# AI Act August 2026: High-Risk AI Obligations and Transparency

> On August 2, 2026, the AI Act makes requirements for high-risk AI systems under Annex III mandatory, as well as the transparency obligations set out in Article 50. Providers and deployers must adapt their practices to comply with these new rules.

- Tags: ai act août 2026, systèmes ia haut risque, obligations ai act, conformité ai act 2026, annexe iii ai act, transparence ia, sanctions ai act, documentation technique ia
- Main keyword: ai act août 2026

## Introduction

In less than two years, on **August 2, 2026**, the European Artificial Intelligence Act (Regulation EU 2024/1689) will fully enter into application. This deadline marks a turning point for organizations that design, import, distribute, or operate AI systems in Europe. Two sets of requirements will then become mandatory: the **rules for high-risk AI systems** defined in Annex III, and the **transparency obligations of Article 50**. The countdown is accelerating to anticipate these major changes.

## Content

## Why is August 2, 2026, a critical milestone for AI compliance?

While the AI Act officially entered into force in August 2024, its application follows a **staged timeline**. After the ban on unacceptable AI practices (February 2025) and the regulation of general-purpose AI models (August 2025), the August 2, 2026, deadline represents the most significant operational shift for businesses.

On this date, three major changes take effect:

- **Full application of obligations for high-risk AI systems (Annex III)**: All providers and deployers in the eight sectors concerned must comply with Chapter III of the regulation.
- **Entry into force of transparency requirements (Article 50)**: Any AI that interacts with humans, generates artificial content, or produces deepfakes is subject to information and labeling obligations.
- **Deployment of the sanctions regime**: Member States must have implemented the prescribed sanctions, including fines of up to 15 million euros or 3% of global annual turnover.

A final wave will follow in August 2027, concerning AI systems integrated into products already regulated (Annex I: medical devices, toys, vehicles). However, August 2026 is when the bulk of operational challenges crystallize.

## The 8 high-risk sectors of Annex III: Are you affected?

Annex III identifies eight categories of use cases where AI is **automatically considered high-risk**. If your system operates in one of these areas, compliance becomes mandatory as of August 2026.

### 1. Biometric systems

This includes remote biometric identification (real-time or post-event), categorization based on sensitive criteria, and emotion recognition. Simple identity verification (authentication) is not covered.

### 2. Critical infrastructure

AI systems involved in the safety or management of water, gas, heating, road traffic, or critical digital infrastructure.

### 3. Education and vocational training

AI systems that determine access to an institution, evaluate learning outcomes, or guide educational/professional paths.

### 4. Employment and HR management

Automation of CV screening, candidate analysis, performance evaluation, and decisions on promotions or terminations: a common use case in business.

### 5. Access to essential services

Eligibility assessment for social benefits, credit scoring, insurance pricing, and financial risk analysis for natural persons.

### 6. Law enforcement

AI used to evaluate the reliability of evidence, profiling in investigations, or estimating recidivism risk.

### 7. Migration and border control

Assessment of migration risks, processing of asylum applications, and detection of falsified documents.

### 8. Justice and democratic processes

Decision-support tools for courts, assistance in legal interpretation, or influence on election results.

> "AI systems referred to in Annex III are considered to be high-risk [...] when they pose a significant risk of harm to the health, safety, or fundamental rights of natural persons." — Article 6, Regulation (EU) 2024/1689

## Exception cases: When is an Annex III system not high-risk?

Article 6, paragraph 3, introduces a **notable exception**. An AI system listed in Annex III may escape the high-risk classification if one of the following conditions is met:

- **Limited procedural tasks**: The AI performs only a simple operation, such as converting or sorting data.
- **Support for human intervention**: The system only assists without decision-making autonomy (e.g., text reformulation, spell checking).
- **Anomaly detection**: The AI flags deviations from human decisions without replacing the final decision.
- **Task preparation**: The result produced by the AI is systematically reviewed by a human.

Warning: This exception **does not apply** to profiling systems that process personal data to evaluate aspects of a person's life (performance, health, behavior, etc.). These remain high-risk. Any invocation of the exception must be **justified and documented before placing the system on the market** and presented to authorities upon request.

## What are the obligations for high-risk AI system providers?

Providers (those who develop or have an AI system developed and market it under their own name) must meet all requirements of Articles 8 to 21. Before August 2, 2026, it is imperative to:

1. **Implement risk management (Art. 9)**: A continuous process covering the entire system lifecycle, including risk identification, assessment, and mitigation measures.
2. **Ensure data governance (Art. 10)**: Training, validation, and testing datasets must be relevant, representative, and of high quality, with specific rules if personal data is processed.
3. **Compile complete technical documentation (Art. 11 + Annex IV)**: A detailed description of the system, its objectives, performance, limitations, and compliance measures, to be drafted before market launch and kept up to date.
4. **Provide automatic logging (Art. 12)**: Automatic recording of key events to ensure traceability.
5. **Inform and ensure transparency (Art. 13)**: Provide clear instructions to deployers regarding the use, capabilities, and limitations of the system.
6. **Enable effective human oversight (Art. 14)**: The system design must allow for human supervision during use.
7. **Guarantee accuracy, robustness, and cybersecurity (Art. 15)**: Achieve and document appropriate levels, including resistance to manipulation.
8. **Affix the CE marking and draft the EU declaration of conformity (Art. 16, 47, 48)**: To be completed before any market launch.
9. **Register the system in the EU database (Art. 49, 71)**: All Annex III systems must be registered in the public EU database.
10. **Implement post-market monitoring (Art. 72)**: Plan for the detection and correction of incidents after market launch.

The documentary and organizational burden is heavy: the technical documentation alone for a complex system can require between 40 and 80 hours of work. Solutions like [compaia](https://compaia.eu/diagnostic) facilitate the structuring and generation of compliance files, with AI assistance and guided forms compliant with Annex IV.

## Responsibilities of deployers: Obligations not to be underestimated

The term "deployer" refers to any entity that uses a high-risk AI system in a professional context. Their obligations, specified in Article 26, are distinct from those of providers and equally essential.

Deployers must, in particular:

- **Use the system in accordance with the provider's instructions**.
- **Ensure human oversight** by competent and trained personnel.
- **Verify the quality of input data** used by the system.
- **Monitor operation** and report any serious incident to the provider and competent authorities.
- **Conduct a Fundamental Rights Impact Assessment (FRIA)** if the entity is public or provides essential public services.
- **Keep logs** generated automatically by the system for the required duration.

For organizations subject to GDPR, the FRIA complements the Data Protection Impact Assessment (DPIA). The provider's documentation then serves as a basis for conducting this impact assessment.

## Article 50: Transparency obligations for all AI systems

Article 50, applicable from August 2, 2026, concerns **a wide range of AI systems**, regardless of their risk level. Four use cases are targeted:

### AI systems interacting with humans

Any system designed to converse or interact with natural persons (chatbots, voice assistants, conversational agents) must **clearly inform the user** that they are interacting with an AI, unless it is obvious.

### Generation of synthetic content

Providers of AI generating audio, image, video, or text content must ensure that these productions are **marked in a machine-readable format** and recognizable as artificial. A Code of Practice on labeling is expected in its final version from the AI Office by June 2026.

### Emotion recognition and biometric categorization

Deployers of emotion recognition or biometric categorization systems must **inform the individuals concerned** and comply with the GDPR for data processing.

### Deepfakes

AI producing deepfakes (images, audio, video) imposes a **disclosure obligation**: the content must be clearly labeled as artificially generated or modified. Exceptions exist for certain artistic, satirical, or criminal investigation uses.

## Sanctions for non-compliance with the AI Act

The sanctions regime, effective August 2, 2026, provides for:

- **35 million euros or 7% of global annual turnover** for violation of prohibited practices (Article 5) — already applicable since February 2025.
- **15 million euros or 3% of global annual turnover** for failure to comply with obligations related to high-risk systems (documentation, CE marking, risk management, etc.).
- **7.5 million euros or 1% of global annual turnover** for failure to comply with transparency obligations.

Adaptations exist for SMEs and start-ups, but the financial and operational risk remains significant. Beyond fines, non-compliance can lead to a ban on commercialization and major reputational consequences.

## Preparing for the deadline: 6 actions to take before August 2026

Time is running out. Here is a concrete roadmap to anticipate compliance:

1. **Inventory all your AI systems**: Identify those you develop, import, or use, including third-party solutions embedding AI (scoring, automation, recommendation).
2. **Classify each system**: Evaluate their risk level according to the regulation. The [free compaia diagnostic](https://compaia.eu/diagnostic) helps you complete this step quickly.
3. **Determine your role**: Provider, deployer, importer, or distributor? Your [obligations](https://compaia.eu/obligations) vary depending on your position in the value chain.
4. **Draft technical documentation**: For high-risk systems, compliance with Annex IV is mandatory. Prioritize the most critical use cases.
5. **Organize AI governance**: Appoint those responsible for human oversight, train your teams in [AI culture](https://compaia.eu/glossaire), and define your monitoring and incident management procedures.
6. **Prepare for conformity assessment**: Depending on the type of system, the assessment may be internal or require a notified body. Anticipate audit timelines.

## Systems already in service: What does Article 111 provide?

For high-risk AI systems already marketed or used before August 2, 2026, the rule is as follows:

The regulation only applies if the system undergoes **a significant change in design** after that date. If the system remains unchanged, it is not immediately subject to the new obligations. However, systems used by public authorities must comply by August 2, 2026, even without modification.

To follow all deadlines and organize your compliance, consult the [full AI Act timeline](https://compaia.eu/echeancier-ai-act) on compaia.

## Official source
- [Source](https://www.aiacto.eu/fr/blog/ai-act-aout-2026-obligations-systemes-ia)
