On 2 August 2026 the EU AI Act enters its operational phase. For months it was described as the deadline that would make high-risk system requirements mandatory, but in the meantime the picture has changed: with Regulation (EU) 2026/1744, the Digital Omnibus on AI published in the Official Journal of the European Union on 24 July 2026 and in force since 27 July 2026, the European institutions have postponed precisely those obligations.
The result: many companies no longer know what applies and what doesn't. Some have stopped altogether ("it's all been postponed anyway"), others are rushing through requirements that don't concern them yet. Both are getting it wrong.
In this article we lay out what actually applies from 2 August 2026, what has been postponed, and why waiting until 2027 is still a bad idea.
In short
On 2 August 2026 the AI Act becomes applicable in its general structure: transparency obligations (Art. 50), national supervision and the full penalty regime.
Regulation (EU) 2026/1744 (in force since 27 July 2026) postpones the obligations for high-risk systems: Annex III to 2 December 2027, Annex I (regulated products) to 2 August 2028.
Providers that placed generative AI systems on the market before 2 August 2026 have until 2 December 2026 to comply with the machine-readable marking of synthetic content (Art. 50(2)).
The prohibitions (Art. 5) and the AI literacy obligation (Art. 4) have been in force since February 2025: no postponement. From 2 December 2026 two new prohibitions are added, covering non-consensual intimate content and AI-generated child sexual abuse material.
Penalties reach up to €35 million or 7% of worldwide turnover.
#The updated timeline, in one table
Deadline | What becomes applicable | Status |
|---|---|---|
2 February 2025 | Prohibited practices (Art. 5) + AI literacy (Art. 4) | Already in force |
2 August 2025 | Obligations for general-purpose AI models (GPAI) | Already in force |
2 August 2026 | Transparency (Art. 50), national governance and supervision, penalties | Applies now |
2 December 2026 | Machine-readable marking of synthetic content (Art. 50(2)) for systems already on the market + new Art. 5 prohibitions | Introduced by Reg. (EU) 2026/1744 |
2 December 2027 | High-risk system obligations (Annex III) | Postponed by Reg. (EU) 2026/1744 |
2 August 2028 | High-risk system obligations (Annex I, regulated products) | Postponed by Reg. (EU) 2026/1744 |
The new dates are no longer a forecast: the amending regulation was published in the Official Journal of the European Union, L series, on 24 July 2026 and entered into force on 27 July 2026, the third day following publication.
#What has been postponed (and what Annex III means)
The postponement concerns the heaviest obligations in the regulation: those for high-risk systems.
Annex III covers the areas where an AI error touches people's fundamental rights: biometrics, employment and worker management (CV screening, staff evaluation), education, access to essential services such as credit scoring, law enforcement and justice. For these systems, requirements such as risk management (Art. 9), technical documentation, human oversight (Art. 14) and transparency towards users (Art. 13) will become binding from 2 December 2027.
Annex I concerns AI embedded in already regulated products (machinery, medical devices, toys) and slips to 2 August 2028.
#What applies anyway from 2 August 2026
This is the point many are underestimating. The postponement is not a suspension of the AI Act: from 2 August 2026 the regulation becomes applicable in its general structure, on three concrete fronts.
1. Transparency obligations (Art. 50)
If your company uses or offers AI systems that interact with people, from 2 August 2026:
- users must know they are talking to an AI (chatbots, virtual assistants, voicebots);
- AI-generated or AI-manipulated content, including deepfakes, must be recognisable as such;
- AI-generated text published to inform the public must be disclosed.
For most SMEs and startups embedding AI in their products, this is the immediate requirement, not the high-risk rules.
There is one clarification introduced by Regulation (EU) 2026/1744. The obligation to mark synthetic content in a machine-readable format (Art. 50(2): watermarks, metadata, fingerprints) comes with a transitional window for providers that placed generative AI systems on the market before 2 August 2026: for those systems the compliance deadline is 2 December 2026. New systems must comply immediately, and in any case the other transparency duties towards people (disclosing the chatbot, labelling deepfakes) apply from 2 August.
You won't be starting in the dark: in June 2026 the Commission published the final version of the Code of Practice on Transparency of AI-Generated Content and the Article 50 guidelines. The Code (voluntary, with a first signature window that closed on 22 July 2026) is set to become the main reference for demonstrating compliance: those who do not sign will have to demonstrate it by other means, facing greater scrutiny.
2. Full penalty regime
Penalties become fully operational:
- up to €35 million or 7% of worldwide turnover for prohibited practices;
- up to €15 million or 3% for breaching the other obligations;
- up to €7.5 million or 1% for supplying incorrect information to authorities.
For SMEs and startups the lower of the absolute amount and the percentage applies, but these are still figures capable of sinking a company.
3. National supervision
National supervisory authorities become operational with inspection and enforcement powers. The "nobody is checking" phase ends.
And don't forget what has been in force since February 2025 with no postponement: the ban on unacceptable practices (social scoring, subliminal manipulation) and the AI literacy obligation. Staff using AI systems must have an adequate level of competence, and that applies to every company, of every size.
#Not just delays: what else Regulation 2026/1744 changes
Reading the Omnibus purely as an extension is misleading. The regulation touches other areas too:
- Two absolute new prohibitions from 2 December 2026: generating or manipulating realistic images, video and audio depicting the intimate parts of identifiable people without explicit consent (so-called nudification tools), and producing child sexual abuse material with AI. The ban hits both those placing systems on the market where such use is reasonably foreseeable and those using them for that purpose.
- Simplifications for SMEs and startups: simplified technical documentation based on Commission templates, quality management systems proportionate to company size, priority access to regulatory sandboxes.
- Lighter EU database registration for systems the provider classifies as not high-risk under Art. 6(3). Note: the documentation supporting that classification must still be kept.
- Stronger AI Office powers, taking direct supervision over general-purpose models and systems from the same provider and over those integrated into very large online platforms, with inspection powers and periodic penalty payments.
- National sandboxes operational by 2 August 2027: a useful space for anyone building systems that will fall into the high-risk category from December 2027.
#"So let's wait until 2027": why that's a mistake
The postponement of high-risk obligations seems to hand you an extra year and a half. In practice, for anyone selling AI software or services to other companies, the market is moving faster than the law:
- Enterprise procurement already demands evidence. Vendor questionnaires increasingly include questions on AI governance, AI risk management and standards such as ISO/IEC 42001, the first certifiable standard for AI management systems. Companies without structured answers lose deals today, not in 2027.
- Compliance cannot be improvised. AI system inventory, risk classification, technical documentation, human oversight: for a high-risk system this is months of work. Whoever starts in mid-2027 will be late.
- AI governance reduces real risks, not just regulatory ones. AI adoption grows faster than the ability to control it: autonomous AI agents, tools adopted by teams without approval (so-called shadow AI). A governance framework serves you before it serves the regulator.
- If you already hold ISO 27001, you're halfway there. ISO/IEC 42001 shares the same management system structure: roughly half of the controls of an information security management system can be reused. Extending is far cheaper than starting from scratch, and covering both means addressing information security and AI governance with a single framework.
#Operational checklist: what to do by 2 August 2026
#How CertAI helps
CertAI guides companies along the compliance journey: inventory and classification of AI systems against AI Act criteria, regulatory gap analysis, documentation generated and tailored to your systems, and a path towards certifiable standards such as ISO/IEC 42001 and ISO/IEC 27001. (see the CertAI service for the AI Act)
2 August 2026 is not the deadline that was announced, but it is not a blanket postponement either. It is the moment the AI Act stops being theory.
Want to understand what the AI Act means for your company? CertAI guides you from AI system inventory to compliance.
Sources: Regulation (EU) 2024/1689 (AI Act); Regulation (EU) 2026/1744 "Digital Omnibus on AI", published in the Official Journal of the EU (L series) on 24 July 2026 and in force since 27 July 2026; European Commission Code of Practice on Transparency of AI-Generated Content and Article 50 guidelines (June 2026). Last updated: 30 July 2026.



