Who this is for: AI compliance leads, DPOs, GPAI model providers, AI deployers operating in the EU, and GRC architects preparing for the August 2, 2026 enforcement milestone.
Enforcement begins August 2, 2026. Art. 50 transparency obligations and GPAI provider requirements become enforceable by the AI Office. Fines for non-compliance: up to 15 million EUR or 3% of global annual turnover for GPAI violations; up to 35 million EUR or 7% for prohibited practices. The European Commission's AI Office is the sole enforcer for GPAI obligations. National market surveillance authorities enforce Art. 50 transparency requirements.
Contents
1. Full Enforcement Timeline 2. What Activates August 2, 2026 3. What Was Deferred by the Omnibus 4. GPAI Grandfathering Rules 5. August 2 Compliance Checklist 6. Obligation-to-Procedure Mapping 7. Detailed Procedure Cards 8. Quick Reference 9. Quick Start 10. References1. Full Enforcement Timeline
The EU AI Act entered into force on August 1, 2024, with obligations phased in over four years. The Omnibus Amendment (political agreement May 7, 2026; Parliament endorsed June 16; Council adopted June 29) modified several deadlines for high-risk AI systems. Official Journal publication is imminent.
Prohibited AI practices (Art. 5) became enforceable. Social scoring, real-time biometric surveillance (with exceptions), subliminal manipulation, and exploitation of vulnerable groups are banned.
AI literacy requirements (Art. 4) took effect. AI governance structures must be in place. Codes of Practice for GPAI published.
Art. 50 transparency obligations + GPAI provider requirements enforceable. This is the current milestone.
GPAI grandfathering ends for models on market before August 2, 2025. High-risk Annex III systems (original deadline, now deferred -- see below).
Omnibus new deadline: High-risk AI obligations for Annex III systems (was August 2, 2027).
Omnibus new deadline: High-risk AI obligations for Annex I systems (safety components in regulated products). Full enforcement of all AI Act provisions.
2. What Activates August 2, 2026
Two categories of obligations become enforceable on this date:
Art. 50: Transparency Obligations for All AI Systems
- AI interaction disclosure (Art. 50(1)): Deployers must inform natural persons that they are interacting with an AI system, unless this is obvious from the circumstances. Applies to chatbots, virtual assistants, and any conversational AI.
- Synthetic content labeling (Art. 50(2)): Providers of AI systems that generate synthetic audio, image, video, or text content must ensure outputs are marked in a machine-readable format and are detectable as artificially generated.
- Deepfake disclosure (Art. 50(4)): Deployers who use AI to generate or manipulate image, audio, or video content that resembles real persons, objects, places, or events must disclose that the content has been artificially generated or manipulated.
- Emotion recognition / biometric categorization (Art. 50(3)): Deployers of emotion recognition or biometric categorization systems must inform exposed natural persons and process personal data in compliance with GDPR, LED, and EUDPR.
GPAI: General-Purpose AI Model Provider Obligations
- Technical documentation (Art. 53(1)(a)): GPAI providers must draw up and keep up to date technical documentation of the model, including training and testing processes and evaluation results, following templates in Annex XI.
- Information for downstream providers (Art. 53(1)(b)): Provide information and documentation to downstream AI system providers integrating the GPAI model, enabling them to understand capabilities and limitations and comply with their own obligations.
- Copyright compliance (Art. 53(1)(c)): Put in place a policy to comply with EU copyright law, including the Text and Data Mining Directive (Art. 4(3) of Directive 2019/790).
- Training data summary (Art. 53(1)(d)): Publish a sufficiently detailed summary of the content used for training the GPAI model, according to the template provided by the AI Office.
- EU representative (Art. 54): GPAI providers established outside the EU must appoint an authorized representative in the Union before making their model available.
- Systemic risk obligations (Art. 55): GPAI models classified as posing systemic risk face additional requirements: model evaluations, adversarial testing, incident tracking, cybersecurity protections, and energy consumption reporting.
3. What Was Deferred by the Omnibus
Omnibus Amendment (formally adopted June 2026): The European Parliament endorsed the AI Act Omnibus Amendment on June 16, 2026, and the Council gave final green light on June 29, 2026. The amendment defers high-risk AI system obligations and delays the Art. 50(2) machine-readable marking requirement for pre-existing systems to December 2, 2026. This does NOT affect Art. 50 transparency (interaction disclosure, deepfake disclosure) or GPAI obligations, which remain on the August 2, 2026 schedule.
| What Was Deferred | Original Deadline | New Deadline | Scope |
|---|---|---|---|
| Annex III high-risk AI | August 2, 2027 | December 2, 2027 | Standalone high-risk AI systems (biometrics, critical infrastructure, employment, credit, law enforcement, migration, justice, democratic processes) |
| Annex I high-risk AI | August 2, 2027 | August 2, 2028 | AI as safety components in regulated products (machinery, medical devices, aviation, automotive, toys, marine equipment, rail) |
Not deferred (still August 2, 2026): Art. 50 transparency, GPAI obligations, AI Office enforcement powers, notification of GPAI models with systemic risk, Codes of Practice.
4. GPAI Grandfathering Rules
GPAI models that were already on the EU market before August 2, 2025 receive a transitional period:
- Compliance deadline: August 2, 2027 (two years from the grandfathering cutoff, one year after enforcement begins)
- Scope: All Art. 53 obligations (technical documentation, downstream provider information, copyright policy, training data summary)
- Exclusion: Models placed on the market after August 2, 2025 must comply from August 2, 2026 (no grandfathering)
- Systemic risk: If a grandfathered model is classified as posing systemic risk, Art. 55 obligations apply from the classification date, not from the general enforcement date
5. August 2 Compliance Checklist
Each checklist item maps to a specific obligation, SWT3 procedure, and the evidence artifact you need to produce.
1. AI Interaction Disclosure (Art. 50(1))
Obligation: Inform users they are interacting with AI before or at the start of interaction.
SWT3 procedure: AI-TRANS.1 -- witnesses disclosure delivery with timestamp, recipient type, and disclosure method.
Action: Implement disclosure banners/messages in all AI-facing interfaces. Integrate witnessTransparency() to mint an anchor for each disclosure event.
2. Synthetic Content Labeling (Art. 50(2))
Obligation: Mark AI-generated content (text, image, audio, video) in machine-readable format.
Omnibus update: For AI systems placed on the market or put into service before August 2, 2026, the machine-readable marking obligation is postponed to December 2, 2026. New systems deployed on or after August 2 must comply immediately.
SWT3 procedure: AI-MARK.1 -- witnesses content provenance marking with content type, marking method, and verification status.
Action: Implement C2PA/IPTC metadata injection or equivalent machine-readable marking. Use witnessContentMarking() to anchor each marking event. If your system predates August 2, begin implementation now for the December 2 deadline.
3. Deepfake Disclosure (Art. 50(4))
Obligation: Disclose when AI-generated content resembles real persons, objects, places, or events.
SWT3 procedure: AI-TRANS.1 + AI-WATERMARK.1 -- transparency disclosure plus watermark/provenance marking.
Action: Add disclosure labels to all synthetic media outputs. Watermark detection should be automated where possible.
4. Emotion Recognition Notice (Art. 50(3))
Obligation: Inform exposed persons when emotion recognition or biometric categorization is in use.
SWT3 procedure: AI-TRANS.1 + AI-CONSENT.1 -- transparency disclosure plus consent/legal basis verification.
Action: If your system uses emotion or biometric analysis, implement real-time disclosure. Verify GDPR legal basis via witnessConsent().
5. Technical Documentation (Art. 53(1)(a))
Obligation: Maintain up-to-date technical documentation following Annex XI templates.
SWT3 procedure: AI-MDL.1 + AI-MDL.5 -- model registry integrity plus weight provenance attestation.
Action: Document model architecture, training methodology, evaluation results, and known limitations. Use witnessModelWeights() to anchor weight hashes and version identifiers.
6. Downstream Provider Information (Art. 53(1)(b))
Obligation: Provide integrators with documentation of model capabilities, limitations, and intended use.
SWT3 procedure: AI-SBOM.1 + AI-CHAIN.1 -- AI software bill of materials plus supply chain attestation.
Action: Publish model cards or equivalent documentation. Use witnessAISBOM() to cryptographically anchor the documentation version provided to each downstream integrator.
7. Copyright Compliance Policy (Art. 53(1)(c))
Obligation: Establish and follow a policy to comply with EU copyright law, including TDM opt-out mechanisms.
SWT3 procedure: AI-DATA.1 + AI-LIC.1 -- training data provenance plus licensing attestation.
Action: Document data sourcing policies. Implement TDM opt-out compliance (robots.txt, ai.txt). Use witnessDataProvenance() to anchor dataset licensing status.
8. Training Data Summary (Art. 53(1)(d))
Obligation: Publish a sufficiently detailed summary of training content per the AI Office template.
SWT3 procedure: AI-DATA.1 -- training data provenance with dataset identifier, provenance hash, and quality score.
Action: Prepare the training data summary using the AI Office template (published Q1 2026). Anchor the published version with witnessDataProvenance().
9. EU Authorized Representative (Art. 54)
Obligation: Appoint an authorized representative established in the EU before making the model available.
SWT3 procedure: AI-GOV.1 -- governance structure attestation documenting the representative appointment.
Action: Engage an EU-based authorized representative. Document the appointment and scope of mandate.
10. Systemic Risk Obligations (Art. 55)
Obligation: Model evaluation, adversarial testing, incident tracking, cybersecurity protections, and energy consumption reporting.
SWT3 procedures: AI-REDTEAM.1 + AI-ROBUST.1 + AI-INCIDENT.1 + AI-CYBER.1 + AI-ENV.1
Action: Conduct and document red team evaluations. Implement incident tracking. Report energy consumption per the AI Office template. Each obligation produces a separate anchor chain.
11. Annex III High-Risk Obligations
Scope: Standalone high-risk AI in biometrics, critical infrastructure, employment, credit, law enforcement, migration, justice, democratic processes.
Action: Begin preparation now. Conformity assessment, risk management, and quality management obligations will apply. The Omnibus deferral provides additional preparation time, not exemption.
12. Annex I High-Risk Obligations (Safety Components)
Scope: AI embedded as safety components in regulated products (medical devices, machinery, automotive, aviation).
Action: Coordinate with existing product safety certification processes. Notified Bodies will need to assess AI components under their existing mandates.
13. Pre-Market GPAI Models
Scope: GPAI models on the EU market before August 2, 2025.
Action: Use the additional year to build technical documentation and training data summaries. Systemic risk classification applies immediately upon designation regardless of grandfathering.
6. Obligation-to-Procedure Mapping
| AI Act Obligation | Article | SWT3 Procedure | Evidence Produced |
|---|---|---|---|
| AI interaction disclosure | Art. 50(1) | AI-TRANS.1 | Disclosure type, recipient type, delivery timestamp |
| Synthetic content labeling | Art. 50(2) | AI-MARK.1 | Content type, marking method, verification status |
| Emotion/biometric notice | Art. 50(3) | AI-TRANS.1 + AI-CONSENT.1 | Disclosure delivery + consent type and legal basis |
| Deepfake disclosure | Art. 50(4) | AI-TRANS.1 + AI-WATERMARK.1 | Disclosure delivery + watermark provenance |
| GPAI technical docs | Art. 53(1)(a) | AI-MDL.1 + AI-MDL.5 | Model hash, version, weight provenance |
| Downstream info | Art. 53(1)(b) | AI-SBOM.1 + AI-CHAIN.1 | Component manifest, supply chain attestation |
| Copyright policy | Art. 53(1)(c) | AI-DATA.1 + AI-LIC.1 | Data provenance hash, licensing status |
| Training data summary | Art. 53(1)(d) | AI-DATA.1 | Dataset identifier, provenance hash, quality score |
| EU representative | Art. 54 | AI-GOV.1 | Governance structure, representative appointment |
| Systemic risk: evaluation | Art. 55(1)(a) | AI-REDTEAM.1 | Test scope, methodology, findings severity |
| Systemic risk: robustness | Art. 55(1)(a) | AI-ROBUST.1 | Adversarial test type, pass/fail, attack vector |
| Systemic risk: incidents | Art. 55(1)(b) | AI-INCIDENT.1 | Incident type, severity, time to report |
| Systemic risk: cybersecurity | Art. 55(1)(c) | AI-CYBER.1 | Control domain, assessment result, framework |
| Systemic risk: energy | Art. 55(1)(d) | AI-ENV.1 | Energy metric, measurement scope, reporting period |
7. Detailed Procedure Cards
Transparency Disclosure
AI Act requires (Art. 50(1)): Deployers must ensure that natural persons are informed they are interacting with an AI system in a timely, clear, and intelligible manner, unless this is obvious from the circumstances and context of use.
How SWT3 addresses it: The witnessTransparency() call mints an anchor recording the disclosure type (AI interaction notification, synthetic content label, deepfake disclosure), recipient type (end user, data subject, general public), and delivery timestamp. The anchor proves the disclosure was generated and delivered before or at the point of AI interaction.
Query AI-TRANS.1 anchors filtered by time range. Each anchor's timestamp proves disclosure occurred. For Art. 50(1), the AI-TRANS.1 anchor must predate or be concurrent with the corresponding AI-INF.1 anchor for the same session. Gap analysis: any AI-INF.1 anchor without a preceding AI-TRANS.1 indicates a transparency gap.
Content Provenance Marking
AI Act requires (Art. 50(2)): Providers must ensure synthetic content is marked in a machine-readable format and detectable as AI-generated. This applies to text, images, audio, and video outputs.
How SWT3 addresses it: The witnessContentMarking() call records the content type (text, image, audio, video), the marking method (C2PA metadata, IPTC, watermark, header), and verification status. Each output generation produces an anchor proving the provenance marking was applied.
AI-MARK.1 anchors should correlate 1:1 with AI-INF.1 anchors for content-generating models. Factor A (content type) identifies what was generated. Factor B (marking method) proves the technical mechanism. If using C2PA, the Content Credential can be cross-referenced with the SWT3 anchor for dual provenance.
Model Registry and Weight Provenance (GPAI)
AI Act requires (Art. 53(1)(a)): GPAI providers must maintain technical documentation of the model, including training processes, evaluation results, and model architecture.
How SWT3 addresses it: witnessModelRegistry() anchors the deployed model hash against an approved registry, proving the model in production matches the documented version. witnessModelWeights() records the weight file hash, version identifier, and provenance chain. Together they create a verifiable link between documentation and deployed artifact.
AI-MDL.1 anchors prove model identity. AI-MDL.5 anchors prove weight integrity. The hash chain from documentation to deployment must be unbroken. Any weight modification without a corresponding AI-MDL.5 anchor indicates an undocumented model change.
Training Data Provenance (GPAI)
AI Act requires (Art. 53(1)(c-d)): GPAI providers must maintain copyright compliance policies and publish training data summaries. Data sourcing must respect TDM opt-out rights.
How SWT3 addresses it: The witnessDataProvenance() call captures the dataset identifier, a SHA-256 hash of the dataset, and a quality/licensing score. This creates an immutable record of what data was used, when it was verified, and whether licensing obligations were met at the time of training.
AI-DATA.1 anchors should predate AI-INF.1 anchors for the model, proving data governance occurred before deployment. Factor A identifies the dataset. Factor B (hash) proves the dataset has not been modified post-assessment. For copyright compliance, cross-reference with AI-LIC.1 anchors to show licensing verification was completed.
8. Quick Reference
| Examiner Question | Where to Look |
|---|---|
| Do you disclose AI interaction to users? | AI-TRANS.1 anchors. Timestamp must predate or match the AI-INF.1 anchor for the same session. Gap: any inference without a preceding disclosure. |
| How do you label synthetic content? | AI-MARK.1 anchors. Factor B identifies the marking method (C2PA, watermark, IPTC). Should correlate 1:1 with content-generating AI-INF.1 anchors. |
| Where is your GPAI technical documentation? | AI-MDL.1 + AI-MDL.5 anchors. Hash chain from documentation to deployed model weights. AI-SBOM.1 for component manifest. |
| How do you comply with copyright/TDM obligations? | AI-DATA.1 + AI-LIC.1 anchors. Data provenance hashes prove dataset identity. Licensing attestation proves TDM compliance was verified. |
| Do you have an EU authorized representative? | AI-GOV.1 anchor documenting the appointment. Cross-reference with the representative's contact details in the AI database registration. |
| How do you handle systemic risk? | AI-REDTEAM.1 (evaluation), AI-ROBUST.1 (adversarial testing), AI-INCIDENT.1 (incident tracking), AI-CYBER.1 (cybersecurity), AI-ENV.1 (energy). Each produces an independent anchor chain. |
| Are your GPAI models grandfathered? | If the model was on market before Aug 2, 2025: compliance deadline is Aug 2, 2027. Check AI-INF.1 anchor history to establish market presence date. |
9. Quick Start
pip install swt3-ai
# Initialize with the EU AI Act profile
swt3 init --profile eu-ai-act --tenant YOUR_TENANT
# Run the demo to see Art. 50 transparency anchors
python -m swt3_ai.demo
# Or use TypeScript
npm install @tenova/swt3-ai
npx swt3-init --profile eu-ai-act
Full SDK documentation: sovereign.tenova.io/docs
Create a free account: sovereign.tenova.io/signup
10. References
- EU AI Act (Regulation 2024/1689) -- Official Journal of the European Union, August 1, 2024
- European Commission AI Act Hub -- Implementation guidance and templates
- AI Office -- GPAI enforcement authority, Codes of Practice, systemic risk designation
- EU AI Act Full Crosswalk -- Comprehensive obligation mapping (all articles)
- GPAI Code of Practice Crosswalk -- CoP commitments mapped to SWT3 procedures
- FRIA/DPIA Evidence Mapping -- Art. 27 + Art. 35 impact assessment evidence
- SWT3 UCT Registry -- 106 AI procedures across 55 namespaces
- SWT3 Bidirectional Framework Crosswalks -- machine-readable JSON, 28 frameworks
- SDK Documentation -- Python, TypeScript, and 5 additional language SDKs