Overall timeline
The European AI Regulation (AI Act), in force since 1 August 2024, applies in stages. 2 August 2026 marks a further step, built around three axes: telling users when they are dealing with an AI, making content produced or altered by such tools traceable, and giving the European Commission direct supervisory powers over large general-purpose models. The heaviest obligations — those on high-risk systems — have been pushed back.

Already in force
Since 2 February 2025 a number of uses have been banned: manipulative techniques, exploitation of vulnerable persons, social scoring, indiscriminate harvesting of facial images, and certain forms of emotion recognition and biometric categorisation. Real-time biometric identification in public spaces is permitted only in narrowly defined cases. Employers must also ensure that staff understand how the AI tools they use work, along with their limits and risks. Since 2 August 2025, the rules on general-purpose models, on governance and on the general penalty regime have applied. The GDPR, employment law, intellectual property, consumer protection and the prohibition of discrimination continue to apply alongside.

What is new on 2 August 2026

Conversational agents — users must be told they are talking to a machine, unless this is self-evident. The information must be intelligible and given at the appropriate moment; the duty falls on the chatbot’s provider.

Content marking — images, video, audio and text output by automated systems must carry a technical trace: metadata, provenance information or a watermark. This marking is intended for verification tools, not necessarily for the public: no systematic, visible “AI-generated” label is therefore required. It must survive minor editing (cropping, brightness adjustment, reformatting). The obligation rests on providers; those who subsequently reuse or alter the content are not expressly required to preserve the marker. Systems placed on the market from 2 August 2026 must comply immediately; those already in circulation have until 2 December 2026.

Deepfakes — the requirement here is stricter: beyond the technical marking, the public must be expressly informed that the content is artificial whenever an identifiable person is depicted. The obligation applies only to professional deployers; strictly private use falls outside it. For artistic, satirical or fictional works, a discreet mention suffices — in the credits, for instance — so as not to spoil the work’s effect.

AI-generated text — disclosure is not universal. It becomes mandatory for informational publications on matters of general interest — political life, election results, public health, security, economy and finance, the environment, justice, public services, major scientific or cultural debates — where the text was generated or heavily reworked by an AI without effective human review. The aim is not to bar AI from writing, but to let readers gauge how large a part it played.

Emotions and biometrics — these technologies are not banned as such. A company deploying them will now have to inform the persons concerned. Their use nevertheless remains prohibited since 2025 in the workplace and in educational establishments, save on medical or safety grounds: an employer may not gauge staff motivation this way, nor a school its pupils’ attention. Unlocking a phone by face, or access control within a lawful framework, remains permissible, subject to the GDPR and privacy rules.

General-purpose models — the European Commission will be able to request further information, verify compliance and impose fines. This applies to models placed on the market after 2 August 2025; earlier generations have until 2 August 2027 to comply. These duties fall on model providers, not on the businesses integrating them.

High-risk systems: postponed
Under the deferral agreed in June 2026, most obligations applying to high-risk systems — candidate screening, school admissions, creditworthiness assessment, migration management — will not bite until 2 December 2027. Systems serving as safety components in regulated products (medical devices, toys, lifts) are covered from 2 August 2028.

Penalties
The general regime has applied since 2 August 2025: national authorities may penalise prohibited practices, up to EUR 35 million or 7 % of worldwide turnover. From 2 August 2026, breaches of the transparency obligations — an undisclosed chatbot, an unidentified deepfake, failure to flag generated content — may attract fines of up to EUR 15 million or 3 % of worldwide turnover. National authorities oversee developers, distributors and users of AI systems; the Commission acts directly against providers of general-purpose models, in particular where they refuse to supply information or to submit to an evaluation.

3.08.2026