If you searched for EU AI Act news this summer, it’s likely that much of what you found is already out of date. Articles written in 2024 and 2025 still describe August 2, 2026 as the day the full high-risk regime becomes enforceable. That deadline has moved.
The Digital Omnibus on AI, in force since July 27, 2026, pushed the high-risk obligations to December 2027 and August 2028.

What actually arrived on August 2 is smaller and more specific, which is good news for lean compliance teams already stretched across GDPR, internal AI use and daily operations.
In this blog, you can find out:
- What took effect on August 2, 2026
- Who enforces the rules and issues fines
- The correct EU AI Act timeline through 2028
- Whether the high-risk delay means the work can wait
- Where small compliance teams get stuck
- What a lean compliance team should do now
What Actually Took Effect on August 2, 2026?
Two things became enforceable on August 2, 2026: Article 50 transparency obligations and the Commission’s enforcement powers over general-purpose AI models.
Article 50 covers four situations:
- Chatbots and AI agents. People must be informed they are interacting with an AI system, unless it is obvious. This duty sits with the provider, but deployers should confirm that their customer-facing tools handle it.
- AI-generated content. The outputs of generative AI systems must carry machine-readable marks that identify them as artificially generated. Systems already on the market before August 2, 2026 get a grace period until December 2, 2026.
- Emotion recognition and biometric categorization. Deployers need to inform people exposed to these systems.
- Deepfakes and public-interest text. Deployers must clearly label deepfakes and AI-generated text published to inform the public on matters of public interest, unless the text went through human review or editorial control.
The Commission’s Guidelines on the Transparency of AI-Generated Content and the accompanying Code of Practice explain how these duties work in practice, including the exemptions for standard editing and business-to-business use.
The second change gets less attention but matters more for the market. Obligations for general-purpose AI model providers have applied since August 2025, but the Commission could not act on violations until now. Since August 2, the AI Office can request information, demand model access and impose penalties.
What didn’t take effect? The high-risk requirements for Annex III systems, such as recruitment screening, credit scoring and employee monitoring tools. Those now apply from December 2, 2027.
EU AI Act Enforcement News: Who Can Fine You Now?
The short answer: national market surveillance authorities enforce Article 50 transparency rules and the EU AI Office enforces general-purpose AI model obligations. Both have held these powers since August 2, 2026.
Fines for transparency and GPAI violations reach up to 15 million euros or 3% of total worldwide annual turnover, whichever is higher. Proportionality can be taken into account for SMEs, as confirmed in the European Commission’s FAQ on Article 50.
One caveat for anyone tracking enforcement developments: authorities in several member states are still being set up and no headline enforcement action exists yet under these provisions. The realistic near-term risk for most organizations is not a surprise fine. Likely, it will be an information request that cannot be answered due to nobody mapping which AI systems are in use.
What Is the EU AI Act Timeline: 2025, 2026, 2027?
Six dates cover the full rollout. Two of them changed this spring: high-risk duties moved to December 2, 2027 and August 2, 2028.
| Date | What Applies |
| February 2, 2025 | Prohibited AI practices banned. AI literacy duties for providers and deployers begin (Article 4). |
| August 2, 2025 | Obligations for general-purpose AI model providers. AI Office operational. |
| August 2, 2026 | Article 50 transparency duties. Commission enforcement powers over GPAI models. Penalty framework active. |
| December 2, 2026 | Marking grace period ends for systems placed on the market before August 2026. New Article 5 ban on non-consensual intimate imagery generators fully applies. |
| December 2, 2027 | High-risk obligations for stand-alone Annex III systems (recruitment, credit scoring, education, law enforcement). |
| August 2, 2028 | High-risk obligations for AI embedded in regulated products (Annex I). |
The December 2027 and August 2028 dates come from the Digital Omnibus, which replaced the original 2026 and 2027 deadlines with fixed later dates. The change is law: Regulation (EU) 2026/1744 was published in the Official Journal on July 24, 2026 and entered into force three days later.
Does the High-Risk Delay Mean the Work Can Wait?
No. The postponed dates cover the formal high-risk compliance package: conformity assessments, technical documentation, logging and registration. Everything else keeps its original schedule:
- GDPR applies in full to every prompt, upload and output that contains personal data. Storage limitation and data minimization did not get a grace period.
- AI literacy duties under Article 4 have applied since February 2025. Staff using AI tools at work need guidance on what those tools may and may not touch.
- Prohibited AI practices have been banned since February 2025, with a new prohibition on non-consensual intimate imagery generators arriving in December 2026.
- Accountability for your own data never moved anywhere. Using an AI system does not transfer responsibility to the AI provider. Your organization still decides whether information may be processed, which tools may access it and how unnecessary copies are removed.
The risk that drives most real incidents has no compliance date at all. As we covered in our post on shadow AI agents, an agent running under an employee’s account inherits that employee’s permissions. A forgotten export in a downloads folder used to sit at the bottom of the data iceberg, invisible in practice. An AI agent that can search, summarize and correlate files makes it findable again.
Where Do Small Compliance Teams Get Stuck?
The most common failure is treating the AI Act as a single-discipline problem. A policy written by the legal team or a tool bought by IT each covers part of the picture, but the obligations spread across both and neither team can close them on its own
In practice, a working setup needs four layers:
- Policy: Which AI tools are approved, for what purposes and with what data categories
- Administrative controls: Vendor contracts with no-training clauses, defined roles (are you a provider or deployer?), an owner for AI-related requests
- User guidance: Practical rules employees can follow on what may go into a prompt, tied to the Article 4 literacy duty
- Technical safeguards: Controls that hold even when policy and training fail, such as restricting which applications and processes can read sensitive folders
Teams also get stuck on role confusion. The obligations follow what you do with AI, not the fact that you use it:
| How AI Is Used | Your Role Under the AI Act | What Applies Today |
| Employees draft emails and code with Copilot or ChatGPT | Deployer (everyday use) | AI literacy, prohibited-use rules, GDPR and confidentiality |
| A vendor tool ranks job candidates or scores credit | Deployer of a high-risk system | Full duties arrive December 2, 2027. Vendor selection, oversight roles and data mapping are the preparation window |
| A chatbot serves customers or AI-generated content is published | Provider or deployer under Article 50 | Disclosure and labeling duties, live since August 2, 2026 |
The same company can sit in all three rows at once, which is exactly why a single policy document rarely covers it.
What Should a Lean Compliance Team Do Now?
Here’s a realistic list for the next quarter, in order:
- Inventory your AI use. List every AI tool in use (sanctioned or not) and note your role for each. This inventory is the input for every other step.
- Check customer-facing AI against Article 50. If a chatbot, voice agent or AI-generated content reaches the public, confirm disclosure and labeling are in place. These duties are already live.
- Refresh user guidance. Short, concrete rules on what data may enter which tool. This step doubles as Article 4 literacy evidence.
- Find your sensitive and obsolete data. Everything starts from discovery. You cannot govern what AI tools can reach if you do not know where personal and confidential data sits, especially old exports and copies nobody remembers.
- Erase what no longer has a purpose. Data that should not exist cannot be rediscovered by an AI agent. GDPR storage limitation already requires this and deleting is not the same as erasing.
- Constrain access for what remains. Decide not only which users but which applications and AI processes may open sensitive folders.
Steps 4 through 6 are where technical safeguards carry the weight. Discovery tools such as BCWipe Search locate sensitive data across endpoints, and application-level access control with BestCrypt Data Shelter can enable Word to open protected folders while an unknown AI client is denied. The AI Act does not prescribe any specific product, but deployers remain responsible for the data within reach of their AI tools. These two controls close the part of the problem that policy and training just cannot do.
The AI Act may determine whether AI use is prohibited, high-risk or subject to transparency rules. It does not remove your responsibility for the personal, confidential and obsolete data within reach of your AI tools.
To map your AI data flows before the next deadline arrives, contact our Data Protection Specialist.
Frequently Asked Questions (FAQs)
Yes. The EU AI Act entered into force on August 1, 2024 and applies in phases. As of August 2, 2026, prohibited practices, AI literacy duties, general-purpose AI model obligations and Article 50 transparency duties all apply. High-risk system obligations follow in December 2027 and August 2028.
The Digital Omnibus on AI, published in the Official Journal as Regulation (EU) 2026/1744 and in force since July 27, 2026, moved high-risk obligations for Annex III systems to December 2, 2027 and for AI embedded in regulated products to August 2, 2028. It also added a ban on AI systems generating non-consensual intimate imagery, softened the AI literacy duty and gave existing systems until December 2, 2026 to meet the content-marking requirement.
Mostly no. Article 50 targets AI that interacts with people or produces content for them: chatbots, deepfakes, emotion recognition and published AI-generated text. Internal drafting, coding and summarizing tools generally fall outside it, though GDPR, confidentiality and AI literacy duties still apply to internal use.
No. The GDPR applies independently of the AI Act and was not changed by the high-risk delay. Personal data entering AI prompts, outputs and caches must still have a lawful basis, be limited to what is necessary and be erased when retention ends. The EDPB’s Opinion 28/2024 confirms that personal data used to develop and deploy AI models remains fully subject to GDPR.