The EU Pressed the Button, But Not the One You Read About: What Actually Changed in the AI Act on August 2

Aug 17, 2026

Wawel Castle silhouette across the Vistula River in Kraków at golden hour

August 2, 2026 had long been circled on calendars as a defining date for the European Union's AI Act. The day came and went. But much of what you've read about it is likely out of date.

As compliance analysts have pointed out, guides written in 2024 and 2025 still describe August 2, 2026 as the day the full high-risk regime takes effect. That date has moved. In this article, we clarify — based on primary sources — what is actually in force, what has been deferred, and what companies serving the EU market should do today.

What Was Deferred?

The big change first: the Digital Omnibus regulation, in force since July 27, 2026, pushed the high-risk obligations for Annex III systems — such as recruitment screening, credit scoring, and employee monitoring tools — to December 2, 2027 and August 2028.

But note: deferred, not removed. As law firm Goodwin's analysis underlines, this is preparation time, not permission to shelve compliance work. The lifecycle obligations requiring risk management systems, technical documentation, and human oversight remain on the calendar.

What Is in Force?

1. Article 50 transparency obligations. In Goodwin's words: on August 2, 2026, the AI Act's transparency and information obligations under Article 50 became generally applicable and enforceable by national competent authorities across the EU. If your product talks to users, generates images, audio, video or text, or scores emotions or biometrics, these duties apply — regardless of whether the system is classified as high-risk.

Concretely, four situations:

  • Chatbots and AI agents: People must be informed they are interacting with an AI system, unless it is obvious. Per the European Commission's guidelines, the notice should be clear, accessible, and given at the start of the first interaction.

  • Generative content: Providers of systems producing AI-generated or manipulated content must mark outputs in a machine-readable and detectable format. Systems placed on the market before August 2, 2026 have until December 2, 2026 to comply with this marking requirement.

  • Deepfake labelling and emotion recognition / biometric categorization disclosure: Deployers must inform individuals exposed to these systems of their operation.

2. The enforcement machinery is live. Obligations for general-purpose AI model providers have applied since August 2025, but the Commission could not act on violations until now. Since August 2, the AI Office can request information, demand model access, and impose penalties.

3. The fines are concrete. Under Article 99(4), non-compliance may give rise to administrative fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.

How Did the Market Respond?

The industry isn't standing still. As the transparency obligations entered into force, around 190 organizations had signed the voluntary Code of Practice on Transparency of AI-Generated Content, endorsed by both the European Commission and the AI Board as an adequate means of demonstrating compliance. Adherence is voluntary, but signatories gain greater legal certainty and a common compliance framework.

What Does This Mean Beyond the EU?

The AI Act's reach doesn't stop at EU borders. If you place your system on the EU market, or its output reaches users in the EU, these rules concern you — even if your headquarters is in Istanbul, Dubai, or New York. Three groups should pay particular attention:

  • Companies exporting SaaS or digital products to the EU: chatbot disclosure and content marking are now product requirements.

  • Agencies and content producers serving EU clients: the marking obligation chain for AI-generated content can extend to you.

  • Firms integrating systems for EU enterprise clients: your client's compliance obligation is already showing up as "AI Act compliance" clauses in supplier contracts.

Five Things to Do Today

The sequence we recommend across our projects:

1. Build an AI inventory. Which of your systems talk to users, generate content, or process emotions or biometrics? Map them against Article 50's four situations.

2. Add chatbot and agent disclosures. At the start of the first interaction, clear and accessible. This is the lowest-cost, fastest-to-close gap on the list.

3. Implement content marking technically. Machine-readable marking is a technical requirement, not a text footnote. Put December 2, 2026 on the calendar for existing systems.

4. Evaluate the Code of Practice. Signing isn't mandatory, but it is currently the clearest framework for demonstrating compliance.

5. Don't treat December 2027 as a waiting room. High-risk obligations require risk management systems and human oversight architecture. These aren't features you add in the final quarter; they are structures you design from the start. If every agent project you build today includes audit trails and human approval points, you won't run a compliance project in 2027. You'll already be compliant.

Conclusion

We've written before about the direction of regulation: one jurisdiction starts, then the standard spreads. China published its framework; the EU has now switched on its enforcement power.

Timelines can be deferred. Direction cannot.

Questions: epochtechnology.co

Sources: European Commission — Guidelines on Article 50 Transparency Obligations (July 20, 2026) and Code of Practice on Transparency of AI-Generated Content; Digital Omnibus / Regulation (EU) 2026/1744; Goodwin Law analysis (August 2026); Cloud Security Alliance research note; Sourcing Speak and Jetico compliance analyses.

Website Carbon Emissions as measured by Digital Carbon Online