2 August 2026 is the general application date of Regulation (EU) 2024/1689, known as the AI Act. It is also the most discussed and most misunderstood date in this year's European regulatory calendar, because part of the obligations that were due to apply on that day has been postponed by Regulation (EU) 2026/1744 of 8 July 2026, known as the Digital Omnibus on AI. This article sets out what applies, what is postponed and what an SME should take from it. The postponements described here are settled: the amending regulation was published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July 2026.
What has been in force since 2025
Two waves of obligations already apply. Since 2 February 2025, the prohibited practices of Article 5 (social scoring, exploitation of vulnerabilities, certain biometric identification uses) are banned, and Article 4 requires providers and deployers alike to ensure a sufficient level of AI literacy among the people who operate these systems on their behalf. Since 2 August 2025, the obligations on providers of general-purpose AI models (Chapter V), the governance structure and the penalties regime have been applicable.
Regulation (EU) 2026/1744 extends that Article 5 list. Two practices are added: producing or manipulating realistic intimate content without the consent of the people depicted, and producing child sexual abuse material. The prohibition covers placing on the market systems designed for those purposes, placing on the market systems that allow such production without reasonable preventive measures, and a deployer using such a system for that purpose. Both prohibitions apply from 2 December 2026, not from the entry into force of the amending regulation.
An SME that uses generative AI tools is therefore already covered by Article 4: staff awareness does not wait until 2 August 2026.
What applies on 2 August 2026: Article 50 transparency
The postponement decided in Regulation (EU) 2026/1744 does not touch Article 50, which applies as planned. It covers four situations. Providers of systems that interact directly with people (conversational agents) must ensure those people know they are talking to an AI, unless it is obvious. Providers of generative AI systems must mark the content produced (text, image, audio, video) in a machine-readable format, so it can be detected as artificially generated or manipulated. Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. Deployers who publish deepfakes, or AI-generated text published to inform the public on matters of public interest, must disclose it, with an exception where the content has undergone human editorial review.
On 20 July 2026 the Commission published its guidelines on transparency obligations, which define the scope of Article 50 and split the obligations between providers and deployers. They are the reference document for qualifying a concrete situation, alongside a Commission FAQ covering the borderline cases, in particular what counts as a deepfake and what counts as editorial review.
Regulation (EU) 2026/1744 introduces a single accommodation on this part: generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking obligation of Article 50(2). Systems placed on the market from 2 August 2026 must mark their output from day one. The other transparency obligations, including informing people who interact with an AI system, get no extra time. The Commission supports this part with the Code of Practice on Transparency of AI-Generated Content, a voluntary instrument that describes marking and labelling methods considered compliant, without creating a stand-alone obligation.
For an SME that deploys a conversational agent on its site or publishes generated content, the transparency obligations are therefore active from August. For one that buys these capabilities from a vendor, the question becomes contractual: check that the provider marks its outputs and informs users.
What Regulation (EU) 2026/1744 postpones
The text, which came out of a Council and Parliament agreement in May 2026, was voted by the Parliament on 16 June and approved by the Council on 29 June. It moves three deadlines. The obligations on stand-alone high-risk systems under Annex III (recruitment, credit scoring, education and access to essential services, among others) move from 2 August 2026 to 2 December 2027. The obligations on high-risk systems embedded in products already regulated elsewhere (Annex I) move from 2 August 2027 to 2 August 2028. The obligation for each Member State to have at least one operational regulatory sandbox is pushed back by one year, to 2 August 2027.
These dates are now fixed: the published regulation replaced the conditional mechanism initially proposed by the Commission (which tied the postponement to the availability of harmonised standards) with firm deadlines. An SME whose use case falls under Annex III, for instance a CV screening tool, gains additional time, but the obligation remains, with an unchanged scope.
Penalties
The penalties regime of Article 99 has been applicable since 2 August 2025, with Member States setting the detailed rules. The ceilings are 35 million euros or 7% of worldwide annual turnover for prohibited practices, and 15 million euros or 3% for most other obligations, including Article 50. The regulation provides an adjustment for SMEs and start-ups: the applicable ceiling is the lower of the percentage and the fixed amount, where the general rule takes the higher.
Attaching AI governance to what already exists
The risk for an SME is treating the AI Act as an isolated project, with its own inventory, its own register and its own owner. The obligations described above attach to governance practices that generalist frameworks already cover. In NIST CSF 2.0, understanding which regulatory obligations apply belongs to the GV.OC category (organizational context) and the risk management strategy to GV.RM. In practice: inventory AI uses (internal and purchased), classify them against the regulation's categories (prohibited, high risk, transparency, minimal), record the associated risks in the existing risk register and cover Article 4 through the awareness programme already in place.
The Komplyo assessment measures the maturity of the GOVERN function, including these categories, and the generated risk register accommodates scenarios tied to AI uses alongside the others. The free diagnostic (23 questions, around 5 minutes) gives a first reading of the GOVERN function.
Sources
- Regulation (EU) 2024/1689 (AI Act), EUR-Lex
- Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), EUR-Lex
- Guidelines on transparency obligations, European Commission, 20 July 2026
- FAQ on the Article 50 transparency obligations, European Commission
- European regulatory framework on AI, European Commission
- Code of Practice on Transparency of AI-Generated Content, European Commission
- NIST Cybersecurity Framework 2.0, NIST