✨ New — try Standpoint free for 14 days: full access to all 15 frameworks. A card is required, but you won’t be charged. Start your free trial →
Standpointby AI Service Pro
Security Intelligence / EU AI Act
Guide

EU AI Act August 2026: What Actually Applies (and What Quietly Moved to 2027)

M
Mohammad
Founder, AI Service Pro · 8 min read

Answer-first: On August 2, 2026, two things become enforceable under the EU AI Act: the Article 50 transparency obligations (you must tell people when they're dealing with AI, and label AI-generated content) and the Commission's power to fine general-purpose AI (GPAI) model providers. Almost everything else you may have read about — the heavy "high-risk" obligations under Annex III — was postponed to December 2, 2027 by the June 2026 Digital Omnibus. So if you shipped an AI feature to EU users expecting a wall of compliance work this August, most of that wall moved. A specific, narrower set of duties did not.

That gap between what people think is due and what's actually due is the whole story of August 2026. This guide walks the line.

What is the EU AI Act, in one sentence?

The EU AI Act is the European Union's horizontal law governing artificial intelligence — the first comprehensive AI statute anywhere — and it regulates AI by risk tier (unacceptable, high-risk, limited/transparency, and minimal) rather than by industry. It applies to you if your AI system or its output reaches people in the EU, regardless of where your company sits. A US startup with EU users is in scope.

Quotable definition: The EU AI Act is not one deadline. It is a staggered rollout of obligations that switch on at different dates between 2025 and 2027 — and in June 2026 the switch-on dates changed.

What actually applies on August 2, 2026?

Three things become live and enforceable on that date:

1. Article 50 transparency obligations

Article 50 is the "limited-risk" transparency layer, and it is the part of the Act most likely to touch an ordinary software company. In plain terms it requires four disclosures:

  • Chatbots / conversational AI: if a person is interacting with an AI system, they must be told — unless it's obvious to a reasonable person.
  • Synthetic content marking: AI systems that generate audio, image, video, or text must mark their output as artificially generated in a machine-readable format.
  • Deepfakes: content that is an AI-generated or manipulated likeness of real people, objects, or events must be disclosed as such.
  • AI-generated text on matters of public interest: must be disclosed when published to inform the public, subject to editorial-oversight exceptions.

2. GPAI enforcement powers switch on

Providers of general-purpose AI models (think foundation-model makers) have technically been subject to obligations since August 2, 2025 — but starting August 2, 2026 the Commission can actually fine violations. The obligation existed; the teeth arrive now. Most SMEs are deployers, not GPAI providers, so this hits the model vendors more than their customers — but it's why your model provider is suddenly asking you to sign updated terms.

3. A narrow watermarking grace period (read this if you generate content)

The Digital Omnibus added a grandfathering rule: generative AI systems already on the market before August 2, 2026 get until December 2, 2026 to meet the machine-readable marking requirement of Article 50(2). Systems launched on or after August 2, 2026 get no grace period — they must mark from day one. The relief covers the marking mechanism only, not the deployer's duty to disclose. Don't over-read it.

What moved to 2027 (and why everyone's confused)

Here's the part the headlines got wrong. The Digital Omnibus — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July — postponed the high-risk (Annex III) obligations to December 2, 2027, and Annex I embedded-AI obligations to August 2028. High-risk is the expensive tier: conformity assessments, risk-management systems, technical documentation, human oversight, logging. If your product is high-risk, you got roughly 16 extra months — but only for those obligations, not for Article 50.

The Omnibus also extended the SME simplified regime to a newly defined small mid-cap category: companies that are not SMEs but employ fewer than 750 people with turnover no more than €150M or a balance sheet total no more than €129M. They get the simplified technical-documentation templates, more proportionate quality-management expectations, priority sandbox access, and tailored penalty caps — meaning far more companies now qualify for lighter-touch documentation.

Does the EU AI Act apply to US companies?

Yes, if your AI system or its output is used in the EU. The Act is extraterritorial by design, mirroring the GDPR (General Data Protection Regulation) model — the trigger is EU users or EU-facing output, not an EU office. A 12-person US SaaS company with a chatbot that European customers use is in scope for Article 50 on August 2, 2026.

How big are the penalties?

The Act's fine ceilings are tiered by violation type:

  • Prohibited-practice violations: up to €35 million or 7% of global annual turnover, whichever is higher.
  • Most other obligation breaches (including Article 50 and GPAI): up to €15 million or 3% of global turnover.
  • Supplying incorrect or misleading information to authorities: up to €7.5 million or 1% of turnover.

For SMEs and startups, the Act specifies that fines are capped at the lower of the percentage or fixed amount — a proportionality carve-out. Still, the reputational and deal-flow cost of a transparency failure usually bites before any regulator does.

the questions founders actually ask

Do I need to do anything if I just use ChatGPT or a third-party model?

Possibly — if you expose an AI chat interface to users or publish AI-generated content, the Article 50 deployer disclosure duties can apply to you even though you didn't build the model.

Is a chatbot on my marketing site "high-risk"?

Almost certainly not. A support or marketing chatbot is a limited-risk system — transparency, not conformity assessment. High-risk is a defined list (Annex III): biometric ID, critical infrastructure, employment screening, credit scoring, and similar.

What does "machine-readable marking" mean in practice?

An embedded, detectable signal (e.g., metadata or watermark) in AI-generated media that a machine can read to identify it as synthetic — not just a visible "AI-generated" caption, though you often want both.

We're pre-revenue. Are we exempt?

No blanket exemption, but the SME simplified regime (now up to 750 employees / €150M) reduces documentation burden, and fine caps favor smaller firms.

Does the delay mean I can ignore the Act until 2027?

No. Article 50 and GPAI fines are live August 2, 2026. The 2027 date only covers high-risk obligations.

How do I know which tier I'm in?

Map each AI feature to a use case, then check it against the prohibited list, the Annex III high-risk list, and the Article 50 transparency triggers. Most SMB features land in limited-risk.

What's the fastest way to find my gaps?

Run a structured self-assessment against the Article 50 triggers before you spend a euro on legal review — know where you stand first.

A 20-minute action list for August 2, 2026

  1. Inventory every place AI touches an EU user — chat interfaces, generated images/text/video, any synthetic-media feature.
  2. Add the disclosure wherever a person interacts with AI ("You're chatting with an AI assistant").
  3. Turn on machine-readable marking for any generative output; if your system predates Aug 2, you have until Dec 2, 2026 — new features, mark from launch.
  4. Label deepfakes / synthetic likenesses explicitly.
  5. Check your model vendor's terms — GPAI enforcement is why they're updating contracts.
  6. Confirm you're not high-risk (Annex III) — if you are, you have until Dec 2, 2027 for those obligations, but start scoping now.
  7. Document what you did — the SME regime lightens this, but "we decided we're limited-risk because X" is worth a paragraph.

FAQ

Q: What is due under the EU AI Act on August 2, 2026?

A: Article 50 transparency obligations (AI disclosure, synthetic-content marking, deepfake labeling) and the Commission's power to fine GPAI model providers. High-risk obligations are not due until December 2, 2027.

Q: Did the EU AI Act get delayed?

A: Partly. The June 2026 Digital Omnibus postponed high-risk (Annex III) obligations to December 2, 2027, but Article 50 transparency and GPAI enforcement still apply from August 2, 2026.

Q: Does the EU AI Act apply to US or non-EU companies?

A: Yes, if your AI system or its output is used in the EU. The Act is extraterritorial, like the GDPR.

Q: Is my chatbot high-risk under the EU AI Act?

A: Almost certainly not. Chatbots are limited-risk and fall under Article 50 transparency rules, not the high-risk conformity regime.

Q: What are the penalties for an Article 50 violation?

A: Up to €15 million or 3% of global annual turnover, whichever is higher — with proportionality caps favoring SMEs.

See where you stand — free
2-minute check · no card · runs in your browser
Run your free check →
Newsletter
Practical AI-governance & security tips, monthly

No fluff, no fear-selling. Unsubscribe anytime.

// Keep reading