The Tech Docket Daily signal on tech & AI — what the world is searching, and why
Policy & Society

EU AI Act: What Actually Changed on August 2, 2026

EU AI Act enforcement began August 2, 2026: chatbot and deepfake disclosure is law and GPAI fines are live, while high-risk rules wait until December 2027.
European Union flag rendered as a circuit board beside a chatbot window carrying an AI disclosure label, marking the AI Act's enforcement start.

Enforcement of the EU AI Act began on Saturday, August 2, 2026. From that date, the European Commission’s AI Office and national authorities police the law: chatbots must say they are AI, deepfakes must be labelled, and makers of general-purpose AI models can be fined up to 3% of worldwide turnover. What did not happen is just as important — the “high-risk” rules many headlines promised were postponed to December 2027 by a last-minute amending law. And because the Act reaches any company whose AI output is used in Europe, the enforcement clock now ticks for Indian IT and SaaS exporters too.

What went live on August 2

The Commission’s announcement is plain about the switch being flipped: “From 2 August 2026, the European Commission’s AI Office, together with national authorities, will begin enforcing the Artificial Intelligence (AI) Act,” with new transparency rules applying from the same date.

Those transparency duties sit in Article 50, and the Commission’s own FAQ breaks them into plain obligations. AI systems that talk to people must disclose they are AI unless it is obvious. AI-generated audio, images, video and text must carry machine-readable marking so other software can detect them. Deployers of deepfakes — AI-edited or AI-generated likenesses — must disclose the content is artificial. People exposed to emotion-recognition or biometric-categorisation systems must be told. AI-written text published on matters of public interest needs a disclosure unless a named human took editorial responsibility.

One transition matters: Regulation 2026/1744 grants a four-month transitional period for content-marking on systems already on the market before August 2, making their practical deadline December 2, 2026. New systems must comply from day one.

The machinery behind the rules also switched on. The AI Office supervises general-purpose model providers directly; national authorities handle everything else; and the Commission opened a complaints tool and a confidential whistleblower channel, adding 38 staff to the AI Office the Friday before enforcement began, per Fortune. To help firms comply, the Commission says more than 180 organisations have signed a voluntary Code of Practice on labelling AI-generated content — though Article 50 binds signatories and non-signatories alike.

The quiet weakness is on the national side. The European Parliament’s research service reported that as of March 2026 only 8 of 27 member states had designated their national enforcement contact point, against an August 2025 legal deadline. The bloc entered enforcement day with that layer still incomplete, leaving the Commission’s directly-run general-purpose AI track as the law’s sharpest edge for now.

The high-risk rules did not start — here is the real timeline

Hiring algorithms, credit scoring and exam-proctoring AI did not become regulated on August 2 — that was the original plan, and it changed six days before the deadline. The “Digital Omnibus on AI,” given final approval by the Council on June 29, was signed on July 8, published as Regulation (EU) 2026/1744 and entered into force on July 27, 2026. Its recitals move stand-alone high-risk systems (Annex III) to December 2, 2027, and high-risk AI embedded in regulated products like medical devices to August 2, 2028. The Future of Privacy Forum’s comparison of the old and new timelines tracks the same shifts, including national regulatory sandboxes slipping a year to August 2027.

Here is the state of play after the Omnibus, date by date:

Obligation Original date Where it stands now
Bans on “unacceptable” AI (social scoring, manipulative systems) 2 Feb 2025 In force, unchanged
General-purpose AI model duties (documentation, copyright policy, training-data summary) 2 Aug 2025 In force, unchanged
Transparency: chatbot disclosure, deepfake labels, content marking 2 Aug 2026 Live now (marking transition for pre-existing systems ends 2 Dec 2026)
Commission’s power to fine general-purpose AI providers 2 Aug 2026 Live now
New ban: AI-generated non-consensual intimate imagery Added by the Omnibus From 2 Dec 2026
National AI regulatory sandboxes 2 Aug 2026 Delayed to 2 Aug 2027
High-risk systems: hiring, credit, education, policing (Annex III) 2 Aug 2026 Delayed to 2 Dec 2027
High-risk AI inside regulated products (Annex I) 2 Aug 2027 Delayed to 2 Aug 2028

One caution for anyone verifying dates: some official EU summary pages still showed the pre-Omnibus timeline in early August 2026 — the amending regulation’s EUR-Lex text is the authoritative version.

The fines are real now, and the arithmetic is uncomfortable

General-purpose AI model makers — the OpenAIs, Googles and Anthropics — have technically owed transparency, copyright-policy and documentation duties since August 2025. What changed on August 2 is that the grace period ended: the Commission’s supervision and fining powers over these providers activated after what the law’s own scheme designed as a one-year adjustment period. Article 101 sets the cap: 3% of annual worldwide turnover or €15 million, whichever is higher, for violations including supplying misleading documentation or refusing model access for evaluation.

For everything else, Article 99’s tiers apply: up to €35 million or 7% of worldwide turnover for banned practices, up to €15 million or 3% for breaching obligations including Article 50 transparency, and up to €7.5 million or 1% for feeding authorities incorrect information — with SMEs and startups paying the lower of each pair rather than the higher.

To make those percentages concrete (our arithmetic, from company-reported figures): Meta reported full-year 2025 revenue of $200.97 billion, so a 3% penalty would be roughly $6 billion and a 7% penalty about $14 billion. Alphabet reported $402.8 billion for 2025, making the same tiers worth about $12 billion and $28 billion. These are ceilings, not predictions — but they are no longer hypothetical ceilings.

Who is inside the tent matters too. OpenAI, Google, Anthropic, Microsoft, Amazon, IBM and Mistral all signed the General-Purpose AI Code of Practice in full; xAI signed only its safety chapter, and Meta refused outright, with policy chief Joel Kaplan saying “Europe is heading down the wrong path on AI.” The Commission has indicated it will focus supervision of signatories on code adherence, leaving holdouts exposed to direct information demands that now carry fines. No major Chinese model maker appears on the signatory list — a gap we noted covering DeepSeek’s price-war launch. And the new enforcement team is not starting with an empty desk: Fortune reports Commission officials have been in bilateral contact with OpenAI and Anthropic after both disclosed AI-agent incidents in July — the same class of agent-gone-wrong problem we examined in the OpenAI–Hugging Face breach.

The India angle

The Act does not care where a company is incorporated. Its scope clause covers providers and deployers “irrespective of whether those providers are established or located within the Union or in a third country” whenever a system is placed on the EU market or its output is used in the EU — a reach law firm Holland & Knight bluntly describes as offering no safe harbor to foreign firms.

That lands directly on India’s IT majors, for whom Europe is a quarter to a third of the business:

Company Europe share of revenue Period Source
TCS 32.6% (UK + Continental Europe) Q1 FY2026-27 Company fact sheet
Infosys ≈32% FY26 Filings aggregation
HCLTech 27.8% (services) FY26 Investor release
Wipro ≈26.5% (IT services) FY26 SEC Form 6-K

The industry saw this coming. TCS, Infosys and Wipro were among the 100-plus signatories of the EU’s voluntary AI Pact back in September 2024, and compliance has become a product line: HCLTech obtained ISO/IEC 42001 certification for its AI management system on July 7, 2026, positioned explicitly as EU AI Act-aligned; Infosys and Wipro sell responsible-AI governance services into the same demand.

The subtler exposure is for smaller exporters. An Indian SaaS company that ships a customer-support chatbot used by EU customers is not covered by its model vendor’s compliance — under the Act it is itself the provider of that AI system, and the Article 50 disclosure duty is its own. The same logic applies to marketing tools generating synthetic media for European clients: labelling is now the exporter’s legal problem, at 3%-of-turnover stakes under Article 99.

The contrast with home is stark. India has chosen a deliberately lighter path: MeitY’s AI Governance Guidelines, released in November 2025, are explicitly voluntary and principles-based, leaning on existing law instead of a new AI statute, and the AI Governance and Economic Group formed in April 2026 is still shaping how they will be applied. India’s nearest binding regime is data protection, where the DPDP Rules notified in November 2025 phase in over 18 months — we unpacked that law in our DPDP explainer. Business Standard’s explainer drew the same line: India has no dedicated AI law comparable to the EU framework. For Indian firms, that means the strictest AI rulebook they face is not Delhi’s — it is Brussels’, effective now. More context on how governments are approaching AI sits in our Policy & Society hub.

What to watch

December 2, 2026 is the next hard date: the content-marking transition for pre-existing systems ends, and the Omnibus’s new prohibition on AI-generated non-consensual intimate imagery takes effect, per Regulation 2026/1744. Watch for the first Article 101 action — information demands on code holdouts like Meta, or the incident follow-ups already on the Commission’s desk. Watch the member-state stragglers, since national-level enforcement of chatbot and deepfake duties cannot outrun authorities that do not exist yet. And watch the 10^25 FLOP systemic-risk threshold, which the Commission says is under review — moving it would redraw which frontier models carry the heaviest duties. The lesson of this deadline: Brussels will move a date under pressure, but it has not yet blinked on an obligation already in effect.

Frequently asked questions

Does the EU AI Act apply to non-EU companies?

Yes. Article 2 covers providers and deployers based anywhere if an AI system is placed on the EU market or its output is used inside the EU. A Bengaluru SaaS firm whose chatbot serves EU customers is in scope with no EU office at all — law firm Holland & Knight calls it a rule with no safe harbor for foreign companies.

What happens if you don't comply with the EU AI Act?

Since August 2, 2026 the penalty machinery is active. National authorities fine banned practices at the top tier and transparency breaches at the middle tier, both scaled to worldwide turnover, while the European Commission alone fines general-purpose AI model makers — the exact tiers are in the article's fines section. SMEs and startups pay reduced caps.

Will the AI Act apply to AI systems already on the market?

Yes, with breathing room. Systems on the market before August 2, 2026 get a four-month transition — until December 2, 2026 — to add machine-readable marking to AI-generated content. General-purpose models released before August 2, 2025 have until August 2, 2027 to reach full compliance. New launches must comply immediately.

Which AI models does the AI Act apply to?

Any general-purpose model — roughly, models trained with more than 10^23 FLOPs of compute that can generate language. Beyond 10^25 FLOPs, the frontier tier from OpenAI, Google, Anthropic and peers is presumed to carry systemic risk and faces extra testing, incident-reporting and cybersecurity duties.

Sources & further reading

  1. Commission starts enforcing AI Act rules and new transparency requirements on 2 August — European Commission (primary source)
  2. Safer and more transparent AI — European Commission news, 2 August 2026 (primary source)
  3. Regulation (EU) 2026/1744 (Digital Omnibus on AI) — Official Journal text (primary source)
  4. Council gives final green light to simplify and streamline AI rules — Council of the EU, 29 June 2026 (primary source)
  5. Article 101: Fines for providers of general-purpose AI models — EC AI Act Service Desk (primary source)
  6. Article 99: Penalties — EC AI Act Service Desk (primary source)
  7. Transparency obligations under Article 50 — European Commission FAQ (primary source)
  8. General-purpose AI obligations under the AI Act — European Commission factpage (primary source)
  9. The General-Purpose AI Code of Practice — official signatory list (primary source)
  10. Enforcement of Chapter V under the EU AI Act — artificialintelligenceact.eu
  11. The AI Act implementation timeline: what changes under the AI Omnibus — Future of Privacy Forum
  12. Enforcement of the AI Act — European Parliament Think Tank (EPRS) (primary source)
  13. Meta declines to sign EU's AI code of practice — CNBC
  14. Google and xAI sign EU AI Code of Practice — The Decoder
  15. EU AI Act enforcement team expands as Anthropic discloses incidents — Fortune
  16. US companies face EU AI Act's possible August 2026 compliance deadline — Holland & Knight
  17. TCS Q1 FY2026-27 Fact Sheet — Tata Consultancy Services (primary source)
  18. Wipro FY26 results — SEC Form 6-K exhibit (primary source)
  19. HCLTech Q4 & Annual FY26 Investor Release (primary source)
  20. Infosys revenue by geography — Bullfincher aggregation of company filings
  21. Google, Microsoft, TCS, Infosys among 100+ signatories to EU AI Pact — Forbes India
  22. HCLTech achieves ISO/IEC 42001:2023 certification — PTI/PRNewswire via The Wire
  23. India AI Governance Guidelines released — Press Information Bureau, MeitY (primary source)
  24. AIGEG: MeitY's AI governance body excludes regulators — MediaNama
  25. DPDP Rules 2025 notified — Press Information Bureau (primary source)
  26. EU AI Act: what changes as new transparency rules take effect from August 2 — Business Standard
  27. Meta Q4 and full-year 2025 results — Meta press release (primary source)
  28. Alphabet Q4 2025 earnings release (primary source)
How this article was made: topic selected from same-day search-trend and community-momentum data across India and the US; researched, drafted and fact-checked with AI assistance under the site's automated quality gates (source citations, originality, no-clickbait and accuracy checks), on the editorial standards set by Saurab Jain. Details in our editorial policy. Spotted an error? Email a correction.

More of today, in 60 seconds: Today's Docket →