AI Act: the checklist for organisations from 2 August 2026

From 2 August 2026 the AI Act is generally applicable and supervisory authorities have full powers. The checklist of obligations already in force for providers and deployers of AI systems, the ones postponed by the Digital Omnibus and what you need to have ready.

AICybersecurityAI ActComplianceGovernanceEURegulation 2024/1689Digital OmnibusHigh RiskTransparencyACNPenalties
Contents
  1. The checklist of obligations in force
  2. What is not mandatory today
  3. The three things to do anyway
  4. Why the dates changed
  5. The obligations in detail
  6. Who supervises and the penalties
  7. Sources
AI Act checklist at 2 August 2026. Applicable from today, Article 50 transparency obligations: chatbots and assistants (50.1), emotion recognition and biometric categorisation (50.3), deepfakes and public-interest text (50.4), technical marking of synthetic content (50.2), with compliance by 2 December 2026 for systems already on the market. Already mandatory before today: AI literacy since 2 February 2025, prohibited practices for the most part since 2 February 2025, rules for GPAI models since 2 August 2025, while providers of models placed before must comply by 2 August 2027
What becomes applicable today and what already was. Sources at the end.

From 2 August 2026 the AI Act is generally applicable and supervisory authorities have full powers. The Digital Omnibus pushed the high-risk part forward, so the list of what is due today is shorter than the one written in 2024.

The tables apply to whoever provides AI systems and to whoever uses them, companies and public bodies alike, with no size thresholds.

The checklist of obligations in force

ObligationWho it applies toIn force sinceWhat you need to have
Disclosing that the other side is an AI (Art. 50.1)providers of systems interacting with people2 Aug 2026a notice at the start of the conversation, in the product and in the documentation
Emotion recognition and biometric categorisation (Art. 50.3)whoever deploys the system2 Aug 2026prior notice to the people captured, aligned with the GDPR one
Disclosing deepfakes and public-interest text (Art. 50.4)whoever deploys the system and circulates the content2 Aug 2026a visible label on the content, unless there is human review or editorial responsibility
Technical marking of synthetic content (Art. 50.2)providers of generative systems2 Aug 2026 for systems placed on the market from today, 2 Dec 2026 for those already on itmachine-readable marking that is effective, reliable and interoperable, making the content detectable as generated or manipulated
AI literacy (Art. 4)providers and deployers2 Feb 2025training measures proportionate to the role, tracked
Staying out of prohibited practices, for the most part (Art. 5)everyone2 Feb 2025a documented check on use cases, reread against the prohibitions the Omnibus added on non-consensual intimate images and synthetic CSAM
Rules for GPAI models (Arts. 53-55)providers of models placed on the market from 2 Aug 20252 Aug 2025technical documentation, copyright policy, summary of training data

What is not mandatory today

ObligationWhen it starts
Stand-alone high-risk systems, Annex III2 December 2027
High-risk systems tied to products, Annex I2 August 2028
Marking of synthetic content (Art. 50.2), only for generative systems already on the market before 2 August 20262 December 2026
Providers of GPAI models placed on the market before 2 August 20252 August 2027
National regulatory sandboxes2 August 2027

The three things to do anyway

An inventory of the AI systems used or supplied, with risk classification against the consolidated text and an internal point of contact. Without it there is no answering a request for information, and it is the same inventory needed for the Cyber Resilience Act and for NIS2, so it makes sense to build only one.

The Article 50 work wherever systems are already exposed. A chatbot on the website, an assistant inside the product or a service that generates content need interface and documentation work measured in days. It is today’s deadline, not a future one.

Using the sixteen months gained on high risk. The postponement to December 2027 moves the date rather than the work: conformity assessment, risk management, data quality and human oversight still have to be built, and they are the same items that come back in the obligations where GDPR and the AI Act overlap.

Why the dates changed

Regulation (EU) 2026/1744 of 8 July 2026, amending Regulation (EU) 2024/1689 along with Regulations (EU) 2018/1139 and (EU) 2023/1230, was published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July. It closes a process that began with the provisional political agreement of 7 May, passed through the European Parliament vote of 16 June and the Council’s adoption on 29 June.

Until 27 July the applicable date was still 2 August 2026, because a political agreement produces no legal effect and negotiated dates become binding only on publication. The postponement therefore took effect with six days of margin over the deadline it moves, and until that moment anyone who had suspended their compliance programme on the strength of the Omnibus was uncovered.

The Omnibus also touches the perimeter: it clarifies the notion of safety component and the high-risk classification criteria, excludes products already governed by the Machinery Regulation from direct application, and introduces support measures for SMEs and small mid-caps.

The obligations in detail

Transparency, Article 50. Anyone providing systems that interact with people has to make their artificial nature recognisable. Anyone deploying emotion recognition or biometric categorisation has to inform the people exposed, and anyone circulating deepfakes has to disclose them. It is the obligation touching the largest number of organisations, because it covers any conversational assistant exposed to customers or citizens. The article also covers generated or manipulated text meant to inform the public, unless there is human review or editorial responsibility. Technical marking of synthetic content, which sits in paragraph 2 of the same article and consists in making it machine-detectable rather than carrying a visible disclosure, applies from today to generative systems placed on the market from 2 August 2026: the transition until 2 December 2026 covers only those who already had their system on the market before that date.

AI literacy. The Article 4 training obligation has been in force since 2 February 2025, but from today someone can check compliance with it. The Omnibus softened its scope compared with the original text, so a programme designed last year should be checked against the consolidated version before being treated as settled. On top of the European layer sits the Italian one: law 132/2025 and its implementing decrees impose cross-cutting training and assign competences to ACN and AgID.

General-purpose models. The Article 53-55 rules apply from 2 August 2025 to models placed on the market from that date, while providers of models placed before it must comply by 2 August 2027. Article 54 concerns authorised representatives of providers established outside the Union and Article 55 covers models with systemic risk. From today the Commission can fully enforce them, penalties included.

Who supervises and the penalties

National authorities had to be designated and given powers by 2 August 2025, and the penalty regime has been applicable since then. What changes today is the object: the Article 50 transparency obligations become verifiable and punishable too, and the Commission gains the power to fully enforce the general-purpose model obligations.

In Italy coordination sits with the National Cybersecurity Agency, with AgID as the second authority designated by law 132/2025 and sector competences for the Data Protection Authority, Banca d’Italia, Consob and IVASS. For practices prohibited under Article 5 the ceiling is EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. For general-purpose model providers the Commission can go up to EUR 15 million or 3%.

Sources

Need support?Under attack?Service Status
Need support?Under attack?Service Status