Skip to content

EU AI Act August 2: What’s Live, What’s Deferred

6 min read

EU AI Act August 2: What's Live, What's Deferred
Photo by Markus Spiske on Pexels

The EU AI Act’s most-watched enforcement date passed on August 2, 2026 — and the results were messier than the headlines suggested. For high-risk AI systems, the deadline quietly moved by 16 months. For chatbots, deepfakes, and AI-generated content, it did not. Whether your compliance work just got easier or just got overdue depends entirely on what you are building and where you deploy it.

The High-Risk Obligations Moved — To December 2027

August 2 was supposed to be the day the AI Act’s most demanding provisions took effect: technical documentation, conformity assessments, human oversight requirements, and registration obligations for high-risk AI systems. Hiring tools, credit scoring models, biometric identification software, student assessment AI — all were meant to be fully compliant by this date.

They are not required to be — not yet.

The European Commission published the Digital AI Omnibus in November 2025, proposing to delay the high-risk deadline. The European Parliament adopted it on June 16, 2026; the Council approved it on June 29; it was signed into law on July 8. The amendment deferred standalone Annex III high-risk systems to December 2, 2027 — a 16-month extension from the original August 2, 2026 date. AI embedded in regulated products under Annex I (medical devices, aircraft, industrial machinery) gets even more time: August 2, 2028.

For enterprises that had been scrambling to audit systems and commission conformity assessments, this is real relief. Conformity assessments alone can take six months when third-party notified bodies are required, and there are not enough notified bodies to meet demand. The extra time is functionally necessary. For enterprises that had not yet started, it is not an invitation to delay indefinitely — the December 2027 deadline is firm.

What Article 50 Requires Right Now

Not everything was deferred. Article 50 — the AI Act’s transparency layer — is live as of August 2, with no grace period. These are not high-risk rules. They are baseline disclosure requirements that apply to any AI system interacting with EU residents, regardless of risk category. If your product is in scope, you are out of compliance today if you have not acted.

Chatbots and conversational agents must disclose at first contact that the user is speaking to an AI. The European Commission’s guidance is unambiguous: the disclosure must happen before or at the very beginning of each interaction. A reference buried in a terms-of-service page does not satisfy the obligation. This applies to customer service bots, sales chat tools, AI onboarding assistants — anything that holds a text or voice conversation with a user in the EU.

Emotion recognition and biometric categorisation systems must inform users that emotional inference or biometric categorisation is occurring. If your system reads facial expressions to assess engagement, or classifies users by detected attributes, that activity must be disclosed at the time it happens.

Synthetic media — AI-generated images, audio, and video that realistically depict real people — must be marked as artificial. Critically, Article 50 requires machine-readable watermarking, not just a visible label. The interoperability standard for these marks is still being finalized by the European AI Office, but the marking obligation itself is active now. Waiting for the standard to finalize is not a compliance defence.

AI-generated text on matters of public interest must disclose its machine-generated origin unless a human editor exercised sufficient control to assume authorial responsibility. AI-written commentary on political candidates, public health policy, or safety matters, published without disclosure, is already non-compliant.

The Revised Compliance Calendar

The Omnibus added two new prohibited practices, effective December 2, 2026 — less than four months away:

  • AI systems designed to generate non-consensual intimate imagery (NCII) — prohibited outright
  • AI systems designed to generate child sexual abuse material (CSAM) — prohibited outright

These are absolute prohibitions. No risk-tier exceptions, no transition periods, no grace clauses.

The full enforcement calendar now looks like this:

ObligationOriginal DeadlineCurrent Deadline
Prohibited AI practices (original list)February 2, 2025Done ✓
GPAI codes of practiceAugust 2, 2025Done ✓
Prohibited practices — NCII and CSAMN/ADecember 2, 2026
Article 50 transparency (chatbots, deepfakes, synthetic media)August 2, 2026August 2, 2026 ✓ Live
High-risk AI — Annex III standalone systemsAugust 2, 2026December 2, 2027
High-risk AI — Annex I embedded in regulated productsAugust 2, 2027August 2, 2028
National AI regulatory sandboxes establishedAugust 2, 2026August 2, 2027

What Enterprises Should Do With the Extra 16 Months

The deferral is real, but treating it as a pause is a mistake. Sixteen months sounds generous; it isn’t, when the path to compliance involves mapping every AI system in your stack against Annex III categories, appointing a qualified compliance lead with authority to pause deployments, engaging notified bodies for conformity assessments, and building the logging and audit infrastructure the high-risk obligations require. If you started this work in 2025, you are ahead. If you stopped when the Omnibus was announced, you have lost time you will need.

Audit your Article 50 exposure first. This is not deferred. Any customer-facing chatbot, AI content tool, or synthetic media system serving EU residents needs to comply today. National regulators in Germany, France, Italy, and the Netherlands have published enforcement priorities that explicitly include transparency violations. The European AI Office has already opened investigations into GPAI providers. The risk of enforcement action in 2026 is not theoretical.

Continue — or begin — your Annex III mapping. If your product touches hiring, credit scoring, healthcare, education, law enforcement, or public services and serves EU users, you need a formal Annex III determination. That determination requires both legal review and technical documentation. It cannot be done in a sprint. Treat the extra 16 months as time to do this correctly, not as time to start later.

Prepare for the December 2026 prohibition deadline. If any system in your stack could generate NCII or similar deepfake content, you have fewer than four months to implement hard technical limits and document them. This applies to fine-tunable models, image generation APIs, and any product with unconstrained content generation.

Check your GPAI status. General-purpose AI model providers trained on more than 1025 FLOPs of compute are already past the GPAI code of practice deadline. The European AI Office has been conducting model evaluations and requesting documentation from major providers since early 2026. If you provide foundation models — even internally — verify whether you are in scope. We covered the earlier EU AI Act compliance picture in March; the Omnibus has shifted the timeline but not the underlying obligations. See our March analysis: EU AI Act: What August 2026 Means for Your Business.

The EU AI Act’s August 2 date was not the end of a compliance sprint. For Article 50, it was the starting gun. For high-risk systems, it marked the beginning of a 16-month window that will close faster than it looks. The enterprises that come out of this period ahead are the ones that treat the deferral as preparation time — not as a reason to stop.

Further Reading

Don’t miss on Ai tips!

We don’t spam! We are not selling your data. Read our privacy policy for more info.

Don’t miss on Ai tips!

We don’t spam! We are not selling your data. Read our privacy policy for more info.

Enjoyed this? Get one AI insight per day.

Join engineers and decision-makers who start their morning with vortx.ch. No fluff, no hype — just what matters in AI.