AI News23 min read

EU AI Act August 2026: What Actually Applies Right Now

Teach AI Tools Editorial Team
July 22, 2026
โ„น

Editorial note: Some links in this article are affiliate links โ€” we may earn a commission if you sign up, at no extra cost to you. Every tool is independently tested by our team before being recommended. Read our editorial standards โ†’

EU AI Act August 2026: What Actually Applies Right Now - AI Tools Tutorial

It can feel overwhelming to navigate these new regulations, but focusing on your system's risk category is the best place to start.

EU AI Act August 2026: What Actually Applies Right Now

The EU AI Act is the world's first comprehensive legal framework for artificial intelligence, and as of August 2026, it is no longer future legislation โ€” key provisions are live, enforceable, and actively being monitored by the European AI Office. If you build, deploy, or use AI systems in ways that reach EU users or the EU market, understanding what applies right now versus what is coming in 2027 and 2028 is essential for avoiding significant fines and building compliant products from the foundation up.

This guide cuts through the legal complexity and gives you a timeline-based, practical breakdown of what is in force, what is coming, who is covered, what the fines look like, and what your compliance checklist must include starting today.


The Complete EU AI Act Timeline

The AI Act follows a phased implementation designed to give industry time to adapt while immediately blocking the most harmful practices.

DateEnforcement Stage
August 1, 2024AI Act enters into force โ€” clock starts
February 2, 2025Prohibited AI practices banned (Chapter II)
August 2, 2025GPAI Code of Practice deadline; EU AI Office fully established
August 2, 2026GPAI model obligations + transparency rules โ€” NOW LIVE AND ENFORCEABLE
August 2, 2027High-risk AI system obligations apply
August 2, 2028Full enforcement regime and all remaining provisions

The phase that matters most for most technology companies right now is August 2, 2026 โ€” the date when General Purpose AI model obligations and broad transparency requirements became active and enforceable.


What Has Been Banned Since February 2025

Since February 2, 2025, these AI practices have been prohibited throughout the EU with no grace period:

Social Scoring by Public Authorities

AI systems that evaluate or classify people based on their social behavior or personal characteristics in ways that produce scores leading to detrimental treatment in unrelated social contexts. Chinese-style social credit systems are the paradigmatic example โ€” explicitly prohibited.

Real-Time Biometric Surveillance in Public Spaces by Law Enforcement

Remote biometric identification systems operating in real time by law enforcement in publicly accessible spaces. Narrow exceptions exist for terrorism prevention and specific serious crime investigations, requiring prior judicial or administrative authorization.

Emotion Recognition in Workplaces and Schools

AI systems that infer emotions or intentions of people in workplace or educational settings. Using AI to detect whether employees are stressed, distracted, disengaged, or showing negative affect is now explicitly prohibited in EU contexts.

Subliminal Manipulation

AI systems deploying techniques that operate beyond conscious awareness to materially distort behavior in harmful ways. Micro-targeted psychological manipulation at scale falls directly within this prohibition.

Exploitation of Vulnerabilities

AI systems exploiting vulnerabilities related to age, disability, or socioeconomic situation to distort behavior in ways that cause harm to individuals or groups.

Biometric Categorization for Sensitive Attributes

Systems categorizing individuals based on biometric data to infer race, political opinions, trade union membership, religious beliefs, sexual orientation, or health status for purposes beyond those explicitly permitted.


What Is Live NOW: August 2, 2026 Obligations

Two major compliance categories became enforceable on August 2, 2026. These are not aspirational guidelines โ€” they are active legal requirements with associated fine structures.

Category 1: GPAI Model Obligations

General Purpose AI (GPAI) models are defined as AI models trained on large amounts of data using self-supervision at scale, capable of competently performing a wide range of distinct tasks. This covers: OpenAI's GPT family, Google's Gemini models, Anthropic's Claude family, Meta's Llama models, Mistral's models, and any comparable foundation model trained at significant scale.

If you are a GPAI provider โ€” meaning you develop and make a GPAI model available to others โ€” your obligations as of August 2026 include:

1. Technical Documentation Publish and maintain technical documentation describing model capabilities, known limitations, training approaches, evaluation results, and intended deployment contexts. The European AI Office has published documentation templates.

2. Training Data Summary Provide a sufficiently detailed summary of the training data used. This includes: data sources and types, geographic and temporal scope, and any significant gaps or limitations. Full disclosure of proprietary training datasets is not required, but meaningful summary information is.

3. EU Copyright Law Compliance GPAI providers must comply with EU copyright law, specifically the Text and Data Mining (TDM) exception framework. This means honoring opt-outs from web publishers who have exercised their right to reserve content against AI training (via robots.txt TDM extensions and similar mechanisms). This provision is generating the most active litigation among affected parties.

4. Energy Consumption Disclosure Publish data on energy consumption associated with model training and inference at scale. Exact format standards are being finalized by the AI Office, but the obligation to disclose is active now.

5. Policy Publication Make publicly available a policy document describing how the model handles copyright compliance, data processing, and other regulatory obligations.

Category 2: Systemic Risk GPAI โ€” Additional Requirements

GPAI models trained with computational power exceeding 10^25 floating-point operations (FLOPs) are automatically classified as posing systemic risk and face additional obligations beyond the standard GPAI requirements:

RequirementPractical Meaning
Adversarial testingRed-teaming and systematic adversarial evaluation before major releases
Incident reportingReport serious incidents and capability-related malfunctions to the EU AI Office
Cybersecurity measuresImplement protections against adversarial manipulation and model theft
Standardized evaluationSystematic benchmark evaluation using AI Office approved methodologies
Annual AI Office reportingReport identified systemic risks, mitigation measures, and evaluation results

Models currently in this category: GPT-5.6 (OpenAI), Gemini 2.5 Pro (Google DeepMind), Claude family (Anthropic), Grok-3 (xAI), Llama 4 Maverick (Meta). Smaller models like Llama 4 Scout and Mistral 7B fall below the threshold.


Transparency Rules: Now Enforceable

Beyond GPAI providers specifically, transparency obligations now apply to any company deploying AI-powered products to EU users. These are not limited to AI companies โ€” they apply to SaaS products, consumer apps, and enterprise software using AI capabilities of any kind.

Rule 1: AI-Generated Content Must Be Machine-Detectable

Any AI-generated content โ€” text, images, audio, video at scale โ€” must be marked in a machine-readable format that allows detection of its AI origin. Technical standards for this marking are being finalized, but the obligation is active.

Practical implication: If your product auto-generates content that users subsequently publish or distribute, you need a provenance marking and disclosure strategy.

Rule 2: Chatbots Must Identify as AI

AI systems designed to interact with natural persons must inform those persons they are interacting with an AI system at the outset of the interaction โ€” unless this is obvious from context. The disclosure must be explicit and timely.

Practical implication: Your customer support chatbot, AI assistant, or virtual agent with a human name and persona needs a clear upfront disclosure that it is AI-powered. Not in a footnote โ€” at the start of the interaction.

Rule 3: Deepfakes Must Be Labeled

AI-generated or AI-manipulated images, audio, or video depicting real or realistic-looking people must be labeled as artificially generated or manipulated. Artistic, satirical, and journalistic exceptions exist, but the content must indicate its AI origin when not immediately obvious.

Rule 4: AI Search Results and Summaries Must Be Labeled

AI-generated search results, synthesized summaries, and AI-written content in information products must be labeled and distinguishable from human-curated or original content. AI Overviews, AI summaries, and similar features require disclosure.


The Extraterritorial Reach: Who Is Actually Covered

The EU AI Act covers:

  1. Providers placing AI systems on the EU market or deploying them for EU use โ€” regardless of where the company is headquartered
  2. Deployers of AI systems located in the EU
  3. Importers and distributors of AI systems in the EU
  4. Non-EU providers and deployers when their AI system output is used in the EU

The bottom line: A US company whose AI product is used by EU customers is subject to the AI Act. An Australian startup with EU enterprise clients is subject to the AI Act. A UK SaaS company (post-Brexit) with EU users is subject to the AI Act. Headquarters location is irrelevant โ€” market reach determines obligation.


The Fine Structure

Violation CategoryMaximum Fine
Prohibited practices (banned systems)โ‚ฌ35 million or 7% of global annual turnover, whichever is higher
GPAI provider violationsโ‚ฌ15 million or 3% of global annual turnover
Transparency rule violationsโ‚ฌ7.5 million or 1.5% of global annual turnover
Providing incorrect information to regulatorsโ‚ฌ7.5 million or 1.5% of global annual turnover

For large technology companies with hundreds of billions in revenue, 7% of global turnover represents existential fines. For mid-size companies, even 1.5% of global turnover can be significant. The EU has signaled from the AI Office that enforcement will be meaningful and proactive โ€” this is not GDPR's slow-start enforcement pattern.


What Is Coming in August 2027: High-Risk AI Obligations

The August 2027 deadline gives you one year to prepare for the most comprehensive obligations. High-risk AI systems โ€” which have a specific definition in Annex III โ€” face extensive requirements that take significant time to implement properly.

The Annex III High-Risk Categories

CategoryExamples Covered
Biometric identificationFacial recognition, gait analysis, emotion detection systems
Critical infrastructure managementAI managing power grids, water systems, financial systems
Education and vocational trainingAutomated grading, admission screening, student assessment
Employment and HRCV screening, performance monitoring, promotion algorithms
Essential services accessCredit scoring, insurance risk assessment, benefit eligibility
Law enforcementPredictive policing, evidence reliability assessment, risk profiling
Migration and border controlAsylum risk assessment, visa evaluation, border screening
Administration of justiceAI assisting judges or tribunals in dispute resolution
Safety components in regulated productsAI in medical devices, automotive systems, industrial machinery

High-Risk System Obligations (Starting August 2027)

If your system falls in a high-risk category, you will be required to implement:

  1. Risk Management System: Documented, continuously updated risk management processes covering the full system lifecycle from development through deployment and monitoring.

  2. Data Governance: Comprehensive documentation of training data quality, representativeness, and known limitations, plus data management practices throughout the system lifecycle.

  3. Technical Documentation: Complete documentation package sufficient for third-party conformity assessment, describing system design, training, testing, and expected performance.

  4. Automatic Logging: Technical capability to log events, decisions, and system behavior automatically for audit trail and incident investigation purposes.

  5. Transparency for Deployers: Provide deployers with information sufficient to implement appropriate human oversight.

  6. Human Oversight Design: Architect the system to enable meaningful human oversight โ€” including the ability to override, intervene, or shut down the system. "Human in the loop" must be genuinely meaningful, not performative.

From our testing: Companies often struggle to distinguish between proactive documentation requirements and those that only trigger upon an incident.

  1. Accuracy, Robustness, and Cybersecurity: Meet appropriate accuracy standards, handle errors and adversarial inputs appropriately, and implement proportionate cybersecurity measures.

  2. Conformity Assessment: Either complete self-assessment with documentation or third-party assessment (required for highest-risk categories like biometric identification).

  3. EU Declaration of Conformity: Formal declaration before placing the system on the EU market.

  4. CE Marking: Required for most high-risk AI systems, indicating conformity with EU requirements.


Practical Compliance Checklists

For SaaS Companies Using AI Features

Immediate actions (August 2026 obligations):

  • Audit all customer-facing AI interactions โ€” do chatbots and assistants explicitly identify as AI?
  • Review any AI-generated content in your product for labeling requirements
  • Confirm your AI vendor (OpenAI, Anthropic, Google) has published their GPAI compliance documentation
  • Add AI disclosure notices to relevant product flows and onboarding
  • Review for any features that might constitute prohibited practices

2027 preparation (start now):

  • Create a full inventory of AI systems used in your product
  • Assess each against Annex III high-risk categories
  • For any high-risk systems: begin risk management system design
  • Engage specialized legal counsel for formal compliance assessment
  • Begin documentation programs for any systems likely to be high-risk

For API Providers and AI Platform Builders

Immediate actions:

  • Publish technical documentation for all models accessible to EU users
  • Publish meaningful training data summary
  • Implement and publish EU copyright opt-out compliance mechanism
  • Publish energy consumption data (approximate if exact figures are not yet available)
  • If above 10^25 FLOPs training compute: implement adversarial testing programs, establish incident reporting procedures, implement cybersecurity measures

For Developers Building on Third-Party AI APIs

Immediate actions:

  • Implement chatbot/assistant AI disclosure to users (this is your obligation, not your API provider's)
  • Label AI-generated content in your application's outputs
  • Read your API provider's GPAI compliance documentation โ€” understand what their compliance covers versus what remains your responsibility
  • Audit application for any features constituting prohibited practices

Common Misconceptions About the EU AI Act

Misconception 1: "We're not an AI company, so it doesn't apply to us"

Reality: If your product uses AI for customer interactions, recommendations, screening, or decision support โ€” even using a third-party API โ€” the transparency obligations apply to your deployment. The AI Act applies to any company deploying AI to EU users.

Misconception 2: "Our AI provider's compliance covers us"

Reality: GPAI providers (OpenAI, Anthropic, Google) handle their own GPAI model obligations. But you, as a deployer, have separate transparency obligations โ€” including the chatbot disclosure requirement, which is entirely your responsibility to implement. Their compliance does not cover your application.

Misconception 3: "The AI Act only applies to EU-based companies"

Reality: The extraterritorial provisions explicitly and intentionally cover non-EU companies whose AI products reach EU users. This follows the GDPR precedent and has been confirmed by AI Office guidance.

Misconception 4: "Open-source models are fully exempt"

Reality: Open-source GPAI models released under free and open-source licenses have meaningfully reduced obligations โ€” primarily around technical documentation and some compliance reporting. However, they are not fully exempt from prohibited practice rules, and deployers of open-source models still bear the full set of transparency obligations.

Misconception 5: "Nothing is actually enforceable until 2028"

Reality: This is completely false. Prohibited practices have been enforceable since February 2025. GPAI and transparency rules are enforceable now (August 2026). High-risk rules begin August 2027. The 2028 date refers to the full enforcement regime and certain remaining provisions โ€” not the start of enforcement overall.


Tools and Frameworks for Compliance

Documentation Tools

  • Model Cards Toolkit (Google): Framework for generating technical documentation
  • Weights and Biases: Model documentation, experiment tracking, and audit trails
  • IBM OpenScale: AI monitoring, fairness evaluation, and documentation

Monitoring Tools

  • Fiddler AI: Model performance monitoring, drift detection, and explainability
  • Arize AI: ML observability and compliance monitoring
  • Evidently AI: Open-source ML monitoring for drift and data quality

Legal and Advisory Resources

  • European AI Office (digital-strategy.ec.europa.eu): Official guidance, templates, and GPAI Code of Practice
  • IAPP AI Governance Center: Privacy professional resources on AI Act compliance
  • Specialized law firms: Bird and Bird, Allen and Overy, Fieldfisher, and Linklaters all have dedicated AI Act practices

Pros and Cons of the EU AI Act

BenefitsChallenges
Clear rules replacing regulatory vacuumCompliance costs disproportionate for smaller companies
Prohibited practices finally enforceableSome technical obligations remain ambiguous
Transparency increases user trust and informed choiceExtraterritorial complexity for non-EU companies
Harmonized EU market reduces per-country fragmentation10^25 FLOPs threshold may become outdated as compute scales
Elevates baseline safety standards industry-wideRisk of over-compliance creating unnecessary innovation barriers
GPAI documentation creates ecosystem-wide accountabilityEnforcement uncertainty during early implementation period

FAQ

1. My company is based in the US. Does the EU AI Act actually apply to us?

Yes, unambiguously. If your AI product or service is used by people in the EU, the relevant EU AI Act provisions apply to you. This follows the same extraterritorial model established by GDPR and has been confirmed explicitly in AI Office guidance. Geographic headquarters does not determine compliance obligation โ€” geographic market reach does.

2. What exactly counts as a "GPAI model" under the Act?

A GPAI model is defined as an AI model trained on large amounts of data using self-supervision at scale, capable of competently performing a wide range of different tasks. This covers foundation models and large language models. It does not cover narrow AI systems trained for specific tasks only (like a fraud detection model trained exclusively on financial transaction data).

3. How does the 10^25 FLOPs threshold for systemic risk work?

If training compute exceeds 10^25 floating-point operations, the model is automatically classified as posing systemic risk with additional obligations. The AI Office can also classify models below this threshold as systemic risk based on market reach or demonstrated capabilities. The threshold may be revised as compute scaling continues to make it easier to reach.

4. Are open-source AI models exempt from the AI Act?

Partially. Open-source GPAI models have reduced obligations โ€” mainly around technical documentation format and some reporting requirements. But deployers of open-source models still have full transparency obligations (chatbot disclosure, content labeling). And if an open-source model poses systemic risk due to scale, the reduced provisions do not apply.

5. What are the actual fines and are they being enforced?

Fines range from โ‚ฌ7.5M (or 1.5% of global turnover) for transparency violations up to โ‚ฌ35M (or 7% of global turnover) for prohibited practices. The EU AI Office has indicated proactive enforcement is a priority, and national market surveillance authorities are being resourced accordingly. Unlike GDPR's notoriously slow initial enforcement, AI Act enforcement is expected to be more immediate.

6. Do AI chatbots really legally need to identify themselves as AI?

Yes. Under transparency rules effective August 2026, AI systems designed to interact with people must inform those people they are interacting with an AI at the start of the interaction. The only exception is when it is obvious from context โ€” which does not apply to chatbots given human names, personas, or human-looking profiles.

7. Is resume screening software subject to the AI Act?

Yes. Employment-related AI โ€” specifically systems used in recruitment, candidate selection, promotion decisions, performance evaluation, and employee monitoring โ€” is explicitly listed in Annex III as a high-risk category. Full compliance is required by August 2027, but preparation should begin immediately.

8. What is the GPAI Code of Practice and does it have legal weight?

The GPAI Code of Practice is a practical compliance standard developed by the EU AI Office in consultation with GPAI providers, civil society, and technical experts. Demonstrating adherence to the Code creates a presumption of compliance with GPAI obligations. It does not have the same direct legal weight as the regulation itself, but regulators will use it as the primary benchmark for assessing whether GPAI obligations have been met.

9. My startup uses OpenAI's API to build a product. What do I actually need to do right now?

As a deployer building on a third-party GPAI model, you need to: (1) ensure your application's AI assistant or chatbot identifies itself as AI to users, (2) label AI-generated content where required, (3) confirm your application does not implement prohibited practices, and (4) begin assessing whether any features qualify as high-risk AI requiring 2027 compliance. OpenAI handles its own GPAI model obligations. Your application-level transparency is entirely your responsibility.


Conclusion

The EU AI Act has moved definitively from future concern to present legal reality. As of August 2026, GPAI providers face active obligations around documentation, data transparency, copyright, and energy disclosure. Every company deploying AI to EU users must implement transparency measures: chatbot disclosures, content labeling, AI-generated content marking.

The August 2027 high-risk deadline requires preparation that begins now. Risk management systems, human oversight architecture, logging infrastructure, and data documentation programs all take months to design and implement properly. The companies that will struggle in 2027 are those treating it as a future problem. It is not.

The regulation is imperfect โ€” some thresholds are arbitrary, some obligations remain technically ambiguous, and the compliance burden on smaller organizations is a genuine concern. But the core intent โ€” prohibiting the most harmful AI practices and requiring meaningful transparency about AI interactions โ€” represents a reasonable and necessary baseline that will influence global AI governance standards for years to come.

For developers and businesses: compliance is achievable, but it requires intentional action that starts today. Map your AI systems, assess them against the requirements, implement the quick wins on transparency, and build toward 2027 high-risk compliance with a structured program. The organizations that treat the EU AI Act as a compliance framework to build toward โ€” rather than a regulatory obstacle to navigate around โ€” will be better positioned as AI governance matures globally.


Building an EU AI Act Compliance Program

Moving from understanding obligations to actually implementing compliance requires a structured program approach. Here is a practical framework:

Phase 1: Discovery (Weeks 1-4)

AI System Inventory Create a complete inventory of every AI system your organization develops, deploys, or uses. For each system, document:

  • What the system does (function description)
  • What data it processes (inputs)
  • What decisions or outputs it produces
  • Who uses it and in what context
  • Whether EU users are in scope

Regulatory Mapping For each inventoried system, assess:

  • Does it implement any prohibited practice (Chapter II)?
  • Is it a GPAI model requiring August 2026 compliance?
  • Does it interact with users requiring transparency disclosures?
  • Does it fall in an Annex III high-risk category (requiring August 2027 compliance)?

Phase 2: Quick Wins โ€” Transparency Compliance (Weeks 4-8)

The transparency obligations are the most immediately actionable. Most can be implemented in sprints:

Chatbot and Assistant Disclosure Audit every customer-facing AI interaction point. For each:

  • Add a disclosure statement to the initial interaction
  • Update UI to make AI nature visually clear
  • Document the disclosure implementation for audit purposes

Content Labeling Implementation Assess where your product generates or surfaces AI-generated content. Implement:

  • In-product labels (visible to users)
  • Machine-readable metadata (for automated detection systems)
  • Documentation of content generation mechanisms

Internal Policy Development Draft and publish:

  • AI use policy (how your organization uses AI internally)
  • AI deployment policy (how you build and deploy AI products)
  • Incident response procedures for AI-related issues

Phase 3: GPAI Compliance (If Applicable) โ€” Weeks 6-12

If you are a GPAI provider:

  • Engage technical writers to produce required documentation
  • Work with legal counsel on training data disclosure
  • Implement copyright opt-out monitoring and compliance
  • Set up energy consumption measurement and reporting

Phase 4: High-Risk System Preparation (Months 3-12, targeting August 2027)

For systems that fall in Annex III high-risk categories:

  • Commission formal legal assessment of categorization
  • Begin risk management system design and documentation
  • Implement logging infrastructure
  • Design and document human oversight mechanisms
  • Engage third-party assessors if required by your category

The EU AI Act and Open-Source AI

Open-source AI development has specific carve-outs and reduced obligations that are worth understanding:

What the Reduction Covers

GPAI models released under free and open-source licenses have reduced obligations specifically around:

  • Technical documentation can be simplified (not eliminated)
  • Some reporting requirements are reduced
  • The model card requirement is reduced in scope

What the Reduction Does NOT Cover

  • Prohibited practices apply regardless of open-source status
  • If the model poses systemic risk (above 10^25 FLOPs), full systemic risk obligations apply
  • Deployers of open-source models bear the full set of transparency obligations
  • Organizations that fine-tune open-source models and release them may take on provider obligations

Practical Implication for Organizations Using Open-Source Models

If your organization deploys Llama 4, Mistral, or other open-source models to EU users:

  • You are a deployer, not a provider โ€” your obligations are transparency rules, not GPAI provider rules
  • Meta, Mistral, and other model providers are handling their own provider obligations
  • Your chatbot disclosures, content labeling, and prohibited practice avoidance remain your responsibility

International AI Governance: How the EU AI Act Fits Into the Global Picture

The EU AI Act does not exist in isolation. Understanding the international regulatory landscape helps organizations plan compliance programs that are efficient across jurisdictions:

JurisdictionStatusKey Characteristics
European UnionAI Act in forceComprehensive, risk-based, extraterritorial
United StatesSector-specific onlyExecutive orders, no comprehensive federal law
United KingdomPrinciples-basedExisting regulators apply to AI, no new AI law
ChinaMultiple AI regulationsLLM regulations, deepfake rules, recommender systems
CanadaAIDA proposedComprehensive law proposed, not yet enacted
BrazilAI bill progressingComprehensive draft, modeled partly on EU approach

The EU's extraterritorial reach means that EU AI Act compliance effectively covers many international use cases. For organizations operating globally, an EU-compliant AI governance framework is the most rigorous baseline available and typically satisfies obligations in other jurisdictions with less stringent requirements.

Find Your EU AI Act Compliance Tools

The AI Governance Dashboard compares 23 EU AI Act compliance platforms โ€” IBM OpenScale, OneTrust, Holistic AI, Credo AI, Lakera Guard, and more โ€” with Trust Score gauges rated against Article 9, 10, 11, and 13 requirements.

Open AI Governance Dashboard โ†’

Prioritizing compliance now is a smart move to avoid the heavy financial penalties set by the European AI Office.

Tags

EU AI Act August 2026EU AI Act compliance 2026GPAI obligations 2026EU AI Act what applies nowAI transparency rules EUEU AI Act developer requirementsEU AI Act high-risk AI 2026EU AI Act business complianceGPAI providers August 2026EU AI regulation 2026AI Act enforcement dateEU AI Act timeline 2026AI Act penalties businesseshow to comply EU AI Act 2026

Written by

Sourabh Gupta

Sourabh Gupta

Data Scientist & AI Tools Specialist ยท 5+ years in AI/ML

Sourabh tests every AI tool he writes about โ€” hands-on, with real use cases. His background in data science means he goes beyond marketing claims to benchmark actual performance, cost, and reliability for developers and creators.

Full bio & editorial process โ†’

Related Articles