EU AI Act · deadlines at a glance
EU AI Act: what really applies on 2 August 2026
In short: 2 August 2026 is not the deadline for high-risk AI. The high-risk obligations for standalone Annex III systems have been postponed to 2 December 2027. What becomes applicable on 2 August 2026 are the transparency obligations under Art. 50 — with a grace period until 2 December 2026 for systems already placed on the market before that date. The prohibitions, AI literacy and the GPAI obligations have been in force for a while already.
This postponement comes from the “Digital Omnibus on AI” (COM(2025) 836), which amends Regulation (EU) 2024/1689. The European Parliament adopted it on 16 June 2026, the Council on 29 June 2026. Since 27 July 2026 the Omnibus has been in force as Regulation (EU) 2026/1744. The dates below are therefore part of applicable law, not merely a political agreement. One addition: further prohibitions take effect on 2 December 2026.
We ourselves worked with 2 August 2026 as the high-risk deadline on this page for a long time. That was wrong, and we have corrected it. The honest message: more time, but not no time.
What happens on 2 August 2026?
The EU AI Act applies in phases. On 2 August 2026 the transparency obligations of Art. 50 become applicable — for example labelling AI interactions, synthetic content and deepfakes. The high-risk obligations once scheduled for that day only take effect later:
- 2. Feb 2025Prohibited practices & AI literacy
Art. 5 (prohibited AI) and Art. 4 (staff literacy) apply. - 2. Aug 2025GPAI & governance
Obligations for general-purpose AI models, the national authorities and the penalty regime. - 2. Aug 2026 deadlineTransparency obligations under Art. 50
Labelling of AI interactions, synthetic content and deepfakes. - 2. Dez 2026End of the Art. 50 grace period
Systems already on the market before 2 August 2026 must comply with Art. 50 as well. The new prohibition of non-consensual intimate imagery and CSAM also takes effect. - 2. Dez 2027High-risk AI under Annex III
Chap. III (Art. 8–27, 43 et seq., 49): risk management, documentation, oversight, conformity assessment. Postponed from 2 August 2026. - 2. Aug 2028High-risk under Annex I
AI embedded in regulated products (e.g. medical devices, machinery). Postponed from 2 August 2027.
Obligations for high-risk AI systems (Art. 8–15)
These requirements apply to standalone Annex III systems from 2 December 2027 — not from 2 August 2026. The work behind them has not changed, only the timing:
Risk management · Art. 9
A continuous, documented process to identify and mitigate risks across the whole lifecycle.
Data governance · Art. 10
Training, validation and test data must be relevant, representative and as error-free as possible.
Technical documentation · Art. 11
Complete documentation per Annex IV that demonstrates conformity — before placing on the market.
Record-keeping · Art. 12
Automatic logging of events to ensure traceability of the system's operation.
Transparency · Art. 13
Deployers must be able to understand and correctly use the system — including instructions for use.
Human oversight · Art. 14
Humans must be able to effectively oversee the system and intervene (stop, override).
Accuracy & robustness · Art. 15
Appropriate accuracy, robustness and cybersecurity throughout the lifecycle.
Obligations for providers and deployers (Art. 16–27)
Beyond the requirements on the system itself, providers and deployers have organisational duties:
- Quality management system (Art. 17) — documented processes at the provider.
- Conformity assessment (Art. 43) and EU declaration of conformity (Art. 47) before market entry.
- CE marking (Art. 48) and registration in the EU database (Art. 49).
- Deployer duties (Art. 26): use as intended, oversight, log retention.
- Fundamental-rights impact assessment (Art. 27, “FRIA”) for certain public-sector deployers.
Fines: what does a breach cost?
up to €35M / 7%
Breach of prohibited practices (Art. 5) — the highest tier (Art. 99).
up to €15M / 3%
Breach of the high-risk obligations and other requirements.
up to €7.5M / 1%
Incorrect or incomplete information provided to authorities.
The higher of the fixed amount or the percentage of worldwide annual turnover applies.
EU AI Act, GDPR and DORA together
If your AI system processes personal data, the AI Act obligations apply on top of the GDPR (legal basis, DPIA under Art. 35 where relevant, automated decisions under Art. 22). For financial entities, DORA adds digital operational resilience. KomplAI checks all three frameworks in one run.
Frequently asked questions
Does the EU AI Act apply to small companies too?
What is a high-risk AI system?
Does 2 August 2026 still apply to high-risk AI?
Do I need to act already?
This guide is a factual orientation and does not replace legal advice. Citations refer to Regulation (EU) 2024/1689.