Skip to content
All insights

What the EU AI Act requires in August 2026 and what moved to 2027

5 min readAI GovernanceEU AI Act
Timeline of the EU AI Act with the 2 August 2026 milestone highlighted: entry into force 2024, prohibited practices 2025, GPAI 2025, transparency and market surveillance 2026, Annex III high-risk in December 2027 and Annex I in August 2028

Updated 1 August 2026. Regulation (EU) 2026/1744 (the Digital Omnibus on AI), in force since 27 July 2026, postponed the bulk of the high-risk regime. This article was published before that amendment and has been rewritten against the current timeline.

For two years, 2 August 2026 was the date in the EU AI Act: the day the bulk of the text applied and the high-risk obligations became enforceable. Not any more. Three weeks before that date, Parliament and Council adopted the Digital Omnibus, which moves the heaviest block to December 2027 and August 2028.

What does not change is the substance of the obligations. What changes is when they can be enforced.

What is still enforceable on 2 August 2026

Transparency (Article 50). This is the real August milestone. When a user talks to a chatbot they must know it is an AI, and generated or manipulated content (deepfakes included) must be marked in a machine-readable format. It affects marketing, customer support and any agent that interacts with people, whether or not the system is high-risk. There is a transitional rule for generative systems already on the market before 2 August 2026: the deadline to comply with Article 50(2) runs to 2 December 2026.

Market surveillance (Chapter IX). Post-market monitoring, serious-incident reporting and the powers of the national surveillance authorities. This is the supervisory machinery, and it comes online in August.

Fines for general-purpose AI providers (Article 101). GPAI obligations have applied since August 2025; the penalty regime specific to them lands now.

What moved

BlockPrevious dateCurrent date
High-risk under Annex III (Art. 6(2))2 Aug 20262 Dec 2027
High-risk under Annex I (Art. 6(1))2 Aug 20272 Aug 2028

What was postponed is Chapter III, Sections 1, 2 and 3, where nearly all the work lives: classification (Art. 6-7), risk management (Art. 9), data governance (Art. 10), technical documentation (Art. 11), event logging (Art. 12), human oversight (Art. 14), accuracy and robustness (Art. 15), and the obligations of providers and deployers (Art. 16-27).

The Regulation itself explains why: the delayed availability of harmonised standards and common specifications, and the delayed establishment of national competent authorities. Without published standards, a provider has nothing to demonstrate conformity against.

Read this precisely. It is not a suspension or a softening. The text of the obligations is untouched: same articles, same requirements, same annexes. What moved is the date from which an authority can require them.

And the penalties

The penalty regime (Art. 99-100) has been in force since August 2025, but it can only punish non-compliance with an obligation that already applies. In practice: today there is exposure for prohibited practices and for GPAI obligations; exposure for the high-risk requirements starts in December 2027.

The three penalty tiers of the EU AI Act: 7% or EUR 35M, 3% or EUR 15M, 1% or EUR 7.5M

The tiers have not changed. The figure that applies is the higher of the percentage of global annual turnover and the fixed amount, so for a large company the percentage rules and for an SME the fixed amount does. The top tier (EUR 35M or 7%) is for the Article 5 prohibited practices, enforceable since February 2025. Breaches of the high-risk obligations sit in the EUR 15M or 3% tier.

One Omnibus change that does tighten things: from 2 December 2026, two new prohibited practices are added to Article 5, covering the generation of non-consensual intimate material and child sexual abuse material. That block sits in the top penalty tier.

Does it apply to you?

The question is not "do we have AI?", but "which category does each system fall into?". The Act distinguishes four levels (prohibited, high-risk, limited risk with transparency obligations, and minimal), and a single product can have parts in different levels. Most companies find they have less high-risk than they feared and more transparency obligations than they thought, and those are exactly the ones falling due now.

To avoid classifying by eye, we built an EU AI Act calculator: answer a few questions and it returns the category, the applicable articles and the timeline that applies to you, already on the Omnibus dates. Free, no email. A CV-screening tool, operated by the deployer, comes back like this:

System: CV screening · role: deployer
Tier:        HIGH-RISK
Legal basis: Art. 6(2) · Annex III, point 4 · Art. 113 §3 point (c)(i)
Deadline:    2 December 2027
Obligations: risk management (Art. 9) · data governance (Art. 10) ·
             documentation and logging (Art. 11-12) · human oversight (Art. 14) ·
             accuracy, robustness and cybersecurity (Art. 15) ·
             conformity assessment and CE marking (Art. 43, 48)

Where to start now

Sixteen months feels like plenty until you count backwards. A high-risk conformity assessment is not something you improvise, and the slowest part (data inventory, traceability, evidence of human oversight) is precisely what you cannot buy in the final quarter. The delay is room to do it properly, not permission to skip it.

  1. Close Article 50 this month. It is the only thing falling due now. AI notices at the points of contact and labelling of synthetic content.
  2. Inventory the AI systems in production or about to launch, including the ones you bought from a third party. The deployer's responsibility is yours even if the model is someone else's.
  3. Classify each one by risk level. This is where most teams need help, because Annex III has nuance, and the Omnibus has also narrowed what counts as a "safety component" on the Annex I branch.
  4. Gap-analyze the distance between what your category requires and what you have documented today, and prioritize by exposure: high-risk and in production first.

There is one point that often goes unnoticed: cybersecurity is no longer optional in compliance. The Act requires high-risk systems to be secure by design, and ENISA reads that as robustness against adversarial attacks. For an AI system that includes things like prompt injection or RAG poisoning, which slip past traditional security controls. Compliance and security overlap more than they seem, and it pays to plan them together.

At KAIX LABS we classify, document and audit AI systems so they arrive in order at each milestone on the calendar, and we do it alongside the security side, not in silos. If you want a quick read on where you stand, start with the calculator; if you would rather talk it through, book a diagnosis.

This article is informational and does not constitute legal advice. Dates and obligations are based on Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.