August 2, 2026, has arrived. With this date, a large portion of the European AI Act becomes applicable. However, anyone who concludes that the AI Regulation is now fully in effect is mistaken. The AI Omnibus, which came into effect shortly before, has once again altered the timeline and, in particular, postponed the obligations for high-risk AI.
For management, IT, and legal departments, therefore, it is not a matter of continuing to use the old deadline calendar with particular determination. What matters is which regulations are already in effect today, which ones can be enforced for the first time, and which ones are still awaiting implementation.
Regulation (EU) 2024/1689 entered into force on August 1, 2024. However, its provisions will be phased in gradually. The AI Omnibus amended this timeline a few days before the current deadline.
As of August 2, 2026, the situation for companies will be as follows:
August 2, 2026, is therefore an important milestone. It is simply not the culmination that it is often portrayed as in older overviews.
First and foremost, the prohibited AI practices remain relevant. For example, companies are not permitted to use AI that manipulates or deceives people into making decisions that cause significant harm. Also prohibited are, among other things, certain forms of social scoring, the indiscriminate collection of facial images to build recognition databases, and emotion recognition in the workplace, unless a strictly limited exception applies.
Such use cases should not be evaluated only during the procurement phase or shortly before the system goes live. Prohibited-activity checks should be part of the approval process for an AI project. A system does not become any less harmful simply because it has already been paid for.
Article 4 also remains applicable. However, the AI Omnibus Act has revised the provision. Providers and operators must take measures to support the development of AI competence among employees and other individuals who work with AI systems on their behalf. They are not, however, required to guarantee a specific level of competence for each individual.
For companies, this continues to make a case for role-based training and information initiatives. A software developer needs different knowledge than an employee who uses a language model for summaries. Prior knowledge, the context of use, and potential impacts on affected individuals are crucial. A one-time, general training slide rarely fulfills this need completely. Above all, it satisfies the desire to have a training slide.
The transparency requirements set forth in Article 50 are now in effect. They apply, among other things, to AI systems that interact directly with people, technically identifiable markers for synthetic content, and disclosure requirements for deepfakes and certain texts concerning matters of public interest.
For small and medium-sized businesses, this may include, for example, customer chatbots, AI-generated advertising content, synthetic voices, or automated information services. Which obligation applies depends on whether the company is a provider or an operator and on the specific function performed by the AI.
A detailed analysis of visible indicators and machine-readable labels is provided in the K11 article “EU AI Act: When AI Must Be Visible.”
A new transitional provision is important: Providers of systems that generate synthetic audio, image, video, or text content and were already placed on the market before August 2, 2026, have until December 2, 2026, to comply with the technical labeling requirement set forth in Article 50, paragraph 2. This is not a general grace period for all transparency requirements. It pertains to a specific provider obligation and should be treated as such.
The obligations for providers of GPAI models have generally been in effect since August 2, 2025. These include technical documentation, information for downstream providers, a strategy for complying with European copyright law, and a public summary of the training content used. Additional requirements apply to particularly powerful models that pose systemic risk.
As of August 2, 2026, the European AI Office will have the authority to fully enforce these regulations. It may request information and access to models, conduct assessments, order corrective measures, and impose sanctions in the event of violations.
Simply using an external language model does not normally make a medium-sized company a provider of a GPAI model. The situation may be different, however, if a model is significantly modified, offered under the company’s own name, or integrated into one of its own market offerings. Roles are determined not by job descriptions, but by how the system is actually used.
The K11 article “EU AI Act: What Obligations Apply to Your AI System?” provides an in-depth overview of how to determine the relevant obligations .
The AI Omnibus has postponed the implementation of the extensive requirements for high-risk AI. For systems in areas such as employment, education, credit scoring, or critical infrastructure, the relevant regulations will generally take effect on December 2, 2027. For AI used as a safety component in certain regulated products, the key date is August 2, 2028.
This does not mean that risk management, technical documentation, record-keeping, human supervision, and specific operator obligations are now fully applicable. Nevertheless, companies should not view this additional time as a regulatory “vacation.”
First, other regulations remain applicable. An AI system used for candidate selection can already cause problems under data protection, labor, or anti-discrimination laws. On the other hand, Article 111 contains a transitional provision for existing high-risk systems. Whether and when a system was placed on the market or put into operation, and whether its design was subsequently significantly altered, can be decisive for its future applicability.
Companies should therefore document the implementation date, intended purpose, versions, and significant changes in a way that is easy to trace. Delaying the process does little good if, later on, no one can recall which system version was actually in use and when.
As of August 2, 2026, the AI Office and the relevant national authorities will be able to enforce the regulations that are already in effect. This applies in particular to prohibited practices, AI competence, transparency requirements, and the guidelines for GPAI providers. The high-risk requirements, which will take effect at a later date, cannot, however, be brought forward through an accelerated implementation schedule.
Germany finalized its regulatory framework shortly before the deadline with the implementation act published in the Federal Law Gazette. The Federal Network Agency will play a central role in coordination, market oversight, advisory services, and complaint handling. In regulated sectors, existing specialized agencies will remain responsible.
Nor should the provisions on fines be understood as a uniform schedule of penalties for every instance of missing documentation. Among other factors, the nature, severity, and duration of a violation, as well as the size of the company, are decisive. The first crucial factor is whether the violated obligation was even applicable at the time in question.
A robust AI Act Check doesn't start with a lengthy policy, but with a useful overview. Companies should now:
In practice, IT, legal, data protection, information security, and the relevant business units should all have access to this overview. The AI Act is not purely an IT project. However, it won’t be any better if every department maintains its own Excel spreadsheet with conflicting information.
As of August 2, 2026, important new provisions of the AI Act have taken effect, particularly the transparency requirements. At the same time, the practical enforcement of existing requirements has already begun. The comprehensive obligations for high-risk AI, however, have been postponed by the AI Omnibus until the end of 2027 and August 2028, respectively.
For companies, precision is now more important than ever: Which systems are being used? What role does the company play? Which obligations apply today, which will apply later, and which transitional provisions are in effect?
K11 helps companies translate these questions into a robust AI governance framework and integrate it with data protection, information security, and existing management systems. After all, regulation doesn’t become clear simply by filing it away in a folder. It becomes clear when responsibilities, systems, and decisions align.