Skip to content
Hendez
← All guides

Guides

EU AI Act: what actually takes effect on 2 August 2026

Last updated

Short answer

What takes effect on 2 August 2026 is Article 50 of the EU AI Act — the transparency duties: machine-readable marking of AI-generated content, disclosure that a user is interacting with an AI system, and disclosure of deepfakes. The heavy high-risk obligations do NOT start on this date. Under the Digital Omnibus they moved to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for Annex I systems embedded in regulated products.

2 Aug 2026Transparency duties (Art. 50) enforceable
2 Dec 2027Annex III high-risk systems — postponed
2 Aug 2028Annex I regulated products — postponed
€15M / 3%Ceiling for transparency breaches

Exactly what starts tomorrow

From 2 August 2026, five separate transparency duties under Article 50 become enforceable. None of them is technically hard — but their absence is visible. A regulator can evidence a breach with a screenshot.

1. AI-interaction disclosure. A person using a chatbot or voice assistant must know they are not talking to a human. The exception is narrow: the situation must already be obvious to a reasonably well-informed, observant and circumspect person.

2. Marking of generated content. Providers of systems producing synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. A visible caption does not satisfy this; the marking must be embedded in the output itself.

3. Emotion recognition and biometric categorisation notice. Deployers must inform the individuals exposed to such systems.

4. Deepfake disclosure. Deployers generating or manipulating image, audio or video must disclose it, with an exception for creative and satirical works.

5. Public-interest text disclosure. Where AI-generated text is published on matters of public interest, this must be disclosed — unless the content underwent human review or editorial control.

One narrow transition exists: providers of systems placed on the market before 2 August 2026 have until 2 December 2026 to implement the technical marking solution. This applies only to provider-side marking, not to the other four duties.

Most guidance online is now out of date

A large share of the compliance material circulating today still says high-risk obligations begin on 2 August 2026. That is no longer correct.

The Digital Omnibus was approved by the European Parliament and the Council in June 2026 and enters into force three days after publication in the Official Journal. It moved stand-alone high-risk systems (Annex III) to 2 December 2027 and high-risk AI embedded in regulated products (Annex I) to 2 August 2028.

This is not relief — it is a price difference. Organisations that leave conformity work to the end of the runway buy the same documentation in a market with scarce assessors and scarce auditors, at several times the cost. Organisations that start now produce it at their own pace with their own people.

Why it binds a company in Türkiye, the Gulf or anywhere else

The Act's scope is not geographic; it follows the output. A provider established outside the EU falls within scope where the output of its system is used inside the European Union.

In practice: any company selling software to a European customer, serving a European parent, or opening a product to the European market is addressed by these duties — even if its own jurisdiction has no AI legislation at all.

There is a second, quieter effect. European buyers are pushing these duties into supplier contracts. So even where the Act does not apply to you directly, it reaches you through your customer's paperwork: tenders now ask suppliers for technical documentation, data-governance records and a defined human-oversight arrangement.

Penalties

Breach of the transparency duties carries a ceiling of €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. SMEs and start-ups face the lower of the two ceilings.

For comparison, prohibited practices reach €35 million or up to 7% of turnover. The GDPR ceiling was €20 million or 4%. This is among the heaviest penalty regimes Europe has enacted.

The same date also activates market-surveillance authority powers and penalty powers over general-purpose AI models. From 2 August there is both a rule and a body to enforce it.

Four things to do first

Inventory. Which AI systems are actually running in the organisation, including purchased tools? Most organisations that build this list find roughly twice what they expected — generative tools in marketing, a bot in the call centre, screening software in HR.

Classification. Which risk tier does each system fall into? Do this against the Act's own criteria, not by intuition.

Transparency gap. Does every customer-facing system disclose? Is generated content machine-readably marked?

Ownership. Who owns this file by name? A compliance programme without a named owner is not a programme.

Who must do what, and by when

DateWhat becomes enforceableWho it binds
2 August 2026Transparency duties (Art. 50)Anyone generating AI content or interacting with users via AI
2 December 2026Technical marking transition endsOnly providers of systems placed on market before 2 Aug 2026
2 December 2027Annex III high-risk obligationsHR, education, credit, insurance, law enforcement, critical infrastructure
2 August 2028Annex I high-risk product obligationsAI embedded in products subject to third-party conformity assessment

Frequently asked

Frequently asked

My company is not in the EU. Does this still apply?

Yes, where the output of your system is used inside the European Union. The Act follows the output, not the place of establishment. And even where it does not apply directly, European customers are writing these duties into supplier contracts.

Were the high-risk obligations really postponed?

Yes. The Digital Omnibus was approved in June 2026, moving stand-alone Annex III systems to 2 December 2027 and Annex I systems embedded in regulated products to 2 August 2028. Much of the guidance online still cites the old date.

What is the penalty for a transparency breach?

Up to €15 million or 3% of total worldwide annual turnover, whichever is higher. SMEs and start-ups face the lower ceiling.

Is a visible disclaimer enough?

No. For generated content the requirement is a machine-readable, detectable mark. A caption on screen does not satisfy it; the mark must be embedded in the output.

Where should we start?

With the inventory. Without a complete list of the AI systems in the organisation you cannot classify them, and without classification you cannot know which obligations fall on you.

Sources

  1. EU Artificial Intelligence Act — Article 50 (transparency obligations)
  2. EU Artificial Intelligence Act — Annex III (high-risk systems)
  3. Digital Omnibus: postponed high-risk deadlines (Gibson Dunn)
  4. What still applies on 2 August 2026 (Jones Walker)

Let us begin

Let us discuss this on your own operation. The first session is free.