AI Technology Brief
EU AI Act enforcement expands on 2 August 2026 - what providers and business deployers need to prepare
On 2 August 2026, EU AI Act transparency requirements begin applying and Commission enforcement powers expand for general-purpose AI obligations. Businesses need role-specific system inventories, disclosures, provider evidence, human authority, and operating records - not one universal fine figure.

01 / Independently verifiable claims
Begin with what the technology and standards actually support.
- The EU AI Act applies in stages. Prohibited-practice and AI-literacy provisions began applying on 2 February 2025, and general-purpose AI model obligations began applying on 2 August 2025 for models placed on the market from that date.
- From 2 August 2026, the European Commission can enforce applicable general-purpose AI provider obligations, including through fines. Models placed on the market before 2 August 2025 have a separate transition to 2 August 2027.
- Article 50 transparency obligations generally apply from 2 August 2026. They cover direct AI interaction, machine-readable marking of qualifying synthetic content, deepfake disclosure, certain public-interest text, and notice for emotion-recognition or biometric-categorisation systems.
- The maximum fine specifically described for general-purpose AI model providers is EUR 15 million or 3% of preceding-year worldwide annual turnover, whichever is higher, under Article 101.
- The EUR 35 million or 7% tier is associated with non-compliance with prohibited AI practices under Article 5. It is not the general fine for every AI provider, deployer, transparency failure, or GPAI infringement.
- Under the revised timetable, Annex III stand-alone high-risk requirements apply from 2 December 2027, while high-risk AI used as a safety component in products governed by listed Union legislation applies from 2 August 2028.
- The Act can apply to actors outside the EU when they place systems or GPAI models on the EU market, put systems into service or use them in the EU, or when an AI system's output is used in the EU. Application remains role- and fact-specific.
- Article 4 has required providers and deployers to take measures supporting sufficient AI literacy since 2 February 2025. The Commission says the measures should reflect the people, context, and risks rather than one universal course or certificate.
02 / The practical distinction
The date, duty, and penalty depend on the organization's role and use case.
One company may be a deployer in one workflow, a provider in another, and neither a GPAI provider nor a high-risk operator in most ordinary uses. Classification must happen before a compliance checklist is assigned.
Role
Provider of an AI system
Develops, or has developed, an AI system and places it on the market or puts it into service under its own name or trademark. Integrating a third-party model into a branded system can require specific analysis.
Role
Deployer
Uses an AI system under its authority in a professional context. A construction or property company using a vendor tool will often begin here, but each workflow still needs classification.
Role
GPAI model provider
Places a general-purpose AI model on the EU market. Using an API or hosted model does not automatically make every customer the provider of that underlying GPAI model.
Obligation
Article 50 actor
A provider or deployer of covered interactive, generative, emotion-recognition, biometric-categorisation, deepfake, or public-interest content use may carry a specific transparency duty.
Obligation
High-risk operator
A provider, deployer, importer, distributor, product manufacturer, or other operator can have additional duties where the system falls within the Act's high-risk categories and no exception applies.
Scope
Affected business outside the EU
Location outside Europe is not a complete exclusion. EU market placement, use in the EU, or output used in the EU can create a connection to the Act.
03 / Operating architecture
Treat AI Act readiness as an operating system, not a footer notice.
The organization needs a repeatable way to identify systems and roles, map obligations, obtain provider evidence, control releases, and preserve proof as systems, models, uses, guidance, and deadlines change.
Inventory
AI system and use register
Record the system, provider, model, version, owner, users, purpose, affected people, territories, inputs, outputs, actions, integrations, and current operating status.
Classification
Role and obligation classifier
Determine provider, deployer, GPAI, Article 50, prohibited-practice, high-risk, literacy, and other relevant conditions with documented legal review where required.
Operation
Transparency and release control
Bind notices, machine-readable marking, visible disclosures, content provenance, human editorial review, consent, and publication approval to the exact channel and output version.
Evidence
Evidence and change control
Track contracts, instructions, technical documentation, model and system changes, training, tests, incidents, corrections, provider notices, legal decisions, and approved releases.
04 / Required records
A buyer needs evidence of the role, system, obligation, and accepted control for each use.
AI system record
System and model identity, provider, owner, purpose, intended use, users, territories, integrations, data categories, outputs, actions, and lifecycle state.
Role assessment
Provider, deployer, importer, distributor, GPAI relationship, rationale, assessor, legal input, applicable dates, assumptions, and review trigger.
Transparency requirement
Interaction notice, marking, deepfake or public-interest disclosure, biometric or emotion notice, exception rationale, channel, language, and effective date.
Provider evidence
Contract, instructions, documentation, declarations, model information, content-marking support, change notices, incident terms, support contact, and retention boundary.
Training and authority
Affected role, required literacy, completed guidance, permitted actions, approval authority, escalation route, review date, and evidence location.
Release and incident record
Output identity, source and model provenance, human review, disclosure, release approval, correction, complaint, incident, notification, and final disposition.
05 / Construction example
Construction and property organizations should classify familiar AI uses separately.
The same company can have ordinary deployer responsibilities for one tool, Article 50 duties for another, and a future high-risk assessment for a consequential workforce or safety use. This is not a single company-wide label.
Interactive AI
Customer or tenant chatbot
Confirm whether people are clearly informed that they are interacting with AI, how handoff works, which records are used, and how the organization handles incorrect or consequential responses.
Synthetic content
Generated proposal and marketing media
Determine which machine-readable marking is supplied by the provider and whether the deployer must visibly disclose a deepfake or certain public-interest content. Preserve source and release evidence.
Annex III review
Recruitment or worker management
Screening, ranking, allocation, monitoring, or employment decisions may require high-risk classification and later controls. Do not wait for the final date to identify the workflow, provider, data, owner, and human authority.
Sensitive use
Biometric site access or categorisation
Separate identity verification from prohibited or high-risk biometric practices, and distinguish access control from emotion recognition or biometric categorisation. Obtain qualified legal, privacy, labor, security, and accessibility review.
06 / Deterministic controls
Operational controls should make the required transparency and authority repeatable.
Role before rule
Do not assign obligations from a vendor category or marketing label. Classify the legal role and use for each system and workflow.
Provider contract boundary
Confirm documentation, marking capability, model and system changes, incident notice, audit support, retention, subprocessors, territories, and exit responsibilities.
Channel-specific transparency
Design the interaction notice, disclosure, marking, language, placement, timing, accessibility, and exception for the actual interface and audience.
Human editorial and consequential review
Record meaningful review for public-interest content and preserve human authority for employment, access, safety, commercial, legal, and professional decisions.
AI literacy by role
Train leaders, operators, reviewers, developers, procurement, security, content teams, and affected staff according to what they use, decide, monitor, or approve.
Change-triggered reassessment
Reassess after a new model, purpose, territory, integration, data category, audience, output, action, provider term, guidance, or legal deadline.
07 / Failure analysis
The most common mistake is treating the Act as one deadline and one compliance label.
Using the 7% figure for every AI breach
The highest Article 99 tier concerns prohibited practices. Different infringements and actors have different ceilings, conditions, authorities, and proportionality requirements.
Calling every customer a GPAI provider
A company using ChatGPT, Claude, Gemini, or another model does not automatically become the provider of the underlying GPAI model. Its own integrated system and branding still require analysis.
Treating a provider promise as the complete control
The vendor may support marking or documentation, while the deployer still owns its use, notice, human review, disclosure, affected people, and operating evidence.
Waiting for high-risk application dates
Inventory, contracts, workflow ownership, records, tests, literacy, and replacement decisions can take longer than the remaining transition period.
Labelling all generated content identically
Provider marking, deployer disclosure, deepfakes, public-interest text, ordinary editing, artistic works, and human editorial review do not share one universal rule.
Publishing political conclusions as legal analysis
Competitiveness claims about Europe do not establish the obligation facing a buyer. The useful question is what role, system, use, date, evidence, and authority apply.
08 / Deployment and cost
Readiness depth should follow the organization's actual role and consequence.
Baseline
Ordinary internal AI use
Maintain an inventory, approved-use boundary, provider record, AI literacy, data controls, human review, and incident route even when Article 50 or high-risk duties do not apply to that use.
Transparency
Interactive or generated-content use
Add Article 50 classification, notices, provider marking support, deployer disclosures, provenance, editorial review, channel testing, accessibility, and correction handling.
Provider analysis
Branded system or composed agent
Assess whether integration, development, substantial modification, own-name release, tools, actions, or downstream supply changes the company's role and documentation responsibilities.
Consequential use
Potential high-risk use
Begin qualified classification, data and risk governance, documentation, logging, human oversight, accuracy, security, monitoring, registration, worker or rights impacts, and provider evidence planning well before the application date.
- AI system discovery, use-case interviews, role classification, legal interpretation, territorial analysis, and continuing regulatory review
- Provider diligence, contract changes, technical documentation, marking support, integration changes, and replacement planning
- Interaction notices, visible disclosures, machine-readable provenance, content workflows, accessibility, translation, and channel testing
- AI literacy, role-based training, reviewer capacity, operator guidance, worker communication, and evidence of completed measures
- Logs, approval records, system and model versioning, monitoring, complaints, corrections, incident response, retention, and audit support
- High-risk readiness, data governance, testing, conformity work, quality management, human oversight, registration, and specialist advice where applicable
09 / Evaluation
Test whether the organization can prove the required behavior, not only display policy text.
- Select representative systems and confirm that the inventory identifies provider, model, owner, purpose, territory, users, affected people, outputs, actions, and current status.
- Give the same use case to business, technical, procurement, and legal reviewers and reconcile conflicting role or obligation classifications.
- Open each covered interface as a first-time user and verify that AI-interaction notices are timely, clear, accessible, and available in required languages.
- Generate representative text, image, audio, and video outputs; inspect provider marking, preserved metadata, visible disclosure, editorial review, and downstream platform behavior.
- Trace one published output to its source material, model or system version, reviewer, disclosure decision, approval, channel, release time, and correction route.
- Test a provider or model change and confirm contracts, classification, transparency, evaluation, training, and approval are reassessed before release.
- Test a complaint, incorrect disclosure, removed metadata, deepfake allegation, provider incident, and suspected high-risk use; confirm ownership, evidence preservation, escalation, correction, and notification review.
- Confirm the organization can distinguish legal requirements from voluntary codes, vendor guidance, internal policy, and non-legal good practice.
10 / Controlled pilot
Prove the operating boundary before expanding it.
Inventory one workflow
Identify the AI system, model, provider, purpose, users, affected people, territory, source data, outputs, actions, interfaces, owner, and current controls.
Classify role and obligation
Document provider or deployer status, GPAI relationship, Article 50 conditions, potential prohibited or high-risk use, literacy needs, dates, assumptions, and legal questions.
Collect provider evidence
Review contracts, instructions, documentation, content-marking support, change notices, incident terms, data handling, support, and exit conditions.
Implement the visible control
Add the correct notice, marking preservation, disclosure, human review, approval, provenance, complaint, correction, and escalation path for the selected workflow.
Test and preserve evidence
Run normal, exception, changed-model, inaccessible-notice, removed-marking, disputed-content, and incident cases while recording decisions and results.
Scale by role, not assumption
Reuse the method for other workflows, but reclassify each use. Obtain qualified advice before consequential deployment or relying on a legal interpretation.
11 / StructuredLayer recommendation
Do not prepare for 2 August 2026 with one AI policy or one fine figure. Build a role-specific register that connects every AI workflow to its provider, obligation, date, transparency control, human authority, and operating evidence.
The immediate buyer task is classification, not political commentary. Construction and property organizations should inventory customer chatbots, generated content, recruitment and worker-management tools, biometric access, safety-related systems, and internally composed agents; confirm who supplies and operates each system; and test notices, marking, review, logging, training, incidents, and change control. This brief supports operating preparation and does not replace legal advice from qualified counsel in the relevant jurisdiction.
12 / Primary sources
Capability, governance, and implementation claims remain inspectable.
EUR-Lex
Regulation (EU) 2024/1689 - Artificial Intelligence Act
European Commission
Navigating the AI Act
European Commission
Guidelines for providers of general-purpose AI models
European Commission
General-purpose AI models in the AI Act - questions and answers
European Commission
Guidelines on Article 50 transparency obligations
European Commission
Quick facts: transparency rules for AI systems
European Commission
Code of Practice on transparency of AI-generated content
European Commission
Guidelines for providers and deployers of high-risk AI systems
Council of the European Union
Council gives final green light to simplify and streamline AI rules
European Commission
AI literacy - questions and answers
Sources reviewed 25 July 2026. Technology capabilities, laws, guidance, terms, and pricing can change.
13 / Related StructuredLayer guidance
Continue from model selection into operating architecture.
Governance
Connect AI-provider rules, access, evidence, incidents, approvals, retention, and accountable human authority.
Permissions and Security for AI
Map identities, records, tools, credentials, approval, monitoring, incidents, and handover for AI-assisted work.
AI Workflow Training
Build role-based capability around workflow selection, tools, verification, governance, and human authority.
Synthetic Video for Construction Communication
Separate generated concepts and communication from project evidence, factual claims, identity, rights, and approved release.
