EU AI Act: What Applies to Your Company Since August 2026

Since August 2, 2026, the transparency and GPAI obligations of the AI Act apply. What to do now, what the Omnibus postponed, and where the fines lie.

After NIS-2 and DORA, the EU AI Act is the next deadline-driven regulation to reach the mid-market. Since August 2, 2026, Regulation (EU) 2024/1689 has applied directly in large parts – and unlike NIS-2, there is no sectoral limitation: anyone who uses or provides AI is, in principle, within the scope. At the same time, the so-called Digital Omnibus pushed the politically most sensitive obligations back. This leads to a widespread misunderstanding: “postponed” does not mean “done,” and what has applied since August 2026 applies in full force.

This article puts into perspective what has actually been applicable since August 2, 2026, what the Omnibus deferred – and what a mid-market company should now concretely do.

The deadline picture, soberly sorted

The AI Act entered into force on August 1, 2024, and becomes applicable in stages. The relevant tiers:

  • February 2, 2025: The prohibitions (Art. 5) for unacceptable AI practices as well as the obligation for AI literacy (Art. 4) apply.
  • August 2, 2025: The governance rules and the obligations for providers of general-purpose AI models (GPAI, Art. 51 et seq.) apply.
  • August 2, 2026: General applicability takes effect – in particular the transparency obligations under Art. 50 as well as the sanctions and enforcement regime.
  • December 2, 2027: The obligations for high-risk systems under Annex III (standalone applications such as applicant screening, creditworthiness assessment, biometrics).
  • August 2, 2028: The obligations for high-risk systems that are embedded in regulated products (Annex I).

The last two dates are the result of the Digital Omnibus: the high-risk obligations of Annex III were moved from the original August 2, 2026, to December 2, 2027, and those of Annex I from August 2, 2027, to August 2, 2028. This postponement relieves companies that operate or develop high-risk systems – but it changes nothing about what has applied directly since August 2, 2026.

What has been in full force since August 2, 2026: transparency under Art. 50

The transparency obligations from Art. 50 were not postponed. They affect practically every company that uses generative AI in customer contact or in content production:

  • Chatbot disclosure (Art. 50(1)): Anyone interacting with an AI system must be informed of it – recognizable in the interaction itself, not hidden in the terms and conditions. A support bot without a clear notice is therefore no longer compliant.
  • Labeling of AI-generated content (Art. 50(2)): Outputs of generative systems must be marked in machine-readable form as artificially generated or modified. For existing systems, the regulation provides a transition period until December 2, 2026; new systems must provide the marking immediately.
  • Deepfake and public-interest labeling (Art. 50(4)): Synthetic media that depict real persons or events must be visibly labeled. AI-generated texts on matters of public interest as well – unless they undergo a documented editorial review with named responsibility.

These obligations sound technical, but in practice they are above all a question of process discipline: who knows where in your own organization generative AI produces customer texts, images, or chat responses?

Provider or deployer – the role question decides the obligations

The AI Act distinguishes two basic roles, and the difference has consequences. A provider develops an AI system or a GPAI model and places it on the market under its own name. A deployer uses such a system under its own responsibility – that is, the typical mid-market company using a purchased tool in operations.

The classification is not static: anyone who substantially modifies, fine-tunes, or resells a purchased model under their own name can themselves become a provider with the associated obligations. For most mid-market companies, the deployer role applies initially – but this is exactly where the documented review pays off, instead of leaving the question open.

What the violations cost

The sanctions regime under Art. 99 has been enforceable since August 2, 2026, and is tiered:

  • Violations of the prohibitions in Art. 5 can be penalized with up to 35 million euros or 7% of worldwide annual turnover – whichever is higher.
  • Violations of most other substantive obligations, including the GPAI and Art. 50 transparency obligations, fall into a lower tier of up to 15 million euros or 3% of worldwide annual turnover.
  • For incorrect or incomplete information to authorities, a third tier of up to 7.5 million euros or 1% applies.

For small and medium-sized enterprises, the regulation provides for proportionality – but the fines remain enforceable, and the order of magnitude makes clear that this is not a formality.

What a mid-market company should now concretely do

The pressure to act does not lie with the elaborate high-risk conformity – that is deferred to 2027 and 2028. It lies with four groundwork tasks that are the precondition for any later compliance anyway:

1. Create an AI inventory

Get a complete overview of where AI is used in the company – including “shadow AI,” that is, the tools that individual departments use without central approval. Without this inventory, no obligation can be cleanly assigned.

2. Risk classification per use case

Assign each use case to the categories of the regulation: prohibited (Art. 5), high-risk (Annex III/I), subject to transparency (Art. 50), or minimal risk. Only this classification tells you which obligations and which deadlines apply to which system.

3. Establish transparency

Implement the Art. 50 obligations where they already take effect today: chatbot notices, labeling of generated content, editorial review processes. This is the part that has been directly verifiable since August 2026.

4. Anchor governance and data hygiene

AI literacy under Art. 4 is not optional, but has been mandatory since February 2025: your employees must understand the systems they use. This includes clear usage policies, named responsibilities, and – often underestimated – data hygiene. Because many governance risks arise not from the regulation, but from the careless outflow of confidential data into external models.

Perspective: an obligation with strategic side benefit

As already with NIS-2, this holds: at its core, the AI Act demands no exotic feats, but a deliberate, documented handling of a technology that has long been in the house anyway. The inventory, the classification, and the data hygiene that the regulation compels are at the same time the basis for using AI in a controlled and economical way at all. A shoebox full of tool subscriptions without governance is neither compliant nor productive.

How sector7 helps

As an owner-led business from Solingen, we guide companies from North Rhine-Westphalia through the AI inventory, the risk classification, and the build-up of robust governance – our AI readiness and governance consulting combines this work with compliance consulting on the AI Act, NIS-2, DORA, and ISO 27001 from a single source. For the most sensitive point – the outflow of data into external models – we offer, with Sovereign AI, secured, private LLM and RAG environments on our own German server park: your data does not leave the controlled environment, which structurally eases data hygiene and transparency obligations.

Part of an honest assessment is also what we do not do: we do not train our own foundation models, do not sell an autonomous “digital workforce,” and do not undercut hyperscaler prices. Our managed AI ops operation with a fixed SLA is being built up. What we deliver today is consulting, governance, and the secure operation of private AI on our own infrastructure – certified for Juniper, Cisco, HPE, F5, Fortinet and Palo Alto Networks.

This article is a professional assessment and does not replace legal advice in individual cases.

Sources

Let's talk about your situation.