AIセキュリティ

EU AI Act: What Actually Starts on 2 August 2026 — and Why High-Risk AI Now Lands in December 2027 and August 2028

Published2026-05-20Updated2026-08-02Ryuta Hamamoto

Digital Omnibus is law: Regulation (EU) 2026/1744, adopted 8 July 2026, published in the Official Journal on 24 July 2026 and in force since 27 July 2026.

EU AI Act: What Actually Starts on 2 August 2026 — and Why High-Risk AI Now Lands in December 2027 and August 2028
Share

Hello, this is Ryuta Hamamoto from TIMEWELL.

"EU AI Act goes fully live on 2 August 2026. That's what most executives thought they knew, and right now they are in full confusion." A legal officer at a major manufacturer sent me almost exactly that message.

That reading is not accurate. The amending act — Digital Omnibus on AI, Regulation (EU) 2026/1744 — was adopted on 8 July 2026, published in the Official Journal on 24 July 2026 (OJ L 2026/1744) and entered into force on 27 July 2026. Under it, the highest-impact high-risk AI obligations now land on 2 December 2027 (Annex III type) / 2 August 2028 (Annex I type).

At the same time, Article 113(2) — "It shall apply from 2 August 2026" — was left unamended, and that day has now passed. So 2 August 2026 turned out to be neither a non-event nor the day everything started. It was the day on which what starts and what does not start finally separated. Misread that split and your compliance programme goes sideways.

What the amendment deferred is narrow: Chapter III Sections 1, 2 and 3, excluding Article 6(5). Section 5 of the same chapter — harmonised standards, conformity assessment, CE marking and registration under Articles 40 to 49 — was left where it was and has been running since 2 August. The split runs at section level, which is exactly where the confusion comes from.

Now that the date has passed, here is the confirmed schedule under the adopted amending act, and the concrete work it implies.

TL;DR

  • Digital Omnibus is law: Regulation (EU) 2026/1744 (adopted 8 July 2026 / OJ 24 July 2026 / in force 27 July 2026). Annex III type high-risk AI applies from 2 December 2027; Annex I type from 2 August 2028
  • What starts on 2 August 2026 is Chapter IV (Article 50, transparency), Chapter III Section 5 (harmonised standards, conformity assessment, CE marking, registration), Chapter VI, Chapters VIII–XI, and Article 101 (the Commission's power to fine GPAI providers) — not the substantive high-risk AI duties
  • GPAI model provider duties and the penalty provisions (Articles 99 and 100) have applied since 2 August 2025. Prohibited practices (Article 5) and AI literacy (Article 4) have applied since 2 February 2025
  • The later high-risk dates are the result of harmonised standards and guidance not being ready, not free extra preparation time
  • Japanese companies should start with (1) extraterritorial scope assessment, (2) Authorised Representative appointment, (3) internal governance on an ISO/IEC 42001 backbone

What Regulation (EU) 2026/1744 changed

Honestly, I read this amendment as an industry last-minute compromise. Annex III type high-risk duties were originally designed to fire on 2 August 2026, but CEN/CENELEC JTC 21 draft harmonised standards were still unsettled in Q2 2026 and guidance was incomplete. Practically: "we can impose duties, but no one knows what compliance means."

The main changes to Article 113:

Subject Old schedule After the amendment
Annex III type (stand-alone) high-risk AI — Art. 6(2) 2 August 2026 2 December 2027 (Chapter III Sections 1–3, plus Arts. 22, 25, 26, 27)
Annex I type (product-embedded) high-risk AI — Art. 6(1) 2 August 2027 2 August 2028
General application date — Art. 113(2) 2 August 2026 2 August 2026 (unamended)
Chapter IV (Art. 50, transparency) 2 August 2026 2 August 2026 (unchanged)
Art. 101 (Commission's power to fine GPAI providers) Applies from 2 August 2026
New prohibited practices — Art. 5(1)(ba) non-consensual sexual deepfakes, (bb) CSAM generation, Art. 5(1a) and (1b) New Apply from 2 December 2026
New Art. 111(4) — providers of synthetic-content AI placed on the market before 2 August 2026 New Must comply with Art. 50(2) by 2 December 2026
Transitional rule for high-risk AI already on the market — Art. 111(2) Fixed cut-off date Only if significant changes in their designs are made after Chapter III applies

The 28 April 2026 trilogue stall was not mainly about "moving the dates as such." The fight was conformity-assessment architecture for Annex I type systems: avoiding double certification against sector rules such as medical devices and machinery. As Bird & Bird noted, the deal was less about the headline high-risk dates and more about the organisational design of conformity assessment. Industry burden relief1.

Note that the amendment is already in force — this is not a "pending formal adoption" situation. On 27 July 2026, the date the amending act entered into force, Articles 102–110 of the AI Act (which amend other EU instruments) also became applicable.

AI Security training, taken seriously

A 2-day intensive course fully aligned with OWASP, NIST, ISO/IEC 42001, and METI. Take it as executives, practitioners, or both.

What did not move is the real core

Many Japanese executives misread this part. What moved later is the substantive high-risk AI duties. These five did not.

First, prohibited practices and AI literacy. Chapter I (general provisions, definitions, Article 4 AI literacy) and Chapter II (Article 5, prohibited AI practices) have applied since 2 February 2025. Emotion inference at the workplace (Article 5(1)(f)) is already banned — and it sits in the top penalty tier, 7% of worldwide turnover. Companies that filed this under "later" have in fact been under the obligation since 2 February 2025.

Second, GPAI (general-purpose AI) model provider duties. Chapter V has applied since 2 August 2025: technical documentation, sufficiently detailed training-data summaries, and EU copyright-compliance policies. Models classified as "systemic risk GPAI" also need adversarial testing, incident reporting, cybersecurity, and energy-use tracking.

Third, penalties. Within Chapter XII, Articles 99 and 100 have applied since 2 August 2025. The subtlety worth knowing: within that same chapter, Article 101 alone was excluded and applies from 2 August 2026 — the Commission's power to fine GPAI providers. It is neither "all penalties from 2025" nor "all enforcement from August 2026"; it splits at article level.

Fourth, Article 50 transparency. Chapter IV — machine-readable marking of AI-generated content and related duties — is not listed in any of the exceptions in Article 113(3) as amended. It applies on the general application date, 2 August 2026. What Digital Omnibus changed in Article 50 is paragraph (7) (codes of practice); the substantive duties in paragraphs (1)–(6) were left unamended. You will see this described as "brought forward"; correctly stated, it stayed where it was.

Fifth, the two things that fire on 2 December 2026. The new prohibited practices (Article 5(1)(ba) non-consensual sexual deepfakes, (bb) CSAM generation, and Article 5(1a) and (1b)), and the new Article 111(4) — providers of synthetic-content generation AI placed on the market before 2 August 2026 must comply with Article 50(2) by that date. Article 50 itself does not start on 2 December.

So the AI Act is running with application dates staggered article by article. Reading it as "everything starts on 2 August" and reading it as "high-risk moved to 2027, so there is nothing to do" are both wrong in practice.

Three patterns that catch Japanese companies—self-diagnosis starting points

Article 2 sets extraterritorial reach. Japanese companies typically fall into three patterns.

Pattern 1: Direct product offering on the EU market. An automaker selling driver-assistance AI vehicles in the EU, or a medtech firm offering AI diagnostic software with CE marking. Both are Annex I product-embedded high-risk AI. CMS's extraterritorial guide is explicit: a Japanese automaker selling AI-assisted braking vehicles into a global market that includes the EU is in scope2.

Pattern 2: SaaS/API whose outputs are used in the EU. A Japanese hiring-screen AI sold to EU clients is Annex III (employment). Credit scoring and education assessment AI are the same. "EU subsidiary uses HQ AI" also fits if outputs are generated or used in the EU.

Pattern 3: Deployer role at an EU subsidiary/branch. If an EU entity uses HQ HR AI for employee evaluation, Article 26 Deployer duties apply: FRIA, log retention, and appointment of human oversight staff.

Common to all three is Article 22's Authorised Representative in the EU. Written mandate required; for non-EU providers it is the practical EU doorway. In my experience, more than half of Japanese companies still do not treat this as a "must-prepare" item.

Strategy: ISO/IEC 42001 as the common backbone

Now implementation. With high-risk dates fixed at 2 December 2027 / 2 August 2028, the most rational move is to introduce ISO/IEC 42001 (AIMS) as the common backbone for internal AI governance.

ISO/IEC 42001 was issued in December 2023 as the world's first AI management-system standard. You will find vendor material quoting a "coverage percentage" against EU AI Act high-risk requirements; there is no official mapping table behind those numbers, so this article does not quote one. Where the two overlap in practice, article by article:

EU AI Act article ISO/IEC 42001 mapping
Art. 9 (risk management) Clause 6.1
Art. 10 (data governance) Annex A.7, A.8
Art. 11 (technical documentation) Clause 7.5
Art. 12 (automatic logging) Annex A.6
Art. 13 (transparency / information) Annex A.4, A.9
Art. 14 (human oversight) Annex A.5
Art. 15 (accuracy / robustness) Annex A.7, A.10
Art. 17 (quality management) Clause 8

What ISO/IEC 42001 will never close is the EU-specific gap:

  • FRIA (Art. 27) — no counterpart concept in ISO 42001
  • Conformity assessment (Notified Body) — third-party certification for some high-risk AI
  • EU database registration — EU-only
  • Authorised Representative — EU-only
  • CE-marking integration — product-embedded only

I describe this as "ISO 42001 as the spine, EU-specific requirements as orthotics layered on top." If a Japanese company must also cover the US (NIST AI RMF), Japan (AI Business Guidelines), and Asia (Korea AI Basic Act, Singapore AI Verify), a shared ISO 42001 language makes market overlays far cheaper.

"Only build for the EU AI Act" almost always becomes regret later.

2026–2028 roadmap

Working backwards from the confirmed dates:

  • By 2 August 2026: Extraterritorial scope (which of the three patterns), Authorised Representative shortlist, internal AI inventory, and verification that your Article 50 transparency implementation is in place
  • 2 August 2026: General application date. Chapter IV (Article 50), Chapter III Section 5 (harmonised standards, conformity assessment, CE marking, registration), Chapter VI, Chapters VIII–XI, and Article 101 start applying
  • 2 December 2026: New prohibited practices (non-consensual sexual deepfakes, CSAM generation) start applying. Separately, synthetic-content generation AI placed on the market before 2 August 2026 must comply with Article 50(2) by this date under Article 111(4)
  • First half of 2027: ISO/IEC 42001 certification path (typically 6–12 months)
  • 2 August 2027: Article 111(3) — compliance deadline for GPAI models placed on the market before 2 August 2025
  • Second half of 2027: FRIA ahead of the Annex III type application date, conformity prep, technical documentation, EU database registration
  • 2 December 2027: Chapter III Sections 1–3 apply to Annex III type high-risk AI (Art. 6(2)). Articles 22, 25, 26 and 27 start the same day
  • 2 August 2028: The same applies to Annex I type (product-embedded, Art. 6(1)) high-risk AI
  • 2 August 2030 / 31 December 2030: Article 111(2) (use by public authorities) / Article 111(1) (Annex X large-scale IT systems)

Move on this calendar and you avoid last-minute FRIA / Notified Body panic just before the December 2027 date. Decide "we can start mid-2027" and certification-body capacity becomes a real risk.

One more point on legacy systems: Article 111(2) was amended so that high-risk AI already on the market is caught only where significant changes in their designs are made after Chapter III starts applying. The reference point is no longer a fixed 2 August 2026; it tracks the Chapter III application dates (2 December 2027 / 2 August 2028). Build your product-modification plans around that linkage.

For implementation steps at the 2 August 2026 milestone, see EU AI Act: August 2026 application and five steps. Read with this piece: strategy here, implementation there.

Where WARP SECURITY fits

TIMEWELL's WARP SECURITY covers the EU AI Act, Digital Omnibus, ISO/IEC 42001 crosswalk, and GPAI Code of Practice alongside OWASP LLM Top 10, NIST AI RMF, and METI AI Business Guidelines. A two-day, leadership-and-practitioner curriculum.

Executive track: how to use the runway until the Annex III type date of 2 December 2027; how to choose an Authorised Representative; who owns FRIA decision rights. Decision drills.

Practitioner track: map the 38 Annex A controls in ISO/IEC 42001 to EU AI Act articles and run a gap analysis on your own AI systems, including RAG log design and machine-readable marking for Article 50.

One of five tabletop incidents is "AI Office document request to a GPAI provider. First 72 hours." It forces legal, IT, comms, and leadership to set RACI in the same room. You cannot learn that from reading alone.

How to use the phrase "general application date"

A post-publication update following the adoption of the amending act. 2 August 2026 is the general application date set by Article 113(2). It is not "full application" and not "fully in force." From that date the Commission can exercise its supervision and enforcement powers over GPAI providers (Article 101), with GPAI-related sanctions of up to €15 million or 3% of worldwide turnover, whichever is higher (Regulatory framework on AI (European Commission)).

The substantive high-risk AI duties, however, do not start on that date — and a striking amount of material, inside and outside Japan, blurs the two. When you write an internal briefing, separate "what starts on 2 August 2026," "what starts on 2 December 2026," and "what starts on 2 December 2027 / 2 August 2028."

Domestically, the 2026 Personal Information Protection Act amendment, including AI training data use, is also moving. Dual EU and Japan readiness is more necessary, not less.

Key takeaways

  • Digital Omnibus is law as Regulation (EU) 2026/1744. High-risk AI applies from 2 December 2027 (Annex III type) and 2 August 2028 (Annex I type)
  • What starts on 2 August 2026 is Chapter IV (Article 50, transparency), Chapter III Section 5, Chapter VI, Chapters VIII–XI and Article 101 — not the substantive high-risk duties
  • Article 50 was not "brought forward to 2 December 2026"; it stayed on 2 August 2026. What fires on 2 December 2026 is the new prohibited practices plus the Article 111(4) deadline for existing systems
  • Prohibited practices (Article 5) have applied since 2 February 2025; GPAI duties and penalties (Articles 99 and 100) since 2 August 2025
  • Start with extraterritorial scope / Authorised Representative / ISO/IEC 42001 gap analysis

Treat the EU AI Act as a wall of "regulation," or as a chance to align internal AI governance with international standards. Post-2028 competitiveness will fork here. Companies that read the later dates as "grace" and those that read them as "last window before standards harden" will not close that gap in three years.

References

Footnotes

  1. Digital Omnibus on AI Trilogue Stalls - Bird & Bird

  2. Guide to the EU AI Act for Businesses Outside the EU - CMS

This article was produced with the help of AI. A human verified the primary sources and edited the text before publication.

How well do you understand AI?

Take our free 5-minute assessment covering 7 areas from AI comprehension to security awareness.

Share this article if you found it useful

Share

Newsletter

Get the latest AI and DX insights delivered weekly

Your email will only be used for newsletter delivery.

Make AI security a skill your team actually has

WARP SECURITY is a two-day intensive aligned with OWASP, NIST, ISO/IEC 42001, and METI guidelines. Executives and practitioners can attend separately.

Related Articles