Regulation · 14 August 2026

On 2 August 2026, part of the AI Act entered into application. It is not “the whole AI Act”. High-risk systems under Annex III are postponed to 2 December 2027. Embedded systems under Annex I are postponed to 2 August 2028, via the Digital Omnibus (Regulation EU 2026/1744, in force since 27 July 2026). A VSE or SME that reads alarmist headlines has an interest in separating what is already due from what is not. Panicking over a conformity assessment file whose deadline is 2027, while forgetting the chatbot disclosure, is the wrong trade-off.

The timetable, without shortcuts

Three layers now coexist.

Already applicable, and for longer than is often said: prohibited practices, with fines of up to €35 million or 7% of worldwide turnover. Also already applicable since 2 February 2025: Article 4 on AI literacy, for providers and for deployers.

Applicable since 2 August 2026: Article 50 transparency (information on interactions with AI, machine-readable marking of synthetic content, visible labelling of professional deepfakes, a mention on certain texts of public interest). Systems already on the market before that date have until 2 December 2026 for the machine-readable marking under Article 50(2). The AI Office may investigate providers of general-purpose models since 2 August 2026. Failures on the transparency strand expose you to up to €15 million or 3% of worldwide turnover.

Not yet applicable: the full regime for Annex III high-risk systems (2 December 2027) and Annex I embedded systems (2 August 2028). That postponement is what many comments too quickly summarised as “the AI Act is delayed”. No. One part is in force. Another is shifted.

What does not yet apply to a typical SME

Most of the agents we see in VSEs and SMEs (appointment booking, FAQ, quote follow-up, hotel reception, site tracking) are not, by that fact alone, high-risk systems within the meaning of Annex III. For as long as the postponement holds, you do not have to produce the assessment file, formalised risk management in the high-risk format, or the post-market monitoring duties of that regime.

That does not mean your use is “outside the AI Act”. You remain a deployer. You remain subject to Article 50 if a human talks to the system. You remain subject to Article 4 if your teams deploy AI without a minimum of competence. You remain subject to the GDPR as soon as personal data transits.

Also beware of an overly optimistic self-diagnosis. A tool that steers recruitment, scores candidates, assists a medical diagnosis or weighs on access to an essential service may fall into high-risk when the time comes. The postponement gives time to prepare. It does not turn a sensitive use into a trivial one.

What you still need to do, now

  • Keep a register of uses. Which tool, which provider, which data, which audience (staff, customers, candidates). One up-to-date page is enough at the start. Without that base, you will be unable to say, in 2027, what has become high-risk.
  • Handle 2026 transparency. Chatbots, agents, generated content: Article 50 does not wait for 2027. That is this summer’s priority job.
  • Do not wait until 2027 for literacy. Article 4 has been running since 2 February 2025. An AI and cybersecurity training programme is not a marketing side-show. It is a deployer obligation.
  • Secure the system, not only the discourse. An agent poorly ring-fenced, with too many rights over messaging or the customer file, is a cyber incident before it is an AI Act file. See our AI cybersecurity offering.
  • Cross-check GDPR and the AI Act. Purpose, legal basis, transfers outside the EU, retention of prompts: a GDPR compliance audit remains the most concrete way to see what actually circulates.
  • Document non-high-risk decisions. If you judge that a use is not Annex III, write why, on which date, on the basis of which facts. In 2027, that note will be worth more than a memory of a meeting.

Avoid two symmetrical mistakes

The first mistake is panic: freeze every AI project until 2027, or buy a “high-risk compliance pack” for an FAQ chatbot. You spend, you think you are covered, and you still have not told the user they are talking to a machine.

The second is denial: “this is only for the big platforms”. The deployer of an SME is named in the text. Fine caps are also calculated as a percentage of worldwide turnover. For a group, the percentage weighs. For a VSE, reputational and contractual risk often weighs faster than the theoretical cap.

Patrick Dajan Mouelle, director of Cybernecs, insists on this order of battle: first the inventory and the disclosure, then access security, then only the heavy files if a use truly approaches high-risk. The reverse order produces binders and opaque agents.

How to move without theatre

If you want a reading of your uses (what is already due, what can wait until 2027, what must be trained), contact us via the contact page. We do not sell fear of 2 December 2027. We frame what is in force on 14 August 2026, and what you can reasonably plan between now and then.

Sources: Artificial Intelligence Regulation (AI Act), Regulation EU 2026/1744 (Digital Omnibus), Touteleurope, L’Express.

Post a comment

Your email address will not be published.

Articles de la même catégorie