AI Act: August 2 Has Passed, But Not in the Way Everyone Predicted
For the past two years, August 2, 2026 was presented as the AI industry’s “day of reckoning.”
The date when the European Union’s AI Act would move from theory to real-world enforcement, bringing mandatory compliance for high-risk AI systems, strict obligations, and potentially massive fines.
Headlines warned businesses to prepare. Consultants sold compliance packages with countdown timers. Webinars promised last-minute guidance before the deadline.
Then, just nine days before that date, the European legislator changed the timeline.
Regulation (EU) 2026/1744, commonly referred to as the AI Digital Omnibus, was published in the Official Journal on July 24 and entered into force on July 27.
The result?
August 2 arrived.
But with very different consequences from the ones most people expected.
Understanding what actually changed matters—not as a legal exercise, but because two equally misleading narratives are currently circulating, and both can lead businesses to make poor decisions.
The First Misconception: “Everything Took Effect”
Many articles still claim that all obligations relating to high-risk AI systems became applicable on August 2.
That simply isn’t true.
The Chapter III provisions governing high-risk AI systems have been postponed.
Standalone high-risk systems listed in Annex III—including AI used for recruitment, credit scoring, education, biometric identification, law enforcement, migration, and justice—will now become applicable on December 2, 2027.
High-risk AI that forms part of regulated products under Annex I has been postponed even further, until August 2, 2028.
That represents a delay of sixteen months in one case and two years in the other.
The Omnibus also narrowed the definition of a safety component.
Only AI systems intended to prevent or mitigate health and safety risks now fall within that category.
In practice, many software tools that companies had cautiously assumed were high-risk no longer fall into that category.
The Second Misconception: “Nothing Changed”
This interpretation may be comforting—but it’s equally incorrect.
August 2, 2026 remains the general application date for significant portions of the AI Act.
Two major areas are now fully operational.
The first is Article 50, which establishes the AI transparency obligations.
The European Commission has confirmed these requirements apply regardless of the Digital Omnibus postponements.
The second concerns the Act’s governance and enforcement framework.
Market surveillance, post-market monitoring, information-sharing obligations, and the powers granted to national authorities are now fully operational.
Member States must designate competent authorities and establish at least one AI regulatory sandbox.
One important clarification often gets overlooked.
The sanctions framework itself did not begin on August 2, 2026.
Chapter XII has applied since August 2, 2025.
What changed this year is that the enforcement machinery behind those rules is now operational.
The AI Act has moved from existing on paper to becoming actively enforceable.
In Italy, those authorities are already in place.
Law No. 132/2025 designated AgID and the National Cybersecurity Agency (ACN) as the competent authorities.
AgID oversees conformity assessment and accreditation.
ACN is responsible for supervision, inspections, cybersecurity oversight, and enforcement.
Importantly, these authorities operate separately from Italy’s Data Protection Authority under the GDPR.
Who Article 50 Actually Applies To
One of the biggest sources of confusion is that Article 50 contains four different obligations, divided between two different actors.
AI Providers
Providers—the companies placing AI systems on the market—must ensure that systems interacting directly with people clearly disclose that users are communicating with artificial intelligence.
They must also apply machine-readable markings to AI-generated synthetic content.
AI Deployers
Deployers—the organizations using AI under their own authority—have separate obligations.
These are the ones most businesses need to pay attention to.
First, organizations using emotion recognition or biometric categorization systems must inform the people affected.
Second, deployers must disclose deepfakes.
This includes AI-generated or AI-manipulated images, videos, or audio that resemble real people, places, events, or objects and could reasonably appear authentic.
Organizations must also disclose AI-generated or AI-manipulated texts published on matters of public interest whenever those texts are released without meaningful human review or editorial oversight.
Think about what that includes:
- promotional videos using cloned voices;
- AI-generated spokespeople;
- synthetic versions of real individuals;
- news-style articles published directly from an AI model without human editing.
These situations now fall within Article 50.
Another important point: outsourcing does not transfer legal responsibility.
If an agency or freelancer creates AI content on behalf of your company, your organization generally remains the deployer under the AI Act.
Contracts may allocate responsibilities internally, but they do not shift legal accountability.
The Exceptions Exist—but They’re Limited
Disclosure that users are interacting with AI isn’t required when that fact would already be obvious to a reasonably informed person.
However, if challenged, you’ll need to demonstrate why that was sufficiently clear.
Similarly, AI watermarking obligations do not apply when AI merely assists with standard editing or does not substantially alter the meaning of the original content.
Correcting grammar is not the same as generating entirely new content.
There are also important transitional provisions.
Machine-readable marking obligations do not immediately apply to systems already placed on the market before August 2, 2026.
Those providers have until December 2, 2026 to comply.
Likewise, AI-generated content published before August 2 does not need to be labeled retroactively.
The Commission encourages voluntary labeling where practical, but it is not legally required.
What Non-Compliance Could Cost
Violations of the transparency obligations fall into the AI Act’s middle penalty tier.
The maximum administrative fine can reach €15 million or 3% of worldwide annual turnover, whichever is higher.
The highest penalties—up to €35 million or 7% of global turnover—remain reserved for prohibited AI practices under Article 5.
Still, transparency obligations are likely to affect a far larger number of organizations.
For multinational companies, the financial exposure can be significant even when the underlying AI project is relatively small.
What I Would Do This Week
You don’t need a six-month compliance program.
You probably need half a day.
Start by documenting every AI system your organization currently uses.
Identify who provides it.
Determine whether your organization acts as the provider or the deployer.
Review your website chatbot.
If it’s AI, make sure users are informed immediately—not hidden inside your privacy policy.
Audit your marketing materials.
Identify any AI-generated or AI-manipulated voices, faces, or realistic imagery that should be disclosed.
Establish an internal rule governing content published without human review.
Finally, update contracts with agencies and freelancers.
Legal responsibility remains yours, but contractual responsibilities should still be clearly documented.
And don’t forget the most overlooked step:
Document every compliance decision you make.
If questions arise later, written records are far more persuasive than memory.
The Bigger Picture
The postponement of high-risk AI obligations is not a suspension of the AI Act.
It simply redistributes the timeline.
Most Italian—and European—companies are not building foundation models.
They’re using AI every day to write content, create advertising, generate videos, and interact with customers.
Those everyday uses are exactly where the AI Act is now taking effect.
There’s another way to interpret all this.
Labeling AI-generated content isn’t simply a regulatory obligation.
It also becomes a trust signal.
In a world flooded with synthetic content, being transparent about what was created by AI—and what was genuinely created or reviewed by people—may become a competitive advantage.
That wasn’t necessarily the regulation’s primary goal.
But it may become one of its earliest business consequences.



