AI Policy
EU AI Act August 2026: What Actually Applies Now (and What Got Delayed to 2027)
Newaiera Desk · 2026-08-03 · 6 min read
August 2 was supposed to be the big high-risk compliance deadline. The Digital Omnibus pushed most of it to December 2027 — but the transparency rules were
If you spent the last year preparing for August 2, 2026, you got a reprieve on most of it — and almost certainly missed the part that did not move.
August 2 was the binding enforcement date for the EU AI Act's high-risk obligations. Then, in June, the European Parliament and Council approved the Digital Omnibus, which pushes most of those deadlines out substantially. The coverage that followed mostly reported "EU delays AI Act" and stopped there.
That is misleading in a way that could get companies fined. Two significant things took effect on August 2 regardless.
What moved, and where it moved to
| Obligation | Original date | New date |
|---|---|---|
| Annex III standalone high-risk systems | 2 Aug 2026 | **2 Dec 2027** |
| Annex I high-risk AI in regulated products | 2 Aug 2026 | **2 Aug 2028** |
| Article 50 transparency duties | 2 Aug 2026 | **Not delayed** |
| Commission GPAI enforcement powers | 2 Aug 2026 | **Not delayed** |
Annex III covers the categories most people picture when they hear "high-risk AI": recruitment and hiring tools, credit scoring, law enforcement applications, education, and border control. Those now have until December 2, 2027.
Annex I covers AI embedded in products already regulated under EU product law — medical devices, machinery, vehicles. Those get until August 2, 2028.
One procedural note that matters: the deferral takes effect once the amendments are published in the Official Journal and enter into force. It is an agreed change, not an informal grace period, but the mechanics are worth confirming against your own legal advice rather than a news article.
What did not move — and this is the expensive part
Article 50 transparency duties were not delayed. These are the rules with the widest practical reach, because they apply to ordinary consumer-facing AI rather than to a narrow list of sensitive use cases:
- Chatbot disclosure — people must be told they are talking to an AI system, not a person.
- AI content marking — synthetic content has to be machine-readable as such.
- Deepfake labelling — manipulated audio, image and video content must be disclosed.
If you run a support chatbot serving EU users, generate marketing imagery with a diffusion model, or ship any synthetic media, Article 50 applies to you now. It applied on August 2. There was no extension.
Alongside it, the Commission's enforcement powers over general-purpose AI models activated on the same date.
The penalties
Article 50 violations sit in a penalty tier of up to €15 million, or 3% of total worldwide annual turnover for the preceding financial year — whichever is higher.
| Revenue €100M | 15 €M |
|---|---|
| Revenue €500M | 15 €M |
| Revenue €1B | 30 €M |
| Revenue €5B | 150 €M |
The "whichever is higher" construction is the thing to notice. Below roughly €500 million in turnover, the €15 million cap binds. Above it, the percentage takes over and the number scales without limit. For a large platform, a transparency failure is not a rounding error.
Why the delay happened
The honest answer is that readiness was poor and everyone knew it.
The high-risk regime requires conformity assessments, risk management systems, technical documentation, data governance evidence, human oversight design and post-market monitoring. Much of it depends on harmonised standards that were not finished in time. Asking companies to certify against standards that do not yet exist is not a workable position, and the Omnibus is largely an acknowledgement of that.
Whether an eighteen-month extension produces genuinely better compliance or simply relocates the same scramble to late 2027 is an open question. The pattern in EU tech regulation has not been encouraging on this point.
What to actually do this month
If you serve EU users, the useful work is narrow and immediate:
- Audit every AI touchpoint a user can reach. Chatbots, generated images, voice, recommendation surfaces that present as human judgement.
- Check your disclosures exist and are visible. Not buried in terms of service — visible at the point of interaction.
- Confirm your synthetic content carries machine-readable marking. This is a technical requirement, not a policy one; a caption is not sufficient.
- Use the extension for the high-risk work. December 2027 is far enough away to do conformity assessment properly and close enough that starting in 2027 will be too late.
The delay bought time on the hard, expensive obligations. It bought no time at all on the easy, cheap ones — which is exactly where enforcement is likely to start.
The caveat
This is a summary of a fast-moving regulatory position, not legal advice. The Omnibus amendments, their Official Journal publication and the guidance from national authorities are all still settling. If you have material EU exposure, this is a conversation to have with counsel rather than a checklist to work from.
What is clear enough to act on: August 2 was not a non-event, and the obligations that survived it are the ones that touch the most products.