Seven Labs
Book a CallContact Us
Back to all posts
August 4, 2026

EU AI Act August 2026: What's Actually Live vs What Just Got Delayed to 2027

EU AI Act August 2026: What's Actually Live vs What Just Got Delayed to 2027

Last updated: August 4, 2026

If you have been following EU AI Act news, you have probably seen headlines like "EU delays AI Act compliance deadline." Those headlines are technically true and practically misleading. The delay - moving Annex III high-risk system obligations from August 2026 to December 2027 - is one part of the regulation. The other parts are not delayed.

As of August 2, 2026, Article 50 transparency obligations and expanded GPAI (General Purpose AI) enforcement are live. If your product uses AI to interact with users, generates synthetic content, or builds on a foundation model, obligations apply to you right now. This post is the compliance calendar you actually need.

What Is Actually In Force Right Now Under the EU AI Act?

As of August 2, 2026, Article 50 transparency obligations and GPAI compliance requirements under Chapter V are in full effect. This means AI systems that interact with users must disclose the AI nature of the interaction, synthetic content must be machine-detectable, and organisations deploying general-purpose AI models above certain capability thresholds must meet documentation, evaluation, and incident reporting requirements. The Annex III high-risk delay does not affect these provisions.

The EU AI Act Compliance Calendar: Everything by Deadline

DeadlineWhat became enforceableDelayed?
February 2, 2025Prohibited practices (Article 5): social scoring, subliminal manipulation, real-time biometric surveillance in public spacesNo - LIVE
February 2, 2025AI literacy obligations (Article 4): organisations must ensure staff operating AI have sufficient knowledgeNo - LIVE
August 2, 2025GPAI rules (Chapter V): documentation, evaluation, copyright transparency for foundation model providersNo - LIVE
August 2, 2025National competent authorities established in member statesNo - LIVE
August 2, 2026Article 50 transparency obligations: AI interaction disclosure, synthetic content watermarking technical standardsNo - LIVE NOW
August 2, 2026GPAI enforcement expanded: systemic-risk GPAI models face adversarial testing requirementsNo - LIVE NOW
December 2, 2026Watermarking technical standards operationalised (machine-readable synthetic content detection)Partial - standards still being finalised
December 2, 2027Annex III high-risk AI systems (recruitment, credit, education, healthcare, law enforcement, critical infrastructure)YES - delayed by Digital Omnibus
August 2, 2028Annex I product-embedded AI systems (machinery, medical devices, aviation, automotive)YES - delayed

The Digital Omnibus amendment - the legislative package that moved Annex III to December 2027 - was motivated by implementation readiness concerns from national regulators and the industry. It does not alter the provisions above it in the calendar.

What Are the Article 50 Transparency Obligations (Live Now)?

Article 50 transparency obligations require AI systems that interact with natural persons to disclose the AI nature of that interaction in a clear and timely manner, unless the context makes this obvious. AI-generated audio, video, image, and text content must be marked with machine-readable signals that allow detection of synthetic origin.

Specifically, as of August 2, 2026:

  • Chatbots and AI assistants must disclose they are AI at the start of the interaction, unless the user has explicitly set up a roleplay context
  • Synthetic media - AI-generated images, video, and audio - must carry machine-detectable watermarks or metadata under Article 50(2) and (4)
  • Emotion recognition and biometric categorisation systems must disclose their operation to subjects, with limited exceptions

Penalties for Article 50 non-compliance fall under Article 99: up to €15 million or 3% of global annual turnover, whichever is higher, for operators; €7.5 million or 1.5% for providers of general-purpose AI systems.

What Does GPAI Compliance Require Right Now?

GPAI compliance under Chapter V requires foundation model providers and organisations deploying models above the 10^25 FLOP training-compute threshold to maintain and publish technical documentation, conduct adversarial testing and red-teaming evaluations, and report serious incidents to the European AI Office. Providers of systemic-risk GPAI models additionally face cybersecurity requirements and energy efficiency reporting.

Key obligations for organisations deploying third-party GPAI models (not just building them):

  1. Use-case disclosure to providers. If you are using a GPAI model for a high-risk application, you must inform the model provider of the deployment context.
  2. Due diligence on the model's compliance documentation. You cannot disclaim responsibility by pointing to the model provider.
  3. Incident reporting. Serious incidents involving GPAI systems must be reported to national competent authorities.

What Are the Prohibited Practices That Have Been Enforceable Since February 2025?

Article 5 prohibited practices have been enforceable since February 2, 2025. These are the hard lines - not obligations to comply with, but things that cannot be done regardless of technical capability:

  • Social scoring by public authorities or anyone acting on their behalf - rating natural persons based on social behaviour with detrimental effects
  • Subliminal manipulation - AI that exploits subconscious vulnerabilities to alter behaviour in ways that cause harm
  • Exploiting vulnerabilities of protected groups - targeting elderly, disabled, or economically disadvantaged people
  • Real-time remote biometric identification in public spaces by law enforcement, with narrow exceptions
  • Emotion inference in workplace and educational settings - with narrow exceptions for safety systems
  • Predictive policing based solely on profiling without individual-level justification
  • Untargeted scraping of facial images from the internet or CCTV to build recognition databases

If your product touches any of these categories, the prohibition has been active for eighteen months. There is no transitional period.

What Got Delayed and Until When?

The December 2027 delay applies specifically to Annex III high-risk AI systems - systems used in:

  • Recruitment and HR decisions (CV screening, interview evaluation, promotion allocation)
  • Credit scoring and access to financial services
  • Educational admission, assessment, and monitoring
  • Healthcare diagnostic systems
  • Law enforcement biometric and profiling systems
  • Critical infrastructure management
  • Migration, asylum, and border control
  • Administration of justice

The delay was introduced through the Digital Omnibus legislative package and is intended to give organisations in these sectors additional time to build conformity assessment processes, technical documentation, and risk management systems to the required standard.

What the delay does not mean: organisations building Annex III systems are not exempted - they are given more runway to achieve compliance. The European AI Office has been clear that organisations should use this period to build compliance infrastructure, not to defer it.

The August 2028 deadline applies to Annex I product-embedded AI - AI components in regulated consumer products like medical devices, machinery, and automotive systems where existing product-safety frameworks need alignment with the AI Act's risk classification.

What SaaS and AI Companies Should Actually Do Right Now

If your product uses AI in any form that users interact with, here is the prioritised compliance checklist for August 2026:

  1. Audit Article 50 exposure. Does any AI system in your product interact with end users? If yes, disclosure requirements are live.
  2. Implement interaction disclosure. Add clear AI disclosure at session start for chatbots, assistants, and AI-generated content. This does not need to be intrusive - it needs to be present.
  3. Assess synthetic content output. If your product generates images, audio, or video using AI, you need a plan for machine-readable watermarking. The technical standards are still being finalised, but building metadata into your generation pipeline now is the safe path.
  4. Document your GPAI model use. If you are deploying GPT-4o, Claude, Gemini, Llama 3, or equivalent models: document the use case, the model version, the capability scope, and your incident response process.
  5. Confirm your incident reporting chain. Identify your national competent authority. Know the reporting threshold and timeline for your jurisdiction.
  6. Check the prohibited practices list against your product roadmap. If anything in your pipeline touches the Article 5 categories, that is an immediate legal stop, not a compliance planning item.
  7. Brief your AI literacy programme. Article 4 AI literacy obligations have been live since February 2025. Any staff who operate AI systems must have documented, sufficient understanding of the technology.

Our VAPT and security compliance work intersects directly with AI Act technical requirements, particularly for organisations where AI components are embedded in security-adjacent systems. See also our banking and LLM deployment guidance for sector-specific compliance architecture.

Is "We Will Comply When It Is Required" a Safe Strategy?

No. For the provisions that are already live - Article 5 prohibitions (February 2025), GPAI Chapter V (August 2025), and Article 50 transparency (August 2, 2026) - this is not a planning question, it is an enforcement question. National competent authorities are operational in all EU member states. Penalties are active. The transitional window for these provisions has closed.

For Annex III high-risk systems delayed to December 2027, the strategy of waiting until 2027 to begin conformity assessment work is structurally dangerous. Third-party conformity assessment, technical documentation, and risk management system implementation take twelve to eighteen months for complex systems. Organisations that start in early 2027 will not be ready by December 2027.

The companies that come out of the EU AI Act compliance cycle in the strongest position are the ones who used the Annex III delay to build robust compliance infrastructure - not to delay engagement with the regulation.


Seven Labs supports AI product teams with compliance-aware architecture, security assessment, and GPAI documentation frameworks. If you are assessing EU AI Act exposure for your product, start with a scoped conversation with our team.


<script type="application/ld+json"> { "@context": "https://schema.org", "@graph": [ { "@type": "Article", "@id": "https://www.sevenlabs.site/blogs/eu-ai-act-august-2026-whats-live-vs-delayed#article", "headline": "EU AI Act August 2026: What's Actually Live vs What Just Got Delayed to 2027", "description": "Article 50 transparency obligations and GPAI compliance requirements are live now as of August 2, 2026. The delay to December 2027 applies only to Annex III high-risk systems. The full EU AI Act compliance calendar.", "datePublished": "2026-08-04", "dateModified": "2026-08-04", "author": { "@type": "Organization", "name": "Seven Labs", "url": "https://www.sevenlabs.site" }, "publisher": { "@type": "Organization", "name": "Seven Labs", "logo": { "@type": "ImageObject", "url": "https://res.cloudinary.com/dywx7ldqr/image/upload/v1779223334/media/img_01.png" } }, "mainEntityOfPage": { "@type": "WebPage", "@id": "https://www.sevenlabs.site/blogs/eu-ai-act-august-2026-whats-live-vs-delayed" }, "keywords": ["EU AI Act", "Article 50", "GPAI compliance", "Annex III", "AI regulation 2026", "Digital Omnibus", "AI transparency obligations"], "articleSection": "AI Compliance & Regulation" }, { "@type": "FAQPage", "mainEntity": [ { "@type": "Question", "name": "What is actually in force right now under the EU AI Act?", "acceptedAnswer": { "@type": "Answer", "text": "As of August 2, 2026, Article 50 transparency obligations and GPAI compliance requirements under Chapter V are in full effect. AI systems that interact with users must disclose the AI nature of the interaction, synthetic content must be machine-detectable, and organisations deploying GPAI models above capability thresholds must meet documentation and incident reporting requirements." } }, { "@type": "Question", "name": "What are the Article 50 transparency obligations now live?", "acceptedAnswer": { "@type": "Answer", "text": "From August 2, 2026: chatbots and AI assistants must disclose their AI nature at interaction start; AI-generated images, video, and audio must carry machine-detectable watermarks; emotion recognition and biometric categorisation systems must disclose their operation to subjects. Penalties reach €15 million or 3% of global annual turnover." } }, { "@type": "Question", "name": "What got delayed in the EU AI Act and until when?", "acceptedAnswer": { "@type": "Answer", "text": "The Digital Omnibus amendment delayed Annex III high-risk AI system obligations from August 2026 to December 2027. Annex III covers AI used in recruitment, credit scoring, education, healthcare diagnostics, law enforcement, and critical infrastructure. Annex I product-embedded AI (medical devices, automotive, machinery) is delayed to August 2028." } }, { "@type": "Question", "name": "Is 'we will comply when it is required' a safe EU AI Act strategy?", "acceptedAnswer": { "@type": "Answer", "text": "No. Article 5 prohibitions (February 2025), GPAI Chapter V (August 2025), and Article 50 transparency (August 2, 2026) are already enforceable - the window has closed. For Annex III delayed to December 2027, conformity assessment and documentation work takes 12-18 months. Starting in early 2027 will not achieve readiness by December 2027." } }, { "@type": "Question", "name": "What EU AI Act obligations apply to SaaS companies right now?", "acceptedAnswer": { "@type": "Answer", "text": "SaaS companies with AI-facing features must: implement Article 50 interaction disclosure for AI chatbots and assistants; plan synthetic content watermarking; document all GPAI model deployments with use-case and incident response chains; comply with Article 5 prohibitions (no social scoring, subliminal manipulation, or prohibited biometric practices); and run AI literacy programmes for staff operating AI systems." } } ] } ] } </script>
Loading...

Read Next

Advanced RAG Chunking Strategies: The Definite Guide

Implementing Advanced RAG Chunking Strategies separates production-grade LLM applications from fragi...

Read article

Why Your Gulf Enterprise AI Agency is Selling You a Chatbot (And What You Actually Need)

Most firms hire a Gulf enterprise AI agency for a chatbot, but actually need production-grade infras...

Read article
Chat with us
Book a Call
Free · 30 min · No commitment

Book a Strategy Call

30 minutes. No sales pitch. We scope your project and tell you honestly if we're the right fit.