There’s a date going around that’s making business owners nervous: 2 August 2026. You may have read that this is when the EU AI Act “comes into force” and starts handing out huge fines. The honest version is calmer and more useful: if you run a normal business that just uses AI tools, what actually changes that day is far smaller than the headlines suggest.
- What was supposed to happen on 2 August 2026
- What actually counts as banned or high-risk?
- What actually changed: the May 2026 delay
- So what actually happens around 2 August 2026?
- Are you actually affected? Provider vs user
- The thing that did NOT get delayed
- Don't panic: what you can safely ignore
- Your bigger day-to-day risk is probably GDPR, not the AI Act
- What to actually do before 2 August 2026
- Frequently asked questions
- Sources
This guide explains, in plain English, what really happens on 2 August 2026, what got quietly pushed back, what was not delayed, and what (if anything) you should actually do about it.
The short version
- 2 August 2026 was meant to be the AI Act’s big day, when the strict “high-risk” rules kicked in.
- In May 2026, the EU agreed to push most of those strict rules back, to December 2027 and August 2028.
- What still lands around 2 August 2026 is much lighter: mainly being open about when you’re using AI (labelling chatbots and AI-generated content).
- One duty was not delayed: making sure the people using AI in your business understand it well enough to use it sensibly. That has applied since early 2025.
- For most small businesses, this is a “do a couple of sensible things,” not a “panic” situation.
This is general information, not legal advice. If your business runs AI in a genuinely sensitive area (hiring, lending, medical, and similar), talk to a qualified lawyer.
What was supposed to happen on 2 August 2026
The EU AI Act sorts AI by how risky it is, and the scariest tier is called “high-risk”: AI used in sensitive areas like hiring decisions, credit scoring, medical devices, or critical infrastructure. The strict rules for that tier (detailed record-keeping, human oversight, monitoring, and so on) were originally set to start on 2 August 2026.
That’s where the alarming headlines came from. “The AI Act bites in August 2026” was technically true for the businesses running high-risk AI. The problem is that most coverage didn’t mention the part that changed.
What actually counts as banned or high-risk?


https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
What actually changed: the May 2026 delay
By late 2025 it was clear the high-risk rules weren’t going to be ready in time. The technical standards and the national authorities meant to enforce them simply weren’t finished. So the EU agreed a reform (its nickname is the Digital Omnibus on AI) to push the deadlines back.
That reform was agreed on 7 May 2026 and pushes the high-risk rules to:
- 2 December 2027 for most high-risk AI (things like hiring and recruitment tools), and
- 2 August 2028 for AI built into physical products (like medical devices or machinery).
One honest caveat worth knowing: as of writing (June 2026), this reform is agreed but not yet fully signed into law. It’s expected to be finalised just before 2 August 2026. Until it’s officially published, the original timeline technically still stands, so if you genuinely run high-risk AI, keep preparing rather than assuming the delay is locked in. For everyone else, the new dates are the sensible planning baseline.
So what actually happens around 2 August 2026?
For a normal business, two things, and neither is dramatic.
1. You need to be open about using AI. From 2 August 2026, the AI Act’s “transparency” rules apply. In plain terms: don’t trick people. If customers are chatting with an AI bot, they should be able to tell it’s a bot, not a human. If you publish AI-generated or AI-edited content where someone could reasonably be misled (think realistic fake images or “deepfake”-style media), it should be clear that it’s AI. The technical bit about automatically “marking” AI-generated content as machine-readable is being phased in a little later, toward December 2026, but the basic honesty principle starts in August.
Here’s the good news: if you already run an honest business, you’re most of the way there. Labelling your chatbot as a bot and not passing AI images off as real photos is common sense as much as compliance.
One thing the transparency rules don’t cover, but which still applies: copyright. The AI Act sits alongside existing EU intellectual-property law, not instead of it. So anything you publish that was AI-generated still has to respect copyright, the same as any other content. Light transparency rules don’t give AI output a free pass on IP.
2. The literacy duty is in full effect (and was never delayed). More on this below, because it’s the one that quietly applies to almost everyone.
Are you actually affected? Provider vs user
This is the question that decides everything, and most articles skip it.
The AI Act treats two roles very differently. A provider builds an AI system and sells it (OpenAI, Google, Anthropic, and so on). A user (the law calls it a “deployer”) simply uses an AI tool in their work. If you use ChatGPT to draft emails, an AI tool to read invoices, or a chatbot on your website, you’re a user, not a provider, and users carry far lighter obligations.
Almost every small business, freelancer and shop in Europe is a user of ordinary, low-risk tools. The heavy high-risk rules (the ones that got delayed) fall on providers and on businesses deploying genuinely high-risk systems. If that’s not you, most of the scary checklist online was never aimed at you in the first place.
One trap to watch, though. If you take a third-party AI tool and put your own brand on it (white-labelling), or you significantly change how it works, you can legally cross the line from user to provider, and inherit the much heavier provider obligations. That risk bites hardest when the underlying tool is high-risk, so if you’re rebranding or reengineering AI rather than just using it, check where you stand.
The thing that did NOT get delayed
While everyone focused on the high-risk delay, the AI literacy duty was not pushed back. Since early 2025, businesses that use AI have been expected to make sure the people using it understand it well enough to use it sensibly. The 2026 reform is set to soften the exact wording of this duty (from a hard “ensure” to a lighter “support and encourage”), but it isn’t disappearing, and it remains the one obligation most likely to apply to an ordinary business that simply uses AI tools.
Before you worry: this is far less scary than it sounds, and it’s genuinely doable for a one-person business. “AI literacy” doesn’t mean certificates or expensive courses. It means the people using AI tools roughly understand what the tool does, where it can get things wrong, and that they shouldn’t blindly trust its output. For a small business using everyday tools, the realistic bar is low. What matters is that you did something deliberate and can point to it.
A sensible minimum:
- Write down which AI tools your business uses, and for what.
- Give your team (or yourself) a short, plain note: what each tool is for, what not to put into it (client personal data, confidential information), and that a human checks anything important.
- Date it and keep it.
That’s it. For most businesses, an afternoon covers the only AI Act duty likely to ever touch them.
Don’t panic: what you can safely ignore
In the spirit of being straight with you:
- You can ignore the long high-risk compliance checklists unless you actually run high-risk AI (hiring filters, credit decisions, medical, biometric). Most businesses don’t.
- You can ignore anyone selling you a four-figure “AI Act audit” if all you do is use normal productivity tools. You’re paying to solve a problem you don’t have.
- You can ignore the claim that “everything is delayed to 2027, so relax.” The transparency and literacy duties are 2026.
- You should not ignore the short literacy note and being honest about AI use. Both are cheap, and both are the parts that actually apply.
One warning the regulators themselves repeated when they announced the delay: extra time isn’t permission to do nothing. If you do run high-risk AI, the later deadline is breathing room to get it right, not a reason to forget about it.
Your bigger day-to-day risk is probably GDPR, not the AI Act
Here’s the practical truth for most businesses: the AI Act’s high-risk regime probably won’t touch you, but GDPR already does, every time you put a customer’s personal details into an AI tool. Where does that data go? Does it leave the EU? Does the tool’s provider offer a proper data agreement? Those questions matter today and are where the real, present risk sits.
We cover exactly where the major AI tools store data, which offer EU data residency, and which have proper data agreements in our dedicated guide: AI Tools with EU Data Residency. For most readers, choosing your tools well on the data question does more for your actual compliance than any amount of AI Act paperwork.
What to actually do before 2 August 2026
If you use ordinary AI tools and aren’t in a high-risk field, this is genuinely the whole list:
- Be honest about AI where customers meet it: label bots and AI-generated content.
- Write the short AI-use note for your team (covers the literacy duty).
- Check your tools on data, not just features: where your data lives, and whether a data agreement is available.
- If you run high-risk AI (hiring, lending, medical, biometric), treat this as the moment to get proper legal advice. Your deadline is later, but the work is bigger.
Frequently asked questions
Does the EU AI Act start on 2 August 2026? Parts of it. The Act has applied in stages since 2024. On 2 August 2026, the transparency rules (being open about AI use) take effect. The strict “high-risk” rules that were due that day have been pushed back to December 2027 and August 2028 under a 2026 reform.
Was the EU AI Act delayed? Only the high-risk part. A reform agreed in May 2026 moved those deadlines to 2027 and 2028. The transparency and AI-literacy duties affecting ordinary businesses were not delayed.
Does this apply to my small business if I just use tools like ChatGPT? You’re a user of low-risk tools, so your duties are light, mainly being open about AI use and the literacy note. The heavy rules fall on the companies that build AI and on businesses running high-risk systems.
What is the AI literacy requirement? A duty to make sure the people using AI in your business understand it well enough to use it sensibly. For a small business, a short written note covering your tools, their limits, and what data not to enter is a reasonable, proportionate response.
What are the fines? They’re large but aimed at serious, large-scale violations: up to €35 million or 7% of global turnover for banned practices, and up to €15 million or 3% for most other breaches. Small businesses are capped at the lower figure, and these are maximums, not starting points.
What’s the one thing I should do? Write a short, dated note on which AI tools you use and their limits, be honest with customers about AI, and choose your tools with their data handling in mind. That covers what’s most likely to apply to you.
Sources
- High-risk deadlines deferred to 2 December 2027 (use-based) and 2 August 2028 (product-embedded); reform agreed 7 May 2026. European Parliament, Legislative Train Schedule, Digital Omnibus on AI (procedure 2025/0359(COD)): https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai
- Transparency rules take effect August 2026; high-risk timeline; prohibited practices and AI literacy in force since February 2025; GPAI rules since August 2025. European Commission, AI Act (official regulatory framework page, updated May 2026): https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
- The reform is provisional and not yet formally adopted, so 2 August 2026 remains an active compliance date until publication in the Official Journal. Gibson Dunn, EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes (May 2026): https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/
Last reviewed 4th of June 2026. The 2026 reform (Digital Omnibus on AI) was agreed in May 2026 and is expected to be finalised before 2 August 2026; we update this guide as the official text is published.



