The EU AI Act's August 2, 2026 deadline: what actually changes

A risk-tiered answer for Dutch SMEs · Orellis

August 2, 2026 is now a transparency deadline. The Article 50 disclosure rules apply that day: if your AI talks to people or generates content, you generally have to say so. The stricter high-risk obligations (human oversight, logging) for uses like hiring or credit decisions were pushed to December 2, 2027 by the EU's Digital Omnibus, adopted in June 2026. Most back-office automation was never high-risk anyway, but confirm your tier with counsel.

That date marks when the transparency duties in Article 50 of the EU AI Act, Regulation (EU) 2024/1689, become applicable across the EU. It used to mark the start of the high-risk obligations in Annex III too, but the EU's Digital Omnibus on AI, adopted in June 2026, moved those to December 2, 2027. For a Dutch SME already using AI in day-to-day operations, some part of the Act almost always applies. The real question is which part reaches into what you actually do, and when.

What actually changes on August 2, 2026

Until recently this deadline carried two very different obligations. The Digital Omnibus separated them. The Article 50 transparency rules still apply on August 2, 2026. The Annex III high-risk obligations now apply from December 2, 2027, so the two halves of the old deadline sit more than a year apart.

Article 50: transparency, broadlyApplies to most AI deployments that interact with people or generate content: chatbots must disclose they're AI, synthetic audio, image, video, or text has to be marked as AI-generated in specific contexts, and deepfakes get labeled. This is the part that lands on August 2, 2026, and it catches a lot of ordinary AI use. Content marking for systems already on the market has a short grace period to December 2, 2026.
Annex III: high-risk, narrowlyApplies only if your AI use falls into a specific listed category: most relevantly for SMEs, decisions about someone's employment or creditworthiness. Human oversight, a risk management system, and logging become mandatory for those uses from December 2, 2027, after the Digital Omnibus postponed them from the original 2026 date. Most simple back-office automation (document assembly, data structuring) sits outside this list entirely.
DateWhat applies
Feb 2, 2025Prohibited AI practices (Article 5) banned; AI literacy obligations begin
Aug 2, 2025General-purpose AI model obligations and penalties apply; governance and enforcement structure in place
Aug 2, 2026Article 50 transparency obligations apply; content-marking grace period runs to Dec 2, 2026
Dec 2, 2027Annex III high-risk obligations apply, postponed from Aug 2, 2026 by the Digital Omnibus
Aug 2, 2028Deadline for high-risk AI embedded in products already regulated by sectoral EU law (Annex I), postponed from Aug 2, 2027

Why this page reads differently now. The Digital Omnibus postponed the high-risk obligations to December 2, 2027 and kept the transparency duties on August 2, 2026. We update these pages when the law moves, so the date you plan around is the one that actually applies.

Which tier are you in? A five-question self-check

None of this replaces a legal read of your specific setup. But most SMEs can get a rough read on where they sit by asking five questions.

  1. Does the AI-assisted output help decide something about a specific person's employment, such as hiring, promotion, task allocation, performance monitoring, or termination? If yes, you're likely inside Annex III's employment category. Look closer.
  2. Does it help decide someone's creditworthiness, a credit score, an insurance risk price, or eligibility for a public benefit? If yes, you're likely inside Annex III's essential-services category. Look closer.
  3. Does your AI system talk to people directly, through a chatbot, a voice assistant, or a client-facing message thread? If yes, Article 50 disclosure applies regardless of your Annex III answer.
  4. Does it generate or edit audio, image, video, or text that could pass as human-made, especially anything published or sent externally? If yes, check the labeling requirement under Article 50.
  5. Is what you're actually doing document assembly, data structuring, or internal admin: drafts a named person reviews before anything is sent or filed? If yes, you're likely in the lower-obligation tier. "Likely" is not "confirmed." That confirmation is your legal counsel's call, not a vendor's.

What this looks like in practice

A logistics office that uses AI to draft a customs declaration for a named reviewer to check before filing is assembling a document, not deciding anything about a person's employment or credit. That use sits outside Annex III, though if the same office runs an AI chat widget for client questions, Article 50's disclosure rule still applies to that widget.

The same office's AI-assisted candidate-screening tool is a different case: if it ranks or filters applicants before a human sees them, that use is squarely inside the employment category of Annex III, and the human-oversight and logging obligations apply from December 2, 2027 regardless of how small the company is, after the Digital Omnibus moved that date back from 2026.

The questions you'd ask first

What changes on August 2, 2026?

As of the EU's Digital Omnibus on AI, adopted in June 2026, August 2, 2026 is the day the Article 50 transparency rules become enforceable. If your AI interacts directly with people or generates content, you generally have to disclose that. Content marking for systems already on the market has a grace period to December 2, 2026. The Annex III high-risk obligations (human oversight, risk management, logging) were postponed to December 2, 2027, so they are no longer part of the August 2, 2026 deadline. Most SME back-office automation sits outside Annex III in any case.

Does the EU AI Act apply to my SME?

In some form, almost certainly yes, but the obligations scale with what the AI actually does, not with your company size. If you use AI to draft documents, structure data, or automate admin that a person then reviews, you're likely in the lower-obligation tier. If AI output feeds directly into a decision about hiring, firing, promoting, or extending credit to a specific person, look closer. That's where Annex III can apply, and those obligations now start on December 2, 2027 rather than in 2026. Your legal counsel should confirm which tier your specific use falls into.

What is Article 50 transparency, and do we need to do anything?

Article 50 requires that people are told when they're interacting with an AI system, unless that's obvious, and that AI-generated or AI-manipulated content (audio, image, video, text) is marked as such in specific contexts, including deepfakes and text published on matters of public interest. If your business runs an AI chatbot, sends AI-assisted client communication, or publishes AI-drafted content, this is the provision to check first, and most of it applies from August 2, 2026, with a grace period to December 2, 2026 for content marking on systems already in use. We're set up to disclose AI involvement on every AI-assisted output we build, regardless of which Annex III tier a client sits in.

What counts as "high-risk" under Annex III?

Annex III lists specific categories: biometric identification, critical infrastructure, education and vocational training, employment (recruitment, and decisions on promotion, termination, or task allocation), access to essential services (creditworthiness and credit scoring, life and health insurance risk pricing, eligibility for public benefits), law enforcement, migration and border control, and the administration of justice. For a typical Dutch SME, the employment and credit-scoring categories are the ones worth checking first. Customs paperwork, translation admin, and CRM status updates are not on this list. These obligations now take effect on December 2, 2027, after the Digital Omnibus postponed them from the original August 2, 2026 date.

We use AI to help screen job candidates or assess credit risk. Are we automatically high-risk?

If AI output materially shapes a decision about a specific person's employment or creditworthiness, that use sits inside Annex III, and the human oversight, risk management, and logging obligations apply from December 2, 2027, the new date set by the Digital Omnibus. The AI use can continue. The workflow needs a documented human reviewer, a risk assessment, and a record of every output. That's the structure a properly built human-in-the-loop workflow already has. If the same tool talks to candidates directly, the Article 50 disclosure duty still applies from August 2, 2026. Confirm the specific classification with your legal counsel.

Is Orellis's own work affected by this?

The workflows we build are already designed with the controls the higher tiers require: a named human reviews every draft before it's sent, every prompt and output is logged, and the system is built to disclose AI involvement rather than hide it. That's true whether or not a specific client's use case sits inside Annex III. Being a client is a head start on this deadline regardless of which tier applies to your case, but the tier decision itself is your counsel's call, not ours.

Where this page can't answer for you

The honest version of this page has to say plainly what it cannot determine.

Which Annex III category, if any, applies to your exact workflow

That depends on the specific mechanics of what the AI does and how much weight its output carries in the final decision. Only your legal counsel can assess those details against your actual system, not a general framework on a page like this one.

Borderline cases

Some uses sit in a gray zone: an AI-drafted performance note that a manager edits and owns, for instance, versus an AI ranking system that pre-filters candidates before a human sees them. Regulatory guidance on exactly where these lines fall is still being published by the European Commission and Dutch authorities. We won't pretend more clarity exists than currently does.

Whether you need a formal Annex III risk assessment

If your legal counsel determines a use is high-risk, the risk management, logging, and human-oversight documentation has specific requirements we are not qualified to certify. We can build the workflow to meet documented requirements; we cannot tell you that it does without your counsel's sign-off.

This is an operational framing, not legal advice. Whether your AI use falls under Annex III, and what Article 50 requires for your specific system, depends on your setup and is a determination for your legal counsel, not for this page or for Orellis. We document the design decisions; your counsel confirms the classification.

How Orellis approaches it

We build the draft step, never the send step, into every workflow we design. A named person reviews before anything is filed or sent. Every prompt and output is logged, so there's a written record of how something was produced. And we disclose AI involvement on what we build rather than hide it. Those are exactly the controls Annex III asks for when it applies, and exactly the disclosure Article 50 asks for when it applies, so being a client is a head start on this deadline no matter which tier your use turns out to be in. The tier itself is still your counsel's call.

We review everything that ships. This page was drafted with our own AI stack and reviewed by a human before it shipped.

Find out where your AI use actually sits

Tell us what the workflow does and we'll tell you honestly what August 2 changes for it, and what it doesn't. We won't ask for system access or your data, and a person will read what you send and reply.

Tell us where the time goes or book a free audit