What Actually Took Effect Under the EU AI Act
The high-risk cliff on 2 August never came. Chatbot disclosure, deepfake labelling and the Commission's fining powers did. A guide to the dates that now apply, after the Digital Omnibus rewrote them.

Much of the coverage of 2 August 2026 said the EU AI Act had been delayed. That is half true, and the wrong half to lead with. The heaviest obligations, for high-risk systems, were pushed back. The obligations that reach every AI product serving European users, and the Commission's power to fine, took effect on schedule. Precision matters, because the penalties attach to the part that is live.
What the Omnibus changed
Regulation (EU) 2026/1744, the Digital Omnibus on AI, was signed on 8 July, published in the Official Journal on 24 July and entered into force on 27 July 2026, nine days before the Act's general date of application. The Commission's guidance explains the reason: the delayed availability of harmonised standards put the high-risk rules' entry into application on 2 August 2026 in jeopardy. The new dates are 2 December 2027 for Annex III high-risk systems, such as those used in employment, credit and critical infrastructure, and 2 August 2028 for AI embedded in physical products such as medical devices, toys and lifts. Member states' regulatory-sandbox deadline moved to 2 August 2027, and the Machinery Regulation was moved to a lighter category of applicable obligations.
What is live now
The Commission's 31 July release is direct: from 2 August 2026, the AI Office, together with national authorities, will begin enforcing the AI Act. Chatbots must tell users they are interacting with AI; deepfakes must be labelled; AI-generated content must carry machine-readable marks. The Commission published a first list of more than 180 organisations that signed the transparency code of practice, which its guidance describes as one way to demonstrate compliance with Article 50, and launched an AI Act complaints tool, a whistleblower tool and a channel for downstream providers. One transitional carve-out, noted by Goodwin and other firms: providers of generative systems already on the market before 2 August have until 2 December 2026 to implement machine-readable marking.
| Obligation | Applies from | Maximum penalty |
|---|---|---|
| Prohibited practices, AI literacy | 2 February 2025 | €35m or 7% of turnover |
| General-purpose model obligations | 2 August 2025 | €15m or 3% |
| Transparency (Article 50), enforcement powers | 2 August 2026 | €15m or 3% |
| New bans: non-consensual intimate imagery, CSAM generation | 2 December 2026 | €35m or 7% |
| Annex III high-risk systems | 2 December 2027 | €15m or 3% |
| AI embedded in regulated products | 2 August 2028 | €15m or 3% |
Penalties for transparency breaches run to €15 million or 3% of global annual turnover, with proportionality for small and mid-sized companies; supplying incorrect or misleading information to regulators can draw up to €7.5 million or 1%. New Article 5 prohibitions on systems that generate non-consensual intimate material or child sexual abuse material apply from 2 December 2026 at the top tier of €35 million or 7%. As of mid-September, no public Article 50 enforcement action has been reported by any national authority or the AI Office, which is an absence of evidence rather than evidence of restraint.
The incidents in the background
Reuters reported on 31 July that the Commission was in talks with OpenAI and Anthropic over recent hacking incidents involving their models, as officials promoted the Act's monitoring requirements for high-risk systems. An unnamed Commission official told Reuters: 'All these, let's say, incidents highlight the importance of really putting in place the necessary monitoring activities by the developers.' OpenAI's head of EMEA policy, Tom Duff Gordon, told Euronews the company had collaborated closely on implementing the Act, including its codes of practice.
Who benefits, who is at risk
Beneficiaries: providers of high-risk systems, who gained 16 months; compliance vendors selling Article 50 tooling; consumers, who now have a legal right to know when they are talking to a machine. At risk: any organisation, including media, agencies and individuals, that deploys generative AI toward EU users without disclosure and marking, since Article 50 is not limited to large companies.
What happens next?
- The first Article 50 enforcement actions by national authorities or the AI Office establish how strictly disclosure and marking are read.
- Harmonised standards for high-risk systems are published ahead of the December 2027 date.
- The 2 December 2026 prohibitions on intimate-imagery and CSAM generation take effect at the top penalty tier.
- The Commission's talks with OpenAI and Anthropic over model incidents shape monitoring guidance.
Related topics
Sources & references
- 01Regulation (EU) 2026/1744 (Digital Omnibus on AI) — EUR-Lexprimary
- 02Navigating the AI Act: frequently asked questions — European Commissionprimary
- 03Commission starts enforcing AI Act rules and new transparency requirements on 2 August — European Commissionprimary
- 04Enforcement of the AI Act — European Commissionprimary
- 05Safer and more transparent AI — European Commissionprimary
- 06EU says necessary to monitor high-risk AI systems after OpenAI, Anthropic AI hacking — Reutersnews
- 07EU AI Act transparency obligations now in force — Goodwinreport
More from Security
OWASP Ranked AI Risks Against Real Incidents, and Agency Jumped
OWASP's GenAI Security Project published the 2026 Top 10 for LLM applications on 4 August, ranking risks with roughly a quarter of the weight on a corpus of 7,714 real incidents. Prompt Injection and Sensitive Information Disclosure stay first and second; Excessive Agency climbs to third; and a new Agent Control Standard defines portable runtime controls for agent platforms.
The Summer AI Agents Learned to Attack
Two disclosed incidents in ten weeks moved AI agent security from forecast to record: frontier models escaping containment during an evaluation, and commercial agents used to compromise hundreds of organisations. Identity and containment, not model alignment alone, are the controls that now matter.
Securing the Agentic Enterprise
An explainer on the new attack surface created by AI agents with tool access, and the controls that decide how far enterprises can let them go.


