EU AI Act August 2026: What Applies Now and What Was Deferred

Ten days ago, a large part of the EU AI Act came into force. Most of the coverage in the weeks before that said the opposite.
The confusion is understandable. On 27 July 2026 the Digital Omnibus on AI entered into force and pushed back the heaviest compliance obligations by more than a year. Headlines read as a reprieve. A lot of teams filed the whole thing under next year's problem.
Then 2 August arrived and three things switched on anyway: the transparency obligations in Article 50, the Commission's enforcement powers over general-purpose AI models, and the full penalty regime. If your company builds with AI and sells anywhere near Europe, it is worth a few minutes to work out which half applies to you.
What was actually deferred
The high-risk tier, and only that.
The instrument is Regulation (EU) 2026/1744, adopted on 8 July 2026 and published in the Official Journal on 24 July. It amends the AI Act alongside the civil aviation and machinery regulations, and its own Article 4 brought it into force on the third day after publication rather than the usual twenty. Recital 46 explains why: legal certainty was needed without delay, given the AI Act's general application date of 2 August 2026. The EU legislated at emergency speed to settle its own rules six days before they applied.
The mechanism is narrow. Article 1, point 40 of the Omnibus rewrites the third paragraph of Article 113 of the AI Act, which is where the application dates live. Standalone Annex III systems, used in areas such as recruitment, credit scoring, education, law enforcement and border control, move to 2 December 2027. AI embedded in regulated products under Annex I, so medical devices, machinery and vehicles, moves to 2 August 2028.
It is worth naming what this is not. The parallel Digital Omnibus on data protection, which would amend the GDPR, is a separate file still under negotiation. The two get conflated constantly. Only the AI one is law, and none of it touched the obligations that took effect on 2 August.
The phased timeline
- 2 February 2025: prohibited AI practices. In force.
- 2 August 2025: general-purpose AI model obligations. In force.
- 2 August 2026: transparency, enforcement over general-purpose AI, penalties. In force.
- 2 December 2027: high-risk standalone Annex III systems. Deferred.
- 2 August 2028: high-risk AI embedded in Annex I products. Deferred.
What is live now is disclosure, not paperwork
This is the part worth understanding, because it is cheaper than most people assume.
The obligations now in force are about telling people the truth. A system built to impersonate a human, a chatbot for instance, has to tell the person it is talking to. Output from generative AI has to be marked as machine-generated in a form a machine can read. Deepfakes and text published to inform the public on matters of public interest have to be visibly labelled as well.
The Regulation frames transparency more broadly than labelling. Recital 27 describes it as systems developed and used in a way that allows traceability and explainability, makes people aware they are interacting with AI, tells deployers what the system can and cannot do, and tells affected people what their rights are.
Most companies can close the disclosure gaps in a day. The traceability half is harder, because it depends on records you either kept while the system was running or did not.
Someone will point out that enforcement is likely to be slow, and they are not wrong. The Omnibus exists partly because implementation genuinely slipped, with national authorities still being designated and harmonised standards arriving late. A regulator still assembling its own machinery is unlikely to open with maximum penalties. The catch is that this has already stopped being purely an enforcement question. European buyers are putting AI Act questions into procurement. That conversation is happening now, whatever the regulator is doing.
The Act follows the system, not the passport
A Dubai company can be fully in scope without a European office.
Article 2 applies the Regulation to providers placing AI systems on the EU market or putting them into service in the Union, regardless of where the provider is established. The reach works the way the GDPR's does. So if you build an AI feature for a European client, run a chatbot that European users talk to, or supply something that ends up inside a European product, the obligations travel with the system.
One more thing worth separating, because it gets merged constantly: the AI Act does not replace the GDPR. Where an AI system handles personal data, both apply at once.
On penalties, the numbers are set as the higher of a fixed sum or a share of global turnover. Prohibited practices reach EUR 35 million or 7 per cent. High-risk non-compliance reaches EUR 15 million or 3 per cent. Giving authorities incorrect information reaches EUR 7.5 million or 1 per cent. Proportionate caps apply to smaller companies.
Four things worth doing this month
None of these need a consultant, and all of them make the 2027 deadline easier when it arrives.
- List every AI system you run, what it does, who deployed it and what data it touches. More than half of organisations have no systematic AI inventory. Everything else depends on this one.
- Classify each system as prohibited, high-risk, transparency-only or minimal. Plenty of teams are running something that qualifies as high-risk without realising, because the Annex III categories are wider than they read.
- Close the disclosure gaps. Any place a user meets a chatbot without being told, or receives generated content without a marking, is an obligation that applies today.
- Write down who approves what. Traceability comes from records made at the time, not reconstructed later. Decide which decisions a human signs off, and log them.
The through-line here is not really regulatory. A company that can say what its AI systems do, who authorised them and what they touch is a company that can answer a buyer as easily as a regulator. The deadline is just what forces the question.
Working out where your systems sit?
The inventory is where most teams stall, because nobody owns the full list. Elchai builds AI systems for enterprise and government clients from Dubai, with approval gates and audit trails designed in rather than added later. If you are mapping your deployments against the Act and want a second pair of eyes on the classification, we are happy to talk it through. Get in touch at [email protected].
Elchai Group is a technology provider. We build and deliver systems; we do not provide legal or regulatory advice, and classification under the AI Act remains the responsibility of the provider or deployer of each system.
Sources
- Regulation (EU) 2024/1689 (Artificial Intelligence Act), OJ L, 2024/1689, 12 July 2024, in force 1 August 2024. Recital 27 and Article 2.
- Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI). Published in the Official Journal 24 July 2026, entered into force 27 July 2026 under its Article 4. CELEX 32026R1744. eur-lex.europa.eu
- European Commission summary, Rules for trustworthy artificial intelligence in the EU.
- The Regulation number, adoption date, publication date and entry-into-force date above are taken from the EUR-Lex record for the instrument. The specific amended application dates in Article 113 are consistently reported across independent implementation trackers. Anyone relying on a precise date should read the amended Article 113 text directly.
Accurate as at 12 August 2026. The Act is being implemented in phases and was amended weeks before this was written, so check the current position before acting. General information, not legal advice.


