Updated August 4, 2026. This article provides general information, not legal advice.
Many compliance plans were built around a simple sentence: most of the EU AI Act applies from August 2, 2026. That sentence is still technically true, but it is no longer a useful summary of what companies need to do.
Just before the deadline, the EU's Digital Omnibus on AI entered into force and changed the timetable. The main obligations for high-risk systems in sensitive areas, such as employment, education and credit, were moved to December 2027. High-risk systems embedded in regulated products received until August 2028. At the same time, the EU did not simply press pause. The transparency rules in Article 50 now apply, national authorities and the AI Office have begun enforcement, and the Commission can impose fines on providers of general-purpose AI models. 1 2
For most companies, the practical message is straightforward. August 2026 is less about completing a giant high-risk conformity exercise and more about knowing what AI the company provides or uses, putting the required disclosures into products and content workflows, supporting employees' AI literacy, and keeping evidence that these measures exist.
The new timeline in plain English
The AI Act has arrived in stages, which is one reason even careful summaries can become outdated.
| Date | Practical significance |
|---|---|
| February 2, 2025 | Most prohibited AI practices and the AI literacy obligation began to apply. |
| August 2, 2025 | Governance provisions and obligations for providers of general-purpose AI models began to apply. |
| August 2, 2026 | Article 50 transparency rules apply. The AI Office and national authorities begin active enforcement. The Commission can enforce general-purpose AI model obligations, including through fines. |
| December 2, 2026 | Providers of synthetic-content systems placed on the market before August 2, 2026 must meet the Article 50(2) machine-readable marking requirement. Certain new prohibitions introduced by the Digital Omnibus also begin to apply. |
| August 2, 2027 | Providers of general-purpose AI models placed on the market before August 2, 2025 must comply with the model obligations. |
| December 2, 2027 | The main requirements for high-risk systems listed in Annex III begin to apply. These include many systems used in biometrics, education, employment, access to essential services, law enforcement and migration. |
| August 2, 2028 | The main requirements for high-risk AI embedded in products covered by Annex I begin to apply. |
The consolidated regulation contains the legally operative schedule, while the Commission's AI Act overview provides a more readable explanation. 1 2
The important distinction is that the high-risk delay did not delay everything else. A customer-facing chatbot may be far from a high-risk system and still need an AI disclosure today. A media tool may need to mark synthetic output. A company using ordinary generative AI may still need an AI literacy program. A foundation-model developer now faces active Commission enforcement even though some downstream high-risk rules have moved.
Start with your role, not the technology label
Companies often begin with the question, "Is this high-risk AI?" That matters, but another question usually comes first: what role does the company play?
Under the Act, a provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its authority. A business can be both. The Act can also reach companies outside the EU when they place systems or models on the EU market, or when system output is used in the EU. 1
In practical terms:
-
Buying a third-party enterprise AI assistant for employees will usually make the company a deployer.
-
Building a branded customer-service assistant around another company's model API can make the company the provider of the finished AI system, even though it did not train the underlying model.
-
Commissioning a custom internal system and putting it into service under the company's name can also create provider responsibilities.
-
Training and releasing a broadly capable foundation model may make the company a provider of a general-purpose AI model, which brings a separate set of duties.
-
Substantially modifying a system, changing its intended purpose, or performing a major model modification can change the company's role and obligations.
This is why a useful AI inventory needs more than a tool name and vendor. It should record the owner, business purpose, affected users, where output is used, whether the system interacts with people, whether content is generated, the underlying model or vendor, and the company's legal role. One product can contain several layers with different responsible parties.
Open source is not a universal exemption either. The Act excludes many systems released under free and open-source licences, but that exclusion does not cover systems falling under the prohibited-practice, high-risk or Article 50 transparency rules. 1
Article 50 is the immediate product deadline
Article 50 is where many product teams will feel the August 2026 deadline most directly. Its requirements are specific enough to create engineering, design, publishing and procurement work.
People should know when they are interacting with AI
Providers of systems intended to interact directly with people must design them so users are informed that they are interacting with AI, unless this is obvious to a reasonably well-informed and observant person in the circumstances. 1
For a typical chatbot, virtual assistant or conversational agent, a clear statement near the beginning of the interaction is the sensible default. Hiding the disclosure on page 47 of the terms of service is difficult to reconcile with Article 50's requirement that information be clear, distinguishable and provided no later than the first interaction or exposure. The disclosure must also meet applicable accessibility requirements.
This is not just a legal-copy task. Product teams should check every entry point, including an embedded website widget, mobile app, messaging channel, voice interface and white-label deployment. If a customer can remove the disclosure through configuration, the provider should decide whether that configuration should exist at all.
Synthetic content may need machine-readable marking
Providers of systems that generate synthetic audio, images, video or text must ensure outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated. The solution must be effective, interoperable, robust and reliable as far as technically feasible. There are exceptions, including systems that only assist with standard editing or do not substantially alter the user's input or its meaning. 1
The words "machine-readable" matter. A visible "Made with AI" badge can help a person, but it does not necessarily satisfy the provider's technical marking obligation. Product teams need to consider metadata, provenance standards, watermarks or other supported techniques, and then test what happens when content is downloaded, resized, transcoded, copied into another system or published through a content-management platform.
Systems already on the market before August 2, 2026 have a limited grace period until December 2, 2026 for this particular marking requirement. The grace period does not postpone the rest of Article 50. The Commission's Article 50 FAQ is unusually helpful on both the exceptions and the transition rule. 4
Deepfakes and some public-interest text need disclosure
Deployers must disclose when they use AI to generate or manipulate image, audio or video content that constitutes a deepfake. Creative, fictional, satirical and similar works receive a more flexible form of disclosure, but not a blanket exemption.
Deployers must also disclose AI-generated or manipulated text published to inform the public on matters of public interest. The Commission gives examples that include politics, public administration, public health, public security, consumer safety, environmental protection, and economic, financial, scientific or cultural developments relevant to public debate. An exception applies when the text has undergone human review or editorial control and a person or legal entity holds editorial responsibility. 4
That exception should not be read as "a human glanced at it." A defensible editorial workflow identifies who reviewed the content, what responsibility they accepted, and which version was approved. It is also specific to the deployer's disclosure duty for public-interest text. It does not erase a system provider's separate duty to support machine-readable marking where Article 50(2) applies.
Emotion recognition and biometric categorisation require notice
Deployers of emotion-recognition and biometric-categorisation systems must inform the people exposed to them and continue to comply with applicable data-protection law. A disclosure does not make an otherwise prohibited use lawful. For example, some workplace and education uses of emotion recognition were already prohibited under the Act, subject to narrow exceptions.
A practical Article 50 product checklist
An August compliance review does not need to become a six-month committee exercise. It does need to reach the real product and publishing workflow.
-
List direct human interactions. Find every chatbot, voice agent, avatar, automated interviewer and AI-driven support channel.
-
Assign the company's role at each layer. Record whether the company is provider, deployer, importer, distributor, model provider or some combination.
-
Implement first-interaction disclosures. Make the language clear, accessible, localised where appropriate, and consistent across channels.
-
Map synthetic-content outputs. Identify which systems create text, image, audio or video and whether the standard-editing exception plausibly applies.
-
Verify marking through the full export path. Do not stop at the model response. Test downloads, screenshots, transformations, API consumers and publishing tools.
-
Create a deepfake and public-interest publishing rule. Give communications, marketing and media teams examples they can recognise without calling Legal for every social post.
-
Document editorial review. Where the public-interest text exception is used, keep a lightweight record of the responsible editor and approved version.
-
Review vendor contracts and technical documentation. A provider cannot implement reliable marking if the underlying vendor strips provenance or offers no usable technical support.
-
Keep evidence. Save product screenshots, test results, policy versions, training records, vendor documentation, design decisions and named owners.
The EU's Transparency Code of Practice is voluntary, but the Commission and AI Board have recognised it as a practical way for signatories to demonstrate compliance with the marking and labelling obligations. Companies using a different approach should be ready to show why their measures are adequate. 5
AI literacy has moved from policy language to enforceable practice
The AI literacy obligation has technically applied since February 2025, but August 2026 changes its practical weight because national market-surveillance authorities can now supervise and enforce it.
The revised Article 4 requires providers and deployers to take measures supporting the development of AI literacy among staff and other people operating or using AI on their behalf. The measures should account for technical knowledge, experience, education, training, the context of use, and the people affected by the system. The Omnibus also clarified that companies do not have to guarantee a particular level of literacy for every individual. 1
There is no required AI officer, mandatory governance-board structure or special Article 4 certificate. The Commission says organisations can keep internal records of training and other guidance initiatives. 6
That flexibility is useful, but it is not permission to send one generic slide deck to everyone and declare victory. A developer integrating a model API needs different guidance from a recruiter using AI-assisted screening, a marketing employee producing campaign images, or an executive approving an autonomous agent. A sensible program combines basic literacy with role-specific instruction, approved-tool guidance, practical examples, and a clear route for asking questions or reporting a problem.
The evidence does not have to be glamorous. Training attendance, guidance versions, role mappings, office hours, assessments, policy acknowledgements and records of follow-up actions can show that the company made a serious, context-aware effort.
General-purpose model developers now face real enforcement
Most companies using a commercial model through an API are not providers of that general-purpose AI model. They may, however, be providers of the downstream AI system they build around it. Model-level and system-level duties should not be mixed together.
For companies that do provide general-purpose AI models, the obligations began applying in August 2025. So, August 2025 obligations apply immediately to models placed on the market from that date, while models already on the market before August 2, 2025 have until August 2, 2027. They include technical documentation, information for downstream providers, a copyright-compliance policy and a public summary of training content. Providers of models with systemic risk have additional evaluation, risk-mitigation, serious-incident reporting and cybersecurity duties. From August 2, 2026, the Commission can enforce these obligations, request information, evaluate models, require corrective measures and impose fines. 7
This also matters to downstream product companies. Procurement should ask whether the model provider supplies the documentation and technical features needed for the finished system to comply. A vendor's compliance problem can quickly become a product team's missing-documentation problem.
The high-risk delay is useful preparation time, not a reason to stop
The main high-risk rules now begin in December 2027 for Annex III systems and August 2028 for AI embedded in regulated products. That is a meaningful extension. It gives the EU more time to complete standards and gives companies more time to build workable controls. 2
Companies working with recruitment, worker management, education, creditworthiness, insurance risk assessment, essential public or private services, critical infrastructure or biometrics should still classify their use cases now. The eventual requirements cover areas such as risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness, cybersecurity, conformity assessment and post-market monitoring.
Those capabilities are difficult to reconstruct shortly before a deadline, especially if the system has changed repeatedly and nobody retained the earlier documentation. The productive use of the extension is to establish an inventory, name owners, preserve model and vendor information, design logging, define human-oversight procedures, and identify which systems need specialist legal review. These steps are useful governance even when a system later turns out not to be high-risk.
Enforcement is no longer theoretical
From August 2026, enforcement is shared among the Commission's AI Office, national competent authorities and, for EU institutions, the European Data Protection Supervisor. The AI Office supervises general-purpose AI models and certain related systems, while national authorities handle most other AI systems. Authorities can request information, investigate and require corrective action. The EU has also launched complaint and whistleblower channels. 8
The maximum fines attract attention for good reason. Prohibited practices can lead to penalties up to EUR 35 million or 7 percent of worldwide annual turnover, whichever is higher. Breaches of several operator obligations, including Article 50 transparency duties, can reach EUR 15 million or 3 percent. For SMEs, the lower of the fixed amount or percentage applies. Actual penalties must consider the facts, including severity, duration, company size, cooperation, negligence and mitigation. 1
The sensible response is not panic. It is evidence. A company should be able to show which systems it considered, how it assigned roles and risks, what it changed, who approved the decision, and how it checks that the control still works. A policy is useful, but a working disclosure, a tested content marker and a documented training program are much easier to defend.
The August 2026 version of the AI Act is more manageable than many companies expected, but it rewards organisations that can connect legal requirements to actual products and employee behaviour. Behaviture AI Adoption Pulse helps make that connection by showing leaders where AI is being used, whether approved tools fit real work, how clearly employees understand policy, and which roles need better guidance or training. Its privacy-first reports and EU AI literacy evidence features turn scattered assumptions into prioritised actions and a repeatable internal record. It does not replace legal advice or certify compliance, but it gives IT, HR, security and governance teams the practical workforce evidence they need to build an AI program that works outside the policy document.
References
-
European Union. Consolidated text of Regulation (EU) 2024/1689, as amended through July 27, 2026.
-
European Commission. AI Act: Regulatory framework and application timeline.
-
European Union. Regulation (EU) 2026/1744, Digital Omnibus on AI.
-
European Commission. Transparency obligations under Article 50 of the AI Act: Questions and answers.
-
European Commission. Code of Practice on Transparency of AI-generated Content.
-
European Commission. AI Literacy: Questions and answers.
-
European Commission. Guidelines for providers of general-purpose AI models.
-
European Commission. The enforcement framework of the AI Act.