Regulation 4 min read

The EU AI Act applies from 2 August: what binds you now and what just got delayed

The AI Act reaches general application on 2 August 2026, but the digital omnibus delays high-risk duties to 2027. What your SMB must comply with now — and what can wait.

Two weeks from now, on 2 August 2026, the EU Artificial Intelligence Act reaches its general application date. And right now is when the noise is loudest: three weeks ago Brussels approved the “digital omnibus” that reshuffles the calendar, and you can find headlines claiming anything from “nothing applies anymore” to “million-euro fines in August”. Neither is true.

If your business uses AI — a chatbot on your website, tools that generate text or images, a SaaS that screens CVs — here is what actually applies to you, with every date checked against the official texts.

The calendar, after the omnibus

Regulation (EU) 2024/1689 has been in force since August 2024 and applies in stages. What changed this summer is one of those stages: the simplification package known as the digital omnibus — voted by the European Parliament on 16 June and adopted by the Council on 29 June 2026 — postpones the obligations for high-risk systems and keeps everything else in place.

This is the map as it stands:

ObligationApplies from
Prohibited practices and AI literacy (arts. 5 and 4)2 February 2025 — already in force
General-purpose AI models (GPAI)2 August 2025 — already in force
Transparency (art. 50): chatbots, generated content2 August 2026
”Stand-alone” high risk under Annex III (HR, credit, education…)2 December 2027 (previously: 2 August 2026)
High risk embedded in regulated products (Annex I)2 August 2028

What has bound you since 2025 (even if you didn’t know)

Two blocks have been applicable for over a year, and almost nobody has them on the radar:

  • Prohibited practices. Most sound remote for an SMB (social scoring, subliminal manipulation), but one hits close to home: using AI to infer your employees’ emotions at work is banned. If an HR or customer-service tool markets “emotion analysis” of your staff, that’s a problem, not a feature.
  • AI literacy (art. 4). If your team uses AI — even if it’s “just” ChatGPT to draft emails — you must ensure they use it with a sufficient level of understanding: what it does, what its risks are, what must never be pasted into it. It doesn’t require certificates; it requires proportionate training you can evidence.

What starts on 2 August: transparency

General application arrives with the transparency obligations of Article 50, the ones most SMBs actually touch day to day:

  • If your website has a chatbot, it must be clear to users that they are talking to an AI, unless it’s obvious. One line of interface copy solves most cases.
  • If you publish hyper-realistic content generated or manipulated with AI (“deepfakes”: images, audio or video that look real), you must disclose that it’s artificial. This applies to marketing campaigns too.
  • Providers of tools that generate synthetic content must mark it in a machine-readable way; systems already on the market before 2 August get a short extension, until 2 December 2026, for that marking.

From that same date, the Commission’s AI Office gains supervisory powers over large models, and in Spain AESIA — the supervision agency, headquartered in A Coruña — handles market surveillance, with the power to inspect and demand documentation.

What moves to 2027 (and why you shouldn’t ignore it)

The omnibus pushes the obligations for Annex III high-risk systems to 2 December 2027. For an SMB, the typical cases are not science fiction: software that screens CVs or scores candidates, systems that rate creditworthiness, assessment tools in training and education. If you use one as a deployer, your duties (human oversight, logs, following the provider’s instructions) move to that date too.

Two caveats matter. First: the postponement is a runway, not an amnesty — documentation and supplier contracts take months, not days. Second: the omnibus doesn’t only loosen; it also adds a new prohibition against generating non-consensual intimate imagery with AI.

The fines, in numbers

The Regulation’s own penalty regime sets the ceilings: up to €35 million or 7% of global turnover for prohibited practices, and up to €15 million or 3% for breaching most other obligations, transparency included. For SMEs and startups there is an explicit proportionality rule: the lower of the two amounts applies, not the higher.

Action plan before 2 August

  1. Inventory the AI you use. Include the SaaS with “AI features” nobody consciously signed up for: CRM, HR, support.
  2. Check your website’s chatbot. If it doesn’t identify itself as AI, add the notice. It’s the cheapest obligation to meet in the entire Regulation.
  3. Label generated content. Set a simple internal rule: what gets marked, with what wording, and who reviews it before publishing.
  4. Document basic training for the team using AI. Two well-spent hours cover Article 4 in most SMBs.
  5. Write to your vendors. If you use HR, credit or assessment tools, ask them in writing for their Annex III compliance calendar. Their answer tells you whether you have a supplier or a problem.

Our recommendation

Complying with the transparency layer today costs little: notices, labels and some training. Improvising it while AESIA asks questions will cost considerably more. And there’s an upside: putting your AI in order to comply is the same work as putting it in order to perform.

If you want to adopt AI properly — automations that comply by design, no hype —, this is how we work and here you can tell us about your case: we’ll tell you within 24 hours whether we can help and at what scope.

Guidance only — not legal or tax advice. Check deadlines and requirements against official sources before acting.

← Back to the blog

Shall we automate this for you?

We apply AI and automation to real processes: invoicing, customer support, operations. We start with one small, measurable case — and reply within 24 h.