
The EU AI Act after August 2, 2026: what actually applies now
August 2, 2026 was the EU AI Act’s most confusing deadline yet: some obligations switched on, the heaviest ones moved back a year or more. Here is the operational read.
What became enforceable this month
Two things are now live and subject to enforcement. First, the Article 50 transparency duties: chatbots must disclose that they are machines, AI-generated content must be marked, and deepfakes must be labeled. Second, the European Commission’s enforcement powers over general-purpose AI models activated the same day (Data Protection Report). If your product talks to users, generates content, or sits on top of a frontier model, these apply to you today — whether you are in Boston or Berlin, if you serve EU users.
What got delayed — and until when
In June, the European Parliament approved amendments moving the Act’s high-risk obligations back: standalone high-risk systems (Annex III — hiring, credit, education, essential services) shifted from August 2026 to December 2, 2027, and product-embedded high-risk systems to August 2, 2028 (DLA Piper). US companies watching the August 2026 deadline got breathing room they did not expect.
Why regulated firms should not relax
The delay is a gift only if you use it. The high-risk requirements — risk management systems, data governance, logging, human oversight, technical documentation — are not paperwork you assemble in the last quarter. They are properties of how a system is built. An agent that was designed with an evaluation harness, an audit trail, and human sign-off from day one is already most of the way to Annex III compliance. An agent bolted together without them will need to be rebuilt, not documented.
This is the same discipline we hold as a design constraint in healthcare and legal work: compliance is a Day-1 architecture decision, not a Day-90 retrofit. The firms that treat the 2027 deadline the way the 12% treat production — eval first, log everything, human in the loop — will spend 2027 selling while their competitors spend it remediating.
What to do this quarter
Three moves. One: if any customer-facing AI touches EU users, close the Article 50 gaps now — disclosure lines and content marking are cheap to add and embarrassing to be caught without. Two: inventory which of your AI workflows would classify as high-risk under Annex III, because the list is broader than most teams assume. Three: make audit trails and evaluation sets a requirement on every new AI build starting today, so the 2027 deadline arrives as a formality instead of a fire drill.
Put an Applied AI Scientist on your problem
Thirty minutes, no deck. Bring the workflow that hurts and leave with an honest read on whether AI can carry it — and what it would take to prove it in your environment.
Book a call with an Applied AI Scientist Explore Intelligent AI World