August 2, 2026 was the date written into the AI Act from the moment it was published, back in 2024: the day most of the regulation would become applicable. It arrived. But six days earlier another regulation entered into force — Regulation (EU) 2026/1744, the "Digital Omnibus on AI" — and it rewrote the calendar.
The result is a picture that none of the summaries circulated in recent months describes correctly. It is worth setting out what is applicable today, August 4, 2026, and what is not.
1. What actually kicked in
Since August 2, Article 50 — the transparency obligations — applies. In practice:
- systems interacting directly with people (chatbots, voice assistants, conversational agents) must make it recognizable that they are AI;
- synthetic content (text, images, audio, video) and deepfakes must be labelled as such;
- emotion recognition and biometric categorization systems require explicit notice to the people exposed to them.
Alongside transparency came the least-reported and most concrete part: governance and penalties are now operational. National authorities take up full supervisory powers, while the European AI Office retains exclusive oversight of general-purpose models.
2. The rewritten calendar
| Date | What applies |
|---|---|
| 2 Aug 2026 | Transparency (Art. 50), governance, penalties |
| 2 Dec 2026 | Technical marking for systems already on the market (Art. 50(2)); new absolute prohibitions |
| 2 Dec 2027 | Stand-alone high-risk systems (Annex III) |
| 2 Aug 2028 | High-risk embedded in regulated products (medical devices, machinery, toys) |
The most significant postponement concerns Annex III: AI used in employment, education, credit scoring, law enforcement, critical infrastructure. It was meant to be the event of August 2, 2026; it moved to December 2, 2027. Anyone who planned compliance around that date just gained sixteen months.
The legislative path is worth recalling, because it explains the rush: Commission proposal on November 19, 2025, trilogue agreement on May 7, 2026, European Parliament vote on June 16, final Council green light on June 29, publication in the Official Journal on July 24, entry into force on the 27th. Six days of margin on the very deadline the regulation was moving.
3. Why the postponement is not a free pass
Two reasons.
First: transparency penalties are already fully enforceable, and they are not symbolic — up to €15 million or 3% of annual worldwide turnover. Article 50 also has the widest perimeter in the entire regulation: it touches not only model developers but any company that has put a chatbot on its website or generates marketing content with AI.
Second: on December 2, 2026 new absolute prohibitions arrive, introduced by the Omnibus and absent from the 2024 text. They cover the non-consensual generation of realistic intimate imagery and the production of child sexual abuse material through AI. For these there is no transitional period.
4. What changes for infrastructure operators
The AI Act does not regulate data centers. It regulates the systems running inside them — and for an infrastructure operator that produces three very concrete effects.
Compute enters the compliance file. High-risk systems must guarantee event logging, traceability and retention of technical documentation. Whoever hosts the training or the inference becomes the physical place where those logs live, with integrity and retention requirements that end up in contracts, not in slide decks.
The supply chain gets longer. A GPU-as-a-service provider is not the "provider" of the AI system under the regulation, but it is part of the chain the provider must be able to document. The questions clients ask us have already changed: where do the workloads run, who can access them, under which jurisdiction do the data sit.
Three rulebooks converge. The AI Act on system conformity, NIS2 on supply-chain security, the Cloud and AI Development Act on capacity and sovereignty levels. Read together, they push in the same direction: European compute, contracted in a verifiable way. That is exactly the perimeter the Apulia Tech Hub project is built on.
5. The August checklist
For anyone using AI in a company, five things to do now rather than in December:
- Inventory every AI-to-user touchpoint — every chatbot, assistant and content generator already in production
- Fix the notices: declare the AI where it interacts, label synthetic output
- Check technical marking of legacy systems ahead of December 2, 2026
- Reclassify the portfolio against Annex III: the postponement to December 2027 should be used, not forgotten
- Ask your suppliers where the compute runs and which logs are guaranteed by contract
Sixteen months of postponement on high-risk is a gift that gets spent fast. August 2 moved a deadline, not the problem.
Note: this article is for informational purposes only and does not constitute legal advice. The classification of individual AI systems must be verified with your advisors.