The EU AI Act's August 2 Deadline: What's the Actual Minimum You Need?
Key takeaways
- -For most companies, the August 2 obligation is transparency (Article 50), not the full high-risk documentation regime. The heavy Annex III obligations were deferred to December 2, 2027.
- -The realistic minimum for a limited-risk company: confirm your risk tier, add AI-interaction disclosures, label AI-generated content and deepfakes, add emotion/biometric notices where relevant, and document what you did.
- -If you're genuinely high-risk, Article 50 transparency still applies on August 2 — but the documentation marathon runs to December 2027. Triage the transparency work now, plan the rest.
August 2 is almost here, and if you haven't started, the internet is not helping. Most of the last-minute advice reads like a fire alarm: conformity assessments, technical documentation, CE marking, database registration, all by August 2. It's enough to make a small team panic-hire a consultant.
Here's the reassuring truth, and it's genuinely reassuring for most companies: a lot of that advice is describing the wrong deadline. The heavy regime got pushed to 2027. What's actually due August 2 is smaller, and for a typical company it's a few days of work, not a compliance programme. Let's separate the panic from the minimum.
What's actually due August 2
After the Digital Omnibus (now adopted), the August 2, 2026 date carries a specific, limited set of obligations:
- Article 50 transparency. Telling people when they're interacting with AI, labelling AI-generated content and deepfakes, and notices for emotion recognition or biometric categorisation. This is the one that touches almost everyone.
- GPAI obligations become enforceable for providers of general-purpose AI models.
- Enforcement powers switch on for national authorities and the AI Office.
And critically, here is what is not due August 2: the full high-risk regime. Risk management, technical documentation, conformity assessment, CE marking, EU database registration, the whole Annex III marathon, all of that was deferred to December 2, 2027. If an article is telling you to complete a conformity assessment by August 2, it's working from the pre-Omnibus timeline. Don't let it set your priorities.
The reframe that saves you
The genuine minimum
Every company in scope should do these two things regardless of tier:
- Confirm your risk tier. You can't scope the work until you know whether you're prohibited, high-risk, limited-risk, or minimal. Most companies using AI land in limited or minimal. A free classification takes a few minutes.
- Write down what you find and do. The difference between "compliant" and "can prove it" is a short written record. It's the cheapest protection there is.
If you're limited-risk (most of you)
If your AI interacts with people or generates content but doesn't make consequential decisions about them, you're almost certainly limited-risk, and your August 2 minimum is short:
- Add AI-interaction disclosures. Chatbots, assistants, and support bots need to tell users they're AI, clearly and up front. Our chatbot disclosure guide has copy you can paste.
- Label AI-generated content and deepfakes. Disclose synthetic images, audio, video, and public-interest text that a person might take as genuine.
- Add emotion or biometric notices if relevant. If you run sentiment or biometric categorisation on people, inform them (and check you're allowed to at all).
- Note the marking grace period. The machine-readable watermarking piece (Article 50(2)) has an extension to December 2, 2026 for systems already on the market, so the technical marking is not the August emergency. The visible disclosures are.
That's the list. For a small SaaS company, it's realistically an afternoon or two of copy and UI changes plus a short written record.
If you're high-risk
If you build AI that makes consequential decisions about people, hiring, credit, insurance, education, essential services, you're likely high-risk. Two things are true at once for you:
- Article 50 transparency still applies August 2. High-risk doesn't exempt you from the transparency obligations. If your high-risk system interacts with people or generates content, do the disclosures now, same as everyone else.
- Your heavy obligations run to December 2, 2027. Risk management, documentation, human oversight, conformity assessment. That's a genuine programme, and sixteen months is the right amount of time to do it properly, not a reason to wait.
So even for high-risk companies, the ten-day priority is the transparency layer. The marathon starts after, not now.
What you can skip for now
Explicitly, so you don't waste the next ten days:
- Full Annex IV technical documentation (that's the 2027 track).
- Conformity assessment and CE marking (2027).
- EU database registration (2027).
- Building watermarking infrastructure in a panic (grace period to December for existing systems).
None of these are optional forever. They're just not the August 2 job. Confusing the two is the single most common way companies waste their remaining time.
Do this in the next 10 days
- Day 1: classify every AI system you run. Separate the limited-risk majority from anything genuinely high-risk or prohibited.
- Days 2 to 5: ship the disclosures. Chatbot notices, content labels, deepfake and biometric notices. Mostly copy and UI.
- Days 6 to 8: check the edge cases. Anything touching emotion recognition in a workplace or school (that's a prohibition question, not a disclosure one). Anything genuinely high-risk (start the 2027 plan, don't cram it).
- Days 9 to 10: write the record. What you run, what tier it is, what you disclosed, where, and when. Done.
The honest summary: for the large majority of companies, meeting the August 2 deadline is a genuinely small job that got buried under warnings about a much bigger job that isn't due yet. Figure out which one is actually yours, do the small thing this week, and you're in good shape. Start with a free classification so you're building the right pile.
Related articles
The deadlines aren't moving. Get updates that matter.
Get EU AI Act updates, enforcement news, and compliance guides delivered to your inbox. No spam — unsubscribe any time.
Check your AI system's risk level for free
Our classifier maps your AI system against the EU AI Act in under 60 seconds. No signup required.
Classify Your AI System