# AI Act: The essentials for AI compliance by August 2, 2026

> On August 2, 2026, the AI Act makes compliance mandatory for high-risk AI systems (Annex III) as well as compliance with transparency rules (Article 50). Both providers and deployers must comply to avoid significant sanctions, subject to a possible postponement to December 2, 2027, if the Digital Omnibus is adopted.

- Tags: ai act août 2026, obligations ai act août 2026, haut risque ia, conformité IA, transparence IA, sanctions AI Act, fournisseurs IA, déployeurs IA
- Main keyword: ai act août 2026

## Key points

- Unless postponed by the Digital Omnibus, August 2, 2026, is the pivot date for the application of high-risk AI obligations (Annex III) and transparency requirements (Article 50).
- Eight families of use cases are considered high-risk: biometrics, critical infrastructure, education, employment, essential services, law enforcement, justice, and border control.
- Providers must develop technical documentation (Annex IV), manage risks (Art. 9), obtain CE marking, and register their systems in the European database.
- Deployers must establish human oversight, archive logs, inform affected individuals, and, in the public sector, conduct a fundamental rights impact assessment.
- Any interactive AI or AI generating content (chatbots, deepfakes) must comply with transparency obligations, even if it is not considered high-risk.
- Non-compliance with rules for high-risk AI exposes entities to sanctions of up to 15 million euros or 3% of global annual turnover.

## Introduction

As August 2, 2026, approaches, the legal framework for artificial intelligence in Europe is about to reach a major milestone. On that day, the AI Act regulation (EU 2024/1689) reaches its turning point: compliance becomes mandatory for high-risk AI systems and transparency duties become effective. For companies and public bodies, it is no longer a matter of anticipating but of being ready.

Before detailing the new obligations, it should be noted that the Digital Omnibus, under discussion in the European Parliament, could postpone some of these rules to December 2, 2027. However, in the absence of an official publication, August 2, 2026, remains the reference date. The requirements described here are based on current legislation.

## Content

## Progressive deployment of the AI Act regulation

The AI Act regulation was not applied all at once, but in stages, starting in August 2024:

- **August 2024**: Launch of the regulation's progressive application calendar.
- **February 2, 2025**: Entry into force of the ban on unacceptable risk practices (Article 5), such as social scoring, subliminal manipulation, or certain real-time biometric processing.
- **February 2, 2025**: Obligation for providers and deployers to ensure AI literacy (Article 4), i.e., the competence of their teams regarding AI issues.
- **August 2, 2025**: Application of rules for general-purpose AI models (GPAI, Articles 51-56), affecting in particular providers of LLM-type models.

This phasing is intended to allow the concerned structures to gradually adapt to the new requirements, but the August 2026 deadline now imposes a sustained pace.

## What changes as of August 2, 2026

### High-risk AI systems (Annex III)

The main upheaval of August 2026 concerns AI systems identified as high-risk. Annex III of the regulation lists eight major sectors where AI is automatically considered as such:

- **Biometrics**: remote recognition, biometric categorization, emotional analysis.
- **Critical infrastructure**: management of electricity, water, gas, and transport networks.
- **Education and training**: AI affecting access to education or learner assessment.
- **Employment and human resources**: recruitment tools, candidate assessment, or performance monitoring.
- **Essential services**: credit scoring, insurance, management of social benefit applications.
- **Law enforcement**: detection of criminal profiles, assessment of evidence, or recidivism risks.
- **Justice and democratic processes**: assistance in judicial decision-making.
- **Border control**: risk assessment and document verification during border crossings.

> If your entity develops or operates an AI system in one of these areas, Chapter III of the AI Act regulation applies to you as of August 2, 2026, whether the solution is internal or from an external provider.

### Transparency: expanded obligations (Article 50)

Article 50 imposes transparency rules on all AI systems interacting with humans or producing generated content:

- **Conversational agents and chatbots (Art. 50§1)**: any interaction with a human must specify that it is an AI, unless it is obvious (professional use or fictional character).
- **Deepfakes and altered content (Art. 50§4)**: audio or visual creations simulating real people must be clearly labeled.
- **Emotional recognition (Art. 50§3)**: any person subjected to such analysis must be warned.

Note: the obligation for machine-readable labeling (Article 50§2) might only be required from November 2, 2026, depending on discussions regarding the Digital Omnibus. The other provisions of Article 50 remain effective as of August 2026.

## Consequences for AI system providers

If you offer a high-risk AI system on the market, you are qualified as a **provider** (within the meaning of Article 3). From August 2026, several duties apply:

- **Complete technical documentation (Art. 11, Annex IV)**: detailed presentation in nine sections (AI description, architecture, data management, risk management, performance, instructions for use, post-market monitoring, quality management, declaration of conformity).
- **Risk management (Art. 9)**: continuous process of identification, assessment, and mitigation of risks throughout the AI system's lifecycle.
- **Data governance (Art. 10)**: justification of the relevance, representativeness, and bias analysis of the datasets used for training.
- **Human oversight (Art. 14)**: ensuring the possibility for a human operator to monitor, understand, and take control of the system's decisions.
- **CE marking and declaration of conformity (Art. 47 to 49)**: certifying that the system meets the regulation's requirements before any market placement.
- **Registration in the European database (Art. 71)**: obligation to reference the system before its commissioning.

The creation of this technical documentation can require between 40 and 80 hours for complex systems. [compaia offers a structured methodology](https://compaia.eu/assistant-vocal-ai-act) to accelerate the development of this documentation.

## Duties of high-risk AI deployers

If you integrate and use a high-risk AI developed by a third party, you are considered a **deployer** (defined in Article 3). Your specific responsibilities are as follows:

- **Implementation of human oversight (Art. 26§2)**: establishing procedures allowing a competent person to monitor the system, interpret its results, and be able to intervene or stop the tool if necessary.
- **Log archiving (Art. 26§6)**: obligation to keep logs generated by the AI for at least six months.
- **Informing affected individuals (Art. 26§6 and Art. 50)**: any person affected by a decision resulting from a high-risk AI must be informed of this influence.
- **Compliance with provider instructions (Art. 26§1)**: the system must be used in accordance with its intended purpose, unless you assume the responsibility of a provider.
- **Fundamental Rights Impact Assessment (FRIA, Art. 27)**: such an assessment is required for public entities and certain essential service operators before any deployment.

## Sanctions provided for in case of non-compliance

Starting in August 2026, a graduated sanction regime applies:

- **Up to 35 million euros or 7% of global annual turnover** for prohibited practices (Article 5), already in effect since February 2025.
- **Up to 15 million euros or 3% of global annual turnover** for non-compliance with requirements related to high-risk systems.
- **Up to 7.5 million euros or 1% of global annual turnover** for providing inaccurate information to authorities.

Authorities take into account the size of the company, but no structure is totally exempt: proportionality applies, not exemption.

## Steps to take before August 2, 2026

To anticipate the deadline, here are the priority actions according to your profile:

1. **Map your AI**: identify those falling under Annex III, Article 50, or low risk. This step conditions all subsequent ones.
2. **Define your status**: are you a provider, a deployer, or both? Your role determines your specific obligations.
3. **Evaluate your SaaS providers**: ensure they are compliant, have the required documentation, and are referenced in the European database.
4. **Build a proof file**: even as a deployer, demonstrate human oversight and mastery of the tool.
5. **Inform your users**: adjust your legal notices and interfaces to integrate the transparency obligations of Article 50.

A [free online diagnostic](https://compaia.eu/diagnostic) allows you to quickly perform the first two steps and obtain a summary of your obligations.

## Summary of the regulatory calendar

- **August 2024**: Launch of the AI Act regulation deployment.
- **February 2, 2025**: Ban on unacceptable risk practices (Article 5) and obligation for AI literacy (Article 4).
- **February 2025**: Certain obligations enter into force.
- **August 2, 2025**: Rules applicable to general-purpose AI models (GPAI).
- **August 2, 2026**: Entry into application of requirements for all high-risk systems (Annex III) and transparency rules (Article 50).
- **August 2026**: Major compliance deadline.
- **March 18, 2026**: Date of the European Parliament's position on the Digital Omnibus.
- **November 2, 2026**: Possible postponement of machine-readable labeling (Art. 50§2).
- **August 2027**: Application to high-risk systems integrated into already regulated products (Annex I).
- **December 2027**: Potential postponement date if the Digital Omnibus is adopted.
- **December 2, 2027**: Alternative deadline depending on the adoption of the Digital Omnibus.

For a complete follow-up of deadlines, refer to the [official AI Act timeline](https://compaia.eu/echeancier-ai-act).

August 2, 2026, is not a symbolic formality: it is an unavoidable legal milestone. Organizations that anticipate this date will strengthen their position during audits, reassure their partners, and enhance their compliance in an environment where trust in AI is becoming a decisive market criterion.

## Official source
- [Source](https://www.aiacto.eu/fr/blog/ai-act-ce-qui-change-2-aout-2026)
