Salta al contenuto principale
Lympha technologies

Governance

AI Act: what actually kicks in on 2 August 2026 (and why it affects you even if you "don't do AI")

The AI Act postponement covers only high-risk systems: on 2 August 2026 the transparency obligations of Article 50 still kick in (chatbots that declare themselves, synthetic content marked, deepfakes labelled), along with penalties and supervisory a…

Updated 12 July 2026 — on this dossier two weeks can change the picture: check the date before trusting it, and for decisions rely only on EUR-Lex.

You've read everywhere that "the AI Act has been postponed to 2027". You've relaxed. Bad idea.

What has slipped is one part: the obligations on high-risk systems. Everything else is running, and 2 August 2026 — three weeks from now — brings the thing that really concerns you if you have a chatbot on your website, generate content with AI or have embedded a model in a product: Article 50, transparency. And there is an even more uncomfortable detail, which almost nobody writes about.

The postponement, technically, is not law yet

Let's reconstruct the sequence, because here the procedural details matter:

WhenWhat
19 Nov 2025The Commission proposes the AI "Digital Omnibus" (COM/2025/836)
7 May 2026Provisional agreement in trilogue
16 Jun 2026The European Parliament approves
29 Jun 2026The Council of the EU formally adopts
todaySignature and publication in the Official Journal of the EU (OJEU) are still missing

The amending regulation enters into force three days after publication in the Official Journal. Until that moment, the AI Act applies in its 2024 version, with the original timeline. Translation for decision-makers:

Anyone planning today on the new dates alone is reasoning on a text that is settled but not yet in force. Publication is expected by the end of July, precisely to land before 2 August: that is a well-founded expectation, not legal certainty.

The timeline, in layers

The most common mental error is to treat the AI Act as a single block that moves as one. It is not: it is a mosaic, and every tile has its own date.

Already in force (since 2025)

The prohibitions — social scoring, subliminal manipulation, exploitation of vulnerabilities — have been operational for over a year, with zero postponements. And there is the most ignored obligation in Europe: AI literacy — anyone using AI systems must understand how they work and where their limits lie, and know when a human eye is needed. It is also the cheapest to close: a documented training plan can be put in place in weeks, and the Digital Omnibus confirms it. Since 2025 the obligations for those releasing general-purpose models have also been in force; in Italy supervision of these sits with the ACN (Legge 132/2025, the Italian law on AI — the allocation of national competences is, however, still in flux: one to check with a lawyer).

2 August 2026 — the date that matters now

The postponement does not touch any of what follows. Article 50 imposes three distinct obligations, which are often conflated into one:

  • Systems that interact with people must declare themselves as AI. The customer-care chatbot must say it is a chatbot. Not "it's obvious anyway": it must say so.
  • Synthetic content must be marked in a machine-readable way — text, images, audio, video, with provenance metadata in open formats (in practice: C2PA / Content Credentials). The obligation falls on the provider of the generative system.
  • Deepfakes and texts of public interest must be visibly disclosed to the user. This falls on the deployer, i.e. whoever publishes.

Who needs to wake up now, in order of urgency: anyone with a chatbot or conversational assistant in production; e-commerce businesses generating product descriptions with a model; agencies, publishers and media outlets publishing generated or manipulated content; anyone reselling a product that embeds a generative model. This is not a big-tech issue: it is an issue for anyone who has put an LLM in a public-facing flow.

Also from 2 August: the national supervisory authorities become fully operational and most of the penalty provisions become applicable. Until now the AI Act was, for many, an academic exercise; from August it has someone knocking at the door. And the general rule applies: whatever is not expressly postponed, applies.

2 December 2026 — the detail almost nobody writes about

Generative systems already on the market before 2 August 2026 get four extra months to comply with content marking; those launched afterwards must be born compliant. The operational consequence everyone misses:

You need to know the date each system went into production, because that is what determines which deadline applies. If your AI inventory does not record "when it went into production", you cannot even say which regime you fall under.

The same date applies to the only point where the Omnibus tightens: two new prohibitions, on "nudification" apps (non-consensual intimate images of identifiable people) and on child sexual abuse material — with provider liability even where the output is reasonably foreseeable in the absence of technical safeguards. For anyone building image-generation tools this is a design requirement, not a line in a policy.

2027–2028 — the part that really is postponed (with a subtlety)

The high-risk obligations slip, but not to a fixed date: it is a conditional postponement. They kick in 6 or 12 months after the Commission confirms, by formal decision, that the technical standards are available; in the absence of that decision, two backstop dates apply anyway — 2 December 2027 for "standalone" high risk (recruitment, credit scoring, public services, education, critical infrastructure) and 2 August 2028 for high risk embedded in already regulated products (medical devices, for example). The reason for the postponement is that the European standards are running late. But the clock can restart sooner than expected: it is not an amnesty, it is a pause with the alarm already set. National regulatory sandboxes also slip by a year — the most questionable point of the package, because they were meant precisely for SMEs.

The picture in one table

DateWhatPostponed?
2 Feb 2025Prohibitions · AI literacyalready in force
2 Aug 2025General-purpose models · governancealready in force
2 Aug 2026Transparency (Art. 50) · penalties · authoritiesNO — it matters now
2 Dec 2026Marking for pre-existing systems · new prohibitionsnew deadline
2 Aug 2027National regulatory sandboxesyes (+12 months)
2 Dec 2027"Standalone" high riskyes, conditional
2 Aug 2028High risk embedded in regulated productsyes, conditional

What to do before August (not "by 2027")

  • 1 · Inventory of AI systems. A spreadsheet or a database: for every system in use, in development or being purchased — supplier, purpose, role (provider or deployer), date it went into production, data processed, risk class. It does not depend on the standards, it does not depend on the Official Journal: you do it today, and it is the prerequisite for everything else.
  • 2 · Classification. Prohibited / high risk / transparency / minimal. Watch the blind spot: AI used for CV screening, performance appraisal, task allocation, worker monitoring is high risk. Many companies have it inside their HR tools without knowing it.
  • 3 · Transparency — the only one with a real three-week deadline. Does the chatbot declare itself as AI? (It is one line of text in the first message, not a project.) Is generated content marked? Are deepfakes visibly labelled?
  • 4 · AI literacy. A documented training plan: an obligation already in force, low cost, high value as proof of diligence.
  • 5 · Don't wait for the standards to start on high risk. A full compliance journey takes on average 8–14 months, with the certification bodies already queuing. The postponement redistributes the work over time; it does not shrink its scope.

The first and second points, note, are not law: they are IT governance — inventorying, classifying, assigning responsibilities, measuring. If you already have a CMDB and orderly processes, you start with half the work done.

Five things you hear that are wrong

  • "The AI Act has been postponed." No: high risk has been postponed. The rest is running.
  • "The postponement is already law." Not yet, at the time of writing: publication in the Official Journal is still missing.
  • "It concerns those who develop AI." No: most of the obligations hit those who use other people's models.
  • "It's a big-tech thing." Article 50 concerns anyone with a chatbot or publishing generated output.
  • "I'll wait for the standards and then move." Inventory and classification do not depend on the standards. And the postponement is conditional: as soon as the Commission confirms, a six-month countdown starts.

The questions we keep being asked

We use ChatGPT or Copilot in the company: are we "providers"?

No, you are deployers (users). The obligations are lighter, but they exist: AI literacy, transparency towards the people concerned, use in line with the provider's instructions, no prohibited uses.

Is our support chatbot "high risk"?

Generally no: it is limited risk, with a transparency obligation (it must declare itself). It becomes high risk if it decides access to essential services or evaluates people.

If an article is written with the help of AI, must that be disclosed?

The Article 50 disclosure targets professional use, for deepfakes and content of public interest; personal, non-professional use is generally excluded. But when the content is monetised or serves to inform the public, the "personal" threshold falls away. It is a grey area: this calls for a lawyer, not a blog.

Does content marking (watermarking) actually work?

Honestly: it is an open problem. A watermark that breaks with a crop or a recompression protects nobody, and the robustness of current techniques is not a solved issue. The law mandates the marking; the technology to make it reliable is a work in progress. Better to know that before selling guarantees that cannot be kept.

Disclaimer (and where to start)

This is an explanatory piece — this is not legal advice: the picture is moving and, at the time of writing, the amending regulation had not yet been published in the Official Journal. For compliance decisions, rely on EUR-Lex and a qualified professional.

What we can say from our own trade is that the urgent part does not require lawyers: it requires a well-built inventory and a chatbot that introduces itself for what it is. These are the things we work on every day — in IT governance, in building AI assistants with verifiable sources within the client's perimeter, and in verifying technical safeguards, penetration testing of conversational agents included. If you want to work out where to start in the three weeks that remain, let's talk.


Sources.

  • Regulation (EU) 2024/1689 (AI Act) — the only authoritative source is EUR-Lex.
  • AI "Digital Omnibus" — proposal COM/2025/836, procedure 2025/0359(COD); formal adoption by the Council of the EU, 29 June 2026.
  • Analyses consulted: Gibson Dunn, NicFab, Studio Legale Stefanelli & Stefanelli, Altalex, Agenda Digitale, Federprivacy (June–July 2026).
  • On content marking: Coalition for Content Provenance and Authenticity (C2PA); CEN-CENELEC JTC21 standards under development.

Share this article

LinkedIn X Email

Lympha Editorial Team

The articles on this blog come from the field experience of our Business Units and Competence Centres: the people writing are the people who design, run and support the systems we write about, every day. Content is provided for information purposes and reflects the state of the art at the date of publication.

You may also like