Press Release

EU AI Act Enforcement Expands on 2 August 2026: Are Your AI Systems Compliant?

The EU Artificial Intelligence Act starts to apply generally on 2 August 2026, when many of its rules take effect. The Digital Omnibus on AI moved the high-risk deadlines to December 2027 and August 2028. It did not generally move the prohibitions or the transparency obligations.

Any individual or business, including a competitor, that considers your AI system doesn’t comply with these rules may file a complaint with the national market surveillance authority. The authority must deal with the complaint. If it has reason to believe that your AI system poses a risk, it must conduct an assessment. It can ask for internal documents, demand corrective measures and impose fines.

The maximum fines are significant: up to €35 million or 7 per cent of total worldwide annual turnover for prohibited practices; up to €15 million or 3 per cent for breaches of the Act’s duties, including transparency duties; and up to €7.5 million or 1 per cent for providing incorrect, incomplete or misleading information in response to an official request.

If you are placing AI systems on the market or putting them into service in the EU, even if you’re based outside the EU, you must be prepared for regulatory scrutiny from 2 August 2026.

Belitsoft is a global AI consulting and development company with offices in North America and Europe. It offers AI consulting services and senior AI developers to build, engineer and maintain AI systems that comply with the EU AI Act.

The investigative process and the burden of proof

If your company is under investigation, you’ll have to demonstrate compliance with the EU Artificial Intelligence Act.

Safeguards matter under the new Article 5 rules on non-consensual sexually explicit or intimate material and child sexual abuse material. These rules can apply when prohibited output was not the system’s intended purpose but was foreseeable and reproducible. In that case, whether you had appropriate technical or other safeguards can determine whether the prohibition applies to your AI system.

This makes documentation, testing and monitoring important. Documented safeguards and test records are your main defence.

Article 5. Prohibited practices

The EU Artificial Intelligence Act prohibits some types of AI activity. Most of the prohibitions set out in Article 5 have applied since 2 February 2025.

Article 5 prohibits the placing on the market, putting into service and use of AI systems that employ manipulative techniques to materially distort behaviour and cause or risk significant harm, exploit vulnerabilities linked to age, disability or social or economic circumstances, or engage in social scoring that leads to unjustified or disproportionate treatment.

This includes using biometric categorisation to infer sensitive characteristics, creating facial recognition databases through untargeted scraping, predicting a person’s risk of committing a criminal offence based solely on profiling, using emotion recognition in workplaces and educational institutions, and using real-time remote biometric identification in publicly accessible spaces for law enforcement.

If your AI systems are doing any of these things, you should have stopped or changed them already.

Additional prohibitions on AI systems that generate or manipulate non-consensual sexually explicit or intimate material or child sexual abuse material will apply from 2 December 2026.

Article 50. Transparency obligations

Where AI systems interact with users or generate content, you may have to tell users that AI is involved, mark the content, or both.

If this is not evident from the context of use, Article 50 requires providers of AI systems intended for interaction with users to design them so that users know they’re interacting with AI. Depending on the interface, a prominent label or banner displayed at the very start of the first interaction may be sufficient. Concealing this information in the terms of use doesn’t meet the requirement.

Audio, images, video or text generated or manipulated by AI must be marked in a machine-readable format so that they can be detected as artificially generated or manipulated, except for standard editing functions and assistive functions that do not significantly alter the input data or its meaning.

Individuals subject to biometric categorisation or emotion recognition systems must be informed that the system is in operation.

Deepfakes and AI-generated or manipulated text published to inform the public on matters of public interest must be labelled as artificially generated. Public-interest text may be exempt if it has been editorially reviewed and an editor or company takes responsibility for publishing it. Artistic, creative, satirical, fictional or similar deepfake works have lighter requirements.

These transparency obligations apply from 2 August 2026, so you must implement these disclosure procedures immediately if your systems interact with users, generate content, or use biometric categorisation or emotion recognition.

Providers of generative AI systems placed on the market before 2 August 2026 must comply with the machine-readable marking obligation under Article 50(2) by 2 December 2026.

Deadlines for high-risk systems have been extended

The main restrictions and transparency obligations have not been postponed, but the deadlines have been extended for systems classified as high-risk. The change comes from Regulation (EU) 2026/1744, the Digital Omnibus on AI. It entered into force on 27 July 2026.

High-risk systems described in Annex III, including those used in recruitment, credit scoring and education, must now comply with the requirements from 2 December 2027. High-risk systems embedded in regulated products must comply with these requirements by 2 August 2028.

These extensions don’t affect most of the prohibitions under Article 5, which have applied since 2 February 2025, or the transparency obligations, which apply from 2 August 2026. Additional prohibitions under Article 5 apply from 2 December 2026.

Your obligations regarding generated content, chatbots and prohibited use cases already apply or will apply before the high-risk deadlines.

Extraterritorial application

The EU AI Act is extraterritorial. The Act applies to providers that place AI systems or general-purpose AI models on the EU market, deployers that use AI systems in the EU, and providers or deployers outside the EU where the system’s output is used in the EU.

Whether you’re located in the EU or the US, if your AI product is placed on the EU market, put into service in the EU, or its outputs are used in the EU, you may be subject to the Act.

Companies using another provider’s high-risk system under the extended deadlines will have duties on monitoring, input data, oversight by their staff and incident reporting. Banks and insurance companies may already meet some of these duties through the financial governance controls they have in place.

If you’re outside the EU and sell into the EU market, compliance is ongoing work.

Your first line of defence is an inventory

Preparation for the EU AI Act starts with compiling an internal inventory of your AI systems.

There is no explicit requirement in the Act to create an inventory for the rules applying from August 2026. However, without one, it becomes much harder to show that you have transparency measures in place under Article 50 or regularly monitor your systems for prohibited practices under Article 5.

If a regulator audits your system, finds non-compliance and orders corrective action, it may require you to bring the AI system into compliance, withdraw it from the market or recall it within a set period. That period may not exceed 15 working days and may be shorter.

You have to know which AI models your company is using, what data they’re consuming, and what each model is being used for right now.

Having a comprehensive and current inventory of all the artificial intelligence systems used by your company is critical to your ability to respond quickly and convincingly to regulatory authorities.

How to make your own inventory

Here is a five-step process to get an AI inventory up fast.

First, you get candidates from three sources:

  • development staff for API calls to OpenAI, Anthropic, Google or your own models;
  • procurement staff for purchased SaaS products with built-in AI features;
  • product managers for features that generate content, chat, recommend, score or recognise.

Second, you check each candidate against the official definition.

The Commission guidelines exclude traditional software that only follows rules defined entirely by its developers. The Act covers machine-based systems that infer from input data how to generate predictions, content, recommendations or decisions.

Third, you check each system with the official, free EU AI Act Compliance Checker on the Commission’s AI Act Service Desk to see which obligations may be triggered.

The Commission’s Compliance Checker is an official tool, but it is still in beta. The results are for information only and don’t constitute legal advice or represent the Commission’s assessment of your situation or obligations. Even so, if you record the result, you have a useful record of the check you carried out.

Fourth, you create a table with columns for the name, intended purpose, model, your role, availability in the EU, Article 5 assessment date, Article 50 obligations, Annex III classification, owner and date of the next review.

Fifth, you assign an owner and require every new AI feature to get a new or updated row before launch.

Maintaining your inventory over time

How the law applies to your products can change over time, so you need to keep your compliance records up to date.

You’ll need to update your inventory when you supply the product to an EU customer, repurpose a feature, change how your marketing describes the product’s purpose, or when the scope of the law changes. In each case, your earlier finding that the law doesn’t apply to a particular product may no longer be valid.

Without updating your inventory and compliance assessments, no one in your company will be aware of this change. Changes in how an AI system is used can create new legal duties. Those duties often follow what the system is meant to do and how it’s used, not the model’s default features.

If you don’t have a policy that every new AI feature gets a new or updated row before launch, your inventory will no longer match the reality of your AI systems.

Conclusion

An inventory of your AI systems protects your business from regulatory surprises. It lists each AI system’s intended purpose, its functions and the test records you hold. That gives you the evidence to answer any enquiry from a regulatory authority.

With a well-organised inventory and documented controls, 2 August 2026 becomes just another date on the calendar.

About the author

Dmitry Baraishuk is a Partner and Chief Innovation Officer at Belitsoft. Belitsoft is a software engineering company specialising in DevOps, AI integration and enterprise application modernisation. The company serves healthcare, fintech and enterprise SaaS clients in the US, UK and Canada. Belitsoft publishes technology trend analyses to help business and technology leaders make informed decisions about software investment.

Author

Leave a Reply

Related Articles

Back to top button