Skip to content
AIRAS Cloud

EU AI Act · 2 August 2026

2 August 2026: what the EU AI Act means for businesses now

Today is not the day every AI system in Europe suddenly becomes high-risk.

It is the day the regulatory position becomes much harder for organisations to ignore.

New transparency obligations now apply. Enforcement begins for the AI Act rules already in scope. Businesses using, supplying or embedding AI need to know what they have, which role they hold, what the system is doing and whether they can produce the evidence behind their decisions.

I built AIRAS Cloud because that work cannot be managed properly through a policy document and a collection of spreadsheets.

Richie HigginsFounder, AIRAS Cloud

Written and approved by Richie Higgins, Founder of AIRAS Cloud. Regulatory review date: 2 August 2026. General information, not legal advice.

The change

What changes on 2 August 2026

The AI Act applies in stages. Some obligations have already been in force for months. Today adds a major new layer: the majority of the remaining framework enters application, Article 50 transparency duties begin, and enforcement starts for the rules that are currently applicable.

The practical impact depends on what AI an organisation develops, supplies or uses, and the role it holds in relation to each system.

01

Transparency obligations apply

Providers and deployers of certain AI systems must now meet Article 50 transparency duties. Depending on the system, this can include telling people when they are interacting with AI and marking certain artificially generated or manipulated content.

Show the detail
  • Chatbots, AI agents and avatars where a person may believe they are interacting with another person.
  • Deepfake image, audio and video content.
  • Defined emotion-recognition and biometric-categorisation uses.
  • Public-interest text generated without human review or editorial control.
  • Machine-readable marking for relevant synthetic content.

Not every AI-generated item carries the same labelling duty. The obligation depends on the system, the content and the role held.

02

Enforcement begins for applicable rules

National and EU-level enforcement now begins for applicable rules covering prohibited practices, AI literacy, general-purpose AI models and transparency obligations.

Show the detail
  • An organisation cannot rely on later high-risk deadlines if it is already subject to a rule currently in force.
03

AI literacy is an operating obligation

Organisations need proportionate AI literacy for the people operating, overseeing or making decisions about AI. A single awareness module is not a substitute for role-based competence and a record that the relevant people were prepared for their responsibilities.

04

Prohibited practices remain a hard gate

Prohibited practices have applied since February 2025 and now sit within the active enforcement environment. They must be screened at intake and cannot be managed away with a favourable risk score.

05

General-purpose AI governance is already live

Rules for providers of general-purpose AI models have applied since August 2025. Organisations integrating or relying on those models also need to understand the supplier documentation and downstream dependencies affecting their own governance position.

What today does not mean

It does not mean every AI system becomes high-risk today.

The implementation timeline was amended in 2026. Rules for Annex III high-risk systems are scheduled to apply from 2 December 2027. Rules for high-risk AI embedded in regulated products under Annex I are scheduled to apply from 2 August 2028.

That is not a reason to wait.

Inventory, role determination, prohibited-practice screening, supplier evidence, ownership, transparency controls, AI literacy and a defensible decision record all take time to establish. An organisation that waits for the final deadline will still need to reconstruct the history of systems already in use.

Readiness is not the same as pretending every future duty applies today.

Immediate actions

What businesses should do immediately

My advice is not to begin with a hundred-page policy rewrite.

Begin with the facts. Find the AI, establish who owns it, determine the role and risk, then build the controls and evidence around the systems that actually exist.

  1. Step 01

    Build one AI inventory

    Include internal models, purchased AI, embedded SaaS capability, staff-adopted tools, vendor APIs, decision-support systems, automations and autonomous agents.

  2. Step 02

    Assign accountable owners

    Every entry needs a business owner, a technical owner where appropriate and a route to independent review.

  3. Step 03

    Determine the role per system

    Record provider, deployer, importer or distributor status per system. Do not use one organisation-wide label.

  4. Step 04

    Screen prohibited practices

    Complete screening before ordinary risk scoring. A positive signal must stop or escalate the case.

  5. Step 05

    Check Article 50 transparency duties

    Identify systems interacting with people or creating, manipulating or publishing covered content. Assign disclosure and marking controls to named owners.

  6. Step 06

    Establish AI literacy by role

    Define what owners, assessors, reviewers, operators, developers and executives need to know. Record completion.

  7. Step 07

    Apply controls and independent human review

    Use one approved, version-controlled assessment method and keep the assessor separate from the approver.

  8. Step 08

    Monitor change and preserve evidence

    Record incidents, model changes, supplier changes, new data sources, widened permissions and altered thresholds.

Consequences

What happens if a company does not comply

The consequence depends on the obligation, the organisation’s role, the severity of the breach and the action taken after it is identified.

The AI Act allows for warnings, corrective measures, restrictions and substantial administrative fines. The figures below are statutory maximums, not automatic penalties.

Prohibited practices

Up to €35 million or 7% of worldwide annual turnover

The maximum for prohibited AI practices is up to €35 million or, for an undertaking, up to 7% of total worldwide annual turnover for the preceding financial year, whichever is higher.

For SMEs, including start-ups, the maximum is the lower of the percentage or fixed amount.

Operator and transparency breaches

Up to €15 million or 3% of worldwide annual turnover

This category includes specified obligations on providers, authorised representatives, importers, distributors and deployers, together with Article 50 transparency obligations.

Proportionality and the circumstances of the case are taken into account.

Incorrect or misleading information

Up to €7.5 million or 1% of worldwide annual turnover

This can apply where incorrect, incomplete or misleading information is supplied to a notified body or competent authority in response to a request.

For SMEs, including start-ups, the maximum is the lower of the percentage or fixed amount.

Corrective action powers

Fines are not the only possible outcome. Where an AI system presents a risk and adequate corrective action is not taken, a market-surveillance authority can take measures to prohibit or restrict the system being made available or put into service, or require withdrawal or recall where the relevant legal conditions are met.

Operational and commercial impact

Not an additional statutory penalty

An organisation may also face delayed procurement, failed customer assurance, audit findings, remediation cost, restricted deployment, board escalation or reputational damage if it cannot explain what AI it uses and how it is controlled. These outcomes are possible consequences, not automatic ones.

The road ahead

What happens from here

  1. 2 August 2026Today

    Major application and enforcement milestone

    Article 50 transparency rules begin. Enforcement starts for currently applicable rules covering general-purpose AI, prohibited practices, transparency and AI literacy.

  2. 2 December 2026

    Further prohibitions and transition point

    New prohibitions concerning systems that generate non-consensual sexual deepfakes and child sexual abuse material apply. A transition deadline also applies to certain synthetic-content systems already placed on the market before 2 August 2026 in relation to Article 50(2).

  3. 2 August 2027

    Regulatory-sandbox milestone

    Member States should have at least one AI regulatory sandbox operational.

  4. 2 December 2027

    Annex III high-risk rules

    Rules for high-risk AI systems in areas including biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration and justice are scheduled to apply.

  5. 2 August 2028

    Annex I regulated-product rules

    Rules for high-risk AI embedded in regulated products are scheduled to apply.

The dates are staged. The operating model should not be.

A business needs one continuous governance process that can apply the obligation in force today, prepare for the next deadline and preserve the evidence in between.

The response

AIRAS Cloud turns the obligation into an operating process

AIRAS Cloud is not a compliance badge and it does not replace an organisation’s legal advisers. It provides the governed operating layer needed to carry the work consistently and prove what happened.

  1. 01

    Discover

    Surface declared and undeclared AI use.

  2. 02

    Qualify

    Establish what the system is, what evidence exists and what remains uncertain.

  3. 03

    Assess

    Apply deterministic, version-controlled criteria, mandatory floors and prohibited-practice checks.

  4. 04

    Control

    Derive control and evidence requirements from the assessed context.

  5. 05

    Human review

    Route independent reviewers with segregation of duties.

  6. 06

    Monitor

    Track incidents, conditions, supplier changes and material-change triggers.

  7. 07

    Evidence

    Preserve inputs, ruleset version, reasoning, controls, approvals and append-only history.

AI does not approve AI.

AIRAS may identify signals, structure evidence, calculate a deterministic risk outcome and route the workflow. The final accountability remains with an authorised human.

Product screens shown across this site are illustrative interfaces using synthetic data.

Founder note

Why I built AIRAS Cloud for this moment

I have spent more than fifteen years working across complex and regulated technology environments.

What I kept seeing was not a shortage of policies. It was a shortage of operational control.

Organisations could describe what they wanted responsible AI to look like, but when somebody asked which systems were in use, who owned them, how risk was assessed, what evidence existed or who made the decision, the answer was spread across spreadsheets, emails, meeting notes and individual memory.

AIRAS Cloud was built to close that gap.

I wanted one governed path from first discovery to final evidence. I wanted the risk result to be reproducible. I wanted mandatory issues to be impossible to score away. I wanted the person approving the system to be genuinely accountable. And I wanted the evidence trail to survive scrutiny months or years later.

2 August 2026 is not the end of the AI Act implementation timeline. It is the point where waiting becomes a much weaker strategy.

Businesses need to know what AI they have and be able to show how they govern it.

That is the job AIRAS Cloud was built to do.

Richie HigginsFounder, AIRAS Cloud · AFRH Consulting Limited

Official sources

Official sources

This page summarises public regulatory information for operational planning. Where this page and the legal text differ, the legal text governs.

General information, not legal advice. Regulatory obligations depend on the organisation's role, the AI system, its intended use, market position and applicable sector requirements. AIRAS Cloud supports governance workflow, assessment, evidence and structured alignment. It does not certify compliance, provide legal advice or guarantee compliance.

AIRAS Cloud closing scene: a governance status panel showing AI inventory, risk assessment, human oversight and audit-ready evidence at sunset.

The pressure is real. The response can still be controlled.

Start with the inventory. Establish ownership. Apply one defensible method. Keep the evidence. AIRAS Cloud brings that work into one governed operating layer.

interest@airascloud.com

AIRAS Cloud — AI Governance Made Operational

AI does not approve AI.

General information, not legal advice. Regulatory obligations depend on the organisation's role, the AI system, its intended use, market position and applicable sector requirements. AIRAS Cloud supports governance workflow, assessment, evidence and structured alignment. It does not certify compliance, provide legal advice or guarantee compliance.