Skip to content

What Still Changes on 2 August 2026 Under the EU AI Act

10 min read · updated August 11, 2026

2 August 2026 was drafted as the AI Act’s general application date — the day the high-risk regime, the transparency duties and the enforcement machinery all became operative at once. Six days before it arrived, an amending Regulation entered into force and took most of it away. What is left on the date is real, considerably narrower, and still catches organisations that believe they are out of scope.

The date that lost most of its content

Article 113 of Regulation (EU) 2024/1689 as adopted stated the rule first and the exceptions after: the Regulation applies from 2 August 2026, save that Chapters I and II applied from 2 February 2025; Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 applied from 2 August 2025 with the exception of Article 101; and Article 6(1) with its corresponding obligations applied from 2 August 2027.

That is no longer the operative timetable. Regulation (EU) 2026/1744, the Digital Omnibus on AI — formally, the regulation amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence — was adopted on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on the third day following publication, 27 July 2026. It moved two dates and added a third:

  • Stand-alone high-risk systems under Annex III: from 2 August 2026 to 2 December 2027. A postponement of roughly sixteen months.
  • High-risk AI embedded in the regulated products of Annex I: from 2 August 2027 to 2 August 2028.
  • The transparency obligations: unchanged at 2 August 2026. This is why the date still matters.
  • A new date of 2 December 2026 for the marking obligations for AI-generated content, as they apply to systems already on the market before 2 August 2026.
This is a statement of application dates, not legal advice. The four changes above are the whole of what this page attributes to Regulation (EU) 2026/1744; see the final section for what it deliberately does not claim. Verify against the consolidated text of the AI Act on EUR-Lex before planning against any of it, and take advice on your own facts.

The high-risk stack, and where it went

This is the block that moved. For Annex III systems — biometrics, critical infrastructure, education, employment, essential public and private services, law enforcement, migration and border control, and the administration of justice and democratic processes — classification under Article 6(2) and the obligation stack that follows it were due on 2 August 2026 and are now due on 2 December 2027. The contents of the stack did not change; only the day it binds:

  • Requirements, Articles 8 to 15. Risk management, data and data governance, technical documentation, record-keeping and logging, transparency and provision of information to deployers, human oversight, and accuracy, robustness and cybersecurity.
  • Provider obligations, Articles 16 to 22. Including the quality management system under Article 17, documentation retention, automatically generated logs, corrective action under Article 20, and the authorised representative requirement for non-EU providers under Article 22.
  • Value chain and downstream roles. Importers and distributors under Articles 23 and 24, the Article 25 rule that turns a distributor, importer, deployer or third party into a provider in defined circumstances, deployer obligations under Article 26, and the fundamental rights impact assessment under Article 27 for the bodies it applies to.
  • Conformity and market entry. Conformity assessment under Article 43, certificates under Article 44, the EU declaration of conformity under Article 47, CE marking under Article 48, and registration in the EU database under Article 49.
  • After market entry. The EU database itself under Article 71, post-market monitoring under Article 72, serious incident reporting under Article 73, and the market surveillance regime in Chapter IX.
  • Article 101. The Commission’s power to fine providers of general-purpose AI models, held back from the August 2025 batch, was set by Article 113 to apply from 2 August 2026. Whether 2026/1744 disturbed that is outside what this page can confirm.

The practical effect of the postponement is not that the work disappears. It is that the sequence with the longest lead time in the whole Regulation — build to Articles 8 to 15, document under Annex IV, run the conformity assessment, declare, mark, register — now has to complete by 2 December 2027 rather than 2 August 2026. Providers who had already built to the original date have lost nothing except urgency; providers who had not now have a runway rather than a breach.

What the date is now about

The transparency obligations in Chapter IV survived the amendment on their original date, and they are now the substance of 2 August 2026 rather than a footnote to it. They are also the part of the Regulation most likely to catch an organisation that has concluded it has no high-risk systems, because Article 50 does not depend on the risk tier at all. In outline: providers must ensure that AI systems intended to interact directly with natural persons are designed so that those persons are informed they are interacting with an AI system, unless it is obvious from the circumstances; providers of systems generating synthetic audio, image, video or text must mark the outputs in a machine-readable format and make them detectable as artificially generated or manipulated; deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them; and deployers generating or manipulating deepfake content must disclose that it has been artificially generated or manipulated, with an adjusted rule for evidently artistic or satirical work and for text published to inform the public on matters of public interest.

Each carries its own exceptions and each has a page in this cluster — the chatbot disclosure duty and the deepfake labelling duty are the two that most commonly apply to ordinary products. The machine-readable marking requirement in particular is a technical obligation, not a policy one, and the standards for satisfying it are still maturing.

There is a second date attached to exactly this point, and it is the one most likely to be missed because it did not exist in the original Regulation. For systems that were already on the market before 2 August 2026, the marking obligations for AI-generated content apply from 2 December 2026 under Regulation (EU) 2026/1744. In other words the amending Regulation postponed the heavy high-risk regime by sixteen months while giving incumbent generative systems four months to retrofit content marking. If you ship a product that generates synthetic audio, image, video or text and it predates August 2026, that December date is the nearest real deadline on your calendar — nearer than anything in the high-risk stack. See the machine-readable marking duty for what satisfying it involves.

What Member States owe

The obligations do not all run to industry. Article 57(1) as adopted requires each Member State to ensure that at least one AI regulatory sandbox is established at national level and is operational by 2 August 2026, with the option of satisfying that duty through participation in a sandbox established with other Member States. Whether that deadline was adjusted alongside the high-risk postponement is one of the details this page cannot confirm — a sandbox exists to help operators prepare for obligations that have now moved, so there is an obvious argument either way, and an argument is not an answer.

Member States were separately required to designate national competent authorities by 2 August 2025 and to lay down penalty rules by the same date, so the enforcement architecture is meant to be in place a year before most of what it enforces.

Systems already on the market

Article 111(2) as adopted contains the grandfathering rule and it is generous. For high-risk AI systems placed on the market or put into service before 2 August 2026, the Regulation applies to operators only if, from that date, the systems are subject to significant changes in their designs. There is a hard backstop for the public sector: providers and deployers of high-risk systems intended to be used by public authorities must take the necessary steps to comply by 2 August 2030 regardless. The date in that provision is tied to the application date that has now moved, so whether the cut-off travelled with it is a question for the consolidated text rather than for inference.

The load-bearing phrase is “significant changes in their designs”, which is not the same wording as the “substantial modification” definition in Article 3 that triggers a fresh conformity assessment under Article 43(4). How far the two diverge is not settled, and a system under active development is unlikely to stay untouched for long enough to make the question academic. Treating Article 111(2) as a permanent exemption for an actively maintained product is optimistic; treating it as breathing room for a stable legacy system is reasonable.

Article 111(1) sets a separate and later rule for the large-scale IT systems listed in Annex X: those placed on the market or put into service before 2 August 2027 must be brought into compliance by 31 December 2030.

What this page cannot confirm

Being explicit about the edge of what is verified is more useful here than a confident summary, because this page was rewritten within weeks of the amendment and much of the secondary commentary in circulation still describes the pre-amendment timetable.

What is stated as confirmed: Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026; the stand-alone Annex III high-risk date moved from 2 August 2026 to 2 December 2027; the Annex I embedded date moved from 2 August 2027 to 2 August 2028; the transparency obligations remain on 2 August 2026; and the marking obligations for AI-generated content apply from 2 December 2026 to systems already on the market before 2 August 2026.

What is not asserted anywhere on this page: what the amending Regulation does to the operation of the EU database in Article 71, to the Article 57(1) sandbox deadline, to Article 101, to the Article 111 transitional rules, or to the drafting of Article 113 itself. Those are not claimed in either direction because they were not checked against the instrument. Several of them plausibly moved with the application date, and plausibility is not a citation.

So the instruction is narrow and firm. Before making any plan that turns on one of those provisions, open the consolidated text of the AI Act on EUR-Lex and read the provision as it currently stands, alongside Regulation (EU) 2026/1744 itself. The four date changes above are safe to plan against; anything beyond them should be read, not inferred from this page or any other.

One thing has not changed at all and is worth ending on. The postponement moved deadlines, not obligations. Every requirement in the high-risk stack still has to be met, by systems that in most cases are being built now, and the Annex I products keep the same structural relationship to their sectoral regimes that they always had. An organisation that treats sixteen extra months as sixteen months of not starting will arrive at 2 December 2027 in the position it would have been in on 2 August 2026.