EU AI Act, August 2026: What's Actually Live, What Got Delayed, and Who It Reaches
The AI Act's "big deadline" was August 2, 2026. That date passed three days ago. Most of

The short version
| Obligation | Status as of Aug 2, 2026 |
|---|---|
| High-risk AI systems (Annex III: hiring, credit scoring, education, etc.) | Delayed to Dec 2, 2027 |
| High-risk AI embedded in regulated products (medical devices, machinery) | Delayed to Aug 2, 2028 |
| AI content disclosure & chatbot transparency (Article 50) | Live now |
| General-purpose AI model obligations (GPAI) | Live since Aug 2, |
| Ban on AI-generated non-consensual intimate imagery / CSAM | Live from Dec 2, 2026 |
Source: Regulation (EU) 2026/1744, "Digital Omnibus on AI," in force since July 27, 2026.
1. What changed on July 27, 2026
The EU published Regulation (EU)
Reason given for the delay: the harmonized technical standards for high-risk systems (Article 40) weren't finished, and national conformity-assessment infrastructure wasn't operational yet.
Revised timeline:
| Date | What applies |
|---|---|
| Feb 2, 2025 | Prohibited AI practices (Art. 5) banned outright. AI literacy obligations (Art. 4) begin. |
| Aug 2, 2025 | GPAI model provider obligations begin (documentation, copyright policy, training-data summary). National authorities and conformity-assessment bodies required to be operational. |
| Aug 2, 2026 | Article 50 transparency obligations apply: AI-interaction disclosure, deepfake labeling - for systems placed on |
| Dec 2, 2026 | Machine-readable AI-content marking (Art. 50(2)) applies to systems already on the market before Aug 2, 2026. New prohibition on AI-generated non-consensual intimate imagery / CSAM ("nudifiers") takes effect. |
| Dec 2, 2027 | Standalone high-risk AI systems (Annex III) must comply - moved from Aug 2,
|
| Aug 2, 2028 | High-risk AI embedded in
|
Also changed: AI embedded in products already covered by the EU Machinery Regulation is now excluded from the AI Act's direct high-risk rules. It's handled instead through delegated acts under the Machinery Regulation.
2. What's
actually live on
your desk right now - Article
50
This is the part with teeth today. Not in 2027.
Applies to:
- AI systems that talk to
people directly (chatbots, voice assistants) - must disclose they're AI, unless it's obvious from context. - Deepfakes - audio/image/video/text resembling
a real person, place, or event, realistic enough to appear authentic - must be labeled as artificially generated or manipulated. - AI-generated or
manipulated text published to inform the public on a matter of public interest - must be disclosed as AI-generated. - Emotion-recognition or
biometric-categorization systems - must tell the people exposed to them that the system is running.
Doesn't apply to:
- Purely internal use, never published externally.
- Content that underwent genuine human review, with a human or organization taking editorial responsibility for it.
- Assistive editing that doesn't substantially alter the input.
- Product descriptions or
marketing copy - the "public interest" text duty doesn't stretch to product/service communication. - Law-enforcement-authorized use, with safeguards.
Penalty: up to €15 million or 3% of global annual turnover, whichever is higher. (Separate, lower tier than the €35M / 7% reserved for Article 5 prohibited practices.)
Machine-readable marking
- the technical watermark layer, Art. 50(2) -
3. The part that has nothing to do with where you're incorporated
Article 2 sets the territorial scope. Three hooks; non-EU businesses only need to trip one.
| Article | Who it catches |
|---|---|
| 2(1)(a) | Anyone placing
|
| 2(1)(b) | Deployers established or located in the EU. |
| 2(1)(c) | Providers and deployers in a third country, where the AI system's output is used in the EU . |
Source: Article 2, AI Act Service Desk, European Commission.
None of the three hooks mention incorporation, headquarters, or nationality. They mention the market and the output.
Applied to
What that looks like in practice:
| Scenario | In scope? |
|---|---|
| Agency builds a chatbot for a US-only client, no EU users, geo-blocked | No - output isn't
|
| Agency builds a chatbot serving EU + global users | Yes - Art. 50(1)
|
| Creator publishes an AI-generated video reaching EU viewers on the open web, not geo-blocked | Yes, if EU reach is foreseeable rather than incidental |
| Company uses AI purely internally, nothing published, no EU customers | No |
| Non-EU fintech's credit-scoring API is called by an EU bank to score EU applicants | Yes - Art. 2(1)(c), output used
|
"Foreseeable" is the operative word: publishing on the open web to a global audience counts. An EU user finding the content by accident through a VPN generally doesn't.
4. The baseline, for reference
Four risk tiers:
| Tier | Examples | Status |
|---|---|---|
| Prohibited | Social scoring, subliminal manipulation, untargeted facial-recognition scraping, real-time biometric ID by law enforcement (narrow exceptions), AI-generated intimate imagery/CSAM | Banned since Feb 2, 2025 (imagery ban from Dec 2, 2026) |
| High-risk | Hiring tools, credit scoring, education/exam scoring, critical infrastructure, migration/border systems | Annex III: Dec 2, 2027. Annex I (embedded in regulated products): Aug 2, 2028 |
| Limited / transparency risk | Chatbots, deepfakes, AI-generated public-interest content, emotion recognition | Live since Aug 2, 2026 (Art. 50) |
| Minimal risk | Spam filters, inventory prediction, most consumer-facing AI features | No specific obligations |
Penalties:
| Violation | Maximum fine |
|---|---|
| Prohibited practices (Art. 5) | €35M or 7% of global turnover |
| Article 50 transparency failures | €15M or 3% of global turnover |
Both figures are "whichever is higher."
Sources
- European Commission, AI Act Service Desk - Article 2:
Scope - European Commission, Digital Strategy - "AI Omnibus enters into force," July 27, 2026
- Regulation (EU) 2024/1689 (EU AI Act)
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)