The EU AI Act on 2 August 2026: What Actually Applies (and What Was Delayed)
For over two years, 2 August 2026 sat in compliance calendars as the day the EU AI Act's core obligations — including the high-risk regime — would switch on. The date has arrived, but it does not mean what those calendars assumed. A late amendment moved the biggest piece, and getting the distinction right matters.
Quick answer: On 2 August 2026 the EU AI Act reaches a milestone, but the high-risk obligations for Annex III systems were deferred to 2 December 2027 by the Digital Omnibus (signed 8 July 2026), pending Official Journal publication. What sharpens today: the AI Office gains enforcement powers over general-purpose AI model obligations, and most Article 50 transparency duties remain anchored to this date. It is a reprieve on high-risk, not a repeal.
What was delayed, and why
The Digital Omnibus on AI, signed on 8 July 2026, deferred the applicability of the high-risk obligations. Stand-alone high-risk systems under Annex III — covering areas such as employment and worker management, creditworthiness assessment, education, and access to essential services — now apply from 2 December 2027. High-risk AI embedded in regulated products under Annex I moves to 2 August 2028.
Two caveats matter. First, this takes legal effect only on publication in the Official Journal; until that happens, the original 2 August 2026 date remains the letter of the law, which matters most to organisations that stood down their compliance programmes early. Second, legal commentators frame the deferral as a reprieve rather than a repeal — the EU delayed because national authorities and harmonised technical standards were not ready, not because it abandoned the requirements.
What actually takes effect today
Two things sharpen on 2 August 2026:
Enforcement of GPAI obligations. Obligations for general-purpose AI models have technically applied since August 2025, but the AI Office's power to investigate and fine arrives now. A rule that already existed suddenly acquires teeth. For all GPAI models that means technical documentation, a copyright policy, and a public summary of training data; for models with systemic risk it adds adversarial testing, incident reporting, and cybersecurity measures.
Article 50 transparency obligations. Most of these remain anchored to today. If you provide EU-facing chatbots or generative systems, deploy synthetic media, or use emotion-recognition or biometric-categorisation systems, the relevant disclosure duties — labelling AI interactions and marking AI-generated content — largely stand on 2 August 2026.
What it means for AI agents
The practical picture for anyone building or deploying agents in the EU:
- A high-risk agent gets more time, but not a pass. If your agent falls under an Annex III use case, the heavy obligations — risk management, human oversight, data governance, logging, conformity assessment — now bite in December 2027. Use the time; the deferral happened because compliance was hard, not because it was unnecessary.
- Transparency may apply now. An agent that converses with users or generates content can fall under Article 50 today, independent of the high-risk timeline.
- The models underneath are already in scope. Agents are typically built on general-purpose models, and the GPAI obligations — now enforceable — flow through to what you build.
The through-line is unchanged by the delay: the Act pushes toward documented, testable evidence of how an AI system behaves, rather than assurances. That is the same direction as OWASP's agentic guidance and the emerging norm of independent evaluation. Adversarial testing and cybersecurity are already live obligations for systemic-risk models — and the recent evaluation-security incidents at major labs are a reminder that testing those behaviours safely is itself now part of the job. See agent evaluation security and our standards overview.
What to do now
- Re-confirm your systems' classification against Annex III — the deadline moved, the classification work did not.
- If you operate an EU-facing agent that interacts or generates content, check your Article 50 transparency posture for today.
- If you build on general-purpose models, confirm the GPAI documentation, copyright, and training-data obligations are met now that they are enforceable.
- Treat December 2027 as runway, not relief, for high-risk conformity work. How to map an eval to the EU AI Act walks through anchoring each check to a specific article, and the EU AI Act high-risk conformance pack is that mapping already built and graded.
Related
- EU AI Act standard · Standards overview
- EU AI Act high-risk conformance pack
- How to map an eval to the EU AI Act
- Agent evaluation security
Sources
The Digital Omnibus on AI (signed 8 July 2026); EU AI Act (Regulation 2024/1689); legal analyses from Gibson Dunn, Jones Walker, and DLA Piper, July 2026. Publication in the Official Journal is procedural and pending; confirm before relying on the deferred high-risk dates. This page summarizes publicly reported obligations and is not legal advice.
FAQ
Not anymore. The Digital Omnibus on AI, signed on 8 July 2026, deferred the high-risk obligations for stand-alone Annex III systems to 2 December 2027, and for AI embedded in regulated products to 2 August 2028 — subject to publication in the Official Journal. Until that publication, the original 2 August 2026 date remains the letter of the law.
Two things sharpen. The AI Office gains its powers to investigate and fine providers of general-purpose AI models, whose obligations technically applied from August 2025 but without enforcement teeth. And most Article 50 transparency obligations remain anchored to this date.
For all general-purpose AI models: technical documentation, a copyright policy, and a public summary of training data. For models with systemic risk: additionally adversarial testing, incident reporting, and cybersecurity measures.
Disclosure duties for AI that interacts with people or generates content — labelling chatbots as AI, marking synthetic media, and disclosing emotion-recognition or biometric-categorisation systems. Most of these remain due on 2 August 2026.
Because national authorities and harmonised technical standards were not ready. The deferral is described by legal commentators as a reprieve, not a repeal — the requirements are coming, later.
An agent that qualifies as high-risk under Annex III now has until December 2027, but an agent that interacts with users or generates content may still fall under Article 50 transparency duties today. And GPAI obligations bite now for the models many agents are built on.