Why 2 August 2026 matters for companies in Germany right now
Since 2 August 2026, the EU AI Act — Regulation (EU) 2024/1689, officially the "Artificial Intelligence Act" — has been generally applicable. This is the third and largest step in a staggered rollout: after the prohibited practices and the AI literacy duty (February 2025) and the rules for general-purpose AI models (August 2025), most of the remaining provisions now apply — including transparency duties and the full sanctions regime.
Regulatory duties belong in your risk inventory — like cyber attacks on SMBs. Shortly before the deadline, the EU postponed key deadlines for high-risk systems through the so-called "Digital Omnibus" Regulation (EU) 2026/1744. Public perception mostly took away one — misleading — message: that regulation as a whole arrived later. In fact, the postponement changes nothing about the general date of application. For most mid-market companies, start-ups and solo entrepreneurs, the relevant question is therefore not whether they are affected at all, but which of the three parallel legal instruments concretely apply to them.
What actually took effect on 2 August 2026 — and what did not
Three legal instruments interact at this deadline, and it is worth separating them clearly:
| Instrument | Status | Meaning |
|---|---|---|
| Regulation (EU) 2024/1689 ("AI Act") | Generally applicable since 2.8.2026 | Core regulation: prohibitions, obligations, penalties |
| Regulation (EU) 2026/1744 ("Digital Omnibus") | In force since 27.7.2026 | Postpones high-risk deadlines, adds new prohibitions |
| KI-MIG (German implementation act) | In force since 29.7.2026 | Sets authority structure and penalty procedure for Germany |
Not postponed, and fully enforceable since 2 August 2026: the transparency duties under Art. 50, the entire sanctions regime under Art. 99, and active enforcement of general-purpose AI model obligations by the EU AI Office. Only the substantive requirements for high-risk AI systems under Chapter III — risk management, data governance, technical documentation, conformity assessment, CE marking — were postponed.
Which transparency duties now apply to chatbots and AI content
Art. 50 of the AI Act has the broadest practical reach because it does not depend on a risk classification, but on how a system is used. A customer-service chatbot, an AI-generated marketing video or an automatically produced article are enough to fall within scope.
- Interaction disclosure: AI systems designed to interact directly with people must make it recognisable that this is AI — unless this is obvious from the circumstances.
- Deepfake labelling: AI-generated or manipulated image, audio or video content that convincingly depicts real people or events must be disclosed as artificially generated.
- Labelling of certain AI text: Published AI-generated text on matters of public interest requires disclosure, unless it is under human editorial control and responsibility.
- Disclosure for emotion recognition or biometric categorisation: Companies using such systems, for example to evaluate customer reactions, must inform the affected individuals.
A special rule applies to machine-readable marking of synthetic content (watermarks, metadata): for systems already in use before 2 August 2026, a shorter separate transition period runs until 2 December 2026 — a date frequently overlooked in public debate.
Who enforces the AI Act in Germany: the Bundesnetzagentur's role
Germany missed the EU's original deadline for designating national authorities (2 August 2025). Only on 29 July 2026 did the national implementation act — the AI Market Surveillance and Innovation Promotion Act (KI-MIG) — enter into force. It designates the Bundesnetzagentur (Federal Network Agency) as the central body:
- Market surveillance authority for all areas not otherwise assigned, particularly AI systems in sensitive fields such as workforce management, critical infrastructure and education
- Single point of contact for AI Act questions, including a dedicated AI service desk for businesses
- Central complaints office — competitors and private individuals alike can report suspected violations
- Host of a Coordination and Competence Centre and at least one AI regulatory sandbox with priority access for SMEs and start-ups
Established jurisdiction in already-regulated sectors remains in place: BaFin oversees AI in the financial sector, BfArM oversees AI as medical devices. For particularly sensitive high-risk use cases — such as real-time biometric identification in law enforcement — an independent AI Market Surveillance Chamber was set up within the Bundesnetzagentur, operating free of instructions.
What fines companies now need to plan for
As of 2 August 2026, the three-tier sanctions regime under Art. 99 of the AI Act is no longer theoretical — it is enforceable:
| Violation | Fine range |
|---|---|
| Prohibited AI practices (Art. 5) | up to €35m or 7% of global annual turnover |
| Other obligations (incl. high-risk requirements, transparency) | up to €15m or 3% of global annual turnover |
| False or misleading information to authorities | up to €7.5m or 1% of global annual turnover |
| SMEs and start-ups | the lower of the amount and the percentage applies |
The SME relief sounds more comforting than it is: for a company with €5m in annual turnover, 3% is already €150,000. In addition, the KI-MIG sets separate fines of up to €50,000 for specific administrative offences — for example, failing to provide required explanations to affected individuals for certain high-risk systems. Not "only tech giants face the big fines" — rather, every company that provides or deploys AI systems falls within scope in principle.
What the Digital Omnibus postponed — and what it did not
The postponement under Regulation (EU) 2026/1744 affects only Chapter III of the AI Act — the obligations for high-risk AI systems:
- Annex III (standalone systems): new deadline 2 December 2027 instead of the original 2 August 2026 — 16 months more. Covers AI in employment contexts (candidate screening, promotion, dismissal decisions), creditworthiness assessment, education and critical infrastructure.
- Annex I (AI embedded in products): new deadline 2 August 2028 — for example AI as a safety component in medical devices, machinery or lifts.
- New prohibited practices from 2 December 2026: AI systems generating non-consensual intimate imagery or child sexual abuse material are additionally banned.
What does not change: the prohibitions under Art. 5 in their existing form, the AI literacy duty and the general-purpose AI model obligations remain in force unchanged since 2025. The substantive requirements for high-risk systems themselves are not relaxed by the Omnibus — only the timing was moved. According to recital 40 of the amending regulation, the reason is delayed standards, guidance and the delayed establishment of national authorities across several member states — a pattern reflected in Germany's own delayed KI-MIG.
Practical checklist: what companies should do now
- Map your AI inventory: list all AI systems and tools in use — including applications individual departments introduced on their own.
- Clarify your role: for each system, is your company a provider or a deployer? Do Art. 50 transparency duties apply?
- Implement transparency notices: equip chatbots with a recognisable AI disclosure, label AI-generated content, and assign internal responsibility.
- Document AI literacy: train staff who work with AI systems and keep verifiable records of participation.
- Check legacy systems: did you place a system generating synthetic content on the market before 2 August 2026? Then the machine-readable labelling deadline already falls on 2 December 2026.
- Identify high-risk candidates early: HR is often underestimated — automated candidate pre-screening tools can become high-risk systems.
These six steps can be completed within a few weeks — provided someone in the company takes ownership, rather than assuming "IT already has it covered."
How the AI Act connects to NIS2 and other obligations
Both instruments require similar building blocks — governance structures, documented risk assessment, and demonstrable compliance towards regulators and customers — but address different areas: NIS2 targets the organisation's cybersecurity, the AI Act targets the actual use of AI systems — see also AI and Risk Management: People First. Companies affected by both should think of their register, training records and reporting channels together rather than building two separate compliance silos. This links back to the question raised in our article on AI agents in business: who is accountable when a system — chatbot or agent — makes a mistake? Our introduction to risk management covers the underlying principle.
Conclusion: Take regulation seriously without falling into panic mode
2 August 2026 is not a date you can dismiss by pointing to the postponed high-risk deadlines — nor is it a reason for panic. Transparency duties, the oversight structure and the sanctions regime are real as of now, regardless of whether your company will ever operate a "high-risk system." Companies that know their AI inventory, clarify roles and retrofit disclosures now have completed the manageable part of the task — and can use the extended deadlines through 2027 for what they are: preparation time, not a postponement of the work.
Next step: Pick one AI system already running in your company — chatbot, text generator or HR tool — and answer for that single system: provider or deployer, transparency duty yes or no? That is more concrete than any general announcement.
This article does not replace legal, tax or insurance advice. The classification of a specific AI system — in particular whether it falls under Annex III of the AI Act — depends on the individual case and should be reviewed by a qualified lawyer, for example from the RisikoRadar network.
