July 12, 2026 · 6 min read

What actually becomes enforceable on August 2, 2026, and what moved to December 2, 2027

The short version

  • Enforceable from Aug 2, 2026: Article 50 transparency duties and the Commission’s enforcement powers over general-purpose AI (GPAI) models, with fines up to €15M or 3% of global turnover.
  • Not enforceable yet: the Annex III high-risk obligations (Art. 8–17, including Art. 12 logging and Art. 14 human oversight). The Digital Omnibus moved them to December 2, 2027. High-risk AI in regulated products (Annex I) follows on Aug 2, 2028.
  • Unchanged: every penalty ceiling. And for perspective: to date there is no publicly verified fine issued under the AI Act.

Why everyone is confused right now

The AI Act’s original schedule put the high-risk obligations on August 2, 2026. The Digital Omnibus (adopted by the European Parliament on June 16, 2026 and by the Council on June 29, 2026) moved them by 16 months, weeks before that date arrived.

The result: most guides, checklists, and vendor pitches written before June 29 are now describing a timeline that no longer exists. If a document tells you that Article 12 automatic logging or Article 14 human oversight is mandatory this August, it predates the Omnibus. That is the honest explanation for the contradictory advice you are seeing, and the reason this page lists only dates from the adopted texts.

What actually becomes enforceable on August 2, 2026

1. Article 50: transparency. People must be told when they are interacting with an AI system (chatbots, voice assistants). AI-generated or AI-manipulated content, including deepfakes, must be disclosed, and synthetic content must be marked machine-readably. One transitional detail: the grace period for the marking obligation runs until December 2, 2026.

2. GPAI enforcement. The duties for general-purpose AI model providers have applied since August 2, 2025. What is new on August 2, 2026 is that the Commission’s enforcement powers kick in. Obligations without an enforcer become obligations with one.

3. Already in force much longer: the Article 5 prohibited practices (social scoring, subliminal manipulation, and others) have applied since February 2, 2025, at the highest penalty tier.

What moved to December 2, 2027

The full Annex III high-risk stack: risk management, data governance, technical documentation, Article 12 automatic logging, Article 14 human oversight, accuracy and robustness requirements (Art. 8–17), plus Article 19 log preservation. This covers the classic high-risk use cases: CV screening, credit scoring, medical decision support, and the rest of Annex III.

High-risk AI embedded in regulated products (Annex I: machinery, medical devices, vehicles) follows on August 2, 2028.

The penalties did not move

The dates moved. The ceilings did not:

ViolationMaximum fine
Art. 5 prohibited practices€35M / 7% of global turnover
High-risk, transparency & GPAI obligations€15M / 3% of global turnover
Misleading information to authorities€7.5M / 1% of global turnover

The enforcement reality check

Three verifiable facts as of July 2026: only 9 member states have fully designated their national enforcement authorities. The harmonised technical standards are still unpublished. And there is no publicly verified fine under the AI Act to date.

Those facts kill two opposite mistakes:

Panic is wrong. Anyone selling you “instant AI Act compliance” against obligations that start in 17 months is selling the confusion, not a solution.

Complacency is also wrong. Article 12 logs must be generated at the moment of use; they cannot be reconstructed retroactively. When the obligations bite in December 2027, the evidence either exists or it never will. Authorities are staffing up now; the first wave of enforcement will land on companies with no audit trail at all.

The high-risk deadline moved once, by 16 months, after a multi-year legislative fight. Planning on a second delay is not a strategy.

What to do with the 17 months

  1. 1

    Classify your AI use cases

    Whether December 2, 2027 concerns you at all depends on where your systems fall. Our free risk classifier answers it in 30 seconds.

  2. 2

    Put the real dates in your roadmap

    Aug 2, 2026 · Dec 2, 2026 · Dec 2, 2027 · Aug 2, 2028. The full sequence is on our EU AI Act timeline.

  3. 3

    Meet Article 50 now

    If you run customer-facing chatbots or generate synthetic content, transparency duties apply to you in weeks, not months. Disclosure labels and content marking are cheap to ship. Do it before August.

  4. 4

    Start accumulating runtime evidence

    Logs, decisions, and oversight records only count if they were produced at the moment of use. Every month of real audit history you build before December 2027 is a month your competitors cannot recover.

  5. 5

    Don't buy panic

    No tool makes you compliant by itself, ours included. What infrastructure can do is enforce your policies at runtime and produce the evidence that supports your compliance case. Treat anyone promising more with suspicion.

Where does your AI stack actually stand?

Classify a use case against the AI Act risk tiers: free, 30 seconds, no signup.

Run the risk classifier

Dates verified against the adopted Digital Omnibus texts (European Parliament June 16, 2026; Council June 29, 2026) as of July 2026. This article explains the law’s schedule; it is not legal advice.

All insights