August 2, 2026 is not a soft date. It is the statutory enforcement deadline under the EU AI Act — the point at which national competent authorities can begin issuing fines, demanding audits, and pulling non-compliant systems from the EU market. This article covers every obligation that applies before that date, for every entity the regulation touches.

🚫
Already in force: Prohibited AI practices under Article 5 have been enforceable since February 2, 2025. If you operate a system that performs social scoring, exploits vulnerable groups, or deploys real-time remote biometric identification in public spaces without authorisation, you are already in violation. August 2 is not your first deadline — it is the next one.

Why August 2, 2026 Specifically

The EU AI Act entered into force on August 1, 2024. The regulation follows a phased compliance calendar keyed from that date. Each phase brings new obligations into effect. August 2, 2026 represents the 24-month mark — and the most commercially significant milestone in the schedule.

From that date, the full framework applies to General Purpose AI (GPAI) models, and national competent authorities in all 27 member states gain full enforcement powers across the entire Act. Penalties stop being theoretical.

August 1, 2024
Act enters into force
20 days after publication in the Official Journal. Compliance clock starts.
February 2, 2025
Prohibited practices enforceable (Chapter II)
Bans on social scoring, manipulative AI, real-time biometric identification, and emotion recognition in workplace/education contexts take effect. Also: AI literacy obligations on providers.
Today — May 19, 2026
75 days remaining
GPAI model registration, documentation, and technical obligations must be completed before August 2. High-risk system operators should have human oversight controls in place now.
August 2, 2026
Full enforcement begins
GPAI obligations, high-risk system requirements, and general transparency rules all enforceable. Market surveillance authorities begin compliance checks.
February 2, 2027
High-risk Annex I systems fully in scope
AI systems in products covered by existing EU harmonisation legislation (medical devices, machinery, toys) face the additional 36-month transition. All other high-risk Annex III systems were already in scope from August 2026.

Who Is Affected Before August 2

The EU AI Act uses four key roles. Your obligations depend on which role — or combination of roles — applies to your organisation.

The Four Roles
  • Provider — develops and places an AI system on the market or puts it into service under their own name Carries the heaviest obligations: conformity assessments, technical documentation, registration in the EU database, post-market monitoring.
  • Deployer — uses an AI system in a professional context Must implement human oversight measures, log outputs where required, and maintain records of use. Cannot override safety guardrails set by providers.
  • GPAI Model Provider — places a general-purpose AI model on the market (including open-weight) New category under the Act. Separate set of obligations distinct from AI system providers. Includes foundation model and API providers.
  • Importer / Distributor — brings an AI system from outside the EU into the EU market or makes it available Must verify that the provider has completed required documentation and registration before placing the system into the supply chain.

A single organisation can hold multiple roles simultaneously. A company that builds a high-risk AI system on top of a third-party foundation model is simultaneously a Provider (for the system they put to market) and a Deployer (using the upstream model). Both sets of obligations apply.

GPAI Model Obligations (New from August 2)

General Purpose AI models — the large foundation models and APIs that power most modern AI applications — face their own dedicated chapter of obligations under Title VIII of the Act. These kick in on August 2, 2026.

All GPAI Model Providers Must:

GPAI Baseline Requirements
  • Maintain technical documentation sufficient for competent authority review Must cover architecture, training data sources, training methodology, capabilities, limitations, and known risks.
  • Publish a summary of training data used, adequate for copyright compliance verification Required under Article 53(1)(d). Must be publicly accessible and updated when training data changes materially.
  • Implement and enforce a copyright compliance policy under Article 53(1)(c) Must include processes for handling opt-out requests from rightsholders under the EU Text and Data Mining Exception.
  • Provide downstream providers and deployers with technical documentation enabling their own compliance If your model is used to build high-risk systems, you must supply documentation that enables those builders to complete their own conformity assessments.
  • Register the model in the EU AI Act database (where required) Registration applies to GPAI models with systemic risk. The AI Office publishes guidance on the threshold (currently: models trained with >10²⁵ FLOPs).

Systemic-Risk Models Face Additional Requirements:

GPAI models designated as posing systemic risk — either by threshold or by AI Office designation — carry a heavier compliance load. The operative threshold is training compute of more than 10²⁵ floating-point operations (FLOPs).

Systemic-Risk GPAI (Additional)
  • Conduct adversarial testing (red-teaming) against the model Must be completed in accordance with the AI Office's methodology. Results and mitigations must be documented.
  • Notify the AI Office of serious incidents within defined timeframes Includes incidents involving high-risk AI systems built on the GPAI model, and incidents involving systemic risks materialising.
  • Implement cybersecurity protections for the model and training infrastructure Must be proportionate to the scale and nature of the risks. The AI Office can request evidence of these protections.
  • Assess and mitigate systemic risks on an ongoing basis Systemic-risk assessment is not a one-time exercise. It must be revisited when the model is updated, fine-tuned, or deployed in new contexts.

"Providers of general-purpose AI models shall draw up and keep up-to-date the technical documentation of the model... and make it available to the AI Office and, on request, to the national competent authorities."

— EU AI Act, Article 53(1)(a)

High-Risk AI System Obligations

High-risk AI systems — those listed in Annex III of the Act, covering areas like employment decisions, education access, creditworthiness assessments, and critical infrastructure — are subject to the most extensive requirements. Most of these obligations applied from August 2, 2026.

Providers of High-Risk Systems Must Complete:

High-Risk Provider Requirements
  • Implement a quality management system (QMS) conforming to Article 17 Must cover design, testing, data governance, and post-market monitoring. Written procedures required.
  • Complete a conformity assessment before market placement Either self-assessment or notified-body assessment depending on the system type. Produces the EU Declaration of Conformity.
  • Register the AI system in the EU database before deployment Registration is mandatory for all Annex III high-risk systems with limited exceptions. Applies to the EU market regardless of where development occurred.
  • Affix the CE marking where required and prepare the EU Declaration of Conformity CE marking signals conformity to the Act and relevant harmonised standards. Declaration must be signed before market placement.
  • Establish a post-market monitoring plan Must include data collection procedures, incident detection, and feedback loops for corrective action. Active monitoring from first deployment.
  • Provide adequate instructions for use to deployers Must enable the deployer to implement human oversight, understand system limitations, and comply with their own obligations.

Deployers of High-Risk Systems Must Complete:

High-Risk Deployer Requirements
  • Implement human oversight measures per Article 14 Must enable designated individuals to monitor, override, and halt the system. Override mechanisms must be technically functional — not just documented.
  • Assign specific oversight responsibility to named individuals Article 14(1) requires that human oversight be exercised by individuals with the competence and authority to do so. Job titles are insufficient — specific accountability is required.
  • Maintain use logs for the required retention period Automatic logging must be enabled. Logs must cover input data, outputs, system decisions, and any human interventions. Minimum 6-month retention.
  • Complete a fundamental rights impact assessment (FRPIA) where required Mandatory for public authorities and for operators using AI in finance, insurance, and other regulated sectors. Must be completed before deployment.
  • Inform affected individuals that they are subject to AI decision-making Transparency to natural persons is required for AI systems making consequential decisions. Must be clear, plain-language, and provided before the decision is made.
  • Report serious incidents to the provider and to national authorities Deployment-stage incidents that cause or could cause harm must be escalated within defined timeframes. Providers must be notified within 15 working days.

Transparency Obligations for All AI Systems

Even systems that are not classified as high-risk face transparency requirements under Article 50. These apply to any AI system that interacts with humans directly or generates synthetic content.

General Transparency (Article 50)
  • Disclose to users that they are interacting with an AI system Chatbots, virtual assistants, and automated response systems must make clear they are not human. Exception: systems obvious in context.
  • Label AI-generated content as artificially generated or manipulated Applies to synthetic audio, image, and video content. Machine-readable watermarking is the preferred method. Human-readable labelling is required at minimum.
  • Enable detection of AI-generated content by downstream platforms Providers of image, audio, or video-generating AI must embed technically detectable markers. Applies regardless of whether the system is high-risk.

Penalties for Non-Compliance

The EU AI Act fine structure is tiered by violation type. Regulators are not required to wait for harm to occur — non-compliance with procedural obligations (missing documentation, failed registration) is itself a basis for fines.

⚠️
Note on penalty calculation: The Act specifies fines as the higher of a fixed amount or a percentage of global annual turnover. For startups with low turnover, the fixed amount may represent the binding ceiling — but for larger operators, the percentage-based cap drives higher exposure.
Violation Type Maximum Fine Example Breaches
Prohibited AI practices (Article 5) €35M or 7% global turnover Social scoring systems, manipulative AI, unauthorised biometric surveillance
High-risk system obligations €15M or 3% global turnover No conformity assessment, missing EU database registration, no post-market monitoring
GPAI model obligations €15M or 3% global turnover Missing technical documentation, no copyright compliance policy, failure to notify incidents
Incorrect or misleading information to authorities €7.5M or 1.5% global turnover False declarations of conformity, inaccurate registration data

SME-adjusted limits apply under Article 99(6). For companies with fewer than 10 employees and <€2M annual turnover, the caps are halved. This does not eliminate the fine risk — it reduces the ceiling.

What to Do in the Next 75 Days

With the deadline approaching, the question is triage: what must be done before August 2, what can be phased afterward (where genuine transition timelines exist), and what was already supposed to be done.

Immediate Priorities (Do Now)

Pre-August 2 Action List
  • Audit your AI inventory against Annex III Know which systems you operate are classified as high-risk. Misclassification is a common failure mode — legal and technical teams need to work this together.
  • Determine which GPAI models you provide or deploy If you are a model API provider, GPAI obligations apply to you from August 2. If you are a deployer using third-party models, verify your provider's compliance status.
  • Complete or commission conformity assessments for high-risk systems Self-assessment for most Annex III categories. Notified body assessment required for biometric identification and certain public-facing safety systems.
  • Register systems in the EU AI database The EU database is live. Registration is mandatory before August 2 for Annex III systems. Providers are responsible; deployers verify registration status.
  • Implement and test human oversight mechanisms Kill switches, override controls, and intervention logging must be technically operational — not just written into policy. See our kill switch implementation guide.
  • Deploy AI literacy training to staff operating AI systems Article 4 obligation applies to providers. Staff who use AI systems in a professional context must receive proportionate training on capabilities and limitations.
  • Conduct GPAI training data documentation and copyright audit GPAI model providers must publish training data summaries and have copyright compliance policies ready before August 2.
  • Verify that Article 50 disclosures are in place for customer-facing AI If any product uses AI to interact with users, generate content, or make decisions, transparent disclosure is already required. Audit front-end touchpoints now.

Using ZeroHumanOS for Compliance Evidence

Regulators will want evidence. Documentation you prepared in 2025 and never updated will not satisfy a 2026 audit. Continuous governance records — showing ongoing monitoring, incident tracking, and oversight activity — carry more weight than a point-in-time compliance package.

ZeroHumanOS tracks live EU AI Act enforcement decisions, regulator actions, and governance events across Europe in real time. The tracker gives compliance teams an ongoing record of how the regulation is being interpreted in practice — a resource that static checklists cannot provide.

ZeroHumanOS
EU AI Act Compliance Intelligence
Live governance tracker plus in-depth compliance research reports. Built for professionals who need to understand the regulation as it is being enforced — not just as it was written.
Open Live Tracker →
Free tracker. Research reports from $2.

The Practical Bottom Line

August 2, 2026 is a real enforcement date. The AI Office is operational, national competent authorities are staffed and mandated, and the EU database is live.

The highest-risk failure modes are: operating a high-risk system without a completed conformity assessment, providing GPAI models without technical documentation and a copyright policy, and deploying high-risk AI without functional human oversight mechanisms. These are not bureaucratic gaps — they are the categories drawing the largest penalties.

Seventy-five days is enough time to complete the required work for most organisations. It is not enough time to start the work from zero on complex high-risk systems. If your programme has not started, it should have already.