The AI Act enters a decisive phase. What has changed on 2 August 2026 and how to prepare
03.08.2026
On 2 August, the AI Act, the world’s first comprehensive regulation of artificial intelligence, entered another key implementation phase. From that date, organizations operating in the EU market will have to meet new transparency obligations. Among other requirements, they must clearly inform users when they are interacting with AI and label algorithm-generated content.
At the same time, the Digital Omnibus package adopted in June has postponed the obligations for high-risk systems until December 2027. This is not a reprieve, but additional time, and experience shows that preparing a large organization for compliance is a matter of quarters, not weeks.
If your organization uses AI in the European Union, the AI Act applies to you — regardless of industry or scale. The regulation is already in force, with further obligations phasing in through 2028. Fines reach 7% of global turnover and scale with the size of the company.
What has changed on 2 August 2026
The most important change is the full entry into force of the transparency obligations (Article 50). Chatbots and other systems that interact with people must clearly disclose that they are interacting with AI. Content generated or manipulated by algorithms, including deepfakes, must be labelled, and emotion recognition systems must notify the people they affect.
Systems already on the market before 2 August 2026 have until 2 December 2026 to implement machine-readable labeling.
The Digital Omnibus has also reinforced the supervisory powers of the European AI Office, including new investigation and inspection authorithies.
“Every AI system running in an organization already has a risk tier — whether anyone has formally assigned it. Estimate it too high and you overspend; too low and you are exposed to penalties. Compliance starts with knowing what you actually have” — says Marcin Mosiołek, AI Competency Center Lead at Sii Poland.
More time, not less responsibility
The Digital Omnibus package has pushed back the timeline for high-risk AI systems. Standalone high-risk AI systems covered by Annex III now have until 2 December 2027, while high-risk AI embedded in regulated products covered by Annex I has until 2 August 2028. EU countries also have more time to set up regulatory sandboxes where companies can test AI solutions under supervision.
The overall direction remains unchanged. High-risk systems will still need to be registered, documented, monitored and designed with proper risk controls, data quality and human oversight. In other words, the market has gained more time, not fewer responsibilities.
“The postponement of the high-risk obligations is not a reprieve, but time that has to be used wisely. Inventorying, classifying and implementing controls in a large organization is work measured in quarters, not weeks. Whoever starts today will be ready in December 2027 — without panic and without overspending”— continues Marcin Mosiołek, AI Competency Center Lead at Sii Poland.
Four risk tiers — and one rule: know what you have
The AI Act sorts all AI systems into four tiers. Prohibited practices have to leave the organization. High-risk systems are allowed, but only with human oversight, testing and full documentation. Systems covered by transparency obligations may operate as long as people know they are dealing with AI. All other AI systems from copilots to internal automations, should still be known, owned and governed by the organization’s rules.
In practice, the biggest challenge is not interpreting the law, but answering a simpler question: Which AI systems are currently in use across the organization? Shadow AI — tools adopted by teams outside official oversight — means many companies today do not know the full list of their own systems, let alone their risk tiers.
Sii’s answer: Compliance built into everyday operations
To help organizations prepare, Sii Poland has developed an AI Act Readiness Program focused on inventorying AI systems, implementing governance processes and maintaining ongoing compliance. The program follows this three-stage approach.
SCAN (2–4 weeks, fixed price) is an inventory and risk classification of every AI system used across the organization — shadow AI included. The result is a living AI register: every system, its risk tier, its owner and its evidence in one place that is always current.
BUILD embeds controls, governance and AI literacy into products and teams. Disclosure, logging and human oversight run in pipelines and products — not in documents.
RUN keeps compliance alive over time: re-classifying what has changed, refreshing controls and delivering a board-ready report. Every new AI application then follows the same line: idea, registered, classified, controls applied, cleared and monitored — compliance becomes part of the design process, rather than an after-the-fact audit.
“For large organizations, AI compliance cannot be treated as a one-off audit. Governance processes need to become part of day-to-day operations so that new AI systems are assessed and documented as they are introduced” — says Marcin Mosiołek, AI Competency Center Lead at Sii Poland.
Where to start
The first step, and the first deliverable of working with Sii, is a risk-classified register of every AI system running in the organization. It is the foundation for informed decisions about what to remove, what to control, what to disclose, and what simply to govern.
Sources
1. Council of the EU, “Artificial intelligence: Council gives final green light to simplify and streamline rules” (29 Jun 2026) — consilium.europa.eu
2. European Commission, “Navigating the AI Act” — digital-strategy.ec.europa.eu
3. Gibson Dunn, “EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes” — gibsondunn.com
4. Morgan Lewis, “EU Approves Delays and Other Amendments to Certain EU AI Act Obligations” (Jun 2026) — morganlewis.com
5. Lewis Silkin, “The Digital Omnibus on AI enters into force today” (27 Jul 2026) — lewissilkin.com
To comply with applicable regulations, this article was reviewed using AI for language and spelling checks.