2 August: the three AI Act obligations taking effect at once
The timetable of Regulation (EU) 2024/1689 on Artificial Intelligence (the “AI Act”) allows for no respite. On 2 August 2026, three obligations of a different nature come into effect simultaneously, yet share a common denominator: they cease to be a regulatory horizon and become enforceable law, backed by genuine sanctioning powers. For operators that deploy, distribute or develop AI systems in Spain, this date carries more legal risk than its comparatively modest media coverage would suggest.
Which AI Act obligations take effect on 2 August?
It is worth pinning down precisely what actually falls due on that date, since not everything discussed this summer in relation to European AI regulation coincides with this deadline.
The Digital Omnibus Package, approved by the European Parliament on 15 June, has pushed back to later dates certain obligations originally scheduled for August 2026 — the most frequently cited example being the marking of synthetic content (watermarking), deferred to 2 December 2026.
What does remain in effect as of 2 August are three specific obligations: (i) the bulk of the transparency obligations under Article 50 of the Regulation; (ii) the full enforcement regime over providers of general-purpose AI (GPAI) models; and (iii) the obligation on Member States to have at least one operational national regulatory sandbox in place.
Transparency towards users: the obligation that no longer admits any extension
Article 50 of the AI Act imposes information obligations on providers and deployers towards persons who interact with AI systems or are exposed to their output: informing individuals that they are interacting with an AI system where this is not otherwise apparent from the context, flagging where content — text, image, audio or video — has been artificially generated or manipulated, and disclosing the use of emotion-recognition or biometric-categorisation systems.
This general obligation should not be conflated with the technical marking standard (machine-readable watermarking), full enforceability of which the Commission has deferred to 2 December 2026 under the Omnibus. What takes effect on 2 August is the substantive duty of transparency; the technical standard for implementing it in relation to synthetic content follows later.
In practice, this already requires — not by December, but now — a review of user-interaction flows in customer service, conversational marketing and AI-assisted content generation.
GPAI: the margin of tolerance for large AI models is running out
The Code of Conduct for providers of general-purpose AI models, in force since August 2025 as a voluntary route to compliance with Articles 53 and 55 of the AI Act, sees its grace period expire on 2 August 2026. From that date, the European Commission holds full enforcement powers: requests for information, model audits and, in the most serious cases, market-withdrawal measures.
This obligation bears with particular intensity on models trained with more than 10²⁵ FLOPs of training compute — the threshold that places GPT, Claude, Gemini or Mistral within the systemic-risk regime — but it also casts an indirect effect over any company that integrates such models into its value chain: due diligence on the AI provider ceases to be a recommended good practice and becomes a matter of contractual and reputational exposure.
Regulatory sandboxes: Spain rolls out its testing ground for AI
The third element is institutional in nature. Each Member State must have operational, at minimum, one regulatory testing environment (sandbox) for AI systems before 2 August 2026. In Spain, this function falls to AESIA (the Spanish AI Supervisory Agency), with its definitive framework still pending completion of the parliamentary process on the draft Organic Law on the Good Use and Governance of Artificial Intelligence, whose amendment deadline expired precisely on 30 June.
The sandbox is not a mere gesture of support for innovation: it is the route the Regulation itself reserves for start-ups and SMEs to test high-risk AI systems under supervision, benefiting from the exemptions and flexibilities the AI Act envisages for this category of operator.
The convergence of these three obligations on a single date is no coincidence: the European legislature intended transparency towards users, control over model providers, and institutional support for innovation to advance at the same pace. For organisations operating in Spain, the practical message is clear: 2 August is not just another AI Act deferral — it is the first day on which the Regulation begins to deploy its full sanctioning force.

Candela Martín es abogada especialista en derecho digital, propiedad intelectual y protección de datos.
Graduada en Derecho por la Universidad de Granada, completó un doble máster en acceso a la abogacía y derecho digital en la Universidad de Navarra. Su práctica se centra en privacidad, comercio electrónico y contratación, con una visión proactiva y resolutiva en el asesoramiento a empresas del entorno tecnológico.






