Policy ยท Regulation

The EU AI Act's Enforcement Era Begins: What the 2 August 2026 Milestone Actually Means

๐Ÿ“… Aug 26, 2026 ๐Ÿท๏ธ AI / Regulation โš–๏ธ AI
โš–๏ธ
On 2 August 2026, the EU AI Act crossed from rulebook to live law: enforcement begins for the general-purpose AI obligations, the transparency rules in Article 50, and the prohibited practices that have applied since February 2025. The same date activates the Digital Omnibus amendments and pushes new prohibitions on non-consensual deepfakes to December. This explainer maps the timeline, what each milestone requires, and who is affected.

The timeline in one view

The AI Act entered into force on 1 August 2024 and applies progressively. Definitions and the AI-literacy duty applied from 2 February 2025, together with the prohibitions on unacceptable-risk systems. The general-purpose AI (GPAI) obligations and the governance architecture applied from 2 August 2025, with a one-year adjustment period before enforcement powers became usable.

2 August 2026 is the enforcement milestone: the Commission can now use its supervision and enforcement powers against GPAI model providers - requesting documentation, conducting evaluations, demanding compliance measures and imposing fines. The transparency obligations in Article 50 become applicable and enforceable, national authorities begin enforcing the prohibitions and the AI-literacy duty, and regulatory sandboxes must be operational in every member state. The European Commission's official AI Act service desk lists the full sequence.

What the GPAI obligations require

Providers of general-purpose AI models have been obliged since August 2025 to keep technical documentation, provide information to downstream providers, adopt a copyright-compliance policy and publish a training-content summary. The new enforcement powers make those obligations real: the Commission can request documentation and information, run evaluations, require risk mitigation, and fine non-compliant providers.

Providers of models presenting systemic risk carry the heavier set: model evaluations, risk assessment and mitigation, serious-incident reporting and cybersecurity requirements. Providers of open-license models are exempt from most documentation duties but must still comply with the copyright policy and training-summary obligations unless the model presents systemic risk. Non-EU providers must appoint an authorised representative in the Union unless they release under a free and open-source licence.

The transparency and deepfake milestones

Article 50 transparency obligations - labelling AI-generated content, disclosing AI interaction and detecting synthetic content - become applicable on 2 August 2026. Providers of AI systems already on the market that generate synthetic content have until 2 December 2026 to comply with the labelling and detection requirements.

On 2 December 2026, the new prohibitions kick in for AI systems that generate or manipulate non-consensual intimate imagery and child sexual abuse material. These are the Digital Omnibus-era additions, and their early activation reflects the political priority on image-based abuse.

The high-risk phases: 2027 and 2028

The rules for high-risk AI systems listed in Annex III - used in areas such as employment, education, credit scoring and migration - apply from 2 December 2027. High-risk systems embedded in regulated products covered by Annex I follow on 2 August 2028. Between the two dates, providers and deployers must work through the full compliance package: risk-management systems, technical documentation, EU database registration, CE marking, human oversight and cybersecurity.

For companies building or deploying AI in the EU, the practical message is to start now: the gap between the August 2026 enforcement milestone and the 2027-2028 high-risk deadlines is shorter than it looks, and the compliance work - documentation, governance, testing - is not something that can be compressed into the final quarter.

Who should be acting now

Three groups are on the clock. GPAI model providers and anyone using their models in high-risk contexts; developers of high-risk systems in Annex III use-cases, who have roughly a year of runway before the December 2027 deadline; and deployers of AI that interacts with people or generates content, who must now ensure transparency labelling and the December 2026 synthetic-content transition are in hand.

The enforcement posture is also clearer than it was: the Commission holds exclusive powers over GPAI providers, national market-surveillance authorities cover the rest, and the AI Office coordinates. For organisations that treat the August 2026 date as the starting gun rather than a deadline, the remaining timeline is manageable.

Frequently asked questions

What actually changed on 2 August 2026?

Enforcement began. The European Commission gained supervision and enforcement powers over general-purpose AI providers - documentation requests, evaluations, compliance measures and fines. Transparency obligations under Article 50 became applicable, national authorities began enforcing prohibitions and AI-literacy duties, and regulatory sandboxes became mandatory.

Do the transparency rules apply to my AI system?

They apply to systems that interact with people, generate or manipulate synthetic content, or operate emotion recognition or biometric categorisation. Providers of synthetic-content systems already on the market before 2 August 2026 have until 2 December 2026 to comply with labelling and detection duties.

When do the high-risk rules apply?

High-risk AI systems listed in Annex III apply from 2 December 2027; high-risk systems embedded in regulated products under Annex I apply from 2 August 2028. Providers and deployers should start the compliance work now - documentation, risk management, human oversight - rather than waiting for the deadlines.