Email Us
Growfiy Logo
EU AI Act Is Now Enforceable: What August 2026's New Rules Actually Require

EU AI Act Is Now Enforceable: What August 2026's New Rules Actually Require

The EU AI Act's high-risk deadline was pushed to December 2027, but Article 50 transparency rules still apply from August 2, 2026. Here's what's live, what's delayed, and what to do about it.

By Growfiy Team10 min read

August 2, 2026 was supposed to be the day the EU AI Act's toughest rules kicked in across the board. That date is still real, but the rulebook changed shape just weeks before it arrived. On July 27, 2026, the EU's Digital Omnibus on AI formally entered into force, pushing back the deadline for high risk AI systems while leaving several other obligations exactly where they were. If you're running an AI product, a marketing tool, or a customer facing chatbot that touches the EU, here is what actually applies right now, what got delayed, and what to do about it.

The Short Version

The EU AI Act did not get delayed as a whole. Only one major piece moved. Here's the breakdown.

High risk AI system obligations (Annex III)

Covering hiring tools, credit scoring, biometric categorization, and similar use cases, these are now due December 2, 2027, not August 2, 2026.

Article 50 transparency obligations

These still apply from August 2, 2026, exactly as originally written.

Prohibited practices

Under Article 5, these have already been enforceable since February 2, 2025.

General purpose AI model obligations

For providers, these have already applied since August 2, 2025.

Watermarking and machine readable labeling

Of AI generated content now applies from December 2, 2026, with a grandfathering window for systems already on the market before August 2026.

In plain terms: the deadline that grabbed headlines got pushed back sixteen months, but a separate set of transparency rules is landing on schedule this month, and it applies far more broadly than most businesses realize.

What Was Delayed, and Why

The Digital Omnibus was first proposed by the European Commission in November 2025 as a simplification package touching the AI Act, GDPR, the Data Act, and the ePrivacy Directive. The core complaint from industry and member states was straightforward: the harmonized technical standards that high risk providers needed to actually comply with Annex III weren't ready in time, making the original August 2026 deadline unworkable.

Negotiations were messy. A first trilogue between Parliament, the Council, and the Commission collapsed on April 28, 2026 after roughly twelve hours without agreement. A second round produced a provisional political deal on May 7, 2026, which the Council confirmed on May 13. Formal adoption followed, and the Omnibus was published in the Official Journal on July 24, 2026, entering into force three days later.

The result: Annex III high risk obligations (risk management, data governance, technical documentation, conformity assessment, CE marking, EU database registration) now apply from December 2, 2027. High risk AI embedded in regulated products under Annex I (medical devices, machinery, and similar categories) moves to August 2, 2028. The registration and conformity assessment process was also simplified for several categories, reducing paperwork for smaller providers.

What Still Applies From August 2, 2026

This is the part getting buried under "the EU delayed the AI Act" headlines, and it's the part most businesses actually need to act on this month.

Article 50 transparency rules require

Telling users clearly when they are interacting with an AI system rather than a human, unless it's obvious from context. Labeling AI generated or manipulated content, including deepfakes and synthetic audio, video, or images. Disclosing when a system uses emotion recognition or biometric categorization on a person. Marking AI generated text published to inform the public on matters of public interest, unless a human has reviewed and takes editorial responsibility for it.

Other obligations that remain untouched and enforceable

Prohibited practices under Article 5, including social scoring, manipulative AI that exploits vulnerabilities, and most forms of real time remote biometric identification in public spaces by law enforcement. General purpose AI model obligations, including technical documentation and copyright compliance measures for providers of foundation models. The AI Office's enforcement powers and the market surveillance framework, which are now fully operational.

Penalties for violations remain steep. Breaches of prohibited practices can draw fines up to EUR 35 million or 7% of global annual turnover, whichever is higher. Other violations, including transparency failures, can draw fines up to EUR 15 million or 3% of global turnover.

Who This Actually Affects

The AI Act applies based on where the AI system's output is used, not where the company is headquartered. That means EU based companies building or deploying AI systems are directly in scope. Non EU companies, including those in the US, UK, and India, are in scope if their AI system's output is used by people in the EU, even without a physical presence there. Providers (companies that build the system) and deployers (companies that use it in a professional capacity) carry different obligations under the Act, and both can be liable.

Practically, if your chatbot, content generator, or AI powered support tool serves EU users, or your SaaS product has EU customers using AI features, Article 50's disclosure rules already apply to you this month, regardless of company size.

What To Do Before December

Even with the Annex III deadline pushed out, waiting until 2027 to start is a mistake, since standards, guidance, and enforcement patterns are being set right now.

Audit every AI touchpoint

Confirm proper disclosure is in place for chatbots, generated content, and any emotion or biometric detection features that reach EU users.

Classify your systems against Annex III now

Even though the deadline moved, reclassification later under time pressure is far more expensive.

Watch the Transparency Code of Practice

For AI generated content, expected to finalize the labeling and watermarking standard that becomes mandatory in December 2026.

Track the Annex I timeline separately

If you build AI into regulated hardware or medical products, since that deadline sits even further out at August 2028.

Frequently Asked Questions

Does the EU AI Act apply to a business based outside the EU, like in the US or India?

Yes, if the AI system's output is used by people located in the EU. Location of the company doesn't matter. A US or India based SaaS company with EU customers using an AI feature is in scope, and needs to meet the Article 50 transparency rules that are active from August 2026.

My company is in the US. Are we required to do anything by August 2026?

If none of your AI outputs reach EU based users, no. If any part of your product serves EU customers, including through a website available to EU visitors, you likely need to meet transparency obligations now, even though the bigger Annex III compliance deadline was pushed to December 2027.

Is my AI chatbot considered high risk under the Act?

Most customer service or marketing chatbots are not high risk. High risk categories are narrower and cover things like hiring decisions, credit scoring, biometric identification, and access to essential services. A standard chatbot still needs to disclose that users are talking to AI under Article 50, but it typically doesn't fall under the heavier Annex III requirements.

What happens if a business simply ignores the August 2026 transparency rules?

Non compliance can draw fines up to EUR 15 million or 3% of global annual turnover, and the AI Office now has functioning enforcement and market surveillance powers to act on it. Given the fines apply per violation category and scale with global revenue, ignoring the disclosure requirements is a real financial risk, not a theoretical one.

EU AI Act 2026Digital Omnibus on AIArticle 50 Transparency RulesEU AI Act High Risk DelayAI Act Annex III DeadlineAI Watermarking Rules 2026EU AI Act ComplianceAI Act PenaltiesAI Act Non EU CompaniesAI Chatbot Disclosure RulesAI Office EnforcementEU AI Regulation Explained