JournalAugust 10, 202618 min read

The EU AI Act in plain language: what applies from 2 August 2026, and to whom

Which obligations apply now, what was postponed to 2027, who has to do what, the fines involved, and why Romanian authorities cannot yet impose AI Act penalties.

On 2 August 2026, the transparency obligations in Article 50 of the EU AI Act started to apply — the part that affects most ordinary companies. In the same weeks, the press was reporting that the AI Act had been postponed. Both statements are true — but about different things, and the confusion between them has left a lot of companies believing that none of it concerns them.

This guide separates the two. It opens with the essentials, in five lines. The rest is for readers who want the detail.

If that was all you needed, you are done. From here on, it is detail.

What the AI Act actually is

It is a European regulation — Regulation (EU) 2024/1689 — setting rules for artificial-intelligence systems used in the European Union. It was amended in July 2026 by a second regulation, known as the Digital Omnibus.

Three things worth understanding about how it works:

It applies directly. Being a regulation rather than a directive, it does not need to be written into national law to have effect. A directive tells member states what result to achieve and leaves them to draft their own law; a regulation is the law. The obligations exist for companies in any member state regardless of what their parliament does.

It does not divide the world into "AI companies" and everyone else. It divides by role — who builds the system and who puts it to use — and by how risky the use is. A company that merely uses a tool it bought has obligations too, just fewer of them.

It applies in stages. That is the source of all the confusion, which is why the next section is a calendar.

The real calendar: what applies now, what moved

  1. 1 Aug 2024

    The regulation enters into force

    Past

    Every deadline below is counted from this date.

  2. 2 Feb 2025

    Prohibited practices and AI literacy

    Applies

    Social scoring, subliminal manipulation, exploitation of vulnerabilities and certain biometric uses are banned. In parallel, companies must take measures so that the people working with AI understand what they are using.

  3. 2 Aug 2025

    General-purpose models and the penalty regime

    Applies

    Obligations for the providers of the large models everyone builds on. The articles on penalties became applicable at the same time.

  4. 2 Aug 2026

    Transparency — Article 50 starts to apply

    Applies now

    Chatbots must identify themselves. Generated content must be marked. Deepfakes must be disclosed. This is the part that affects most ordinary businesses.

  5. 2 Dec 2026

    Marking grace period ends — and two new prohibitions begin

    Coming

    Generative systems placed on the market before 2 August 2026 have until then to implement machine-readable marking; that obligation only, the rest already applied. The same date makes applicable two prohibitions added by the July amendment: AI systems that generate non-consensual intimate imagery, and systems that generate child sexual abuse material. Both sit in the highest penalty band.

  6. 2 Feb 2027

    Detection tools become interoperable

    Coming

    Signatories of the Code of Practice commit that by this date their markings can be verified from the outside — through a public standardised API, a readable signpost embedded in the content, a shared solution run by a consortium, or an equivalent.

  7. 2 Aug 2027

    General-purpose models already on the market

    Coming

    Models placed on the market before 2 August 2025 must be brought into compliance by this date. This concerns model providers, not the companies using them.

  8. 2 Dec 2027

    Stand-alone high-risk systems

    Postponed

    Recruitment, student assessment, creditworthiness, access to essential services. The original date was 2 August 2026 and it moved by more than a year. This is the postponement that made the headlines.

  9. 2 Aug 2028

    AI embedded in regulated products

    Postponed

    Medical devices, machinery, toys, vehicles — products that already had European safety rules and now have an AI component inside them.

Does it concern you? The short answer, by situation

Pick your situation

Seven common cases. Every answer is on the page — the buttons only take you straight to yours.

Yes, this concerns you.

It has to be clear that the visitor is talking to a program, not a person — a visible note at the first interaction.

If the bot was bought from a vendor, the design obligation sits with them. In practice, though, the Commission's guidance allocates responsibility according to who decided to deploy the system and who determines how it is actually used — which is often you.

What is banned outright

This part gets discussed least, even though it carries the largest fine and has applied since February 2025. There is no grace period, no carve-out for small companies, and the cap is €35 million or 7% of worldwide turnover.

Among the prohibited practices:

  • manipulation through subliminal or deceptive techniques that distorts a person's behaviour in a way likely to cause significant harm;
  • exploiting vulnerabilities of age, disability or socio-economic situation;
  • social scoring — classifying people by behaviour or personal characteristics, with detrimental effects in contexts unrelated to the data collected;
  • predicting the risk that a person will commit a crime, based on profiling or personality traits;
  • untargeted scraping of facial images from the internet or CCTV to build recognition databases;
  • emotion recognition in the workplace and in education, outside medical or safety reasons;
  • biometric categorisation that infers race, political opinions, trade-union membership, religious beliefs or sexual orientation;
  • real-time remote biometric identification in public spaces for law enforcement — with narrowly listed exceptions.

Two of these reach ordinary companies more often than you would expect: emotion recognition on employees — including the automated "tone" or "attitude" scores built into some call-centre platforms — and biometric categorisation of customers. If a vendor is selling you a feature that sounds like either, ask precisely what it measures.

From 2 December 2026, two further prohibitions apply: AI systems that generate non-consensual intimate imagery, and systems that generate child sexual abuse material.

The four transparency obligations

Article 50 is the part that applies from 2 August 2026. It applies regardless of the system's risk level. The European Commission adopted interpretive guidelines on 20 July 2026 — not binding, but the reference.

1. People must know they are talking to a machine

Systems intended to interact directly with people must be designed so that the person is informed they are dealing with an AI system.

Exception: where it is obvious to a reasonably well-informed, observant and circumspect person, taking into account the circumstances and the context of use. The test is measured against the audience you are actually addressing. Also outside the duty: systems that merely support an internal decision, where the person never interacts with them.

In practice: a short note at the start of the conversation. Not a legal paragraph — one sentence anybody can read.

Copy this, if you have a chatbot

You are talking to an automated assistant, not a member of the team.

The law requires the disclosure to be clear and to reach the person no later than the first interaction. The rest is our implementation advice: keep it visible without a click, and put the route to a person next to it — an address or a button.

2. Generated content must be marked machine-readably

The outputs of generative systems — audio, image, video and text — must be marked as artificially generated or manipulated, in a format a program can read. This is not visible text on the image; it is a marking inside the file — signed metadata or an imperceptible watermark.

Who carries it: the provider of the system. For most companies, that means the vendor you buy the tool from, not you.

Exceptions: assistive functions for standard editing, and outputs that do not substantially alter the input. The guidelines further exclude machine-to-machine communication, intermediate outputs inside closed-loop industrial workflows, machine translation, source code and very short outputs.

Special deadline: systems on the market before 2 August 2026 have until 2 December 2026 for this obligation.

3. Emotion recognition and biometric categorisation must be announced

Anyone exposing people to a system that reads their emotions or classifies them on biometric criteria — physical or behavioural traits, from face to voice — must inform them.

For most ordinary businesses this does not trigger. It becomes relevant in retail with video analytics, in call centres with voice analysis, and in security. Note the prohibited-practices section, though: with employees, some of these uses are not announced, they are stopped.

4. Deepfakes and public-interest text

Deepfakes. A deployer publishing AI-generated or AI-manipulated image, audio or video that resembles real people, objects, places or events and would falsely appear authentic must disclose it. Intent to deceive is not required. The test is judged against the audience the material actually reaches — the threshold is lower where children are among them.

Artistic, satirical or fictional works get a partial exception: the disclosure is made in a way that does not spoil the work. The final guidelines narrowed it, though — content that is exclusively informative or commercial cannot rely on it. A brand campaign does not become a "work" by being stylised.

Copy this, for images

If the image was generated from scratch

AI-generated image.

If it is a real photograph that AI altered

Image altered using AI.

The regulation treats generated content and manipulated content differently, so the label has to say what actually happened. Place it next to the image, in the caption or on it — not buried in metadata where nobody sees it. For video, at the start or in a persistent corner label.

Text. AI-generated text published to inform the public on matters of public interest must be disclosed — unless it went through human review or editorial control and somebody takes responsibility for it. This exception removes most ordinary company content from scope.

Provider or deployer: the role decides everything

The regulation assigns obligations by role, not by company size.

RoleWhat it means
ProviderDevelops an AI system — or has one developed for it — and places it on the market under its own name or trademark, for payment or free of charge.
DeployerUses an AI system in a professional capacity, under its own authority.
ImporterEstablished in the EU, places on the market a system carrying a non-EU company's name.
DistributorAny other actor in the chain making the system available.

Most companies are deployers. Their obligations are the third and fourth limbs of Article 50, plus AI-literacy measures for staff — making sure the people using the tools understand what those tools do and where they go wrong.

The final text deliberately dropped the word "user" in favour of "deployer", so that the company putting a system into service is not confused with the person sitting in front of the screen. Language versions follow the same shift, which matters if you search the text for a role and cannot find it.

What "high risk" actually means

The term is everywhere and rarely explained. A system is high risk by one of two routes:

Annex III — listed domains. Biometrics, critical infrastructure, education and learner assessment, employment and worker management (including CV screening), access to essential public and private services — among them creditworthiness assessment and life and health insurance pricing — law enforcement, migration and asylum, justice and democratic processes.

Annex I — a safety component in a regulated product. The system is part of a product that already goes through a European conformity assessment: a medical device, machinery, a toy, a lift, a vehicle.

There is a release valve: a system in a listed domain is not high risk if it performs only a narrow procedural task, improves the result of a previously completed human activity, detects patterns without replacing human assessment, or performs a preparatory task. The exception falls away entirely if the system profiles natural persons.

The practical difference is large. High risk means a risk-management system, data governance, technical documentation, logging, human oversight, conformity assessment and registration in a European database. Transparency means one sentence and a label.

Using American tools does not get you out

A company in the EU using an American AI tool is a deployer and falls under the regulation, because it is established in the Union. The regulation also reaches providers and deployers outside the EU where the output produced by the system is used in the Union.

What is excluded

National security and military use. Scientific research. Testing before placing on the market — except testing in real-world conditions. Purely personal, non-professional use. Free and open-source software has an exception — but it falls away for high-risk systems, prohibited practices and the transparency obligations.

Small companies have no blanket exemption

There is no blanket SME exemption. There are mitigations: simplified technical documentation, priority access to the regulatory sandboxes run by authorities, reduced conformity-assessment fees. Almost all of them matter only if you are a provider of a high-risk system. For transparency they change nothing. The one real benefit is on fines.

The fines

Levied by national market-surveillance authorities.

What you breachCapHow it is calculated
Prohibited practices€35m or 7%Of worldwide annual turnover. The higher figure applies.
Other obligations, including transparency€15m or 3%The higher figure applies.
Incorrect information to authorities€7.5m or 1%The higher figure applies.
The same breaches by an SME or start-upthe lower figureThe cap inverts in the small company's favour.

That last line matters more than it looks. For a small company the cap is not "€15 million or 3%, whichever is higher" — it is whichever is lower. For a company turning over one million euro, that is the difference between €15 million and €30,000. The July 2026 amendment extended the lower cap to small mid-caps as well: companies that are not SMEs, employ fewer than 750 people, and have either annual turnover of no more than €150 million or an annual balance-sheet total of no more than €129 million.

The amount takes into account gravity and duration, the number of people affected, previous penalties, the size of the company, the benefit gained and the degree of cooperation.

Separately, the European Commission can fine providers of general-purpose models directly, also from 2 August 2026, and the AI Office can impose periodic penalties of up to 5% of average daily turnover.

The situation in Romania

There is an important Romania-specific point here, and it is a useful illustration of what happens across the Union when a member state is late.

There is no national implementing law. No act, no ordinance, no government decision. What exists is a government memorandum of 12 March 2026 designating the authorities — an internal instrument, which cannot confer powers of inspection or sanction.

The authorities proposed in it, among others: ANCOM for market surveillance and as single point of contact with the European institutions, ADR as the authority assessing and designating conformity-assessment bodies, ASF and BNR for the financial sector, the data-protection authority for biometrics, justice and democratic processes, plus the labour inspectorate, the medicines agency and the naval authority for systems embedded in products.

On 24 July 2026, ANCOM stated publicly that the authorities are still drafting the national framework and will be able to verify and sanction only after the national act enters into force.

What is currently misunderstood

Every claim below is circulating actively, in the press or in consultancy material.

The AI Act was postponed.
Only the high-risk part, which moved to 2 December 2027 and 2 August 2028. Transparency arrived on schedule on 2 August 2026, and the prohibited practices have applied since February 2025. A lot of published guidance still carries the old dates.
The amendment that moved the deadlines is still a proposal.
No. It was published on 24 July 2026 and entered into force on 27 July 2026.
Nothing applies in Romania, because there is no national law.
False. The regulation applies directly. What is missing is only the mechanism by which a Romanian authority can issue fines.
All AI-written text has to be labelled.
No. Only text published to inform the public on matters of public interest, and only where it did not go through human editorial control.
Putting your company's name on an AI system automatically makes you a provider.
Only for high-risk systems. Otherwise you become a provider by developing the system — directly or through someone else — and placing it on the market under your own name. Rebranding an off-the-shelf tool does not make you a provider, though it can still leave you answerable for transparency, on a different basis.
We only use ChatGPT, so it does not concern us.
You are a deployer — the deployer obligations and the AI-literacy duty apply.
Open-source software is exempt.
The exemption falls away for high-risk systems, prohibited practices and the transparency obligations.
The AI-literacy requirement was scrapped.
It was softened, not scrapped: from “ensure a sufficient level” to “take measures to support the development of”. The duty stands.
Limited risk is a legal category in its own right.
It does not exist as such in the regulation. The transparency obligations cut across every risk level.
SMEs are exempt.
No exemption. Only procedural mitigations and the lower fine cap.

What to actually do

  1. Take an inventory: where are you actually using AI?

    A chatbot, text or image generation, CV filtering, shop recommendations, call analysis. The inventory can surface uses the team did not think of as AI. Without that list you cannot answer any of the questions below.

  2. Check whether any use lands in the prohibited category.

    Automated emotion or attitude scores on employees, and biometric categorisation of customers, can arrive by accident, inside features a vendor switched on. No label fixes this one: the use stops.

  3. Establish your role for each one: provider or deployer?

    If the tool is bought and used as it comes, you are a deployer. You become a provider by developing it yourself and placing it on the market under your own name, or by changing its purpose so that it becomes high risk.

  4. Check that the chatbot says it is a bot.

    A straightforward compliance check and usually a simple fix. One sentence, at the first interaction, visible without anyone having to dig for it. The wording is above, ready to copy.

  5. Check the images you publish from 2 August 2026 onward.

    Ordinary adjustments are fine. Images where elements were added or removed, and which look real, need to be disclosed. For anything generated before 2 August 2026 there is no retroactive duty.

  6. Write down who takes responsibility for the text.

    The editorial-control exception only works if a person genuinely reviews and answers for it. A written process, however short, is worth more than an intention.

  7. If you work with vendors or clients, put the role in the contract.

    Who is provider and who is deployer for each system delivered. It does not change what the law says, but it settles between you who fixes and who pays. It is a simple contractual clarification — revisit it if roles, vendors or the way the system is used change.

  8. Do a minimum of internal training.

    The AI-literacy duty has applied since February 2025 and does not require certification or prescribe a single threshold. As a practical starting point: documented training tailored to the tools you actually use, rules for data that must not go into external services, and a clear escalation point for new cases. The Commission says explicitly that measures should reflect your role, risks and context — there is no single recipe.

  9. If you touch recruitment, credit or assessment of people, put December 2027 in the calendar.

    The obligations specific to high-risk systems do not apply yet. Until then the ones already in application remain relevant: prohibited practices, AI literacy and, where applicable, transparency. From 2 December 2027 you add documented human oversight, informing the people assessed, logs and conformity assessment. Companies that start a year ahead are not improvising in the last month.

What comes next

No harmonised standards for the transparency obligations have been cited in the Official Journal yet — meaning the technical specifications that, once followed, give you a presumption of conformity. In their place there is a Code of Practice, published on 10 June 2026 and found adequate by the Commission and the European AI Board on 8 and 9 July 2026, with roughly 190 signatories by the end of July. It is not binding, but following it is a strong argument.

The Code describes three marking mechanisms: cryptographically signed, time-stamped, tamper-evident provenance metadata — the main standard used in practice for this kind of provenance being C2PA, also known as Content Credentials — imperceptible watermarking that survives format conversion, and, optionally, content fingerprinting with logging.

How this guide is kept current

The rules are still evolving: interpretive guidance, standards and national decisions keep arriving. This guide is updated as they do. From the first revision onward, the date of the last update appears next to the publication date at the top of the article, and the full history stays here.

Change log:

  • 10 August 2026, revision 2 — corrections following an external editorial audit. Entry into force of the regulation is now kept separate from the dates on which obligations become applicable. The Romania claim is narrowed to Romanian authorities and AI Act penalties. The implied universal threshold for AI literacy, and the "nothing to do now" advice for uses that become high risk in 2027, are gone. Labels for generated and for altered content are now separate. The small mid-cap definition is complete.
  • 10 August 2026 — first publication. Checked against the consolidated text of Regulation (EU) 2024/1689, the European Commission's transparency guidelines of 20 July 2026, ANCOM's statement of 24 July 2026, and the Code of Practice on transparency.

If you spot something outdated or wrong, write to us — we will correct it and note the change here.

Sources

The full text of Regulation (EU) 2024/1689, amended by Regulation (EU) 2026/1744, in force since 27 July 2026. The application timeline, the transparency guidelines and the Code of Practice, published by the European Commission. The text of Article 50 on the Commission's AI Act Service Desk, together with the transparency-obligations FAQ and the AI-literacy Q&A. ANCOM's statement of 24 July 2026 on the state of implementation in Romania.

This guide is information, not legal advice. For your company's specific situation, read the text of the regulation or ask a lawyer.

Why we wrote it

We have been building digital products since 2017, we use artificial intelligence daily in our own work, and we run our own products in production. When the transparency obligations started to apply we went looking for a clear explanation and found either legal texts that are hard to read or articles repeating, wrongly, that everything had been postponed.

So we wrote one, with the sources in plain view. If you have a project with AI in it and you want to know which obligations fall on you, write to us.

Related work