PublishedJuly 24, 2026
Last reviewedJuly 24, 2026
Editorial ownerFounder, Fortera Labs
Review status✓ Human-approved
AI assistedYes — disclosed
Sources5 cited
Back to Insights
GenAI GovernanceEU AI ActRegulatory5 min

August 2 Still Matters: The EU AI Act Deadline That Didn't Move

Brussels bought companies seventeen extra months on the AI Act's hardest requirements. It did not touch the rule most businesses will feel first: Article 50's transparency duties still bind on August 2, with the same fines attached.

Fortera Governance PracticeReviewed by Founder, Fortera Labs · Last reviewed July 24, 2026

The European Union has given companies an extra 17 months to comply with the AI Act's most demanding requirements. The reprieve does not extend to the rules most businesses will feel first: on August 2, 2026, transparency obligations for AI-generated content become enforceable across the bloc, carrying fines of up to €15 million or 3 percent of worldwide annual turnover.

A Narrower Reprieve Than It Appears

The deferral arrives through the Digital Omnibus package, which the European Parliament endorsed on June 16 and the Council of the European Union approved on June 29. Under the amended timeline, obligations for stand-alone high-risk AI systems listed in Annex III of the Act — those used in recruitment, credit scoring, education, and access to essential services — move from August 2, 2026 to December 2, 2027. Requirements for high-risk AI embedded in regulated products such as medical devices and vehicles shift from August 2027 to August 2028, according to analysis by Gibson Dunn.

The package made further changes along the way. It added a prohibition to Article 5 covering systems whose reasonably foreseeable use is the generation of non-consensual intimate imagery or child sexual abuse material, softened the Article 4 requirement on AI literacy from guaranteeing specific skill levels to supporting their development, and pushed the deadline for national regulatory sandboxes to August 2027.

What the omnibus left untouched is Article 50. The transparency regime proceeds on its original schedule — and it reaches nearly every organization that places AI-generated output before users in the European Union.

What Takes Effect on August 2

The obligations divide along the Act's central distinction between providers, which develop or substantially modify AI systems, and deployers, which use them professionally. Providers of conversational systems must ensure users know they are interacting with a machine, unless that is already obvious to a reasonably well-informed, observant, and circumspect person. Providers of systems that generate audio, image, video, or text must mark outputs as artificially generated in machine-readable form, to the extent technically feasible. Systems already on the market before August 2 have until December 2, 2026 to meet the marking requirement; newly released systems do not.

Deployers carry the disclosure duties. Artificially generated or manipulated image, audio, or video content — deepfakes, in the statute's language — must be labeled as such, with exceptions for evidently creative, artistic, satirical, or fictional works. Individuals exposed to emotion-recognition or biometric-categorization systems must be informed. And organizations that publish AI-generated text on matters of public interest must disclose its origin, unless the material has undergone human review and a person holds editorial responsibility for it — an exception that rewards disciplined editorial process, as analysis by Jones Walker observes.

Enforcement is substantive. Violations of Article 50 carry fines of up to €15 million or 3 percent of worldwide annual turnover, whichever is higher, with reduced ceilings for qualifying small and mid-sized enterprises. For companies weighing how literally to take the marking requirement, the European Commission's code of practice on transparent AI systems offers the nearest thing to a safe harbor: Jones Walker advises organizations to evaluate it as a compliance framework, and to document any exception they claim — the obviousness of a chatbot, the artistic character of a work — rather than assume a regulator will infer it.

The Reach Extends Well Beyond Europe

Like the General Data Protection Regulation before it, the AI Act ties jurisdiction to effect rather than establishment. A United States firm whose chatbot serves European customers, or whose generated content reaches European audiences, falls within scope regardless of where it is incorporated — a point Holland & Knight has pressed on American clients. For most professional-services firms and mid-market adopters, which license and integrate third-party models without substantially modifying them, the operative classification is deployer, and the operative duties are disclosure.

The delayed high-risk program, meanwhile, has moved rather than vanished. Conformity assessments, technical documentation, registration in the EU database, and ten-year record retention still await providers of Annex III systems in December 2027, and non-EU providers will also need an authorized representative established in the Union, empowered to verify compliance and retain records. Complex systems typically require more than a year of preparation. Companies that treat the deferral as a pause rather than a runway are arranging to repeat this year's compressed scramble at the end of next year.

The Readiness Deficit

The larger problem is visibility. A Cloud Security Alliance research note, citing an appliedAI analysis of 106 enterprise AI systems, reports that more than half of organizations lack systematic AI inventories and that roughly 40 percent of enterprise systems cannot be clearly classified under the Act's risk framework at all. An organization cannot mark output from a system it has not cataloged, and it cannot claim the editorial-review exception for a workflow no one has documented.

The work of the next ten days is unglamorous but tractable: an inventory of every EU-facing AI system, with the organization's role recorded for each; disclosures built and tested wherever the organization acts as provider; every claimed exception — obviousness, creative work, human editorial review — documented with a named owner, so the claim survives a regulator's first question; and the high-risk workstream kept moving against the December 2027 date rather than restarted in the middle of next year.

The omnibus bought time for the AI Act's hardest requirements; it did not grant permission to pause.

The omnibus bought time for the AI Act's hardest requirements; it did not grant permission to pause. Organizations that treat August 2 as a live deadline and December 2027 as a runway will spend less, scramble less, and meet clients and regulators holding the one asset that cannot be assembled retroactively: evidence.

Source basis

  1. 01DLA PiperThe Digital/AI Omnibus: proposed deferral of high-risk obligations under the AI Act
  2. 02Gibson DunnOmnibus agreement: postponed high-risk deadlines and other key changes
  3. 03Jones WalkerArticle 50 transparency analysis and code-of-practice guidance
  4. 04Holland & KnightExtraterritorial reach: US companies face the EU AI Act's August 2026 compliance deadline
  5. 05Cloud Security AllianceEnterprise AI inventory and classification readiness (appliedAI analysis of 106 systems)

Related reading

Working through a governance question like this one?

Talk to the practice