2 August 2026 has come and gone. In many European boardrooms the date was circled in red for two years, then quietly crossed out in the spring when the Digital Omnibus package pushed back the heaviest obligations. Both reactions miss the point. Part of the AI Act became enforceable on Sunday, and it covers exactly the systems companies rolled out fastest: conversational interfaces and generated content.

The AI Act (Regulation EU 2024/1689) is the world's first binding framework for artificial intelligence. It sorts AI systems by risk level and attaches a distinct set of obligations to each. Since 2 August 2026, its transparency rules apply: any company exposing customers or employees to an AI system has to tell them so.

Telling the two apart is worth ten minutes of board time before the autumn.

What applies since 2 August 2026?

Since 2 August 2026, Article 50 of the AI Act imposes four transparency duties: tell users they are interacting with an AI system, mark synthetic content in a machine-readable format, disclose manipulated content, and inform people subjected to emotion recognition.

The detail matters, because the burden does not always sit with the same actor in the chain:

  1. Direct interaction with an AI system. The provider must ensure the person knows they are talking to a machine, unless it is obvious to a reasonably well-informed user. In practice: any conversational agent facing a customer, a candidate or an employee.
  2. Synthetic content. The provider must mark audio, image, video and text outputs in a machine-readable format, using a robust and interoperable solution. Systems already in service get additional time, until 2 December 2026.
  3. Manipulated content and text on matters of public interest. Here the deploying company carries the duty to disclose that content was artificially generated or altered. One exception rests on review: text that went through human editorial control falls outside the scope.
  4. Emotion recognition and biometric categorisation. The deployer informs the people exposed, and GDPR obligations continue to apply on top.

The regulation requires the disclosure to be clear and distinguishable, and given no later than the first interaction. A line buried in terms and conditions does not meet that bar, and neither does a banner that appears after three exchanges with the agent.

What does a customer-facing chatbot have to show now?

This is the most common question, because it is the most common deployment. A conversational agent in customer service has to state what it is on the first screen, in wording the reader can actually parse. The regulation prescribes no standard formula, which leaves genuine latitude on tone and placement.

What separates a disclosure that holds from a cosmetic one comes down mostly to visibility: the message has to be read before the first exchange, not on hover. A user coming back a week later should find it too.

Then comes the part teams rarely handle, and the one a supervisory authority can actually test: proof. Being able to demonstrate, six months after an incident, what was displayed on a given date and for which deployed version of the system. That means versioning your disclosure wording the same way you version code, which few product teams do today.

The same reasoning covers internal use. An assistant that pre-screens applications or answers employee HR questions sits inside the scope, with no public exposure at all.

Were the high-risk obligations really postponed?

Yes, and that is where the confusion comes from. The Digital Omnibus package moves the obligations for stand-alone Annex III high-risk systems, covering recruitment, credit scoring, education, biometrics and border control, from 2 August 2026 to 2 December 2027. AI embedded in already-regulated products under Annex I (medical devices, machinery, vehicles) moves from 2 August 2027 to 2 August 2028. The text also narrows the high-risk qualification for certain assistance functions unrelated to safety.

The transparency duties, the penalty regime and the supervisory architecture, on the other hand, were left untouched. The regulation provides for fines of up to 35 million euros or 7 % of worldwide annual turnover for the most serious breaches, enforced by the market surveillance authority designated in each member state.

What should companies do with sixteen months of reprieve?

The temptation is familiar: shelve the file, reopen it in autumn 2027. Three published measures explain why that maths works badly.

Deloitte (2025) finds that 21 % of companies deploying AI agents have mature governance in place. MIT (2025) finds that 95 % of generative AI pilots never reach measurable P&L impact. S&P Global (2025) finds that 46 % of proofs of concept are abandoned before production. Gartner expects 40 % of agentic AI projects to be cancelled by 2027. Four numbers, one blind spot: organisations know how to launch systems, far less how to keep them running under control.

High-risk compliance does not get built in a quarter. It assumes a system inventory, a classification you can defend to a third party, technical documentation, human oversight, usable logging and periodic review. Every one of those bricks has to be laid on systems already in production, by teams with other commitments on their roadmap. The reprieve therefore shifts the workload onto a tighter calendar, at the point where those same teams will be absorbing the next wave of deployments.

The sensible read fits in one sentence: handle transparency now, since it is enforceable, and spend the months gained mapping what already exists.

How do you know whether your company is in scope?

Five questions are enough to frame a first discussion at board level.

A company that answers these five questions in the room knows where it stands. A company that has to launch an internal survey to answer them knows too. Our AI maturity assessment covers that ground in a few minutes and places the level of governance reached, agentic dimension included.

Who should own AI Act compliance internally?

The default answer points at legal or the DPO. It produces clean files on paper and exposed systems in production, because the decisions that create the risk are taken elsewhere: in the choice of a model, in the scope of action granted to an agent, in the trade-off between full automation and human validation.

The subject therefore pulls in three functions at minimum. A legal or compliance function that qualifies the systems. An IT function that documents, logs and can replay a decision. A business owner who stands behind the use cases and the trade-offs attached to them. Governance means writing down who decides what, what an agent may do on its own, what goes back to a human, and how that decision can be found in the logs six months later. That is the principle behind the LOOP™ methodology, and it is also, phrased differently, the documentation the AI Act ends up demanding.

For the full calendar by risk level and the obligations attached to high-risk systems, our AI Act compliance page sets out the complete set of deadlines.

What 2 August 2026 actually changed

The date did not trigger the wave of enforcement some expected. It made enforceable the part of the regulation customers can see for themselves, precisely as companies multiply conversational agents. A customer service chatbot that does not declare itself as AI is now a breach, rather than a user experience trade-off. The rest of the calendar leaves room, provided you start by knowing what is running.