AI Act, Things Get Serious from 2 August 2026: What Really Kicks In for Businesses — Transparency, Penalties and Postponements
The Digital Omnibus has postponed the obligations on high-risk systems, but on 2 August the transparency rules on chatbots and AI-generated content come into force anyway, and the penalty framework becomes operational. A guide to understanding what concerns your company now.
The postponement did happen, but 2 August is no ordinary day
In recent months two opposing narratives have been chasing each other around the AI Act. The first: “it’s all been postponed, there’s nothing to do”. The second: “from 2 August, obligations kick in for anyone using artificial intelligence”. As so often happens, the truth lies in between, and it’s written in black and white in Regulation (EU) 2026/1744, the so-called Digital Omnibus on AI, published in the Official Journal of the European Union on 24 July 2026 and in force three days later.
We already discussed the path that led to the postponement of the heaviest obligations when the political agreement was reached, in the article on why SMEs must not stand still after the Omnibus agreement. Now that the regulation is law, we can say precisely what has slipped and, above all, what does come into force on 2 August 2026. Because something really does come into force, and it concerns far more companies than people think.
What has been postponed (and until when)
The Digital Omnibus intervenes surgically on the timetable of the AI Act, not on its framework. The postponements essentially concern high-risk systems, meaning those used in sensitive areas such as recruitment, access to credit, education, justice or biometric identification.
There are three new dates. The obligations on “standalone” high-risk systems (those in Annex III: employment, credit, essential services and the like) slip from 2 August 2026 to 2 December 2027. Those on high-risk systems built in as safety components of products already regulated by European rules — machinery, medical devices, toys — slip to 2 August 2028. The classification rules, i.e. the criteria for establishing whether a system is high-risk, will apply from 2 August 2027. Also postponed is the obligation to technically mark generated content (so-called watermarking), which moves to 2 December 2026.
So if your company develops or uses systems that fall into these categories, you have more time. But be careful not to read this time as permission to do nothing: it’s time to get ready, not to forget about it.
What really kicks in on 2 August: transparency
The heart of what becomes applicable on 2 August 2026 is Article 50 of the AI Act, the one on transparency obligations. And here the scope widens enormously, because we’re not talking about exotic high-risk systems: we’re talking about tools that thousands of Italian companies use every day.
In practice, two rules above all. The first: anyone who makes interactive systems available — a chatbot on a website, a virtual assistant in customer service — must ensure the user knows they’re talking to a machine and not a person. The second: anyone who generates synthetic content with artificial intelligence — text, images, audio, video intended for the public — must make it recognisable, in ways that vary depending on the context and the type of content.
If your company has a chatbot on the front line with customers, or publishes content generated with generative AI tools, these obligations concern you right away. It’s no coincidence that we anticipated the logic of this when we discussed AI tools for content creation: using AI to produce more doesn’t exempt you from declaring it, and those who do so transparently gain in credibility too.
Penalties and governance: the machinery starts up
The second change of 2 August is less visible but just as important: the framework of governance and penalties becomes fully operational. The designated national authorities gain supervisory powers and can impose the penalties set out in the regulation, which for the most serious infringements reach significant percentages of annual worldwide turnover, with proportionate reductions provided for SMEs.
Until yesterday the AI Act was, for many companies, a rule “on paper”: obligations defined but no one tasked with enforcing them. From August the full machinery exists: applicable rules, authorities with powers, penalties that can be imposed. It’s the difference between a no-entry sign and a switched-on speed camera.
It’s also worth recalling what has been active since February 2025 and which the postponement did not touch: the ban on unacceptable-risk practices (manipulation, social scoring and the like) and the obligation of AI literacy for staff who use these systems in the company. To which the Digital Omnibus adds, from 2 December 2026, new explicit bans on systems that generate non-consensual intimate material and child sexual abuse material.
What to do now: three concrete checks
For most Italian SMEs, getting compliant with what kicks in on 2 August isn’t a compliance project costing tens of thousands of euros. It’s a targeted check on three fronts.
1. Taking stock of the tools
The first question is only seemingly trivial: which AI systems does your company really use? Chatbots on the website, assistants in contact forms, content-generation tools for social media and newsletters, AI features inside the management system or the CRM. Without this map you can’t know which obligations concern you. In the insurance sector, where AI tools are spreading rapidly, we carried out a similar exercise in the article on the AI Act and insurance intermediaries: the method holds for any sector.
2. Transparency towards users
If you have a chatbot, check that it presents itself as such: a clear label, an opening message, no ambiguity about the fact that there’s software on the other side. If you publish AI-generated content, define an internal policy on how to flag it. These are interventions a web team resolves in days, not months — but they need to be done.
3. Training your people
The AI literacy obligation has been active for a year and a half, yet it remains the most ignored. Anyone in the company using artificial intelligence tools must know what they are, what they can get wrong and what limits they have. You don’t need a master’s degree: you need training proportionate to the role, documented and kept up to date.
In summary
The Digital Omnibus moved the obligations on high-risk systems to 2027 and 2028, but on 2 August 2026 the AI Act nonetheless stops being a rule on paper: the transparency obligations on chatbots and generated content come into force, and the supervisory and penalty framework becomes operational. For SMEs, today’s game isn’t major compliance, but three targeted checks: knowing which AI tools you use, declaring them transparently to users, and training those who use them. Those who do this now take the worry off the table with little effort; those who put it off will find themselves doing it under pressure when the first challenges arrive.
At A126 we help companies map the artificial intelligence tools in use, bring chatbots and content into line with transparency obligations, and set up the training required by the rules, with interventions proportionate to the company’s real size. If you want to understand in half a day where you stand on the AI Act, get in touch for a free consultation.
A126 Corporate Advisors — digital innovation, done by the book.