Engraved navy and gold calendar dial with one date marker illuminated and gears slipping to a later notch, representing the EU AI Act compliance timeline

EU AI Act GPAI Obligations: What Actually Lands August 2, and What Just Slipped to 2027

July 20, 2026
Executive Summary
  • August 2, 2026 is a real deadline, but it is not the one most coverage describes: the high-risk AI obligations everyone braced for were formally postponed to December 2027 and August 2028.
  • What actually lands on August 2 is Article 50 transparency: telling people they are talking to a machine, and marking AI-generated content.
  • EU AI Act GPAI obligations are not new. They have been enforceable since August 2, 2025, and the penalty regime came with them.
  • The delay is adopted but not yet published in the Official Journal, so as of today the original deadlines technically remain the law.
  • Penalties run to €35 million or 7% of worldwide turnover at the top tier, and transparency breaches sit at €15 million or 3%.

Back in June I wrote a piece about which parts of the EU AI Act actually reach US companies. It was accurate when I published it. It is now partly out of date, which is a fair summary of what it feels like to track this regulation. Between that article and this one, the EU formally agreed to move its biggest compliance deadline by sixteen months, and almost nothing you will read this month has caught up.

So here is a corrected map, thirteen days out from the date everyone circled.

Line-engraved automaton head emitting a marked ribbon of output, representing AI transparency and disclosure obligations

What Actually Changes on August 2, 2026

Article 50 transparency obligations become enforceable, and general penalties switch on for most operator duties. That is the honest short version.

Article 50 is the least glamorous part of the Act and the part most likely to touch an ordinary US software company. It requires three things in practice. If your system interacts directly with a person, you have to tell them they are dealing with AI. If your system generates or manipulates synthetic content (text, image, audio, video), that content has to be marked as artificially generated. And that marking has to be machine-readable, not just a line of small print a human might notice.

If you sell a B2B product with a support chatbot, a drafting assistant, or anything that produces content a European will read, this is your deadline. Not the high-risk regime. This one.

The AI Act Service Desk, the Commission's own reference, describes August 2, 2026 as the point where the majority of the rules apply and enforcement begins for applicable rules. Regulatory sandboxes activate the same day. There is a narrow carve-out worth knowing: for generative systems already placed on the market before August 2, the machine-readable watermarking requirement slides to December 2, 2026. That is a grace period on the marking mechanism, not on the obligation to disclose.

Engraved clockwork escapement held back by a brass pawl while a second dial keeps running, representing the delayed high-risk deadline

The High-Risk Delay, and What It Does Not Cover

The Annex III high-risk obligations moved from August 2, 2026 to December 2, 2027, a 16-month postponement, and Annex I embedded systems moved to August 2, 2028.

This came through the Digital Omnibus on AI, the simplification package the Commission proposed and the co-legislators spent the spring negotiating. The procedural trail is short and worth committing to memory, because the details matter more than the headline. Trilogue agreement landed May 7. The European Parliament formally endorsed it June 16. The Council gave final adoption June 29.

According to DLA Piper, "the Council of the EU has given its final green light to the AI Act simplification package... The legislative act will be published in the EU's official journal shortly and will enter into force on the third day after this publication."

Read that last clause again, because it is the part that should govern your behavior this quarter. The Omnibus is adopted. It is not yet published. It enters into force 3 days after it appears in the Official Journal, and as of this writing that has not happened. The trackers are blunt about the implication. AIActDeadlines puts it plainly: the Omnibus "is approved but not yet law... on paper, the original dates in Regulation (EU) 2024/1689 still stand."

I do not think anyone seriously expects the delay to fall apart. Both co-legislators have voted. But there is a difference between a deadline that has moved and a deadline that is expected to move, and if you are the person who has to sign something, that difference is your whole job. The practical read: plan around December 2027, do not dismantle the work you have already done, and watch for the OJ citation before you tell your board the pressure is off.

What the Omnibus explicitly did not touch is also instructive. It did not move the prohibitions. It did not move the GPAI obligations. It did not move Article 50. The EU delayed the expensive engineering-heavy regime and kept the disclosure regime on schedule, which tells you something about where the political appetite actually sits.

Engraved central sphere feeding brass conduits into smaller downstream mechanisms, representing general-purpose AI models and downstream systems

EU AI Act GPAI Obligations Have Been Live Since 2025

General-purpose AI model obligations took effect August 2, 2025. They are not a future problem, and they are not part of the delay.

This is the single most common error I see in client conversations, and it is an easy one to make, because "GPAI" and "August 2" appear together in so much coverage that the year gets lost. The Commission's own regulatory framework page states that the governance rules and the obligations for GPAI models became applicable on 2 August 2025. That was nearly one year ago.

A general-purpose AI model, in the Act's framing, is a model trained on broad data at scale that displays significant generality and can competently perform a wide range of distinct tasks, and that can be integrated into a variety of downstream systems. Large language models are the obvious case. If you fine-tune or substantially modify one and then place it on the EU market, you can inherit provider obligations along with it, which is the trapdoor most teams do not see coming.

The obligations themselves are documentation-shaped rather than engineering-shaped. Providers maintain technical documentation covering training, capabilities, limitations and risks. They pass enough information downstream that the companies building on the model can meet their own duties. They publish a sufficiently detailed summary of training data content and put a copyright policy in place. Models judged to carry systemic risk (the very large, very capable ones) pick up additional evaluation, adversarial testing, incident reporting and cybersecurity duties on top.

Most companies reading this are not GPAI providers. They are deployers building on someone else's model, and their real exposure is second-hand: if your upstream provider has not given you the documentation you need, you cannot complete your own compliance story. That is a vendor-management problem, and it belongs in your procurement questions now rather than in a scramble later. It pairs naturally with the kind of risk assessment that isn't theater that I keep arguing for.

Engraved hemisphere with brass filaments crossing an ocean toward a ring of twelve stars, representing extraterritorial reach of the EU AI Act

Whether the EU AI Act GPAI Obligations Reach Your US Company

Probably, if Europeans use your output. Physical location is close to irrelevant under this Act.

Article 2 sets territorial scope in three parts, and the third one is the one that surprises people. Article 2(1)(a) covers providers placing AI systems on the market or putting them into service in the Union, "irrespective of whether those providers are established or located within the Union or in a third country." Article 2(1)(b) covers deployers located in the Union. Article 2(1)(c) covers providers and deployers established in a third country "where the output produced by the system is used in the Union."

That third limb is an effects test, and it is broad by design. Your servers can sit in Virginia. Your company can have no European entity, no European staff, and no European bank account. If the predictions, recommendations, decisions or generated content your system produces are used in the Union, you are in scope.

"Placing on the market" carries its ordinary EU product-law meaning: the first making available of a system, whether for a fee or free of charge. A free tier counts. An open signup form that a German company can complete counts. An API a Dutch startup can call counts.

So the practical test is not "do we operate in Europe." It is closer to: can a European sign up, and does what we produce end up in front of one? For most US SaaS companies with self-serve pricing, the answer is yes and has been for years. One consequence teams routinely miss is that a non-EU provider making a system available on the EU market is expected to appoint an authorised representative established in the Union. That is a named entity with a mailing address, not a checkbox, and it takes longer to arrange than people budget for.

Engraved four-tier balance scale with progressively larger brass weights, representing the EU AI Act penalty tiers

What the Fines Actually Look Like

Four tiers, each expressed as a fixed euro amount or a percentage of worldwide annual turnover, whichever is higher.

Article 99 sets them out. Prohibited practices under Article 5 carry up to €35 million or 7% of total worldwide annual turnover. Most other operator obligations, and this is the bucket Article 50 transparency sits in, carry up to €15 million or 3%. Supplying incorrect, incomplete or misleading information to authorities carries up to €7.5 million or 1%. GPAI model provider violations run through Article 101 at €15 million or 3%.

"Whichever is higher" is doing real work in those sentences. For a company of any size, the percentage is the operative number, and it is calculated on worldwide turnover rather than European revenue. A US company earning a rounding error of its revenue in Europe can still be assessed against its global top line. There is a proportionality safeguard for SMEs and startups, where authorities generally apply the lower of the two figures.

I would not build a compliance program around fear of maximum fines. Regulators rarely open at the ceiling, and the first enforcement year of any regime is mostly about establishing precedent against obvious offenders. But the tiering tells you what the EU considers serious, and it is worth noticing that transparency failures sit in the same bracket as high-risk system failures. Not telling someone they are talking to a bot is treated as a comparable offense to botching a credit-scoring model's risk management. That is a deliberate signal.

Engraved column of circular gauges being filled by a compass-and-rule hand, representing an AI compliance checklist

What to Do Before August 2

Inventory what talks and what generates, then fix the disclosure gaps. That is the whole assignment for this window.

Start with a list of every place your product speaks to a person or produces content. Chatbots, support deflection, email drafting, summarization, image or audio generation, anything that writes copy a customer sees. For each one, answer two questions: does a user know this is AI, and is the output marked as machine-generated in a way a machine can detect? Those two answers are most of your Article 50 posture.

Then check your upstream. Ask every model vendor for the documentation the Act obliges them to pass downstream, in writing. If a vendor cannot produce it, you have learned something useful about that vendor that has nothing to do with Europe.

Then decide your high-risk posture deliberately rather than by default. If you were building toward August 2026 for an Annex III use case (hiring, credit, education, essential services, biometrics), you now have until December 2027, and that is genuine relief. Do not treat it as permission to stop. The requirements did not soften, and sixteen months disappears quickly when conformity assessment and notified bodies are involved. Teams that keep momentum through a delay tend to arrive calm. Teams that stand down tend to repeat this exact scramble in a year.

Finally, sort out the authorised representative question if you are in scope and have not. It is administrative, it is unglamorous, and it is the kind of thing that blocks a launch when someone finally asks about it.

None of this needs a consultant, a platform, or a six-figure program. It needs someone to own it and two weeks of unglamorous attention, which is roughly the argument I made about responsible AI without the compliance theater and I have not changed my mind.

Wide engraved row of gold keyhole and aperture shapes on navy, section break before the frequently asked questions

Frequently Asked Questions

When Does the EU AI Act Take Effect?

It already has, in stages. The Act entered into force August 1, 2024. Prohibited practices and AI literacy duties applied from February 2, 2025. GPAI model obligations and the governance and penalty framework applied from August 2, 2025. Article 50 transparency and general enforcement apply from August 2, 2026. High-risk obligations now land December 2, 2027 for standalone Annex III systems and August 2, 2028 for Annex I systems embedded in regulated products.

What Is a General-Purpose AI Model Under the EU AI Act?

A model trained on broad data at scale that shows significant generality, can competently perform a wide range of distinct tasks, and can be integrated into many downstream systems. Large language models are the clearest example. The classification attaches to the model, not the application built on top of it, though substantially modifying a model can pull you into provider obligations.

Does the EU AI Act Apply to US Companies?

Yes, in many cases. Article 2(1) applies to providers placing systems on the EU market regardless of where they are established, and to providers and deployers in third countries where the output of the system is used in the Union. Neither corporate domicile nor server location is the deciding factor. If Europeans can access your product or consume what it produces, assume you are in scope until you have checked properly.

What Are the August 2026 EU AI Act Obligations?

Article 50 transparency, principally: disclosing AI interaction to users, labeling synthetic or manipulated content, and marking AI-generated output in machine-readable form. General enforcement and penalties for most operator obligations also begin, and regulatory sandboxes activate. The high-risk obligations originally scheduled for this date have been postponed.

How Do You Comply With the EU AI Act's GPAI Rules?

If you provide a general-purpose model: maintain technical documentation on training, capabilities and limitations, pass sufficient information to downstream deployers, publish a summary of training data content, and keep a copyright policy. Systemic-risk models add evaluation, adversarial testing, incident reporting and cybersecurity duties. If you only deploy someone else's model, your practical task is collecting that documentation from your vendor and keeping it current.

Were the EU AI Act High-Risk Deadlines Actually Delayed?

They were adopted for delay, which is not quite the same as delayed. Parliament endorsed the Digital Omnibus on June 16, 2026 and the Council adopted it June 29, 2026, moving Annex III systems to December 2, 2027 and Annex I systems to August 2, 2028. The amending regulation enters into force three days after publication in the Official Journal, which has not yet occurred. Until then the original dates remain the text of the law.

If you want a second set of eyes on where your product actually sits in this, that is precisely what our System Review Diagnostic is for.

References

Back to Blog

Need Help?

Schedule a time to meet with us using the calendar below...