EU AI Act countdown to 2 August 2026: what businesses must do


Updated July 2026.

Every day a company posts an AI-generated image, lets a chatbot answer its customers, or edits an ad with a synthetic voice. Until recently those were creative choices. From 2 August 2026 they also become regulatory obligations. That is the date the EU AI Act, Regulation (EU) 2024/1689, makes the transparency obligations of Article 50 applicable and switches on the penalty regime: anyone who produces or distributes AI-generated content must make it recognisable, and anyone who fails to do so faces fines of up to 3% of worldwide turnover. If you have been searching for what the eu ai act august 2026 deadline actually requires, this is the practical answer.

Much of the recent debate has centred on the so-called AI/Digital Omnibus, which pushed some deadlines back. Read the detail, though: that postponement covers high-risk systems, not transparency. The 2 August 2026 date holds. This article is the operational checklist for that deadline: which AI Act obligations for businesses apply, who does what, which content has to be labelled, and which tasks you need to close before the clock runs out.

The short answer, if you have little time to get ready: map the AI systems you use, work out who is a provider and who is a deployer, make the synthetic content you distribute recognisable, keep records of what you generated and how, and tell users when they are interacting with a machine. The detail follows.

What changes on 2 August 2026: GPAI obligations and Article 50 in brief

On 2 August 2026 the transparency obligations of Article 50 become applicable and the penalty regime under Articles 99 and 101 takes effect. From that date, national authorities can act on breaches and issue fines.

Article 50 of Regulation (EU) 2024/1689 sets out two categories of transparency. The first concerns interaction: anyone who makes available an AI system that talks to people, such as a chatbot, must ensure the user knows they are dealing with a machine, unless this is already obvious. The second concerns content: images, audio, video and text generated or manipulated by AI must be marked in a machine-readable format and be recognisable as artificial. The marking can take various forms, from metadata to watermarks to cryptographic identifiers, as long as it is effective, interoperable and robust as far as technically feasible. For deepfakes and for text published to inform the public on matters of general interest, the duty to disclose the artificial nature is explicit. The transparency obligations apply regardless of the system's risk level: they hold even for uses the AI Act does not classify as high-risk.

The same date marks another shift: the full application of obligations for GPAI models, the general-purpose AI models whose rules started to apply on 2 August 2025. Providers of these models must prepare technical documentation, respect copyright and publish a summary of the content used for training. Whoever placed a GPAI model on the market before 2 August 2025 has a transitional window to adapt: compliance is due by 2 August 2027. For how the Article 50 labelling rules work in practice, see our dedicated insight on synthetic content labelling.

Providers and deployers: who does what and which content must be labelled

The obligations fall on two roles, and the same company can hold both. A provider is whoever develops an AI system or places it on the market under their own name. A deployer is whoever uses that system in their professional activity. You do not have to be a tech giant: a business using an image-generation tool for marketing is a deployer, with obligations of its own.

In the AI Act the distinction between provider and deployer decides who answers for what. The provider must design the system so it automatically marks generated content with a machine-readable signal, under Article 50(2). The deployer, also governed by Article 26 for high-risk systems, has transparency duties towards its own users: it must disclose when content is a deepfake and, for text on matters of public interest, that the content was artificially generated. In practice the provider embeds the technical marking at the root, while the deployer ensures the visible disclosure downstream. Note, though: if a deployer substantially modifies a system or places it on the market under its own brand, it can itself take on the role of provider, with the obligations that follow. Responsibility is not either-or: both answer, each for their part, and the same organisation is often a deployer of third-party tools and a provider of the content it publishes.

Which content must be labelled

Labelling applies to content generated or substantially modified by an AI system. It covers images produced by text-to-image generators, synthetic video and audio, cloned voices, deepfakes portraying real people in situations that never happened, and text published to inform the public on matters of general interest. It leaves out purely assistive or standard editing uses that do not materially alter the content, and uses authorised by law, for example in criminal investigations. To place a given use within its risk category, the map of AI Act risk categories is a useful reference.

The compliance steps before the deadline

Here is what to do, in order, to meet the EU AI Act August 2026 deadline. The logic is simple: first understand what you use, then classify it, then put transparency and record-keeping in place.

Preparing for the AI Act breaks down into six operational steps. First, mapping: an inventory of every AI system in use across the company, internal and third-party, with its purpose noted. Second, risk classification of each system according to the categories of Regulation (EU) 2024/1689, so you know which obligations apply. Third, recognisable labelling of the synthetic content you produce or distribute, in a format readable by both people and machines. Fourth, retention of information on what was generated, by which system and when. Fifth, disclosure to users when they interact with a chatbot or receive AI-generated content. Sixth, internal governance, with roles, responsibilities and staff training. These six steps are not a one-off exercise: they need to be documented and kept up to date, because your inventory of systems and their associated risks change with every new tool the company adopts.

Three of these points deserve a closer look.

The inventory is the foundation of everything. Without knowing which tools are running in marketing, HR, customer support and the legal team, any compliance assessment is blind. Many businesses discover at this stage a use of AI far broader than they assumed.

Retaining information is not a formality for its own sake. In the event of a challenge or dispute, being able to show which system generated a piece of content, with which data and at what moment, is what makes a company's position defensible. We have covered this in a separate insight on AI Act record-keeping requirements.

There is also an obligation whose deadline has already passed but is often overlooked: AI literacy. Article 4 has required, since 2 February 2025, that anyone using AI on behalf of the organisation has an adequate level of competence in it. It is a piece of governance that, where missing, needs closing at once.

Penalties and timeline

The AI Act penalties are calibrated to the seriousness of the breach and, like the GDPR, carry a ceiling expressed as a percentage of worldwide turnover. The regime becomes operational for the transparency obligations on 2 August 2026.

Article 99 of Regulation (EU) 2024/1689 grades penalties across three levels. Prohibited AI practices carry fines of up to 35 million euro or 7% of total worldwide annual turnover, whichever is higher. Breaching other obligations, including the transparency duties of Article 50, reaches up to 15 million euro or 3% of turnover. Supplying incorrect or misleading information to authorities costs up to 7.5 million euro or 1% of turnover. For each band the higher of the fixed sum and the turnover percentage applies, and it is national supervisory authorities that impose the fines. For providers of GPAI models, Article 101 sets penalties of up to 3% of worldwide turnover or 15 million euro. The Regulation requires authorities to take proportionality into account and, in particular, the interests of SMEs and start-ups when setting the amount.

Enforcement runs on two levels. National supervisory authorities in each Member State handle most obligations, while the European AI Office oversees GPAI models. The percentages follow the same logic the GDPR made familiar, so teams that already deal with data-protection fines have a reference point for the scale of exposure.

Timeline of deadlines

Date What applies
2 February 2025 Ban on prohibited practices and AI literacy obligation (Art. 4)
2 August 2025 Obligations for GPAI models
2 August 2026 Transparency (Art. 50), application of GPAI obligations and penalty regime
2 August 2027 Compliance for GPAI models already on the market before 2 August 2025
2 December 2027 High-risk systems under Annex III (postponed by the AI/Digital Omnibus)
2 August 2028 High-risk systems under Annex I

Penalties matrix

Type of breach Reference Maximum amount
Prohibited AI practices Art. 99 35M euro or 7% of turnover
Other obligations (incl. Art. 50 transparency) Art. 99 15M euro or 3% of turnover
Incorrect information to authorities Art. 99 7.5M euro or 1% of turnover
GPAI model provider obligations Art. 101 15M euro or 3% of turnover

Why labelling synthetic content is not enough

Labelling answers half the problem. It declares that a piece of content is artificial, but it does not prove that another piece of content is authentic. And the label itself is fragile information: a metadata field or a watermark can be stripped by compression, a screenshot, a crop. Whoever wants to deceive removes the label; whoever follows the rules is left without proof when they need to show their own material is genuine. Then there is the other half of what a company publishes every day: the real photos of a product, a video shot on site, a screenshot of a conversation. Precisely these materials, when they become evidence in a dispute, need guarantees of origin and integrity that labelling the synthetic does not provide. Transparency about the synthetic therefore has to be completed with proof of the authentic: a certification that starts at the source and stays defensible over time.

This is where TrueScreen fits. TrueScreen is the Data Authenticity Platform that captures and certifies with legal value photos, videos, audio, screenshots and documents, applying a forensic methodology of data certification: proof of the content's origin and integrity is fixed at the moment of capture, not reconstructed after the fact. Into that certification process TrueScreen integrates the electronic seal and qualified timestamp issued by third-party qualified QTSPs, so the certified content carries a certain date and verifiable integrity. Where Article 50 labelling signals what is AI-generated, certification at the source guarantees what is real, closing the other half of the transparency problem.

A concrete example. A company's marketing team runs a campaign mixing real product shots with AI-generated images. On the latter it applies the synthetic content label, as the AI Act requires. On the former, the authentic photos of the product and the plant, it uses forensic certification that fixes origin, date and integrity: if a competitor tomorrow challenges the authenticity of those images, or if a piece of content is republished in manipulated form, the company has defensible proof of what it actually produced. A label on the fake, certification on the real. To see how certified capture works, a good starting point is the forensic browser or the overview of TrueScreen solutions.

FAQ: EU AI Act August 2026

When does the EU AI Act take effect?
The EU AI Act, Regulation (EU) 2024/1689, entered into force on 1 August 2024 and applies in phases. The bans and the AI literacy obligation apply from 2 February 2025, GPAI obligations from 2 August 2025, Article 50 transparency and penalties from 2 August 2026. High-risk systems are pushed to 2027 and 2028.
Who must comply with the AI Act?
It applies to providers that develop or place AI systems on the market and to deployers, the professional users of those systems, including SMEs. A business using an image generator or a chatbot falls among the deployers and has transparency duties towards its users, whatever its sector.
What happens if you do not comply?
Article 99 penalties reach up to 35 million euro or 7% of worldwide turnover for prohibited practices, up to 15 million or 3% for breaching transparency obligations, and up to 7.5 million or 1% for incorrect information to authorities. For GPAI models, Article 101 sets up to 3% or 15 million euro. Proportionality applies for SMEs.
What content must be labelled as AI-generated?
Images, audio and video generated or substantially manipulated by AI, synthetic voices, deepfakes portraying real people and text published to inform the public on matters of general interest must all be made recognisable. Assistive uses that do not materially alter the content, and uses authorised by law, are excluded.
What must businesses do before 2 August 2026?
Ahead of the EU AI Act August 2026 deadline, businesses need to map the AI systems in use, classify their risk, label the synthetic content they produce or distribute, keep records of what was generated and when, inform users in their interactions with AI, and set up internal governance with staff training. In parallel, the AI literacy obligation, in force since 2 February 2025, needs to be met.

Certify the authenticity of your content

Turn every photo, video, audio, screenshot and document into evidence with legal value. TrueScreen captures and certifies your content at the source, with a forensic methodology.

mockup app