Skip to main content
Redergo

EU AI Act after August 2026: what applies and what slipped

5 minutes read
EU AI Act after August 2026: what applies and what slipped

From 2 August 2026 the AI Act transparency obligations in Article 50 apply and penalties become enforceable, while the Commission gains full supervisory powers over general-purpose AI model providers. The Digital Omnibus package moved high-risk obligations to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems.

The 2nd of August 2026 came and went with nothing visible happening. No inspections, no letters. Yet from that date the AI Act moved into its operational phase, and for the first time the European Commission can fine providers of general-purpose models. In the companies we work with the reaction is usually one question: so what do I actually have to do?

The short answer depends on what you do with AI, not on how big you are. The long answer means separating three things that keep getting mixed up: what is already binding, what has been postponed, and what nobody will ever ask you for in writing but you need anyway.

What kicked in on 2 August 2026

From 2 August 2026 the transparency obligations of Article 50 apply, together with the governance rules: member states must have working authorities, and penalties become enforceable. The Commission can also exercise its full supervisory powers over providers of general-purpose AI models, whose own obligations had been in force since 2 August 2025. Breaching those can cost up to 15 million euro or 3 per cent of annual worldwide turnover, whichever is higher.

It helps to recall what was already live before that date. Since 2 February 2025 certain practices have been banned, including social scoring, emotion recognition in the workplace and untargeted scraping of facial images, and the AI literacy duty applies to anyone putting AI in the hands of staff. That last one is the most widely ignored obligation in the whole regulation, and also the cheapest to satisfy.

Transparency: who declares what

Article 50 splits the work between whoever builds the system (the provider) and whoever puts it to use (the deployer). If a system interacts directly with people, the provider has to design it so that it is clear there is a machine on the other side. If it generates or manipulates images, audio or video that look real, the output has to be marked in a machine readable way, and whoever publishes it has to disclose that to users. At the end of July 2026 the Commission published guidelines explaining how to apply all of this, technical marking included.

In practice, for a company: if you run a chatbot on your site, the visitor has to understand immediately that they are not writing to a person. If you use synthetic voices or faces in marketing material, you say so. If your software analyses emotions or biometric data, you have a bigger problem than a disclaimer and it is worth talking it through before development starts.

High risk slipped to 2027, it did not disappear

The Digital Omnibus package pushed the heaviest part back. Obligations for standalone high-risk systems, the ones listed in Annex III such as recruitment, credit scoring and access to essential services, start on 2 December 2027. Those for systems embedded in products already covered by EU product rules, Annex I, start on 2 August 2028.

There is a wrong reading of that delay and a right one. Wrong: we have two years, let us talk about it later. Right: we have two years for the slow part, which is not writing documentation but working out whether a system is high risk and renegotiating the contracts with whoever supplies it. A candidate scoring model that nobody looks at today becomes, under that classification, a system with requirements on data quality, logging, human oversight and conformity assessment. That work does not compress into a quarter.

Business meeting reviewing compliance documents at an office table

Who supervises, in Italy

Italy has its own AI law, 132/2025, layered on top of the European regulation, and it names the national authorities: AgID as notifying authority for the bodies that will assess conformity, and ACN as market surveillance authority, with inspection and sanctioning powers. For a software developer that changes little in substance and a lot in practice. Your counterpart in an inspection is Italian, and ACN is the same agency that already receives NIS2 incident notifications.

If you use AI but do not build it

Most companies sit in this box: they buy tools, they do not develop them. Deployer obligations are lighter, not empty. Three concrete things are needed. Knowing which AI tools are actually running in the company, and the answer is not the one IT gives you, it is the one you get by walking past the desks. A minimum documented training on what can and cannot go into a prompt. A clause in supplier contracts that guarantees you the information you need to stay compliant yourself.

The inventory is the part that surprises people. Every time we run one, a personal subscription used on company data turns up that nobody had recorded.

What changes in the projects we build

On the technical side these duties turn into things you wanted anyway. Chatbot disclosure is one line of interface. Traceability is a log of model calls with the prompt version, input and output kept for as long as they are useful. Human oversight is an approval step before an irreversible action fires, which in our agent projects is already there for operational reasons rather than legal ones.

If you are scoping an AI project right now, the place to slot these requirements in is the analysis document, not the acceptance test. You can see how we approach AI work, or just write to us.

Frequently asked questions

Does the AI Act apply to us if we only use tools like ChatGPT?

Yes, as a deployer, with a lighter set of duties. You need AI literacy for the staff using those tools, transparency towards people who interact with an AI system you have put in front of them, and respect for the banned practices. You are not subject to provider obligations unless you rebrand a system as your own or substantially modify it, in which case you can become the provider.

What are the penalties under the AI Act?

Banned practices go up to 35 million euro or 7 per cent of annual worldwide turnover. Breaches of other obligations, transparency included, go up to 15 million euro or 3 per cent. Supplying incorrect or misleading information to authorities goes up to 7.5 million euro or 1 per cent. The higher of the two figures applies, with lower caps for smaller companies.

Since high-risk obligations were postponed, can we wait?

The deadline moved, the work did not shrink. Classifying a system as high risk or not, gathering evidence on training data, setting up logging and human oversight, and renegotiating supplier contracts all take months and involve people outside the technical team. Companies that start in 2027 will be buying the same work under time pressure.

Who is the competent authority in Italy?

Under law 132/2025, ACN is the market surveillance authority with inspection and sanctioning powers, and AgID is the notifying authority for conformity assessment bodies. Sector regulators such as the Bank of Italy or the data protection authority keep their own competences where AI touches their areas.

Related questions

  • What does Article 50 of the AI Act require for chatbots?
  • What did the Digital Omnibus change in the AI Act timeline?
  • Who has to comply with the AI Act, providers or deployers?

Do You Have a New Project?