What the EU AI Act actually requires on 2 August 2026
On 2 August the AI Act's transparency rules and its fines both switch on. The high-risk rules didn't - they slipped to 2027. Here's what really applies.
7 min read
Two things switch on across the EU on 2 August 2026: the AI Act's transparency obligations under Article 50, and the penalty regime that enforces them. The high-risk obligations everyone spent a year bracing for did not — they were pushed back to December 2027 and August 2028. So the rule that lands this week is the one most teams weren't preparing for: if your product talks to users, or generates content with a model, you have a disclosure obligation and there is now a fine attached to it.
What actually applies on 2 August
Article 50 covers four situations. Crucially, it is not limited to high-risk systems — it applies to ordinary products, and the obligation falls on different parties depending on the case. From the Article 50 text:
| Situation | Who's obliged | What's required |
|---|---|---|
| AI systems that interact directly with people | Provider | Design it so people are informed they're interacting with an AI |
| AI-generated synthetic content (audio, image, video, text) | Provider | Outputs marked in a machine-readable format and detectable as AI-generated |
| Emotion recognition & biometric categorisation | Deployer | Inform the people exposed to it |
| Deepfakes, and AI text published to inform the public | Deployer | Disclose that the content is artificially generated or manipulated |
Two details do most of the work in practice. Disclosure must happen "at the latest at the time of the first interaction or exposure," clearly and distinguishably — a line buried in a settings screen or a terms page isn't compliance. And there are narrow carve-outs: the interaction rule doesn't apply where it's obvious to a reasonably informed person, and assistive editing that doesn't substantially alter the input (a grammar fix) is exempt from the marking rule. The exemption for AI-generated public-interest text requires human review plus someone holding editorial responsibility — an unattended publishing pipeline doesn't qualify.
What got postponed — and why that's the trap
The Digital Omnibus on AI, agreed in May 2026 and signed in July with publication in the Official Journal the final step, moved several deadlines:
- Stand-alone high-risk systems (Annex III — recruitment screening, biometric identification, and similar): from August 2026 to 2 December 2027.
- AI embedded in regulated products (Annex I — machinery, lifts): to 2 August 2028.
- Machine-readable marking for generative systems already on the market before 2 August 2026: a grace period to 2 December 2026.
The trap is reading "postponed" as "nothing happens in August." The delay applies to the high-risk regime, not to Article 50. And the grace period on marking is narrow — it covers systems already on the market, machine-readable marking specifically. Ship something new in August and you're in scope on day one.
The part with teeth
Here's what changes the calculus: the AI Act's penalty provisions become operative on the same date. Article 99 wasn't enforceable before; from 2 August 2026, it is.
Breaches of Article 50 sit in the middle tier — up to €15,000,000, or 3% of total worldwide annual turnover, whichever is higher for an undertaking. (The top tier, 7% or €35m, is reserved for prohibited practices; the bottom tier, 1% or €7.5m, is for supplying incorrect information.)
One provision genuinely helps smaller companies, and it's widely misread. For SMEs and start-ups, Article 99 says each fine is capped at the percentage or the amount "whichever thereof is lower." The comparison is inverted relative to large undertakings. If you're a small company, your exposure is bounded by your turnover percentage rather than the headline millions — which makes this proportionate, not existential. It does not make it ignorable.
The obligation that arrives in August isn't a compliance programme. It's a sentence of UI copy, a content-marking step in an export pipeline, and knowing which of the two you are — provider or deployer.
What to do this week
If you ship anything with a model in it, five concrete checks:
- Work out whether you're the provider or the deployer for each AI feature. The obligations differ, and if you build a product on someone else's model you may be both — provider of your system, deployer of theirs.
- Audit every surface where a user talks to a model. Chat, support widgets, voice, in-app assistants. Each needs a clear disclosure at first interaction, not on a help page.
- Find every path that emits generated content and check whether marking is applied on export. Provenance metadata usually needs to be attached at generation time — retrofitting it downstream is much harder, which is exactly why the December grace period exists.
- Check your published text. If a model drafts anything you publish to inform the public, you either disclose it or you can evidence human review with named editorial responsibility. "Someone skimmed it" is not the standard.
- Write down the assessment. Even where you conclude an exemption applies — it's obvious, it's assistive-only — record why. The reasoning is what you'll need if anyone asks, and it takes an hour now versus a scramble later.
One thing worth flagging for anyone building the way we do: running a model on-device doesn't exempt you. Article 50 is about what the user is told, not where the inference happens. A fully private, on-device assistant still has to say it's an AI. That's a low bar and a good habit anyway, but we've seen teams assume local processing puts them outside the regime. It doesn't.
Our opinion
This is the rare regulation whose first phase is mostly good product design, and teams should treat it that way rather than as a legal fire drill. Telling someone they're talking to a machine, and marking content a machine made, is what an honest product does regardless of jurisdiction. The compliance deadline is just the moment the honest version stopped being optional.
We'd also argue the postponement of the high-risk rules is being read too optimistically. Two extra years is real relief for anyone building recruitment screening or biometric systems, but nothing about the underlying obligations got easier — conformity assessment, risk management, technical documentation are all still coming. Teams that treat December 2027 as "later" will meet the same wall with less runway. The ones who use the extra time to build the documentation habit now will find the deadline unremarkable.
The pattern is familiar. We made essentially this argument about accessibility when the European Accessibility Act came into force: the products that had to scramble were the ones that had treated a well-signposted requirement as a future problem. Regulatory deadlines in the EU are published years ahead. They are the most predictable engineering constraint you will ever get.
How Ashvara helps
We build AI features with the disclosure and provenance work included rather than bolted on — the interaction notice in the UI, content marking applied at generation, and a written record of which obligations apply and why. Most of it is hours, not weeks, when it's designed in from the start.
That's part of how we approach AI solutions, and it's consistent with how we build generally: our own apps run their AI on-device wherever we can, because the best answer to a data obligation is usually not to move the data at all. If you're not sure whether Article 50 touches your product, or you'd rather have it handled before August, tell us what you've built and we'll map it.
This is a summary of a regulation for a technical audience, not legal advice — for a specific compliance position, take proper counsel.
Sources: EU Artificial Intelligence Act, Article 50 — Transparency Obligations (artificialintelligenceact.eu) and Article 99 — Penalties (artificialintelligenceact.eu); Digital Omnibus on AI deadline changes per Skadden, "AI Act State of Play," 2026 (skadden.com).