The EU AI Act after August 2, 2026: What's In Force, What Got Postponed
A practical guide for engineering and product teams. Not legal advice โ but legal advice based on outdated dates is worse, so let's start with what's actually true right now.
The 60-second summary
- GPAI obligations have been live since 2 August 2025. As of 2 August 2026 the European Commission (through the AI Office) can actively enforce them โ information requests, model access, and fines up to โฌ15M or 3% of global annual turnover, whichever is higher.
- Article 50 transparency obligations went live on 2 August 2026 as originally scheduled. Chatbot disclosure ("you are talking to an AI"), machine-readable marking of AI-generated content, and deepfake labelling all apply now. Exception: pre-existing systems have until 2 December 2026 to comply with the machine-readable watermarking duty.
- The Digital Omnibus on AI (Regulation (EU) 2026/1744, signed 8 July, in force since 27 July 2026) deferred the substantive high-risk deadlines:
- Stand-alone Annex III systems (employment screening, credit scoring, biometric ID, etc.) โ 2 December 2027
- AI embedded in Annex I regulated products (medical devices, machinery, toys) โ 2 August 2028
- New Article 5 prohibition added by the Omnibus: AI systems that generate or manipulate non-consensual intimate imagery (NCII) or child sexual abuse material (CSAM) โ the so-called "nudifier" apps โ become prohibited practices on 2 December 2026. A safe harbour applies for systems with effective technical safeguards that reliably prevent such outputs.
- GPAI grace period: models placed on the EU market before 2 August 2025 have until 2 August 2027 to reach full compliance. Unchanged.
Timeline as of August 2026
| Date | What applies | Status |
|---|---|---|
| 2 Feb 2025 | Prohibited practices (Art. 5): social scoring, predictive policing, untargeted facial-recognition scraping, etc. | live |
| 2 Aug 2025 | General-purpose AI model obligations (Art. 53, 55). AI Office operational. | live |
| 27 Jul 2026 | Digital Omnibus on AI (Reg. (EU) 2026/1744) enters into force. Deferrals below become law. | live |
| 2 Aug 2026 | GPAI enforcement powers active โ Commission / AI Office can investigate, request info and model access, and fine up to โฌ15M or 3% of global turnover. | live |
| 2 Aug 2026 | Article 50 transparency: chatbot disclosure, deepfake labelling. Machine-readable watermarking applies to new systems now; pre-existing systems get until 2 Dec 2026. | live |
| 2 Dec 2026 | New Art. 5 prohibition: AI-generated non-consensual intimate imagery and CSAM ("nudifier" apps). Safe harbour for effective technical safeguards. | upcoming |
| 2 Dec 2026 | Machine-readable watermarking obligation for pre-existing systems. | upcoming |
| 2 Aug 2027 | GPAI grace period ends for models placed on the EU market before 2 Aug 2025. | unchanged |
| 2 Dec 2027 | Annex III high-risk systems obligations (employment screening, education, biometric ID, credit scoring, etc.). Deferred from 2 Aug 2026 by the Omnibus. | postponed (in force) |
| 2 Aug 2028 | Annex I product-embedded AI (medical devices, machinery, toys). Deferred from 2 Aug 2027 by the Omnibus. | postponed (in force) |
"Postponed (in force)" means the Omnibus deferral is now legally binding โ as of 27 July 2026 the new dates in the right column are the operative ones. "Upcoming" means the date is fixed but has not yet arrived.
Are you in scope?
Three questions to ask, in order:
1. Do you put a GPAI model on the EU market?
If you train, fine-tune, or deploy a general-purpose AI model that's made available in the EU โ even via API to EU users from a US-hosted endpoint โ you're a "provider" of a GPAI model. Articles 53 and 55 apply. This includes the obvious frontier labs and a long tail of fine-tuners who modify a base model "substantially" (the threshold is fuzzy and is the subject of ongoing AI Office guidance).
Key duties: technical documentation, training data summary, copyright policy, and โ for "systemic risk" models trained above the 10ยฒโต FLOPs threshold โ additional model evaluation, incident reporting, and cybersecurity duties.
2. Do you deploy a "high-risk" AI system in the EU?
Annex III lists eight broad areas: biometric identification, critical infrastructure, education and vocational training, employment and worker management, access to essential services, law enforcement, migration and border control, and administration of justice. If you're using AI to filter rรฉsumรฉs, score loan applications, or rank candidates for university admission to EU residents, you're in this bucket.
Original deadline: obligations were set to apply 2 August 2026.
Current deadline (Digital Omnibus, now law): 2 December 2027 for stand-alone Annex III systems, 2 August 2028 for AI embedded in Annex I regulated products.
The substance hasn't changed โ risk management system, data governance, technical documentation, record-keeping, transparency to users, human oversight, accuracy/robustness/cybersecurity, conformity assessment, post-market monitoring. The grace period just got longer. The Omnibus also introduces a proportionality mechanism (fewer duties for SMEs deploying widely-available high-risk systems), still being fleshed out in AI Office guidance.
3. Do you publish synthetic media or run a chatbot?
Article 50 obligations went live 2 August 2026. The Omnibus did not touch these:
- Synthetic content (text, audio, image, video) generated by AI must be machine-readably marked โ typically C2PA / SynthID-style watermarking or signed manifests. Pre-existing systems have until 2 December 2026 to comply.
- Deep fakes must be clearly labelled when published (with limited journalistic-purpose exceptions).
- Chatbots that interact with humans must disclose they are AI, unless this is obvious from context.
- Emotion recognition and biometric categorisation systems must inform the natural persons exposed.
The chatbot disclosure rule is the one most builders miss. If you run an AI customer support agent on a public site for EU users, you need a clear "you are talking to an AI" disclosure that the user can't easily miss.
4. Do you provide image or video generation?
New for August 2026: the Digital Omnibus expanded Article 5 to prohibit AI systems that generate or manipulate non-consensual intimate imagery (NCII) or child sexual abuse material โ including so-called nudifier apps. The prohibition is on the outputs, so it reaches any provider whose system produces this content as a reasonably foreseeable outcome, not just those who designed for it.
Effective date: 2 December 2026.
Safe harbour: the prohibition doesn't apply where the system has effective technical safeguards that reliably prevent such outputs. What "effective" and "reliably" mean is going to be litigated โ expect the AI Office to publish guidance before December.
Practical implication for general-purpose image/video generators: foreseeable misuse now has to be documented in your risk management materials. Reactive blocklists are not likely to satisfy "effective technical safeguards"; upstream input classification and output filtering will be the standard.
The builder's checklist (regardless of what the Omnibus does)
The Omnibus postpones application, not the substance of the rules. Doing the work now is still useful โ and the August 2026 GPAI enforcement date doesn't move.
For GPAI providers (live since Aug 2025, enforced from Aug 2026)
- Maintain up-to-date technical documentation that follows the AI Office templates.
- Publish a training data summary covering content sources, scale, and lawful basis.
- Have a written copyright policy, including how you handle Article 4(3) opt-outs from the Copyright Directive (TDM reservations).
- If you're a "systemic risk" model (above the 10ยฒโต FLOPs threshold, or designated by the AI Office): implement model evaluations against the safety-and-security chapter of the GPAI Code of Practice, document incidents, and notify the Commission of serious incidents within set timeframes.
- Consider signing the GPAI Code of Practice. It's voluntary but is becoming the de facto compliance benchmark โ and signed adherence is what regulators will look at first.
For Annex III high-risk deployers (deadline moved, but don't stop)
- Catalogue every high-risk AI system you operate. The deferred deadline is for systems "placed on the market" โ meaning systems already deployed before that date have a different (and harder) path.
- Stand up a risk management system. The ISO/IEC 42001 framework is the practical mapping most companies are using.
- Establish data governance: training, validation, and testing data must be relevant, representative, and (as far as possible) free of errors.
- Implement human oversight. Not theoretically โ actually staff the role, design the override UI, and test it.
- Document accuracy, robustness, and cybersecurity measures. The conformity assessment will ask.
For everyone subject to Article 50 (deadline is Aug 2026, unchanged)
- Audit your synthetic content pipelines โ does every AI-generated artefact carry a machine-readable mark?
- Audit your chatbot UIs for "you are talking to an AI" disclosures. "Hi, I'm Sandy ๐" with no further context does not satisfy this.
- If you use emotion recognition or biometric categorisation, add an in-flow disclosure to the natural persons being processed.
- Check your terms of service against the Article 50 text. Many will need updates.
Things that still aren't clear
- What counts as "substantial modification" of a GPAI model โ the threshold determining whether a fine-tuner becomes a provider โ is still being clarified.
- Open-source carve-outs exist but their scope is contested. Releasing weights under a permissive licence does not automatically exempt you, especially if you also host an API.
- How Annex I deferrals interact with sectoral product law (CE marking for medical devices, machinery, etc.) is the trickiest area; in many cases the sectoral conformity assessment still needs the AI risk pieces.
- What "effective technical safeguards" means for the new Article 5 nudifier / NCII / CSAM prohibition. This will define whether general-purpose image and video generators need architectural changes or can rely on content filters. AI Office guidance expected before the 2 December 2026 effective date.
- The scope of the SME proportionality mechanism introduced by the Omnibus โ how "widely-available" is measured, and what specifically drops off the deployer duty list.
- How the Commission's new enforcement powers get exercised in practice. The powers activated 2 August; the first public information-request or model-access order will set the tone for how aggressive the AI Office is willing to be.
Useful primary sources
- Regulation (EU) 2024/1689 (the AI Act) โ full consolidated text on EUR-Lex
- Regulation (EU) 2026/1744 (the Digital Omnibus on AI) โ full text
- European Commission AI Act portal (the official compliance landing page)
- General-Purpose AI Code of Practice (Final Version, July 2025)
- EU AI Act explorer โ readable, cross-referenced version of the text
FunWithText tools that pair with this
None of these are a substitute for compliance work, but several of our client-side tools map directly onto specific Act obligations:
- PII Sanitizer โ pre-flight check before pasting personal data into LLM prompts. Helps with Article 5 prohibited-practices hygiene and Annex III high-risk data-governance duties.
- Prompt Injection Scanner + Indirect Prompt Injection Scanner + Multimodal Injection Check โ useful for the "robustness and cybersecurity" duties under Article 15.
- MCP Inspector โ for GPAI deployers using Model Context Protocol servers; surfaces supply-chain risks that the safety-and-security chapter of the Code of Practice asks you to consider.
- Agent Log Redactor โ for the record-keeping duties: keep logs without leaking secrets or personal data.
Caveats
This is general information for builders, not legal advice. The Digital Omnibus is a moving target; the AI Office is producing guidance documents weekly; the precise scope of "substantial modification" is being argued in real time. For specific compliance decisions, talk to a lawyer who specialises in EU tech regulation. For the political weather, the substack EU AI Act Newsletter is the best signal-to-noise source we've found.