Back to blogCompliance

    AI Act August 2, 2026: What Is Actually Binding

    Transparency, sanctions and national supervision apply from August 2, 2026. Annex III high-risk obligations do not: the Digital Omnibus moved them to December 2, 2027.

    ZeroFive.AI August 6, 2026Updated on September 18, 2026 6 min

    In the days around August 2nd we read dozens of headlines about the AI Act, and they do not all say the same thing. Some talk about transparency and fines, others add high-risk systems as if those kicked in too, others blend deadlines from different years into a single paragraph. For a board that needs to decide what to do on Monday morning, the nuance matters: it separates a real obligation from an alarm that has already expired.

    Let's sort it out, source by source.

    Three Obligations Become Operative Today

    Three things go live on August 2nd, 2026, and they are real.

    The first is transparency under Article 50: providers of chatbots, voice assistants or systems that interact with people must make their artificial nature recognisable, and the same applies to text, images, audio and video generated or altered by AI, marked in a readable way within the limits of available technology. The Digital Omnibus grants a window until December 2nd, 2026 for systems already on the market before today: a tool launched in June still has four months, one launched tomorrow does not.

    The second is the sanctions regime, fully enforceable from today for violations of these transparency obligations and for the prohibited practices of Article 5, in force since February 2025. The figures are precise: up to fifteen million euros or 3% of global turnover for transparency, up to thirty five million or 7% for prohibited practices. These are not theoretical ceilings, the Commission published operational guidelines in the days before the deadline specifically to make them enforceable from day one.

    The third is less visible but weighs heavily for companies operating in Italy: national supervision becomes fully operational today. Law 132/2025 designated the National Cybersecurity Agency as the authority with inspection and sanctioning powers, and the Agency for Digital Italy for notification and accreditation, while Banca d'Italia, CONSOB and IVASS retain competence over systems used in banking, financial and insurance services. An inspection, from now on, has a specific counterpart with a name and a phone number.

    The Confusion Around Annex III

    Here lies the misunderstanding circulating most. Several articles published before July 24th, when the Digital Omnibus was still a draft, listed August 2nd, 2026 as the date when obligations for high-risk systems under Annex III would also become applicable: recruitment, credit, education, essential services. That was accurate when it was written. Regulation (EU) 2026/1744, published in the Official Journal on July 24th and in force since the 27th, moved that deadline to December 2nd, 2027. Those articles remained online, indexed, and are circulating today as if they described the current situation.

    The practical consequence: if a company system falls under Annex III, nothing is being violated this morning. An obligation that is not yet applicable cannot be sanctioned, and this is precisely the point the noise of these past days has failed to clarify enough.

    For high-risk systems embedded in already regulated products, Annex I, the deadline is further out still: August 2nd, 2028.

    Two Obligations Stay Where They Were

    Two requirements are not news from August, they simply remain where they already stood. The prohibitions of Article 5, covering manipulative practices, social scoring, emotion recognition at work, have been in force since February 2nd, 2025. The obligations on general-purpose AI models, GPAI, have been operative since August 2nd, 2025, together with European governance and the designation of national authorities. Companies that had not yet addressed these two fronts do not have a new August deadline, they have an overdue one.

    The Map Matters More Than the Date

    The right question for a company is not which exact date applies, it is what the company actually has running. Mapping the AI systems in use or in procurement, with a first classification against Annexes I and III, is worth as much today as it will be worth in December 2027: without that map, every regulatory deadline arrives as a surprise, regardless of when it falls.

    According to the Artificial Intelligence Observatory of Politecnico di Milano, 71% of large Italian companies have active AI projects, yet only 9% have structured governance. That gap widens precisely in moments like this one, when deadlines multiply and contradictory news makes it hard to know what to act on first. A company that already has a map of its own systems reads August 2nd as one deadline among others. A company without that map risks reacting to the wrong headline, or ignoring the right one.

    The reference remains the consolidated text: Regulation (EU) 2024/1689 (the AI Act) as amended by Regulation (EU) 2026/1744, published in the Official Journal of the European Union on July 24th, 2026, together with Law 132/2025 for the Italian authority framework. Every other source, including the most recent ones, should be checked against its publication date before being taken at face value.

    Regulatory deadlines are meant to be managed, not read twice with two different meanings.

    Want to discuss this for your company?

    30 minutes with us to figure out where to start, or an AI Rating to measure your starting point.

    #AI Act#compliance#Article 50#Annex III#Digital Omnibus#Law 132/2025#AI governance
    Share

    Keep reading