Compyl
GRC Your Way

The EU AI Act’s High-Risk Deadline Moved: What Actually Took Effect on August 2, 2026

Compyl Research

The EU AI Act’s High-Risk Deadline Moved: What Actually Took Effect on August 2, 2026

By Compyl ResearchLast updated: August 11, 20267 min read

On August 2, 2026 the EU AI Act’s transparency obligations became applicable and the Commission’s AI Office gained power to fine general-purpose AI providers up to 3% of global turnover. The high-risk obligations expected that day did not arrive: Regulation (EU) 2026/1744 moved Annex III systems to December 2, 2027 and product-embedded systems to August 2, 2028.

Key takeaways
  • The high-risk deadline moved, but only for Chapter III. Regulation (EU) 2026/1744, in force since July 27, 2026, defers Annex III high-risk obligations to December 2, 2027 and Annex I product-embedded systems to August 2, 2028.
  • Article 50 transparency applies now. Chatbot disclosure, deepfake labeling, and machine-readable marking of synthetic content became applicable on August 2, 2026, with a grace period to December 2, 2026 for generative systems already on the market.
  • GPAI fines are live. The AI Office can now request documentation, evaluate models, and fine general-purpose AI providers up to EUR 15 million or 3% of worldwide annual turnover under Article 101.
  • Penalties for prohibited practices reach EUR 35 million or 7% of worldwide turnover, and the Commission confirms prohibitions became enforceable on August 2, 2026.
  • Member state enforcement capacity is thin. The designation deadline for national authorities was August 2, 2025, and as of mid-2026 only a minority of member states had fully designated authorities or passed implementing legislation.

What Actually Took Effect on August 2, 2026?

Three things changed on August 2, 2026 — and none of them was the high-risk regime most compliance teams spent 2025 preparing for.

First, Article 50 transparency obligations became applicable. Providers of AI systems that interact directly with people must ensure users are informed they are dealing with an AI. Providers of generative systems must mark synthetic audio, image, video, and text in a machine-readable format that is detectable as artificially generated. Deployers of emotion recognition or biometric categorization systems must notify the people exposed to them, and deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, per the Article 50 rules as summarized by the AI Act explorer. Generative systems already on the market before August 2, 2026 have until December 2, 2026 to complete the machine-readable marking required by Article 50(2).

Second, the Commission’s enforcement toolkit for general-purpose AI switched on. Since August 2, 2026 the AI Office can request technical documentation, conduct model evaluations, demand corrective measures, and impose fines on GPAI model providers. Wilson Sonsini noted in an August 3, 2026 client alert that these powers sit with the AI Office rather than national market surveillance authorities.

Third, the Commission’s own guidance closed out. The Commission published its final Article 50 guidelines on July 20, 2026 and confirmed the Code of Practice on Transparency of AI-generated Content — published June 10, 2026 — as an adequate voluntary route to demonstrating compliance. Roughly 190 companies and organizations had signed it by the end of July 2026. Signing evidences good-faith compliance but does not discharge the statutory duty.

The Commission’s AI Act Service Desk states the position plainly: from August 2, 2026 the provisions on prohibited AI practices, transparency requirements for certain AI systems, and the rules for general-purpose AI models are enforceable.

What Did the Digital Omnibus Actually Delay?

Regulation (EU) 2026/1744 of July 8, 2026 — the Digital Omnibus on AI — entered into force on July 27, 2026, six days before the original deadline. It amends Regulation (EU) 2024/1689 and two product-safety regulations.

The deferral covers all of Chapter III: risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity, conformity assessment, EU database registration, and the deployer duties in Articles 26 and 27. The European Commission’s AI Act page now records that high-risk use cases in the sensitive areas listed in Annex III apply from December 2, 2027, while high-risk AI embedded in regulated products under Annex I applies from August 2, 2028.

The stated rationale is standards readiness. The harmonized standards that give providers a presumption of conformity are still in the pipeline: CEN-CENELEC reported in its 2026 update on European standards supporting the AI Act that prEN 18286 on quality management systems had completed public enquiry and moved to formal vote, prEN 18228 on risk management was in public enquiry, and prEN 18283 on managing bias was still under development.

Four other changes matter for planning. National AI regulatory sandboxes, originally due to be operational by August 2, 2026, are now due by August 2, 2027. Article 4 on AI literacy was rewritten as an obligation of means — providers and deployers must support the development of AI literacy among staff, but are not required to guarantee any individual’s competence level. Two new prohibitions were added to Article 5 covering AI systems that generate non-consensual intimate imagery or child sexual abuse material, with a transition period to December 2, 2026. And a new “small mid-cap” category (under 750 employees and turnover at or below EUR 150 million) gets simplified documentation and proportionate penalty caps.

Obligation Applies from Status as of August 11, 2026
Prohibited practices (Article 5) Feb 2, 2025 In force; enforceable since Aug 2, 2026
AI literacy (Article 4) Feb 2, 2025 In force; reworded as an obligation of means
GPAI model obligations (Chapter V) Aug 2, 2025 In force
Governance, notified bodies, national penalty regimes Aug 2, 2025 In force; unevenly implemented
Transparency for certain AI systems (Article 50) Aug 2, 2026 Applies now
Commission fines for GPAI providers (Article 101) Aug 2, 2026 Applies now
Marking of content from pre-existing generative systems (Article 50(2)) Dec 2, 2026 Grace period running
New prohibitions on NCII and CSAM generators Dec 2, 2026 Transition period running
National AI regulatory sandboxes (Article 57) Aug 2, 2027 Deferred from Aug 2, 2026
Legacy GPAI models placed on market before Aug 2, 2025 Aug 2, 2027 Pending
High-risk standalone systems (Annex III, Chapter III) Dec 2, 2027 Deferred from Aug 2, 2026
High-risk systems embedded in regulated products (Annex I) Aug 2, 2028 Deferred from Aug 2, 2027

Our EU AI Act compliance timeline tracks each of these dates as they shift.

Are the Penalties Real Yet?

Yes — for the obligations that are actually in force. Article 99 sets three tiers: up to EUR 35 million or 7% of total worldwide annual turnover for breaching the Article 5 prohibitions; up to EUR 15 million or 3% for most other infringements, including Article 50 transparency duties; and up to EUR 7.5 million or 1% for supplying incorrect, incomplete, or misleading information to authorities or notified bodies. In each case the higher of the two figures applies, except for SMEs and start-ups, where the lower figure applies.

Separately, Article 101 gives the Commission the power to fine general-purpose AI model providers up to EUR 15 million or 3% of worldwide annual turnover for infringing the regulation, failing to comply with information requests, ignoring requested measures, or refusing model access for evaluation. Those powers became operative on August 2, 2026.

Two caveats keep this in proportion. Fines under Article 99 attach only to obligations that have become applicable, so nothing in the deferred high-risk regime is fineable until December 2027 at the earliest. And Article 99 penalties are imposed by member states through their national regimes — which is where the picture gets uneven.

Are Member States Ready to Enforce?

Mostly not. Article 70(2) required every member state to designate its notifying authority and market surveillance authorities and communicate them to the Commission by August 2, 2025. A year past that deadline, the AI Act national implementation tracker records only nine member states as having clearly designated both categories, twelve with partial or announced designations, and six with no designated competent authorities at all. The one deadline that was met cleanly was the earlier one: all 27 member states designated fundamental rights authorities under Article 77 by November 2, 2024.

National implementing legislation is further behind. Cullen International’s April 2026 snapshot found only three member states — Denmark, Finland, and Italy — had adopted national AI laws, with proposals pending in nine more. Italy was first, with Law No. 132/2025 entering into force on October 10, 2025.

The practical consequence: the venue with real capacity right now is Brussels, not the capitals. The AI Office has centralized supervision of general-purpose AI models, a staffed enforcement function, and a signed code of practice to measure providers against. National market surveillance of AI systems — the machinery that would police an ordinary deployer’s Article 50 breach — is patchy and in several jurisdictions does not yet exist in designated form. That is a transitional condition, not a reprieve: the extra months on the high-risk clock exist so member states, notified bodies, and standards bodies can build the capacity that was missing in August 2026.

What Should In-Scope Companies Do Now?

AI deployment has outpaced AI governance. Eurostat reported on December 11, 2025 that 20.0% of EU enterprises with ten or more employees used AI technologies in 2025, up from 13.5% in 2024 — a 6.5 percentage point jump in a single year, led by Denmark at 42.0%. The obligations moved; the systems did not.

Four priorities for the next quarter:

  1. Close out Article 50 now. Inventory every user-facing system: chat interfaces, voice agents, synthetic media tooling, AI-assisted publishing. Confirm disclosure at first interaction, confirm machine-readable marking on generative outputs, and confirm deployer-side deepfake labeling. Systems already live before August 2, 2026 have until December 2, 2026 for the marking requirement — that window is four months wide, not four quarters.
  2. Finish the classification work anyway. Knowing which of your systems fall into Annex III is the input to every downstream decision, and the criteria did not change. Our EU AI Act compliance guide walks through the classification logic and the Chapter III obligations that now land in December 2027.
  3. Build the management system, not the paperwork. The deferral buys time to stand up something auditable rather than assemble a document set. ISO/IEC 42001 maps closely to the AI Act’s quality and risk management expectations, and prEN 18286 is built on the same foundations. See how the frameworks line up in our comparison of NIST AI RMF, ISO 42001, and the EU AI Act.
  4. Push the diligence upstream. If you deploy someone else’s models, your Article 50 marking position depends on their implementation. Get contractual commitments on watermarking, provenance metadata, and code-of-practice signatory status at the next renewal.

For teams starting from a blank page, our AI governance implementation guide sequences the inventory, classification, and control work into a program you can run against the December 2027 date.

Frequently asked questions

Did the EU AI Act’s high-risk rules take effect on August 2, 2026?
No. Regulation (EU) 2026/1744, in force since July 27, 2026, moved the Annex III high-risk obligations to December 2, 2027 and high-risk AI embedded in regulated products under Annex I to August 2, 2028. Only the transparency, prohibition, and general-purpose AI provisions became enforceable on August 2, 2026.
What is the Digital Omnibus on AI?
It is Regulation (EU) 2026/1744, adopted July 8, 2026 and in force July 27, 2026. It amends the AI Act to defer high-risk deadlines, soften the Article 4 AI literacy duty, postpone national regulatory sandboxes to August 2, 2027, add prohibitions on intimate-imagery and CSAM generators, and create relief for small mid-cap companies.
What are the penalties under the EU AI Act right now?
Article 99 allows fines up to EUR 35 million or 7% of worldwide annual turnover for prohibited practices, EUR 15 million or 3% for most other breaches including Article 50 transparency, and EUR 7.5 million or 1% for misleading information. SMEs face the lower of the two figures. Article 101 lets the Commission fine GPAI providers up to EUR 15 million or 3%.
Do I have to label AI-generated content in the EU now?
Yes. Article 50 applied from August 2, 2026. Providers of generative systems must mark outputs in a machine-readable, detectable format, and deployers must disclose deepfakes and certain AI-generated public-interest text. Generative systems placed on the market before August 2, 2026 have until December 2, 2026 to complete machine-readable marking.
Which authority enforces the EU AI Act?
The Commission’s AI Office supervises general-purpose AI models and holds the Article 101 fining power that became operative on August 2, 2026. National market surveillance authorities enforce most obligations on AI systems, but designation is incomplete: only a minority of member states have fully designated authorities and only three had adopted national implementing laws as of April 2026.
Should companies pause their AI Act compliance work?
No. Transparency obligations, prohibitions, and GPAI rules are enforceable today, and the deferred high-risk requirements still demand risk management systems, data governance, technical documentation, human oversight, and conformity assessment by December 2, 2027. The extension is time to build auditable governance, not a cancellation.

Track Every EU AI Act Deadline in One Place with Compyl

Compyl maps your AI systems to AI Act obligations, ISO 42001, and the NIST AI RMF in a single control set, so a shifting deadline updates your program instead of restarting it. See continuous evidence collection and automated control monitoring against the December 2027 high-risk date.

Request a demo →

About this article. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.


By clicking “Accept”, you agree to the use of cookies on your device in accordance with our Privacy and Cookie policies