EU AI Act · deadlines at a glance

EU AI Act: what really applies on 2 August 2026

In short: 2 August 2026 is not the deadline for high-risk AI. The high-risk obligations for standalone Annex III systems have been postponed to 2 December 2027. What becomes applicable on 2 August 2026 are the transparency obligations under Art. 50 — with a grace period until 2 December 2026 for systems already placed on the market before that date. The prohibitions, AI literacy and the GPAI obligations have been in force for a while already.

This postponement comes from the “Digital Omnibus on AI” (COM(2025) 836), which amends Regulation (EU) 2024/1689. The European Parliament adopted it on 16 June 2026, the Council on 29 June 2026. Since 27 July 2026 the Omnibus has been in force as Regulation (EU) 2026/1744. The dates below are therefore part of applicable law, not merely a political agreement. One addition: further prohibitions take effect on 2 December 2026.

We ourselves worked with 2 August 2026 as the high-risk deadline on this page for a long time. That was wrong, and we have corrected it. The honest message: more time, but not no time.

What happens on 2 August 2026?

The EU AI Act applies in phases. On 2 August 2026 the transparency obligations of Art. 50 become applicable — for example labelling AI interactions, synthetic content and deepfakes. The high-risk obligations once scheduled for that day only take effect later:

Obligations for high-risk AI systems (Art. 8–15)

These requirements apply to standalone Annex III systems from 2 December 2027 — not from 2 August 2026. The work behind them has not changed, only the timing:

Risk management · Art. 9

A continuous, documented process to identify and mitigate risks across the whole lifecycle.

Data governance · Art. 10

Training, validation and test data must be relevant, representative and as error-free as possible.

Technical documentation · Art. 11

Complete documentation per Annex IV that demonstrates conformity — before placing on the market.

Record-keeping · Art. 12

Automatic logging of events to ensure traceability of the system's operation.

Transparency · Art. 13

Deployers must be able to understand and correctly use the system — including instructions for use.

Human oversight · Art. 14

Humans must be able to effectively oversee the system and intervene (stop, override).

Accuracy & robustness · Art. 15

Appropriate accuracy, robustness and cybersecurity throughout the lifecycle.

Obligations for providers and deployers (Art. 16–27)

Beyond the requirements on the system itself, providers and deployers have organisational duties:

Fines: what does a breach cost?

up to €35M / 7%

Breach of prohibited practices (Art. 5) — the highest tier (Art. 99).

up to €15M / 3%

Breach of the high-risk obligations and other requirements.

up to €7.5M / 1%

Incorrect or incomplete information provided to authorities.

The higher of the fixed amount or the percentage of worldwide annual turnover applies.

EU AI Act, GDPR and DORA together

If your AI system processes personal data, the AI Act obligations apply on top of the GDPR (legal basis, DPIA under Art. 35 where relevant, automated decisions under Art. 22). For financial entities, DORA adds digital operational resilience. KomplAI checks all three frameworks in one run.

Frequently asked questions

Does the EU AI Act apply to small companies too?
Yes. The AI Act attaches to the AI system and its intended purpose, not to company size. SMEs that provide or deploy a high-risk system are covered too — there are only limited reliefs on documentation and fees.
What is a high-risk AI system?
In short: AI in one of the eight Annex III areas (e.g. employment, creditworthiness, critical infrastructure) or as a safety component of regulated products (Annex I). Details and the Art. 6(3) exception are covered in our Annex III guide.
Does 2 August 2026 still apply to high-risk AI?
No. Since the Digital Omnibus, standalone high-risk systems under Annex III are subject to 2 December 2027, and high-risk AI under Annex I product law to 2 August 2028. What becomes applicable on 2 August 2026 are the Art. 50 transparency obligations — which affect far more companies than high-risk does, including every chatbot and every piece of generated content.
Do I need to act already?
Yes. The prohibitions (Art. 5) and AI literacy (Art. 4) have applied since February 2025, the GPAI obligations since August 2025, and Art. 50 arrives in August 2026. And anyone who starts on high-risk implementation only in 2027 is too late: inventory, classification and documentation take lead time. Our implementation roadmap shows the steps in the right order.

This guide is a factual orientation and does not replace legal advice. Citations refer to Regulation (EU) 2024/1689.