EU AI Act: What Actually Changed on 2 August 2026 — and What’s Still Coming

Date: 23/09/2026

EU AI Act: what actually changed on 2 August 2026

The deadline moved. The rules didn’t go away.

2 August 2026 was meant to be the EU AI Act’s biggest day — the date most of the rulebook landed on businesses. Six days before it arrived, the EU moved part of the goalposts. Regulation (EU) 2026/1744, the “Digital Omnibus on AI”, was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It pushed the headline obligations for “high-risk” AI back to December 2027.

That is not the same as a reprieve. A smaller set of rules took effect on 2 August exactly as planned, a further set arrives on 2 December 2026, and the delayed obligations are delayed, not deleted. If your business uses any kind of artificial intelligence — a chatbot on your website, software that screens job applications, a tool that scores risk — this still matters to you, even if you have never thought of yourself as an “AI company”.

Think of the AI Act the way you think of GDPR: common-sense guardrails to make sure technology treats people fairly. If you are already GDPR-compliant, you are closer to ready than you think. It is also one of several EU rules that now sit alongside GDPR — our companion piece walks through four other EU rules that might apply to your business. This article is the deep dive on this one.

Does the AI Act actually apply to you?

Short answer: probably, at least a little. The AI Act applies to anyone who builds, sells, or simply uses AI systems in the EU. That covers a lot of ordinary business tools:

  • Recruitment software that screens CVs
  • Chatbots that handle customer queries
  • Tools that score creditworthiness or insurance risk
  • Systems that recommend products or personalise pricing

Most businesses fall into the lowest-risk category, which mainly means being transparent with customers when they are interacting with AI. A smaller group — using what the Act calls high-risk systems — carries extra obligations like documentation and human oversight. It is that high-risk group whose deadline moved.

What took effect on 2 August 2026

The date did not pass quietly. From 2 August 2026, the Article 50 transparency obligations apply. In practice: if people interact with an AI system — a chatbot, an AI-generated recommendation — you generally need to tell them so, and certain AI-generated content has to be marked. For most ordinary businesses this is the part to act on now.

This sits on top of the AI Act’s earlier rules, already in force: the outright bans on “unacceptable-risk” uses (from 2 February 2025) and the baseline duties on general-purpose AI models (from 2 August 2025).

One widely-misreported point deserves its own line. The high-risk deferral is limited to Chapter III of the AI Act. It did not touch Article 50. So a business running a high-risk system still owes the transparency duties today, even though its Chapter III obligations are not due until 2027.

Watermarking: a grace period, not a postponement

This is the detail most summaries get wrong, and getting it wrong costs you time you do not have.

Article 50(2) requires providers of AI systems generating synthetic audio, image, video or text to mark their output in a machine-readable way. Regulation (EU) 2026/1744 did not postpone that duty. What it added is a narrow grace period for systems already on the market before 2 August 2026 — those have until 2 December 2026 to comply.

Systems placed on the market on or after 2 August 2026 must comply from that date. So if you have adopted a generative AI tool recently, or are about to, the marking obligation is live now. The practical question to ask your provider is simple: was this system on the EU market before 2 August 2026, and does its output carry machine-readable marking?

What arrives on 2 December 2026

Regulation (EU) 2026/1744 added new prohibited practices to Article 5, and they are worth knowing about even though they will not touch most businesses. The Act now bans AI systems used to generate or manipulate child sexual abuse material, and AI systems used to generate non-consensual intimate or sexually explicit material depicting an identifiable person — the so-called “nudifier” applications. The prohibition covers images, video and audio.

These prohibitions apply from 2 December 2026, not from 2 August 2026. If you provide or deploy a generative AI system capable of producing such content, the safeguards, moderation policies and terms of use are the things to review before then.

What got pushed back — and to when

This is the substance of what changed. Under Regulation (EU) 2026/1744, the bulk of the Chapter III obligations for high-risk systems now apply from:

  • 2 December 2027 — for standalone high-risk systems (the Annex III list: biometrics, critical infrastructure, employment, education, access to essential services, law enforcement, migration, administration of justice). Originally 2 August 2026. This is the big one. If you use AI to make decisions that significantly affect people, you now have until December 2027 to show you understand how the system works and keep it under human review.
  • 2 August 2028 — for AI built into products already covered by EU health and safety law (the Annex I list: medical devices, machinery, aviation equipment and similar).

The Regulation also clarified the term “safety component”: AI that only assists users or optimises performance is not automatically treated as a safety component where its failure creates no health or safety risk. That narrows the circumstances in which an operational or productivity tool gets pulled into the high-risk category — a genuinely helpful change for ordinary businesses.

And the Article 4 AI literacy duty was softened: providers and deployers must now take measures to support a sufficient level of AI literacy among staff, rather than to ensure it. The underlying expectation has not gone away, but the standard is more proportionate.

Careful: two Omnibuses, only one of them law

The wider Digital Omnibus package published on 19 November 2025 is two separate files, and conflating them is the most common mistake being made about it right now:

  • The AI Omnibus is done. Regulation (EU) 2026/1744 — everything described above — is in force.
  • The Data Omnibus is not. The proposals amending GDPR, the ePrivacy Directive, NIS2 and the Data Act remain under negotiation between the Parliament and the Council as of September 2026.

Nothing about your GDPR obligations or your cookie banner has changed as a result of the Omnibus, whatever the headlines suggest.

The good news: GDPR already did some of the work

If you use AI to process personal data — and most business AI does — GDPR already required you to have a lawful basis, to consider a data protection impact assessment for higher-risk processing, and to keep records of what you do with people’s data. The AI Act builds on that foundation rather than replacing it. Businesses that take GDPR seriously are rarely starting from zero — and the delayed deadlines give room to close gaps calmly rather than in a panic.

Simple next steps

  1. List the AI tools you actually use — including ones bought off the shelf, like HR platforms or marketing tools with AI features switched on by default.
  2. Check whether customers are told when they are talking to a bot or receiving an AI-generated recommendation. This transparency duty is already live.
  3. For any generative tool, ask the provider whether it was on the EU market before 2 August 2026 and whether its output carries machine-readable marking.
  4. Flag anything that makes decisions about people — hiring, pricing, credit, access to a service. These are the high-risk candidates now due by December 2027.
  5. Review your existing GDPR documentation. Much of it already applies here.
  6. Use the extra runway wisely: get a second opinion now, while there is time to fix things properly.

You do not need to become an AI expert. You need to know what you are using and be able to explain it simply — to a regulator, and to your customers.

Not sure which of your tools the AI Act reaches, or what you owe and when? Let’s Talk GDPR.

Related reading


References

  1. Regulation (EU) 2024/1689 (AI Act) — harmonised rules on artificial intelligence; Article 5 (prohibited practices), Article 50 (transparency obligations), Chapter III (high-risk systems), Article 113 (application dates).
  2. Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI) — amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230; published in the Official Journal 24 July 2026, in force 27 July 2026.
  3. Regulation (EU) 2026/1744, amending Article 113 of the AI Act — Chapter III, Sections 1 to 3 apply from 2 December 2027 for Annex III high-risk systems and 2 August 2028 for Annex I high-risk systems; the new Article 5 prohibitions apply from 2 December 2026.
  4. Regulation (EU) 2026/1744, amending Article 111 of the AI Act — providers of systems generating synthetic audio, image, video or text placed on the market before 2 August 2026 must comply with Article 50(2) by 2 December 2026.
  5. European Commission, Digital Omnibus package (19 November 2025) — the AI strand was separated and fast-tracked; the remaining proposals amending GDPR, ePrivacy, NIS2 and the Data Act remain under negotiation.
  6. Regulation (EU) 2016/679 (GDPR) — Articles 6 (lawfulness), 30 (records of processing) and 35 (data protection impact assessment).
Latest Articles & Insides