The EU AI Act Applies Today — But Not the Way Most Companies Think

Damir Andrijanic
EU AI Act application timeline on August 2, 2026
August 2 is a real compliance milestone, but the AI Act now follows a split timeline.

Today, 2 August 2026, is one of the most important dates in the EU AI Act's implementation. It is also one of the easiest dates to describe incorrectly.

The AI Act did not first enter into force today; it entered into force on 1 August 2024. Some duties have applied since February 2025 and August 2025. Nor does every high-risk requirement suddenly apply today. The final AI Omnibus moved key high-risk dates into 2027 and 2028.

What changes today is still substantial: Article 50 transparency rules become applicable, and the AI Office together with national authorities moves into the next phase of implementation, supervision, and enforcement.

The accurate headline is not “the entire AI Act starts today.” It is: the AI Act becomes operational on a split timeline.

The Timeline as It Stands Today

DateRuleStatus
2 Feb 2025Prohibited practices and AI literacyAlready applicable
2 Aug 2025Governance and GPAI obligationsAlready applicable
2 Aug 2026Article 50 transparency and broader enforcementApplicable today
2 Dec 2027Annex III high-risk systemsExtended
2 Aug 2028High-risk AI embedded in regulated productsExtended

What Applies from Today

1. People must know when they are interacting with AI

Providers of AI systems intended to interact directly with natural persons must inform them that they are interacting with AI, unless this is obvious from the circumstances and context. A hidden sentence in a privacy policy is not the same as a timely product disclosure.

For chatbots, agents, assistants, and automated support, the practical control belongs in the interface: before or at the beginning of the interaction, in language the user can understand, and in a form that survives mobile layouts, embedded widgets, and accessibility tools.

2. Synthetic content needs technical marking

Providers of systems that generate synthetic audio, image, video, or text must ensure outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated, subject to the Act's scope and exceptions.

A visible “made with AI” label may help people, but it is not automatically a substitute for machine-readable provenance. Teams need to evaluate metadata, content credentials, watermarking, detection, interoperability, and what happens when content is exported or transformed.

3. Some deployers have their own disclosure duties

Deployers must inform affected people when using emotion recognition or biometric categorisation in covered situations. Deepfakes must be disclosed, and certain AI-generated or manipulated text published to inform the public on matters of public interest must also be labelled, subject to the Act's conditions and exceptions.

4. Enforcement becomes more concrete

From today, the AI Office and Member State authorities take on the next operational phase of implementing, supervising, and enforcing the Act. That does not mean every company will receive an inspection tomorrow. It does mean that “we plan to add it later” is becoming a weaker answer than dated evidence showing what was live, tested, reviewed, and owned.

What Did Not Suddenly Start Today

Several important obligations were already applicable. Prohibited AI practices and AI literacy have applied since 2 February 2025. Governance provisions and obligations for providers of general-purpose AI models started applying on 2 August 2025.

If an organisation uses AI but has no inventory, no assigned owners, and no role-based literacy programme, the relevant gap did not appear this morning. It already existed.

What the AI Omnibus Delayed

The high-risk framework now follows later dates. Obligations for Annex III high-risk use cases apply from 2 December 2027. High-risk AI systems embedded in regulated products under Annex I follow on 2 August 2028.

This is meaningful additional time for risk management, data governance, technical documentation, logging, human oversight, conformity assessment, quality management, and post-market monitoring. It is not a reason to postpone classification until the final quarter before the deadline.

Procurement teams, investors, insurers, and enterprise customers may request evidence earlier than the statutory application date. An extension changes the legal timetable; it does not erase commercial expectations or the cost of rebuilding an undocumented system.

Five Actions Companies Should Take Now

1. Build an AI system inventory

Record each production and internal AI use case, its intended purpose, users, model supplier, data categories, output channels, owner, and deployment date. Classify systems individually rather than assigning one risk label to the whole company.

2. Map your role per use case

A company can be a provider of its own AI product and a deployer of a third-party system at the same time. Identify who defines the intended purpose, controls the interface, places the system on the market, and distributes its outputs.

3. Test Article 50 journeys

Verify disclosures across desktop, mobile, localisation, logged-out states, embedded widgets, consent-denied states, keyboard navigation, and screen readers. Check exported content separately from the interface in which it was generated.

4. Preserve evidence

Store dated screenshots, release identifiers, test results, legal reasoning, supplier documentation, exception decisions, and named control owners. Compliance evidence should show both design and operation.

5. Use the high-risk extension as build time

If Annex III or Annex I may apply, create a roadmap now for risk management, data governance, documentation, logging, oversight, cybersecurity, quality management, and monitoring. The extension is most valuable when it prevents rushed retrofitting.

Where a Public Website Scan Helps—and Where It Stops

A public-surface scan can identify visible AI interaction disclosures, transparency pages, privacy information, consent signals, and other externally observable gaps. It can help a team prioritise questions and locate evidence that customers will see.

It cannot prove full AI Act compliance. It cannot see internal intended purpose, training data, risk-management files, human oversight in practice, private workflows, or systems behind login. Those require a deeper internal assessment.

The Practical Conclusion

August 2 is neither a fake deadline nor the day every AI Act requirement arrives at once. It is the point where transparency and enforcement become more operational while the high-risk framework continues on a longer path.

Do not ask only “was the AI Act delayed?” Ask which obligation applies to which system, in which role, on which date—and what evidence proves your answer.

Check your public AI compliance signals

Scan publicly observable AI, GDPR, and ePrivacy signals, then use the findings as a starting point for a deeper internal assessment.

Primary sources

This article provides general technical and regulatory information, not legal advice. Applicability depends on the system, intended purpose, role, deployment context, and final legal text.