Blog · AI

AI Act: what actually applies since 2 August 2026

Aug 28, 20269 min readby Scroll
AI Act: what actually applies since 2 August 2026
On this page

The Digital Omnibus pushed high-risk obligations to December 2027. What already applies, what was postponed, and what to do in between.

Since 2 August 2026, most of the European AI regulation applies, but not the part almost every article published this year announced. A regulation adopted this summer, the “Digital Omnibus on AI”, pushed the heaviest obligations, those covering so-called high-risk systems, from 2 August 2026 to 2 December 2027. What did come into application on 2 August 2026 is the transparency obligation, the enforcement powers of national authorities, and the framework around staff training.

The practical consequence fits in two sentences. If you read over the past months that you had to be “high-risk compliant” by August 2026, that information is out of date. And if you concluded there was nothing left to do this year, so is that: three obligations apply right now, and one of them concerns just about every company that has put a chatbot on its website.

What changed this summer: the Digital Omnibus

The Regulation (EU) 2026/1744, nicknamed the “Digital Omnibus on AI”, was published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July 2026. It amends Regulation (EU) 2024/1689, the AI Act, along with two sector-specific texts. The Commission presents it as targeted simplification: lighter procedures for smaller organisations, broader regulatory sandboxes, legal clarifications, and above all the postponement of several deadlines.

The legislative path was fast: Commission proposal on 19 November 2025, political agreement between Parliament and Council on 7 May 2026, Parliament vote on 16 June, final green light from the Council on 29 June. The text also adds a new prohibition, covering the generation of non-consensual intimate content and child sexual abuse material.

What to take away: the AI Act timeline published everywhere since 2024 is no longer the right one, and many reference sites still have not updated it. Checking an application date on a page written before August 2026 is like consulting last year’s train timetable.

The real AI Act timeline, up to date

Here are the deadlines as they stand after the omnibus.

  • 1 August 2024: the regulation enters into force, with no immediate obligation.
  • 2 February 2025: the practices listed in Article 5 are prohibited (social scoring, manipulation, emotion recognition at work and in education, untargeted scraping of facial images), and the training obligation in Article 4 starts to apply.
  • 2 August 2025: obligations for general-purpose AI models (GPAI), European governance, and the penalty regime.
  • 2 August 2026: transparency obligations under Article 50, control and enforcement powers of national authorities, regulatory sandboxes operational.
  • 2 December 2027: obligations for high-risk systems listed in Annex III, instead of 2 August 2026.
  • 2 August 2028: obligations for high-risk systems embedded in already-regulated products, medical devices or industrial machinery for instance, instead of 2 August 2027.

What has applied since 2 August 2026

The transparency obligation, Article 50

This is the broadest obligation, and the easiest to meet provided you think about it at design time. Article 50 covers four situations. An AI system interacting directly with a person must inform them they are dealing with a machine, unless that is obvious from the context. Generated or manipulated content (audio, image, video, text) must be marked in a machine-readable format. Emotion recognition and biometric categorisation systems must inform the people exposed to them. And deepfakes must be disclosed as such by whoever publishes them.

The exceptions are narrow and worth knowing: standard editing tools that do not substantially alter the content, artistic, satirical or fictional works, with lighter disclosure, and AI-generated text that has undergone human review under editorial responsibility.

In practice, on a website or an application: a clear notice when the chat window opens, not a line buried in the terms and conditions. If you run a conversational assistant, that is the first thing to fix, and we cover the rest in our article on chatbots and their limits.

Enforcement powers, and the penalty tiers

Since 2 August 2026, national authorities can actually impose penalties. Article 99 sets three tiers, each taking the higher of a fixed amount and a percentage of worldwide annual turnover: up to 35 million euros or 7% for prohibited practices, up to 15 million or 3% for other obligations, transparency included, and up to 7.5 million or 1% for supplying incorrect information to authorities. For SMEs and start-ups the rule inverts: the lower of the two applies, and Member States must take the company’s viability into account.

Training your teams

The “AI literacy” obligation has existed since February 2025: providers and deployers must ensure a sufficient level of AI understanding among the people using it on their behalf. The omnibus relaxed it and gave authorities a stronger role in promoting it. It remains the only obligation that touches the organisation rather than the product, and the easiest to document: an internal usage note, a training session, a written trace. It is also the best antidote to shadow AI, those AI tools adopted by teams outside any framework.

What was postponed, and why not to wait

What exactly is a high-risk system

Annex III lists eight domains: biometrics, critical infrastructure, education and vocational training, employment and worker management, access to essential services (including creditworthiness assessment and insurance pricing), law enforcement, migration and border control, and the administration of justice and democratic processes.

For an ordinary company, the category that bites is almost always the same: employment. A tool that screens applications, evaluates performance or allocates tasks between employees falls within scope, even when it is a feature of off-the-shelf software. The December 2027 postponement does not change that classification: it only changes the date by which you must be able to document it.

Eighteen months is not a lot

High-risk compliance is not a checkbox. It requires a risk management system, technical documentation, governance of training data, event logging, effective human oversight and a conformity assessment. For a system you bought rather than built, it mostly requires obtaining those elements from your vendor, so writing them into a contract, which takes months when the contract is already running.

The arithmetic is simple: companies that wait until late 2027 will discover at the same moment that their vendors are saturated. Those that use the postponement to map their usage and negotiate will have a phased project rather than a wall.

Does this concern me?

Two questions are enough to place yourself, and they come in this order.

First question: are you a provider or a deployer? The provider develops an AI system, or has one developed, and places it on the market under its own name. The deployer uses it under its own authority. The vast majority of small and mid-sized companies are deployers: they buy a tool and fit it into their processes. One caveat: integrating a model through an API into your own product and offering it to your customers moves you to the provider side, with markedly heavier obligations.

Second question: what risk level does each use case fall into? The regulation defines four. Prohibited practices, applicable since February 2025. High-risk systems, postponed to December 2027. Systems subject to transparency, applicable since August 2026: chatbots, generated content, deepfakes. And everything else, minimal risk, with no specific obligation.

In practice, the most common case among our clients combines two things: a majority of minimal-risk uses (writing, document summarisation, coding assistance) and one or two transparency obligations as soon as a system speaks to the public. A well-scoped AI transformation handles both in a matter of days, not months.

Five actions to take before December 2027

  • Inventory your uses. List every place AI is involved: tools you bought, features switched on inside existing software, internal developments, and informal use by teams. It is the starting point, and it almost always surfaces uses management did not know about.
  • Classify each use. Prohibited, high-risk, transparency, minimal. One line per use, with the reason for the classification. That table is what an authority will ask for, and what an enterprise customer will request in their procurement questionnaire.
  • Add transparency wherever the public is involved. A notice when a chat opens, disclosure of generated content, information for people subject to biometric analysis. This is product work, not legal work.
  • Write a usage policy and train people. What is allowed, with which data, in which tools, and who approves what. One page is enough to start, and it covers the training obligation.
  • Review your vendor contracts. Where the data is hosted and logged, for how long, with which sub-processors, and what happens if you leave. It is the same exercise as for AI data sovereignty, and it can be done once for both.

The AI Act does not replace the GDPR

The two texts stack, and that is a frequent source of confusion. The AI Act governs the system: what it does, how it was built, what must be told to the people exposed to it. The GDPR governs the personal data flowing through it: legal basis, minimisation, retention period, data subject rights, transfers outside the European Union.

An internal assistant connected to your documents falls under both: the AI Act for transparency and training, the GDPR as soon as a document contains personal data. The French data protection authority, the CNIL, publishes AI-specific recommendations, and its developer GDPR guide remains the reference on the design side. If your website also collects data, our article on GDPR compliance for a website covers the web side.

What we take from it

The AI Act is not a wall that falls on a given date: it is a series of deadlines, two of which have just moved. For most European companies, the 2026 exercise is not a heavy compliance project, it is an honest inventory followed by two or three product corrections. The real work, the one covering high-risk systems, starts now and ends in December 2027, and it plays out with your vendors as much as internally.

At Scroll we scope these questions at the point where they cost least: before building. If you have an assistant, an agent or an intelligent automation project and compliance is holding you back, let’s talk. It is usually shorter than people fear.