2 August 2026 was meant to be the AI Act's "D-day": full application of the high-risk obligations. That is no longer the plan. Regulation (EU) 2026/1744 (the AI Digital Omnibus), published in the EU Official Journal on 24 July 2026 and in force since 27 July, has redrawn the timeline. The question to answer first is twofold: what was postponed, and what still starts on 2 August? The short answer: high risk slips, but transparency, supervision and penalties genuinely begin.
The new timeline after Regulation EU 2026/1744
The Digital Omnibus amends Regulation (EU) 2024/1689 without touching its structure: risk categories, prohibitions and penalty tiers stay as they were. What changes are the application dates of the high-risk obligations.
| Date | What applies |
|---|---|
| 2 February 2025 | Bans on unacceptable-risk practices (Art. 5) and AI literacy (Art. 4) — already in force |
| 2 August 2025 | Rules on general-purpose AI (GPAI) models, governance and the penalties framework |
| 2 August 2026 | Transparency (Art. 50) for systems placed on the market from this date; supervision and penalties fully operational; national regulatory sandboxes up and running |
| 2 December 2026 | Content marking for generative systems already on the market before 2 August 2026; new prohibitions on non-consensual intimate material and child sexual abuse material |
| 2 December 2027 | Obligations for stand-alone high-risk systems under Annex III (moved from 2 August 2026) |
| 2 August 2028 | Obligations for high-risk systems embedded in regulated products under Annex I (moved from 2 August 2027) |
One detail worth more than the postponement itself: the Commission's initial proposal tied the new dates to the availability of harmonised standards. That mechanism was dropped from the final text: the dates are now unconditional. Counting on a further slip is a bet, not a plan.
What actually starts on 2 August 2026
Three things, all operational:
- Transparency (Art. 50) — whoever places on the market or uses chatbots, emotion recognition systems or synthetic content generators must comply with the information and marking obligations for systems placed from this date (for systems already on the market, content marking kicks in on 2 December 2026).
- Supervision — national market surveillance authorities acquire full powers, and every Member State must have at least one operational regulatory sandbox.
- Penalties — the sanctions framework, applicable on paper since 2 August 2025, becomes fully actionable; from this date the Commission can also fine providers of GPAI models (Art. 101).
In other words: 2 August 2026 does not bring the wave of high-risk obligations — it brings the enforcers.
Penalties: what is at stake
Article 99 of Regulation (EU) 2024/1689 sets three tiers; in each, the higher of the fixed amount and the percentage of worldwide annual turnover applies:
- up to €35 million or 7% — breach of the Art. 5 prohibitions;
- up to €15 million or 3% — breach of the obligations of providers, deployers, importers, distributors and notified bodies, including Art. 50 transparency;
- up to €7.5 million or 1% — incorrect, incomplete or misleading information supplied to authorities.
For SMEs and start-ups the rule flips: the lower of the two amounts applies. When setting a fine, authorities must weigh the gravity and duration of the breach, the operator's size, cooperation and intent: showing up to an inspection with an AI system inventory and an orderly documentation file is not cosmetic — it is a mitigating factor.
Who supervises in Italy: AgID, ACN and the Garante
Italy moved earlier than most Member States with Law no. 132 of 23 September 2025, the national AI law:
- AgID is the notifying authority: it accredits and oversees the bodies charged with verifying the conformity of AI systems, alongside promoting AI development;
- ACN (the National Cybersecurity Agency) is the market surveillance authority, with inspection and sanctioning powers;
- sector regulators (Bank of Italy, Consob, IVASS) and the Garante, the Italian data protection authority, retain their competences: when an AI system processes personal data, the GDPR continues to apply in parallel.
In June 2026 the Council of Ministers gave preliminary approval to the implementing decrees under the law's delegation: they define the authorities' powers and procedures, the national sanctions regime and an Italian sandbox run by AgID and ACN. The process is not finished, but the direction is clear: the enforcement machinery is switching on now.
The postponement is not a pause: what to do now
If your company develops or uses systems likely to qualify as high-risk, the 2027/2028 postponement is usable time, not free time. Three concrete moves:
- Close out what is already mandatory: AI literacy, compliance with the prohibitions, transparency towards users and recipients of generated content.
- Freeze your inventory and classification of the AI systems in use: it is the prerequisite of any plan (we covered it in our SME checklist).
- Plan high-risk compliance backwards from 2 December 2027: risk management systems, data governance, technical documentation and human oversight cannot be improvised in a quarter.
Where to start
The fastest way to find out whether the new timeline gives you slack or takes it away is an independent gap assessment: a snapshot of where you stand against the Regulation and Law 132/2025, with priorities, owners and dates. It is the first step towards facing the authorities — European or Italian — with a plan rather than an excuse.