Who this is for: AI compliance leads, DPOs, GPAI model providers, AI deployers operating in the EU, and GRC architects preparing for the August 2, 2026 enforcement milestone.

Enforcement begins August 2, 2026. Art. 50 transparency obligations and GPAI provider requirements become enforceable by the AI Office. Fines for non-compliance: up to 15 million EUR or 3% of global annual turnover for GPAI violations; up to 35 million EUR or 7% for prohibited practices. The European Commission's AI Office is the sole enforcer for GPAI obligations. National market surveillance authorities enforce Art. 50 transparency requirements.

Contents

1. Full Enforcement Timeline 2. What Activates August 2, 2026 3. What Was Deferred by the Omnibus 4. GPAI Grandfathering Rules 5. August 2 Compliance Checklist 6. Obligation-to-Procedure Mapping 7. Detailed Procedure Cards 8. Quick Reference 9. Quick Start 10. References

1. Full Enforcement Timeline

The EU AI Act entered into force on August 1, 2024, with obligations phased in over four years. The Omnibus Amendment (political agreement May 7, 2026; Parliament endorsed June 16; Council adopted June 29) modified several deadlines for high-risk AI systems. Official Journal publication is imminent.

February 2, 2025 (past)

Prohibited AI practices (Art. 5) became enforceable. Social scoring, real-time biometric surveillance (with exceptions), subliminal manipulation, and exploitation of vulnerable groups are banned.

August 2, 2025 (past)

AI literacy requirements (Art. 4) took effect. AI governance structures must be in place. Codes of Practice for GPAI published.

August 2, 2026 ( days)

Art. 50 transparency obligations + GPAI provider requirements enforceable. This is the current milestone.

August 2, 2027

GPAI grandfathering ends for models on market before August 2, 2025. High-risk Annex III systems (original deadline, now deferred -- see below).

December 2, 2027

Omnibus new deadline: High-risk AI obligations for Annex III systems (was August 2, 2027).

August 2, 2028

Omnibus new deadline: High-risk AI obligations for Annex I systems (safety components in regulated products). Full enforcement of all AI Act provisions.

2. What Activates August 2, 2026

Two categories of obligations become enforceable on this date:

Art. 50: Transparency Obligations for All AI Systems

GPAI: General-Purpose AI Model Provider Obligations

3. What Was Deferred by the Omnibus

Omnibus Amendment (formally adopted June 2026): The European Parliament endorsed the AI Act Omnibus Amendment on June 16, 2026, and the Council gave final green light on June 29, 2026. The amendment defers high-risk AI system obligations and delays the Art. 50(2) machine-readable marking requirement for pre-existing systems to December 2, 2026. This does NOT affect Art. 50 transparency (interaction disclosure, deepfake disclosure) or GPAI obligations, which remain on the August 2, 2026 schedule.

What Was DeferredOriginal DeadlineNew DeadlineScope
Annex III high-risk AIAugust 2, 2027December 2, 2027Standalone high-risk AI systems (biometrics, critical infrastructure, employment, credit, law enforcement, migration, justice, democratic processes)
Annex I high-risk AIAugust 2, 2027August 2, 2028AI as safety components in regulated products (machinery, medical devices, aviation, automotive, toys, marine equipment, rail)

Not deferred (still August 2, 2026): Art. 50 transparency, GPAI obligations, AI Office enforcement powers, notification of GPAI models with systemic risk, Codes of Practice.

4. GPAI Grandfathering Rules

GPAI models that were already on the EU market before August 2, 2025 receive a transitional period:

5. August 2 Compliance Checklist

Each checklist item maps to a specific obligation, SWT3 procedure, and the evidence artifact you need to produce.

Active August 2

1. AI Interaction Disclosure (Art. 50(1))

Obligation: Inform users they are interacting with AI before or at the start of interaction.

SWT3 procedure: AI-TRANS.1 -- witnesses disclosure delivery with timestamp, recipient type, and disclosure method.

Action: Implement disclosure banners/messages in all AI-facing interfaces. Integrate witnessTransparency() to mint an anchor for each disclosure event.

Active August 2

2. Synthetic Content Labeling (Art. 50(2))

Obligation: Mark AI-generated content (text, image, audio, video) in machine-readable format.

Omnibus update: For AI systems placed on the market or put into service before August 2, 2026, the machine-readable marking obligation is postponed to December 2, 2026. New systems deployed on or after August 2 must comply immediately.

SWT3 procedure: AI-MARK.1 -- witnesses content provenance marking with content type, marking method, and verification status.

Action: Implement C2PA/IPTC metadata injection or equivalent machine-readable marking. Use witnessContentMarking() to anchor each marking event. If your system predates August 2, begin implementation now for the December 2 deadline.

Active August 2

3. Deepfake Disclosure (Art. 50(4))

Obligation: Disclose when AI-generated content resembles real persons, objects, places, or events.

SWT3 procedure: AI-TRANS.1 + AI-WATERMARK.1 -- transparency disclosure plus watermark/provenance marking.

Action: Add disclosure labels to all synthetic media outputs. Watermark detection should be automated where possible.

Active August 2

4. Emotion Recognition Notice (Art. 50(3))

Obligation: Inform exposed persons when emotion recognition or biometric categorization is in use.

SWT3 procedure: AI-TRANS.1 + AI-CONSENT.1 -- transparency disclosure plus consent/legal basis verification.

Action: If your system uses emotion or biometric analysis, implement real-time disclosure. Verify GDPR legal basis via witnessConsent().

Active August 2 (GPAI providers only)

5. Technical Documentation (Art. 53(1)(a))

Obligation: Maintain up-to-date technical documentation following Annex XI templates.

SWT3 procedure: AI-MDL.1 + AI-MDL.5 -- model registry integrity plus weight provenance attestation.

Action: Document model architecture, training methodology, evaluation results, and known limitations. Use witnessModelWeights() to anchor weight hashes and version identifiers.

Active August 2 (GPAI providers only)

6. Downstream Provider Information (Art. 53(1)(b))

Obligation: Provide integrators with documentation of model capabilities, limitations, and intended use.

SWT3 procedure: AI-SBOM.1 + AI-CHAIN.1 -- AI software bill of materials plus supply chain attestation.

Action: Publish model cards or equivalent documentation. Use witnessAISBOM() to cryptographically anchor the documentation version provided to each downstream integrator.

Active August 2 (GPAI providers only)

7. Copyright Compliance Policy (Art. 53(1)(c))

Obligation: Establish and follow a policy to comply with EU copyright law, including TDM opt-out mechanisms.

SWT3 procedure: AI-DATA.1 + AI-LIC.1 -- training data provenance plus licensing attestation.

Action: Document data sourcing policies. Implement TDM opt-out compliance (robots.txt, ai.txt). Use witnessDataProvenance() to anchor dataset licensing status.

Active August 2 (GPAI providers only)

8. Training Data Summary (Art. 53(1)(d))

Obligation: Publish a sufficiently detailed summary of training content per the AI Office template.

SWT3 procedure: AI-DATA.1 -- training data provenance with dataset identifier, provenance hash, and quality score.

Action: Prepare the training data summary using the AI Office template (published Q1 2026). Anchor the published version with witnessDataProvenance().

Active August 2 (non-EU GPAI providers)

9. EU Authorized Representative (Art. 54)

Obligation: Appoint an authorized representative established in the EU before making the model available.

SWT3 procedure: AI-GOV.1 -- governance structure attestation documenting the representative appointment.

Action: Engage an EU-based authorized representative. Document the appointment and scope of mandate.

Active August 2 (systemic risk GPAI only)

10. Systemic Risk Obligations (Art. 55)

Obligation: Model evaluation, adversarial testing, incident tracking, cybersecurity protections, and energy consumption reporting.

SWT3 procedures: AI-REDTEAM.1 + AI-ROBUST.1 + AI-INCIDENT.1 + AI-CYBER.1 + AI-ENV.1

Action: Conduct and document red team evaluations. Implement incident tracking. Report energy consumption per the AI Office template. Each obligation produces a separate anchor chain.

Deferred to December 2, 2027

11. Annex III High-Risk Obligations

Scope: Standalone high-risk AI in biometrics, critical infrastructure, employment, credit, law enforcement, migration, justice, democratic processes.

Action: Begin preparation now. Conformity assessment, risk management, and quality management obligations will apply. The Omnibus deferral provides additional preparation time, not exemption.

Deferred to August 2, 2028

12. Annex I High-Risk Obligations (Safety Components)

Scope: AI embedded as safety components in regulated products (medical devices, machinery, automotive, aviation).

Action: Coordinate with existing product safety certification processes. Notified Bodies will need to assess AI components under their existing mandates.

Grandfathered until August 2, 2027

13. Pre-Market GPAI Models

Scope: GPAI models on the EU market before August 2, 2025.

Action: Use the additional year to build technical documentation and training data summaries. Systemic risk classification applies immediately upon designation regardless of grandfathering.

6. Obligation-to-Procedure Mapping

AI Act ObligationArticleSWT3 ProcedureEvidence Produced
AI interaction disclosureArt. 50(1)AI-TRANS.1Disclosure type, recipient type, delivery timestamp
Synthetic content labelingArt. 50(2)AI-MARK.1Content type, marking method, verification status
Emotion/biometric noticeArt. 50(3)AI-TRANS.1 + AI-CONSENT.1Disclosure delivery + consent type and legal basis
Deepfake disclosureArt. 50(4)AI-TRANS.1 + AI-WATERMARK.1Disclosure delivery + watermark provenance
GPAI technical docsArt. 53(1)(a)AI-MDL.1 + AI-MDL.5Model hash, version, weight provenance
Downstream infoArt. 53(1)(b)AI-SBOM.1 + AI-CHAIN.1Component manifest, supply chain attestation
Copyright policyArt. 53(1)(c)AI-DATA.1 + AI-LIC.1Data provenance hash, licensing status
Training data summaryArt. 53(1)(d)AI-DATA.1Dataset identifier, provenance hash, quality score
EU representativeArt. 54AI-GOV.1Governance structure, representative appointment
Systemic risk: evaluationArt. 55(1)(a)AI-REDTEAM.1Test scope, methodology, findings severity
Systemic risk: robustnessArt. 55(1)(a)AI-ROBUST.1Adversarial test type, pass/fail, attack vector
Systemic risk: incidentsArt. 55(1)(b)AI-INCIDENT.1Incident type, severity, time to report
Systemic risk: cybersecurityArt. 55(1)(c)AI-CYBER.1Control domain, assessment result, framework
Systemic risk: energyArt. 55(1)(d)AI-ENV.1Energy metric, measurement scope, reporting period

7. Detailed Procedure Cards

AI-TRANS.1

Transparency Disclosure

AI Act requires (Art. 50(1)): Deployers must ensure that natural persons are informed they are interacting with an AI system in a timely, clear, and intelligible manner, unless this is obvious from the circumstances and context of use.

How SWT3 addresses it: The witnessTransparency() call mints an anchor recording the disclosure type (AI interaction notification, synthetic content label, deepfake disclosure), recipient type (end user, data subject, general public), and delivery timestamp. The anchor proves the disclosure was generated and delivered before or at the point of AI interaction.

What to show the examiner

Query AI-TRANS.1 anchors filtered by time range. Each anchor's timestamp proves disclosure occurred. For Art. 50(1), the AI-TRANS.1 anchor must predate or be concurrent with the corresponding AI-INF.1 anchor for the same session. Gap analysis: any AI-INF.1 anchor without a preceding AI-TRANS.1 indicates a transparency gap.

AI-MARK.1

Content Provenance Marking

AI Act requires (Art. 50(2)): Providers must ensure synthetic content is marked in a machine-readable format and detectable as AI-generated. This applies to text, images, audio, and video outputs.

How SWT3 addresses it: The witnessContentMarking() call records the content type (text, image, audio, video), the marking method (C2PA metadata, IPTC, watermark, header), and verification status. Each output generation produces an anchor proving the provenance marking was applied.

What to show the examiner

AI-MARK.1 anchors should correlate 1:1 with AI-INF.1 anchors for content-generating models. Factor A (content type) identifies what was generated. Factor B (marking method) proves the technical mechanism. If using C2PA, the Content Credential can be cross-referenced with the SWT3 anchor for dual provenance.

AI-MDL.1 + AI-MDL.5

Model Registry and Weight Provenance (GPAI)

AI Act requires (Art. 53(1)(a)): GPAI providers must maintain technical documentation of the model, including training processes, evaluation results, and model architecture.

How SWT3 addresses it: witnessModelRegistry() anchors the deployed model hash against an approved registry, proving the model in production matches the documented version. witnessModelWeights() records the weight file hash, version identifier, and provenance chain. Together they create a verifiable link between documentation and deployed artifact.

What to show the examiner

AI-MDL.1 anchors prove model identity. AI-MDL.5 anchors prove weight integrity. The hash chain from documentation to deployment must be unbroken. Any weight modification without a corresponding AI-MDL.5 anchor indicates an undocumented model change.

AI-DATA.1

Training Data Provenance (GPAI)

AI Act requires (Art. 53(1)(c-d)): GPAI providers must maintain copyright compliance policies and publish training data summaries. Data sourcing must respect TDM opt-out rights.

How SWT3 addresses it: The witnessDataProvenance() call captures the dataset identifier, a SHA-256 hash of the dataset, and a quality/licensing score. This creates an immutable record of what data was used, when it was verified, and whether licensing obligations were met at the time of training.

What to show the examiner

AI-DATA.1 anchors should predate AI-INF.1 anchors for the model, proving data governance occurred before deployment. Factor A identifies the dataset. Factor B (hash) proves the dataset has not been modified post-assessment. For copyright compliance, cross-reference with AI-LIC.1 anchors to show licensing verification was completed.

8. Quick Reference

Examiner QuestionWhere to Look
Do you disclose AI interaction to users?AI-TRANS.1 anchors. Timestamp must predate or match the AI-INF.1 anchor for the same session. Gap: any inference without a preceding disclosure.
How do you label synthetic content?AI-MARK.1 anchors. Factor B identifies the marking method (C2PA, watermark, IPTC). Should correlate 1:1 with content-generating AI-INF.1 anchors.
Where is your GPAI technical documentation?AI-MDL.1 + AI-MDL.5 anchors. Hash chain from documentation to deployed model weights. AI-SBOM.1 for component manifest.
How do you comply with copyright/TDM obligations?AI-DATA.1 + AI-LIC.1 anchors. Data provenance hashes prove dataset identity. Licensing attestation proves TDM compliance was verified.
Do you have an EU authorized representative?AI-GOV.1 anchor documenting the appointment. Cross-reference with the representative's contact details in the AI database registration.
How do you handle systemic risk?AI-REDTEAM.1 (evaluation), AI-ROBUST.1 (adversarial testing), AI-INCIDENT.1 (incident tracking), AI-CYBER.1 (cybersecurity), AI-ENV.1 (energy). Each produces an independent anchor chain.
Are your GPAI models grandfathered?If the model was on market before Aug 2, 2025: compliance deadline is Aug 2, 2027. Check AI-INF.1 anchor history to establish market presence date.

9. Quick Start

# Install the SDK
pip install swt3-ai

# Initialize with the EU AI Act profile
swt3 init --profile eu-ai-act --tenant YOUR_TENANT

# Run the demo to see Art. 50 transparency anchors
python -m swt3_ai.demo

# Or use TypeScript
npm install @tenova/swt3-ai
npx swt3-init --profile eu-ai-act

Full SDK documentation: sovereign.tenova.io/docs

Create a free account: sovereign.tenova.io/signup

10. References