If you research the EU AI Act right now, you’ll find plenty of outdated material: many vendors still advertise 2 August 2026 as the hard deadline for high-risk AI. That is no longer accurate. The AI Omnibus entered into force on 27 July 2026 and pushes exactly those obligations well into the future. What has actually applied since 2 August 2026, meanwhile, tends to get lost in the deadline panic.
The deadlines at a glance (as of 10 August 2026)
| Obligation | Applies from | Status |
|---|---|---|
| Existing prohibited AI practices (Art. 5) | 2 February 2025 | in force |
| AI literacy (Art. 4) | 2 February 2025 | in force; simplified by the Omnibus |
| Obligations for GPAI models placed on the market from this date | 2 August 2025 | in force |
| Transparency duties (Art. 50): including chatbots, deepfakes and certain AI content | 2 August 2026 | in force |
| Enforcement of applicable GPAI, prohibition and transparency duties | 2 August 2026 | in force |
| New Omnibus prohibitions, including certain non-consensual intimate content and child sexual abuse material | 2 December 2026 | apply from this date |
| Transition for machine-readable marking by certain systems already on the market before 2 August 2026 | 2 December 2026 | limited transition under Art. 50(2) |
| Obligations for GPAI models placed on the market before 2 August 2025 | 2 August 2027 | transition ends |
| High-risk systems in specified use areas (Annex III) | 2 December 2027 | postponed via Omnibus |
| High-risk AI embedded in regulated products (Annex I) | 2 August 2028 | postponed via Omnibus |
Key reasons for the postponement were delays involving harmonised standards, conformity assessment and governance structures. The delay is preparation time, not an all-clear — the obligations themselves remain.
Article 4 still requires providers and deployers to support appropriate AI literacy measures. It does not require a guaranteed, identical competence level for every person; scope and depth depend on role, prior knowledge, context and risk.
What has counted since 2 August 2026
For many business applications, Art. 50 is relevant irrespective of whether the system is classified as high-risk: people generally need to be informed when they are interacting with an interactive AI system such as a chatbot, unless this is already obvious. Deployers of emotion-recognition or biometric-categorisation systems must inform the people affected. Providers of generative systems must add machine-readable markings to certain synthetic content. Deployers generally need to visibly disclose deepfakes; tailored rules apply to artistic, satirical and comparable works. For AI-generated or manipulated public-interest text, disclosure applies unless substantial human review or editorial control has taken place and a person or organisation holds editorial responsibility. For certain systems already placed on the market before 2 August 2026, only the marking and detection duty under Article 50(2) has a transition until 2 December 2026. Further exceptions and the allocation of duties between provider and deployer need to be checked for the specific use case.
Germany’s supervisory structure is now defined by law. The implementation act that entered into force in late July 2026 gives the Bundesnetzagentur a central role in market surveillance, coordination and innovation support.
And the GDPR?
It continues to apply unchanged, and in practice it is the more common stumbling block: data minimisation, purpose limitation, a deletion concept, processing agreements — and the question of which data an AI system needs to see at all. Compliance and good architecture pull in the same direction here: clear boundaries, verifiable decisions, no data sprawl.
What this means for your AI project
- Determine the risk class early. Many common business applications may fall outside the high-risk categories; purpose and deployment context are decisive. Documenting the assessment reduces uncertainty and retrofit costs.
- Do an Art. 50 check. Customer-facing chatbot, deepfake or AI-generated public-interest content? Clarify which disclosure has applied since 2 August 2026, whether a transition applies — and whether you act as provider or deployer.
- Use the extended runway. If you are planning a high-risk system covered from 2 December 2027, you now have time for proper preparation: AI inventory, risk classification, governance — instead of a scramble at the last minute.
- Don’t forget the GDPR behind the AI Act. The two frameworks interlock; the data-protection question often decides architecture and model choice (EU hosting, on-premise).
For a first read on where your project stands, try our AI self-check — six questions, no registration. How we consider data protection and EU AI Act requirements when building AI applications is explained on our AI & LLM applications page.
We clarify the risk class before the first line of code, keep the human in the decision, and host fully in the EU on request. That turns “compliant” from an afterthought patch into part of the design.
Sources: European Commission: AI Omnibus enters into force · European Commission: Article 50 guidelines · European Commission: Article 50 FAQ · EU AI Act Service Desk: current timeline · EUR-Lex: Regulation (EU) 2026/1744 · German Federal Government: implementation of the AI Act. Not legal advice — consult your legal counsel for a binding assessment of your case.