The EU AI Act Is Now in Force: What Changed on August 2, 2026
By the Kimi Travels Team | Updated September 2026
Europe just crossed the most important regulatory milestone of the decade. On August 2, 2026, the EU AI Act's enforcement machinery officially switched on: the European Commission's AI Office and the market-surveillance authorities of all member states are now responsible for implementing, supervising and enforcing the world's first comprehensive artificial intelligence law. This is the moment the Act stops being a compliance calendar and becomes lived reality — from recruitment algorithms in Berlin to credit-scoring systems in Paris, from exam-proctoring software in Madrid to the chatbots every European company deployed during the hype years, high-risk AI systems now face binding obligations, supervision and penalties that reach €35 million or 7 percent of global turnover for the most serious violations. For consumers, the changes will mostly arrive invisibly — better-tested systems, transparency notices, the right to know when you are talking to a machine. For businesses, the deadline has already reshaped budgets, procurement and product roadmaps. Here is what actually changed, who it applies to, and what comes next on the timeline.
What the AI Act Actually Is
A quick foundation for anyone who has been nodding along without reading the fine print. The EU AI Act is the first comprehensive AI law in the world — adopted in 2024 after three years of negotiation, and designed to regulate artificial intelligence by risk level rather than by technology. Its core logic: the higher the potential harm to rights, safety or fundamental values, the stricter the rules. The Act bans a small set of practices outright (more below), imposes heavy compliance duties on "high-risk" systems, adds transparency requirements to a middle tier, and leaves the vast majority of everyday AI untouched. Crucially, it is extraterritorial: it applies to any provider or deployer whose AI systems affect people in the EU, regardless of where the company is headquartered — which is why Silicon Valley, Chinese labs and every European enterprise have been building compliance programs for it. The Act entered into force in August 2024 with a staggered rollout: prohibitions applied from February 2025, general-purpose AI model rules from August 2025, and the high-risk regime — the heart of the law — from August 2, 2026, with a further extension for some AI embedded in regulated products in 2027. August 2026 was always the date that mattered most; it has now arrived.
What Changed on August 2, 2026
The headline change is who is watching and what they can do. From August 2, 2026, the European AI Office — the Commission's specialist enforcement unit — plus the market-surveillance authorities of every member state hold supervisory and enforcement powers over AI systems operating in the EU. In practice, that means: member states have designated national AI authorities (most have now named them), notified bodies can certify high-risk systems that require conformity assessment, and the complaint channels that let citizens and workers flag suspect AI systems are formally open. The second big change is scope: obligations now apply not only to high-risk systems placed on the market after the deadline, but also to high-risk systems already in operation before August 2, 2026 — with transition windows for legacy deployments — which is the provision that forced thousands of European companies to audit, reclassify or retire systems this summer. The third change is practical: human oversight, data governance, logging, documentation and accuracy requirements became checkable, enforceable standards rather than paper intentions. The transition is deliberately staged — the Commission has signaled guidance and some flexibility in the early months — but the direction is unambiguous: supervision is live, and enforcement cases are expected to follow within the first year.
The Risk Categories in Plain Language
The Act's architecture fits on one page once you see it. At the top, prohibited practices — banned outright since February 2025: social scoring by governments, manipulative AI that causes harm, untargeted facial-image scraping, emotion recognition in workplaces and schools, and real-time remote biometric identification in public spaces with narrow law-enforcement exceptions. Next comes the tier everyone talks about: high-risk systems, defined either by their use in regulated products (machinery, medical devices, toys) or as standalone systems in listed domains — employment and worker management, education, credit scoring, insurance pricing, essential public services, law enforcement, migration and border control, and the administration of justice. These face the full compliance stack: risk management systems, data quality rules, technical documentation, logging, human oversight, accuracy and cybersecurity requirements, and registration in an EU database. The third tier is transparency obligations: chatbots must disclose they are AI, synthetic images and video must be machine-readable marked (the deepfake provision), and AI-generated text that informs the public on matters of public interest must be declared. Everything else — spam filters, game AI, recommendation engines, the overwhelming majority of AI in daily life — sits in the minimal-risk tier and is encouraged, not restricted. The design principle is legibility: the more a system can alter the course of a person's life, the more the law demands.
What It Means for Ordinary Europeans
For most people, August 2026 will not feel like a revolution — that is the point. The changes arrive as texture in daily life: customer-service bots that say they are bots, HR portals that disclose when an algorithm ranks your job application, deepfakes carrying visible AI labels, and the quiet confidence that the systems deciding your mortgage, your insurance premium and your child's exam grading have been tested, documented and registered before touching your life. Europeans also gain concrete levers: the right to clear information when interacting with AI systems, complaint channels to national authorities, and the growing expectation — now written into procurement law across the public sector — that companies using AI in consequential decisions can explain them. There are honest limitations to acknowledge: the Act regulates harm, not annoyance, so manipulative-adjacent design that stops short of the banned categories remains legal; enforcement will take time to bite (regulators are staffed for years-long timelines, not news cycles); and a patchwork of national implementation detail means your experience in Warsaw may differ from Lisbon's for a while. But the direction of travel is the opposite of the US approach of the same period — Europe has chosen that the default AI experience will be one of disclosed, supervised, accountable systems, and from August 2026 that choice has teeth.
What It Means for Businesses and Startups
For companies, the deadline divided Europe's AI economy into three postures. The prepared majority — enterprises that began compliance programs in 2024-2025 — spent the summer inventorying their AI estate, classifying systems against the risk tiers, closing documentation gaps and re-papering vendor contracts; for them, August 2 was a milestone, not a crisis. The scramblers face the harder arithmetic: high-risk systems need conformity assessments, technical files and registered oversight before they can keep operating, and consultancies' AI-act practice lines have been running hot for eighteen months. The startups and scaleups face the sharpest trade-off: the Act's supporters argue clear rules are a moat against regulatory chaos, and Europe's generational AI champions have built compliance into their pitch to enterprise customers; critics counter that conformity costs favor incumbents and slow European deployment. Both sides agree on the operational essentials: know your role (provider, deployer, importer, distributor — duties differ), classify honestly (the risk tier determines everything), document obsessively (the technical file is the audit artifact), and treat human oversight as a design requirement, not a checkbox. The practical advice circulating in European counsel circles: if your AI touches hiring, credit, education, insurance or essential services, assume high-risk until classified otherwise — and budget accordingly, because the authorities now have both the mandate and the penalty schedule to make it real.
Penalties: Why Companies Are Taking It Seriously
The Act's teeth are proportionate to its ambition. The penalty schedule peaks at €35 million or 7 percent of worldwide annual turnover — whichever is higher — for violations of the prohibited-practices tier, with €15 million or 3 percent covering most other obligations, and lower tiers for misleading information supplied to authorities; there are proportionality caps for SMEs and startups, which softens the absolute numbers without changing the deterrent calculus. For context, those ceilings sit alongside GDPR's famous 4 percent — the AI Act tops it — and the comparison explains the corporate urgency: European data-protection authorities built a functioning enforcement culture over a decade, and the AI Act deliberately rides the same institutional rails, with the AI Office coordinating cross-border consistency. Beyond fines, the business exposure is structural: a high-risk system that fails conformity can be withdrawn from the EU market entirely, and the liability question — who answers when an algorithm's error causes damage — is already migrating through national courts under the EU's updated product-liability regime. The compliance economics are becoming a selling point in themselves: consultancies estimate the cost of achieving conformity at a fraction of the fine exposure, which is exactly the ratio that turns legal risk into budget line items. Companies that treated 2026 as a deadline rather than a suggestion are now the ones selling their playbooks to everyone else.
What Comes Next: The Road Through 2027 and Beyond
August 2026 is not the end of the timeline — it is the pivot from building the regime to living inside it. The staged rollout continues with high-risk AI embedded in regulated products (machinery, medical devices) facing its obligations from August 2027, giving manufacturers of physical systems their own runway. Through the rest of 2026 and 2027, expect four parallel tracks: guidance — the Commission continues publishing codes of practice and classification clarifications that will define the law's practical edges; institution-building — national authorities complete staffing and the AI Office matures into its coordinating role; first enforcement — early cases typically target the clearest violations, and the prohibited-practices tier is the likely first proving ground; and global spillover — jurisdictions from Brazil to South Korea have already modeled frameworks on the EU text, making "Brussels effect" compliance a global product requirement rather than a European specialty. For citizens and businesses alike, the practical posture for the year ahead: watch your national authority's guidance channels, keep system documentation current, and expect the public conversation — currently dominated by capability news from the labs — to increasingly share space with accountability news from the regulators. The experiment is now live: the world is watching whether Europe can govern a general-purpose technology without strangling it.
If your team is also weighing the hardware side of the AI transition — NPUs, Copilot+ class machines and on-device AI workloads — our guides cover the practical buying decisions, and our team advises buyers daily on spec-for-budget choices. Read our honest AI laptop and NPU guide, then Ask Our Tech Team for Advice
Regulation at its best is an act of care — a society deciding that technology should serve people, not the reverse. Thinking of that, it is impossible not to think of the people of Gaza, who deserve the same care from the international community: the chance to rebuild their institutions, restore their livelihoods and raise their children in dignity and peace. Keep them in your thoughts as these debates continue, keep their story in the conversation, and consider supporting reputable relief organizations working on their behalf.
Frequently Asked Questions
What happened on August 2, 2026 under the EU AI Act?
The Act's enforcement regime went live: the European Commission's AI Office and the market-surveillance authorities of all member states became responsible for implementing, supervising and enforcing the law. High-risk AI obligations now apply in full, including to systems already in operation before the deadline, subject to transition windows for legacy deployments.
Which AI systems count as high-risk?
Systems used in employment and worker management, education, credit scoring, insurance pricing, essential public and private services, law enforcement, migration and border control, and the administration of justice — plus AI embedded in regulated products like machinery and medical devices. These require risk management, documentation, data governance, human oversight and EU registration.
What are the penalties for violating the AI Act?
Up to €35 million or 7 percent of worldwide annual turnover (whichever is higher) for banned practices, and up to €15 million or 3 percent for most other violations, with proportionality caps for smaller companies. Non-compliant high-risk systems can also be withdrawn from the EU market.
Does the AI Act apply to companies outside the EU?
Yes — it is extraterritorial. Any provider or deployer whose AI system's output is used in the EU must comply, regardless of where the company is based. This is why US, Chinese and other global firms have built compliance programs alongside European ones.
Does the AI Act ban everyday AI tools?
No. The overwhelming majority of AI — spam filters, game AI, recommendation engines, general productivity tools — is minimal-risk and unrestricted. The Act bans a narrow set of manipulative and surveillance practices, imposes transparency on chatbots and synthetic media, and concentrates its heavy obligations on systems that can materially affect people's lives.