Connect with us

Hi, what are you looking for?

Technology

What Startups Need to Do Before the EU AI Act’s August 2 Deadline?

What Startups Need to Do Before the EU AI Act’s August 2 Deadline?

EU AI Act August 2 Deadline: What Startups Must Know

Only a few days remain until the EU AI Act deadline of August 2nd, and the deadline itself has emerged as the most misunderstood date within AI regulations. Founders expect that August 2nd, 2026 is the date when the EU AI Act will “come into effect.” This is not true. A number of duties prescribed by the act became effective months ago – certain prohibited AI operations and requirements for general purpose AI models became enforceable before the deadline was even set out. The August 2nd deadline includes less obligations than what many people think it does.

Consult our AI startup legal compliance attorneys today. 

In a nutshell, the deadline was shortened, not extended. On June 16, 2026, the Digital Omnibus amendments were approved by the European Parliament, receiving 423 votes for, 57 against, and 174 abstained. The Council officially adopted the text on June 29, 2026, and it entered into force on July 27, 2026, as Regulation (EU) 2026/1744. Accordingly, the deadline for the obligations of High-Risk AI systems according to Article 6 and Annex III was postponed from August 2, 2026, till December 2, 2027. As for product-embedded High-Risk AI systems listed in Annex I, such as AI in medical devices and machinery, the deadline was even more postponed – till August 2, 2028.

Amendments, which were not postponed, concern practically all startups using AI for EU users: Article 50 transparency obligations and GPAI models’ rules enforcement.

AI Risk Categories Every Startup Should Know

The risks, rather than the founder’s objective, determine the obligations. It should be mentioned that this rule has not undergone any changes despite the June amendments, and there has been no change except for the schedule for the particular risk.

Prohibited AI Practices Remain in Force

Article 5’s prohibitions became effective from February 2, 2025, and are still enforceable to this day. Such prohibitions relate to real-time biometric processing in publicly accessible environments, social scoring mechanisms, and dark pattern AI – AI purposely designed to manipulate users. With the adoption of the June amendments, there was another prohibition added under Article 5 of the Act, related to AI systems that generate and modify non-consensual intimate visual representations and CSAMs, and it will take effect on December 2, 2026.

High-Risk Systems Under Annex III

Article 6 and Annex III high-risk systems fit into eight types of applications: employment, education, credit and essential services, biometrics, critical infrastructure, law enforcement, migration, and judicial applications. The AI-powered resume screening service for recruitment, a credit decision-making algorithm at a fintech firm, and an automatic scoring tool for admissions purposes are the most obvious examples of use cases that founders think are relevant to their systems – but as of June, they are not yet. Individual obligations for high-risk systems now last until December 2, 2027, which is considerable time, not an excuse to procrastinate because technical requirements, upon which these obligations are based, are not fully determined yet.

A simple check whether the risk is high or not: Is your system’s output used in making an important decision on a person? Is it related to credit, employment, admission or other similar decision? Is the system processing biometric data or making decisions regarding critical infrastructure and healthcare? If yes, then the system belongs to Article 6 and Annex III, even though the final determination will depend on the criteria in the regulation rather than on marketing of the product.

Limited-Risk Transparency Obligations

It is Article 50 transparency obligations that make most startups nervous about exposure to liability issues, with the general compliance deadline of August 2, 2026 being separate from that of the Omnibus regulation itself which goes into effect on July 27, 2026. Let us take an example of an AI-based customer support tool used on the SaaS website: according to Article 50(1) obligation, it should inform users that they are talking to AI in an understandable and timely way before or during such interactions. Such obligations do not depend on whether any subsequent editing by humans takes place. It is impossible to hide such obligations within terms of use.

In addition, according to Article 50(2) and (3), systems that produce any imagery, audio, and video, including marketing images created via GPT-4o or Midjourney, are required to provide machine-readable marking of this information. As far as visible labeling of AI-generated text is concerned, it is narrower and applies to the publication of text on public interest issues and it has several exceptions, including those cases when some natural/legal person assumes editorial responsibility of content following the human review process. Content associated with actual people and events requires additional labeling.

 

GPAI Compliance for Foundation Model Users

Requirements for GPAI compliance from the side of the providers of foundation models have been effective since August 2025. What happens on August 2, 2026, is the enforcement teeth, as the Commission will gain the ability to demand information and model access and impose corrective actions or restrictions on the use of the model when it is used by the non-compliant provider.

Here comes into play the importance of the role distinction, when the startup using GPT-4o, Claude, Llama or Mistral by API becomes the downstream deployer but not the provider of GPAI, therefore not being obliged to the requirements for the provider, however having the risk of restriction or removal of the used model from the EU market.

AI Legal Requirements for U.S. Startups Serving EU Users

Yes, and neither do the June amendments take this into account. The regulation deals with the question of whether the application of the AI system falls under its jurisdiction rather than the one under which the firm operates. This implies that even when the firm is based in the United States and does not have any operations in Europe, the firm becomes subject to regulations when it starts addressing questions posed by an individual from Berlin.

There are practical issues for firms regarding the territorial jurisdiction of the regulation. For example, it would be necessary to have an authorized representative for the High-Risk systems operating in the European Union.

AI Act Compliance Checklist for Startup Governance

As far as the operational compliance checklist is concerned, it is crucial to ensure that all surfaces that were exposed to EU users owing to the AI presence are included there, including chat on websites, in-app assistants, voice agents, and advertising generation, and to assume that this checklist is incomplete since even testing of an unapproved chatbot by the QA team becomes the ground for compliance requirements despite the lack of knowledge of the leadership regarding this issue. In the case of chatbots, the disclosure of AI needs to occur right during the conversation rather than in the form of a footnote.

It is necessary to mention the fact that the text that was created using AI and reviewed by the human editor is not covered by Article 50(4) since the editor is a known person. Finally, it is important to classify all of the systems into corresponding groups and to document this procedure for all of the systems, even the ones classified as minimal risk since reasoning will always prove to be helpful in cases of regulator’s questions. High Risk Roadmap also needs to be updated by December 2027.

Penalties and AI Startup Legal Compliance Costs

Penalties for breach of Article 5 can amount up to €35 million or 7% of worldwide turnover, depending upon the prohibited use that cannot be satisfied once the prohibition kicks in. High Risk Violation of Annex III, which will come into force on December 2, 2027, entails penalties of up to €15 million or 3% of worldwide turnover for any usage related to recruitment, credit, education, and biometric application. Violation of Article 50, for example, non-transparency with respect to hidden chatbots, hidden AI content, and deepfakes without proper labeling, carry the same upper cap too.

These amounts are statutory caps rather than automatic outcomes of the violation and will vary depending upon the nature of the violation and the specific provision being breached. Some statutory exemption for startups from statutory obligations comes in the form of reduced upper cap for penalties.

Why This Matters for Founders Building a U.S. Case

One more group which is frequently ignored by compliance guidelines is the group of founders whose experience with development included relocation to or expansion into the US. If you are currently engaged in the preparation of your O-1A, EB-1A or EB-2 NIW applications, then you have to consider your efforts with regards to governance, classification and documentation, as evidence of your involvement in the creation of the infrastructure of compliance as a leader.  It should be discussed with your immigration attorney from the very start, since it will complement rather than replace legal compliance.

The most efficient resource that you can create now is a registry of your AI systems which must include such information about each of the systems: name, purpose, provider, date of deployment, risk classification and the person who performed it. If you are working with high-risk or GPAI systems, then evidence should also be added to the registry.

Building AI products for global users? Speak with Silicon Path Law to develop an AI compliance strategy before regulatory risks impact your business. 







Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

You May Also Like