AgenTomte

August 17, 2026 · 7 min read

The EU AI Act in August 2026: What Applies to You Today

By Sahan, co-founder, systems and delivery

As of 17 August 2026, the honest answer is short: the transparency obligations bind you now, and the high-risk chapter does not. Article 50 of the EU AI Act has applied since 2 August 2026 to every in-scope AI system on the EU market that day, regardless of when it was first placed there, according to the European Commission’s Article 50 guidelines C(2026) 5054 of 20 July 2026. The high-risk rules, the ones most compliance packages were sold against, moved to 2 December 2027 and 2 August 2028.

That move came from Regulation (EU) 2026/1744, the Digital Omnibus on AI, dated 8 July 2026, published in the Official Journal of the European Union on 24 July 2026 and in force since 27 July 2026. If you were told to be “AI Act compliant by August 2026” and then read three articles giving three different deadlines, this is why. The law changed weeks ago and much of the web has not caught up.

Which AI Act obligations are binding today, and which ones moved?

Binding today: Article 50 transparency, the Article 4 AI literacy duty, and the general-purpose AI model rules that applied from 2 August 2025. Moved: the high-risk chapter. Under Regulation (EU) 2026/1744, Annex III and Article 6(2) systems now apply from 2 December 2027, and Annex I product-embedded systems from 2 August 2028.

ObligationStatus on 17 August 2026Stated by
Article 50(1), “you are talking to an AI” disclosureBinding since 2 August 2026, no grace periodEuropean Commission, guidelines C(2026) 5054, 20 July 2026
Article 50(2), machine-readable marking of synthetic outputBinding now, except for generative systems placed on the market before 2 August 2026, which have until 2 December 2026European Commission, same guidelines
Article 4, AI literacyIn force, wording weakened by the omnibusOfficial Journal, Regulation (EU) 2026/1744
General-purpose AI model obligationsApplied from 2 August 2025, unchanged by the omnibusEuropean Commission
High-risk, Annex III and Article 6(2)Moved to 2 December 2027Official Journal, Regulation (EU) 2026/1744
High-risk, Annex I, product-embeddedMoved to 2 August 2028Official Journal, Regulation (EU) 2026/1744

The Commission’s stated reason for the delay, in its Navigating the AI Act FAQ, is the delayed availability of harmonised standards. Nobody could comply with a technical rulebook that did not exist yet.

Two things to be clear about. The general-purpose model rules only bite if you place a model on the market, not if you use one through an API. And there is no general carve-out exempting small deployers from the AI Act. If a vendor says otherwise, ask them to name the article.

Why does so much of the web still say 2 November 2026?

Because the European Parliament’s Legislative Observatory summary carries 2 November 2026 for the machine-readable marking obligation. That page describes Parliament’s negotiating proposal, not the adopted text. The Commission’s guidelines C(2026) 5054 of 20 July 2026 state 2 December 2026 for the grandfathered systems, and that is the date to plan against.

A proposal date got copied into blog posts, then into vendor checklists, then into someone’s board deck, and none of them link back to the adopted regulation. In our experience, a compliance claim without a document number and a date is a guess wearing a suit.

Are you a provider or a deployer of an AI system?

This is the distinction that decides how much work you actually have. Under the Commission’s C(2026) 5054 guidelines, providers must build transparency into the system by the time it is placed on the market or put into service. Deployers use AI systems under their own authority for professional purposes. Most small businesses assume they are only ever deployers. Many are wrong.

Here is the trap. If you take a third-party generative system, modify it, and put it into service under your own name, you become the provider of that new system. Not the vendor. You. A branded chatbot on your site, built on someone else’s model with your prompts, your knowledge base, and your logo, is very likely your system under the AI Act.

Deployer duties are lighter and follow from how you use the tool. Provider duties are heavier and front-loaded, because they attach when the thing goes live, not when someone complains.

So the first question is not “which risk tier are we in”. It is “for each AI system touching our business, are we the provider or the deployer, and on what evidence”. That answer changes per system, and most businesses have more systems than they think.

What does an Article 50 mistake cost, and what do SMEs get off?

Article 50 penalties run to EUR 15,000,000 or 3% of worldwide turnover, whichever is higher, per the Commission’s C(2026) 5054 guidelines. For SMEs, including start-ups, the calculation flips: the fine is the lower of the two. That is a real difference, and it is one of the few places the regulation explicitly bends for smaller companies.

The other is documentation. Regulation (EU) 2026/1744 allows SMEs, including start-ups, and small mid-caps to provide Annex IV technical documentation in a simplified manner. Less paperwork, same substance.

Article 4 also got lighter. The duty is now to take measures to support the development of AI literacy, and it does not require guaranteeing any specific level of literacy for any individual. Weakened, not deleted. A short written training note and a record that your team received it is proportionate for most small businesses.

What is an AI system inventory and risk register, in practice?

It is a spreadsheet, and it is one hour of honest work. One row per AI system your business touches, with these columns: system name, vendor, what it does, who owns it internally, are we provider or deployer, does it interact with humans, does it generate synthetic content, what is logged, and who approves its output before it reaches a customer.

Most owners guess they have three AI systems. The list usually runs to twelve once you count the chatbot, the email assistant, the ad tool, the transcription service, and the thing someone in sales signed up for on a card.

The register is also the pre-deployment review nobody wants to do. IBM’s Cost of a Data Breach 2026, published 29 July 2026, found one in four malicious breaches were AI-enabled, a 56% increase year over year, averaging USD 6 million against a USD 4.99 million global breach average. Shadow AI is the same governance gap on both sides: regulatory and security.

We run our own agent fleet on exactly this discipline. Every agent is registered before it runs, has a named owner, a defined boundary, and a run log, and the agent fleet proof page shows what that control looks like in production. You own the register either way. Building that inventory is the first hour of an AI Operations Audit, fixed price, fixed scope, delivered in writing, and it is also the artefact that stops pilots dying quietly, which is why most AI pilots fail.

Do Texas, Colorado, or the UK change your plan?

Not much, and not yet. Texas HB 149, the TRAIGA, was signed 22 June 2025 and took effect 1 January 2026. Per the Texas Legislature, it is intent-based: liability requires intent to unlawfully discriminate. Enforcement sits only with the Attorney General, with a 60-day cure period, curable violations at USD 10,000 to 12,000 and uncurable at USD 80,000 to 200,000. Most affirmative duties fall on governmental entities, not on general private business.

Colorado SB26-189 was signed 14 May 2026 and, per the Colorado General Assembly, repealed and reenacted the state’s automated decision-making rules. Developer duties start 1 January 2027, and the Attorney General must adopt rules by 1 January 2027. So the shape of that regime is not final.

In the UK, SI 2026/425 was made 16 April 2026 and came into force 12 May 2026, per legislation.gov.uk. It requires the Information Commissioner to prepare a code of practice on developing and using AI and on automated decision-making, including guidance on children’s personal data. The finding worth writing down: the instrument sets no deadline for that code. Anyone quoting you a publication date is inventing it.

The register you build for Article 50 answers most of these too. Same rows, different columns.

If you want that inventory built and ranked without a single call, describe your setup and a written scope comes back. Written reply within one business day, no meetings, no calls, and you own everything we produce. For what lands at day ten, read what an operations audit actually hands over, or Start async.

Tell us what you want automated

Describe the work in writing. You get a written reply within one business day: a fixed-price proposal, a scoping question, or an honest referral out.

Start at /start

▸ written reply within one business day · no call scheduled, ever

Doesn't fit a package? Tell us what you need anyway.

Questions? Ask in writing

no chatbot · a human replies

Ask us anything, in writing

A founder replies within one business day. That is the same promise clients get.