The column · L'algoritmo e il provvedimento · Episode 1 · 2 August 2026

The AI Act's 2 August has come: what applies from today, what is postponed

From today the European AI Regulation is in general application: transparency towards users, supervision and penalties. But the Digital Omnibus, in force since 27 July, has rewritten the high-risk timetable. The full map for businesses, professionals and individuals.

The legislation

Regulation (EU) 2024/1689 (AI Act), Articles 4, 5, 50, 99, 101 and 113 · Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJEU 24 July 2026, in force since 27 July 2026 · Italian Law No 132/2025 (national provisions on artificial intelligence)

The texts are available on EUR-Lex and in the Italian Official Gazette.

The date stands, the timetable changes

Under the original Article 113 of the AI Act, 2 August 2026 was the date of general application of the Regulation. The date has survived; its content has not. By Regulation (EU) 2026/1744, the so-called Digital Omnibus on AI, published in the Official Journal on 24 July and in force since 27 July 2026, the European legislature has pushed back the most onerous block of obligations, those on high-risk systems, while leaving everything else intact. From today, then, the AI Act is no longer a regulation in waiting: it is applicable law, with supervisory authorities in operation and penalties that can be imposed.

What applies from today

Three blocks of rules enter into application on 2 August 2026. The first is user-facing transparency under Article 50(1), (3) and (4): providers of systems intended to interact with people must make the artificial nature of the interlocutor evident from the outset, a rule that covers every chatbot addressed to clients, users or staff; deployers of emotion-recognition or biometric-categorisation systems must inform the persons exposed to them; and those who generate or disseminate deepfakes must disclose that the content is artificial.

The second block is enforcement. From today Article 99 applies: fines of up to EUR 35 million or 7 per cent of worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3 per cent for breaches of other obligations, with the lower of the two amounts for SMEs. Market surveillance by national authorities also begins: in Italy, Law No 132/2025 has designated the National Cybersecurity Agency (ACN) as supervisory authority and AgID as notifying authority, and a decree given preliminary approval by the Council of Ministers is completing the alignment with the European framework.

The third block concerns large models. Providers of general-purpose AI models have been subject since 2 August 2025 to the obligations on documentation, copyright and training-content summaries; from today, breaches become punishable by the Commission, through the AI Office, with fines of up to 3 per cent of worldwide turnover or EUR 15 million (Article 101).

What is postponed, and until when

The postponement effected by the Digital Omnibus concerns high-risk systems only. The obligations for the standalone high-risk systems of Annex III, the most relevant to administrative life: recruitment, credit scoring, access to essential public services, education, justice, will apply from 2 December 2027; those for systems embedded in products under Annex I from 2 August 2028. In both cases a conditional acceleration mechanism applies if the Commission confirms earlier that harmonised technical standards are available. The deadline for national regulatory sandboxes also slips to 2 August 2027.

One intermediate deadline, however, was not touched by the postponement but fixed by it: from 2 December 2026 the machine-readable marking of AI-generated or manipulated content (Article 50(2)) becomes mandatory, and two new prohibitions added to Article 5 apply, on systems generating non-consensual intimate images and on AI-generated child sexual abuse material.

For businesses

The immediate duty is transparency: every chatbot addressed to the public or to staff must declare itself, and every synthetic content disseminated must be recognisable. The high-risk postponement is not a suspension of the compliance effort: a full conformity pathway takes on average 8 to 14 months across risk management, data governance, human oversight and technical documentation, and those deploying recruitment software, credit scoring or biometric controls now have a window to arrive prepared, not a licence to ignore the matter. The Article 5 prohibitions and the AI literacy duty of Article 4, in force since 2025, remain: the Omnibus softened the verb, from ensure to promote, but not the substance.

For professionals

For law firms, accountants and professionals using generative AI tools, the same transparency rules apply from today whenever the tool interacts with clients, and the duty to train staff who use such systems remains. The more delicate front, however, is the litigation to come: ACN supervision and the penalty regime open a new chapter of administrative law, made of measures, objections and challenges, in which the classic categories of procedure and process will meet technology.

For individuals

From 2 August everyone has the right to know when they are talking to a machine, when they are exposed to an emotion-recognition system and when a piece of content is a deepfake. The unacceptable-risk practices banned since February 2025 remain prohibited: subliminal manipulation, exploitation of vulnerabilities, social scoring, emotion recognition in the workplace and in schools. And with national supervision now under way, there is an authority to which violations can be reported. The most incisive protection, over high-risk decisions affecting work, credit and services, will follow the 2027 timetable: until then, protection runs through the general rules of administrative procedure and the GDPR.

The point of method

2 August 2026 delivers a two-speed framework: transparency and penalties now, high risk later. For those dealing with public administrations the lesson is one: AI Act compliance is no longer tomorrow's issue but today's requirement, with a supervisory authority in place and fines of up to 7 per cent of turnover. The time gained on high risk is valuable only to those who use it.

Sources

Regulation (EU) 2024/1689, Articles 4, 5, 50, 99, 101, 113; Regulation (EU) 2026/1744, OJEU 24 July 2026; Italian Law No 132/2025. On average adaptation times and the timetable: European Commission and Council of the EU documentation on the Digital Omnibus on AI.

The information in this article is general in nature and does not constitute legal advice on any specific case.

← All insights