The August 2026 deadline: what to finish before summer
14 May 2026 · 6 min read

If you run a small team in Europe, one date should be on your calendar: 2 August 2026. That is when the transparency duties of the EU AI Act start to apply, the rules on chatbots and on labelling AI-generated content, which reach many of the businesses using AI day to day. The heavier high-risk obligations were pushed back to 2 December 2027 by the 2026 Digital Omnibus, but August 2026 is still a real deadline and the literacy evidence is already overdue. It sounds far off, but the useful window is smaller than it looks. The sensible target is to be demonstrably ready before the summer, so you are not scrambling in July when half your team is on holiday.
The good news is that for a typical five to fifty person studio, agency or small SaaS, this is not a quarter of work. It is closer to an afternoon of real effort, spread thoughtfully over a few weeks. The trick is sequencing. Do things in the right order and each step feeds the next. Do them at random and you repeat yourself. This piece lays out what actually changes on 2 August 2026, what already applied before it, and a realistic month-by-month plan to get there calmly.
The EU AI Act, formally Regulation (EU) 2024/1689, entered into force on 1 August 2024 and applies in phases. Two obligations have been live for over a year already, and it is worth being clear that they are not new in August 2026.
Since 2 February 2025, two things have applied to everyone, regardless of size:
Then on 2 August 2025, the rules for general-purpose AI models, the governance framework, and the penalty provisions began to apply, and Member States started designating their national authorities.
So what actually changes on 2 August 2026? This is when the transparency duties under Article 50 apply: telling people when they are dealing with a chatbot, and labelling AI-generated or manipulated content. The heavy high-risk obligations under Annex III were originally due on this date too, but the 2026 Digital Omnibus moved them to 2 December 2027. Annex III still covers AI used in areas like employment and worker management, which for a small business is the one to watch: tools that screen CVs, rank candidates, allocate tasks or evaluate staff can fall into the high-risk tier, with duties around human oversight, record-keeping, transparency and risk management. If you use AI in hiring, that is the category to examine first, even though the formal deadline for those Annex III duties is now December 2027.
The dates that matter
A deadline is not a finish line you sprint across at the last second. Being ready a few weeks early buys you three things. First, slack: if one tool turns out to be trickier to classify than expected, you have room to think rather than panic. Second, coverage: training your whole team is much easier in May and June than in the last week of July when people are away. Third, evidence: readiness is not just being compliant, it is being able to show you are compliant. A dated record you finalised in June is a calmer thing to hand to a client or insurer than one stamped 1 August.
Most of you are deployers, not providers. A provider develops an AI system and places it on the market. A deployer uses an AI system under its own authority in a professional context. Almost every small business is a deployer, which means your duties are lighter and more practical than the ones on the toolmakers. The exception worth remembering: if you materially modify a high-risk system or put your own name on it, you can step into provider territory. For the plan below, we assume you are a deployer.
Here is a realistic sequence for a small team. Each block is a short session, not a full week of work. The order matters, because you cannot classify tools you have not listed, and you cannot train people on a policy you have not written.
Start with a simple list of every AI tool your team touches. The writing assistant, the meeting transcriber, the design generator, the support chatbot, the CV screener. For each one, note who uses it and what for. Then classify each against the four risk tiers:
This inventory is the foundation. Almost every later decision points back to it.
With the list classified, deal with the sharp end first. If anything landed in the prohibited tier, stop that use now; this is the one category with no workaround. If anything is high-risk, decide deliberately: do you keep it with the proper safeguards in place, such as human oversight and record-keeping, or do you swap it for something simpler? For most small teams this is a short conversation about one or two tools, not a research project. The point is that the decision is made, written down and dated, rather than left vague.
Article 4 asks for a sufficient level of AI literacy, and it is explicitly proportionate. A designer using an image generator does not need the same training as the person running your hiring pipeline. So train by role. Give each person the understanding they need to use their tools responsibly and to spot the risks, then issue a dated certificate for each. The certificate is not bureaucracy for its own sake. It is the artefact that turns "our team knows what they are doing" into something you can actually show.
Once people are trained, write the short policy that captures how your team uses AI: what is allowed, what is not, where human review is required, and how you handle disclosure for chatbots and generated content. Keep it to a page or two in plain language. Publishing it after training, not before, means it reflects what your team actually learned rather than a guess written in a vacuum.
Finally, pull the pieces together into one dated bundle: the classified inventory, the training certificates, the policy, and a record of the decisions you made along the way. This is the thing you hand to a client during due diligence, to an insurer, to a partner, or to a regulator if they ever ask. Finalise it in July, or better, in June, and the August deadline arrives as a non-event.
Enforcement is national. Each Member State designates its own market surveillance authorities. In the Netherlands, the Autoriteit Persoonsgegevens has taken a coordinating role for algorithm and AI supervision through its algorithm-coordination directorate, working alongside sector regulators and the RDI, and has signalled a focus on transparency and prohibited uses. In Germany, there is no single federal AI authority yet; the Bundesnetzagentur is widely expected to take a central coordinating role alongside the data protection authorities, with the final split set by national legislation. In the meantime German supervisors have emphasised existing data-protection duties.
On penalties, the figures are maximum caps, and for SMEs and startups the fine is the lower of the fixed sum or the percentage of worldwide annual turnover. Prohibited practices carry up to 35 million euro or 7 percent. Other obligations, including high-risk and transparency duties, carry up to 15 million euro or 3 percent. Supplying incorrect or misleading information to authorities carries up to 7.5 million euro or 1 percent. These are ceilings, not expected outcomes for a small studio, and they are best read as a reason to keep your evidence tidy rather than a reason to lose sleep.
Notice what the plan is really building: four artefacts that turn "we tried" into "we can show it". A risk-classified tool inventory, role-based training with dated certificates, an AI usage policy, and a dated compliance record. That is the shape of readiness for a deployer, and it is well within reach for a small team working a few weeks ahead of the deadline.
This is exactly the sequence Klaar is built to walk you through, keeping the inventory, certificates, policy and record in one place so the export at the end is a click rather than a chore. Whether you use a tool or a spreadsheet, the sequencing is the same: list, classify, resolve, train, publish, export. Start in spring, work in short sessions, and 2 August 2026 becomes a date you have already prepared for rather than one that catches you out.
Klaar walks you through inventory, training, policy and the dated evidence.