← All Insights
Technology Law

The AI Act in August 2026: What Applied and What Slipped

YARD Law Co. · Reviewed 19 August 2026  ·  YARD Law Legal Team

The obligations for high-risk AI systems were due to bite on 2 August 2026. Six days before that date, Regulation (EU) 2026/1744 postponed them. That is not the news that matters for most Bulgarian firms, however - because another part of the Regulation arrived exactly on schedule and is now enforceable.

What did Regulation (EU) 2026/1744 postpone?

The Regulation, known as the Digital Omnibus for artificial intelligence, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.

Two groups of obligations were deferred:

  • for standalone high-risk systems under Annex III - from 2 August 2026 to 2 December 2027;
  • for high-risk AI embedded in products covered by Union product legislation under Annex I - to 2 August 2028.

Annex III covers uses that look entirely ordinary. Recruitment is among them. If you use AI to screen CVs or to score candidates, you are operating in a sensitive area regardless of the size of your firm. The heavy obligations on that front genuinely have slipped. But the postponement moves the deadline, not the responsibility, and supervisory authorities name this very area among the first they intend to watch.

What arrived on schedule?

This is the more important part, and it gets missed because the July headlines were all about the delay.

The Article 50 transparency obligations apply from 2 August 2026. Chatbots must identify themselves as machines to the people they talk to. Deepfake-type content must be labelled as artificially generated or manipulated. The European Commission published its guidelines on the interpretation of Article 50 on 20 July 2026, less than two weeks before the deadline, accompanied by a Code of Practice on the marking and labelling of AI-generated content.

The obligations on providers of general-purpose AI models have applied since 2 August 2025, including the copyright policy and the training-data summary. What is new from 2 August 2026 is that the Commission now has powers to impose penalties.

The Article 5 prohibitions have applied since 2 February 2025, as has the AI literacy duty under Article 4.

The practical consequence: from 2 August 2026, breaches of the transparency requirements in force and of the general-purpose model obligations can be penalised, not merely noted.

Is there a grace period for watermarking?

Yes, but a partial one, and the distinction matters.

Article 50(2) requires providers of generative systems to embed machine-readable marking in synthetic text, audio, images and video - a technical signal allowing specialised software to establish reliably that content was created or substantially modified by AI.

For systems placed on the market before 2 August 2026, that specific obligation applies from 2 December 2026. For systems placed on the market after that date there is no grace period at all. In practice the transitional window covers almost every service in use today.

The reprieve is narrow in two further senses. It covers only the technical embedding by the provider - visible labelling and the disclosure duties are not deferred. And content generated before 2 August 2026 is not subject to retroactive marking, though the Commission encourages applying it backwards where that is practicable.

As a deployer you do not owe the embedding of a watermark. But nor should you strip embedded signals out of content you publish.

What new prohibitions does the Regulation add?

Regulation (EU) 2026/1744 does not only postpone. It widens the list of prohibited practices under Article 5 with effect from 2 December 2026, adding AI systems for creating non-consensual intimate content - so-called "nudify" applications - and for generating child sexual abuse material.

It also provides reliefs for small mid-cap enterprises, defined as companies with up to 750 employees, and a strengthened role for the European AI Office in relation to systems built on general-purpose models.

What does this mean for a Bulgarian business?

Picture a law firm or an accountancy practice of fifteen people. Nobody there develops an AI system. But half the team uses generative tools every day - for summaries, draft letters, research.

Such a business barely touches the postponed high-risk rules. It falls squarely within Article 4, because its people use AI in their daily work. The AI literacy duty has not been deferred and does not depend on the size of the firm.

If the firm runs a client-facing chatbot, it also falls within Article 50 from 2 August 2026. If it publishes generated content, it owes labelling under the same article.

Postponing the high-risk obligations gives time to prepare to those who genuinely fall within Annex III - in recruitment, for example. It does not give grounds to postpone the subject.

Who supervises this in Bulgaria?

Here the position is less settled than at European level, and that should be said plainly.

The Regulation applies directly - being a regulation, it needs no transposition. Enforcement, however, is shared between the European Commission and the national supervisory authorities designated by the Member States. At European level, oversight of general-purpose models sits with the AI Office within the Commission.

The lead department for implementation in Bulgaria is the Ministry of e-Government. The Ministry's position is that supervision of high-risk systems should be assigned to existing specialised regulators rather than by creating new administrative structures. An interdepartmental working group was tasked with proposing a national legal framework by 31 March 2026.

The national supervisory and penalty layer is still being built. Before assessing a specific exposure, check against primary sources which bodies have been designated as market surveillance authority and notifying authority within the meaning of Art. 70 of Regulation (EU) 2024/1689, and whether a national penalty regime under Art. 99 has been adopted. This matters in practice: the European rules apply directly, but national enforcement depends on those decisions.

Penalty levels at European level are tiered: the highest threshold applies to breaches of the Article 5 prohibitions, while breaches of the transparency duties and of the obligations on providers of general-purpose models fall into a lower band. The specific thresholds in Art. 99 should be taken from the primary text of the Regulation as currently in force.

What to do now

Three concrete steps, in order of urgency:

  1. Article 4. Establish who in the firm uses generative tools and for what. Provide basic training and document it. This obligation has applied since February 2025 and is both the easiest to satisfy and the easiest for a regulator to spot.
  2. Article 50. If you have a chatbot, it must present itself as a machine. If you publish generated content, it must be labelled. Check your supplier contracts too: who is responsible for the embedded machine-readable marking, and from what date.
  3. Annex III. Review whether any of your uses falls within the high-risk categories, above all in recruitment. If it does, you have until 2 December 2027. That is not long for a conformity assessment, documentation and human oversight.

Frequently asked questions

Have the AI Act obligations been postponed?

Only for high-risk systems. For Annex III the deadline is 2 December 2027, and for high-risk AI embedded in products under Annex I it is 2 August 2028.

What applies from 2 August 2026?

The Article 50 transparency obligations and the powers to impose penalties, including in relation to providers of general-purpose AI models.

Is there a grace period for watermarking?

For systems placed on the market before 2 August 2026, the machine-readable marking under Article 50(2) applies from 2 December 2026. For newer systems there is no grace period.

Does it affect me if I only use ChatGPT?

Yes. The AI literacy duty under Article 4 has applied since February 2025 and has not been postponed.

Who is the supervisory authority in Bulgaria?

At European level, general-purpose models sit with the Commission's AI Office. The national framework is still being built, with the Ministry of e-Government as lead department.

This article states the position as at 19 August 2026, following the entry into force of Regulation (EU) 2026/1744. It is general information and does not constitute legal advice. Prepared by the legal team at YARD Law Co., a law firm based in Sofia, Bulgaria.

Need your AI Act exposure assessed?

Article 4 and team training, Article 50 and labelling, an Annex III review and your contracts with AI suppliers.