On 2 August 2026 the EU's AI Act stopped being a rulebook and became an enforced law. Transparency obligations went live for chatbots, deepfakes and AI-generated content, and the AI Office gained real investigatory and fining powers.[4][1][6] This digest maps what actually changed, what the AI Omnibus delayed, and the milestones still ahead.
The Act entered into force on 1 August 2024, but its provisions apply in stages.[5] Prohibitions on "unacceptable risk" systems and the AI-literacy rules applied from 2 February 2025; general-purpose AI obligations and the governance framework followed on 2 August 2025.[4][1] Then, on 2 August 2026, the third major wave entered into force.[4] The Commission's official line: "The enforcement powers of the AI Office and the national competent authorities of the Member States apply from 2 August 2026, when certain provisions of the AI Act become enforceable."[2]
The most visible change: "The transparency rules of the AI Act will come into effect in August 2026."[1] Chatbots and agents must come clean — "Users must be clearly informed when they are not interacting with a real person, but an AI system, for example a chatbot, AI agent, and avatar."[7] Deepfakes — "images, audio, and video content that resemble existing persons, objects, places, entities, or events" — must be clearly and visibly labelled with machine-readable marks.[7][4] Article 50 imposes four main categories of transparency duties on providers and deployers, from informing individuals they are interacting with AI to technically marking AI-generated content so outputs can be identified as such.[4] The Commission published the first list of more than 180 organisations covered, alongside voluntary guidance including a Code of Practice on Transparency of AI-Generated Content.[6][4]
Enforcement is now real. The AI Office holds "both investigative and sanctioning powers" over GPAI models and certain AI systems; national competent authorities enforce the rules for other AI systems, and the European Data Protection Supervisor enforces for EU institutions themselves.[2] National market-surveillance authorities "may investigate potentially non-compliant AI systems, require access to information and documentation (and, in defined circumstances, data or source code) and order corrective action, restriction, withdrawal or recall."[4] Anyone can lodge a complaint, and suspected infringements fall within the EU Whistleblowing Directive.[4] Punishment scales with risk: prohibited practices carry fines "of up to €35 million or 7% of the offender's total worldwide annual turnover"; breaches of GPAI obligations up to €15 million or 3%; other AI-system breaches up to €7.5 million or 1%.[2]
This wave is narrower than originally planned. The AI Omnibus — proposed 19 November 2025 as part of the digital omnibus package — entered into force on 27 July 2026, weeks before the deadline, "bringing extended timelines to administrative simplification."[3] Its effect on the big-ticket item is explicit: the Omnibus "delayed the high-risk AI system requirements – which account for many of the Act's most substantive requirements – until 2 December 2027 (for stand-alone high-risk AI systems) or 2 August 2028 (for high-risk systems embedded in certain regulated products)."[4] The original schedule had high-risk obligations arriving around 2027 via a 36-month delay for some high-risk systems, so the delay is an extension, not a removal.[5] High-risk obligations, when they land, cover risk assessment, dataset quality, logging, documentation, human oversight and cybersecurity.[1]
The next milestone is December 2026: "Prohibition 9 comes into effect in December 2026 and was introduced as a part of the AI Omnibus" — banning AI systems that generate non-consensual sexually explicit or intimate content and child sexual abuse material.[1][3] After that, December 2027 for stand-alone high-risk systems, and August 2028 for high-risk systems embedded in regulated products.[4] For businesses outside the EU, the Act's enforcement era matters too: it is the world's first comprehensive AI law, and its fines apply to any provider or deployer whose AI reaches the EU market.[5][2]
Honest note: this digest reflects sources fetched live on 2026-08-31 — the Commission's official pages, its 2026-08-02 press material, an NYU Compliance & Enforcement blog post (authors from Debevoise & Plimpton) published 2026-08-28, and Wikipedia's overview of the Act. Two EC pages describe the transparency rules as applying in "August 2026" while the NYU post and the 2-August press release pin the date to 2026-08-02; I present the Commission's own "from 2 August 2026" wording for enforcement and its vaguer "August 2026" for transparency rather than smoothing the discrepancy. The 180-organisation list was referenced but not exhaustively read.
[1] digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai — "Regulatory framework on AI" (European Commission, fetched live 2026-08-31)
[2] digital-strategy.ec.europa.eu/en/policies/enforcement-ai-act — "Enforcement of the AI Act" (European Commission, fetched live 2026-08-31)
[3] digital-strategy.ec.europa.eu/en/news/ai-omnibus-enters-force — "AI Omnibus enters into force" (European Commission, 2026-07-27)
[4] wp.nyu.edu/compliance_enforcement/…third-wave-of-eu-ai-act-requirements… — "The Third Wave of EU AI Act Requirements Are in Force" (NYU PCCE / Debevoise & Plimpton, 2026-08-28)
[5] en.wikipedia.org/wiki/Artificial_Intelligence_Act — "Artificial Intelligence Act" (Wikipedia, fetched live 2026-08-31)
[6] digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august — "Commission starts enforcing AI Act rules and new transparency requirements on 2 August" (European Commission, 2026-08-02)
[7] commission.europa.eu/…/safer-and-more-transparent-ai-2026-08-02_en — "Safer and more transparent AI" (European Commission press release, 2026-08-02)