The EU AI Act's August 2 deadline came and went. Here's what actually happened

Published 2026-08-03

For two years, August 2, 2026 was the date on every EU AI Act compliance calendar: the day the high-risk rules would bite and the Commission's enforcement powers would switch on. The date has now come and gone, and the strangest thing about it is how much of it stopped being true in the final week before it arrived.

I wrote about what the original August 2 deadline covered last month. This is the follow-up: what actually applies as of today, what quietly moved to 2027 and 2028, and the one surprising name on a signature list the Commission published two days before the deadline.

Quick answer: As of August 2, 2026, the AI Act's transparency obligations (Article 50) and the Commission's enforcement powers over general-purpose AI providers, including fines up to 3% of global turnover, are live. The high-risk system obligations everyone associated with this date are not: the Digital Omnibus, in force since July 27, moved them to December 2, 2027.

What actually switched on on August 2?

Two things, and both matter.

Article 50 transparency obligations. If you provide or deploy generative AI in the EU, the disclosure duties now apply: people must be told when they are interacting with an AI system, synthetic audio, image, video and text must be marked as such in a machine-readable way, and deepfakes must be labelled. One carve-out: for generative systems already on the market before August 2026, the machine-readable marking requirement gets a grace period to December 2, 2026. The rest applies now.

Commission enforcement over general-purpose AI providers. This one ends a strange year. The obligations for GPAI model providers, the transparency, copyright and safety duties that apply to companies like OpenAI, Google and Anthropic, have been binding since August 2, 2025. But the Commission's power to actually enforce them, to demand documentation, evaluate models, order corrective measures, or fine up to 3% of worldwide turnover or €15 million under Article 101, only activated on August 2, 2026. For a full year, the rules bound the providers and nobody could enforce them. That gap is now closed.

What did not change at all: the Article 5 prohibitions and the Article 4 AI literacy duty have applied since February 2025, and the Article 99 fine tiers (€35 million or 7% for prohibited practices at the top) are untouched.

What moved to 2027 and 2028?

The Digital Omnibus, formally Regulation (EU) 2026/1744, was signed on July 8, published in the Official Journal on July 24, and entered into force on July 27, three days after publication. The regulation's own recitals say it took effect "as a matter of urgency" in view of "the imminent general application" of the AI Act, which is the EU acknowledging, in its own text, how tight it cut the timing. Six days before the deadline it reshapes. The law that moved August 2 arrived the same week as August 2.

The new dates:

  • Annex III standalone high-risk systems (hiring, credit scoring, education, essential services): August 2, 2026 → December 2, 2027
  • Annex I embedded high-risk systems (AI in regulated products): August 2, 2027 → August 2, 2028
  • National regulatory sandboxes: August 2, 2026 → August 2, 2027

The political detail worth knowing, because it tells you whether these dates will move again: the Commission's original Omnibus proposal tied the high-risk postponement to a standards-readiness trigger. The rules would apply once the Commission confirmed that harmonised standards were available, at the latest by the end of 2027. The adopted text dropped that conditional mechanism entirely and replaced it with fixed calendar dates. December 2, 2027 applies whether the standards are ready or not. A moving target became a hard one, which cuts both ways: more certainty for planning, and no escape hatch if standardisation runs late again.

The Omnibus also added something: two new Article 5 prohibitions, covering AI systems that generate or manipulate non-consensual intimate imagery (the "nudifier" ban) and systems generating child sexual abuse material, both applying from December 2, 2026. Neither was in the Commission's original Omnibus proposal; Parliament and Council amendments put them there, which makes this one of the few places where the Omnibus made the Act stricter rather than later.

Who signed the transparency code, and which name is the surprise?

Two days before the deadline, on July 31, the Commission published the initial signatory list for the Code of Practice on Transparency of AI-Generated Content, the voluntary instrument that helps companies meet the Article 50 marking duties that just switched on. The Commission's own numbers: about 190 organisations, and about half of them are small, recent companies, which is not the profile these codes usually attract.

Section 1, for generative AI providers, includes the names you would expect: Aleph Alpha, Anthropic, Black Forest Labs, Cohere, Google, Microsoft, Mistral, OpenAI, Synthesia. And one you might not: Meta, the company that very publicly refused to sign the 2025 GPAI Code of Practice, is on the list. Whatever changed in Menlo Park's calculus between the code it rejected and the code it signed, the practical read is that marking AI-generated content is now table stakes even for the loudest holdout, while the GPAI code fight was about something else. Section 2, for deployers, is the more interesting signal about where this is heading: Bulgari, Getty Images, Lenovo, Lufthansa. Airlines and jewellers signing an AI transparency code is what "AI compliance went mainstream" looks like.

Are the member states actually ready to enforce any of this?

Mostly no, and this is the least-reported part of the story. National market-surveillance authorities were supposed to be designated by August 2, 2025. As of the freshest public tracker, the AI Act implementation monitor, last updated June 17, 2026, nine member states have both required authorities clearly designated, twelve are partial or pending, and six have designated nothing at all. A year past their own deadline, two thirds of member states are not fully set up, and that tracker stamp is itself seven weeks old as I write, which says something about how fast the picture is moving.

The Commission side has its own capacity question. Analysts and civil-society reports have spent the summer questioning whether the AI Office has the staffing to actually use the enforcement powers it just received. And so far the honest answer on enforcement is: nothing has happened yet. No first investigation, no test case, no headline fine. The powers arrived on schedule; their first use is still ahead.

What should you do if you just use AI at work?

The provider-versus-deployer distinction from the original article still does most of the work. If you build or fine-tune models, this date mattered enormously. If you deploy AI tools, three things are worth doing this month:

  1. Fix your calendar. If your compliance plan has Annex III obligations landing this year, it is wrong as of July 27. The new date is December 2, 2027, and it is fixed rather than standards-conditional.
  2. Check your disclosure surfaces. Article 50 is live now. If your product puts AI-generated content in front of EU users without disclosure or marking, that is the obligation that actually applies to you today, not the high-risk regime.
  3. Keep evidence of what your AI tools do. Enforcement is arriving unevenly, but the direction is consistent: automated actions should leave records. That principle is why the six controls a compliance team needs start with a data-flow map and an audit trail, and it is cheaper to build the habit before a regulator, a client, or your own legal team asks.

Calmara sits in that third bucket, disclosure first as always: it is my product, and its audit surfaces exist because "prove what the AI did" is the requirement I kept finding under every regulation I read, whichever year its enforcement date lands in.

FAQ

Did the EU AI Act's high-risk rules take effect on August 2, 2026?

No. The Digital Omnibus, in force since July 27, 2026, moved the Annex III high-risk obligations to December 2, 2027 and the Annex I embedded high-risk obligations to August 2, 2028. The dates are now fixed, no longer tied to whether harmonised standards are ready.

What did take effect on August 2, 2026?

Article 50 transparency obligations (AI-interaction disclosure, machine-readable marking of synthetic content, deepfake labelling) and the Commission's enforcement powers over general-purpose AI providers, including Article 101 fines of up to 3% of worldwide turnover or €15 million.

Why could the Commission not enforce GPAI rules before August 2026?

The AI Act staggered them deliberately: GPAI provider obligations applied from August 2, 2025, but the Commission's supervision and fining powers activated a year later. During that year the rules were binding with no EU-level enforcement mechanism behind them.

Who signed the Transparency Code of Practice?

About 190 organisations as of the initial list published July 31, 2026. Providers signing Section 1 include Google, Microsoft, OpenAI, Anthropic, Mistral, Aleph Alpha, and, notably, Meta. Deployers signing Section 2 include Getty Images, Lufthansa, Lenovo, and Bulgari.

Is signing the Transparency Code mandatory?

No, it is voluntary. The underlying Article 50 obligations are mandatory; the code is a compliance pathway that signals how signatories intend to meet them.

Did the Omnibus change the AI Act's fines?

No. The Article 99 tiers stand: up to €35 million or 7% of worldwide turnover for prohibited practices, €15 million or 3% for most other violations, €7.5 million or 1% for supplying misleading information, with SMEs paying the lower of each pair.

Are national authorities enforcing the AI Act now?

Unevenly at best. As of the June 17, 2026 tracker update, only nine member states had fully designated their market-surveillance and notifying authorities, a year past the designation deadline. Commission-level GPAI enforcement is live in law but has produced no public action yet.

Did anything get stricter in the Omnibus?

Yes: two new Article 5 prohibitions, covering AI systems that generate or manipulate non-consensual intimate imagery (including nudifier apps) and systems generating child sexual abuse material. Both apply from December 2, 2026, and neither was in the Commission's original Omnibus proposal.

---

If your own compliance calendar still shows the old dates, the fix is a twenty-minute exercise: reread it against the three dates that moved and the two obligations that did not. And if the "keep evidence" point landed, the compliance-controls checklist is the practical place to start.

← All articles

Written by Dan Hagen

Try Calmara

Auditable AI memory, tasks, calendar, and notes. Self-hostable, BYOK, free tier.

Get started free