Back to blog
EU AI Act

EU AI Act Enforcement: What Actually Changes on 2 August 2026 (and What Does Not)

The transparency duties, the obligations that were rescheduled to 2027–2028, who enforces what, and a one-week action plan for B2B SaaS teams.

Govarna Editorial TeamReviewed July 23, 202611 min read
Timeline of EU AI Act application dates showing the 2 August 2026 Article 50 milestone

Legal disclaimer: This guide is general information, not legal advice. Confirm how the EU AI Act applies to your systems, role, and deployment with qualified counsel.

Status: The Article 50 transparency duties apply from 2 August 2026. That date is not expected to move. The rescheduled high-risk dates below remain pending legal adoption of the Digital Omnibus.

2 August 2026 is the EU AI Act's most visible application date, and the most misunderstood. It is neither the day "the AI Act comes into force" (parts of it have applied since February 2025) nor the day high-risk obligations bite (those were rescheduled to 2027–2028, pending adoption). What becomes applicable on that date are the Article 50 transparency duties — the rules that require people to be told when they interact with AI, synthetic content to carry machine-readable marking, and specified biometric and deepfake uses to carry notices.

This guide separates the three layers — what already applied, what changes on 2 August 2026, and what was rescheduled — and closes with a one-week action plan.

What already applied before August 2026

Two earlier application dates are already behind us, and both still generate compliance questions in buyer reviews:

  • Prohibited practices and AI literacyapplicable since 2 february 2025. Article 5 bans specified practices such as certain social scoring and specified workplace emotion-recognition uses, and Article 4 expects organisations to ensure adequate AI literacy among staff operating AI systems.
  • General-purpose AI model obligationsapplicable since 2 august 2025. These sit with model providers, but downstream SaaS teams inherit documentation questions from them in security reviews.

If your governance program has not recorded a position on Article 5 exposure, do that before worrying about anything below — prohibited-practice exposure is the highest-severity finding a review can surface.

What becomes applicable on 2 August 2026

The Article 50 transparency duties apply from 2 August 2026. In practical terms, four obligations will apply to providers and deployers of in-scope systems:

  1. 50(1) — AI interaction disclosure. People must be informed when they interact directly with an AI system, unless that is obvious in context. The everyday case: customer-support chatbots and voice assistants.
  2. 50(2) — machine-readable content marking. Synthetic audio, image, video, and text must be marked in a machine-readable, detectable format, with a carve-out for assistive standard editing.
  3. 50(3) — biometric and emotion-recognition notices. Deployers must inform people exposed to emotion-recognition or biometric-categorisation systems.
  4. 50(4) — deepfake and public-interest text disclosure. Deployers must disclose qualifying deepfakes and certain AI-generated public-interest text that lacks human editorial responsibility.

The full breakdown — including adaptable disclosure wording and a 10-step implementation checklist — is in our Article 50 transparency guide.

What 2 August 2026 does not cover: the rescheduled high-risk dates

A large share of the "deadline" commentary conflates Article 50 with the high-risk regime. They are different obligations on different timelines. Under the May 2026 political agreement on the Digital Omnibus — pending legal adoption — the high-risk application dates moved:

Obligation setDateStatus
Article 50 transparency2 August 2026Applies from 2 August 2026
Annex III high-risk systems2 December 2027Scheduled under the May 2026 political agreement; legal adoption pending
Product-integrated (Annex I) high-risk2 August 2028Scheduled under the May 2026 political agreement; legal adoption pending

Two cautions. First, the rescheduled dates are not law until the Omnibus is adopted — build to the schedule, but track it. Second, the extra time is not slack: classification, risk management, technical documentation, and conformity assessment for a genuine Annex III system routinely consume more than a year. Teams that treat December 2027 as distant will repeat the exact scramble the market is seeing around Article 50. See the full category breakdown in our Annex III guide.

Who enforces what

Enforcement is decentralised. Each member state designates national market surveillance authorities for AI systems in its territory; the Commission's AI Office supervises general-purpose AI models. For Article 50 breaches, Article 99(4) provides maximum administrative fines of EUR 15 million or 3% of total worldwide annual turnover, subject to the Regulation's rules for undertakings and SMEs.

For most B2B SaaS companies, the first enforcement pressure will not arrive as a regulator's letter. It arrives as a buyer's security review: procurement teams are adding EU AI Act sections to questionnaires, and "show us your Article 50 analysis" is a question a label alone cannot answer. A defensible position needs an AI inventory, a recorded role analysis (provider vs deployer, per system), and evidence of the notices and marking you implemented.

The one-week action plan

  1. Day 1 — inventory. List every feature that interacts with people, generates content, or processes biometric signals. Include third-party model APIs.
  2. Day 2 — role analysis. Record whether you act as provider, deployer, or both for each system. This determines which Article 50 duties are yours.
  3. Day 3 — Article 5 screen. Confirm nothing you ship touches a prohibited practice. Escalate anything ambiguous to counsel immediately.
  4. Day 4 — map duties. Match each in-scope system to Article 50(1)–(4) and record why each duty applies or does not.
  5. Day 5 — implement and verify. Ship missing disclosures, verify upstream machine-readable marking, and document what your product adds.
  6. Days 6–7 — record and assign. Version the decision record, attach implementation evidence, and assign an owner to track Commission guidance and the Omnibus adoption.

Not sure whether you are a provider or a deployer?

The free assessment gives you a suggested provider/deployer classification and risk-exposure result in about three minutes — the day-2 step above, done for you.

Run the free assessment

EU AI Act enforcement FAQ

Did the whole EU AI Act become enforceable on 2 August 2026?

No. 2 August 2026 is the application date for the Article 50 transparency duties and further institutional provisions. Prohibited practices and AI-literacy duties have applied since 2 February 2025, and general-purpose AI model obligations have applied since 2 August 2025. The Annex III high-risk obligations are scheduled for 2 December 2027 under the May 2026 political agreement, pending legal adoption.

Were the high-risk obligations delayed?

Under the May 2026 political agreement on the Digital Omnibus, the Annex III high-risk application date moves to 2 December 2027 and the product-integrated (Annex I) date to 2 August 2028. That agreement is pending legal adoption, so treat the new dates as scheduled rather than final — and note that the extra time is for a workload that most teams underestimate.

Can a US or UK company ignore this?

Not automatically. The Act reaches providers placing AI systems on the EU market and certain providers and deployers outside the EU where the system’s output is used in the EU. Whether you are caught depends on your role and deployment, not your registered address.

What are the penalties for an Article 50 breach?

Non-compliance with Article 50 can fall under Article 99(4), which provides maximum administrative fines of EUR 15 million or 3% of total worldwide annual turnover, subject to the Regulation’s rules for undertakings and SMEs. National market surveillance authorities determine actual penalties case by case.

Is a chatbot disclosure label enough?

A label is one control, not a compliance program. Article 50 also covers machine-readable marking of synthetic content, biometric and emotion-recognition notices, and deepfake disclosure — and regulators and buyers will ask how you decided which duties apply, not just whether a label exists.

Turn the action plan into a standing record

Govarna keeps your AI inventory, role analysis, policies, controls, evidence, and change history together — so the next review starts from a record, not a scramble.

See the governance workspace