The EU AI Act on 2 August 2026: What Actually Applies (and What Was Delayed)

For over two years, 2 August 2026 sat in compliance calendars as the day the EU AI Act's core obligations — including the high-risk regime — would switch on. The date has arrived, but it does not mean what those calendars assumed. A late amendment moved the biggest piece, and getting the distinction right matters.

Quick answer: On 2 August 2026 the EU AI Act reaches a milestone, but the high-risk obligations for Annex III systems were deferred to 2 December 2027 by the Digital Omnibus (signed 8 July 2026), pending Official Journal publication. What sharpens today: the AI Office gains enforcement powers over general-purpose AI model obligations, and most Article 50 transparency duties remain anchored to this date. It is a reprieve on high-risk, not a repeal.

What was delayed, and why

The Digital Omnibus on AI, signed on 8 July 2026, deferred the applicability of the high-risk obligations. Stand-alone high-risk systems under Annex III — covering areas such as employment and worker management, creditworthiness assessment, education, and access to essential services — now apply from 2 December 2027. High-risk AI embedded in regulated products under Annex I moves to 2 August 2028.

Two caveats matter. First, this takes legal effect only on publication in the Official Journal; until that happens, the original 2 August 2026 date remains the letter of the law, which matters most to organisations that stood down their compliance programmes early. Second, legal commentators frame the deferral as a reprieve rather than a repeal — the EU delayed because national authorities and harmonised technical standards were not ready, not because it abandoned the requirements.

What actually takes effect today

Two things sharpen on 2 August 2026:

Enforcement of GPAI obligations. Obligations for general-purpose AI models have technically applied since August 2025, but the AI Office's power to investigate and fine arrives now. A rule that already existed suddenly acquires teeth. For all GPAI models that means technical documentation, a copyright policy, and a public summary of training data; for models with systemic risk it adds adversarial testing, incident reporting, and cybersecurity measures.

Article 50 transparency obligations. Most of these remain anchored to today. If you provide EU-facing chatbots or generative systems, deploy synthetic media, or use emotion-recognition or biometric-categorisation systems, the relevant disclosure duties — labelling AI interactions and marking AI-generated content — largely stand on 2 August 2026.

What it means for AI agents

The practical picture for anyone building or deploying agents in the EU:

The through-line is unchanged by the delay: the Act pushes toward documented, testable evidence of how an AI system behaves, rather than assurances. That is the same direction as OWASP's agentic guidance and the emerging norm of independent evaluation. Adversarial testing and cybersecurity are already live obligations for systemic-risk models — and the recent evaluation-security incidents at major labs are a reminder that testing those behaviours safely is itself now part of the job. See agent evaluation security and our standards overview.

What to do now

Related

Sources

The Digital Omnibus on AI (signed 8 July 2026); EU AI Act (Regulation 2024/1689); legal analyses from Gibson Dunn, Jones Walker, and DLA Piper, July 2026. Publication in the Official Journal is procedural and pending; confirm before relying on the deferred high-risk dates. This page summarizes publicly reported obligations and is not legal advice.

FAQ

Do the EU AI Act high-risk obligations apply from 2 August 2026?

Not anymore. The Digital Omnibus on AI, signed on 8 July 2026, deferred the high-risk obligations for stand-alone Annex III systems to 2 December 2027, and for AI embedded in regulated products to 2 August 2028 — subject to publication in the Official Journal. Until that publication, the original 2 August 2026 date remains the letter of the law.

What actually takes effect on 2 August 2026?

Two things sharpen. The AI Office gains its powers to investigate and fine providers of general-purpose AI models, whose obligations technically applied from August 2025 but without enforcement teeth. And most Article 50 transparency obligations remain anchored to this date.

What are the GPAI obligations now enforceable?

For all general-purpose AI models: technical documentation, a copyright policy, and a public summary of training data. For models with systemic risk: additionally adversarial testing, incident reporting, and cybersecurity measures.

What are the Article 50 transparency obligations?

Disclosure duties for AI that interacts with people or generates content — labelling chatbots as AI, marking synthetic media, and disclosing emotion-recognition or biometric-categorisation systems. Most of these remain due on 2 August 2026.

Why were the high-risk obligations delayed?

Because national authorities and harmonised technical standards were not ready. The deferral is described by legal commentators as a reprieve, not a repeal — the requirements are coming, later.

What does this mean for AI agents specifically?

An agent that qualifies as high-risk under Annex III now has until December 2027, but an agent that interacts with users or generates content may still fall under Article 50 transparency duties today. And GPAI obligations bite now for the models many agents are built on.

← Back to guides