The EU AI Act’s first hard enforcement date arrives August 2 on the calendar it was always written to, four days after the Digital Omnibus on AI entered into force on July 27. Parliament backed the Omnibus on June 16, the Council signed off June 29, and the text hit the Official Journal July 24. The Commission got its simplification, but it didn’t get a reprieve on Sunday’s headline provisions.

What lands is narrow and sharp. Article 50 transparency obligations become enforceable: chatbot disclosure, synthetic-content marking, deepfake labeling. GPAI penalty powers switch on in parallel, and because the underlying obligations attached in August 2025, the AI Office can pursue foundation-model providers above the 10^25 FLOPs systemic-risk threshold retroactively. Twenty-four organizations have signed the GPAI Code of Practice, including Anthropic, Google, Microsoft, Mistral, and Meta; xAI signed only the Safety and Security chapter.

The Omnibus did move things. Annex III high-risk obligations covering recruitment, credit scoring, education, and law enforcement slip from August 2, 2026 to December 2, 2027. Annex I products (medical devices, lifts, toys) get until August 2, 2028. Regulatory sandboxes are due August 2, 2027. December 2, 2026 pulls double duty: pre-August generative tools must add machine-readable markers under Article 50(2), and Article 5 picks up new prohibitions on AI-generated non-consensual intimate imagery and CSAM.

The member-state picture is the real story. At least twelve missed the August 2025 deadline to designate national competent authorities. Roughly ten (Ireland, Germany, Spain, Italy, the Netherlands among them) show advanced infrastructure. France hadn’t notified a single point of contact to the Commission as of June. Germany’s KI-MIG was still in Bundestag readings in July.

Brussels legislated on schedule. Capitals didn’t. That gap, not the text of the Act, is what companies will actually navigate on Monday morning.

Sources

Sources