What actually applies on August 2, 2026
Most write-ups of this date are out of date. The Digital Omnibus on AI deferred the Annex III high-risk regime by sixteen months. What attaches on August 2, 2026 is Article 50 transparency — narrower than the original plan, and closer than most teams think.
Updated July 24, 2026 · Informational guidance, not legal advice
The correction most sources have not made
The high-risk regime moved to December 2, 2027
Regulation (EU) 2024/1689 originally made the Annex III high-risk obligations applicable on August 2, 2026. The Digital Omnibus on AI — approved by the European Parliament on June 16, 2026 and by the Council on June 29, 2026 — deferred them to December 2, 2027, and deferred Annex I embedded-product high-risk to August 2, 2028. Article 50 transparency was not deferred.
This matters because a large amount of published guidance, including several widely-cited reference sites, still describes August 2, 2026 as the date the high-risk regime lands. If you are planning against that, you are planning against a timeline that no longer exists — in one direction on conformity assessment, and in the other on transparency, which is genuinely nine days away at the time of writing.
The timeline as it now stands
- August 1, 2024 — the Regulation entered into force. No obligations applied yet.
- February 2, 2025 — the Article 5 prohibited practices and the Article 4 AI literacy duty started to apply. Both are already in force.
- August 2, 2025 — general-purpose AI model obligations, the EU governance structure, national competent authorities, and the penalty framework.
- August 2, 2026 — Article 50 transparency obligations and the measures supporting innovation. Enforcement begins for general-purpose AI, the prohibitions, transparency, and AI literacy.
- December 2, 2026 — the Article 50(2) grace period ends for systems already on the market, and new Article 5 prohibitions on AI generating child sexual abuse material and non-consensual intimate imagery start to apply.
- August 2, 2027 — Member States must have at least one AI regulatory sandbox operational.
- December 2, 2027 — the Annex III high-risk regime: Articles 9–15, deployer obligations under Article 26, fundamental rights impact assessments under Article 27, conformity assessment, registration, post-market monitoring, and serious-incident reporting.
- August 2, 2028 — high-risk AI that is a safety component of a product regulated under Annex I sectoral law.
What Article 50 actually requires
Article 50 splits by role, and the split is the part teams most often get wrong. Two paragraphs bind providers and two bind deployers, and a company can be both for different systems.
- Article 50(1) — providers. A system that interacts directly with people must be designed so those people are informed they are dealing with an AI system, unless that is obvious to a reasonably well-informed and observant person. The Commission's guidelines read that exception restrictively, because relying on it removes the disclosure entirely.
- Article 50(2) — providers. Systems generating synthetic audio, image, video, or text must mark outputs in a machine-readable format detectable as artificially generated or manipulated. Narrow carve-outs exist for assistive editing functions, short sequences, source code, and machine-to-machine output not exposed to a person.
- Article 50(3) — deployers. People exposed to an emotion recognition or biometric categorisation system must be informed of its operation. The obligation is to disclose that it operates, not to explain its purpose.
- Article 50(4) — deployers. Deepfakes must be disclosed on first exposure, in a clear and distinguishable way that does not require technical tools to notice. Published AI-generated text on matters of public interest must also be disclosed — unless it went through genuine human review or editorial control, which spell-checking does not satisfy.
The grace period is narrow
Systems placed on the market before August 2, 2026 get until December 2, 2026 — but only for the Article 50(2) marking and detection obligation. Everything else in Article 50 applies from August 2, 2026 regardless of when the system shipped.
Breach of Article 50 carries administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher, with proportionality considered for SMEs. Enforcement sits with national market surveillance authorities.
What the deferral does and does not buy you
Sixteen extra months on Annex III is real relief, and it is worth being honest about that rather than manufacturing urgency. But three things do not move.
- The prohibitions have applied since February 2025. If a system performs an Article 5 practice, the deferral is irrelevant — it should not be on the EU market now.
- The Article 4 literacy duty has applied since February 2025 and covers providers and deployers alike.
- Article 50 applies on August 2, 2026. For most product teams shipping customer-facing AI — assistants, support copilots, generated content — this is the obligation that actually attaches, and it is the nearest one.
The deferral also does not change what a buyer asks for. Enterprise procurement and security reviews already ask how AI systems are inventoried, classified, and overseen, and those questions do not wait for an application date. A December 2027 obligation with no record built against it is the same problem in eighteen months that it is today, minus the runway.
What a defensible record looks like now
The work that pays off under either timeline is the same, because every downstream obligation depends on it:
- An AI system register: every system in scope, its intended purpose, its role — provider or deployer — and its risk classification with the Article 6 and Annex III reasoning written down.
- An Article 50 determination per system: which limb applies, who bears it, and what the disclosure actually says. This is the one with a date in nine days.
- An obligation map that distinguishes what applies now from what applies in December 2027, so nobody mistakes deferred for absent.
- Named owners per control, with human-oversight assignments identifying a person with competence and authority rather than a mailbox.
- Evidence with review dates, and a review rhythm that keeps the record honest as systems, vendors, and uses change.
Sequence it by date, not by fear
Classify every system, then work the Article 50 determinations first because they are due. Treat the Annex III work as a program with a December 2027 deadline rather than an emergency — and start it early enough that conformity assessment is not being discovered in the final quarter.
Find out which limb applies to your system
The free Attevera classifier walks Articles 5, 6, 50, and the Annex III list for one system in a few minutes — no signup, and you keep the reasoning and the dates.
Run the free classifierFrequently asked questions
Did the EU AI Act get delayed?
Parts of it. The Digital Omnibus on AI deferred the Annex III high-risk regime from August 2, 2026 to December 2, 2027, and Annex I embedded-product high-risk to August 2, 2028. The prohibitions, the AI literacy duty, general-purpose AI obligations, and Article 50 transparency were not deferred.
So is anything due on August 2, 2026?
Yes — Article 50 transparency obligations apply, for providers and deployers alike, and enforcement begins for general-purpose AI, the prohibitions, transparency, and AI literacy. For teams shipping customer-facing AI features this is the operative date.
Does the EU AI Act apply to companies outside the EU?
Yes, when the AI system is placed on the EU market or its output is used in the Union. A US company selling AI features to EU customers, or whose system's output affects people in the EU, is in scope regardless of where it is established.
We only use vendor AI tools. Are we off the hook?
No. Using AI under your own authority makes you a deployer. Article 50(3) and 50(4) bind deployers directly from August 2, 2026, and Article 26 deployer duties attach to high-risk systems from December 2, 2027. Vendor compliance helps; it does not discharge your own obligations.
What should we do first?
Inventory and classify. You cannot determine which Article 50 limb applies, scope oversight, or plan for December 2027 until you know which systems you operate, your role for each, and each system's risk class.