The EU AI Act in August 2026: What Changed, What Got Delayed, and What Small Businesses Must Do

If you followed the EU AI Act coverage over the last year you probably came away with two contradictory impressions: that a major deadline landed in August 2026, and that everything got postponed to 2027. Both are true, which is why so much of the commentary has been confusing. Here is the position as it actually stands. What happened The AI Act entered into force on 1 August 2024 with obligations phased in over several years. By late 2025 it was clear that implementation was behind schedule, and on 19 November 2025 the European Commission proposed the Digital Omnibus on AI, a package of amendments whose headline measure was a delay to the heaviest obligations. Negotiations nearly collapsed in April 2026. A political agreement was reached on 7 May, and the Omnibus entered into force on 27 July 2026. What got delayed High-risk obligations under Annex III move from 2 August 2026 to 2 December 2027. These are the use-based high-risk categories, and they include the one most likely to touch an ordinary company: AI used in employment decisions. Recruitment screening, candidate selection, performance evaluation, task allocation, monitoring, promotion and termination decisions all sit in this bucket. High-risk obligations under Annex I, covering AI embedded in regulated products such as medical devices, lifts and radio equipment, move from 2 August 2027 to 2 August 2028. National regulatory sandboxes move from 2 August 2026 to 2 August 2027. If you were racing to complete a conformity assessment for a recruitment tool, you have sixteen additional months. What did not get delayed This is the part that gets lost. On 2 August 2026, three things took effect on schedule. Article 50 transparency obligations. These apply broadly and are the ones most relevant to ordinary businesses. Enforcement powers over general-purpose AI models. The AI Office can request technical documentation, evaluate models, require corrective measures and issue fines. The full penalty regime. Fines are now live across the Act. From 2 August 2026, the AI Office and national authorities in each member state are responsible for implementing, supervising and enforcing the regulation. Before that date the enforcement machinery was partly theoretical. It is not any more. The Omnibus also added a new prohibition to Article 5 covering AI-generated non-consensual intimate imagery and child sexual abuse material. What Article 50 requires of an ordinary business Most small businesses are deployers rather than providers, and the transparency obligations are the practical ones. Tell people when they are talking to a machine. If you run a chatbot or an AI phone system that interacts with customers, those customers must be informed they are dealing with an AI, unless it would be obvious to a reasonable person. For a phone receptionist this matters. A caller does not automatically know. Mark synthetic content. AI-generated or manipulated images, audio and video must be marked in a machine-readable way. There is a grace period to 2 December 2026 for systems already on the market before 2 August 2026. Disclose deepfakes. Content that resembles real people, places or events and could mislead has to be labelled as artificially generated. Disclose emotion recognition and biometric categorisation. If you use these, the people subject to them must be told. The Omnibus also extended the simplification measures for small and medium businesses to small mid-caps, and reworked the AI literacy obligation. The AI literacy point is worth a moment. The Act expects organisations to ensure staff using AI systems have a sufficient level of understanding of them. For a small company that is not a training programme. It is a short internal note about what the tools do, what they get wrong, and when a human has to check. A practical checklist List the AI systems you actually use. Most companies underestimate this. Customer-facing chatbots, phone systems, recruitment screening, content generation, translation, meeting transcription. Write them down. Sort them by risk category. Prohibited, high-risk, limited-risk with transparency obligations, minimal risk. The large majority of small business use falls into the last two. Check anything touching employment decisions. That is your most likely high-risk exposure. December 2027 sounds distant, and conformity assessments take longer than people expect. Fix your disclosures now. Chatbot greeting, phone system opening line, website notice, labels on generated images. This is a week of work at most, and it is enforceable today. Ask vendors where they sit. Any AI vendor selling into the EU should be able to tell you whether they are a provider under the Act, what risk category their system falls into, and what documentation they can give you. Vendors that cannot answer this in August 2026 have not been paying attention. European vendors tend to be readier on this than others, simply because the regulation is their home market. Mirage Cloud, for example, publishes a full Article 28 data processing agreement with a named sub-processor list and a documented acceptable use policy that explicitly requires AI output to be verified before use. Neither of those is exotic. They are just the paperwork you need when a customer or an auditor asks, and having it ready is the difference between a five-minute answer and a five-week project. The realistic summary The delay is genuine and useful for anyone with high-risk exposure. It is not a general reprieve. Transparency rules, general-purpose AI enforcement and the penalty regime are all operative now. For most small businesses the compliance work is modest: know what you use, tell people when they are talking to a machine, label synthetic content, and keep a human in the loop on anything consequential. That is close to what a careful company would do anyway.

Disclaimer: This and other personal blog posts are not reviewed, monitored or endorsed by TalkMarkets. The content is solely the view of the author and TalkMarkets is not responsible for the content of this post in any way. Our curated content which is handpicked by our editorial team may be viewed here.

Comments