Skip to content
Skip to article text

EU AI Act in Germany: What Changed for Companies on 2 August 2026

Modern German office desk with a glowing AI interface beside official EU and German regulation documents

Why 2 August 2026 matters for companies in Germany right now

Since 2 August 2026, the EU AI Act — Regulation (EU) 2024/1689, officially the "Artificial Intelligence Act" — has been generally applicable. This is the third and largest step in a staggered rollout: after the prohibited practices and the AI literacy duty (February 2025) and the rules for general-purpose AI models (August 2025), most of the remaining provisions now apply — including transparency duties and the full sanctions regime.

Regulatory duties belong in your risk inventory — like cyber attacks on SMBs. Shortly before the deadline, the EU postponed key deadlines for high-risk systems through the so-called "Digital Omnibus" Regulation (EU) 2026/1744. Public perception mostly took away one — misleading — message: that regulation as a whole arrived later. In fact, the postponement changes nothing about the general date of application. For most mid-market companies, start-ups and solo entrepreneurs, the relevant question is therefore not whether they are affected at all, but which of the three parallel legal instruments concretely apply to them.

What actually took effect on 2 August 2026 — and what did not

Three legal instruments interact at this deadline, and it is worth separating them clearly:

Instrument Status Meaning
Regulation (EU) 2024/1689 ("AI Act") Generally applicable since 2.8.2026 Core regulation: prohibitions, obligations, penalties
Regulation (EU) 2026/1744 ("Digital Omnibus") In force since 27.7.2026 Postpones high-risk deadlines, adds new prohibitions
KI-MIG (German implementation act) In force since 29.7.2026 Sets authority structure and penalty procedure for Germany

Not postponed, and fully enforceable since 2 August 2026: the transparency duties under Art. 50, the entire sanctions regime under Art. 99, and active enforcement of general-purpose AI model obligations by the EU AI Office. Only the substantive requirements for high-risk AI systems under Chapter III — risk management, data governance, technical documentation, conformity assessment, CE marking — were postponed.

Which transparency duties now apply to chatbots and AI content

Art. 50 of the AI Act has the broadest practical reach because it does not depend on a risk classification, but on how a system is used. A customer-service chatbot, an AI-generated marketing video or an automatically produced article are enough to fall within scope.

  • Interaction disclosure: AI systems designed to interact directly with people must make it recognisable that this is AI — unless this is obvious from the circumstances.
  • Deepfake labelling: AI-generated or manipulated image, audio or video content that convincingly depicts real people or events must be disclosed as artificially generated.
  • Labelling of certain AI text: Published AI-generated text on matters of public interest requires disclosure, unless it is under human editorial control and responsibility.
  • Disclosure for emotion recognition or biometric categorisation: Companies using such systems, for example to evaluate customer reactions, must inform the affected individuals.

A special rule applies to machine-readable marking of synthetic content (watermarks, metadata): for systems already in use before 2 August 2026, a shorter separate transition period runs until 2 December 2026 — a date frequently overlooked in public debate.

Who enforces the AI Act in Germany: the Bundesnetzagentur's role

Germany missed the EU's original deadline for designating national authorities (2 August 2025). Only on 29 July 2026 did the national implementation act — the AI Market Surveillance and Innovation Promotion Act (KI-MIG) — enter into force. It designates the Bundesnetzagentur (Federal Network Agency) as the central body:

  • Market surveillance authority for all areas not otherwise assigned, particularly AI systems in sensitive fields such as workforce management, critical infrastructure and education
  • Single point of contact for AI Act questions, including a dedicated AI service desk for businesses
  • Central complaints office — competitors and private individuals alike can report suspected violations
  • Host of a Coordination and Competence Centre and at least one AI regulatory sandbox with priority access for SMEs and start-ups

Established jurisdiction in already-regulated sectors remains in place: BaFin oversees AI in the financial sector, BfArM oversees AI as medical devices. For particularly sensitive high-risk use cases — such as real-time biometric identification in law enforcement — an independent AI Market Surveillance Chamber was set up within the Bundesnetzagentur, operating free of instructions.

What fines companies now need to plan for

As of 2 August 2026, the three-tier sanctions regime under Art. 99 of the AI Act is no longer theoretical — it is enforceable:

Violation Fine range
Prohibited AI practices (Art. 5) up to €35m or 7% of global annual turnover
Other obligations (incl. high-risk requirements, transparency) up to €15m or 3% of global annual turnover
False or misleading information to authorities up to €7.5m or 1% of global annual turnover
SMEs and start-ups the lower of the amount and the percentage applies

The SME relief sounds more comforting than it is: for a company with €5m in annual turnover, 3% is already €150,000. In addition, the KI-MIG sets separate fines of up to €50,000 for specific administrative offences — for example, failing to provide required explanations to affected individuals for certain high-risk systems. Not "only tech giants face the big fines" — rather, every company that provides or deploys AI systems falls within scope in principle.

What the Digital Omnibus postponed — and what it did not

The postponement under Regulation (EU) 2026/1744 affects only Chapter III of the AI Act — the obligations for high-risk AI systems:

  • Annex III (standalone systems): new deadline 2 December 2027 instead of the original 2 August 2026 — 16 months more. Covers AI in employment contexts (candidate screening, promotion, dismissal decisions), creditworthiness assessment, education and critical infrastructure.
  • Annex I (AI embedded in products): new deadline 2 August 2028 — for example AI as a safety component in medical devices, machinery or lifts.
  • New prohibited practices from 2 December 2026: AI systems generating non-consensual intimate imagery or child sexual abuse material are additionally banned.

What does not change: the prohibitions under Art. 5 in their existing form, the AI literacy duty and the general-purpose AI model obligations remain in force unchanged since 2025. The substantive requirements for high-risk systems themselves are not relaxed by the Omnibus — only the timing was moved. According to recital 40 of the amending regulation, the reason is delayed standards, guidance and the delayed establishment of national authorities across several member states — a pattern reflected in Germany's own delayed KI-MIG.

Practical checklist: what companies should do now

  • Map your AI inventory: list all AI systems and tools in use — including applications individual departments introduced on their own.
  • Clarify your role: for each system, is your company a provider or a deployer? Do Art. 50 transparency duties apply?
  • Implement transparency notices: equip chatbots with a recognisable AI disclosure, label AI-generated content, and assign internal responsibility.
  • Document AI literacy: train staff who work with AI systems and keep verifiable records of participation.
  • Check legacy systems: did you place a system generating synthetic content on the market before 2 August 2026? Then the machine-readable labelling deadline already falls on 2 December 2026.
  • Identify high-risk candidates early: HR is often underestimated — automated candidate pre-screening tools can become high-risk systems.

These six steps can be completed within a few weeks — provided someone in the company takes ownership, rather than assuming "IT already has it covered."

How the AI Act connects to NIS2 and other obligations

Both instruments require similar building blocks — governance structures, documented risk assessment, and demonstrable compliance towards regulators and customers — but address different areas: NIS2 targets the organisation's cybersecurity, the AI Act targets the actual use of AI systems — see also AI and Risk Management: People First. Companies affected by both should think of their register, training records and reporting channels together rather than building two separate compliance silos. This links back to the question raised in our article on AI agents in business: who is accountable when a system — chatbot or agent — makes a mistake? Our introduction to risk management covers the underlying principle.

Conclusion: Take regulation seriously without falling into panic mode

2 August 2026 is not a date you can dismiss by pointing to the postponed high-risk deadlines — nor is it a reason for panic. Transparency duties, the oversight structure and the sanctions regime are real as of now, regardless of whether your company will ever operate a "high-risk system." Companies that know their AI inventory, clarify roles and retrofit disclosures now have completed the manageable part of the task — and can use the extended deadlines through 2027 for what they are: preparation time, not a postponement of the work.

Next step: Pick one AI system already running in your company — chatbot, text generator or HR tool — and answer for that single system: provider or deployer, transparency duty yes or no? That is more concrete than any general announcement.

This article does not replace legal, tax or insurance advice. The classification of a specific AI system — in particular whether it falls under Annex III of the AI Act — depends on the individual case and should be reviewed by a qualified lawyer, for example from the RisikoRadar network.

This text was created with AI assistance and editorially reviewed.

Frequently asked questions

Does the EU AI Act still apply from 2 August 2026 despite the deadline extension?

Yes. Only the obligations for high-risk AI systems were postponed. The Act itself, the transparency duties under Art. 50 and the sanctions regime have applied unchanged since 2 August 2026.

Does the AI Act affect small companies that only use ChatGPT?

Usually yes. Any company using AI tools in daily work counts as a deployer under the Act — which already triggers the AI literacy duty under Art. 4, in force since February 2025.

What fines can companies face under the AI Act?

Up to €35m or 7% of global annual turnover for prohibited practices, and up to €15m or 3% for other violations. SMEs and start-ups benefit from the lower of the two values.

Which authority enforces the AI Act in Germany?

Since the KI-MIG entered into force on 29 July 2026, the Bundesnetzagentur (Federal Network Agency) is the central market surveillance authority, single point of contact and complaints office. Sector regulators such as BaFin retain jurisdiction in regulated fields.

Does our website chatbot now need an AI disclosure?

An AI system designed to interact directly with people must make clear that users are interacting with AI, unless this is obvious from the context. Check this with your chatbot provider.

What exactly was postponed, and until when?

High-risk obligations for standalone systems (Annex III, e.g. candidate screening) now apply from 2 December 2027; for AI embedded in products (Annex I) from 2 August 2028.

Does this article replace a legal assessment of our AI use?

No. Whether a specific system qualifies as high-risk AI depends on the individual case. This article summarises the public legal status — for your specific situation we recommend a qualified lawyer.

Clarify risks in your business?

Book a free intro call – 30 minutes, no obligation.

Book a free intro call