Security3 min read666 words

EU AI Act, August 2026: What Applies to Software Teams

The Act's most consequential obligations landed on 2 August 2026, and some were then moved. What is in force now, what shifted, and what an engineering team building AI features should actually do about it.

JL

Jishu Labs

The EU AI Act reached its most consequential milestone on 2 August 2026, when Annex III high-risk obligations, Article 50 transparency duties, conformity assessment, CE marking and AI Office enforcement powers were scheduled to take effect. A subsequent Digital Omnibus package moved some of it. Both facts matter, and conflating them is how teams end up either panicking or ignoring it entirely.

This is engineering guidance, not legal advice

The Act's application depends on your role (provider, deployer, importer), your users' location, and how your system is classified. The Digital Omnibus changes were still moving through formal adoption at the time of writing. Get advice from counsel before making a compliance determination — what follows is about what to build, not about whether you are in scope.

What applies regardless of the delays

Article 50 transparency obligations are the part most software teams touch. In practice they mean people should know when they are interacting with an AI system rather than a human, and AI-generated content should be identifiable as such. The obligation for labelling generated content was deferred by roughly four months, to 2 December 2026.

  • A chatbot should disclose that it is a machine, unless it is obvious from context.
  • Synthetic content should be marked in a machine-readable way.
  • Emotion-recognition and biometric categorisation systems must inform the people exposed to them.

What high-risk classification actually demands

If a system falls under Annex III, the obligations are documentation-heavy and largely engineering work:

  • Technical documentation covering design, training data and testing, maintained rather than written once.
  • Data governance — training, validation and test sets meeting stated quality criteria, with their provenance recorded.
  • Logging sufficient for traceability and audit, retained for the system's lifecycle.
  • Transparency to deployers — stated purpose, known limitations and required human oversight.
  • Registration in the EU database before the system is placed on the market.

The Digital Omnibus moved the deadline for standalone Annex III systems to 2 December 2027, pending formal adoption. That is more runway, not a repeal.

What to build now, irrespective of dates

Almost everything the Act asks for is something a well-run AI system should have anyway. Building it now costs little and removes the deadline scramble:

  • An inventory. Which AI systems exist, what each does, whose data it touches, which model version is in production. Most organisations cannot answer this today.
  • Traceable logs. Inputs, outputs, model version and the human decisions layered on top, retained and queryable.
  • Documented data provenance. Where training and evaluation data came from and what rights attach to it.
  • A stated human-oversight mechanism. Not a paragraph in a policy — an actual point where a person can review and override, and evidence that it is used.
  • Disclosure in the interface. Cheap to add now, awkward to retrofit across a mature product.

Why non-EU companies are reading this

The Act reaches providers placing systems on the EU market and, in defined circumstances, systems whose output is used in the EU — which is why US companies have been working to the August 2026 date. Geography of incorporation is not the test.

The pragmatic position

Treat the transparency obligations as in force and build them. Treat high-risk classification as a question to answer deliberately with counsel rather than assume away. And build the inventory and the logs regardless, because every framework that follows this one will ask for the same things.

Frequently Asked Questions

Does the Act apply if my company is not in the EU?

It can. The Act reaches providers placing AI systems on the EU market and certain uses whose output is used in the EU. Where you are incorporated is not the deciding factor.

Was the August 2026 deadline cancelled?

No. Article 50 transparency obligations took effect, with content-labelling deferred to December 2026. A separate deferral for standalone Annex III systems to December 2027 was still pending formal adoption.

Is a general-purpose chatbot high-risk?

Usually not by itself. Risk classification follows the use case, not the technology — the same model can be minimal-risk in one product and high-risk in another.

References

  1. US Companies Face EU AI Act's Possible August 2026 Compliance DeadlineHolland & Knight
  2. AI Act Update: EU Resolves to Change Rules and Extend DeadlinesLatham & Watkins
  3. EU AI Act Compliance Deadlines: Key Dates and ObligationsJAGGAER
JL

About Jishu Labs

Jishu Labs is a software development company founded in 2016. We build custom software, AI/ML systems, and full-stack web and mobile applications for clients, and we make eight AI tools for software teams.

Related Articles

Security3 min read

What Is Prompt Injection?

Prompt injection is when untrusted text reaching a model's context gets treated as instruction rather than data. It has held OWASP's number one LLM risk slot across every edition, and agents made it materially worse.

Jishu Labs

August 7, 2026

Security3 min read

Model Risk and Audit Trails in Financial Services AI

Financial services has governed models for decades. Generative AI does not escape that framework - it stresses it. What model risk management asks of an LLM feature, and what to instrument.

Jishu Labs

August 4, 2026

Security3 min read

Shipping AI Features Under HIPAA

Adding an LLM to a product that touches protected health information changes who your subprocessors are, what your logs contain, and what you must be able to prove. An engineering view of the constraints.

Jishu Labs

August 3, 2026

Ready to Build Your Next Project?

Let's discuss how our expert team can help bring your vision to life.

AI Tools,
Built
End-to-End

Ready to Get Started?

Get consistent results. Collaborate in real-time.
Build Intelligent Apps. Work with Jishu Labs.

SCHEDULE MY CALL