EU AI Act August 2026: a compliance checklist for companies
The EU AI Act August 2026 checklist is the tool every CISO, DPO and AI project lead in Europe is asking for these weeks. On 2 August 2026, the obligations for general-purpose models (GPAI), the sectoral codes of conduct and part of the penalty regime come into force. Although the European Commission has postponed some pieces until 2027, that date still marks a before and after for any company using AI in the EU.
What really comes into force in August 2026
It is worth separating the noise from the regulatory fact. On 2 August 2026, the obligations on GPAI model providers, part of the transparency obligations, the designation of national authorities and the penalty regime associated with those pieces apply. Everything relating to high-risk systems in full has been moved to December 2027 and August 2028, as I already analysed in the postponement of the European AI law.
Compliance checklist to arrive ready for August 2026
I have built this list from real implementation projects in banking and public administration. It is ordered by priority and by logical order of execution, not by the order of the articles.
- Updated AI asset inventory with a risk classification per system. It is the basis for everything else.
- Mapping of providers of the foundational and GPAI models used, with reviewed contractual clauses.
- Internal AI use policy formalised, communicated and signed by key employees.
- Mandatory AI literacy programme (Article 4) for all staff who design, operate or supervise AI systems.
- Transparency procedure towards end users: notices of interaction with AI, labelled synthetic content.
- Risk assessment mechanism before deploying any new system, integrated into the project cycle.
- Incident register and a notification channel to the designated national authority.
- Data governance aligned with the GDPR: training bases, fine-tuning and sensitive prompts.
- Penalty response plan: up to €35M or 7% of global turnover.
- Light internal audit quarterly, with evidence ready for a possible inspection.
Typical mistakes in the months before the deadline
The most expensive mistake I am seeing is confusing the partial postponement with a total one. Some teams have slowed down the AI inventory or AI literacy because “DG Connect has given more time”. Another frequent mistake is delegating all compliance to the legal department: the EU AI Act is a technical-operational regulation and is complied with from the product design, not from the contract.
Who should lead the checklist in the company
In companies that have already reached compliance milestones, the pattern is clear: a senior AI Project Manager coordinates, the DPO validates the privacy piece, the CISO validates the security piece and the AI committee approves policies. If your organisation does not have that bridging figure, you are going to be late. I went deeper into this hybrid role in the new role of AI in leadership.
Another front that opens in August is registration in the European database of Article 71. I break it down in detail in the EU register of AI systems.
Conclusion: act before the summer
Three months seem like a lot until you subtract holidays, committees and legal reviews. If the checklist is not 80% complete in June, August will catch you improvising. If you need support to speed up the closing or validate the roadmap, we can talk about it.
For a complete view of the regulatory framework, see the NIS2 penalties in 2026, the general guide to IT regulations 2026: NIS2, DORA and the EU AI Act and the EU AI Act compliance timeline after the Digital Omnibus.
Are you taking AI from pilot to real work? Let us talk.
Book 20 minutes