Skip to main content

EU AI Act Enters Main Phase: What Actually Changes Tomorrow

Ilustrační obrázek
August 2, 2026. After two years of phased rollouts, prohibited-practice bans, GPAI obligations, and a last-minute "AI Omnibus" simplification, the EU Artificial Intelligence Act reaches its main application date tomorrow. If you build, deploy, or buy AI systems in Europe, most of the rulebook now applies — not as a future roadmap, but as enforceable law across 27 member states. Here is what actually changes, who it affects, and where the real enforcement questions begin.

Two years in the making — the timeline that got us here

The AI Act was published in the Official Journal on July 12, 2024 and entered into force on August 1, 2024. The European Commission deliberately staged the deadlines so the most urgent bans came first and industrial compliance followed later. The result is a timeline that every AI operator in Europe should have pinned to the wall:

Date What applies Who is affected
2 February 2025 Prohibited AI practices (social scoring, untargeted scraping, emotion recognition in workplaces/schools, real-time remote biometric ID) + AI literacy obligations All providers and deployers in the EU
2 August 2025 Governance rules, general-purpose AI (GPAI) model obligations — transparency, copyright summaries, systemic-risk mitigation GPAI model providers (OpenAI, Google, Meta, Mistral, etc.)
2 August 2026 Main application: high-risk AI system obligations, transparency for synthetic content, enforcement powers activate Providers and deployers of high-risk AI; any organisation using chatbots, deepfakes, biometric categorisation, or emotion recognition
2 December 2027 High-risk AI systems in sensitive areas (Annex III): biometrics, critical infrastructure, education, employment, migration, border control, justice Companies whose AI is used in these sectors
2 August 2028 High-risk AI embedded in regulated products (Annex I): lifts, toys, medical devices, machinery Manufacturers of regulated products with AI components

That 2027 and 2028 shift is important: the AI Omnibus simplification package, adopted November 2025 and in force since July 27, 2026, pushed those Annex III deadlines back from the original August 2026 date. If you heard the main phase was "everything at once" — it is not. The high-risk compliance burden for recruitment, education, and justice AI systems now lands in late 2027, not tomorrow.

What changes on August 2 — the practical list

According to the European Commission's implementation overview and the July 31 enforcement press release, the following becomes applicable tomorrow:

High-risk AI systems — obligations go live

AI systems that can create serious risks to health, safety, or fundamental rights now face mandatory requirements. The categories include AI used in recruitment (CV-sorting software), education (exam scoring), access to essential services (credit scoring, benefit claims), law enforcement, migration administration, and parts of the justice system. Providers must implement:

  • Risk management systems — documented throughout the AI lifecycle
  • Data governance — training datasets must be examined for bias, representativeness, and errors
  • Technical documentation — detailed enough for regulators to assess compliance
  • Activity logging — traceable results for the system's lifetime
  • Human oversight measures — a real person must be able to intervene
  • Accuracy, robustness, and cybersecurity — tested against adversarial inputs and edge cases

Deployers — the companies and public bodies that actually use these systems — carry their own duties: follow the provider's instructions, appoint qualified human overseers, monitor performance, and keep records. Public bodies and providers of essential services must also conduct fundamental-rights impact assessments.

Transparency — synthetic content must be detectable

This is the part that affects the broadest range of organisations. From August 2:

  • Chatbots and AI interaction: people must be informed when they are talking to an AI system, unless it is "obvious from the circumstances."
  • Synthetic media: providers of systems that generate audio, images, video, or text must make outputs detectable in a machine-readable form — watermarks, metadata, or equivalent technical markers.
  • Deepfakes: deployers must disclose when content has been artificially generated or manipulated. The same applies to emotion-recognition and biometric-categorisation systems when deployed in publicly accessible spaces.

The Commission published transparency guidelines on July 20, and the Code of Practice on marking AI-generated content is available as a voluntary compliance tool. But here is what the guidelines cannot solve: a disclosure in metadata is trivially stripped by re-encoding, resizing, or reposting content. The practical effectiveness of this rule depends on platform policies and technical standards that are still maturing.

The enforcement puzzle — 27 regulators, one rulebook

The AI Act creates a two-tier enforcement architecture. National market surveillance authorities handle day-to-day supervision — investigating complaints, inspecting systems, and issuing fines. The European AI Office, established within the Commission, coordinates implementation across member states and holds direct enforcement powers over general-purpose AI models.

The obvious risk is fragmentation. A French regulator with 50 AI specialists and a Bulgarian regulator with five will not enforce the same way. Cross-border AI services — think a recruitment platform deployed across half a dozen countries — could face overlapping or contradictory demands from multiple authorities. The European Times reported in June that enforcement specialists were already feeling the pressure; that pressure now moves from preparation to daily casework.

The fine structure is not trivial. For prohibited practices, penalties can reach €35 million or 7 % of global annual turnover, whichever is higher. For most other infringements — including high-risk system non-compliance — the cap is €15 million or 3 %. Supplying incorrect information to authorities carries up to €7.5 million or 1 %. These numbers were written to hurt.

What it looks like from our production server

We operate AI pipelines — article generation, transcription, text-to-speech, benchmarking — on our own infrastructure from the Czech Republic. Most of what we run falls into the "minimal or no risk" category: editorial AI used with human oversight, clearly disclosed outputs, no consequential decisions about individuals. Under the Act, that is where the vast majority of AI systems live, and no new obligations apply there beyond the transparency rules already in effect.

The line gets interesting for anyone building tools that could be classified as high-risk if deployed in the wrong context. A language model that evaluates job applications is a high-risk system. A language model that drafts marketing copy is not. The Act regulates use cases, not the model itself — unlike the GPAI chapter, which regulates the model provider directly. Companies on the borderline should document their intended-purpose statements carefully: the Act's risk classification is tied to what the system is designed to do, not merely what a creative customer might do with it.

For European AI startups, there is a practical silver lining. The AI Omnibus extended simplified documentation requirements to small mid-cap companies (SMCs), not just SMEs. Regulatory sandboxes — including a new EU-level sandbox — let companies test AI solutions in real-world conditions without full compliance from day one. And the AI Act Service Desk provides direct access to guidance.

What the AI Act does not do — and why that matters

The Act does not ban open-weight models. It does not require pre-market approval for most AI systems (high-risk systems are self-assessed against harmonised standards, not pre-authorised by a regulator). It does not block API access to frontier models for European developers. And it does not impose the same obligations on end-users tinkering with AI for personal, non-professional purposes.

Those distinctions matter because the regulatory debate outside Europe often caricatures the Act as a blanket AI ban. It is not. It is a risk-tiered compliance framework that mostly leaves low-risk AI alone. Whether it achieves its goals — protecting fundamental rights without stifling innovation — depends on whether the 27 national regulators can enforce it consistently, and whether the transparency rules can survive contact with the open internet.

The easy part — passing the law — ended in 2024. Tomorrow, the hard part begins.

Does the AI Act apply to my company if I am based outside the EU?

Yes, if your AI system's output is used in the EU. The Act has extraterritorial reach: any provider placing AI systems on the EU market, regardless of where the company is incorporated, must comply. If a US-based SaaS company sells an AI recruitment tool to a German employer, the Act applies to the US provider and the German deployer. The same logic follows GDPR — Brussels regulates by market access, not geography.

What if I use ChatGPT or Claude for internal work — do I need to comply?

For general business use — drafting emails, summarising documents, coding assistance — you are deploying a minimal-risk AI system, and no specific obligations apply beyond the transparency duty (if you publish AI-generated text as public-interest information, it must be labelled). The GPAI obligations sit with the model provider (OpenAI, Anthropic), not with you as the deployer. If you integrate a GPAI model into a high-risk application — say, an automated loan-eligibility system — the full high-risk obligations apply to you as the provider of that system.

Are there any AI systems that are now completely illegal in the EU?

Yes. Since February 2025, nine practices are prohibited: AI-based manipulation causing harm, exploitation of vulnerabilities (age, disability), social scoring by public authorities, individual criminal-risk prediction, untargeted scraping of faces from the internet or CCTV, emotion recognition in workplaces and schools, biometric categorisation to infer protected characteristics (race, religion, sexual orientation), real-time remote biometric identification in public spaces (with narrow law-enforcement exceptions), and — from December 2026 — AI "nudification" apps generating non-consensual intimate imagery.

X

Don't miss out!

Subscribe for the latest news and updates.