EU AI Act, August 2, 2026: What Changes for B2B Companies and Their Vendor Risk Evaluations
AI interaction notices, synthetic media labels, and deepfake duties are now enforceable. Here's what the EU AI Act's August 2026 phase means for your vendor risk evaluations.

The EU AI Act has been rolling out in phases since it entered into force in August 2024.
- February 2025 — General provisions and prohibitions
- August 2025 — Rules for general purpose AI models and the governance structure
- August 2, 2026 — The majority of the remaining rules come into force, and enforcement starts for everything applicable so far.
This is not the finish line. The full rollout, including the bulk of high-risk system obligations, has been pushed out to August 2028 under the Digital Omnibus on AI amendments.
But three things are live starting now, and they matter for any B2B company using or building AI.
What Took Effect on August 2, 2026
AI Interaction Notice
If your company has any AI system that talks to employees or customers, the AI interaction disclosure rule now applies. A support chatbot, an internal AI agent, anything with a direct back and forth with a person, has to make clear it is AI, unless that is already obvious from context.
Synthetic Media Labels
If your company generates content with AI, image, audio, video, or text, that content now needs a machine readable marking showing it was AI generated. This sits with whoever built the generation capability. If you built it in-house, that is you. If you licensed the capability from someone else, that duty sits with them.
Deepfake and Public Content Duties
If your company publishes AI generated output, a separate duty can apply regardless of who built the underlying model. Publishing a deepfake, or AI generated text meant to inform the public on a matter of public interest, is a deployer duty tied to whoever puts the content out. The exception is where a human has actually reviewed the content and someone holds editorial responsibility for the publication, since at that point a person, not the AI system, is accountable for what got published.
Enforcement Activation
Separately, enforcement itself just turned on. National authorities can now act on the AI literacy duty and the banned practices list, both of which have technically existed since February 2025 but lacked a working regulator behind them. General purpose AI models now answer to the AI Office directly, not to national authorities, with real power to demand documentation and issue fines.
What This Means for Vendor Due Diligence
As the next phase of the EU AI Act takes effect, here are a few things to add to your TPRM checklist.
- Where are your vendors on the provider or deployer split? Ask them to name it directly. A vendor that generates content is a provider under Article 50(2). A vendor that publishes AI generated content on your behalf, or that you rely on to publish it, may be pulling you into deployer obligations too. Get this mapped before you get into anything else.
- Can they show the disclosure, not describe it? Ask for a live example or evidence, like a chatbot notice, content label, deepfake acknowledgment. A vendor that only has a policy paragraph on this has not built it yet.
- What is their machine readable marking method? Ask specifically if it’s C2PA, watermarking, metadata tagging, or some combination. Then ask what survives a screenshot or a re-upload. If they have not thought about that, the marking probably will not hold up either.
- If they build on a general purpose model, do they know who regulates it? Their model provider now answers to the AI Office directly. It’s worth knowing before something upstream breaks and you need to figure out who is accountable.
- Do they know their own scope, or are they claiming broad compliance? "We are AI Act compliant" usually means one product line touches these obligations, not the whole platform. Push for specifics on which systems the disclosure and marking rules actually apply to.
The one line worth carrying into every vendor call from here: know whether they are the provider, the deployer, or both, and know which one that makes you.



