Connect with us

AI

The EU AI Act Is Live, Minus Its Costly Half

The EU AI Act’s chatbot labels and GPAI fines took effect on 2 August 2026 after Brussels postponed high-risk duties to December 2027.

Published

on

The EU AI Act’s transparency rules became enforceable on 2 August 2026, after Brussels postponed the high-risk regime. Chatbots must now say they are AI. Deepfakes must be labelled.

The €35 million figure on every briefing slide is real, and it is also old. It attaches to banned practices that have been illegal since February 2025. The audits that companies budgeted for hiring tools, credit scoring and border systems do not start until 2 December 2027.

August 2 Arrived Carrying Half the Rulebook

Regulation (EU) 2024/1689 entered into force on 1 August 2024 on a staggered clock. For two years, 2 August 2026 sat on compliance calendars as the day the core duties would switch on across the single market.

That is not what happened. The date still arrived. It arrived carrying disclosure rules, enforcement powers for the European Commission’s AI Office, and national market surveillance. The heavy high-risk chapters did not travel with it.

On 16 June 2026 the European Parliament approved the Digital Omnibus on AI with 423 votes in favour, 57 against and 174 abstentions. The Council adopted the act on 29 June. The Commission’s own notice is blunt: from 2 August the AI Office and national authorities began enforcing the Act, and new transparency rules started to apply.

Henna Virkkunen, Executive Vice-President for Tech Sovereignty, Security and Democracy, had already framed the delay as a way to make it easier to innovate without lowering the bar on safety. The Omnibus text that followed also simplified the company AI-literacy duty, shifting more of that work onto the Commission and the Member States.

A Fine Ladder That Starts at €7.5 Million

The penalty machinery is live even where the high-risk chapters are not. The AI Office can send requests for information, evaluate models, demand access, and ask providers to restrict a model’s public availability. National authorities police most other systems. The European Data Protection Supervisor covers AI used by EU institutions.

THE FINE LADDER NOW IN FORCE

Infringement Maximum penalty What it covers
Prohibited AI practices €35 million or 7% of worldwide annual turnover, whichever is higher Bans such as social scoring, workplace emotion recognition, and untargeted facial scraping
Other breaches, including GPAI model duties €15 million or 3% of worldwide annual turnover, whichever is higher Transparency failures, general-purpose model rules, and most operator duties already in force
Bad replies to information requests on AI systems €7.5 million or 1% of worldwide annual turnover, whichever is higher Incorrect, incomplete or misleading answers; GPAI providers face the higher GPAI cap instead

Those fines of up to €35 million sit on Article 5 bans, not on the postponed Annex III audits. A company that still runs social scoring or workplace emotion recognition is in the top tier now. A company that has not labelled a customer chatbot sits in the middle tier. A lab that files a sloppy reply to Brussels can be hit for the answer itself.

Parliament Voted to Push High-Risk to 2027

The delay is statutory, not a rumour. Regulation (EU) 2026/1744 in the Official Journal is dated 8 July 2026, was published on 24 July, and entered into force on 27 July, six days before the old high-risk deadline.

Standalone systems listed in Annex III, including recruitment tools, credit scoring, education, law enforcement, border control and critical infrastructure, now face full duties from 2 December 2027. That is 16 months later than the original 2 August 2026 date. AI embedded in regulated products under Annex I, such as medical devices, toys and lifts, must comply by 2 August 2028, a 24-month slide. Machinery is being steered into the machinery regulation instead of a double run under the AI Act.

The Commission presents this as an implementation fix. Harmonised standards and support tools were late. Small mid-cap firms get SME-style relief. Sandboxes get more room. The risk-based design of the Act was not reopened. The high-risk rules from 2 December 2027 still require risk management, data governance, logs, documentation, human oversight, and accuracy and cybersecurity once they land.

THE TWO-SPEED AI ACT CALENDAR

  1. 1 August 2024: The AI Act enters into force as Regulation (EU) 2024/1689.
  2. February 2025: Eight prohibited practices and the original literacy duty start to apply.
  3. August 2025: Duties for providers of general-purpose AI models start to apply, still without Commission fine powers.
  4. 16 June 2026: Parliament approves the Digital Omnibus on AI.
  5. 27 July 2026: Regulation (EU) 2026/1744 enters into force and rewrites the high-risk dates.
  6. 29 July 2026: Germany’s KI-MIG enters into force and names the Federal Network Agency as lead supervisor.
  7. 2 August 2026: Transparency rules, national market surveillance and GPAI enforcement powers apply.
  8. 2 December 2026: The ban on AI that generates non-consensual intimate images or child sexual abuse material applies, and legacy systems must finish machine-readable marking.
  9. 2 December 2027: Annex III high-risk duties apply.
  10. 2 August 2028: Annex I product-embedded high-risk duties apply.

Trade unions argued the workplace clauses were weakened by parking employment systems until late 2027. Industry, with Germany among the loudest voices, wanted factory-floor AI kept under product-safety law rather than a second AI file.

The Chatbot Label Is Mandatory From August

Article 50 is the part of the statute that actually changed on 2 August 2026 for ordinary deployers. The Commission published transparency guidelines on 20 July 2026 and, on 31 July, a first list of more than 180 organisations that had signed the Code of Practice on transparency of AI-generated content.

TRANSPARENCY DUTIES LIVE SINCE 2 AUGUST

  • Interactive systems: Chatbots and other tools that talk to people must make clear that the user is dealing with AI, not a human.
  • Synthetic media: AI-generated or altered content must carry machine-readable marks so it can be detected.
  • Deepfakes: Images, video or audio that have been edited or generated with AI must be labelled.
  • Public-interest text: AI-written text on matters of public interest needs a visible label when there is no human editorial control.
  • Emotion and biometrics: People must be told when they are subject to emotion recognition or biometric categorisation, in the cases those tools are still allowed.

Systems already on the market before 2 August 2026 have until 2 December 2026 to finish the machine-readable marking under Article 50(2). Anything placed on the market after 2 August has to comply from day one. HR chatbots sit in this bucket now. CV-sorting software that decides who gets an interview does not, until 2 December 2027.

That split is the practical joke of the calendar. The tool a candidate talks to must announce itself. The tool that ranks the candidate can wait.

Germany’s Network Agency Took the Watch

The AI Act is a regulation, so the duties apply directly. Each Member State still had to name who knocks on the door. Germany missed the 2025 designation deadline and then moved fast after the new government formed.

The Bundestag adopted the KI-Marktüberwachungs- und Innovationsförderungsgesetz, the KI-MIG, on 11 June 2026. It entered into force on 29 July 2026, four days before the general application date. The Federal Network Agency, the Bundesnetzagentur, is the central market-surveillance authority and the single point of contact for Brussels.

BaFin keeps AI that is tied to regulated financial activity, including insurance. The Federal Commissioner for Data Protection keeps the GDPR overlay. An independent chamber inside the Network Agency is meant to handle the most rights-sensitive high-risk files, such as justice and law enforcement, once those chapters apply. The statute is organisational. It does not add extra duties on top of the EU text.

That architecture is now running ahead of the high-risk workload it was built for. Until December 2027, the German supervisor’s live docket is bans, labels, complaints, and coordination, not a conveyor belt of Annex III conformity files.

Who Faces Penalties While High-Risk Rules Wait?

The first exposed parties are GPAI model providers, who can be compelled and fined by the AI Office, and any firm whose chatbot, deepfake pipeline or synthetic-content stack still has no disclosure, because those Article 50 duties have applied since 2 August 2026 while hiring, credit and policing systems remain under older law until 2 December 2027.

WHO IS IN THE WINDOW NOW

  • Model labs: General-purpose model duties have applied since August 2025; the Commission’s power to investigate and fine applied from 2 August 2026.
  • Customer-facing bots: HR assistants, support chat and voice agents must identify themselves as AI.
  • Media and marketing stacks: Deepfakes and other synthetic output need labels, with a short grace period only for older generators.
  • Banned-practice holdouts: Social scoring, untargeted facial scraping and workplace emotion recognition were already illegal; they can now be punished.

Workers do not get the same pause everywhere. Italy’s Law 132/2025, with 2026 implementing decrees, says decisions on hiring, changes to the contract, discipline and dismissal cannot rest on automated processing alone. The last word stays with a natural person who actually has authority. A dismissal that breaks that rule is void. Employers also have to explain, through a person, how an AI-informed decision was reached.

In the rest of the Union, Annex III employment tools stay outside the AI Act’s dedicated risk-management, logging and oversight duties until 2 December 2027, unless a system is significantly redesigned. GDPR limits on solely automated decisions still apply. They are not a substitute for the high-risk chapter that was supposed to land in August.

Model Providers Already Have Letters From Brussels

The Commission did not wait for a test case to use its new kit. In late August 2026 it began sending requests for information to general-purpose model providers in several regions, covering security, independent evaluations, post-market monitoring and training-content summaries. A Commission spokesman put the first wave at more than 30 companies. Incorrect or misleading replies can be fined. Ignoring a request issued by decision can be fined too.

That is a different enforcement story from the one sold around the €35 million poster. Frontier labs now answer to the AI Office on documentation, copyright summaries and systemic-risk controls. National authorities watch chatbots and bans. The hiring engine and the credit model sit in the gap until 2027, unless a Member State fills it the way Italy did.

Separate files are already moving under the same statute. Brussels has opened an AI Act file on OpenAI agents after a wiki-swarm incident, a reminder that GPAI oversight is not theoretical. The complaint and whistleblower channels the AI Office launched are built for that track, not for a high-risk register that does not yet apply.

The Act that companies must obey in September 2026 is a labelling law, a model-provider law, and a ban list. The product-safety law for high-risk systems is still on the calendar, dated 2 December 2027, and it will take another statutory change to move it again.

Disclaimer: This article is news reporting on the EU AI Act and related national measures, and it is for information only. It is not legal advice, a compliance programme, or a determination of any company’s risk, fine exposure or classification under Regulation (EU) 2024/1689 or Regulation (EU) 2026/1744. Readers who deploy or provide AI systems should consult a qualified EU regulatory or data-protection lawyer, and their national market-surveillance authority, before changing products, contracts or filings. Penalty caps, application dates and national procedures reflect the official texts and Commission notices cited here and can change if the law is amended or if authorities issue new guidance.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending