News

The AI Act's August 2026 deadline: what applies now and what comes next

Three of the AI Act's five dates have already passed, and 2 August 2026 switches on the bulk of the regulation. Here is what is enforceable today and what lands next.

By Auditra Team · Published · Updated

Regulation (EU) 2024/1689 — the AI Act — never arrives all at once. It entered into force on 1 August 2024 and phases in over three years, which means the honest answer to "does the AI Act apply to us?" is always a question back: which of your AI systems, and which date. The full phase-in runs from 2 February 2025 to 2 August 2027, and most of it is now behind us.

What is already enforceable

Since 2 February 2025, the unacceptable-risk practices are banned outright. There is no documentation package, no mitigation and no transition period for a prohibited practice: social scoring, manipulative techniques that materially distort behaviour, untargeted scraping of facial images, emotion recognition in workplaces and schools. If a system in your estate lands in that band, the only compliant response is to stop it. The same date brought the AI literacy duty, which is easy to underestimate — it requires that the staff who deal with AI systems on your behalf have a sufficient level of understanding to do so responsibly.

Since 2 August 2025, the obligations for general-purpose AI models have applied, the governance structures are operational, and the penalty provisions are in force. Most organisations are not GPAI providers, but they consume GPAI through an API — and the documentation their model provider must now maintain is precisely what makes downstream compliance possible. Asking for it, and filing it, is a task for this quarter rather than next year.

2 August 2026: the bulk of the regulation

This is the date the AI Act stops being a planning exercise for most companies. The remaining obligations take effect, including the Annex III high-risk requirements and the transparency duties. Annex III is where ordinary businesses land: a tool that ranks job applicants, a model that prices insurance, a system that decides who gets credit. None of those companies think of themselves as AI companies, and all of them are in scope.

What high-risk asks for is a work programme, not a label: a risk management system, data governance for training and testing data, technical documentation, logging, instructions for use, human oversight designed into the product, and accuracy, robustness and cybersecurity measures — then conformity assessment, CE marking and registration before the system reaches the market. Deployers get a shorter list, but it is the list an authority asks about first: use according to instructions, competent human oversight, relevant input data, monitoring, log retention, informing affected workers, and in certain cases a fundamental rights impact assessment before first use.

2 August 2027: the last door closes

The final date closes the extended transition for high-risk AI embedded in products already regulated under other EU legislation — the Annex I route: machinery, medical devices, vehicles and the rest. If your AI is a safety component inside a regulated product, you have a year longer than everyone else, and you will need it, because the AI Act file has to sit alongside the product conformity file rather than replace it.

What to do with the time that is left

The sequence has not changed since the first deadline, and it is stubbornly unglamorous. Inventory every AI system you build, buy or quietly enable inside a SaaS tool. Fix your role for each one — provider, deployer, importer or distributor — because duties follow the role, not the industry. Classify the risk level, and flag anything that is or builds on a general-purpose model. Then map obligations and dates against each system and give every item an owner. A classification nobody owns is not a compliance position.

Organisations that already run a NIS2 programme have an advantage here: the muscle is the same one. The technical work is usually further along than the paperwork, and the regulation is written in artefacts. Start from the artefact list, map what exists, and treat the gaps as documentation tasks with dates against them. Our AI Act guide covers scope, the risk pyramid, requirements, GPAI and penalties in detail, and the AI Act document packages — inventory and classification, the deployer pack, and the full provider programme — are in development against exactly these deadlines.

Related reading

Related

AI Act key dates and deadlines — the full reference page behind this article.

← All news