Guides · 03/08/2026 · 5 min
AI Act: what has applied since 2 August 2026 — and what is still to come
The transparency deadline has passed: chatbots declared, deepfakes labelled, generated content flagged. The full picture — what applies, what the Digital Omnibus postponed (high risk: 2 December 2027), what Swiss companies must do this week.
On 2 August 2026, the AI Act entered its general phase
Since 2 August 2026, the transparency obligations of Article 50 of the AI Act — the European regulation on artificial intelligence (Regulation (EU) 2024/1689) — have applied. Anyone operating a public-facing chatbot must say so, content generated by artificial intelligence (AI) must be identifiable, deepfakes labelled. The regulation's penalty regime is likewise fully applicable.
That deadline held despite the calendar revision made by the “Digital Omnibus AI” regulation (Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July, in force since 27 July 2026). The omnibus postponed the high-risk obligations — not transparency. That gap creates a misleading situation: many companies took away “the AI Act has been postponed” when part of the text concerns them right now.
What applies now: the four cases of Article 50
First case, the chatbot (art. 50(1)): anyone interacting with a conversational AI system must know they are speaking to a machine, from the start of the exchange. Second case, generated content (art. 50(2) and 50(4)): machine-readable marking on the provider's side, a visible mention for published information texts without human editorial review. Third case, deepfakes (art. 50(4)): an explicit label on any realistic generated or manipulated content. Fourth case, emotion recognition and biometric categorisation in their lawful uses (art. 50(3)): prior information of the persons exposed.
Penalties reach 15 million euros or 3 % of worldwide annual turnover (art. 99(4)). For a small or medium-sized enterprise (SME), art. 99(6) applies the lower of the two ceilings, and the omnibus has opened the way to warnings and non-pecuniary measures for small structures.
The application guidance exists: the European Commission published its final guidelines on Article 50 on 20 July 2026, and the code of practice on the transparency of generated content had gathered roughly 190 signatory organisations by the end of July. Our dedicated guide to Article 50 (/conseils/obligations-chatbot-aout-2026) covers each case with a one-week compliance plan.
What already applied before that date
2 August 2026 is not the regulation's starting point. Since 2 February 2025, the prohibited practices of art. 5 — manipulation, exploitation of vulnerabilities, social scoring, emotion recognition at work and in education — have been banned, with penalties up to 35 million euros or 7 % of worldwide turnover (art. 99(3)). The obligation of AI literacy for staff (art. 4), softened by the omnibus into a best-efforts obligation, has run since the same date.
Since 2 August 2025, providers of general-purpose AI models (GPAI) have had their own obligations, and the European governance of the regulation is in place.
What comes next: three deadlines to diarise
2 December 2026: two new prohibitions become applicable (generation of non-consensual intimate images, child sexual abuse material), and the reprieve on machine-readable marking granted to generative systems placed on the market before 2 August 2026 ends. If your generative tools predate the summer, check with your providers that marking will be switched on in time.
2 December 2027: the full obligations for high-risk systems of Annex III — CV screening, credit scoring, education, biometrics — become applicable. This is the omnibus's main postponement: the original date was 2 August 2026, sixteen months have been gained.
2 August 2028: high risk under Annex I follows, that is AI embedded in already regulated products such as machinery, toys or medical devices.
Swiss companies: concerned, barring an exception
The AI Act has extraterritorial reach (art. 2). A Swiss company falls within scope as soon as it sells services incorporating AI to customers in the European Union (EU), or the outputs of its systems — scores, decisions, content — are used in the EU. A chatbot answering French visitors is enough. Only a strictly Swiss activity, with no link at all to the European market, stays out of scope — and even then, the Federal Act on Data Protection (FADP) already requires transparency of processing (art. 19 FADP).
Switzerland's own AI law is taking shape: the Confederation signed the Council of Europe Framework Convention on AI in March 2025, and a preliminary draft is expected to go to consultation by the end of 2026, with a sectoral approach. Complying with Article 50 today most probably anticipates the future Swiss requirements.
The postponement to December 2027 is not a pause
The sixteen months gained on high risk are a preparation window, not a dispensation. The Annex III obligations — risk management system, technical documentation, data governance, human oversight — take months to put in place, and the most frequent category in SMEs is employment: screening applications, evaluating staff. Companies that discover these requirements in mid-2027 will handle them under pressure, at full price.
The rational course today comes down to three moves: inventory your AI uses, including the functions embedded in business software; deal immediately with the public-facing touchpoints (chatbot notices, generated content); and classify what will fall under high risk in 2027 and cost the effort now.
Where to start
AI-Karma's free tool, designed for Swiss SMEs, covers those three moves: the AI Act classification module (/aiact) places each use case — prohibited, high risk, transparency or minimal risk — with its deadline; the transparency module (/transparence) generates ready-to-paste notices in four languages; the full assessment (/evaluation) returns, in about fifteen minutes, a picture across 24 indicators with an action plan.
This is not legal advice. For complex situations — provider role, high risk, regulated sector — have your analysis validated by specialised counsel.
Frequently asked questions
What exactly changed on 2 August 2026?
The transparency obligations of art. 50 became applicable: informing people facing a chatbot, marking AI-generated content, labelling deepfakes, informing people in cases of lawful emotion recognition. The regulation's penalty regime applies as well (up to EUR 15 M or 3 % of worldwide turnover for transparency, art. 99(4)).
Wasn't the AI Act postponed?
Partly. The Digital Omnibus (Regulation (EU) 2026/1744) postponed Annex III high risk to 2 December 2027 and Annex I high risk to 2 August 2028. It kept the 2 August 2026 deadline of art. 50 — its only adjustment is a targeted transition: machine-readable marking of content (art. 50(2)) by earlier generative systems is due by 2 December 2026 at the latest. The prohibited practices have applied since February 2025.
Is my Swiss company concerned?
Yes, as soon as a link with the European market exists (art. 2): customers in the EU, or outputs of your systems used in the EU — a chatbot accessible to European visitors is enough. A strictly Swiss activity stays outside the AI Act, but the FADP already requires transparency of processing (art. 19 FADP).
What happens on 2 December 2026?
Two new prohibitions apply (non-consensual intimate images, child sexual abuse material) and the reprieve on machine-readable marking for generative systems placed on the market before 2 August 2026 ends. The chatbot and deepfake obligations, for their part, have been due since 2 August 2026.
Where to begin this week?
Inventory your public-facing AI touchpoints (chatbot, generated content, visuals), display the required notices, then classify your uses against the high risk of 2027. AI-Karma's free /aiact module reproduces that classification question by question, and /transparence generates ready-to-paste notices.
And your company, where does it stand?
A score across 24 indicators, AI Act classification, an action plan — 15 minutes, free, no account.