EU AI Act guide · updated 2 August 2026

August 2, 2026: what just became enforceable under the EU AI Act

On 2 August 2026, the obligations for high-risk AI systems listed in Annex III of Regulation (EU) 2024/1689 — the EU AI Act — became applicable, together with the penalty regime that gives them teeth. The preparation period is over: from this date, national market-surveillance authorities can demand documentation, order corrective action, and fine non-compliance.

What exactly is enforceable now

The Act has been rolling out in stages since it entered into force on 1 August 2024:

  • Since 2 February 2025 — the Article 5 prohibitions: manipulative techniques, social scoring, untargeted facial-image scraping, emotion recognition at work and school, and the other banned practices.
  • Since 2 August 2025 — duties for general-purpose AI model providers (Articles 53/55) and the governance structure around the AI Office.
  • Since 2 August 2026 (now) — the full high-risk regime for Annex III systems: risk management, data governance, Annex IV technical documentation, logging, human oversight, conformity assessment and registration for providers; Article 26 duties for deployers; Article 50 transparency duties; and the Article 99 penalty tiers behind all of it.
  • By 2 August 2027 — high-risk rules extend to AI embedded in Annex I regulated products (medical devices, machinery, vehicles and the rest).
The penalty tiers now live: up to €35M or 7% of global turnover for prohibited practices, €15M or 3% for breached high-risk, transparency or GPAI obligations, and €7.5M or 1% for supplying misleading information to authorities — whichever is higher. Full breakdown in the penalty guide.

Who is exposed today

Three groups should treat this week as a deadline that has already passed:

  • Providers of Annex III systems — anyone selling or operating AI for recruitment and worker management, credit scoring, insurance pricing (life/health), education, essential services, biometrics, critical infrastructure, law enforcement, migration or justice. If that is you, the Annex IV documentation must exist before the system is on the EU market.
  • Deployers of vendor AI — companies that merely use high-risk AI bought from vendors. Article 26 puts its own obligations on them, and vendor compliance does not transfer. Details in the deployer guide.
  • Everyone shipping AI-facing features — chatbots, synthetic media and emotion-recognition features carry Article 50 transparency duties regardless of risk tier.

The first 30 days: a sane response

The wrong response is a six-month consultancy engagement scoped in a panic. The right response is a triage sequence:

  • Inventory every AI system you build, embed or deploy — including vendor tools in HR, finance and support.
  • Classify each one against Article 5, Annex III and Article 50. Most SaaS products land in the transparency tier; the point is being able to show that conclusion.
  • Document — for high-risk systems, start the Annex IV skeleton now; for everything else, keep the classification record that proves you looked.
  • Remediate in order of exposure — human oversight and logging gaps first; they are what an authority asks about in week one.

Start with step one: classify a system in 10 minutes

The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.

Run the free assessment →

The companies that handled GDPR well in 2018 were not the ones that spent the most — they were the ones that could produce a defensible paper trail quickly. The AI Act is the same movie. Being able to show a dated, article-referenced classification for every system is 80% of a calm first conversation with a regulator.

Frequently asked questions

Did the whole EU AI Act become enforceable on 2 August 2026?

No — it applies in stages. Prohibited practices have been banned since 2 February 2025 and GPAI model duties since 2 August 2025. What changed on 2 August 2026 is that the high-risk obligations for Annex III systems became applicable together with the penalty regime, so national authorities can now fine breaches. High-risk rules for AI embedded in regulated products under Annex I follow by 2 August 2027.

We're not an EU company — are we affected?

Very likely, if your AI touches the EU. The Act applies extraterritorially: to any provider placing an AI system on the EU market and to providers and deployers whose system's output is used in the EU (Article 2). This is the same reach that made GDPR a de facto global standard.

What should we do first?

Inventory and classify. You cannot know your obligations until every AI system you build or deploy is mapped to its risk tier — prohibited, high-risk, transparency-only or minimal. Classification of a single system takes about 10 minutes with a structured assessment; the gap report then tells you what to fix in what order.

Will regulators really fine anyone this early?

Early enforcement typically starts with information requests and corrective orders rather than headline fines — but the exposure exists from day one, and GDPR's pattern is instructive: authorities built cases during the first year and the fines followed. The cheapest moment to close gaps is before the first letter arrives.

Where does your AI system actually stand?

The free AnnexWise assessment classifies a system in about 10 minutes — risk tier, open obligations and a gap report, with article references throughout. It runs in your browser; answers never leave your device.

Run the free assessment →

Keep reading

AnnexWise is compliance software, not a law firm; this guide is general information about Regulation (EU) 2024/1689, not legal advice for your situation. Verdict logic is documented on the methodology page.