Field Note
The AI Act enters its operating phase
August 2 shifts the practical question from when rules arrive to how teams keep roles, evidence, and decisions current.
5 min read · Published 2026-08-04
August 2 did not make the EU AI Act simple. It made the work more operational.
The regulation reached a major application milestone on August 2, 2026. For organizations building or using AI, the practical question is no longer only when do the rules arrive? It is can we show which rules apply to each system, who owns the decision, and whether the supporting evidence is still current?
That is a healthier question. Dates matter, but a date cannot govern a changing model, provider, integration, or use case. An operating practice can.
One Act, several clocks
The August milestone is important precisely because it is not one universal deadline.
The European Commission says the AI Act became broadly applicable on August 2, subject to phased exceptions. Its enforcement powers for general-purpose AI model obligations also began on that date; those obligations had applied to providers of newer GPAI models since August 2, 2025.
Transparency requirements under Article 50 now apply to covered systems and uses. Depending on the role and context, these include informing people when they are interacting with AI, machine-readable marking of certain generated content, and disclosure duties for particular uses of synthetic content. The rules include exceptions and a limited transition until December 2, 2026 for the marking and detection obligations of some systems placed on the market before August 2.
At the same time, Regulation (EU) 2026/1744 moved the application dates for key high-risk-system requirements. The current dates are December 2, 2027 for systems classified under Annex III and August 2, 2028 for AI used as a safety component of regulated products under Annex I.
The result is a layered calendar, not a finish line. A plan built around a single “AI Act date” is now too blunt to guide real work.
A role is not a company-wide label
The Act assigns responsibilities to roles such as provider and deployer. In practice, one organization can occupy different roles across different AI systems. A company may use a third-party model in one workflow, place its own AI system on the market in another, and substantially modify a model elsewhere.
That makes the inventory more than a list of model names. For each system, teams need a short, reviewable account of:
- what the system does and where it is used;
- which organization owns each relevant role and why;
- which model, provider, data sources, tools, and downstream systems are involved;
- which application date and obligations the team believes apply; and
- what change would trigger a fresh assessment.
The last question is easy to overlook. A new model version, a new audience, a different decision context, or a material change in functionality can make old analysis stale even when the document itself still looks complete.
Turn obligations into evidence loops
The strongest governance programs connect each applicable requirement to an operating record. That record should identify an owner, the current evidence, the last review date, and the event that requires revalidation.
Depending on the system and role, evidence might include technical documentation, evaluation results, transparency controls, human-oversight decisions, incident records, or information supplied to a downstream provider. Not every artifact applies everywhere. The discipline is to make the mapping explicit rather than collecting a large folder of material and hoping it answers the eventual question.
Teams can make useful progress now without turning the work into a paperwork exercise:
- Reopen the AI inventory and assign roles system by system.
- Replace the single compliance date with the current layered calendar.
- Map each applicable obligation to an owner and a specific evidence artifact.
- Define the model, product, provider, and use-case changes that force review.
- Where incident reporting applies, test whether the reporting path can produce the required facts quickly.
This does not settle legal applicability for any particular organization. It does make conversations with counsel, security, product, and engineering much more concrete.
The PrivacyFirst view
Governance is operational when a team can answer five questions without assembling a committee: Which system are we discussing? What role do we hold? What decision did we make? What evidence supports it? What would make us revisit it?
If those answers live only in a readiness presentation, the program will drift as the AI system changes. If they live in an owned, dated, and inspectable operating record, regulation becomes part of how the system is managed—not an exercise that happens after the fact.
August 2 did not end AI Act preparation. It made the quality of that operating record easier to see.