LINK-V
LINK-V · Article

EU AI Act, August 2026: What's Actually Live, What Got Delayed, and Who It Reaches

August 5, 2026

The AI Act's "big deadline" was August 2, 2026. That date passed three days ago. Most of what was supposed to happen on it didn't - a late amendment moved it. Here's what changed, what didn't, and why your location has nothing to do with any of it.


EU AI Act, August 2026: What's Actually Live, What Got Delayed, and Who It Reaches

The short version

ObligationStatus as of Aug 2, 2026
High-risk AI systems (Annex III: hiring, credit scoring, education, etc.)Delayed to Dec 2, 2027
High-risk AI embedded in regulated products (medical devices, machinery)Delayed to Aug 2, 2028
AI content disclosure & chatbot transparency (Article 50)Live now
General-purpose AI model obligations (GPAI)Live since Aug 2, 2025 - unaffected by the delay
Ban on AI-generated non-consensual intimate imagery / CSAMLive from Dec 2, 2026

Source: Regulation (EU) 2026/1744, "Digital Omnibus on AI," in force since July 27, 2026.

1. What changed on July 27, 2026

The EU published Regulation (EU) 2026/1744 in its Official Journal on July 24, 2026. It entered into force three days later - five days before the AI Act's original high-risk deadline. It amends the AI Act (Regulation (EU) 2024/1689); it doesn't replace it.

Reason given for the delay: the harmonized technical standards for high-risk systems (Article 40) weren't finished, and national conformity-assessment infrastructure wasn't operational yet.

Revised timeline:

DateWhat applies
Feb 2, 2025Prohibited AI practices (Art. 5) banned outright. AI literacy obligations (Art. 4) begin.
Aug 2, 2025GPAI model provider obligations begin (documentation, copyright policy, training-data summary). National authorities and conformity-assessment bodies required to be operational.
Aug 2, 2026Article 50 transparency obligations apply: AI-interaction disclosure, deepfake labeling - for systems placed on the market after this date.
Dec 2, 2026Machine-readable AI-content marking (Art. 50(2)) applies to systems already on the market before Aug 2, 2026. New prohibition on AI-generated non-consensual intimate imagery / CSAM ("nudifiers") takes effect.
Dec 2, 2027Standalone high-risk AI systems (Annex III) must comply - moved from Aug 2, 2026.
Aug 2, 2028High-risk AI embedded in regulated products (Annex I) must comply - moved from Aug 2, 2027.

Also changed: AI embedded in products already covered by the EU Machinery Regulation is now excluded from the AI Act's direct high-risk rules. It's handled instead through delegated acts under the Machinery Regulation.

2. What's actually live on your desk right now - Article 50

This is the part with teeth today. Not in 2027.

Applies to:

  • AI systems that talk to people directly (chatbots, voice assistants) - must disclose they're AI, unless it's obvious from context.
  • Deepfakes - audio/image/video/text resembling a real person, place, or event, realistic enough to appear authentic - must be labeled as artificially generated or manipulated.
  • AI-generated or manipulated text published to inform the public on a matter of public interest - must be disclosed as AI-generated.
  • Emotion-recognition or biometric-categorization systems - must tell the people exposed to them that the system is running.

Doesn't apply to:

  • Purely internal use, never published externally.
  • Content that underwent genuine human review, with a human or organization taking editorial responsibility for it.
  • Assistive editing that doesn't substantially alter the input.
  • Product descriptions or marketing copy - the "public interest" text duty doesn't stretch to product/service communication.
  • Law-enforcement-authorized use, with safeguards.

Penalty: up to €15 million or 3% of global annual turnover, whichever is higher. (Separate, lower tier than the €35M / 7% reserved for Article 5 prohibited practices.)

Machine-readable marking - the technical watermark layer, Art. 50(2) - is a separate deadline: Dec 2, 2026, and only for systems already on the market before Aug 2, 2026.

3. The part that has nothing to do with where you're incorporated

Article 2 sets the territorial scope. Three hooks; non-EU businesses only need to trip one.

ArticleWho it catches
2(1)(a)Anyone placing an AI system or GPAI model on the EU market - regardless of where they're established.
2(1)(b)Deployers established or located in the EU.
2(1)(c)Providers and deployers in a third country, where the AI system's output is used in the EU .

Source: Article 2, AI Act Service Desk, European Commission.

None of the three hooks mention incorporation, headquarters, or nationality. They mention the market and the output.

Applied to Article 50: a chatbot's disclosure duty, or a deepfake's labeling duty, triggers on where the interaction happens or where the content is consumed - not on where the company issuing it sits.

What that looks like in practice:

ScenarioIn scope?
Agency builds a chatbot for a US-only client, no EU users, geo-blockedNo - output isn't used in the EU
Agency builds a chatbot serving EU + global usersYes - Art. 50(1) applies
Creator publishes an AI-generated video reaching EU viewers on the open web, not geo-blockedYes, if EU reach is foreseeable rather than incidental
Company uses AI purely internally, nothing published, no EU customersNo
Non-EU fintech's credit-scoring API is called by an EU bank to score EU applicantsYes - Art. 2(1)(c), output used in EU

"Foreseeable" is the operative word: publishing on the open web to a global audience counts. An EU user finding the content by accident through a VPN generally doesn't.

4. The baseline, for reference

Four risk tiers:

TierExamplesStatus
ProhibitedSocial scoring, subliminal manipulation, untargeted facial-recognition scraping, real-time biometric ID by law enforcement (narrow exceptions), AI-generated intimate imagery/CSAMBanned since Feb 2, 2025 (imagery ban from Dec 2, 2026)
High-riskHiring tools, credit scoring, education/exam scoring, critical infrastructure, migration/border systemsAnnex III: Dec 2, 2027. Annex I (embedded in regulated products): Aug 2, 2028
Limited / transparency riskChatbots, deepfakes, AI-generated public-interest content, emotion recognitionLive since Aug 2, 2026 (Art. 50)
Minimal riskSpam filters, inventory prediction, most consumer-facing AI featuresNo specific obligations

Penalties:

ViolationMaximum fine
Prohibited practices (Art. 5)€35M or 7% of global turnover
Article 50 transparency failures€15M or 3% of global turnover

Both figures are "whichever is higher."

Sources

  • European Commission, AI Act Service Desk - Article 2: Scope
  • European Commission, Digital Strategy - "AI Omnibus enters into force," July 27, 2026
  • Regulation (EU) 2024/1689 (EU AI Act)
  • Regulation (EU) 2026/1744 (Digital Omnibus on AI)
LINK-V LINK-V