If you've read three different explainers of the EU AI Act's "August 2026 deadline" and come away with three different pictures of what actually happens on that date, you're not alone — and as of five days ago, the picture genuinely changed. The Digital Omnibus on AI entered into force on July 27, 2026, deferring a large chunk of the Act's high-risk-system deadlines by well over a year. But two other deadlines on the same August 2, 2026 date did not move. Here's what's actually true as of today, sourced against the Act's own text and the Omnibus's entry into force.
The date confusion, resolved
The single error worth killing first: General-Purpose AI (GPAI) obligations did not start on August 2, 2026. They started a full year earlier, on August 2, 2025 — model documentation, copyright-policy summaries, and systemic-risk assessment requirements for models trained above the 10^25 FLOPs threshold have applied since then. What changes on August 2, 2026 is enforcement: the European Commission's AI Office gains the actual power to request documentation, run technical evaluations, demand risk-mitigation measures, restrict or withdraw a model from the EU market, and issue fines against GPAI providers who have been out of compliance with rules that were already binding. The obligations existed for a year with no enforcement teeth; from August 2, 2026, they have them.
What holds on August 2, 2026
Two things are confirmed to take effect on schedule, unmoved by the Omnibus:
GPAI enforcement (Article 101). Fines of up to 3% of global annual turnover or €15 million, whichever is higher, for GPAI providers found non-compliant with obligations that have applied since August 2025.
Article 50 transparency obligations. These apply well beyond GPAI providers, to any organization deploying AI systems that interact directly with people, including a customer-facing chatbot with no high-risk classification at all. The requirements: disclose to users that they're interacting with an AI system; disclose deepfake content to viewers on first exposure, clearly and distinguishably; and mark generative-AI outputs with machine-readable, interoperable marks that let the content be identified as AI-generated. Scope is defined by the content and the user's location, not the provider's headquarters — a UK or US company serving EU users is in scope regardless of where it's incorporated.
What just moved (the Digital Omnibus)
The Digital Omnibus on AI cleared its full legislative path faster than most compliance content anticipated: European Parliament endorsement on June 16, 2026, Council of the EU final approval on June 29, 2026, and entry into force on July 27, 2026 — five days before the August 2 deadline it partly reshapes. Its effect on high-risk AI obligations:
| High-risk category | Original deadline | New deadline under the Omnibus |
|---|---|---|
| Stand-alone Annex III systems (recruitment screening, credit scoring, law-enforcement decision support, border control) | August 2, 2026 | December 2, 2027 (~16-month deferral) |
| AI embedded in regulated products (Annex I — machinery, medical devices, etc.) | August 2, 2027 | August 2, 2028 |
| GPAI enforcement (Article 101) | August 2, 2026 | Unchanged |
| Article 50 transparency obligations | August 2, 2026 | Unchanged |
The Omnibus also added, rather than removed, a prohibition: coverage indicates AI "nudifier" apps face a ban effective this December.
Penalty tiers, and why they're not one number
Two separate penalty ceilings apply depending on what's violated, and compliance content regularly conflates them: Article 101 caps GPAI-specific breaches at €15 million or 3% of global turnover, whichever is higher; Article 99 covers broader AI Act violations — prohibited-practice deployment, other systemic breaches — at a higher ceiling of €35 million or 7%. Both are statutory maximums, not typical or expected fines, and no confirmed first-enforcement case exists as of this writing under either article.
A practical checklist, given where things actually stand
- If you provide a GPAI model above the systemic-risk threshold: your documentation and risk-assessment obligations have applied since August 2025 — August 2, 2026 is when non-compliance becomes actionable, not when the paperwork starts.
- If you deploy any user-facing chatbot, AI agent, or generative content tool, EU users or not headquartered in the EU: check Article 50 specifically, separate from whether you have any high-risk AI system at all — this obligation is scoped to the interaction, not to a risk tier.
- If you build or deploy a stand-alone high-risk Annex III system: your compliance deadline just moved to December 2, 2027 — real relief, but not indefinite, and worth confirming against the Omnibus's final published text rather than pre-Omnibus explainers still circulating.
- Don't extrapolate a specific fine amount from the statutory ceilings — €15M and €35M are caps, and there is no enforcement track record yet to calibrate against.
Sources: artificialintelligenceact.eu on Chapter V enforcement, artificialintelligenceact.eu on Article 50, European Commission digital-strategy FAQ on Article 50, AI Act Service Desk, Article 50 text, Gibson Dunn on the Omnibus agreement, DLA Piper GENIE on the Digital Omnibus deferral, ComplianceHub.Wiki on what moved and what didn't, Tech Times on the Omnibus entering into force.
