AI literacy obligations (ensuring staff working with AI have adequate knowledge)Applied
August 2, 2025Governance rules and obligations for GPAI modelsApplied
August 2, 2026Application in principle (transparency obligations, GPAI enforcement)Now applicable
December 2026Prohibition 9 (generating sexual deepfakes and child sexual abuse material, CSAM)Upcoming
December 2, 2027High-risk AI (Annex III, standalone use)Extended deadline
August 2, 2028High-risk AI (Annex I, embedded in products)Extended deadline
View official source →
The AI Act defines 4 levels of risk for AI systems / The AI Act entered into force on 1 August 2024, and becomes on 2 August 2026, with some exceptions / prohibited AI practices and AI literacy obligations entered into application from 2 February 2025 / the governance rules and the obligations for GPAI models became applicable on 2 August 2025 / the rules for high-risk AI systems embedded into regulated products (Annex I) have an extended transition period until 2 August 2028 and the rules for high-risk use cases in certain sensitive areas (Annex III) have been extended to 2 December 2027 / Prohibition 9 comes into effect in December 2026 and was introduced as a part of the AI Omnibus package. / This legislative proposal (dubbed as the 'AI Omnibus') was adopted on 19 November 2025, a political agreement was reached on 7 May 2026 and entered into force on 27 July 2026. — From the four risk levels, the entry into force and the August 2, 2026 application date (with exceptions), the two 2025 dates, the extended deadlines for high-risk and Prohibition 9, and the AI Omnibus entry into force (the phrase `becomes on` appears as written on the source page)

What begins on August 2, 2026

Two things start moving on this date. The first is the transparency obligations in Article 50 — telling people they are dealing with AI, and marking generated content. The second is enforcement. The Commission's AI Office and the Member State authorities formally took up responsibility for implementing, supervising, and enforcing the Act.

This is the change that matters most in practice. The obligations for GPAI models had existed since August 2, 2025 — but an obligation existing and an authority being able to punish you are two different things. From August 2, the AI Office can request technical documentation, evaluate models, require corrective measures, and issue fines. The stretch where rules existed but went unenforced is over.

View official source →
From 2 August 2026, the AI Office and authorities of the Member States are responsible for implementing, supervising and enforcing the AI Act. The AI Office holds enforcement powers over GPAI models. It can request technical documentation, evaluate models, require corrective measures and issue fines for non-compliance. / The transparency rules of the AI Act will come into effect in August 2026. — From the description of governance, enforcement, and when the transparency rules take effect

What does not begin on August 2, 2026

Knowing what does not start keeps you from over-preparing. Obligations for "high-risk AI" — hiring, credit, education, critical infrastructure, the uses with heavy consequences for people's lives — do not start on August 2. Standalone high-risk AI (Annex III) moved to December 2, 2027, and high-risk AI embedded in products (Annex I) to August 2, 2028.

The stated reason for the extension is to let supporting tools such as standards reach companies before the obligations bite. The substance of the obligations did not disappear. Only the start date moved. The background to the delay is covered in detail in our article on the EU AI Act Omnibus.

The ninth prohibition — AI that generates non-consensual sexual imagery or CSAM, the so-called "nudification" apps — also lands in December 2026 rather than August 2. Prohibitions 1 through 8 have been in effect since February 2025.

View official source →
the rules for high-risk AI systems embedded into regulated products (Annex I) have an extended transition period until 2 August 2028 and the rules for high-risk use cases in certain sensitive areas (Annex III) have been extended to 2 December 2027 as a result of the political agreement on the proposal to simplify the AI Act – 'AI Omnibus' / Prohibition 9 comes into effect in December 2026 and was introduced as a part of the AI Omnibus package. / AI systems that generate non-consensual sexually explicit and intimate content or child sexual abuse (CSAM) material, such as AI 'nudification' apps — From the high-risk application schedule and the substance and timing of Prohibition 9

What the transparency obligations actually require

The transparency obligations are nothing like the heavy apparatus required of high-risk AI. They amount to making it clear that this is AI — that is all. But the scope is broad, and most businesses offering AI-powered services fall inside it. The obligations split between providers (those who build) and deployers (those who use).

Article 50 transparency obligations (who owes what)

Providers (para. 1)
AI that interacts directly with people must be designed so people know it is AI
Providers (para. 2)
Mark generated audio, image, video, and text in a machine-readable format
Deployers (para. 3)
Inform people exposed to emotion recognition or biometric categorisation that it is operating
Deployers (para. 4)
Disclose that deepfake content was artificially generated
Both (para. 5)
Provide the information clearly, no later than the first interaction or exposure
View official source →
Deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto of the operation of the system, and shall process the personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable. — From the provision requiring deployers of emotion recognition and biometric categorisation systems to inform those exposed to them

Chatbots have to be designed so people know it is AI

Article 50(1) requires providers of AI systems that interact directly with people to design and develop them so the person is informed they are interacting with an AI system. There are two exceptions. One is where this is obvious to a natural person who is reasonably well-informed, observant and circumspect. The other covers AI systems authorised by law to detect, prevent, investigate, or prosecute criminal offences, subject to appropriate safeguards for third parties' rights and freedoms — though systems available to the public for reporting a criminal offence are carved back in. The second is aimed at law enforcement, so only the first is relevant to ordinary businesses. For an AI chat window on your own site, stating it outright beats leaning on the exception.

The timing of the notice is fixed too. The information under paragraphs 1 to 4 must be provided in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. Not mid-conversation, and not buried in the terms of service — at the entrance.

View official source →
Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. This obligation shall not apply to AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to appropriate safeguards for the rights and freedoms of third parties, unless those systems are available for the public to report a criminal offence. / The information referred to in paragraphs 1 to 4 shall be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. — From Article 50(1), including both exceptions, and Article 50(5)

Generated content has to carry a machine-readable mark

Paragraph 2 requires providers of AI that generates synthetic audio, image, video, or text to mark the outputs in a machine-readable format so they are detectable as artificially generated or manipulated. General-purpose AI systems are named as included. The implementation detail worth noticing: what is required is an embedded mark a machine can read, not a human-visible "AI generated" label.

Paragraph 4 falls on the using side. Deployers who generate or manipulate image, audio, or video content constituting a deepfake must disclose that it was artificially generated or manipulated. The builder marks; the user discloses. Two layers.

To help with this, the European Commission is preparing a Code of Practice on marking and labelling AI-generated content, along with transparency guidelines. The code is positioned as a voluntary tool to guide providers and deployers of generative AI toward compliance. Not mandatory — but useful to work from.

View official source →
Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated. / Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated. — From Article 50(2) and 50(4)
View official source →
The code will be a voluntary tool to guide providers and deployers of generative AI systems to comply with transparency obligations. — From the description of the code's status

The code of practice and the guidelines are both in English and both long. If you only need to pull the relevant provisions accurately, converting the web page to Markdown first moves faster.

Free ToolURL to Markdown ConverterConvert any public web page URL to Markdown. Preserves headings, tables, lists, and links — perfect for LLM and RAG preprocessing, research notes, and archiving web articles.Try it now →

GPAI enforcement and how large the fines are

The other pillar is enforcement against general-purpose AI models. GPAI means the foundational models usable across a wide range of purposes, and they sit underneath a great many AI systems in the EU. Supervisory power in this area was concentrated in the Commission's AI Office rather than left with Member States. The AI Omnibus explicitly reinforces the AI Office's powers and centralises oversight, a design meant to avoid divergence across Member States.

View official source →
Reinforce the AI Office's powers and centralise oversight of AI systems built on general-purpose AI models, reducing governance fragmentation — From the description of how the AI Omnibus reinforces the AI Office's powers and centralises oversight

Fines cap at EUR 15 million or 3% of worldwide turnover, whichever is higher

Fines against providers of GPAI models sit in Article 101. The ceiling is 3% of annual total worldwide turnover in the preceding financial year or EUR 15,000,000, whichever is higher. The Commission imposes them, and the triggers are intentional or negligent infringement, plus failure to supply requested documents or information, supplying misleading information, failing to comply with a requested measure, and refusing the Commission access to a model for evaluation.

There are procedural protections. Before imposing a fine, the Commission must communicate its preliminary findings to the provider and give it an opportunity to be heard. Decisions are reviewable by the Court of Justice of the European Union with unlimited jurisdiction to cancel, reduce, or increase the fine. The structure is not "maximum penalty out of nowhere" but a sanction arrived at through exchange.

View official source →
The Commission may impose on providers of general-purpose AI models fines not exceeding 3 % of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher. / when the Commission finds that the provider intentionally or negligently: / (a) infringed the relevant provisions of this Regulation; / (b) failed to comply with a request for a document or for information pursuant to Article 91, or supplied incorrect, incomplete or misleading information; / (c) failed to comply with a measure requested under Article 93; / (d) failed to make available to the Commission access to the general-purpose AI model or general-purpose AI model with systemic risk with a view to conducting an evaluation pursuant to Article 92. / Before adopting the decision pursuant to paragraph 1, the Commission shall communicate its preliminary findings to the provider of the general-purpose AI model and give it an opportunity to be heard. / The Court of Justice of the European Union shall have unlimited jurisdiction to review decisions of the Commission fixing a fine under this Article. It may cancel, reduce or increase the fine imposed. — From the provisions on the fine ceiling and triggering conduct, the prior opportunity to be heard, and the Court of Justice's review powers

Enforcement runs through the AI Office and national authorities

Enforcement is two-tiered. The AI Office holds direct enforcement powers over GPAI models; Member State authorities supervise everything else. What the AI Office can do: request technical documentation, evaluate models, require corrective measures, and impose fines.

The institutional build-out continues. In July 2026 the Commission published an action plan on cybersecurity and AI, stating it will launch a call to increase EU capacity to evaluate AI models before they are placed on the market. That capacity is expected to be operational by 2027. August 2 is the starting line for enforcement, not the finished form of it.

View official source →
The July 2026 action plan on Cybersecurity and AI sets out a coordinated approach to help Member States, businesses and public authorities address cybersecurity and resilience challenges posed by the most advanced AI models. The Commission will launch a call to increase EU evaluation capacity of AI models, before they are placed in the EU market. Expected to be operational by 2027, this will strengthen third-party assessment of AI capabilities and risks and contribute to the regulatory function of the AI Office. — From the description of strengthening evaluation capacity

Who outside the EU is caught, and what to check now

For a business based outside the EU, the first fork is whether you are in scope at all. The Act draws the line not by where you are but by where the output is used, so having no EU establishment does not put you outside it.

Regional differences are worth holding in view as well. In the United States, the federal AI Kill Switch Act is still at the introduction stage, and at state level the Colorado AI Act was repealed before it took effect. On the evidence available, the EU is ahead in reaching the stage of full application of a comprehensive law. Other jurisdictions do have binding AI legislation, though, so reading this as "only the EU" would not be accurate.

If "the output is used in the Union," it applies

Article 2(1) sets out scope in seven parts, and (c) is the one that reaches businesses in third countries. It states plainly that providers and deployers established or located in a third country are covered where the output produced by the AI system is used in the Union. Providers placing AI models on the EU market are covered by (a) regardless of where they sit.

Conversely, a purely domestic service with no EU users and no output used in the EU is not directly covered. The whole judgment starts from one question: is anyone in the EU using the output of your AI?

View official source →
providers placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the Union, irrespective of whether those providers are established or located within the Union or in a third country / providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union — From Article 2(1)(a) and 2(1)(c)

Three things to check right now

If you might be in scope, three items rank highest as of August 2. High-risk obligations have until December 2027, so there is no need to rush those.

  • Do you run a chatbot that reaches users in the EU? If so, check that the entry point makes clear an AI is responding
  • Are you distributing AI-generated content into the EU? If so, check whether you can apply machine-readable marking
  • Does the AI you use qualify as GPAI? If so, confirm with the provider whether they are meeting the transparency and copyright-related obligations

The third gets overlooked. Even if you do not build models, the provider's compliance status feeds directly into whether your own service keeps running. Rather than leaving it to the provider, put it on the checklist at contract renewal.

The Commission's AI Act pages and guidelines are all in English and substantial in volume. If you only want to skim the provisions you need, converting the page to Markdown before handing it to an AI preserves the heading and list structure and improves accuracy. Copying from the screen tends to drag in navigation and decoration, so cleaning it down to body text first is the safer route.

Free ToolURL to Markdown ConverterConvert any public web page URL to Markdown. Preserves headings, tables, lists, and links — perfect for LLM and RAG preprocessing, research notes, and archiving web articles.Try it now →

Conclusion: the one thing to verify is whether your output is used in the EU

August 2, 2026 is the day the EU AI Act moved from regulation on paper to regulation that gets enforced. That does not mean heavy obligations landed all at once. What actually started is transparency obligations and the enforcement machinery. The high-risk obligations, the ones that cost companies the most, slipped to December 2027 and August 2028. For a business outside the EU, the first thing to establish is whether your AI's output is used inside the Union. Start and stop there. If the answer is yes, chatbot notices and marking of generated content are enough to begin with, and high-risk design work can wait. When you go read the provisions or the Commission's explanations yourself, converting to Markdown first keeps the article numbers intact.

Free ToolURL to Markdown ConverterConvert any public web page URL to Markdown. Preserves headings, tables, lists, and links — perfect for LLM and RAG preprocessing, research notes, and archiving web articles.Try it now →

FAQ

Q. Does all of the EU AI Act apply from August 2, 2026?
No. August 2 is the date the Act becomes applicable in principle, but exceptions remain. Obligations for high-risk AI — the systems with heavy consequences for people's lives — were pushed to December 2, 2027 for standalone use (Annex III) and August 2, 2028 for AI embedded in regulated products (Annex I). What actually starts on August 2 is the transparency obligations and the authorities' enforcement machinery over GPAI models.
European Commission — AI Act, Application timeline
The AI Act entered into force on 1 August 2024, and becomes on 2 August 2026, with some exceptions … the rules for high-risk AI systems embedded into regulated products (Annex I) have an extended transition period until 2 August 2028 and the rules for high-risk use cases in certain sensitive areas (Annex III) have been extended to 2 December 2027 European Commission — AI Act, Application timeline
Q. Does it matter if my business operates only outside the EU?
If the output of your AI is used inside the EU, the Act applies even when your establishment is elsewhere. It covers providers and deployers located in a third country where the output produced by the AI system is used in the Union. A purely domestic service with no EU-facing offering is not directly caught.
EU AI Act Article 2(1)(c) — Scope
providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union EU AI Act Article 2(1)(c) — Scope
Q. Does simply having a chatbot create an obligation?
If it interacts directly with people in the EU, you have to design it so the person knows they are talking to an AI system. There is an exception where this is obvious from the point of view of a reasonably well-informed, observant and circumspect person. When in doubt, err toward stating it on screen.
EU AI Act Article 50(1) — Transparency obligations
Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect EU AI Act Article 50(1) — Transparency obligations
Q. How large are the fines?
For providers of general-purpose AI models, the European Commission can impose fines capped at 3% of annual total worldwide turnover in the preceding financial year or EUR 15,000,000, whichever is higher. Intentional or negligent infringement, failure to supply requested documents, and refusing access to a model for evaluation are all covered.
EU AI Act Article 101 — Fines for providers of general-purpose AI models
not exceeding 3 % of their annual total worldwide turnover in the preceding financial year or EUR 15 000 000, whichever is higher EU AI Act Article 101 — Fines for providers of general-purpose AI models

Related Tools

Related Tool Categories

Articles