AI Act Since 2 August 2026: What Companies Need to Review Now
Further parts of the AI Act have applied since 2 August 2026. Companies now need a complete AI inventory, clear roles, appropriate transparency, AI literacy and documented approvals.

01
Legal position and sources reviewed on 3 August 2026. This article provides practical guidance on implementing the AI Act in business. It is not legal advice and does not replace an assessment of the individual case.
02
2 August 2026 Is Not a Universal Start Date for Every Obligation
Further central parts of the European AI Act have applied since 2 August 2026, particularly the transparency obligations under Article 50. The European Commission can also fully enforce the obligations for providers of general-purpose AI models that have applied since 2 August 2025. Models placed on the market before 2 August 2025, however, benefit from a transitional period until 2 August 2027.
At the same time, Regulation (EU) 2026/1744 postponed important obligations for high-risk AI. The requirements for standalone high-risk applications under Annex III generally apply from 2 December 2027. For AI that forms part of certain regulated products under Annex I, the date is 2 August 2028.
That does not mean companies should postpone the subject until then. Prohibitions on certain AI practices have applied since 2 February 2025, measures to promote AI literacy are already required, and transparency obligations may have been directly relevant since 2 August 2026.
The point is that there is no single AI Act switch. The decisive factors are the role, the system and its specific intended purpose.
03
Provider or Deployer: The Role Determines the Obligations
Most SMEs are deployers to begin with. A deployer uses an AI system under its authority for professional purposes. A simple example is a property developer using a purchased AI assistant for property descriptions, customer communication or the evaluation of project documents.
A provider develops an AI system, or has one developed, and places it on the market under its own name or trade mark. This is comparable to a manufacturer that does not merely use a tool but offers it as its own product.
The role can change. An organisation that develops or commissions an AI system and places it on the market or puts it into service under its own name is a provider. For high-risk AI, Article 25 additionally defines when distributors, importers, deployers or other third parties assume provider obligations themselves, for example by attaching their own name, making a substantial modification to a system that remains high-risk, or changing its intended purpose so that it becomes high-risk. The statement “we only bought the software” is therefore not always sufficient.
| Situation | Likely Starting Point | What Should Be Reviewed |
|---|---|---|
| A standard AI service is used internally | Deployer | Purpose, data, transparency, training and oversight |
| An AI solution is supplied to customers under the company’s own brand | Potentially a provider | Contractual and technical responsibility and provider obligations |
| A system is used for a new purpose not intended by the provider | Possible change of role | New intended purpose and its effect on classification |
| A service provider uses AI on the company’s behalf | Clarify the allocation of roles | Contract, instructions, data access, approvals and evidence |
04
No Risk Classification Without a Specific Intended Purpose
A language model, image-recognition system or forecasting tool does not automatically have a fixed risk classification. What matters is how the specific AI system is used.
AI that drafts text for an internal brainstorming exercise must be assessed differently from a system that pre-screens job applicants. It also matters whether a forecast merely supports project planning or influences decisions about access to housing.
The review should therefore not begin with product names. It should begin with the process: Which decision is being prepared or made? Who is affected? What data is used? What consequences could an incorrect result have?
05
Five Priority Tasks for Deployers
1. Create a Reliable AI Inventory
An AI inventory is a structured list of all AI systems in use. It works much like an asset register: only systems that are known can be reviewed, protected and governed properly.
The inventory should include more than officially procured tools. It should also cover AI functions in existing software, self-configured assistants and publicly available services used by employees in their daily work.
- System name and provider
- Business unit and responsible person
- Specific intended purpose
- Affected individuals or groups
- Data used and any personal data involved
- Outputs generated and resulting decisions
- Human review before further use
- Internal or external publication of results
- Contractual, storage and deletion rules
- Status of business approval
For real estate developers and property developers, relevant AI functions may include document management, sales, planning, defect recording, applicant management or customer service. Whether special obligations arise depends on the actual use in each case.
2. Assign Roles in Writing
For every system, it should be clear whether the company is a deployer, a provider or potentially both. Internal ownership must also be assigned.
A practical allocation has three levels: the business unit owns the process value; a designated function reviews data, security and rules; and a named manager approves the use. For sensitive applications, data protection, information security, employee representatives and legal advisers should be involved early.
Particular attention is required when building proprietary assistants, adapting third-party models or integrating AI functions into customer products. In these cases, simple use can develop into a provider role.
3. Review Transparency for Each Use Case
Article 50 of the AI Act has applied since 2 August 2026. It covers certain interactive systems and AI-generated or manipulated content. The specific obligations differ between providers and deployers.
Providers of interactive AI systems must generally design the system so that people know when they are interacting directly with AI, unless this is already obvious. For deployers, disclosures may be relevant for certain deepfakes, emotion-recognition systems, biometric categorisation and certain AI-generated texts on matters of public interest.
In simplified terms, a deepfake is image, audio or video content that appears real but was generated or altered by AI in a way that may make it appear authentic.
For generative AI systems placed on the market before 2 August 2026, the amended law contains a limited transitional period until 2 December 2026. This concerns machine-readable marking by providers under Article 50(2); it is not a general postponement of all transparency obligations.
- Is it clear to users that they are communicating with AI rather than a human?
- Are image, audio or video contents used that appear genuine and could therefore qualify as deepfakes?
- Are AI-generated texts on matters of public interest published without human review?
- Is there a defined disclosure rule for deepfakes and unreviewed AI-generated texts on matters of public interest?
- Are technical markings from the system preserved?
- Is it documented who reviews and approves content before publication?
4. Align AI Literacy with the Actual Risk
Under Article 4 as amended in July 2026, providers and deployers must take measures to support the development of AI literacy among the people involved. They do not have to guarantee a particular level of competence for every individual. AI literacy does not mean that everyone must learn to code; employees should understand the systems they use, their limitations and the rules that apply to their own role.
A general one-hour training session can be a useful starting point, but often does not cover the different risks of each use. Someone who uses AI only for initial text drafts needs different knowledge from a person who analyses contractual documents or prepares decision papers.
| Usage Profile | Required Competence | Practical Evidence |
|---|---|---|
| Occasional text assistance | Do not enter confidential data, review results and follow disclosure rules | Short briefing and confirmed usage rules |
| Regular document analysis | Understand data quality, possible errors, data protection and source verification | Role-specific training and review steps |
| Preparation of consequential decisions | Recognise system limitations, human-oversight requirements and possible adverse effects | Advanced training, approval procedures and documented oversight |
| Technical integration or adaptation | Assess changes of role, system modifications, logging and supplier documentation | Technical documentation and named owners |
5. Document Approvals and Changes
The AI Act does not expressly require one standard approval form for every conceivable use of AI. Nevertheless, documented approval remains one of the most important operational governance tools.
Without an approval process, it remains unclear which purpose was reviewed, what data is permitted and who is responsible. AI services also change continuously. A use approved today may need a different assessment after a new model, an additional data source or an automated integration is introduced.
A proportionate approval should record at least the purpose, role, data types, affected individuals, human oversight, transparency measures, residual risks and responsible manager. Changes to the purpose or technical integration must trigger a new review.
06
A Simple Operating Model: Inventory, Classify, Safeguard and Approve
- Inventory: record all official and unofficial AI applications.
- Classify: clarify the deployer or provider role and the specific intended purpose.
- Safeguard: review data, transparency, human oversight, literacy and contracts.
- Approve: document the decision, conditions and responsible people.
- Monitor: regularly assess changes, incidents and new purposes.
This model deliberately does not begin with a particular technology. The process must be reliable first. Only then can a company decide whether AI delivers demonstrable value and under which conditions it can be used.
07
A Compact Checklist for Management
- Is there a complete and up-to-date AI inventory?
- Is a specific purpose documented for every use?
- Has it been clarified whether the company is a deployer or provider?
- Has the company checked whether prohibited practices may be involved?
- Are applicable transparency obligations under Article 50 being met?
- Are there rules for AI-generated text, image, audio and video content?
- Do employees know what data they are permitted to use?
- Is training proportionate to the task and its possible impact?
- Is human oversight provided at the decisive points?
- Are approvals, restrictions and changes documented transparently?
- Are supplier information and contracts available?
- Is a date set for the next review?
08
Conclusion: Establish Visibility First, Then Conduct the Detailed Review
Since 2 August 2026, waiting is no longer a sensible strategy. Companies also do not need to treat every use of AI as high-risk by default. What matters is a sound inventory with specific intended purposes.
A structured approach to AI inventory, roles, transparency, literacy and approvals creates more than formal order. These foundations also show which applications deliver reliable process value and where data, workflows or responsibilities are not yet ready.
For a structured starting point, use the AI Act Readiness Assessmentcan be used. The focus should not be the technology itself, but whether processes, data and responsibilities are organised on a sound basis.
09
Sources and Further Reading
- Regulation (EU) 2024/1689 on Artificial Intelligence
- Regulation (EU) 2026/1744 – Digital Omnibus Regulation on AI
- European Commission: Guidelines on transparency obligations for providers and deployers of AI systems
- European Commission: Transparency obligations under Article 50 of the AI Act
- European Commission: Guidelines for providers of general-purpose AI models
- European Commission: AI literacy under amended Article 4
Next Step
Apply the Question to Your Own Company.
In the discovery call, we assess your specific situation and define a realistic next step.
