The EU AI Act’s High-Risk Deadline Moved: What Actually Took Effect on August 2, 2026
On August 2, 2026 the EU AI Act’s transparency obligations became applicable and the Commission’s AI Office gained power to fine general-purpose AI providers up to 3% of global turnover. The high-risk obligations expected that day did not arrive: Regulation (EU) 2026/1744 moved Annex III systems to December 2, 2027 and product-embedded systems to August 2, 2028.
- The high-risk deadline moved, but only for Chapter III. Regulation (EU) 2026/1744, in force since July 27, 2026, defers Annex III high-risk obligations to December 2, 2027 and Annex I product-embedded systems to August 2, 2028.
- Article 50 transparency applies now. Chatbot disclosure, deepfake labeling, and machine-readable marking of synthetic content became applicable on August 2, 2026, with a grace period to December 2, 2026 for generative systems already on the market.
- GPAI fines are live. The AI Office can now request documentation, evaluate models, and fine general-purpose AI providers up to EUR 15 million or 3% of worldwide annual turnover under Article 101.
- Penalties for prohibited practices reach EUR 35 million or 7% of worldwide turnover, and the Commission confirms prohibitions became enforceable on August 2, 2026.
- Member state enforcement capacity is thin. The designation deadline for national authorities was August 2, 2025, and as of mid-2026 only a minority of member states had fully designated authorities or passed implementing legislation.
What Actually Took Effect on August 2, 2026?
Three things changed on August 2, 2026 — and none of them was the high-risk regime most compliance teams spent 2025 preparing for.
First, Article 50 transparency obligations became applicable. Providers of AI systems that interact directly with people must ensure users are informed they are dealing with an AI. Providers of generative systems must mark synthetic audio, image, video, and text in a machine-readable format that is detectable as artificially generated. Deployers of emotion recognition or biometric categorization systems must notify the people exposed to them, and deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, per the Article 50 rules as summarized by the AI Act explorer. Generative systems already on the market before August 2, 2026 have until December 2, 2026 to complete the machine-readable marking required by Article 50(2).
Second, the Commission’s enforcement toolkit for general-purpose AI switched on. Since August 2, 2026 the AI Office can request technical documentation, conduct model evaluations, demand corrective measures, and impose fines on GPAI model providers. Wilson Sonsini noted in an August 3, 2026 client alert that these powers sit with the AI Office rather than national market surveillance authorities.
Third, the Commission’s own guidance closed out. The Commission published its final Article 50 guidelines on July 20, 2026 and confirmed the Code of Practice on Transparency of AI-generated Content — published June 10, 2026 — as an adequate voluntary route to demonstrating compliance. Roughly 190 companies and organizations had signed it by the end of July 2026. Signing evidences good-faith compliance but does not discharge the statutory duty.
The Commission’s AI Act Service Desk states the position plainly: from August 2, 2026 the provisions on prohibited AI practices, transparency requirements for certain AI systems, and the rules for general-purpose AI models are enforceable.
What Did the Digital Omnibus Actually Delay?
Regulation (EU) 2026/1744 of July 8, 2026 — the Digital Omnibus on AI — entered into force on July 27, 2026, six days before the original deadline. It amends Regulation (EU) 2024/1689 and two product-safety regulations.
The deferral covers all of Chapter III: risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity, conformity assessment, EU database registration, and the deployer duties in Articles 26 and 27. The European Commission’s AI Act page now records that high-risk use cases in the sensitive areas listed in Annex III apply from December 2, 2027, while high-risk AI embedded in regulated products under Annex I applies from August 2, 2028.
The stated rationale is standards readiness. The harmonized standards that give providers a presumption of conformity are still in the pipeline: CEN-CENELEC reported in its 2026 update on European standards supporting the AI Act that prEN 18286 on quality management systems had completed public enquiry and moved to formal vote, prEN 18228 on risk management was in public enquiry, and prEN 18283 on managing bias was still under development.
Four other changes matter for planning. National AI regulatory sandboxes, originally due to be operational by August 2, 2026, are now due by August 2, 2027. Article 4 on AI literacy was rewritten as an obligation of means — providers and deployers must support the development of AI literacy among staff, but are not required to guarantee any individual’s competence level. Two new prohibitions were added to Article 5 covering AI systems that generate non-consensual intimate imagery or child sexual abuse material, with a transition period to December 2, 2026. And a new “small mid-cap” category (under 750 employees and turnover at or below EUR 150 million) gets simplified documentation and proportionate penalty caps.
| Obligation | Applies from | Status as of August 11, 2026 |
|---|---|---|
| Prohibited practices (Article 5) | Feb 2, 2025 | In force; enforceable since Aug 2, 2026 |
| AI literacy (Article 4) | Feb 2, 2025 | In force; reworded as an obligation of means |
| GPAI model obligations (Chapter V) | Aug 2, 2025 | In force |
| Governance, notified bodies, national penalty regimes | Aug 2, 2025 | In force; unevenly implemented |
| Transparency for certain AI systems (Article 50) | Aug 2, 2026 | Applies now |
| Commission fines for GPAI providers (Article 101) | Aug 2, 2026 | Applies now |
| Marking of content from pre-existing generative systems (Article 50(2)) | Dec 2, 2026 | Grace period running |
| New prohibitions on NCII and CSAM generators | Dec 2, 2026 | Transition period running |
| National AI regulatory sandboxes (Article 57) | Aug 2, 2027 | Deferred from Aug 2, 2026 |
| Legacy GPAI models placed on market before Aug 2, 2025 | Aug 2, 2027 | Pending |
| High-risk standalone systems (Annex III, Chapter III) | Dec 2, 2027 | Deferred from Aug 2, 2026 |
| High-risk systems embedded in regulated products (Annex I) | Aug 2, 2028 | Deferred from Aug 2, 2027 |
Our EU AI Act compliance timeline tracks each of these dates as they shift.
Are the Penalties Real Yet?
Yes — for the obligations that are actually in force. Article 99 sets three tiers: up to EUR 35 million or 7% of total worldwide annual turnover for breaching the Article 5 prohibitions; up to EUR 15 million or 3% for most other infringements, including Article 50 transparency duties; and up to EUR 7.5 million or 1% for supplying incorrect, incomplete, or misleading information to authorities or notified bodies. In each case the higher of the two figures applies, except for SMEs and start-ups, where the lower figure applies.
Separately, Article 101 gives the Commission the power to fine general-purpose AI model providers up to EUR 15 million or 3% of worldwide annual turnover for infringing the regulation, failing to comply with information requests, ignoring requested measures, or refusing model access for evaluation. Those powers became operative on August 2, 2026.
Two caveats keep this in proportion. Fines under Article 99 attach only to obligations that have become applicable, so nothing in the deferred high-risk regime is fineable until December 2027 at the earliest. And Article 99 penalties are imposed by member states through their national regimes — which is where the picture gets uneven.
Are Member States Ready to Enforce?
Mostly not. Article 70(2) required every member state to designate its notifying authority and market surveillance authorities and communicate them to the Commission by August 2, 2025. A year past that deadline, the AI Act national implementation tracker records only nine member states as having clearly designated both categories, twelve with partial or announced designations, and six with no designated competent authorities at all. The one deadline that was met cleanly was the earlier one: all 27 member states designated fundamental rights authorities under Article 77 by November 2, 2024.
National implementing legislation is further behind. Cullen International’s April 2026 snapshot found only three member states — Denmark, Finland, and Italy — had adopted national AI laws, with proposals pending in nine more. Italy was first, with Law No. 132/2025 entering into force on October 10, 2025.
The practical consequence: the venue with real capacity right now is Brussels, not the capitals. The AI Office has centralized supervision of general-purpose AI models, a staffed enforcement function, and a signed code of practice to measure providers against. National market surveillance of AI systems — the machinery that would police an ordinary deployer’s Article 50 breach — is patchy and in several jurisdictions does not yet exist in designated form. That is a transitional condition, not a reprieve: the extra months on the high-risk clock exist so member states, notified bodies, and standards bodies can build the capacity that was missing in August 2026.
What Should In-Scope Companies Do Now?
AI deployment has outpaced AI governance. Eurostat reported on December 11, 2025 that 20.0% of EU enterprises with ten or more employees used AI technologies in 2025, up from 13.5% in 2024 — a 6.5 percentage point jump in a single year, led by Denmark at 42.0%. The obligations moved; the systems did not.
Four priorities for the next quarter:
- Close out Article 50 now. Inventory every user-facing system: chat interfaces, voice agents, synthetic media tooling, AI-assisted publishing. Confirm disclosure at first interaction, confirm machine-readable marking on generative outputs, and confirm deployer-side deepfake labeling. Systems already live before August 2, 2026 have until December 2, 2026 for the marking requirement — that window is four months wide, not four quarters.
- Finish the classification work anyway. Knowing which of your systems fall into Annex III is the input to every downstream decision, and the criteria did not change. Our EU AI Act compliance guide walks through the classification logic and the Chapter III obligations that now land in December 2027.
- Build the management system, not the paperwork. The deferral buys time to stand up something auditable rather than assemble a document set. ISO/IEC 42001 maps closely to the AI Act’s quality and risk management expectations, and prEN 18286 is built on the same foundations. See how the frameworks line up in our comparison of NIST AI RMF, ISO 42001, and the EU AI Act.
- Push the diligence upstream. If you deploy someone else’s models, your Article 50 marking position depends on their implementation. Get contractual commitments on watermarking, provenance metadata, and code-of-practice signatory status at the next renewal.
For teams starting from a blank page, our AI governance implementation guide sequences the inventory, classification, and control work into a program you can run against the December 2027 date.
Frequently asked questions
Did the EU AI Act’s high-risk rules take effect on August 2, 2026?
What is the Digital Omnibus on AI?
What are the penalties under the EU AI Act right now?
Do I have to label AI-generated content in the EU now?
Which authority enforces the EU AI Act?
Should companies pause their AI Act compliance work?
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex
- European Commission, AI Act regulatory framework
- European Commission, AI Omnibus enters into force (July 27, 2026)
- European Commission, AI Act Service Desk FAQ
- European Commission, Code of Practice on Transparency of AI-generated Content
- Eurostat, 20% of EU enterprises use AI technologies (December 11, 2025)
- CEN-CENELEC, European standards supporting the AI Act (2026)
- EU AI Act Article 99: Penalties
- EU AI Act Article 50 transparency rules: a practical guide
- AI Act national implementation plans tracker
- Cullen International, National implementation of the EU AI Act (April 2026)
- Wilson Sonsini, EU AI Act Enforcement Phase Begins (August 3, 2026)
- White & Case, EU AI Omnibus enters into force, amending the AI Act
Track Every EU AI Act Deadline in One Place with Compyl
Compyl maps your AI systems to AI Act obligations, ISO 42001, and the NIST AI RMF in a single control set, so a shifting deadline updates your program instead of restarting it. See continuous evidence collection and automated control monitoring against the December 2027 high-risk date.
About this article. By Compyl Research. Last updated August 11, 2026. This is general information, not legal advice — consult counsel for your specific obligations. Compyl is an AI-powered, agentic GRC platform built by CISOs.
