AI Act: what actually applies since 2 August 2026
2 August 2026 was the big milestone of the EU AI Act – but it brings something different from what many expected. What applies now, what already applied, and what was postponed:
New since 2 August: transparency
Now applicable are, in particular, the transparency duties of Art 50 AI Act: anyone deploying a chatbot or other AI system in customer contact must disclose that users are interacting with a machine – unless that is obvious. AI-generated or manipulated content, especially deepfakes, must be labelled. Violations carry substantial fines.
In force for a while already
Since February 2025, the prohibitions of certain practices – such as manipulative techniques and social scoring – have applied, as has the duty to ensure adequate AI literacy among your own staff. Anyone using AI tools in their business has long needed an internal policy and training.
Postponed: the high-risk obligations
The extensive obligations for high-risk systems – such as AI in recruitment or credit scoring – were pushed back at EU level: for standalone systems under Annex III to the end of 2027, for AI embedded in products even later. Anyone deploying or planning such systems gains time, but should use it – the requirements on data quality, documentation and human oversight are considerable.
In practice
For most companies the task list is manageable: implement the chatbot notice and labelling of AI-generated content, update the internal AI policy, document training – and use the transition period to prepare for any planned high-risk applications. Alongside all this, the GDPR applies unchanged: it remains the stricter yardstick as soon as personal data flows into AI systems.
This information is general in nature and does not replace legal advice on an individual case.