EU AI Act: What Changed on 2 August 2026?

EU AI Act transparency rules now apply. We explain the scope for companies outside the EU, the delayed provisions, and a practical first checklist.

2026-08-18

2 August 2026 was an important milestone for the European Union’s AI Act. It did not, however, mean that every obligation started on the same day. Some rules were already applicable, some high-risk system deadlines were extended, and the most visible change for businesses using generative AI concerns transparency.

Being established outside the EU does not automatically put a company outside the Act. A business that places an AI system on the European market, or whose system output is used in the EU, may fall within scope. The right first step is therefore not a generic compliance project. It is identifying your role and the actual uses that need assessment.

An AI system being inspected for transparency and compliance in a real testing laboratory

This article provides general information, not legal advice. Scope and obligations should be assessed against your product, its use and its target market.

What actually started on 2 August?

The European Commission’s transparency guidelines published on 20 July 2026 confirm that the obligations in Article 50 apply from 2 August 2026. The main business-facing requirements include:

  • A person interacting directly with an AI system must be told that it is AI unless this is already obvious from the context.
  • Systems that generate synthetic audio, images, video or text must, as far as technically feasible, mark their output in a machine-readable form so that it can be detected as artificially generated or manipulated.
  • Deepfakes and certain AI-generated text published to inform the public on matters of public interest must be disclosed.
  • People exposed to emotion recognition or biometric categorisation systems must be informed.

The role distinction matters. You may simply use a third-party tool internally. If you offer an AI feature to customers under your own product or brand, however, you may move closer to the role of a provider. A company deploying an off-the-shelf system and a company placing that system on the market do not have the same responsibilities.

Which rules were delayed?

The AI Omnibus that entered into force on 27 July extended the timetable for high-risk systems. Rules for the Annex III high-risk use cases now apply from 2 December 2027. AI embedded in regulated physical products such as machinery, toys and lifts moves to 2 August 2028.

That extension is not a reason to ignore the Act. Transparency requirements are already applicable. A company that does not record its AI systems, data flows and suppliers now will face a much more expensive classification and evidence exercise later.

Why can a company outside the EU be affected?

Article 2 on scope includes providers and deployers established in a third country where their system output is used in the Union. Placing an AI system on the EU market is another route into scope.

Practical examples include:

  • An AI-enabled SaaS product offered to European customers,
  • Automated customer service responding to consumers in the EU,
  • Candidate scoring used in a European recruitment process,
  • Tools generating advertisements, images or public information for an EU market.

These examples do not all fall into the same risk category. But “our server is outside Europe” or “we use a third-party model” is not, by itself, a complete scope assessment.

A practical first checklist

Start with a verifiable inventory rather than a policy document running to hundreds of pages:

  1. Inventory actual use. Which team uses which AI tool, with what data, and to support which decision?
  2. Identify your role. For each use, are you closest to a provider, deployer, distributor or integrator?
  3. Find human touchpoints. Check where AI disclosure appears in chat, call centre, application and recommendation flows.
  4. Keep content provenance. Can you connect the model and version, generation date, human approval and final published output?
  5. Question suppliers. Does the model or media tool support machine-readable marking, provenance information and audit logs?
  6. Define error and appeal paths. When an incorrect output affects a customer, who reviews it, how is it corrected, and how is the incident recorded?
  7. Give legal counsel technical evidence. Supply the real data flow and use case, not only the name of the product.

Signing the Commission’s transparency code is voluntary. But the Commission makes clear that non-signatories still need to demonstrate compliance by other adequate means. The objective is not a badge. It is evidence that the controls work.

Displaying a notice in the right interface, marking synthetic output, recording model versions and tracing supplier output are product and engineering tasks. Legal teams define what is required; product and technical teams make the requirement real.

A useful first deliverable has four parts: an AI use inventory, a risk classification table, a list of missing controls and an implementation plan with named owners. To review your current systems from that perspective, see our security audit and digital transformation consulting services, or contact us to scope the work together.