RightAgent
Back to Blog

The EU AI Act Rule Actually Live Right Now

Two very different things happened on August 2, 2026: the scary "high-risk" rules got delayed to 2027, but a separate, broader rule that applies to almost every AI agent went live exactly on schedule. Here's what's actually required now.
agentadmin

agentadmin

August 7, 2026

4 min read 4 views
Share:
The EU AI Act Rule Actually Live Right Now

On this page

If you've read anything about "the EU AI Act deadline" this month, there's a good chance it told you one of two things: either that a huge, expensive compliance regime just went live on August 2, 2026, or that the whole thing got delayed and you can stop worrying. Both of those are half right, and believing the wrong half could genuinely cost you. Here's what actually happened.

The scary part got pushed back - but not the part that applies to you

The EU AI Act's toughest rules - the ones for "high-risk" AI systems, covering things like hiring algorithms, credit scoring, and law enforcement tools - did get delayed. A simplification package called the Digital Omnibus pushed those obligations from August 2026 to December 2027 for standalone systems, and August 2028 for AI embedded inside other products. If your agent isn't operating in one of those narrow, explicitly listed high-risk categories, this part genuinely doesn't apply to you yet. But a separate rule - one that applies to nearly every AI agent that talks to a person - did not get delayed. It became enforceable exactly on schedule, on August 2, 2026.

The rule that's actually live: if your agent talks to people, it has to say so

This is Article 50 of the Act, and it's much broader than the high-risk regime - it doesn't care whether your agent is officially classified as "high-risk." It applies to any AI system that does one of four things:

  • Talks directly to a person - a chatbot, a voice assistant, an AI agent handling support or sales

  • Generates content - images, audio, video, or text

  • Performs emotion recognition or biometric categorization

  • Produces deepfakes, or AI-written text published on a matter of public interest

If your agent falls into the first category - and most conversational AI agents do - the requirement is straightforward in principle: users need to be told they're interacting with AI, unless that's already obvious from the context. Generated content in the other categories needs a machine-readable mark showing it's AI-made.

Yes, the fines are real, and they're not small

Violations carry fines up to €15 million or 3% of worldwide annual turnover, whichever is higher - and this applies regardless of where your company is based. If your agent's outputs reach users in the EU, you're in scope, full stop. That's a meaningfully different bar than "we're not an EU company, so this doesn't apply to us." One narrow exception: generative AI systems that were already on the market before August 2, 2026 get until December 2, 2026 specifically for the machine-readable marking requirement - everything else on the obligation list applies immediately, with no grace period.

What to actually check before you deploy (or before you pick an agent)

Whether you're building an agent or deciding which one to use, this is now a real item to check, not a hypothetical:

  • Does the agent disclose it's AI during conversations with EU users? A visible note, a name that doesn't impersonate a human, or a clear statement at the start of a conversation all count - silence does not.

  • Does generated content carry a detectable AI marking? If the agent produces images, audio, video, or written content, check whether that output is machine-readably marked as AI-generated.

  • Is there human review before anything gets published on a public-interest topic? Deepfakes and AI-generated text on public-interest matters carry stricter obligations, including requirements around editorial oversight.

  • Does the vendor's documentation even mention this? If a tool's marketing page and terms make zero mention of EU transparency compliance and its users clearly include EU traffic, that's worth asking about directly before you commit budget to it.

None of this requires a legal team or a six-figure compliance program - the transparency obligations are fundamentally about disclosure, not the heavier certification and risk-assessment machinery reserved for high-risk systems. But "small" doesn't mean "optional." The clearest sign this is being taken seriously: the European Commission published official guidance on these exact rules on July 20, 2026, less than two weeks before enforcement began.

The practical takeaway isn't "panic" and it isn't "ignore the headlines either." It's this: check whether the specific agent you're building or buying actually tells people it's AI. As of this month, that's no longer just good practice - it's the law.

Found this useful?

Share it with someone weighing the same decision.

Share: