On August 2, 2026, a date that many founders have waved away as distant future suddenly gets sharp. From that day, new obligations under the EU AI Act take effect, and they apply to everyone who uses AI in a product or in daily operations, not only to the big model builders. I have looked at what actually matters and what you should have done by then.
First, so no one panics: the AI Act does not arrive as one giant wall. It comes in stages, and some deadlines have recently even been pushed back. Still, August 2026 remains a hard cutoff, and anyone who fails to sort things out now will be chasing later.
More on this topic: AI in the Founder's Working Day – background, practice and every article in one place.
What actually applies on August 2, 2026
The most important block that kicks in that day is the transparency obligations under Article 50. Put simply: people must know when they are talking to an AI and when content was generated by one. Chatbots must identify themselves as machines. AI-generated images, audio, and video, including deepfakes, must be labeled as artificial. That sounds trivial, but it matters to anyone running a customer-service bot, a text or image generator, or voice automation. If you want to understand what such an agent technically is and does, I explained it in detail in What is an AI agent.
What was postponed, and why that is no free pass
Through the so-called Digital Omnibus, which the Council of the EU gave final approval to in late June 2026, the stricter obligations for high-risk AI were pushed back. Stand-alone high-risk systems under Annex III now have more time, and systems embedded in regulated products have until August 2028. That buys some breathing room, but it changes nothing about two things: the transparency obligations still apply on August 2, 2026, and the duty to train your team in the use of AI has been in force since February 2025 anyway. Anyone leaning back now is confusing a delay with a done deal.
Who is bound by what
Providers are those who develop an AI system or bring it to market under their own name. The heaviest load sits here. Deployers are everyone who uses an AI system commercially, which is most small and mid-sized businesses. As a deployer, what mainly hits you is transparency toward your users and the care not to run a prohibited system. Since February 2025, practices like social scoring or manipulative nudging have been banned. Most founders are deployers, not providers, and that is the good news.
The practical checklist from a founder's view
First, inventory: Write down which AI runs in your company, from the chatbot to marketing image generation to applicant screening. Without that list you cannot even judge what is regulated.
Second, labeling: Make sure every chatbot identifies itself as an AI and that AI-generated content is visibly or technically marked.
Third, clarify roles: Are you a provider or a deployer for a given system? Careful: anyone who heavily adapts a third-party model or offers it under their own name can become a provider themselves.
Fourth, training: Your people need a basic grasp of what AI may and may not do. That is a duty, not an optional extra.
Fifth, governance: Define who in the company is responsible for AI, and document decisions. How far AI takes over entire workflows is something I describe in The autonomous organization.
Why I take this seriously but not fearfully
The fines are steep, up to 35 million euros or 7 percent of worldwide annual turnover for prohibited practices. But the truth is: for a normal mid-sized company that uses AI responsibly as a tool, compliance is doable. If you label cleanly, train your team, and keep an honest inventory, you have handled most of it. I see less of a brake here than a chance to build trust. The binding rules and the official timeline are available directly from the European Commission.
Frequently Asked Questions
What exactly changes on August 2, 2026?
That day the transparency obligations under Article 50 of the AI Act take effect. AI chatbots must identify themselves as machines and AI-generated content such as deepfakes must be labeled as artificial. This affects practically anyone who uses AI in customer-facing contexts.
Does the AI Act also apply to small and mid-sized companies?
Yes. Most small companies are deployers, not providers, and therefore carry mainly transparency and training obligations. The heaviest high-risk duties usually do not apply to them and have also been pushed back in time.
Were AI Act deadlines postponed?
Yes. Through the Digital Omnibus, which the Council of the EU finalized in late June 2026, the obligations for high-risk AI were delayed, both stand-alone Annex III systems and embedded systems into 2028. The transparency obligations due in August 2026 are unaffected.
How high can the fines be?
For prohibited AI practices, penalties can reach up to 35 million euros or 7 percent of worldwide annual turnover, whichever is higher. Lower tiers apply to other violations. For normal, responsible use, however, compliance is very achievable.
Warm regards,
Dennis Weidner





