top of page
ICON-Final-05_edited.png

The EU AI Act in August 2026: what applies now and what's been postponed?

  • 7 hours ago
  • 3 min read

August 2, 2026 was set to be one of the big dates in the EU's AI Act. That's when the full requirements for high-risk AI systems were originally due to take effect. That didn't happen. Through the so-called Digital Omnibus regulation, the EU has pushed back the heaviest requirements — but that doesn't mean companies can sit back. Several important parts of the legislation are already in force, and more is on the way as early as December. Here's a summary of where things stand right now.



What's already in force

Two stages of the AI Act are already in effect and apply to organizations across every industry:

  • Since February 2, 2025: Bans on AI systems with unacceptable risk, such as social scoring and certain forms of biometric categorization, along with requirements for baseline AI literacy among staff who work with AI systems.

  • Since August 2, 2025: Requirements for providers of general-purpose AI models (GPAI), such as underlying language models. These requirements have not been changed by the Digital Omnibus.


New as of August 2, 2026: the transparency requirements

Article 50 of the regulation takes effect on its original schedule as of now. Among other things, this means:

  • chatbots must inform users that they are interacting with AI,

  • AI-generated image, audio, and video content (such as deepfakes) must be labeled,

  • AI-generated text published on matters of public interest must be clearly disclosed as AI-generated,

  • emotion recognition and biometric categorization systems must notify the people exposed to them.


Existing systems do get some breathing room, though: machine-readable labeling for services already on the market doesn't need to be in place until December 2, 2026.


What's been postponed

The big news is that the full requirements for stand-alone high-risk systems — including those used in recruitment, credit scoring, law enforcement, and education — have been pushed back to December 2, 2027, 16 months later than planned. For AI embedded in products already covered by other regulations, such as medical devices and machinery, the deadline moves to August 2, 2028. Public authorities that both develop and deploy high-risk systems get even longer, until 2030.


The reason the EU gives is that the technical standards and support tools companies need in order to actually meet the requirements weren't ready in time. At the same time, the EU introduced relief for smaller companies: a new "small mid-cap" category (up to 750 employees) gets access to simplified documentation and priority access to regulatory sandboxes.


A new ban on the way

Starting December 2, 2026, an explicit ban takes effect on AI systems that generate or manipulate non-consensual sexualized content, including material depicting children. The ban covers not only systems built for this purpose, but also systems where such content is a foreseeable risk if adequate safeguards aren't in place.


Why you should still act now

The fact that the heavy high-risk requirements have been pushed back is no reason to pause your work:

  1. The transparency requirements already apply. If you use chatbots, generate marketing material with AI, or expose customers to emotion recognition, you need labeling and disclosure in place now.

  2. The postponement isn't an amnesty. Companies that develop or plan to deploy high-risk systems should keep preparing — the standards are coming, and 2027 is closer than it sounds.

  3. The AI Act applies even if you only use AI tools, not just if you develop them. Many organizations discover late that their HR, customer service, or marketing tools contain AI functionality covered by the regulation.

  4. The penalties are unchanged — up to €35 million or 7% of global turnover for prohibited AI systems, and up to €15 million or 3% for other violations.


Getting started

A good first step is to map out which AI systems your organization actually uses or provides, classify them by risk level, and check which transparency requirements already apply to your operations. If you need help figuring out where your organization stands and what to prioritize, reach out to us at Cyber Instincts — we help companies navigate both AI security and regulatory compliance in practice.


Sources: European Commission, Lawgent, Teknikministeriet, Orrick, Gibson Dunn.


bottom of page