CertAI
EU AI Act from 2 August 2026: what actually kicks in (and what has been postponed)
D

Domenico Ruggiano

updated on

AI ActAI Governance

EU AI Act from 2 August 2026: what actually kicks in (and what has been postponed)

On 2 August 2026 the EU AI Act enters its operational phase. For months it was described as the deadline that would make high-risk system requirements mandatory, but in the meantime the picture has changed: with the Digital Omnibus package (approved by the European Parliament on 16 June 2026 and formally adopted by the Council on 29 June), the European institutions have postponed precisely those obligations.

The result: many companies no longer know what applies and what doesn't. Some have stopped altogether ("it's all been postponed anyway"), others are rushing through requirements that don't concern them yet. Both are getting it wrong.

In this article we lay out what actually applies from 2 August 2026, what has been postponed, and why waiting until 2027 is still a bad idea.

In short
On 2 August 2026 the AI Act becomes applicable in its general structure: transparency obligations (Art. 50), national supervision and the full penalty regime.
The Digital Omnibus postpones the obligations for high-risk systems: Annex III to 2 December 2027, Annex I (regulated products) to 2 August 2028.
The prohibitions (Art. 5) and the AI literacy obligation (Art. 4) have been in force since February 2025: no postponement.
Penalties reach up to €35 million or 7% of worldwide turnover.

#The updated timeline, in one table

Deadline

What becomes applicable

Status

2 February 2025

Prohibited practices (Art. 5) + AI literacy (Art. 4)

Already in force

2 August 2025

Obligations for general-purpose AI models (GPAI)

Already in force

2 August 2026

Transparency (Art. 50), national governance and supervision, penalties

Applies now

2 December 2027

High-risk system obligations (Annex III)

Postponed by the Digital Omnibus

2 August 2028

High-risk system obligations (Annex I, regulated products)

Postponed by the Digital Omnibus

The new dates are now final: the amending regulation has been formally adopted (European Parliament on 16 June 2026, Council on 29 June 2026), and publication in the Official Journal of the EU is expected by the end of July, in any case before 2 August, with entry into force three days later.

#What has been postponed (and what Annex III means)

The postponement concerns the heaviest obligations in the regulation: those for high-risk systems.

Annex III covers the areas where an AI error touches people's fundamental rights: biometrics, employment and worker management (CV screening, staff evaluation), education, access to essential services such as credit scoring, law enforcement and justice. For these systems, requirements such as risk management (Art. 9), technical documentation, human oversight (Art. 14) and transparency towards users (Art. 13) will become binding from 2 December 2027.

Annex I concerns AI embedded in already regulated products (machinery, medical devices, toys) and slips to 2 August 2028.

#What applies anyway from 2 August 2026

This is the point many are underestimating. The postponement is not a suspension of the AI Act: from 2 August 2026 the regulation becomes applicable in its general structure, on three concrete fronts.

1. Transparency obligations (Art. 50)

If your company uses or offers AI systems that interact with people, from 2 August 2026:

  • users must know they are talking to an AI (chatbots, virtual assistants, voicebots);
  • AI-generated or AI-manipulated content, including deepfakes, must be recognisable as such;
  • AI-generated text published to inform the public must be disclosed.

For most SMEs and startups embedding AI in their products, this is the immediate requirement, not the high-risk rules.

You won't be starting in the dark: in June 2026 the Commission published the final version of the Code of Practice on Transparency of AI-Generated Content and the Article 50 guidelines. The Code (voluntary, with a first signature window that closed on 22 July 2026) is set to become the main reference for demonstrating compliance: those who do not sign will have to demonstrate it by other means, facing greater scrutiny.

2. Full penalty regime

Penalties become fully operational:

  • up to €35 million or 7% of worldwide turnover for prohibited practices;
  • up to €15 million or 3% for breaching the other obligations;
  • up to €7.5 million or 1% for supplying incorrect information to authorities.

For SMEs and startups the lower of the absolute amount and the percentage applies, but these are still figures capable of sinking a company.

3. National supervision

National supervisory authorities become operational with inspection and enforcement powers. The "nobody is checking" phase ends.

And don't forget what has been in force since February 2025 with no postponement: the ban on unacceptable practices (social scoring, subliminal manipulation) and the AI literacy obligation. Staff using AI systems must have an adequate level of competence, and that applies to every company, of every size.

#"So let's wait until 2027": why that's a mistake

The postponement of high-risk obligations seems to hand you an extra year and a half. In practice, for anyone selling AI software or services to other companies, the market is moving faster than the law:

  1. Enterprise procurement already demands evidence. Vendor questionnaires increasingly include questions on AI governance, AI risk management and standards such as ISO/IEC 42001, the first certifiable standard for AI management systems. Companies without structured answers lose deals today, not in 2027.
  2. Compliance cannot be improvised. AI system inventory, risk classification, technical documentation, human oversight: for a high-risk system this is months of work. Whoever starts in mid-2027 will be late.
  3. AI governance reduces real risks, not just regulatory ones. AI adoption grows faster than the ability to control it: autonomous AI agents, tools adopted by teams without approval (so-called shadow AI). A governance framework serves you before it serves the regulator.
  4. If you already hold ISO 27001, you're halfway there. ISO/IEC 42001 shares the same management system structure: roughly half of the controls of an information security management system can be reused. Extending is far cheaper than starting from scratch, and covering both means addressing information security and AI governance with a single framework.

#Operational checklist: what to do by 2 August 2026

#How CertAI helps

CertAI guides companies along the compliance journey: inventory and classification of AI systems against AI Act criteria, regulatory gap analysis, documentation generated and tailored to your systems, and a path towards certifiable standards such as ISO/IEC 42001 and ISO/IEC 27001. (see the CertAI service for the AI Act)

2 August 2026 is not the deadline that was announced, but it is not a blanket postponement either. It is the moment the AI Act stops being theory.

Want to understand what the AI Act means for your company? CertAI guides you from AI system inventory to compliance.

Book a demo

Sources: Regulation (EU) 2024/1689 (AI Act); "Digital Omnibus on AI" regulation (approved by the European Parliament on 16 June 2026, adopted by the Council on 29 June 2026); European Commission Code of Practice on Transparency of AI-Generated Content and Article 50 guidelines (June 2026). Last updated: 19 July 2026.