EU AI Act from August 2, 2026: What Actually Applies, What Was Postponed, and What an SME Must Do
August 2, 2026 is the most misunderstood date in the EU AI Act: high-risk obligations were postponed to 2027, but transparency rules do apply. Chatbots that must disclose themselves, labeled AI content, documented training: here is what an SME needs to do now, with the correct dates and a 6-point checklist.
Gaetano Castaldo
In short
From August 2, 2026 the transparency obligations of the EU AI Act (Article 50) become applicable: chatbots must disclose they are AI, generated content must be labeled, deepfakes must be marked. The obligations on high-risk systems were instead postponed to December 2, 2027 by the Digital Omnibus package, while the prohibitions and the training obligation have been in force since February 2025, with enforcement starting precisely in August. There is a lot of confusion around this date: some say everything kicks in, others say everything was postponed, and getting it wrong in either direction is expensive. Here you will find the correct dates, who is affected, and a 6-point checklist to get compliant.
What changes on August 2, 2026 under the AI Act?
On August 2, 2026 the part of the AI Act (Regulation EU 2024/1689) that affects the largest number of companies becomes applicable: the transparency obligations of Article 50. They do not only concern AI developers, but anyone using AI towards customers and the public. In practice:
- Chatbots and virtual assistants must inform users they are talking to an AI, unless it is obvious from the context. This applies to the widget on your website, the assistant in customer service, the voicebot on the phone.
- AI-generated or AI-manipulated content (texts published to inform the public, audio, images, video) must be recognizable as such, with machine-readable marking where technically feasible.
- Deepfakes and synthetic content depicting real people, places or events must be explicitly labeled.
For systems already on the market there is an adjustment window on marking until December 2, 2026: three months, not six as originally planned. That is not much, especially if your chatbot was configured by an external vendor and you need to coordinate with them.
The enforcement machine also becomes operational in the same period: national authorities start their checks, including those on the training obligation we cover below.
Was the AI Act postponed? Yes, but only in part
This is where the confusion comes from. With the Digital Omnibus package, the Council and the European Parliament reached an agreement on May 7, 2026 that only moves forward the obligations on high-risk systems: those used for hiring and people management, access to credit, education, justice, biometric identification. Formal adoption of the text is expected before August 2, 2026.
| Date | What happens | Status |
|---|---|---|
| February 2, 2025 | Prohibitions on unacceptable practices (Art. 5) and AI literacy obligation (Art. 4) | Already in force |
| August 2, 2025 | GPAI model rules, governance, penalties applicable | Already in force |
| August 2, 2026 | Transparency (Art. 50): chatbots, generated content, deepfakes | Applies now, not postponed |
| December 2, 2026 | End of the marking window for systems already on the market | Confirmed |
| December 2, 2027 | Obligations for high-risk systems under Annex III | Postponed (was August 2, 2026) |
| August 2, 2028 | High-risk in regulated products (Annex I: machinery, medical devices) | Postponed |
Two traps to avoid. The first: reading "postponement" and shelving the topic. Transparency, prohibitions and training were not touched, and they are precisely the obligations that apply to a typical SME. The second: forgetting that the high-risk postponement buys time, it does not grant amnesty. If you use AI to screen candidates or evaluate people, that deadline will come, and preparing takes months.
Is my company affected even if it only uses ChatGPT or a chatbot?
Almost certainly yes. According to the ISTAT "Enterprises and ICT" report of December 2025, 16.4% of Italian companies with at least 10 employees use at least one artificial intelligence technology: double the 8.2% of 2024 (it was 5% in 2023). And in nearly 60% of the companies that evaluated AI investments without activating them, the declared blocker is the lack of skills. And the AI Act does not only look at who produces the technology: it also looks at who uses it (the "deployer"). Three very common situations in an SME:
- You have a chatbot on your website or in customer service: from August 2 it must disclose itself as AI. If it generates answers for the public, the transparency requirement is yours, even if the software belongs to a vendor.
- Your marketing team generates content with AI: published informative texts, synthetic images and videos must be recognizable as generated. You need an internal rule on when and how to label.
- Your employees use AI tools in their daily work: the AI literacy obligation of Article 4 applies, in force since February 2025, with active enforcement from August 2026. Training must be real and documented: we covered it in detail in our guide to the AI training obligation for SMEs.
On top of this comes the Italian layer: Law 132/2025 on artificial intelligence adds national safeguards in sectors such as healthcare, labor and professions.
What are the penalties for non-compliance?
The AI Act penalties are already applicable and their ceilings leave no room for underestimation:
- up to 35 million euros or 7% of global turnover for the practices prohibited by Article 5;
- up to 15 million euros or 3% of turnover for violations of the other obligations, transparency included.
For SMEs and startups the lower of the fixed amount and the percentage applies: a corrective designed precisely for small companies, which however does not turn the fine into a symbolic figure. Beyond the fine there is reputational damage: being caught with a chatbot pretending to be human, after August 2, is also a customer trust problem.
What to do now: the AI Act checklist for an SME
Six concrete steps, in the order to tackle them:
- Map the AI systems in use. Not just ChatGPT: also the AI features inside CRM, helpdesk, ERP and marketing tools. If you do not know where AI is, you cannot be compliant. It is the same principle as the inventory we use in our AI Act compliance guide.
- Check the Article 5 prohibitions. Emotion recognition in the workplace, social scoring, manipulation: banned since February 2025, with the highest fines in the entire regulation.
- Get transparency in order by August 2. A chatbot that discloses itself, labels on published generated content, marking of synthetic content. For systems already live you have the window until December 2, 2026: use it to coordinate with vendors.
- Document AI training. The Article 4 obligation applies to every company using AI, and enforcement starts in August. A few well-designed hours per employee are enough, but they must be part of a documented plan.
- Write an internal usage policy. What can and cannot be uploaded to AI tools (the 7 things never to upload are a good starting point), who approves generated content, how errors get reported.
- Map high-risk uses now. If you use AI in recruiting, evaluations or credit, the postponement to 2027 is time to prepare, not to procrastinate.
Frequently asked questions on the AI Act and August 2, 2026
Was the AI Act postponed to 2027?
Only in part. The Digital Omnibus postpones the obligations on high-risk systems to December 2, 2027 (Annex III) and August 2, 2028 (Annex I). The transparency obligations of Article 50 remain set for August 2, 2026, while the prohibitions and the training obligation have been in force since February 2025.
What becomes mandatory on August 2, 2026?
Article 50 transparency: anyone using AI towards the public must disclose it. Chatbots must present themselves as AI, generated content (text, images, audio, video) must be recognizable as such, deepfakes must be labeled. For systems already on the market, marking must be completed by December 2, 2026.
Does a chatbot on a company website have to disclose it is an AI?
Yes, from August 2, 2026, unless it is already obvious from the context. The obligation falls on whoever uses the system towards their own customers, even if the software is developed or configured by an external vendor.
Is AI training mandatory for companies?
Yes. Article 4 of the AI Act requires every company using AI systems to ensure an adequate level of AI literacy among staff. It has been in force since February 2, 2025 and enforcement starts in August 2026: training must be real and documented.
What penalties does an SME risk for not complying with the AI Act?
Up to 35 million euros or 7% of global turnover for the practices prohibited by Article 5; up to 15 million or 3% for violations of the other obligations, transparency included. For SMEs and startups the lower of the two amounts applies.
Want to know if your company is compliant? Start here
AI Act compliance is not a big-enterprise project: for a well-organized SME the first four points of the checklist can be closed in a few weeks. The point is starting with a clear map instead of deadline anxiety.
If you want a hand, our free Pre-Assessment starts exactly there: an inventory of the AI systems in use and adjustment priorities, with a concrete plan. And if you would rather see how other SMEs are handling this first, the Solutions Hub community has a channel dedicated to AI rules where every week we review regulatory news in plain language.
Tags
Founder & CEO · Castaldo Solutions
Sono un consulente di trasformazione digitale con esperienza enterprise. Aiuto le PMI italiane ad adottare AI, CRM e architetture IT con risultati misurabili in 90 giorni.