Last updated: 2026-08-09 · Jurisdiction: European Union · Instrument: Regulation (EU) 2024/1689 (AI Act), application under Article 113 as amended
EU AI Act: what applies from 2 August 2026
On 2 August 2026 the European Commission's AI Office, together with national authorities, began enforcing the Artificial Intelligence Act, and Article 50 transparency obligations for certain AI systems started to apply. This page is a vendor-neutral explainer of that date in the Regulation's real schedule: what was already live, what flipped, which fine regime applies to which failure, and what is still on a different high-risk track. It is not a product pitch and not legal advice.
The short version
Treat 2 August 2026 as an enforcement and transparency hinge, not as the day the whole Act switched on. Article 5 prohibitions have applied since 2 February 2025. Chapter V GPAI model obligations have applied since 2 August 2025; from 2 August 2026 the Commission can investigate and fine GPAI providers under Article 101. Article 50 disclosure and marking duties apply from 2 August 2026 (with a four-month Art. 50(2) grace period to 2 December 2026 for generative systems already on the market before that day) and sit in the Article 99(4) national fine band (up to EUR 15M or 3%, whichever is higher). High-risk Chapter III Sections 1-3 apply later under Regulation (EU) 2026/1744: 2 December 2027 for Annex III / Article 6(2) systems and 2 August 2028 for Annex I / Article 6(1) product-route systems.
Why a dedicated timeline page (and not only the existing posts)
Two practitioner posts already cover pieces of this ground: the Article 50 transparency overview and the high-risk Digital Omnibus delay read. Neither is a durable, sourced map of the 2 August 2026 hinge that separates (a) already-live prohibitions and GPAI duties, (b) newly applicable transparency and enforcement, and (c) the high-risk track. This guide is that map. It is written so an AI answer can cite a dated schedule with primary sources, not a single blog angle.
If you need to classify one system or model into a risk tier, use the free EU AI Act risk-tier checker. If you need documentation completeness for one model, use the AI model documentation completeness checker.
Application timeline: the dates that actually matter
Article 113 does not switch the whole Regulation on at once. It stages chapters. The table below is the structure most “AI Act deadline” headlines flatten.
| Date | What applies | Anchor |
|---|---|---|
| 1 August 2024 | Regulation enters into force (twentieth day after OJ publication). | Article 113, first paragraph |
| 2 February 2025 | Chapters I and II apply: definitions, scope, and the Article 5 prohibited practices, plus AI literacy duties that sit with those early chapters. | Article 113(a) |
| 2 August 2025 | Chapter V (general-purpose AI models), governance chapters, and the Chapter XII penalty framework apply. Providers of GPAI models placed on the market from this date are expected to meet Chapter V obligations. Enforcement powers for those rules are not yet fully live (see next row). | Article 113(b): Chapter V, Chapter VII, Chapter XII among others |
| 2 August 2026 | Default application date for the rest of the Regulation. Article 50 transparency obligations apply (with a limited Art. 50(2) grace period for certain legacy generative systems; see next row). The AI Office and national competent authorities can exercise their supervision and enforcement powers, including for GPAI. The Commission announced enforcement of GPAI rules and the new transparency duties from this date. High-risk Chapter III Sections 1-3 are not on this day (see 2027/2028 rows). | Article 113 default date (as amended); Article 50; Commission press IP/26/1714 |
| 2 December 2026 | End of the four-month transitional period for Article 50(2) machine-readable marking: providers of generative AI systems already placed on the market before 2 August 2026 must have taken the steps needed to comply with Article 50(2) by this date (Regulation (EU) 2026/1744). Also the application date for certain new Article 5 prohibitions added by that Omnibus (e.g. non-consensual intimate imagery / related child-sexual-abuse material bans as amended). | Regulation (EU) 2026/1744 amending Art. 50 / Art. 113; recital on four-month Art. 50(2) transition |
| 2 August 2027 | Providers of GPAI models already on the market before 2 August 2025 must have taken the steps needed to comply with the Regulation's GPAI obligations by this date (Article 111 transitional rule). | Article 111 (GPAI legacy models) |
| 2 December 2027 | Chapter III Sections 1, 2 and 3 (high-risk classification and most high-risk requirements) apply for AI systems classified as high-risk under Article 6(2) and Annex III (standalone high-risk use cases), with the express exception of Article 6(5) under the amended Article 113 schedule. | Article 113 as amended by Regulation (EU) 2026/1744 |
| 2 August 2028 | Chapter III Sections 1, 2 and 3 apply for AI systems classified as high-risk under Article 6(1) and Annex I Section A-style product-safety routes (embedded high-risk). Amended Article 2(2) substantially limits how far the AI Act's high-risk machinery reaches systems tied to Annex I Section B sectoral acts; those systems largely follow their sectoral regime rather than the full Chapter III package. | Article 113 and Article 2(2) as amended by Regulation (EU) 2026/1744 |
Version and jurisdiction stamp: Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI, in force 27 July 2026), application under Article 113 as amended, and transitional rules under Article 111. Checked 2026-08-09.
What flipped on 2 August 2026
- Enforcement powers went live. The AI Office and national competent authorities can implement, supervise and enforce the Act. For GPAI models, the AI Office can request documentation and information (Article 91), conduct model evaluations (Article 92), require measures (Article 93), and impose fines under Article 101. That is the difference between “obligations on the books since August 2025” and “a regulator that can compel and fine.”
- Article 50 transparency obligations apply. Providers and deployers of certain AI systems must meet the disclosure and marking rules summarised below. Article 50 is not the high-risk instruction-for-use duty in Article 13; it is the limited-risk transparency chapter that applies from this date under Article 113.
- Default application of the rest of the Regulation. Article 113 says the Regulation applies from 2 August 2026 except where earlier paragraphs already pulled chapters forward. Anything not covered by the 2 February 2025 or 2 August 2025 early-apply lists is in the default bucket, subject to later amendments that specifically retarget high-risk timing.
The Commission's own 31 July 2026 press release frames the day exactly that way: enforcement of GPAI rules plus new transparency requirements. Use that framing when you brief executives; it matches the legal structure better than “the AI Act is now fully applicable” without qualification.
Article 50 at a glance (what the transparency duty is)
Original plain-English paraphrase of the operative paragraphs, including the horizontal Article 50(5) rules that apply to all of them. Exceptions and conditions in the Article still control; this table is a map, not a substitute for the text.
| Who | Trigger | Core duty |
|---|---|---|
| Providers (Art. 50(1)) | AI systems intended to interact directly with natural persons | Design so people are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person. |
| Providers (Art. 50(2)) | AI systems (including general-purpose AI systems) that generate synthetic audio, image, video or text | Mark outputs in a machine-readable format so they are detectable as artificially generated or manipulated; technical solutions must be effective, interoperable, robust and reliable as far as possible. |
| Deployers (Art. 50(3)) | Emotion recognition or biometric categorisation systems | Inform the natural persons exposed to the system; process personal data under the GDPR / LED / EUDPR as applicable (with stated law-enforcement exceptions). |
| Deployers (Art. 50(4)) | AI systems that generate or manipulate image, audio or video content constituting a deep fake (and certain text that informs the public on matters of public interest) | Disclose that the content has been artificially generated or manipulated, subject to the criminal-investigation and artistic/creative presentation carve-outs in the Article. |
| Providers and deployers (Art. 50(5)) | Any information required under paragraphs 1 to 4 | Provide that information to the natural persons concerned in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure, and in a form that conforms to applicable accessibility requirements. A buried terms-and-conditions mention is not enough. |
Breach of Article 50 sits in the Article 99(4) national fine band (Article 99(4)(g)), not in the Article 5 prohibited-practice band and not in the Commission's Article 101 GPAI band. For generative systems already on the market before 2 August 2026, Regulation (EU) 2026/1744 gives providers until 2 December 2026 to meet the Article 50(2) machine-readable marking duty; the other Article 50 paragraphs are not covered by that four-month runway. Commission guidelines on AI-generated content transparency expand how providers and deployers should implement these duties in practice.
GPAI models: obligations since 2025, enforcement from 2026
Chapter V duties for providers of general-purpose AI models (documentation, information for downstream providers, copyright policy, training-content summary under Article 53; plus evaluation, systemic-risk mitigation, serious-incident reporting and cybersecurity for systemic-risk models under Article 55) applied from 2 August 2025. From 2 August 2026 the Commission enforces those duties: documentation requests, model evaluations, corrective measures, and fines under Article 101.
Article 111 adds a transitional rule for models already on the market before 2 August 2025: providers must take the steps needed to comply by 2 August 2027. That is a legacy runway, not a reason to ignore Chapter V if you placed a model on the market after August 2025.
If your near-term work is documenting one model against Annex IV / Annex XI style areas, the free AI model documentation completeness checker scores documentation completeness without claiming to decide your legal role.
Two fine regimes: do not blend Article 99 and Article 101
This is the most common error in secondary write-ups. The Regulation does not have one “AI Act fine.” It has an Article 99 administrative-fine framework for operators and notified bodies (primarily applied by Member States, and by the AI Office mutatis mutandis for AI systems under its exclusive competence under the amended Articles 75/75d) and a separate Commission framework for GPAI model providers (Article 101).
| Regime | Who enforces | Ceiling (undertakings) | Typical triggers |
|---|---|---|---|
| Article 99(3) | Member States (national rules); AI Office mutatis mutandis for systems under its exclusive competence (Arts 75/75d as amended) | Up to EUR 35 000 000, or for an undertaking up to 7% of total worldwide annual turnover of the preceding financial year, whichever is higher | Non-compliance with the Article 5 prohibited practices |
| Article 99(4) | Member States (national rules); AI Office mutatis mutandis for systems under its exclusive competence | Up to EUR 15 000 000, or for an undertaking up to 3% of total worldwide annual turnover of the preceding financial year, whichever is higher | Listed operator and notified-body failures, including Article 50 transparency obligations (Art. 99(4)(g)), plus provider/deployer duties under Articles 16, 22-24, 26 and notified-body duties |
| Article 99(5) | Member States (national rules); AI Office mutatis mutandis for systems under its exclusive competence | Up to EUR 7 500 000, or for an undertaking up to 1% of total worldwide annual turnover of the preceding financial year, whichever is higher | Supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities |
| Article 101 | European Commission (GPAI model providers) | Not exceeding 3% of annual total worldwide turnover of the preceding financial year, or EUR 15 000 000, whichever is higher | Intentional or negligent infringement of relevant GPAI rules; failure to provide documents/information under Article 91; failure to comply with a measure under Article 93; failure to grant model access for evaluation under Article 92 |
For SMEs including start-ups, Article 99(6) inverts the large-firm rule: each Article 99 fine is up to the percentage or the euro amount, whichever is lower. Regulation (EU) 2026/1744 adds a parallel lower-of protection for small mid-cap enterprises (SMCs) in Article 99(6a) for the Article 99(4) and 99(5) bands. Article 101 is a separate Commission power and is worded as a single ceiling of 3% or EUR 15 000 000, whichever is higher. Always name the article when you quote a number.
The high-risk track is not the same calendar day
High-risk classification (Article 6, Annexes I and III) and the Chapter III requirements (risk management, data governance, technical documentation, logging, human oversight, conformity assessment, registration) are a different workstream from Article 50. Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force since 27 July 2026, fixed the application dates: 2 December 2027 for systems classified as high-risk under Article 6(2) and Annex III (Chapter III Sections 1-3, except Article 6(5)), and 2 August 2028 for systems classified as high-risk under Article 6(1) and Annex I product-safety routes. Amended Article 2(2) substantially limits how far those Chapter III duties reach systems tied to Annex I Section B sectoral acts. Those replace the original Article 113 schedule that would have put most high-risk duties on 2 August 2026 / 2 August 2027.
Practical consequence: a team that hears “the AI Act applies from 2 August 2026” and freezes high-risk conformity work, or a team that assumes every high-risk duty is already enforceable today, can both be wrong. Our earlier post on the high-risk delay as a warning rather than a reprieve still holds as a planning posture: inventory systems, classify against Annex III, and build the governance practices that any version of the standard will demand. The dates are fixed; the unfinished-standards reason for the delay is still the warning.
Classify a system, then come back to the calendar
The free EU AI Act risk-tier checker walks Article 2, 5, 6, 50 and 51 logic and returns prohibited, high-risk, limited (transparency), minimal, GPAI, or GPAI-with-systemic-risk. It runs in your browser and stores nothing. Use this guide for the dated enforcement picture; use the checker for one system's tier.
Seven mistakes that produce the wrong plan
Treating "2 August 2026" as one monolithic compliance day
The date is a default application and enforcement hinge, not a single on/off switch for every duty. Prohibitions already applied from 2 February 2025. GPAI Chapter V obligations already applied from 2 August 2025. Article 50 transparency and broader enforcement powers are what the Commission foregrounded for 2 August 2026. High-risk Chapter III Sections 1-3 apply from 2 December 2027 (Annex III) and 2 August 2028 (Annex I product route) under Regulation (EU) 2026/1744.
Ignoring the Article 50(2) four-month grace for legacy generative systems
Article 50 applies from 2 August 2026, but Regulation (EU) 2026/1744 gives providers of generative systems already on the market before that date until 2 December 2026 to meet the machine-readable marking duty in Article 50(2). Other Article 50 paragraphs are not on that runway. Planning as if every marking duty had zero transition, or as if every Article 50 duty had the same transition, both mis-read the Omnibus.
Collapsing Article 50 transparency with high-risk transparency (Article 13)
Article 50 is the limited-risk transparency chapter for certain systems (chatbots, synthetic content, emotion recognition, deepfakes). Article 13 is a high-risk requirement about instructions for use and information to deployers. Different tiers, different triggers, different proof.
Blending the Article 99 and Article 101 fine regimes into one number
Article 99 is the Member-State administrative-fine framework for operators and notified bodies, with three ceilings and an SME lower-of rule in Article 99(6). Article 101 is a separate Commission power against providers of general-purpose AI models. Same order of magnitude at the 3% / EUR 15M band, different addressee and enforcer. Do not invent a single blended penalty.
Assuming GPAI duties only started when enforcement started
Chapter V applied from 2 August 2025. What arrived on 2 August 2026 is the Commission's ability to investigate, evaluate models, require measures and fine under Article 101. Legacy GPAI models on the market before 2 August 2025 still have until 2 August 2027 under Article 111.
Ignoring your role (provider vs deployer vs importer)
Article 50 splits duties between providers (design-time disclosure and machine-readable marking) and deployers (informing people subject to emotion recognition/biometrics; deepfake disclosure). The same system can create different duties for different parties in the chain.
Reading only the blog posts and skipping the Regulation's date structure
Our earlier posts on Article 50 transparency and on the high-risk Digital Omnibus delay remain useful context, but they are not a substitute for the Article 113 schedule, the Article 111 transitional rules, or the current Official Journal text after Omnibus amendments.
Where this page sits in the EU AI Act cluster
| Surface | Job | Format |
|---|---|---|
| This guide | Explain what 2 August 2026 actually changed, with dates, articles, and separate fine regimes | Long-form explainer |
| EU AI Act risk-tier checker | Classify one system or model into a risk tier | Free tool |
| AI model documentation checker | Score documentation completeness for one model (Annex IV / Annex XI style areas) | Free tool |
| ISO 42001 readiness checker | Score AIMS management-system readiness (voluntary standard often used as operational backbone) | Free tool |
| EU AI Act framework page | Product-oriented overview of working under the AI Act with ISMS Copilot | Framework hub |
| Transparency blog post · High-risk delay blog post | Angle pieces on Article 50 and on reading the Omnibus delay; complementary, not substitutes for this timeline | Blog |
Browse the full set of free compliance tools, including the boundary guide on what AI agents can and cannot be trusted to do in compliance.
Frequently asked questions
What actually changed on 2 August 2026?
Two things the Commission itself stressed: (1) the AI Office, with national authorities, began enforcing the AI Act, including rules for providers of general-purpose AI models; and (2) Article 50 transparency obligations for certain AI systems began to apply (with a limited four-month grace to 2 December 2026 for Article 50(2) marking on generative systems already on the market before 2 August 2026). The Regulation's default application date remains 2 August 2026 under Article 113, but high-risk Chapter III Sections 1-3 are deferred by Regulation (EU) 2026/1744 to 2 December 2027 (Annex III) and 2 August 2028 (Annex I product route).
Did GPAI model obligations only start on 2 August 2026?
No. Chapter V and related provisions applied from 2 August 2025 under Article 113(b). Providers of models placed on the market after that date were already under the obligation set. What is new from 2 August 2026 is the Commission's enforcement toolkit (information requests, model evaluations, corrective measures, and Article 101 fines). Models already on the market before 2 August 2025 have a compliance runway to 2 August 2027 under Article 111.
Does Article 50 apply to every chatbot and every deepfake?
Article 50 applies to defined triggers, not to every AI system. Paragraph 1 covers systems intended to interact directly with natural persons (with an obviousness carve-out). Paragraph 2 covers systems generating synthetic audio, image, video or text and requires machine-readable marking. Paragraphs 3 and 4 put information and disclosure duties on deployers of emotion recognition / biometric categorisation systems and of deepfake (and certain public-interest text) systems, with law-enforcement and presentation exceptions. Read the Article's conditions and exceptions; do not treat the label as automatic for every generative feature.
What is the maximum fine under the EU AI Act?
There is no single maximum. Article 99(3) can reach EUR 35 000 000 or 7% of worldwide annual turnover (whichever is higher) for prohibited practices. Article 99(4) can reach EUR 15 000 000 or 3% for listed operator failures including Article 50. Article 99(5) can reach EUR 7 500 000 or 1% for misleading information to authorities. Separately, Article 101 lets the Commission fine GPAI model providers up to 3% of worldwide annual turnover or EUR 15 000 000, whichever is higher. For SMEs and start-ups, Article 99(6) takes the lower of the percentage and the euro amount.
Are high-risk AI system duties fully live as of 2 August 2026?
No. Regulation (EU) 2026/1744 (Digital Omnibus on AI, in force 27 July 2026) amended Article 113 so that Chapter III Sections 1, 2 and 3 apply from 2 December 2027 for high-risk systems under Article 6(2) and Annex III, and from 2 August 2028 for high-risk systems under Article 6(1) and Annex I. Classification work and governance design still matter now; the conformity-assessment clock for those sections is not the 2 August 2026 headline day.
How is this different from the free EU AI Act risk-tier checker?
This page is the dated legal structure: what flipped when, which articles, which enforcer, and which fine regime. The free checker at /resources/eu-ai-act-risk-checker classifies one system or model into a risk tier (prohibited, high-risk, limited/transparency, minimal, or GPAI / GPAI-systemic) from your answers. Use the guide for the calendar and the enforcement picture; use the checker for the tier of a specific system.
Is this legal advice?
No. It is educational content that paraphrases the structure of Regulation (EU) 2024/1689 and Commission materials in original wording. Classification, role, and the current high-risk application dates after Omnibus amendments are fact-specific. Confirm against EUR-Lex, your competent authority, and counsel.
Primary sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act): Articles 50 (transparency, including 50(5) clear/distinguishable/accessible disclosure at first interaction), 99 (penalties), 101 (fines for providers of general-purpose AI models), 111 (transitional rules), and 113 (entry into force and application). eur-lex.europa.eu (checked 2026-08-09).
- Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 (Digital Omnibus on AI): amends Article 113 high-risk application dates to 2 December 2027 (Annex III / Art. 6(2)) and 2 August 2028 (Annex I / Art. 6(1)); four-month Article 50(2) transition to 2 December 2026 for generative systems placed on the market before 2 August 2026; in force 27 July 2026. eur-lex.europa.eu (checked 2026-08-09).
- European Commission press release IP/26/1714, 31 July 2026: Commission starts enforcing AI Act rules and new transparency requirements on 2 August (AI Office enforcement of GPAI rules; Article 50 transparency duties). ec.europa.eu (checked 2026-08-09).
- European Commission, AI Act policy page (regulatory framework): application timeline, GPAI rules effective August 2025, enforcement powers of the AI Office and Member State authorities from 2 August 2026. digital-strategy.ec.europa.eu (checked 2026-08-09).
- European Commission, Guidelines on transparency obligations for providers and deployers of certain AI systems (Article 50 applies from 2 August 2026). digital-strategy.ec.europa.eu (checked 2026-08-09).
- European Commission AI Act Service Desk, Article 99 (Penalties): administrative fine ceilings including Article 99(4)(g) for Article 50 transparency obligations; SME lower-of rule in Article 99(6). ai-act-service-desk.ec.europa.eu (checked 2026-08-09).
- European Commission, enforcement framework of the AI Act: AI Office investigative and sanctioning powers for GPAI models and certain AI systems, applicable from 2 August 2026. digital-strategy.ec.europa.eu (checked 2026-08-09).
Written and maintained by the ISMS Copilot team. Our compliance content is produced by certified information security professionals, including a CISM-certified ISO 27001 Lead Implementer who still runs audits. Last reviewed 2026-08-09.
This page paraphrases the structure of Regulation (EU) 2024/1689 and Commission materials in original wording. It is educational content, not legal advice and not a binding determination of any system's risk tier or any organisation's role. Confirm against the current Official Journal text (including Digital Omnibus on AI amendments) and your competent authority or counsel.
Ready to do compliance work faster?
Built for speed, accuracy, and audit-ready output.
