The EU AI Act in 2026: what's already in force and what comes next
The EU AI Act in 2026: what's already in force and what comes next

TLDR
→ The EU AI Act has been in force since August 2024. Prohibited practices are enforceable since February 2025. GPAI model obligations have been in force since August 2025. → August 2, 2026 activates three things simultaneously: GPAI penalty enforcement powers, Article 50 transparency obligations for customer-facing AI agents, and full market surveillance authority for national regulators. → The Article 50 transparency requirement is the most immediately operational for most enterprises: any AI system interacting with EU users must disclose at the first moment of interaction that it is an AI. This applies from August 2, 2026. → A May 7, 2026 provisional agreement on the Digital Omnibus deferred high-risk Annex III obligations from August 2, 2026 to December 2, 2027. This does not affect GPAI penalties or the August 2026 transparency requirements. → The compliance gap is real: most organizations lack systematic inventories of their AI systems. The three immediate priorities are completing an AI inventory, classifying systems against the risk tiers, and implementing August 2026 transparency requirements for customer-facing agents. Updated on 6th July 2026
The EU AI Act entered into force in August 2024. Two years on, the regulatory picture has changed significantly. Several provisions are already in force. A landmark deal in May 2026 reshaped the high-risk AI timeline. And August 2, 2026, still weeks away at the time of writing, is a genuinely consequential enforcement date for most enterprises deploying AI in or into the EU market.
This article sets out what is in force now, what changes on August 2, 2026, what the May 2026 Digital Omnibus deal means for high-risk AI timelines, and what enterprise leaders should be doing to prepare.
What is already in force
The EU AI Act entered into force on August 1, 2024. Prohibited practices and AI literacy obligations took effect on February 2, 2025. Governance rules and obligations for providers of General Purpose AI (GPAI) models became applicable on August 2, 2025.
This means that as of today, three tiers of obligation are already operative:
Prohibited practices (in force since February 2025): Eight categories of AI use are banned outright under Article 5. These include AI systems that manipulate human behavior to circumvent free will, social scoring systems, real-time remote biometric identification for law enforcement in public spaces, emotion recognition in workplaces and educational institutions, and biometric categorization used to infer protected characteristics. Any enterprise operating AI systems in these categories was required to cease that use from February 2025.
GPAI model obligations (in force since August 2025): Providers of General Purpose AI models — the foundation models and large language models that underpin most enterprise AI deployments — have been subject to documentation, transparency, and systemic risk assessment obligations since August 2025. Starting August 2, 2026, the Commission can impose fines for GPAI non-compliance. The maximum penalty is €15 million or 3% of global annual turnover, whichever is higher.
What changes on August 2, 2026
August 2, 2026 is the most consequential single date remaining in the Act's calendar. Three separate enforcement mechanisms activate simultaneously.
GPAI penalty enforcement. The Commission gains full penalty powers over GPAI model providers from August 2, 2026. The AI Office — the Commission body with exclusive competence over GPAI models — has full investigatory authority from that date, including documentation requests, model access, on-site inspections, and corrective measures.
Article 50 transparency obligations. Any AI system designed to interact with natural persons must inform those persons that they are interacting with an AI at the first moment of interaction. AI systems that detect emotions or categorize users based on biometric data must notify users at the time of operation. AI systems placed on the EU market from August 2, 2026 onward that generate or manipulate synthetic audio, image, or video must embed machine-readable markers identifying outputs as AI-generated.
Market surveillance authority. National market surveillance authorities gain full investigatory and sanctioning powers from August 2, 2026.
For enterprises deploying customer-facing AI agents in EU markets, the Article 50 transparency obligations are the most immediately operational requirement. Any chatbot, virtual assistant, or AI support agent that interacts with customers in the EU must disclose that it is an AI at the start of the interaction. This applies from August 2, 2026 regardless of where the deploying organization is headquartered.
What the May 2026 Digital Omnibus deal means for high-risk AI
The most significant recent development is the May 7, 2026 political agreement on the Digital Omnibus on AI. EU lawmakers reached provisional agreement deferring the high-risk compliance deadline — originally set for August 2, 2026 — to December 2, 2027 for new or substantially modified high-risk AI systems listed in Annex III.
Annex III high-risk systems include AI used in employment decisions (recruitment, performance evaluation, task allocation, worker monitoring, promotion, and termination), credit scoring, educational access, and border management. For enterprises using AI in HR, recruitment, or performance management contexts, this extension provides additional preparation time.
However, several important caveats apply. The Omnibus is a provisional agreement pending formal adoption, expected in July 2026. Enterprises should treat December 2, 2027 as the planning anchor for high-risk Annex III obligations while monitoring formal adoption. The extension does not affect GPAI model obligations or the August 2, 2026 transparency requirements, both of which remain on their original timeline.
The risk-based framework and what it means for enterprise AI
The EU AI Act's core structure categorizes AI systems by risk level, with obligations scaling accordingly.
Prohibited systems face an outright ban on specific use cases as described above.
High-risk systems in Annex III categories face the most extensive obligations: conformity assessments, technical documentation, data governance requirements, human oversight mechanisms, and registration in the EU AI database. The December 2, 2027 deadline applies to new or substantially modified Annex III systems.
Limited-risk systems — which includes most enterprise AI agents, including customer-facing chatbots and internal productivity copilots — face primarily transparency obligations. The requirement to disclose that users are interacting with an AI at the first moment of interaction is the primary obligation for this category, activating August 2, 2026.
Minimal-risk systems — recommendation engines, spam filters, AI-assisted search — face no mandatory obligations.
The practical question for most enterprise leaders is not whether they have prohibited or minimal-risk AI. It is whether their customer-facing agents and internal copilots fall into the limited-risk category requiring transparency disclosures, or whether any of their AI systems touch Annex III high-risk categories.
What enterprises should be doing now
The compliance gap is real. Analysis of enterprise readiness consistently finds that most organizations lack systematic inventories of the AI systems they have in production, which makes risk classification and compliance planning impossible.
Three actions are immediately practical regardless of where an organization sits in the compliance cycle.
Complete an AI system inventory. Document every AI system in production or development that touches EU users or operates in the EU market. For each system: what does it do, what data does it process, what decisions does it affect, and who uses it. This inventory is the foundation of all classification and compliance work.
Classify against the risk tiers. Map each inventoried system against the Act's risk categories. Most enterprise AI deployments will fall into limited-risk (requiring transparency disclosures) or minimal-risk (no mandatory obligations). The systems that require careful assessment are those touching Annex III categories: recruitment and HR decisions, credit assessment, and systems making decisions about access to essential services.
Implement August 2026 transparency requirements now. For any customer-facing AI agent interacting with EU users, the disclosure requirement activates August 2, 2026. This is a concrete, immediately actionable requirement that does not require a conformity assessment or technical documentation — it requires the agent to inform users at the start of an interaction that they are talking to an AI. If this is not already in place, it should be implemented before August 2, 2026.
Nebuly
Nebuly is the ROI platform for enterprise AI. It connects to the AI agents your business runs on, the assistants your customers interact with, and the tools your employees use every day, including Claude, ChatGPT, and Copilot, and translates that activity into business value. How much time is being saved across teams. What revenue your AI is influencing. What adoption and AI proficiency look like in practice, across departments and geographies. All aggregated at the organizational level, never tied to individuals.
Nebuly supports self-hosted deployment on AWS, Azure, and GCP, keeping all interaction data within your own infrastructure. It meets SOC 2 Type II, ISO 27001, and ISO 42001 standards.
If you need clarity on what your AI investment is actually delivering, book a demo.
FAQs
What EU AI Act obligations are already in force in 2026?
As of mid-2026, two waves of EU AI Act obligations are already operative. The first, in force since February 2025, covers prohibited AI practices under Article 5 — eight categories of AI use that are banned outright, including emotion recognition in workplaces, social scoring, and real-time biometric identification for law enforcement in public spaces. The second, in force since August 2025, covers GPAI model providers — the foundation models and large language models underpinning enterprise AI. GPAI providers have been subject to documentation, transparency, and systemic risk assessment obligations since August 2025.
What happens on August 2, 2026?
Three enforcement mechanisms activate on August 2, 2026. The Commission gains penalty powers over GPAI model providers, with maximum fines of €15 million or 3% of global annual turnover. Article 50 transparency obligations take effect, requiring AI systems that interact with natural persons to disclose at the start of the interaction that they are an AI — this applies to customer-facing chatbots, virtual assistants, and AI support agents deployed in EU markets. National market surveillance authorities gain full investigatory and sanctioning powers. For most enterprises, the Article 50 transparency requirement is the most immediately actionable deadline.
What did the May 2026 Digital Omnibus deal change?
The May 7, 2026 provisional agreement on the Digital Omnibus deferred the high-risk Annex III compliance deadline from August 2, 2026 to December 2, 2027 for new or substantially modified high-risk AI systems. Annex III systems include AI used in employment decisions, credit scoring, educational access, and border management. The extension provides enterprises using AI in HR, recruitment, and performance management with approximately 16 additional months to prepare. The deal does not affect GPAI model obligations or August 2026 transparency requirements, which remain on their original timeline.
Which enterprises are most affected by the EU AI Act?
The Act applies to any organization that develops, deploys, or uses AI systems within the EU, or whose AI systems are used within the EU market, regardless of where the organization is headquartered. The most immediately affected enterprises are those deploying customer-facing AI agents in EU markets (Article 50 transparency requirements activate August 2, 2026), those providing or deploying GPAI models (penalty enforcement from August 2, 2026), and those whose AI systems touch Annex III high-risk categories including HR decisions, credit assessment, and access to essential services.
What should enterprise leaders be doing right now to prepare?
Three actions are immediately practical. First, complete a systematic AI system inventory documenting every AI system in production that touches EU users or operates in EU markets. Without this inventory, risk classification is impossible. Second, classify each system against the Act's risk tiers to identify which require conformity assessments (Annex III), which require transparency disclosures only (limited-risk), and which face no mandatory obligations (minimal-risk). Third, implement the Article 50 disclosure requirement for any customer-facing AI agent interacting with EU users before August 2, 2026 — this requires no conformity assessment, only a disclosure at the start of each interaction that the user is interacting with an AI.


Stay up to date on what we're learning, building, and seeing as enterprise teams deploy and measure AI agents in production.



