Home/Insights/AI Regulation

EU AI Act: What Actually Changes on 2 August 2026?

By Ani BjörkströmPublished 2 August 2026Reviewed 20 September 20267 min video + articleAI Regulation

EU AI Act: What Actually Changes on 2 August 2026?
▶ Watch the full 7-minute tutorial · free on YouTube

AI REGULATION

EU AI Act: what actually changes on 2 August 2026?

In short: The Digital Omnibus on AI (Regulation 2026/1744) moved the full high-risk compliance deadline from 2 August 2026 to 2 December 2027 — 16 extra months — entering into force six days before the deadline it was built to move.

Key takeaways

  • The Digital Omnibus on AI (Regulation 2026/1744) moved the full high-risk compliance deadline from 2 August 2026 to 2 December 2027 — 16 extra months — entering into force six days before the deadline it was built to move.
  • Article 50 transparency rules did not move: from 2 August 2026, customer-facing AI must disclose itself in the conversation, and synthetic content needs machine-readable AI markings.
  • Violating Article 50 carries fines up to 15 million euros or 3% of worldwide annual turnover, enforced by national market surveillance authorities — not Brussels.

Almost everything published about the EU AI Act before this summer is out of date. The Parliament approved the Digital Omnibus on AI on 16 June (423 for, 57 against, 174 abstentions), and it hit the Official Journal on 24 July as Regulation 2026/1744.

Which EU AI Act deadlines moved?

High-risk AI under Annex 3 — credit scoring, insurance pricing, hiring, education — no longer faces its full compliance package on 2 August 2026; the deadline is now 2 December 2027. For AI embedded in regulated products like medical devices and industrial machinery, the date moved from August 2027 to 2 August 2028.

Delayed does not mean deleted. Existing model governance rules apply today, and the European Banking Authority has said rules like DORA already cover much of this ground — no compliance holiday.

What still applies from 2 August 2026?

Two things did not move: Article 50 transparency duties and enforcement over general-purpose AI providers. Article 50 contains four duties, and at least two almost certainly touch your business.

Article 50 dutyRequirement from 2 August 2026
Conversational AIChatbots, voice agents, and robo-advisors must disclose AI in the conversation itself — terms and conditions do not count.
Synthetic contentAI-generated text, images, audio, and video need machine-readable AI markings (metadata, watermarking).
Emotion recognitionPeople exposed to emotion recognition or biometric categorization — such as call sentiment analysis — must be informed.
Deepfakes and public textDeepfakes need visible labels; AI-generated public-information text must be disclosed unless a named human editor takes responsibility.

One nuance almost everyone gets wrong: systems on the market before 2 August get until 2 December 2026 to comply with marking, but anything launched after must be marked from day one. General-purpose AI provider obligations have applied since August 2025 — what is new is teeth: from 2 August the Commission's AI Office can demand documentation, run evaluations, and fine providers up to 15 million euros or 3% of global turnover. Fine-tuning or redistributing a model under your own name may make you a provider too.

What should banks and asset managers do before Monday morning?

Work through a five-point checklist: inventory every EU-facing conversational AI and add in-conversation disclosure; verify machine-readable marking survives your export pipeline; set a deepfake policy and name an editor for AI-drafted public content; check your vendors; and do not stand down your high-risk program — December 2027 arrives fast. An internal LLM copilot is not high risk by itself, but the moment it faces customers, the disclosure duty applies.

Financial institutions also keep their national financial supervisors — in Sweden, Finansinspektionen. Ani Björkström has condensed the analysis into a free one-page classification checklist, linked in the video description.

FAQ

Is credit scoring still high-risk AI?

Yes. Credit scoring for individuals remains high risk, as does AI pricing in life and health insurance — the obligations simply land on 2 December 2027 instead.

Who enforces the Article 50 fines?

National market surveillance authorities, not Brussels — up to 15 million euros or 3% of worldwide turnover, whichever is higher, under Article 99.

Are pre-2026 guides to the AI Act still usable?

Mostly not. Guides published before summer 2026 describe deadlines that have since moved, including explainers with hundreds of thousands of views.

Full transcript of the video (890 words, 8 sections)

Chapters: 0:00 The deadline you prepared for changed · 0:29 What actually happened · 1:06 What moved: Dec 2027 & Aug 2028 · 1:40 Why your checklist is outdated · 2:04 Article 50: NOT delayed · 2:21 Duty 1 — chatbot disclosure · 2:42 Duty 2 — machine-readable marking · 3:12 Duty 3 — emotion recognition · 3:24 Duty 4 — deepfakes & AI text · 3:39 The fines: €15M or 3 · 3:59 GPAI enforcement begins · 4:33 For finance teams · 4:44 Your classification map · 5:26 Who supervises you · 5:41 Checklist before Monday · 6:28 Free checklist + read the law

0:03 On Sunday, the biggest AI law switched on and almost everything you read about this before is out of date. Now, some deadlines moved on, but there are still two things that applies already from 2nd of August and one of them can result in fines up to 15 million euros. In the next 6 minutes, I will explain what stayed, what is moved, and what to update until Monday morning. Let's get started. Let's start with what actually happened because the timeline itself is the story. On June 16th, the European Parliament approved what's called the Digital Omnibus on AI. 423 votes in favor, 57 against, and notably, 174 abstentions. The council adopted it on June 29th.

0:52 It was published in the official journal on July 24th as a regulation 2026/1744. And it entered into force on July 27th. That is 6 days before the deadline it was built to move. So, what moved? The headline change is high-risk AI. If your system falls under Annex 3, credit scoring, insurance pricing, hiring, education, the full compliance package was supposed to apply from August 2nd, 2026. That deadline is now December 2nd, 2027. 16 extra months. And for AI embedded in regulated products, like medical devices and industrial machinery, the date moved from August 2027 to August 2nd, 2028. And this is exactly why so much of what you'll find online is now wrong.

1:45 Any guide, checklist, or webinar published before this summer describes a legal position that no longer exists. Even the biggest explainers with hundreds of thousands of views are describing the old law. But before anyone stands down their compliance program, two things did not move at all. The first is Article 50, the transparency rules. These apply from this Sunday, August 2nd, exactly as scheduled. And these are not edge cases. Article 50 contains four duties, and at least two of them almost certainly touch your business. Duty one, if you run any AI that talks to people, a customer chatbot, a voice agent, a robo-advisor, you must tell users they are dealing with AI, unless it is genuinely obvious.

2:34 And the disclosure has to live in the conversation itself. A line buried in your terms and conditions does not count. Duty two, if your systems generate synthetic content, text, images, audio, or video, the output must be marked as AI generated in a machine-readable format. Think metadata and watermarking. One nuance almost everyone gets wrong, systems already on the market before August 2nd get until December 2nd, 2026 to comply. Anything you launch after Sunday must be marked from day one. Duty three, if you deploy emotion recognition or biometric categorization, for example, sentiment analysis on customer calls, you must inform the people exposed to it.

3:24 Duty four, deep fakes must be visibly labeled. And AI-generated text published to inform the public must be disclosed as well, unless a human editor reviews it and a named person takes editorial responsibility for it. Now, the part that gets attention, the fines. Violating Article 50 carries penalties of up to 15 million euros or 3% of total worldwide annual turnover, whichever is higher. That's under Article 99, and who enforces it? Not Brussels. Your national market surveillance authorities do. The second thing that did not move, enforcement over general-purpose AI, the companies behind the big models. Their obligations have actually applied since August 2025. What's new on Sunday is teeth.

4:13 From August 2nd, the European Commission's AI office can demand documentation, run model evaluations, order mitigation measures, and fine providers up to 15 million euros or 3% of global turnover. And a warning, if your firm fine-tunes or redistributes a model under its own name, you may count as a provider yourself. So, let's make this concrete for financial services, because this is where I work every day. If you're at a bank, an insurer, or an asset manager, here is your map. Credit scoring and creditworthiness models for individuals, still high risk, but the full obligations now land in December 2027. The same goes for AI pricing in life and health insurance. Delayed, not deleted.

5:00 Your internal LLM assistant, the co-pilot your teams use on client data, is not high risk by itself. But the moment it faces customers, the disclosure duty applies from Sunday. And supervisors expect the usual governance around it. The European Banking Authority has said existing rules like DORA already cover much of this ground. There is no compliance holiday. One more finance-specific detail. Even where the AI office takes over supervision elsewhere, financial institutions stay with their national financial supervisors. Here in Sweden, that means the Finance Inspection. So, here is your checklist before Monday morning. One, inventory every EU-facing conversational AI.

5:46 Chatbots, voice agents, robo advisors, and add clear in-conversation disclosure. Two, if you generate content with AI, verify that machine-readable marking actually survives your export pipeline. Three, set a deepfake policy for marketing, and name an editor responsible for AI-drafted public content. Four, check your vendors. Is your model supplier meeting its obligations? And five, the one people get wrong, do not stand down your high-risk program. December 2027 arrives faster than you think, and your existing model governance rules apply today. I've put all of this into a free one-page classification checklist. The link is in the description.

Want this working inside your finance team?

Ani Björkström

Ani Björkström — founder of QvantX Sweden AB, a Stockholm consultancy building AI solutions for banks, asset managers and finance teams. Anthropic partner. Every article starts from a real client build, minus the confidential parts. LinkedIn →