The AI Act After 2 August 2026
4 Aug 2026 · RS Management
TL;DR
- The 2 August 2026 date now means something different from what 2025 compliance plans assumed.
- Article 50 transparency obligations took effect. Requirements for Annex III high-risk systems moved to 2 December 2027, through Regulation (EU) 2026/1744, which landed six days before the original deadline.
- Recruitment and workforce management stay in the high-risk category.
For more than two years, 2 August 2026 stood as the date the EU AI Act would apply in full. Six days before that deadline the picture changed. Regulation (EU) 2026/1744, published in the Official Journal on 24 July and in force from 27 July 2026, pushed the heaviest obligations back by well over a year. The deadline did not disappear, but it now means something different from what most compliance plans written in 2025 assumed.
Classifying a specific system is worth doing with a qualified lawyer involved.
The calendar worth keeping in view
Regulation (EU) 2024/1689 entered into force on 1 August 2024 and has been arriving in stages ever since, under Article 113:
| Date | What starts to apply |
|---|---|
| 1 August 2024 | Regulation (EU) 2024/1689 enters into force |
| 2 February 2025 | Prohibited practices and the AI literacy obligation (Chapters I and II) |
| 2 August 2025 | General-purpose models, supervisory bodies, penalties, confidentiality |
| 2 August 2026 | The remainder of the Regulation, including Article 50 transparency and Article 101 |
| 2 December 2026 | New Article 5 prohibitions; end of the transition on content marking |
| 2 December 2027 | Standalone high-risk systems under Annex III (postponed) |
| 2 August 2028 | High-risk systems embedded in Annex I products (postponed) |
- 2 February 2025: prohibited practices and the AI literacy obligation (Chapters I and II).
- 2 August 2025: general-purpose AI models, the supervisory authority structure, the penalty provisions and confidentiality (Chapter III Section 4, Chapters V, VII and XII except Article 101, plus Article 78).
- 2 August 2026: the remainder of the regulation, including the Article 50 transparency obligations and Article 101, which covers fines for providers of general-purpose AI models.
- 2 December 2027: stand-alone high-risk systems under Annex III, moved from 2 August 2026.
- 2 August 2028: high-risk systems embedded in products covered by sectoral legislation under Annex I, moved from 2 August 2027.
The amendment also added two intermediate dates. From 2 December 2026, new prohibitions under Article 5 take effect, covering the generation of non-consensual intimate material and child sexual abuse material. The same day closes the transition period for machine-readable content marking for systems placed on the market before 2 August 2026.
What genuinely started on 2 August
The Article 50 transparency obligations survived the reshuffle, and they are the operational work landing on desks right now. They come down to a handful of situations. Anyone interacting with an AI system has to be told. Synthetic audio, images, video and text have to be marked in a machine-readable format on the provider side. Emotion recognition and biometric categorisation systems require notice to the people involved, and deepfakes and public-interest text require disclosure by the deployer, with exceptions where a human takes editorial responsibility.
In practice this reaches plenty of companies that do not consider themselves technology businesses: the chatbot on the website, the assistant in a customer service channel, an image generated for a marketing campaign. Reviewing those touchpoints takes a few working days and is the cheapest work available this quarter.
Penalties, and the SME exception
Article 99 sets three tiers: up to EUR 35 million or 7% of total worldwide annual turnover for breaching the prohibited practices, up to EUR 15 million or 3% for most other breaches, and up to EUR 7.5 million or 1% for supplying incorrect or misleading information.1 For undertakings, the higher of the two figures applies.
Here sits the detail most often missed in board conversations. Paragraph 6 of the same article reverses the rule for small and medium-sized enterprises, including start-ups: for them the lower of the two applies. The July amendment added a comparable mechanism for small mid-cap companies. For a business turning over a few tens of millions, that gap separates a painful fine from an existential one.
HR as a high-risk area
Point 4 of Annex III covers employment and workforce management. Sub-point (a) lists systems used for recruitment and selection, in particular for placing targeted job advertisements, analysing and filtering applications and evaluating candidates. Sub-point (b) covers systems informing decisions on terms of employment, promotion and termination, allocating tasks based on individual behaviour or personal traits, and monitoring and evaluating performance and conduct.
A CV ranking tool, a candidate scoring model, analysis of recorded interviews, a system assigning tasks from a worker profile: each falls inside that point. The full requirements now bite on 2 December 2027, which hands HR teams roughly sixteen extra months.
That time is worth using, because the work runs longer than it looks. A sensible order starts with an inventory of every tool touching candidates and employees, including AI features switched on inside an applicant tracking system without a separate purchasing decision. Then comes a review of supplier contracts against the documentation those suppliers must hand over, the design of human oversight with a named person with the standing to overrule the system, and the rules for informing candidates and staff.
Deployer obligations beyond HR
Article 26 places obligations on the organisation using a high-risk system, separate from the provider’s. They cannot be contracted away, which tends to surprise teams who have just bought a finished tool from a reputable vendor.
The core of these duties repeats across industries: using the system in line with the provider’s instructions, assigning oversight to people with suitable competence and support, monitoring operation, and suspending use and informing the provider and supervisory authority where a risk to health, safety or fundamental rights appears. Deployers also retain automatically generated logs and keep input data appropriate to the purpose, to the extent they control it. Some, including public bodies and providers of certain services, additionally carry out the fundamental rights impact assessment under Article 27.
Polish supervision starts in autumn
The national layer closed at almost the same moment. The Polish Act of 3 July 2026 on artificial intelligence systems was published in the Journal of Laws on 27 July 2026, with most of its provisions taking effect on 11 August 2026. It establishes the Commission for the Development and Security of Artificial Intelligence (KRiBSI) as the national market surveillance authority. The Ministry of Digital Affairs expects the chair to be appointed in October 2026 and the Commission to be operational in November. The EU obligations run regardless of that body’s readiness, so waiting for it moves no deadline.
Making use of the extra sixteen months
Pushing deadlines back is good news for delivery schedules and risky for discipline. What we see repeatedly is that projects deferred without a named owner reappear a quarter before the deadline, once the room to negotiate with suppliers has closed.
A workable split looks like this. Close out the Article 50 obligations this quarter, since they already apply and are comparatively cheap. Run the inventory and Annex III classification through to the end of 2026, while decisions are still reversible. Renegotiate supplier terms at the next contract renewal rather than in 2027 under deadline pressure. That sequence costs little and removes most of the last-minute risk.
Footnotes
-
Regulation (EU) 2024/1689, Article 99, Official Journal text: https://eur-lex.europa.eu/eli/reg/2024/1689/oj. ↩
RS Management is an advisory practice run by one person. Who stands behind it and with what experience: About.
Blog content is informational and educational. It does not constitute legal or tax advice, nor individual business advisory. The scope of our services is described in the terms.
This topic is covered by the AI Strategy package: 4 weeks of analysis + strategy and a 90-day schedule.
See the package: AI Strategy