The EU AI Act After 2 August 2026: What Applies Now and What Comes Next

The EU AI Act reached another major application date on 2 August 2026. For many organisations, AI governance has moved from preparation into normal operations. The work now is to make transparency, accountability and control survive contact with real systems.

The AI Act entered into force on 1 August 2024 and has applied in stages. Prohibited practices and AI-literacy duties began to apply in February 2025. Governance rules and obligations for providers of general-purpose AI models followed in August 2025.

On 2 August 2026, most of the remaining framework became applicable, including important transparency obligations. The date does not mean every high-risk rule now applies. The 2026 AI Omnibus extended the timetable for certain high-risk systems, creating later application dates in December 2027 and August 2028.

This phased structure can make the regulation look like a calendar exercise. It is better understood as a sequence of operating changes. Organisations need to know which AI they use, which role they play, how the systems affect people and where the evidence lives.

What already applies

Several parts of the AI Act were in effect before August 2026.

Prohibited AI practices

Certain uses are prohibited because their risk to safety or fundamental rights is considered unacceptable. Organisations should have a process that prevents prohibited use cases from being purchased, built or enabled through a configuration change.

A policy that says “we do not use prohibited AI” is not enough if nobody reviews new use cases or understands which features a vendor can activate.

AI literacy

Providers and deployers must take measures to ensure a sufficient level of AI literacy among relevant staff and others operating AI systems on their behalf.

This is broader than general awareness training. A procurement team needs to recognise hidden AI functionality and contractual risk. A developer needs to understand data, evaluation and security issues. A business user needs to know the limitations of the system and when a human decision is required. An incident responder needs to know which logs and dependencies can explain unexpected behaviour.

The required literacy depends on the role and risk. One generic course will rarely be sufficient for everyone.

General-purpose AI obligations

Rules for providers of general-purpose AI models have applied since 2 August 2025. These include transparency and copyright-related obligations, with additional safety and security duties for models with systemic risk.

The European Commission and AI Board have endorsed a voluntary General-Purpose AI Code of Practice. The code provides a route for providers to demonstrate compliance and is organised around transparency, copyright, and safety and security.

The code is voluntary; the underlying legal obligations are not. Providers that do not sign still need to show how they comply.

What changed on 2 August 2026

The August 2026 milestone brings wider parts of the AI Act into application. One of the most visible areas is transparency.

Providers of relevant interactive AI systems must design them so people are informed when they are interacting with AI, unless this is obvious in the circumstances. Providers of systems generating synthetic content face requirements related to machine-readable marking. Deployers have duties in defined situations involving deepfakes, emotion recognition, biometric categorisation and AI-generated content on matters of public interest.

These rules are intended to reduce deception and make AI involvement visible. They also create practical design questions:

  • Where should the disclosure appear?
  • Does it remain visible across different channels and languages?
  • Can the system preserve required marking when content is exported?
  • Who is responsible when a supplier provides the model but the organisation controls the user experience?
  • What happens when human editors substantially change generated content?
  • Can the organisation prove which version of the disclosure was active at a given time?

Transparency is therefore not only wording. It is a product and records-management function.

High-risk deadlines moved, but the risk did not

The final AI Omnibus entered into force in July 2026 and extended the application timetable for high-risk AI rules.

Rules for systems used in certain sensitive high-risk areas, including biometrics, critical infrastructure, education, employment, migration, asylum and border control, are scheduled to apply from 2 December 2027. Rules for high-risk AI embedded in regulated products such as medical devices, toys or lifts are scheduled from 2 August 2028.

The extension gives organisations more time and allows standards, guidance and support tools to mature. It should not be interpreted as permission to postpone governance.

Systems are already being selected, integrated and trained. Data is already being collected. Contracts are being signed for several years. If documentation, logging, human oversight and quality controls are absent from the architecture, adding them shortly before the legal deadline will be expensive and sometimes impossible.

The deadline moved. The lifecycle did not.

The provider–deployer distinction remains critical

Many organisations describe themselves as users of AI and assume the provider obligations sit entirely with a technology vendor. That can be wrong.

An organisation may become a provider when it develops a system, places it on the market under its own name or makes a substantial modification that changes the system’s purpose or compliance position. The details depend on the arrangement and should be reviewed carefully.

Even as a deployer, the organisation retains responsibilities. It controls the operational context: who uses the system, which data it can access, how outputs influence decisions and whether human oversight is meaningful.

Contracts should clarify roles, but a contract cannot change the facts of how the system is built and used.

General-purpose AI needs a supply-chain view

Most organisations will not train a frontier model. They will use general-purpose models through applications, platforms or APIs. The result is an AI supply chain.

One service may involve a model provider, cloud host, application vendor, integration partner, vector database and internal retrieval sources. A model update can change behaviour without the deployer changing its own code.

Useful supplier questions include:

  • Which model and version provide the service?
  • Can the provider change models without notice?
  • How are prompts, outputs and uploaded files used or retained?
  • Which locations and subprocessors are involved?
  • What evaluation and security information is available?
  • How are serious incidents and vulnerabilities communicated?
  • Can the organisation export logs and configuration?
  • What is the fallback if the model or provider is unavailable?

The AI Act adds new reasons to ask these questions, but they also support GDPR, NIS2, DORA and ordinary operational risk management.

Build an inventory that can answer operational questions

Many AI inventories are little more than lists of approved tools. That is not enough for governance.

For each use case, the inventory should record:

  • business purpose and owner;
  • provider, deployer and other relevant roles;
  • model, version and hosting arrangement;
  • data categories and retrieval sources;
  • users and affected people;
  • decisions or actions influenced by the system;
  • AI Act classification and other applicable laws;
  • integrations and tool permissions;
  • human oversight and escalation;
  • evaluation, monitoring and incident routes;
  • review date and change history.

The inventory must include embedded and unofficial AI. Features arrive inside productivity suites, security tools, customer platforms and developer services. Employees may also use consumer tools outside approved channels.

Discovery should combine procurement data, network and identity telemetry, interviews, expense information and technical scanning. Asking departments to complete a spreadsheet once a year will miss too much.

Treat transparency as a testable control

Organisations should be able to test whether a person receives the correct information in the real user journey.

For example, a chatbot may provide disclosure on its website but not when the same service is used through a messaging channel. A generated image may contain a machine-readable marker until it is processed by a publishing platform. A deepfake disclosure may be visible in the original video but disappear in a shortened clip.

Testing should include the outputs and channels that users actually encounter. The result should be documented, and changes to the model, interface or content pipeline should trigger review.

AI literacy should follow authority

Training should become more specific as a person’s authority increases.

Someone using AI to brainstorm internal text needs a different level of knowledge from someone approving a recruitment system, connecting an agent to production infrastructure or signing a contract for a general-purpose model.

A practical literacy programme can have layers:

  1. Baseline training for all staff on approved use, data handling, verification and escalation.
  2. Role-specific training for procurement, developers, security, privacy, HR and business owners.
  3. Decision training for executives and governance bodies approving high-impact use cases.
  4. Exercises for incident teams investigating AI-related failures or misuse.

Completion records matter, but competence matters more. Scenario-based exercises show whether people can apply the rules.

Regulation and investment are moving together

The EU is combining regulation with investment. The InvestAI initiative, launched in 2025, aims to mobilise €200 billion for AI investment, including €20 billion for AI gigafactories. The broader AI Continent Action Plan supports computing infrastructure, data, skills and adoption.

This matters because the European approach is not simply to restrict AI. It seeks to create conditions for trustworthy development and competition.

For organisations, compliance and innovation should not be opposing programmes. Good inventories, controlled data, reliable evaluation and clear ownership make it easier to scale useful AI because the organisation knows what it is accepting.

The next phase is operational

The most important AI Act milestone is not the one printed on the calendar. It is the moment an organisation can answer basic questions without assembling a temporary task force.

Which AI systems are in use? Which obligations apply? Who owns the risk? What changed in the last release? How are people informed? Can a human intervene? What happens when the provider is unavailable? Can an incident be reconstructed?

After 2 August 2026, these should become normal operating questions.

The later high-risk deadlines provide time to improve the answers. They do not reduce the need to start.

Sources and further reading

This article provides general technical and operational context, not legal advice.

Leave a Reply

Your email address will not be published. Required fields are marked *