EU AI Act Delayed: What Still Applies on 2 August 2026

Did you see the headline “EU delays the AI Act” and quietly move compliance onto next year’s pile? You would not be the first. The headline is true. It is also the most expensive half-truth in European tech right now, because the rules did not all move together. One set of duties became applicable on 2 August 2026, and it reaches far more businesses than most founders assume.

The EU AI Act, formally Regulation (EU) 2024/1689, is the world’s first comprehensive law on artificial intelligence. It sorts AI systems by the risk they create, from prohibited practices at the top, through high-risk systems carrying a heavy compliance regime, down to systems subject only to transparency duties or to none at all. It entered into force on 1 August 2024 and applies in phases.

In the summer of 2026 the EU rewrote part of that calendar. The Digital Omnibus on AI, Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. This article explains what it postponed, what it left untouched, which duties land on ordinary businesses that merely use AI, and what the penalties look like.

Credit where it is due. The postponement is genuine, and it covers the heaviest part of the Act.

High-risk AI systems are those listed in Annex III, meaning systems used for purposes such as screening job applicants, evaluating students, assessing creditworthiness or operating critical infrastructure, together with AI embedded in products already regulated under the EU harmonisation legislation listed in Annex I, such as medical devices, machinery and toys. Providers of high-risk systems face the full package: risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity requirements, plus conformity assessment.

Those obligations were due on 2 August 2026. Under the Digital Omnibus, standalone Annex III systems now have until 2 December 2027, a deferral of sixteen months, and high-risk AI embedded in Annex I regulated products has until 2 August 2028, a deferral of twelve months. The new dates are fixed rather than tied to the availability of harmonised standards, which is what the Commission had originally proposed. Systems placed on the market before the relevant date fall within the requirements only if they are substantially modified afterwards.

Why the change? Because the supporting infrastructure was not ready. The harmonised technical standards and compliance tools businesses need in order to demonstrate conformity had not been finalised.

Here is the part of the headline almost nobody read. Article 50 of the AI Act, the transparency regime, became applicable on 2 August 2026 exactly as originally scheduled. It imposes four duties.

First, providers of AI systems intended to interact directly with people must design them so that individuals are informed they are dealing with an AI system, unless that is obvious to a reasonably well-informed person. Second, providers of generative AI systems must mark synthetic audio, image, video and text outputs in a machine-readable format detectable as artificially generated. Third, deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. Fourth, deployers must disclose deepfakes, meaning AI-generated or manipulated image, audio or video content resembling real persons or events that would falsely appear authentic, and must also disclose AI-generated or manipulated text published to inform the public on matters of public interest.

Each duty carries carve-outs. Where deepfake content forms part of an evidently artistic, creative, satirical or fictional work, disclosure is limited to a form that does not hamper enjoyment of the work. The text disclosure duty does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for its publication. Certain law enforcement uses are also exempt.

The information must be provided clearly and distinguishably, at the latest at the time of first interaction or exposure, and in an accessible format. The Commission adopted its final Guidelines on these obligations and confirmed the voluntary Code of Practice on the Marking and Labelling of AI-Generated Content. The Guidelines make clear that burying a disclosure in your terms and conditions does not satisfy Article 50(1).

The AI Act does not regulate only the companies building AI systems, called providers. Several duties fall on deployers, meaning any business using an AI system under its own authority in the course of a professional activity.

Publish a marketing video containing AI-generated footage of something that never happened, and the labelling duty is yours. Publish AI-written articles on matters of public interest with no human editorial review, and the disclosure duty is yours. Run emotion recognition on customers, and the notification duty is yours, though you should first check whether that particular use is prohibited outright.

The chatbot on your website is the interesting case. Designing the disclosure is legally the provider’s obligation under Article 50(1), but it is your website, your customers and your brand in the screenshot. Two practical steps follow. Confirm the disclosure is actually live and visible, and review your vendor contract to see whether anyone has warranted AI Act compliance in writing. If nobody has, the commercial risk sits with you by default.

Two earlier waves are routinely overlooked.

Since 2 February 2025, the prohibitions in Article 5 have applied. They cover, among others, social scoring, AI using subliminal or manipulative techniques that materially distort behaviour and cause significant harm, exploitation of vulnerabilities linked to age, disability or socio-economic situation, untargeted scraping of facial images from the internet or CCTV footage to build facial recognition databases, and emotion recognition in the workplace and in education institutions outside narrow medical and safety purposes.

Also since 2 February 2025, Article 4 has required AI literacy. The Digital Omnibus softened the wording from a duty to ensure a sufficient level of literacy into a duty to take measures supporting its development, which converts it from an obligation of result into an obligation of effort. The duty itself survived and remains binding on every provider and deployer.

Since 2 August 2025, providers of general-purpose AI models have had their own rulebook. If you build on top of someone else’s foundation model, that layer is largely your supplier’s responsibility.

Four dates now matter.

2 August 2026. Article 50 transparency obligations apply, and national market surveillance authorities gain their supervisory powers.

2 December 2026. Machine-readable marking applies to legacy generative systems, and two new prohibitions take effect, targeting AI systems that generate non-consensual intimate imagery, including so-called nudifier applications, and AI-generated child sexual abuse material.

2 December 2027. High-risk obligations apply to standalone Annex III systems.

2 August 2028. High-risk obligations apply to AI embedded in Annex I regulated products.

Penalties sit in three tiers under Article 99. Breach of the Article 5 prohibitions attracts administrative fines of up to 35 million euros or 7 percent of total worldwide annual turnover, whichever is higher. Breach of provider, deployer or transparency obligations, including Article 50, attracts up to 15 million euros or 3 percent, whichever is higher. Supplying incorrect, incomplete or misleading information to authorities attracts up to 7.5 million euros or 1 percent. There is meaningful relief for smaller businesses. For SMEs, including start-ups, the ceiling is whichever of the two figures is lower, and the Digital Omnibus extended comparable proportionality to a newly defined category of small mid-cap enterprises.

One caution to tape beside that calendar. This was a delay, not a pardon. The same package strengthened the AI Office, giving it exclusive supervisory competence over AI systems built on general-purpose models from the same provider and over AI systems integrated into very large online platforms and search engines. The regulator got stronger while the deadline got kinder.

The delay bought time for one specific group, namely providers of high-risk AI. Everyone else is already inside the regime, including SaaS businesses running chatbots, agencies publishing AI-assisted content and companies whose staff simply use AI tools at work.

The practical next steps are unglamorous and effective. Classify every AI system you provide or deploy. Verify that your chatbot, deepfake and emotion recognition disclosures are live and visible at first contact. Check what your vendors have actually warranted. Document your AI literacy measures. And if you are building high-risk AI, treat the extra months as a project plan rather than a pause.

Have specific questions?

Not ready for a call

No worries! In the meantime, subscribe to our Knowledge center to stay updated on the latest legal developments.

And don't worry, it's free!

Share the Post:

Related Posts

Related Posts
Loading related posts…
Scroll to Top