This Sunday marks one of the European AI Act's dates, and most of what is being written about it is not accurate. Articles published this week announce that 2 August brings the obligations for high-risk systems: recruitment, credit scoring, infrastructure management. It does not. The Digital Omnibus, published and in force since 27 July, pushed those to 2 December 2027.
The two lists are worth separating, because confusing them leads to the two expensive mistakes: chasing an obligation that does not apply, or ignoring the one that does.
What takes effect on 2 August
The transparency obligations of Article 50. Two simple ideas. First: when a person interacts with an AI system, they must know it. Second: artificially generated or manipulated content, whether audio, image, video or text, must be marked so its synthetic origin is detectable.
They apply immediately to systems placed on the market from that date. Systems already operating before it have a transition period for marking, until 2 December 2026.
What does not
Annex III high-risk systems move to 2 December 2027. AI embedded in products covered by their own sectoral legislation, such as toys or watercraft, goes further still: August 2028. And two new prohibitions, the generation of non-consensual intimate content and of child sexual abuse material, take effect in December of this year.
If you run a company that does not build AI
Most organizations are not AI providers. They are users. And for a user, this Sunday's date comes down to three concrete things, and nothing more:
- If a chatbot serves your customers, it must be clear that it is a machine. Not in the privacy policy: in the conversation.
- If you publish AI-generated content, text, images or video, it needs marking. And here the uncomfortable question is usually a different one: do you know where in your organization that content is already being produced?
- If you buy AI from a supplier, outsourcing does not outsource the obligation. Better to have it in the contract before you need it.
There is a fourth that does not start on Sunday but that almost nobody has closed: the AI literacy duty in Article 4 has applied since February 2025, and national authorities are only now beginning to supervise it. In Spain that authority is AESIA.
The calendar has moved twice in a year. What has not moved is the inventory: knowing where AI sits in your organization, who put it there and what data it touches. That list holds for whatever date comes next.
What I would do this week
This is not a compliance programme. It is an afternoon or two: walk the areas where AI is already in use, note who owns each use, check whether any customer-facing touchpoint is an automated system that does not say so, and read what the contracts of the suppliers embedding it actually promise.
That inventory is also the answer to the question arriving in December 2027, when high-risk obligations stop being a future problem. The difference between organizations that reach those dates calmly and those that reach them running is not the date. It is whether somebody keeps the list current across the sixteen months in between.
If the underlying problem interests you, AI agents being adopted faster than they are governed, we covered it in Governing AI agents.