The AI Act on 2 August 2026: What Actually Applies to Your Business
Eric Leroy
On 2 August 2026, the AI Act enters its phase of general application. For several weeks now, a steady stream of articles has been telling small and mid-sized businesses that their AI systems "become regulated" on that date, complete with heavy documentation duties around recruitment, credit scoring or employee assessment. That account is now inaccurate: the obligations covering high-risk systems have been postponed. Here is what genuinely applies in a few days' time, and what does not apply yet.
What changed this summer
The regulation's original timetable provided that the obligations weighing on high-risk AI systems would enter into application on 2 August 2026, at the same time as the rest of the text. That timetable was amended by the simplification package adopted in the spring, commonly referred to as the Digital Omnibus.
The Council of the European Union gave the text its final green light on 29 June 2026, following a political agreement with the Parliament in May. The stated reason is operational rather than political: the harmonised standards that companies need to rely on in order to demonstrate compliance were not available in time, which made the August deadline difficult to hold.
The outcome is a substantial delay. According to the official timeline published by the European Commission, the rules applying to high-risk systems falling under Annex III will apply on 2 December 2027, and those covering systems embedded in already regulated products on 2 August 2028.
What genuinely applies on 2 August 2026
The postponement does not mean that nothing changes. On that date, the bulk of the regulation's rules enter into application and the enforcement phase begins, which includes the power of national authorities to impose penalties on the parts already in force.
The most concrete point for a small or mid-sized business is that the transparency obligations set out in Article 50 start to apply. They cover uses that are far more widespread than high-risk systems: a publicly accessible conversational agent, the generation of synthetic content, or the use of a system that interacts directly with people.
It is also worth recalling what has already been applicable for several months, and which many companies still overlook. The prohibited practices and the AI literacy obligations entered into application on 2 February 2025. The rules on general-purpose models and governance followed on 2 August 2025. A company discovering the subject in July 2026 therefore has no runway left on those points: it is already within scope.
What this changes for businesses
For the vast majority of small and mid-sized companies, the practical consequence fits in a single sentence: the heavy documentation burden that some articles announced for this summer is not arriving now, but the transparency obligations most certainly are.
In concrete terms, if your website offers a chatbot, if you use a conversational assistant in contact with your customers, or if you publish AI-generated content, the subject concerns you from August onwards. Users must know that they are addressing a machine, and synthetic content must be identifiable as such. These are interface and disclosure adjustments, not multi-month projects, but they do assume you have taken stock of what is actually running inside your organisation.
If, on the other hand, you were considering a system for screening job applications, scoring customers or assessing performance, the postponement gives you real preparation time, through to the end of 2027. That extra time is not an invitation to shelve the subject: it corresponds to the time needed to properly design the traceability, data quality and human oversight that such systems will demand. Companies that wait until the autumn of 2027 to deal with it will discover that these requirements are designed upfront, not retrofitted.
The third effect is less visible but just as important. The gap between the actual timetable and what many sources are publishing creates a risk of poor decisions: abandoning a useful project in the belief that the deadline is imminent, or conversely assuming you are out of scope because you read that "everything has been postponed". Both conclusions are wrong.
How to check your own situation
The useful approach comes down to three steps, and you do not need a specialist law firm to get started.
- Take an inventory of what genuinely uses AI in your company, including the tools adopted by teams without going through the technical department.
- Classify each use according to whether it involves an interaction with people, the generation of content, or a decision affecting individuals.
- Deal with transparency first, since it applies in August, before the high-risk topics, which have additional time.
For definitions and scope, the text of the regulation published in the Official Journal of the European Union is authoritative, and the Commission provides an official FAQ as well as an overview of the regulatory framework. On the French side, the CNIL publishes its recommendations on AI, which are particularly useful on how the rules interact with the GDPR, which continues to apply independently of the AI Act. Support schemes for businesses are listed on the entreprises.gouv.fr portal.
The bottom line
2 August 2026 is a genuine deadline, but not the one many are announcing. What is arriving is the general application of the regulation and the transparency obligations, which affect everyone who exposes a chatbot or publishes generated content. What is not arriving now are the obligations on high-risk systems, pushed back to December 2027 and August 2028 for want of available standards.
For a small or mid-sized business, the right posture is neither panic nor wait-and-see. It is to know precisely which AI systems are running in the company, to handle transparency now because it is simple and immediately applicable, and to use the extra time granted on high risk to design properly rather than to procrastinate. If you are preparing an AI integration project and the compliance question shapes your technical choices, tell us about your situation: we will tell you which regime you fall under before you commit to anything.