EU Artificial Intelligence Act: what changes from August 2026 and how it affects users and companies

Since August 2, the transparency obligations for chatbots, deepfakes, and AI-generated content come into effect. The stricter rules for high-risk systems are postponed until 2027 and 2028.

5 minutes

EuropaPress 7053510 ordenador siglas ai artificial intelligence inteligencia artificial 24

EuropaPress 7053510 ordenador siglas ai artificial intelligence inteligencia artificial 24

Add DEMÓCRATA to Google

Ask FREN

Published

Last updated

5 minutes

Most read

As of August 2, 2026, the European Regulation on Artificial Intelligence comes into general application. The most visible change for citizens affects transparency: users must know when they are interacting with an AI, and certain content, such as deepfakes or artificially generated texts on matters of public interest, must be identified. However, Brussels has postponed a good part of the most demanding obligations for systems considered high risk.

The European Union has reached one of the fundamental dates in the implementation calendar of its Artificial Intelligence Law. Since August 2, 2026, Regulation (EU) 2024/1689 will be applied generally after a two-year transitional period since its entry into force.

This does not mean that all its rules have now begun. Some prohibitions have been in effect since February 2025, and the obligations for large general-use artificial intelligence models began to apply in August of that same year. Additionally, a European reform approved this summer has postponed until 2027 and 2028 a good part of the obligations corresponding to high-risk AI systems.

What does the EU Artificial Intelligence Law consist of?

Although it is commonly referred to as the "Artificial Intelligence Law" or AI Act, legally it is a European regulation and, therefore, is directly applicable in all Member States, including Spain, without the need for each country to previously transform it into national law.

The regulation uses a risk-based system: the greater the potential harm of an artificial intelligence application to security or fundamental rights, the greater the obligations it must fulfill.

It generally distinguishes between prohibited practices, high-risk systems, systems subject to specific transparency obligations, and applications of minimal risk.

As of August, it will be necessary to notify when we talk to an AI

One of the changes that citizens will notice most directly comes from Article 50, applicable from August 2.

Providers must design certain systems so that a person is informed that they are interacting with an artificial intelligence, unless it is evident from the circumstances.

This especially affects tools such as chatbots, virtual assistants, or automated customer service systems. The goal is to prevent a person from believing they are having a conversation with another human being when they are actually dealing with a machine.

The images, videos, and audios generated by AI must be detectable

Providers of systems capable of producing audio, images, videos, or synthetic texts must also incorporate mechanisms that allow for the technical identification that this content has been generated or manipulated by AI.

The Regulation requires that this information be detectable in a machine-readable format and that the solutions used be effective, interoperable, robust, and reliable to the extent that it is technically possible.

There is, however, an important transitional exception. Systems that were already marketed before August 2, 2026, have until December 2, 2026 to adapt this marking function.

Deepfakes will have to be identified

The regulation also introduces a specific obligation for deepfakes.

When an AI tool generates or manipulates an image, audio, or video in such a way that it appears authentic, whoever publishes or uses that content must clearly inform that it has been artificially created or modified.

The legislation introduces nuances for artistic, satirical, creative, or fictional works: it must be warned of the use of artificial intelligence, but in a way that does not hinder the normal enjoyment of the work.

There are also exceptions related to certain legally authorized uses for investigating, preventing, or prosecuting crimes.

What changes for the media?

This is one of the particularly relevant aspects for newspapers, television, websites, and social networks.

Since August, when an AI system generates or manipulates a text intended to inform the public about matters of public interest, it must be indicated that the content has been artificially created.

However, the Regulation itself incorporates a fundamental exception: it will not be mandatory to label the text as AI-generated when it has gone through a process of human review or editorial control and there is a natural or legal person who assumes editorial responsibility for its publication.

Therefore, the regulation differentiates between the automated publication of information and the use of AI tools within a journalistic process supervised by professionals.

It must also be notified of the recognition of emotions

People must be informed when they are exposed to certain systems of emotion recognition or biometric categorization.

For example, if a company uses a system that attempts to identify certain emotional states through the face, voice, or other biometric signals, the individuals subjected to the system must know how it works.

These tools are also subject to other restrictions. Some uses of artificial intelligence to infer emotions in educational centers and workplaces have already been prohibited since February 2025, except for exceptions primarily related to medical or security reasons.

What rights do citizens gain?

Since the general application of the Regulation, several protection mechanisms are also fully operational.

Any natural or legal person who believes that the AI Law has been violated can file a complaint with the competent market surveillance authority.

The Regulation also provides a right to receive explanations when certain decisions that produce legal effects or significantly affect a person are made based on artificial intelligence systems considered high risk.

The practical application of this last guarantee will be linked to the specific timetable of high-risk systems, whose main obligations have been postponed.

Fines can reach 15 million for violating transparency rules or 3% of a company's annual global turnover, applying the proportionality criteria established for small and medium-sized enterprises.

Surveillance will mainly fall on the competent national authorities. The European Artificial Intelligence Office will have specific competencies over certain systems and general-purpose models, while the European Data Protection Supervisor will act regarding the institutions of the Union.

What is postponed until 2027 and 2028?

The major exception affects high-risk artificial intelligence.

In July 2026, the EU modified the timetable through Regulation 2026/1744 due, among other reasons, to the delay in the development of technical standards and tools that would allow companies to meet the requirements correctly.

The complete obligations for the systems used in sensitive areas of the annex III, such as employment, education, access to certain essential services, biometrics, migration, asylum, border control, or administration of justice, will begin to apply on December 2, 2027.

The high-risk systems incorporated into regulated products, such as certain medical devices, machinery, or products subject to European safety legislation, will have until August 2, 2028.

Therefore, August 2, 2026 represents an important leap in the application of the European Artificial Intelligence Act, but does not yet represent the end of its regulatory calendar.

More key points, information and questions with FREN

AI-GENERATED CONTENT

What parliamentary procedures were required for the approval of the European Artificial Intelligence Regulation and what were its main stages in the Council and the European Parliament?

The European Artificial Intelligence Regulation (AI Act) was approved through the ordinary legislative procedure, which involved an initial proposal from the Commission, parallel negotiations in the Council and the European Parliament, and finally trilogues to finalize a common text. The original proposal was COM(2021) 206 final, presented in April 2021, and the political agreement between co-legislators was reached in December 2023. The Parliament gave its approval in March 2024 and the Council granted final approval in May 2024, before publication in the Official Journal and entry into force at the end of July/beginning of August 2024. Below are the main procedures and stages in the Council and Parliament.

1. Commission Initiative: COM(2021) 206 final

The process started on April 21, 2021, when the European Commission approved the proposal for Regulation COM(2021) 206 final, which establishes harmonized rules on AI and amends various sectoral legislation. The proposal can be consulted in the official Eur-Lex reference of the COM(2021) 206 proposal. With this adoption, the ordinary legislative procedure under Article 294 TFEU was formally opened.

2. Processing in the Council of the EU

2.1 Work in working groups and technical guidelines

Since 2021, the proposal has been discussed in the Council's working groups (telecommunications, internal market, etc.), where Member States have been shaping positions on the definition of AI, list of prohibited systems, high-risk regime, governance (AI Office), and sanctions. This phase culminated with the adoption of a general approach.

2.2 Council "General approach"

In December 2022, the Council adopted its general approach, which sets the negotiation position vis-à-vis the Parliament. The agreed text is in the Council's position document available in the general approach. From that moment, the Council was mandated to enter trilogues.

2.3 Final approval by the Council

After the political agreement in December 2023, the Council formally adopted the Regulation in May 2024. The press release collected by the Spanish Administration titled “The Council gives final green light to the first global AI rules” summarizes that the Council approved on May 20 a “landmark” risk-based law, and details the schedule for entry into force and phased application (note on the Council's green light). The Council itself describes the act as the first global AI rules in its official statement.

3. Processing in the European Parliament

3.1 Registration and committee work

In the Eurochamber, the file is registered as 2021/0106(COD), with a record accessible in the procedure 2021/0106(COD). The IMCO (Internal Market) and LIBE (Civil Liberties) committees took on the joint rapporteurship, receiving thousands of amendments and negotiating compromise texts on sensitive points: biometric identification, high-risk systems, generative AI, fundamental rights, and governance.

3.2 Negotiation mandate and trilogues

Once the report was approved in IMCO/LIBE (May 2023), Parliament granted a mandate to negotiate with the Council. Several trilogues were held thereafter, culminating in the provisional political agreement of December 2023, under the Spanish Presidency of the Council. According to the Council's summary, the provisional agreement between co-legislators was reached on December 8, 2023, marking the political closure of the negotiation (Council reference).

3.3 Vote in the Eurochamber Plenary

On March 13, 2024, the European Parliament Plenary approved the Artificial Intelligence Act. The institutional chronicle “The Eurochamber approves a historic law to regulate artificial intelligence” indicates that the Regulation, the result of the December 2023 negotiations, was supported with 523 votes in favor, 46 against, and 49 abstentions (note on the Parliament vote). The approved legal text can be consulted in the Parliament decision.

4. Publication, entry into force, and subsequent stages

After signature by the Presidents of Parliament and Council, the Regulation was published in the OJ EU as Regulation (EU) 2024/1689, with the text accessible on Eur-Lex (Regulation (EU) 2024/1689). It enters into force 20 days after publication, and its application is phased: prohibitions of unacceptable risk practices apply after six months, rules for general-purpose AI models after 12 months, and full high-risk obligations after 24–36 months, as detailed in the Parliament's note (historic AI law).

The Commission summarizes this phase in its press release “The European Artificial Intelligence Act enters into force” (Commission note), and the Spanish Government frames the Regulation within its national AI strategy in the note “What is the 2024 Artificial Intelligence Strategy?” (AI Strategy 2024). From Spain, the newspaper Demócrata has also analyzed the entry into force and political significance of the new framework in articles such as “The entry into force of the new AI Regulation”, “Europe faces a new step to regulate artificial intelligence”, and “Europe wants to become an AI continent”, highlighting the Regulation's role as a central piece of the EU's new digital regulatory architecture.

Could you detail what changes the European Parliament introduced on the original COM(2021) 206 proposal regarding generative AI or biometric recognition? What specific application schedule does Regulation 2024/1689 establish for prohibitions, general-purpose models, and high-risk systems? What role has Spain, and particularly its Presidency of the Council in 2023, played in closing the trilogues and approving the AI Act?

What are the competencies of the European Artificial Intelligence Office according to current European legislation?

The European Artificial Intelligence Office (AI Office) is the Commission body responsible for applying and enforcing much of the European Artificial Intelligence Act (AI Act), with direct competencies over general-purpose models and a coordinating role vis-à-vis Member States. Its legal basis combines the AI Regulation itself and a specific Commission decision that creates the Office and assigns it functions. Besides supervision and sanctioning, it acts as a public policy center, technical support, scientific coordination, and promoter of trustworthy AI innovation in the EU.

Legal basis and institutional position

According to the official note on the AI innovation package, the Commission adopts a decision to create an AI office within the institution itself, with the mandate to “ensure the development and coordination of AI policy at the European level and oversee the application and compliance of the future AI Act” (AI innovation package).

When the European AI Regulation enters into force, the Commission specifies that the Artificial Intelligence Office will be the main enforcement body of the AI Act at the EU level and the authority responsible for enforcing rules on general-purpose AI models (AI Act entry into force). The Office is integrated within the Commission but acts as the central point of the Regulation's governance system, alongside the European AI Board and other advisory bodies.

Regulatory and supervisory functions

Strictly regulatory competencies attributed to the Office by legislation and Commission decisions can be grouped into several blocks:

  • Enforcement of the AI Act at the EU level: it is the “main enforcement body” of the Regulation, especially regarding general-purpose models (GPAI), and “will directly enforce the rules for general-purpose AI models” (creation of the AI Office and entry into force).
  • Supervision and coordination with national authorities: it must “ensure coherent implementation of the AI Act by supporting Member States' governance bodies” and closely cooperate with the European AI Board, which groups national authorities (creation of the AI Office).
  • Information and sanction powers: the Office can “request information and impose sanctions, when necessary” regarding general-purpose models that breach the rules (creation of the AI Office). The maximum sanction regime (up to 7% of global turnover in the most serious cases) is set in the Regulation, which the Office helps to enforce.
  • Development of guidelines and codes of conduct: it prepares “guidelines on the definition of AI systems and on prohibitions” and coordinates the development of “codes of practice for obligations related to general-purpose AI models” within the deadlines set by the Regulation (creation of the AI Office).

Technical, scientific, and innovation support role

Beyond sanctioning, the Office has a broad mandate to provide technical support and foster a European trustworthy AI ecosystem:

  • Technical model assessment: it coordinates and conducts “testing and evaluation of general-purpose AI models” in cooperation with developers, the scientific community, and other stakeholders (creation of the AI Office).
  • Network of experts and advisory bodies: it works with the European AI Board, an independent Scientific Panel of experts, and an Advisory Forum integrating industry, SMEs, academia, and civil society, to ensure regulatory decisions are based on scientific evidence and sectoral expertise (creation of the AI Office and entry into force).
  • Promotion of an innovative ecosystem: it “will promote an innovative ecosystem in the EU for trustworthy AI,” providing advice on best practices and facilitating access to AI testing environments, real-world testing, and other European support structures such as experimentation facilities and European Digital Innovation Hubs (creation of the AI Office).
  • Support for research and specific initiatives: it supports R&D activities in AI and robotics and launches initiatives like GenAI4EU so that generative models developed and trained in Europe are applied in key economic sectors (creation of the AI Office and AI innovation package).

Strategic and international dimension

Finally, legislation and Commission communications assign the Office a strategic and international function:

  • Coordination of European AI policy: it must become the “central coordinating body for AI policy at the EU level” and develop knowledge and understanding about AI to guide regulatory action and foster adoption (AI innovation package).
  • International projection: the Office has an “international vocation” and must ensure “a strategic, coherent, and effective European approach to AI at the international level, becoming a global reference point” (creation of the AI Office and AI innovation package).

In summary, the European Artificial Intelligence Office combines powers of supervision and sanction, coordination with Member States, production of guidelines and codes, and scientific and innovative support, functioning as the core of the European AI governance model established by the AI Act.

Within what specific timelines will the various competencies of the European AI Office be deployed according to the AI Act schedule? How does the European AI Office coordinate with the Spanish Artificial Intelligence Supervisory Agency and other national authorities? What specific sanctioning powers does the European AI Office have against providers of general-purpose models?

What are the main requirements and procedures companies must comply with to adapt their AI systems marketed before August 2, 2026?

Companies that already have AI systems on the market in Spain and the EU must, by summer 2026, classify them according to the European AI Regulation (AI Act), conduct a risk and compliance gap analysis, and begin adapting technical documentation, data governance, human oversight, and internal processes. Prohibited AI systems must be withdrawn or redesigned before the prohibition regime is fully applicable; high-risk systems must progressively align with quality, traceability, risk management, and conformity assessment requirements, although many full technical obligations extend beyond August 2026. Spain relies on the Spanish Artificial Intelligence Supervisory Agency (AESIA) and the controlled testing environment to facilitate this transition. Below is a summary of key elements companies should have in place before August 2, 2026.

1. System classification and strategic decision

The first step is to inventory all marketed AI systems and classify them into four main categories:

  • Prohibited AI: uses such as severe subliminal manipulation or social scoring. They must cease marketing when the prohibition enters into force (before 2026), or be redesigned to exit that category.
  • High-risk AI: for example, systems affecting employment, education, essential services, or critical infrastructure. These are the main focus of technical obligations.
  • Limited-risk AI: systems requiring enhanced transparency (notices that one is interacting with AI, synthetic content labeling, etc.).
  • General-purpose AI / foundational models: large models reusable in multiple products.

Before August 2026, the company should have a clear decision for each system: continue and adapt, withdraw from the market, or replace it.

2. Technical requirements for already marketed systems

Although the AI Act introduces staggered schedules, high-risk systems already on the market will have a transitional regime: they may continue operating but must progressively comply with key safety and governance requirements. In practice, before August 2, 2026, it is advisable to have advanced:

  • Risk management system: identification of risks to fundamental rights, health, and safety, mitigation measures, and periodic review.
  • Data governance: traceability of training, validation, and test datasets; bias control; documentation of data provenance and quality.
  • Human oversight: definition of who can intervene, deactivate, or review automated decisions, and under what procedures.
  • Robustness and cybersecurity: documented tests, response plans for failures and attacks, known usage limits.
  • Technical documentation: a “technical file” of the system that allows authorities such as AESIA and, where applicable, notified bodies, to understand its design, data, tests, and controls.

3. Organizational and compliance procedures

Besides the technical part, companies must organize internally for compliance:

  • Internal AI governance: policies approved by management, clear roles (AI compliance, DPO, security), and an approval circuit for new deployments.
  • Conformity assessment: for high-risk AI, preparation for self-assessments or, when applicable, third-party assessments, in line with the experience of the Spanish “sandbox” regulated by Royal Decree 817/2023.
  • Post-market surveillance: system to collect incidents, complaints, adverse outcomes, and improve the model.
  • Incident notification: procedures to report serious incidents or systematic failures to authorities when required by the AI Act.
  • Registration: prepare for the eventual registration of high-risk systems in the corresponding European databases.

4. Spain's role: AESIA and controlled environment

In Spain, Royal Decree 729/2023 approves the Statute of the Spanish Artificial Intelligence Supervisory Agency, which will be the national authority responsible for supervising the application of the AI Act. Spanish legislation configures it as a central piece of the supervisory ecosystem and as a contact point with the EU.

Complementarily, the high-risk AI testing environment regulated in Royal Decree 817/2023 allows companies to test compliance with the future Regulation's requirements in a controlled framework, with guidance and support. Participating in this sandbox can be a practical tool to adapt systems already marketed before the European deadlines.

5. Other pieces of the Spanish regulatory ecosystem

Alongside these structural rules, the BOE includes complementary measures that, although they do not directly regulate the AI Act's transitional regime, show the construction of the Spanish AI framework: sectoral aid (Order TDF/1494/2024, Order TDF/304/2025), advisory bodies (International AI Advisory Council), and the deployment of AESIA itself (Order TDF/774/2025, Resolution of August 25, 2025, constitution of the contracting board). In the judicial field, the General Council of the Judiciary has approved a specific instruction on the use of AI in courts (Instruction 2/2026).

Many other BOE resolutions reflect the expansion of AI training in universities and the integration of digital skills (Royal Decree 532/2025, Royal Decree 546/2023, and various curricula such as those of the University of Santiago de Compostela, CUNEF, University of Navarra, or the University of La Rioja, among many others).

All this configures an environment in which, by August 2026, companies with AI systems already marketed will have to combine the technical adaptation required by the AI Act with increasing interaction with AESIA and, when appropriate, with the regulatory testing programs available in Spain.

What specific timelines does the AI Act set for the entry into force of high-risk, general-purpose, and prohibition obligations? How can I determine if a specific AI system of my company falls into the high-risk category according to the European Regulation? What specific functions and powers will the Spanish Artificial Intelligence Supervisory Agency have over systems already deployed on the market?

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

What is the general application date of the European Artificial Intelligence Regulation (EU 2024/1689)?

Question 1 of 3

What obligation do providers have regarding AI-generated content such as images, videos, and audios?

Question 2 of 3

What exception exists for AI systems marketed before August 2, 2026, regarding content identification?

Question 3 of 3

Hola, soy Fren. ¿Cómo te ayudo?