LinkedInInstagramXTikTok

EU AI Act: what applies from 2 August 2026?

Why 2 August 2026 is a turning point for businesses

On 2 August 2026, the bulk of the EU AI Act becomes fully applicable. From this date the requirements for high-risk systems, transparency and stricter supervision take effect – and it is when supervisory authorities can begin to impose penalties. For many businesses, this is the first time AI regulation will have concrete consequences in day-to-day operations.

If you develop, sell or use AI systems that affect people – for example in recruitment, credit assessment or customer service – there are good reasons to act now. This article explains what starts to apply, what it means in practice and how to prepare in good time.

What is the EU AI Act?

The AI Act is the world’s first comprehensive law on artificial intelligence. It entered into force on 1 August 2024 and applies in stages. The ban on certain AI uses took effect as early as 2 February 2025, and the obligations for providers of general-purpose AI models (GPAI models) from 2 August 2025.

The regulation is built on a risk-based model. The greater the risk an AI system poses to people’s health, safety or fundamental rights, the stricter the requirements. Systems are divided into four tiers: unacceptable risk (prohibited), high risk, limited risk (transparency obligations) and minimal risk.

What starts to apply on 2 August 2026

High-risk systems under Annex III

From 2 August 2026, the full requirements apply to the high-risk systems listed in Annex III to the regulation. These include AI used in biometrics, critical infrastructure, education, employment and workforce management, access to essential private and public services (such as credit scoring and insurance risk assessment), law enforcement, migration and the administration of justice.

Providers of such systems must, among other things, carry out a conformity assessment, establish a risk-management system, ensure good data quality, keep logs, prepare technical documentation, enable human oversight and register the system in the EU database before placing it on the market. Those who use a high-risk system (deployers) also take on obligations, such as using the system in line with the instructions and ensuring human oversight.

An exception applies to high-risk systems embedded in already regulated products, for example medical devices or machinery. For these, an extended transition period runs until 2 August 2028.

Transparency obligations under Article 50

Article 50 applies to a broader range of systems, not just high-risk ones, and sets out four core obligations. First, anyone interacting with a chatbot or similar AI system must be informed that they are dealing with an AI. Second, content generated or manipulated by AI – including so-called deepfakes of image, audio or video – must be labelled as artificially created. Third, AI-generated text published to inform the public on matters of public interest must be disclosed as such. Fourth, people must be informed when emotion-recognition or biometric-categorisation systems are used.

Providers must also ensure that AI-generated content is marked in a machine-readable format so that it can be detected as artificially created. In June 2026 the Commission published a voluntary code of practice to support how these marking requirements can be met.

Stricter supervision of general-purpose AI models

The obligations for providers of GPAI models, such as large language models, have applied since 2 August 2025. From 2 August 2026, however, the EU AI Office gains full enforcement powers, meaning it can request information, require action and ultimately impose penalties on providers that fail to meet the requirements.

What penalties do businesses risk?

The penalties under the AI Act are significant and are calculated as the higher of a fixed amount or a share of global annual turnover. For prohibited AI use, fines can reach EUR 35 million or 7 per cent of global turnover. For breaches of other obligations, such as the requirements for high-risk systems or transparency, fines can be up to EUR 15 million or 3 per cent. Supplying incorrect or misleading information to authorities can cost up to EUR 7.5 million or 1 per cent.

What applies in Sweden?

Each member state must designate national authorities responsible for supervision. In Sweden, the government has proposed that the Swedish Post and Telecom Authority (PTS) become the main market surveillance authority and coordinating point of contact, alongside a number of additional sector authorities responsible for their respective areas. The Swedish Authority for Privacy Protection (IMY) has argued in its consultation response that it alone should be responsible for supervising prohibited AI systems under Article 5. The proposed Swedish supplementary legislation is intended to enter into force in time for 2 August 2026.

Because the details of the Swedish framework are still being finalised, businesses should follow developments and not assume the allocation of responsibility is settled.

Practical example: an AI tool in recruitment

Suppose a Swedish company uses an AI tool that ranks job applications and suggests which candidates to invite for interview. AI systems used for recruitment and selection fall under Annex III and therefore count as high risk. From 2 August 2026, this means the company must ensure the tool meets the requirements: that documentation and human oversight are in place, that decisions are not made in a fully automated way without meaningful human control, and that candidates are informed appropriately. If the company also uses a chatbot in the application flow, applicants must be told they are talking to an AI. Simply trusting that the vendor “handles compliance” is not enough – the deployer has its own obligations too.

Common mistakes companies make

A common mistake is to assume the AI Act only applies to tech companies or those that build AI. In reality, it also covers businesses that merely use AI systems in their operations. Another mistake is lacking a complete overview of which AI systems are actually in use – many organisations discover late that their HR, marketing or customer-service tools contain AI that may be regulated. Finally, many underestimate the time it takes to produce documentation, human-oversight procedures and vendor agreements.

Recommended actions ahead of 2 August 2026

Start by mapping all AI systems in your operations and classifying them by risk level. Identify which may be high risk under Annex III and which fall under the transparency obligations of Article 50. Review your vendor contracts and make sure responsibility for compliance is clearly regulated. Put in place internal procedures for human oversight, logging and documentation, and appoint someone responsible for AI matters. Also ensure that staff have sufficient AI literacy, as that requirement already applies. The earlier you begin, the lower the risk of last-minute pressure and mistakes once supervision starts.

Frequently asked questions

Does the AI Act apply to my company if we only use AI rather than build it?

Yes. The regulation covers both providers and users of AI systems. A deployer of a high-risk system has its own obligations, such as following the instructions and ensuring human oversight.

Do we have to label content created with AI?

If you publish AI-generated text on matters of public interest, or generate image, audio or video content that constitutes a deepfake, the content must be labelled as artificially created under Article 50. Chatbots must also inform the user that they are an AI.

What happens if we are not ready by 2 August 2026?

From that date, supervisory authorities can begin to act and impose penalties. Being able to show that a structured compliance effort is under way is better than having done nothing at all, but the aim should be to meet the requirements in time.

Conclusion

2 August 2026 marks the shift from theory to practice for the EU AI Act. The requirements for high-risk systems, transparency and supervision take effect, and the penalties can be substantial. Businesses that map their AI systems now, classify the risks and put the right procedures in place will stand far stronger than those that wait. At Lawgent, we help companies understand the AI Act and turn it into concrete action – from mapping and risk classification to contracts, documentation and internal governance. Get in touch if you want to make sure your use of AI is ready for 2 August 2026.

Leave a Reply

Your email address will not be published. Required fields are marked *


0Cart0,00 

No products in the cart.

Return to shop