A lot of what you have read about 2 August 2026 is now wrong. For two years, "2 August 2026" was the date the EU AI Act's high-risk obligations were supposed to bite, and most compliance content was written against that assumption. Then the Digital Omnibus moved the high-risk deadline. The result is a stale-content problem: guides that tell you to have a full high-risk conformity programme ready this summer are describing a deadline that no longer exists, while the duties that do land on 2 August 2026 get buried. This page is the corrected version. Here is what actually applies on 2 August 2026, what slipped to December 2027, and what it means for a company that records and analyses meetings.
On 2 August 2026 the AI Act's Article 50 transparency duties, the general-purpose AI (GPAI) rules, and the full fining powers (up to 15 million euro or 3 percent of worldwide turnover for transparency breaches) become enforceable. The high-risk obligations under Annex III that were originally due the same day were postponed by the Digital Omnibus to 2 December 2027. The Act was not delayed as a whole; one specific tranche moved.
What the Digital Omnibus actually changed
The European Commission published the Digital Omnibus on AI on 19 November 2025 as a simplification package. The European Parliament endorsed it on 16 June 2026 and the Council of the EU gave final approval on 29 June 2026, with entry into force following publication in the Official Journal. The headline change relevant to almost every buyer of AI software is a single deferral: the compliance deadline for standalone high-risk AI systems listed in Annex III moved from 2 August 2026 to 2 December 2027. For AI embedded in products already regulated under Annex I (medical devices, machinery and similar), the date moved to 2 August 2028.
What the Omnibus did not touch matters just as much. It did not delay the Article 50 transparency obligations. It did not delay the general-purpose AI model rules. It did not reopen the prohibited practices that have been banned since 2 February 2025, and it did not remove the AI literacy duty. If a guide tells you "nothing happens until the high-risk rules in 2026," it is now doubly wrong: the high-risk rules moved to 2027, and real obligations still land in August 2026.
First, which one are you: provider or deployer?
The AI Act assigns different duties to different roles, and most of the confusion in circulation comes from readers applying the wrong role to themselves. The two that matter for a company buying meeting-intelligence software are the provider (the organisation that develops an AI system and puts it on the market) and the deployer (the organisation that uses an AI system in a professional capacity).
If your company buys a call-recording or meeting-analysis tool and uses it on your own calls, you are a deployer, not a provider. Being a deployer means fewer obligations than the vendor carries, but it does not mean zero. Deployer duties under Article 50, the AI literacy duty under Article 4, and, for high-risk uses from December 2027, human oversight and monitoring, all sit with you. Your GDPR duties as the data controller for the personal data in those meetings sit with you regardless of the AI Act.
What applies on 2 August 2026
Three blocks of obligation become enforceable on this date.
1. Article 50 transparency
Article 50 splits into provider duties and deployer duties:
- Article 50(1), provider duty: AI systems that interact directly with people (chatbots and similar) must be built so a person is informed they are dealing with AI, unless it is obvious from context.
- Article 50(2), provider duty: providers of generative AI must mark synthetic audio, image, video and text in a machine-readable way so it can be detected as artificially generated.
- Article 50(3), deployer duty: if you deploy an emotion-recognition system or a biometric categorisation system, you must inform the people exposed to it.
- Article 50(4), deployer duty: if you publish deepfakes or AI-manipulated media, or AI-generated text on matters of public interest, you must disclose that it is artificial, unless a human has reviewed it and holds editorial responsibility.
2. General-purpose AI (GPAI) rules
Obligations for providers of general-purpose AI models become enforceable. Models placed on the market before 2 August 2025 have a longer runway (until 2 August 2027) to reach full compliance. This tranche mainly affects model providers, not the average deployer, but it is part of what "goes live" on the date.
3. Penalty powers
This is the change that turns the rest from theory into risk. From 2 August 2026 the enforcement and penalty provisions are active, so a breach of the transparency duties can attract fines of up to 15 million euro or 3 percent of worldwide annual turnover, whichever is higher. Before this date the transparency duties existed on paper; after it, they carry teeth.
What moved to 2 December 2027
The high-risk obligations under Annex III are the ones that involve conformity assessment, risk management systems, technical documentation, logging, human oversight design and registration in the EU database. Annex III explicitly lists AI used in employment for the monitoring and evaluation of workers. That is the category a conversation-intelligence tool can fall into when it scores, ranks or evaluates individual employees, and it is precisely why this deferral is not a reason to relax.
| Obligation | Applies from | Who it lands on |
|---|---|---|
| Prohibited practices, including workplace emotion inference (Art. 5) | 2 Feb 2025 (penalties live Aug 2025) | Everyone |
| AI literacy duty (Art. 4) | 2 Feb 2025 | Providers and deployers |
| Article 50 transparency duties | 2 Aug 2026 | Providers and deployers |
| General-purpose AI model rules | 2 Aug 2026 (legacy models to Aug 2027) | Model providers |
| Full penalty and enforcement powers | 2 Aug 2026 | Everyone |
| Watermarking of generative output already on market (Art. 50(2) transition) | 2 Dec 2026 | Providers |
| High-risk Annex III systems (incl. worker monitoring) | 2 Dec 2027 | Providers and deployers |
| High-risk AI embedded in Annex I regulated products | 2 Aug 2028 | Providers and deployers |
Procurement teams at larger buyers are already writing the December 2027 requirements into contracts now, because a vendor cannot retrofit high-risk conformity in the final quarter. The deferral buys time to do the work, not permission to skip it.
Does an AI notetaker have to announce itself in the meeting?
This is the question we hear most, and the honest answer has two layers.
Under the AI Act: the Article 50(1) "you are talking to an AI" duty is a provider duty aimed at systems that interact directly with a person, such as a chatbot. A passive transcription tool that listens and summarises is not the archetype Article 50(1) was written for. Where a meeting tool does cross into Article 50 for a deployer is narrower and more specific: if it performs emotion recognition (Article 50(3), you must inform participants) or produces synthetic media that gets published (Article 50(4)). So the AI Act does not, by itself, impose a blanket "the bot must announce itself" rule on ordinary transcription.
Under everything else: disclosure is still the right default, because other law already requires participants to know a recording is happening. GDPR requires a lawful basis and transparency for processing personal data. In Germany, section 201 StGB makes recording the spoken word without consent a criminal offence, and works-council co-determination under section 87 BetrVG applies when a tool is capable of monitoring employee performance. So the practical answer for any EU deployment is: tell people the meeting is being captured and why. The AI Act is not the reason, but the outcome is the same. We wrote the country-by-country version of this in our guide to GDPR-compliant call and meeting recording in Europe.
The trap that already applies: emotion recognition at work
One part of the AI Act is not on a 2026 or 2027 timeline at all, because it has been in force since 2 February 2025: the prohibition in Article 5(1)(f) on AI systems that infer the emotions of a person in the workplace, outside narrow medical and safety exceptions. Penalties for prohibited practices have been enforceable since August 2025, at the top fine tier of up to 35 million euro or 7 percent of worldwide turnover.
This matters for conversation-intelligence buyers because several tools in the category market "sentiment analysis" of calls. Where that feature infers the emotional state of an employee on a call, it sits uncomfortably close to a banned practice, and it is already live risk, not a future one. We will publish a dedicated analysis of where the Article 5(1)(f) line actually falls for sales-call sentiment features. For now the safe reading is: transcription and topic detection are ordinary processing; inferring a worker's emotions is the thing the Act singled out to prohibit.
What to do before 2 August 2026
A short, deployer-focused checklist that does not require a high-risk conformity programme:
- Confirm your role. For bought-in tools you are almost always a deployer. Document that, and get the provider's own AI Act position in writing.
- Fix your disclosure. Make sure meeting participants are told capture is happening, on a lawful basis, in your invite or a standing notice. This satisfies GDPR and, in Germany, section 201 StGB, and it covers the Article 50(3) case if any emotion or biometric feature is in play.
- Check for banned features. Turn off, or do not buy, any feature that infers employees' emotions from calls. This is a live prohibition, not a 2027 item.
- Close the AI literacy gap. Article 4 has required, since February 2025, that staff who use AI systems have adequate AI literacy. A short internal briefing on how the tool works and its limits is the minimum. Very few companies have done this; it is overdue, not upcoming.
- Front-run December 2027. If your tool scores or ranks individual employees, treat it as a probable high-risk use and start asking vendors now about human oversight, logging and documentation. The clock to 2027 is shorter than a procurement cycle.
- Keep your GDPR house in order. Lawful basis, retention limits, sub-processor chain and, where required, a data protection impact assessment sit with you as controller independently of every AI Act date.
Where Numi sits, honestly
Numi is a meeting and call intelligence tool, which for the AI Act makes our customers deployers. We do not claim that using Numi makes you "AI Act compliant," because compliance is a property of how you deploy, disclose and govern, not something a vendor can grant. What we can do is remove the friction from the duties that are actually yours: we make in-meeting disclosure and consent capture straightforward, we do not ship a workplace emotion-inference feature, and we process and host on EU-owned infrastructure so your GDPR and data-sovereignty posture lines up with the transparency duties rather than fighting them. On the December 2027 high-risk question, if you use scoring to evaluate individuals we will give you the documentation and oversight hooks a deployer needs, in writing, rather than leaving you to reverse-engineer them.
That is the control-not-origin point we make across our writing: what protects you is not a claim on a marketing page but the ability to show, on demand, who can touch the data, under which jurisdiction, and what the system does and does not infer. The AI Act's August 2026 tranche rewards exactly that kind of legibility.
This article is general information about the EU AI Act as of 30 July 2026, not legal advice. The Digital Omnibus text takes effect on publication in the Official Journal and implementing detail is still settling; confirm dates and obligations against the final published text and your own counsel before acting. Sources: EU AI Act (Regulation 2024/1689), Articles 4, 5, 50, 99 and 113; the Digital Omnibus on AI simplification package (Commission proposal 19 November 2025; Parliament endorsement 16 June 2026; Council approval 29 June 2026).