← All posts

EU AI Act Compliance: 5 Obligations Due in August 2026

EU AI Act Compliance: 5 Obligations Due in August 2026
TL;DR

The EU AI Act's August 2026 enforcement deadline brings three new obligations into force: high-risk AI system compliance under Annex III, transparency rules under Article 50, and regulatory sandbox requirements. This framework walks through all five current obligations with concrete steps for each, including the often-overlooked AI literacy requirement that has been in force since February 2025. Includes a self-assessment matrix and ISO 42001 mapping.

The EU AI Act Is Here. Do You Know Which Obligations Apply to You?

The EU AI Act entered into force on 1 August 2024, but it rolls out in phases. Right now we are at the most consequential inflection point: 2 August 2026 marks the date when high-risk AI system obligations under Annex III, transparency rules under Article 50, and regulatory sandbox requirements all become enforceable. If your organisation develops, deploys, or procures AI systems that touch the EU market, the compliance clock has stopped ticking. It is now ringing.

This post is not another overview of what the AI Act says. There are plenty of those, including on this blog. What follows is a practical compliance framework: the five obligations you must address, the concrete steps for each, a self-assessment matrix, and how ISO 42001 can serve as your operational backbone.

The Five Obligations: What Is Actually Due

Already in force (since 2 February 2025):

  • Article 4, AI Literacy: Any organisation deploying or using AI systems must ensure staff have a sufficient level of AI literacy. This applies to everyone, not just high-risk operators.
  • Article 5, Prohibited Practices: Certain AI practices are banned outright: subliminal manipulation, exploitation of vulnerabilities, social scoring by public authorities, real-time remote biometric identification in public spaces (with narrow exceptions), and emotion recognition in workplaces and schools.

Now enforceable (from 2 August 2026):

  • Articles 8 to 15, High-Risk AI Systems (Annex III): Full obligations for AI systems in biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and democratic processes.
  • Article 50, Transparency: Users must be informed when interacting with AI, including emotion recognition and deepfake disclosure. Applies to providers and deployers.
  • Article 57, Regulatory Sandboxes: Each member state must have at least one AI regulatory sandbox. Organisations can use these to test high-risk systems under supervision.

Obligation 1: AI Literacy, The One Nobody Talks About

Article 4 is deceptively simple: "Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff." No standalone fines are specified. But regulators use non-compliance as an aggravating factor in enforcement actions. If a system causes harm and your staff cannot explain how it worked, your Article 4 gap becomes Exhibit A in a negligence finding.

What to do:

  • Inventory your AI-adjacent roles. This is broader than engineers. Procurement teams evaluating vendors, HR using screening tools, marketing generating content with AI. If the role touches AI output, it needs literacy.
  • Define "sufficient" per role. Engineers need different literacy than recruiters reviewing AI-ranked candidates. Map three tiers: technical (data scientists, ML engineers), operational (procurement, legal, compliance), and general (anyone using AI-assisted tools).
  • Document the programme. A one-off lunch-and-learn does not cut it. You need initial assessment, role-specific training, periodic refreshers, attendance records, and comprehension testing.
  • Map to ISO 42001 Clause 7.2 (Competence). Your competence management process already requires documented evidence of AI-related skills. Article 4 slots directly into that framework.

Common pitfall: Treating AI literacy as an IT problem. Legal, HR, and procurement are often the biggest gaps.

Obligation 2: Prohibited Practices, Are You in the Clear?

Article 5 bans eight categories of AI practice. Most are obvious enough that no legitimate business would touch them. But two categories catch organisations by surprise.

Emotion recognition in workplaces and education (Article 5(1)(f)): If your HR team uses AI that analyses facial expressions or vocal tone during interviews, you are in prohibited territory. This extends to employee monitoring tools claiming to detect fatigue or attention. The ban applies regardless of consent.

Subliminal or manipulative techniques (Article 5(1)(a)): The threshold is "materially distorting behaviour" in a way that causes or is likely to cause harm. Dark patterns in AI interfaces, addictive design loops, and engagement-maximising algorithms pushing users toward harmful content all fall under scrutiny.

What to do: Conduct a prohibited-practices audit across every AI tool. Does it analyse emotions? Does it manipulate behaviour beyond reasonable personalisation? If yes, stop using it immediately. Fines reach EUR35 million or 7% of global annual turnover, whichever is higher.

Obligation 3: High-Risk AI Classification, The One That Hurts

Annex III lists eight domains where AI systems are high-risk by default. If your system falls into one, you must implement risk management (Article 9), data governance (Article 10), technical documentation (Article 11), record-keeping (Article 12), transparency and information provision (Article 13), human oversight (Article 14), and accuracy, robustness and cybersecurity (Article 15).

The eight Annex III domains:

  1. Biometrics (remote identification, categorisation, emotion recognition outside prohibited contexts)
  2. Critical infrastructure (safety components in energy, transport, water, digital)
  3. Education (admissions, assessment, proctoring)
  4. Employment (recruitment, promotion, performance evaluation, monitoring)
  5. Essential services (credit scoring, insurance pricing, emergency dispatch)
  6. Law enforcement (risk assessments, profiling, evidence analysis)
  7. Migration and border control (risk assessment, application examination)
  8. Administration of justice and democratic processes (judicial research, election influence)

What to do:

  • Classify every AI system. Create a register. For each system, ask: does it operate in an Annex III domain? If yes, it is high-risk unless you can demonstrate it poses no significant risk of harm to health, safety, or fundamental rights, with documented justification.
  • Build the compliance dossier. This is not a policy document. It is a technical file: system description, risk assessment methodology, training data provenance, testing results, accuracy metrics, bias evaluation, human oversight design, and cybersecurity measures.
  • Map to ISO 42001 Clauses 6.1 (Risk), 8.1 (Operational Planning), and Annex A controls. An existing ISO 42001 management system gives you documented processes that Annex III demands. You still need AI-specific technical content, but the governance scaffolding is already there.

Fines for Articles 8 to 15 violations reach EUR15 million or 3% of global annual turnover.

Obligation 4: Transparency Rules, More Than a Disclosure

Article 50 applies to providers and deployers. When people interact with an AI system, they must be informed. The implementation gets nuanced quickly.

What triggers Article 50:

  • AI systems that interact directly with people (chatbots, voice assistants, AI-generated recommendations)
  • Systems generating synthetic audio, image, video, or text content (deepfakes, AI-generated articles, synthetic media)
  • Emotion recognition or biometric categorisation systems (even if not prohibited under Article 5)
  • AI systems generating text published to inform the public on matters of public interest (with exceptions for journalistic use under editorial control)

What to do:

  • Audit your customer-facing AI touchpoints. Chatbot on your website needs a clear AI disclosure. AI-generated marketing copy may need labelling. AI-generated images need machine-readable watermarks where feasible.
  • Deployers carry the obligation. If you integrate a third-party AI chatbot on your site, you are the deployer and you carry the transparency obligation. The provider's compliance does not absolve you.
  • Document your disclosures. You must demonstrate to a supervisory authority that disclosures are clear, distinguishable, and context-appropriate. Keep records of disclosure mechanisms and placement decisions.

Violations of Article 50 fall under the same penalty tier as high-risk systems: up to EUR15 million or 3% of turnover.

Obligation 5: Regulatory Sandboxes, An Opportunity

Article 57 requires each EU member state to establish at least one AI regulatory sandbox by 2 August 2026. For vendors and deployers, this is worth engaging with. Sandboxes provide supervised environments to test high-risk AI systems under real conditions with regulatory guidance and, in some cases, relaxed requirements during the testing period.

The EU AI Act resource hub maintains a current list of national sandbox programmes and application procedures. Check which member state is most relevant before preparing an application.

What to do:

  • Identify your applicable sandbox. If based in the EU, it is your home state. If outside the EU but your system is used there, appoint an authorised representative and use their member state's sandbox.
  • Prepare an application. You need: system description, intended use, regulatory questions to resolve, and a testing plan. The more specific the request, the more useful the feedback.
  • Use participation as compliance evidence. Regulators look favourably on proactive engagement. A system that went through a sandbox and implemented the feedback is strong evidence of good-faith compliance in any subsequent enforcement action.

The Self-Assessment Matrix

Here is a five-minute diagnostic. Answer honestly.

Obligation Yes Partially No
AI literacy programme documented for all AI-adjacent roles
Prohibited-practices audit completed for all AI tools in use
AI system register with Annex III classification
Technical documentation dossier for each high-risk system
Transparency disclosures deployed on all AI touchpoints
Regulatory sandbox identified and engagement planned

Scoring: Four or more "Yes" answers means you are in reasonable shape, but verify quality. Two to three "Partially" means awareness but incomplete execution. Any "No" on obligation 1 or 2 is an urgent gap. Any "No" on obligation 3 means you are at material risk of enforcement action.

What Happens If You Are Not Ready

The EU AI Act has no grace period past August 2026 for these obligations. National supervisory authorities now have the legal mandate to investigate, request documentation, and impose corrective measures. The penalty structure, set out in detail here for non-EU organisations and in Regulation (EU) 2024/1689, Articles 99 to 101, is tiered:

  • Prohibited practices (Article 5): Up to EUR35 million or 7% of global annual turnover
  • High-risk system obligations and transparency (Articles 8 to 15 and 50): Up to EUR15 million or 3% of turnover
  • Incorrect or misleading information to authorities: Up to EUR7.5 million or 1.5% of turnover

Unlike GDPR, where enforcement built slowly, EU member states have had two years to prepare their supervisory authorities. Expect enforcement activity to begin in the second half of 2026 and ramp through 2027. For organisations looking for a governance framework that predates the AI Act, the NIST AI Risk Management Framework provides complementary guidance on mapping, measuring, and managing AI risks alongside the Act's requirements.

Where ISO 42001 Fits

If you are pursuing ISO 42001 certification, you have a significant head start:

  • Risk management (ISO 42001 Cl. 6.1) to AI Act Article 9: The risk assessment methodology gives you the process framework. You still need AI-specific risk analysis but the governance layer is built.
  • Competence (ISO 42001 Cl. 7.2) to AI Act Article 4: Your competence records are direct evidence of AI literacy compliance.
  • Operational planning (ISO 42001 Cl. 8.1) to AI Act Articles 10 to 15: Documented processes for data management, transparency, monitoring, and human oversight form the scaffolding for your technical documentation.

ISO 42001 is not a safe harbour from AI Act enforcement. But a certified AI management system is the most credible evidence you can present to a supervisory authority that non-compliance, if any, is a gap in execution rather than a gap in intent.

One Page You Can Use Today

If you walk away with one action, make it the AI system register. Create a spreadsheet. Columns: system name, vendor (if third-party), purpose, data processed, Annex III domain check (yes/no), Article 5 prohibited practice check (yes/no), Article 50 disclosure status (implemented/pending/not applicable), risk classification. Populate it this week. This single document tells you which obligations apply, what the priority order is, and where your evidence gaps sit.

Need help with the technical documentation or classification? Get in touch or see how we work. Want to understand what a compliance assessment looks like? Download a sample audit report. The AI Act enforcement window is open. Walk through it prepared.

Written by David Swan, reviewed and fact-checked against primary regulatory sources. AI-assisted but human-directed.

Frequently asked questions

What is the August 2026 EU AI Act deadline?

The 2 August 2026 deadline marks the date when high-risk AI system obligations under Annex III become enforceable alongside transparency rules under Article 50 and regulatory sandbox requirements under Article 57. These join the already-enforced prohibited practices ban and AI literacy obligation that came into force in February 2025.

Does the EU AI Act apply to companies outside the EU?

Yes. The EU AI Act has extraterritorial reach. It applies to any provider or deployer whose AI system output is used in the EU, regardless of where the organisation is based. Non-EU companies placing AI systems on the EU market must appoint an authorised representative in a member state.

What are the penalties for EU AI Act violations?

Penalties are tiered: up to EUR 35 million or 7% of global annual turnover for prohibited practice violations under Article 5, up to EUR 15 million or 3% of turnover for high-risk system and transparency violations under Articles 8 to 15 and Article 50, and up to EUR 7.5 million or 1.5% for providing incorrect information to authorities.

What is Article 4 AI literacy and who does it apply to?

Article 4 requires all organisations deploying or using AI systems to ensure their staff have a sufficient level of AI literacy. This applies to every organisation using AI, not just those operating high-risk systems. It covers technical staff, operational roles like procurement and legal, and general employees using AI-assisted tools.

How does ISO 42001 help with EU AI Act compliance?

ISO 42001 provides the management system framework that maps directly to several AI Act requirements: risk management methodology maps to Article 9, competence management maps to Article 4 AI literacy, and operational planning controls map to Articles 10 to 15 documentation requirements. While not a safe harbour, ISO 42001 provides documented evidence of good-faith compliance efforts.

How do I know if my AI system is high-risk under Annex III?

An AI system is high-risk if it operates in one of eight Annex III domains: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, or democratic processes. If your system falls into one of these categories, it is high-risk by default unless you can demonstrate with documented justification that it poses no significant risk to health, safety, or fundamental rights.