The EU AI Act became enforceable on August 2, 2026. That much is accurate in most of the coverage published this month. What most of it gets wrong is what "enforceable" actually covers.
A lot of content published in the last few weeks describes high-risk AI obligations, hiring tools, credit scoring, biometric identification, as if they hit their deadline on August 2. They didn't. The Digital Omnibus on AI, signed into law as Regulation 2026/1744 on July 27, pushed that deadline to December 2, 2027. What did go live on August 2 is a narrower, but immediately binding, set of transparency rules. Conflating the two leads to either false urgency or false comfort, depending on which stale article someone reads first.
Here's the current state, as of this month.
What Changed on August 2, 2026
Three things became enforceable simultaneously, confirmed directly by the European Commission's AI Office:
Article 50 transparency obligations. Any chatbot, voice agent, or interactive AI system deployed to EU users now has to disclose at the start of an interaction that the user is dealing with AI, not a person. AI-generated or altered content, including deepfakes, now has to carry machine-readable labels. This applies regardless of where the deploying company is based, as long as EU residents are the end users. More than 180 organizations have already signed the Code of Practice that operationalizes these rules.
GPAI enforcement powers. The AI Office can now issue fines against general-purpose AI model providers, and those fines apply retroactively to August 2025, when GPAI obligations first took effect. The eight foundation models above the 10^25 FLOPs compute threshold have been submitting systemic risk evaluations for a year. The difference now is the Commission can actually penalize non-compliance.
Prohibited practices at full penalty. Social scoring, manipulative AI, and exploitative AI targeting vulnerabilities were banned starting in February 2025. As of August 2, those bans carry the maximum penalty tier: up to €35 million or 7% of global annual turnover. GPAI violations top out lower, at €15 million or 3%.
What the Digital Omnibus Delayed
The Digital Omnibus was a genuine concession to industry, and a reasonable one. The original conformity assessment regime for high-risk systems was widely seen as unworkable on the original timeline, particularly for smaller AI vendors. The deferral applies specifically to:
- Standalone high-risk AI systems under Annex III (employment, credit scoring, law enforcement, biometric ID, healthcare): deferred from August 2, 2026 to December 2, 2027
- High-risk AI embedded in regulated products under Annex I: deferred to August 2, 2028
- Article 50(2) transparency requirements for legacy systems already on the market: apply from December 2, 2026
What didn't move: the core Article 50 disclosure rules, the AI literacy duty under Article 4, and the prohibited-practices regime. The relief is real and substantial for the heaviest part of the compliance burden. It is also narrow. Most organizations reading "the AI Act deadline was delayed" and closing the tab are making a mistake, just a different mistake than the ones reading "the deadline hit and we're all exposed."
The Obligation Hiding in Plain Sight
Here's the part most coverage of this deadline skips entirely: you can't comply with Article 50 disclosure requirements for AI systems you don't know are running.
That sounds obvious stated directly, and it's still where most enterprises are exposed today, deadline extension or not. Industry surveys this year put visibility into employee AI tool usage at somewhere between 25% and 30% across enterprises. The gap isn't primarily about sanctioned enterprise deployments, it's about the AI tools employees are already using without IT's knowledge: personal ChatGPT and Claude accounts, browser extensions, AI features embedded in SaaS tools nobody inventoried. None of that shows up in a compliance program built around the systems a company officially deployed.
That's a problem regardless of where an organization sits on the high-risk timeline. If an employee is using an unsanctioned AI chatbot to interact with EU customers, and that chatbot doesn't disclose it's AI, the fact that the company's own sanctioned high-risk systems have until 2027 doesn't help. The disclosure obligation still applies. The company just doesn't know it's exposed, because it doesn't know the interaction happened.
This is the actual sequencing problem for AI governance teams right now: documentation and disclosure obligations that are live today assume a level of AI usage visibility that most enterprises don't have. Building that visibility isn't a 2027 project tied to conformity assessments. It's foundational to obligations that already carry penalties.
Where This Leaves Governance Teams
A few things are true at the same time, and worth holding separately rather than collapsing into one deadline:
- If your organization deploys AI that interacts with EU users or employees, Article 50 disclosure and content-labeling obligations apply now, not in 2027.
- If you're building toward high-risk conformity assessment for Annex III systems, you have a genuine 16-month extension, use it, but don't mistake it for a pause on AI governance generally.
- Neither of the above is achievable without an accurate, current inventory of what AI systems, sanctioned and unsanctioned, are actually touching your data and your users. That inventory work doesn't get easier by waiting.
The enforcement architecture the EU built here rewards exactly this kind of clarity. The AI Office has said its opening move is "technical compliance dialogues" rather than immediate formal proceedings, and companies that can document good-faith compliance efforts and active AI governance are in a materially better position than those that can't show the work. A verifiable, timestamped record of what AI interactions actually happened, on what platform, isn't just useful for audit prep. It's the evidentiary foundation the dialogue-first enforcement model is built around.
This is the same reason we built Receipts the way we did: not as another detection layer trying to infer AI usage after the fact, but as a direct, cryptographically verifiable record of AI interactions as they happen, across the platforms employees are actually using. Detection tools tell you AI use is probably happening somewhere. A provable record tells you what happened, when, and where. For an enforcement regime that's explicitly asking companies to "show the work," that distinction is the whole point.
FAQ
What changed under the EU AI Act on August 2, 2026? Article 50 transparency obligations (AI disclosure, deepfake and AI-content labeling), GPAI provider enforcement powers, and full penalties for prohibited AI practices all became enforceable.
Did the EU AI Act's high-risk AI deadline get delayed? Yes. The Digital Omnibus on AI, in force since July 27, 2026, deferred standalone high-risk (Annex III) obligations to December 2, 2027, and high-risk AI embedded in regulated products (Annex I) to August 2, 2028.
Do chatbots have to disclose they're AI under the EU AI Act? Yes, as of August 2, 2026, under Article 50. Any AI-powered chatbot or interactive system serving EU users must clearly disclose that at the start of the interaction.
Does the high-risk deadline extension mean AI governance can wait until 2027? No. Article 50 disclosure and labeling obligations are enforceable now, and they apply to every AI system interacting with EU users, sanctioned or not, high-risk or not.
What is shadow AI, and why does it matter for EU AI Act compliance? Shadow AI is employee use of AI tools without IT's knowledge or approval. It matters because disclosure and documentation obligations that are already enforceable assume visibility into AI usage that most enterprises don't currently have.
