August 2026 EU AI Act Deadline: Is Your Business Ready?
If you have been hearing conflicting things about the EU AI Act and the looming August 2026 deadline, you are not alone. This guide sets out where things currently stand, what is changing, and the steps worth taking regardless of how the final details land.
It is worth noting that over the last months, there have been changes to the EU AI Act and enforcement dates change. As such,we advise you to keep monitoring developments closely over the coming weeks. The EU AI Act resource hub and the EU AI Office are useful places to track formal adoption of the Digital Omnibus and any further guidance published ahead of August.
What is Happening on 2nd August 2026?
The EU AI Act entered into force on 1st August 2024 and becomes fully applicable two years later, on 2nd August 2026. According to the European Commission's official policy page on the AI Act, this date was originally set to bring most of the Act's remaining obligations into force, including the rules governing high-risk AI systems and the transparency obligations that apply to AI-generated content.
High-risk AI systems are those used in areas such as recruitment, employment decisions, biometric identification, critical infrastructure, education, and access to essential services. Providers of these systems were expected to have completed conformity assessments, technical documentation, and EU database registration by this deadline, with deployers required to put human oversight and monitoring arrangements in place.
Why The Picture Has Recently Changed
In November 2025, the European Commission proposed a package of amendments known as the Digital Omnibus on AI, intended to simplify parts of the AI Act's implementation. After several rounds of negotiation, the European Parliament formally approved those amendments in a vote of 423 to 57, with 174 abstentions. The amendments defer the application of high-risk obligations for standalone systems listed in Annex III, covering areas including employment, biometrics, and critical infrastructure, until 2nd December 2027, a delay of around sixteen months from the original date.
A separate, longer extension applies to AI systems that form part of regulated products, such as medical devices or machinery, which now have until 2nd August 2028. Formal publication in the Official Journal is the final step before the changes take full legal effect.
The Omnibus amendments also introduced a number of other changes worth knowing about. Exemptions that previously applied only to small and medium-sized enterprises have been extended to small mid-cap companies. The processing of personal data for bias detection purposes is now explicitly permitted, which is a meaningful clarification for organisations carrying out equality and fairness testing on their AI systems. The definition of what counts as a safety component has also been sharpened, which affects which systems fall within the scope of the longer 2028 deadline.
What Is Not Changing, Regardless Of The Delay
It is worth being clear that the delay only applies to high-risk system obligations. Several other obligations remain firmly on track, for now. Transparency requirements under Article 50, including the duty to label AI-generated content and inform users when they are interacting with a chatbot, apply from 2nd August 2026. The one exception is watermarking, which has been pushed back to 2nd December 2026 for systems placed on the market before 2nd August 2026.
The Omnibus amendments also introduced an outright ban on AI systems capable of generating child sexual abuse material or non-consensual intimate imagery. Businesses have until 2nd December 2026 to comply with that prohibition, making it one of the more urgent near-term requirements regardless of what sector you operate in.
On the transparency side, the European Commission published a Code of Practice on Transparency of AI-Generated Content in June 2026. This Code helps providers and deployers of generative AI systems demonstrate compliance with their Article 50 obligations around labelling and marking AI-generated content. Once endorsed by the Commission and the AI Board, organisations that sign up to it can rely on their adherence as evidence of compliance, though signing up does not guarantee it and adherence remains voluntary. The Commission has also released a set of optional icons that can be used to label AI-generated content, supporting compliance with the specific obligation to disclose deep fakes and AI-generated text on matters of public interest.
Every EU member state is also expected to have at least one operational AI regulatory sandbox in place by August, and the broader governance infrastructure, including the AI Office, continues to develop its enforcement activity.
This means that even with the high-risk timeline extended, businesses using generative AI tools, AI chatbots, or AI systems that produce synthetic content still have real compliance work to do this summer.
What This Means If You Employ People Or Sell Into The EU
For UK and other non-EU businesses, the AI Act's reach extends beyond companies physically based in the EU. If your AI system's output is used by, or affects, people in the EU, you are likely within scope regardless of where your business is headquartered. This mirrors the extraterritorial approach taken by the GDPR, and it means UK employers using AI tools for recruitment, performance management, or workforce monitoring of any EU-based staff should continue treating compliance as a live priority, not a problem that has gone away.
Practical Steps To Take This Summer
Given the genuine uncertainty around final adoption, the safest approach is to keep moving on the assumption that the original deadline could still apply, while staying alert to confirmed changes. Begin by building or refreshing an inventory of every AI system your business uses or provides, noting its intended purpose, the data it processes, and the population of people it affects. Map each system against the AI Act's risk categories so you know which obligations could apply to you.
Where you use third-party AI vendors, check your contracts to confirm what assurances they are giving about their own compliance, since your obligations as a deployer can depend heavily on theirs as a provider. If your AI systems generate synthetic content, such as text, images, or audio, start preparing for the transparency and labelling obligations now, since these remain on track regardless of the high-risk delay.
Finally, keep monitoring developments closely over the coming weeks. The EU AI Act resource hub and the EU AI Office are useful places to track formal adoption of the Digital Omnibus and any further guidance published ahead of August.
How Data Protection Law Fits In
One thing that sometimes gets overlooked in AI Act conversations is the role of the GDPR. As a technology-neutral law, the GDPR applies wherever personal data is processed, which means it catches a wide range of AI systems even where the AI Act's definitions might not clearly apply. It also offers something the AI Act largely does not: direct routes to redress for individuals who have been harmed.
The GDPR's prohibition on decisions made solely by automated means, without meaningful human involvement, is broader in scope than the AI Act's equivalent provisions. For individuals affected by automated recruitment decisions, credit scoring, or other consequential determinations, this can be a more accessible avenue for challenge. If your organisation uses AI in any context that processes personal data about individuals in the EU or the UK, GDPR compliance and AI Act compliance need to be considered together, not in isolation.
August 2026 marks a real regulatory moment, even though the timeline for some obligations has shifted. The transparency requirements are live, the ban on certain harmful AI-generated content is approaching, and the expectation that organisations understand their own AI systems has not changed.
If your business uses or provides AI systems with any connection to the EU or the UK, and you are unsure how the current picture affects your specific situation, speaking to a specialist now will help you avoid scrambling to catch up later.
How Can Gerrish Legal Help?
Gerrish Legal is a dynamic digital law firm. We pride ourselves on giving high-quality and expert legal advice to our valued clients. We specialise in many aspects of digital law such as GDPR, data privacy, digital and technology law, commercial law, and intellectual property.
We give companies the support they need to successfully and confidently run their businesses whilst complying with legal regulations without the burdens of keeping up with ever-changing digital requirements.
We are here to help you, get in contact with us today for more information.