Skip to main content

AI Act: next deadline on August 2nd. Here is what you need to know.

star ellipse

AI /

AI Act: next deadline on August 2nd. Here is what you need to know.

Discover the AI Act deadlines starting August 2, 2026, the updates in the AI Omnibus, the obligations under Art. 50, and governance strategies for SMEs and large enterprises.

logo Smart Shaped

Smart Shaped

ago 9 min.

August 2, 2026, is the deadline when the transparency obligations of the AI Act (Regulation (EU) 2024/1689) become directly applicable, specifically those under Article 50 regarding chatbots, deepfakes, and synthetic content. It is not the only date: governance and GPAI provisions take effect earlier (2025), while high-risk systems have deadlines further down the line (2027–2028).

The AI Act (Regulation (EU) 2024/1689, the European Artificial Intelligence Act) is the European Union's first comprehensive regulatory framework for safety, ethics, and transparency. The "game-changing" deadline for many organizations is not the one for high-risk systems, but rather the one for transparency: starting August 2, 2026, specific disclosures become mandatory, operational, and verifiable according to the guidelines of the European Commission (2026).

What are the AI Act deadlines from 2025 to 2028?

The next key deadline is August 2, 2026, but not all rules under the AI Act take effect simultaneously. The official EU timeline distinguishes between: outright bans (first), governance and GPAI (General-Purpose AI models) in 2025, transparency in 2026, and heavier obligations for high-risk AI systems in 2027–2028. The AI Act entered into force on August 1, 2024 (European Commission, 2026).

Date Regulatory Scope & Obligations
February 2025 Absolute bans enter into force for systems presenting "unacceptable risk" (e.g., mass surveillance, social scoring, behavioral manipulation).
August 2025 Application of general governance rules, the institutional oversight architecture, and the sanctions framework.
July 27, 2026 Official entry into force of the AI Omnibus, a supplementary regulation designed to simplify administrative burdens for enterprises.
August 2, 2026 Key milestone date: full applicability of general transparency obligations (Article 50).
December 2, 2026 Expiration of the 4-month extension for content generation systems already placed on the market before August 2, 2026.
December 2, 2027 New postponed deadline (via AI Omnibus) for compliance of high-risk AI systems (Annex III and standalone systems).
August 2028 Final completion of the European regulatory framework with the application of the last remaining provisions.

For a broader introductory overview, see also The European Union and the AI Act: Impact and Regulatory Adjustments.


What changes starting August 2, 2026, under Article 50 of the AI Act?

Starting August 2, 2026, transparency obligations under Article 50 (the AI Act provision regarding the end user's "right to know") become directly applicable for specific AI use cases, particularly chatbots, deepfakes (manipulated or synthetic audio/video/image content simulating reality), and AI-generated content (generated by an AI system). The European Commission confirms that Article 50 transparency obligations apply as of August 2, 2026 (European Commission, 2026: Art. 50 guidelines).

These guidelines define the scope of application of transparency obligations for providers and deployers of AI systems under Article 50 of the AI Act.

— European Commission, Institution of the European Union

Who is affected: typically providers (those who develop/supply) and deployers (those who use and operationalize) AI systems, including generative tools and conversational assistants. A practical example: a customer service chatbot must immediately disclose its artificial nature, for instance, "You are talking to a virtual assistant."

  • Declared Interactions

    The disclosure must be provided to the end user upfront, except in cases where the artificial nature is "obvious from the context" (European Commission, 2026).

  • Watermarked Content

    Watermarking (technical marking, often machine-readable) is a possible measure, but transparency can also include text labels and metadata (European Commission, 2026: code of practice).

  • Deepfakes and Public Information

    If a synthetic video is used in marketing or training, the organization must indicate that the content was generated or manipulated by AI, except under specific exceptions and responsible human oversight (European Commission, 2026).

Important distinction: "AI-generated" does not equal "AI-assisted." An assisted text (a draft proposed by an LLM and rewritten with substantial human review) may require different internal disclosure policies compared to content published as an almost integral output of the model.


What are the most common operational challenges in AI Act compliance?

The main difficulty lies not in understanding the key date, but in translating legal obligations into verifiable and auditable technical processes. In practice, AI Act compliance requires bridging legal/compliance, IT, and security teams, alongside a coordinated interpretation with the GDPR (Regulation (EU) 2016/679) whenever AI processes personal data.

Technical standards and harmonized rules

Harmonized standards (EU technical standards granting a presumption of conformity) are not always available or mature when companies must implement controls. This is where CEN-CENELEC (European standardization organizations) and the AI Office (EU coordination body on the AI Act) play a role in clarifying expectations and best practices.

Market velocity vs. regulatory timelines

LLMs and generative tools evolve faster than policy cycles: watermarks and detectors can become obsolete. For this reason as well, the EU code reiterates that adherence is voluntary, but Article 50 requirements remain binding legal obligations (European Commission, 2026: code of practice).

Most frequent practical errors

  • Incomplete mapping: shadow AI tools (ChatGPT, Gemini, plugins) not inventoried.
  • Lack of ownership: no designated owner for disclosure and controls.
  • Inconsistent labeling: differing labels across marketing, HR, and training departments.
  • Vendor dependency: contractual clauses without verifiable guarantees.

Three quick fixes: create a unified registry, standardize disclosure templates, and introduce a release checklist for synthetic content. From a "people & process" perspective, taking an approach similar to ESG implementation can help: see tools for ESG implementation in enterprises.


How to build proactive AI governance before August 2, 2026?

Effective AI governance starts with an inventory, assigned roles, policies, and documented controls. Before August 2, 2026, the goal is not to "block AI," but to make transparency repeatable: who publishes content, who approves disclosures, and who verifies vendors.

  1. AI register (inventory): census models, SaaS tools, and automations by department, including use cases and generated outputs.
  2. Ownership and roles: assign responsibilities across Legal, Compliance, IT, Security, and business units.
  3. Transparency policy: define disclosure rules for chatbots, synthetic content, and deepfakes, complete with templates and use-case examples.
  4. Vendor checklist: carry out due diligence and establish clauses covering transparency, logging, incident response, and software updates.
  5. Workflow + training: implement pre-publication approval steps and practical training for users (marketing, HR, instructors, developers).

For an operational deep-dive, see managing AI governance and compliance with the EU AI Act.


What penalties does the AI Act impose, and how much does compliance cost?

Financial risk under the AI Act stems both from potential fines and organizational adaptation costs. Violations of transparency obligations (Article 50) can carry fines up to €15 million or 3% of total worldwide annual turnover, whichever is higher (TrueScreen, 2026: fines and Art. 50). Furthermore, the penalty structure is tied directly to overall governance and GPAI obligations (Il Sole 24 Ore, 2026).

Type of Violation Subject Entities Penalty Threshold Practical Example
Transparency (Art. 50) Deployer / provider Up to €15M or 3% global turnover Chatbot operating without initial disclosure
Inaccurate information to authorities Enterprise under audit Case-dependent (AI Act) Incomplete technical documentation during an audit
Governance and GPAI obligations GPAI provider / deployer AI Act penalty framework Absence of mandatory measures required starting 2025
Prohibited practices (unacceptable risk) Provider / deployer Most severe tier (AI Act) Prohibited use of behavioral profiling

How much compliance costs depends on the entity's role (provider vs. deployer), the number of use cases, and the regulatory environment (e.g., banking). Generally, the main cost drivers are: initial auditing and inventory, staff training, vendor contract updates, and logging/monitoring tools. For architectural choices impacting costs and risk (such as on-premise LLMs), see privacy and security of local LLMs: 2026 guide.


How organizational compliance changes ahead of August 2, 2026?

AI Act compliance is undergoing a major shift for all organizations as the August 2, 2026 deadline approaches. The central mandate is ensuring that every interaction, product, or content piece generated by artificial intelligence is clearly recognizable as such. This requires adopting internal disclosure policies, maintaining use-case registries, and overhauling data management workflows.

Organizations must adapt their auditing, transparency, and vendor control mechanisms, aligning the AI Act's new requirements with existing frameworks like the GDPR and third-party risk management rules. Priorities are shifting toward activity logging, technical documentation for AI systems, and practical staff training on responsible usage policies.

Many organizations are already anticipating these needs by establishing internal guidelines and disclosure standards to mitigate non-compliance risks and foster responsible AI adoption. Industry-wide initiatives, such as signing European codes of conduct or voluntary pacts, signal a growing focus on proactive compliance ahead of the new rules taking effect.

FAQ on the AI Act and the August 2, 2026 deadline

Does the August 2, 2026 deadline apply to organizations that only use ChatGPT or Gemini?

Yes, if an organization acts as a deployer using ChatGPT or Gemini to interact with users or publish content, it may fall under Article 50 transparency obligations. The deadline does not target "the tool itself," but rather the specific use case: public-facing chatbots, synthetic content, and deepfakes require disclosure.

Do I need to label all content created with AI?

No. Article 50 does not mandate a universal label for every piece of content "touched" by AI. The requirement depends on the context and the risk of misleading users: customer interactions with chatbots, fully synthetic/manipulated media, and deepfakes require transparency; internal drafts that are AI-assisted can be managed via internal corporate policies.

What are the maximum penalties for transparency violations?

For breaches of transparency obligations (Article 50), fines can reach up to €15 million or up to 3% of global annual turnover, whichever is higher (thresholds cited in specialized regulatory analyses in 2026). Beyond financial fines, reputational damage and potential litigation over deceptive content represent significant risks.

What happens to systems already in production before 2026?

The AI Act timeline incorporates transitional windows and differentiated deadlines. Specifically, for certain content generation systems already on the market prior to August 2, 2026, an operational extension is indicated until December 2, 2026. Nevertheless, it is prudent to adapt disclosures and workflows immediately to prevent sudden operational disruptions.

What is the first practical step for an SME to achieve compliance?

The first step is conducting a baseline use-case inventory: which teams utilize generative tools, what outputs are produced, and where they are published. From there, implement two quick measures: standard disclosure templates for chatbots and synthetic media, and designate an internal owner to approve releases whenever transparency is legally required.