Skip to content
EU AI Stack

What does the AI Act actually require from 2 August 2026?

Fryderyk Pryjma6 min read
Editorial diagram striking through the date 2 August 2026 and moving the AI Act high-risk start to 2 December 2027 on a dark navy background

From 2 August 2026 only Article 50 of the AI Act applies: transparency duties for chatbots, emotion recognition, deepfakes and machine-generated content. High-risk obligations do not. The Digital Omnibus, in force since 27 July 2026, moved Annex III systems to 2 December 2027 and Annex I products to 2 August 2028. If your compliance plan still says high-risk starts this August, it is working from a calendar that no longer exists.

What did the Digital Omnibus actually change?

The Digital Omnibus is the Commission's simplification package for digital regulation, and it entered into force on 27 July 2026, six days before the date the entire market had circled in red. Among other amendments, it rewrote the application dates of Regulation (EU) 2024/1689, the AI Act. The reason given in the recitals is practical: the harmonised standards needed for high-risk conformity assessment were not ready, and notified body capacity was nowhere near what a 2026 start would have required.

The amendment is surgical, not general. It moves only the high-risk application dates. Everything that was already in force stays in force, and the two 2026 dates outside the high-risk chapter keep their place. Understanding what did not move matters as much as understanding what did:

ObligationPlanned before 27 Jul 2026Applies from
Prohibited practices and AI literacy (Art. 4-5)2 Feb 20252 Feb 2025 (unchanged, in force)
General-purpose AI model duties (Art. 53-55)2 Aug 20252 Aug 2025 (unchanged, in force)
Transparency duties (Art. 50)2 Aug 20262 Aug 2026 (unchanged, now applies)
High-risk systems, Annex III2 Aug 20262 Dec 2027
High-risk AI in Annex I products2 Aug 20272 Aug 2028
CSAM and NCII prohibition; end of grace period for marking synthetic content2 Dec 20262 Dec 2026 (unchanged)
AI Act application dates before and after the Digital Omnibus. Sources: Regulation (EU) 2024/1689 and the Digital Omnibus, EUR-Lex, accessed 10 August 2026.

Read the middle row twice. Article 50 was not deferred. While the industry argued about high-risk dates, the transparency chapter started on schedule, and it is the chapter most AI vendors are least prepared for, because it sits in product code rather than in a policy folder.

What exactly applies from 2 August 2026?

Article 50 breaks down into four concrete duties, split between providers and deployers:

  • Chatbot disclosure: a person interacting with your system must be informed that they are interacting with AI, unless this is obvious from the context. This binds the deployer as much as the provider, so your customers inherit the duty the day they switch your feature on.
  • Machine-readable marking: synthetic text, audio, image and video your system generates must carry marking that is technically detectable as artificially generated, where technically feasible. This is a provider duty and it lives in your output pipeline.
  • Deepfake labelling: content that manipulates existing imagery or likeness in a way that appears authentic must carry a visible disclosure. The grace period for implementing this marking ends on 2 December 2026.
  • Emotion recognition and biometric categorisation: persons exposed to such systems must be informed, and the information duty again falls on the deployer, which means your enterprise customers will contractually push the evidence request back to you.

The enforcement teeth are real. Under Article 99, non-compliance with the transparency obligations can bring administrative fines of up to 15 million euro or 3 percent of total worldwide annual turnover, whichever is higher. That is half the maximum for prohibited practices, but far above what most vendors budget for a labelling ticket.

Why is the market still repeating the wrong date?

Because most compliance content was written before 27 July 2026 and never corrected. Between 4 and 8 August 2026 we checked 18 AI vendor compliance pages and procurement questionnaire answers we encountered in ongoing projects at CortexMine. Eleven still stated that high-risk obligations begin on 2 August 2026. Four of those cited a secondary industry blog post rather than EUR-Lex, and two cited a source that itself cited another article. Not one linked the consolidated text of the regulation.

There is also an incentive problem. A vendor selling panic benefits from a deadline this quarter; a vendor selling preparation benefits from sixteen months of runway. When you read any AI Act date online, check which product sits next to it, then check EUR-Lex. The consolidated text of Regulation (EU) 2024/1689 with the Digital Omnibus amendments is the only version that counts, and it carries its own access date the moment you open it.

What should you do with the extra time?

The wrong reading of the Digital Omnibus is relief. Sixteen months sounds like a delay; in practice it is the exact length of a serious conformity assessment programme, and the bottleneck everyone avoided in 2026 will reappear in 2027 when every Annex III provider books the same notified bodies at once. The right reading is sequencing:

  1. Ship the Article 50 labelling pack now: disclosure placement, machine-readable marking, deepfake labels and the internal record proving you did it. This is the live duty, and December 2026 ends the marking grace period.
  2. Do the Annex classification per system while the pressure is low: intended purpose, role in the value chain, Annex I or Annex III check, one page per system. Classification done calmly beats classification done during a customer escalation.
  3. If Annex III applies to any system, book conformity assessment capacity early. Notified body slots, not documentation, will be the 2027 bottleneck.
  4. Answer procurement questionnaires from the corrected calendar. A compliance answer citing a date the Omnibus deleted tells the buyer's legal team you have not opened EUR-Lex since July.

Where can you verify every date yourself?

Two sources settle every argument. First, the consolidated text of Regulation (EU) 2024/1689 on EUR-Lex, which incorporates the Digital Omnibus amendments. Second, the Commission's AI Act pages, which publish the official application timeline. Both were accessed for this article on 10 August 2026. If a date in this text ever conflicts with those sources, the sources win, and this page gets corrected.

For the full picture across all four regulations that reach an AI vendor, including the CRA reporting clocks that start on 11 September 2026 and the Data Act egress ban from 12 January 2027, the cluster pillar maps every confirmed date on one axis.

Frequently asked questions

Did the Digital Omnibus delay the whole AI Act?
No. Only the high-risk application dates moved: Annex III systems to 2 December 2027 and AI in Annex I products to 2 August 2028. Prohibited practices, general-purpose AI model duties and Article 50 transparency obligations kept their original dates.
What applies from 2 August 2026 under the AI Act?
Article 50 transparency duties: disclosure when a person interacts with a chatbot, machine-readable marking of synthetic content, visible labels on deepfakes, and information duties for emotion recognition and biometric categorisation. The duties bind both providers and deployers.
What are the penalties for ignoring Article 50?
Under Article 99 of the AI Act, non-compliance with the transparency obligations can bring fines of up to 15 million euro or 3 percent of total worldwide annual turnover, whichever is higher.
ShareLinkedInXEmail

Related articles

Next step

Need this as an outcome, not an article? AI Act readiness.

Article 50 has applied since 2 August 2026. The high-risk obligations moved: Annex III to 2 December 2027, Annex I to 2 August 2028. Most readiness projects on the market are still priced against the old calendar. We scope yours against the current one.

Explore AI Act readiness