02-347-7730  |  Saeree ERP - Complete ERP System for Thai Businesses Contact Us

EU AI Act 2 August 2026 Deadline: Some Duties Delayed, Transparency Rules Still Apply

  • Home
  • Articles
  • EU AI Act 2 August 2026 Deadline: Some Duties Delayed, Transparency Rules Still Apply
EU AI Act 2 August 2026 Deadline: Some Duties Delayed, Transparency Rules Still Apply
  • 20
  • July

Through mid-2026 a comfortable story circulated among exporters: "the EU has postponed its AI law." That is only half true. What was postponed is the compliance burden on high-risk AI systems. The transparency duties in Article 50 still start to apply on 2 August 2026, exactly as originally scheduled. If your company ships products, services or content touched by AI into the European market, you still have homework due next month. This article separates what moved from what did not, identifies which Thai exporters and suppliers are actually in scope, and sets out the documentation and traceability you need — building on the practical view of AI governance inside an organisation we published earlier.

In one line: The EU delayed only the high-risk obligations — Annex III stand-alone systems to 2 December 2027 and Annex I embedded systems to 2 August 2028 — while the duty to tell people they are dealing with AI, or looking at AI-generated content, still bites on 2 August 2026.

What the EU AI Act is, and why 2 August 2026 matters

The EU AI Act is the world's first cross-sector law governing artificial intelligence. It was not written for technology companies specifically; it was written around the risk of a given use. Uses judged unacceptable are banned outright. High-risk uses carry a heavy compliance package. Ordinary uses carry almost nothing. And a separate band of uses is not high-risk at all but still has to be honest with the people on the other end — that band is what Article 50 governs.

The Act never applied all at once. It landed in waves: prohibitions and AI-literacy duties first, then rules for general-purpose AI models and the penalty regime, and then 2 August 2026 as the date "the rest of the Act starts to apply" — which originally included the high-risk obligations. When news of a postponement broke, many readers concluded the whole August deadline had evaporated. It did not.

For Thai businesses this is not distant foreign news. The AI Act follows a market-effects logic rather than a place-of-establishment logic, the same reasoning that pulled Thai companies into GDPR's orbit, and the same reason Thailand's own draft AI legislation is being drafted with international practice in view.

What was actually delayed

During 2026 the European Commission advanced a simplification package widely referred to as the Digital Omnibus. The European Parliament adopted the final text on 16 June 2026 and the Council of the EU gave its final green light on 29 June 2026. The change with the biggest calendar impact is the deferral of the high-risk start dates.

Stand-alone high-risk systems under Annex III — AI used to screen job applicants, score creditworthiness, or make decisions in education, for example — move to 2 December 2027. AI embedded in products already covered by EU product-safety legislation under Annex I — machinery, medical devices, lifts, toys — moves to 2 August 2028.

Date What applies Status
2 Feb 2025 Prohibitions on unacceptable-risk AI; AI-literacy duties for staff In force
2 Aug 2025 General-purpose AI (GPAI) model rules, governance bodies, penalties In force
2 Aug 2026 Article 50 transparency obligations and the remainder of the Act Unchanged — not delayed
2 Dec 2026 Grace period for machine-readable marking on generative systems placed on the market before 2 Aug 2026 Per the Omnibus agreement
2 Dec 2027 Obligations for stand-alone high-risk systems (Annex III) Deferred from 2 Aug 2026
2 Aug 2028 Obligations for high-risk AI embedded in regulated products (Annex I) Deferred from the original date

An important caveat on legal status: the deferral only takes legal effect once the text is published in the Official Journal of the European Union. The final act was signed on 8 July 2026 and enters into force on the third day after publication. As of the date of writing (20 July 2026) publication was expected before 2 August 2026, but each organisation should verify the current status itself rather than plan on the assumption that the delay is already law.

Article 50 — the "say it is AI" rules that did not move

Article 50 reads more plainly than most of the Act: people must know when they are dealing with a machine rather than a human, and must know when what they are seeing was generated or manipulated by AI. The common misreading is that this is a problem for model developers only. Several of the duties in fact fall on the deployer — the ordinary business that picks up an off-the-shelf AI tool and puts it in front of customers.

Situation Who is responsible What is required Main exception
AI systems that interact directly with people, such as customer-service chatbots Provider Inform the person that they are interacting with an AI system Not required where it is already obvious in context
Systems generating synthetic content — text, image, audio, video Provider Mark outputs so they are machine-readable and detectable as artificially generated Assistive editing functions that do not substantially alter the input
Emotion-recognition and biometric categorisation systems Deployer Notify the people exposed to the system; comply with EU data-protection law Law-enforcement use subject to safeguards
Deepfakes and AI-generated text published to inform the public Deployer Clearly disclose that the material was artificially generated or manipulated Artistic, satirical or fictional work; human-reviewed editorial content

One piece of breathing room: under the Omnibus agreement, generative systems already on the market before 2 August 2026 have until 2 December 2026 to satisfy the machine-readable marking requirement. Disclosure aimed at humans — telling a user it is a chatbot, or labelling AI-generated content — is not covered by that grace period.

Which Thai companies are actually in scope

The useful question is not "are we an AI company?" but "does the output of AI we use end up in front of someone in the EU?" If the answer is yes, work through the table below. It also pays to read this alongside the wider debate on accountability for AI outcomes, because the underlying expectation is the same everywhere: somebody must be answerable.

Thai business type Point of contact with the AI Act What to do before 2 Aug 2026
Exporters of food, auto parts, electronics AI used to draft product copy, generate imagery or produce marketing documents sent to EU buyers Label AI-generated material and keep a record of who approved publication
OEM/ODM contract manufacturers supplying EU brands Downstream customers request process evidence so they can complete their own compliance file Prepare a process and traceability document pack that can be produced on request
Thai software houses and agencies selling into Europe Chatbots or content-generation features embedded into products delivered to EU clients Add in-product disclosure and settle in the contract who is provider and who is deployer
HR functions with EU subsidiaries or staff AI tools screening candidates or assessing performance High-risk duties move to 2027, but start the inventory of AI tools in use now
Machinery and equipment makers with smart functions AI embedded in products already covered by safety legislation Time runs to 2028, but build the technical documentation alongside existing certification work

The real exposure: the most common failure is not deliberate breach — it is an organisation that simply does not know where it uses AI. Marketing adopts an image generator, sales adopts an email assistant, support switches on a chatbot, and nobody keeps a central list. When an EU customer sends a supplier questionnaire, the company cannot answer accurately. An incomplete or incorrect answer in a document a customer relies on for their own compliance is a contractual risk that arrives long before any European regulator does.

The documentation and traceability you need

Whether a given rule was deferred or not, the AI Act asks for the same underlying thing: evidence. Who did what, when, on which data, and who approved it. That is precisely what a well-run back office should already be able to produce.

What to prepare Owner Evidence to hold
Inventory of AI systems actually in use IT together with process owners Register of tools, users, purpose and start date
Risk classification of each system Legal / compliance Written rationale for the classification and a review date
Disclosure text shown to end users Product and marketing Screenshots or copies of the live wording, with publication dates
Goods traceability from receipt to delivery Warehouse and production Lot and serial numbers linked from goods receipt through to delivery note
Change and approval history on documents Accounting and procurement Audit trail of who changed which value, when, and who approved it
Contractual terms with partners Procurement and legal Clauses setting out roles, liability and the right to request documentation

Where an ERP helps — and where it does not

To be direct: an ERP system does not make an organisation compliant with the EU AI Act, and no software issues a certificate of conformity. Classifying risk, interpreting scope, and deciding whether your company is a provider or a deployer are jobs for legal counsel and the relevant authorities, not for an accounting system.

What a back-office system genuinely provides is the evidence layer. When an EU customer asks which raw materials went into a given lot, who handled it and when it shipped, the gap between answering in minutes and hunting through spreadsheets on several machines is very visible to a buyer. Saeree ERP maintains a continuous document trail from purchase order to goods receipt, links lot and serial numbers through to the delivery note, records an audit trail of who changed which record and when, and lets an administrator set access rights per user. Those are the raw materials of an answer that survives being checked later — the same discipline that underpins sustainability reporting from ERP data.

The AI assistant inside Saeree ERP is still in development and training, and is not generally available. In this context that is worth stating plainly, because knowing exactly which systems contain AI and which do not is itself an entry in the AI inventory you have to keep — much as an organisation has to know where personal data lives in order to meet Thailand's new rules on personal-data access requests.

Something you can do this week: open one file and build a three-column table — AI tool in use / does the output reach an EU customer / who owns it. That single table answers more than half of a typical supplier questionnaire, and it is the seed of the AI inventory you will need regardless of how the timetable shifts.

Disclaimer: this article is general information for orientation, not legal advice. Classification of AI systems, the scope of application, and each organisation's role depend on specific facts. Companies exporting or providing services into the European Union should confirm their own classification with qualified legal counsel and check the text as published before acting on it.

Conclusion

"The EU delayed its AI law" is half a story. The half that moved is the heavy compliance package for high-risk systems, which buys machinery makers and users of AI in HR or credit decisions until 2027 and 2028. The half that did not move is the duty to be honest with users under Article 50, which starts on 2 August 2026 and reaches a large number of Thai businesses that generate content with AI or run a chatbot for European customers.

The sensible response is not to wait and see whether the dates slip again. It is to do the two things that pay off whichever way the legislation moves — keep a register of where the organisation uses AI, and make sure the systems of record can answer "who did what, when" without anyone digging through old email.

"A law can postpone its deadline. It cannot postpone the question of whether your organisation can say who did what, and when."

- The Saeree ERP team

References

Information checked on 20 July 2026 — publication of the Omnibus package in the Official Journal was still pending as at that date.

Looking for an ERP system for your organisation?

If an EU customer asked you to trace a product lot today, how many days would it take? Talk to the Grand Linux Solution team about document trails, lot and serial linkage, and audit trails — free, no obligation.

Request a Free Demo

Tel 02-347-7730 | sale@grandlinux.com

Saeree ERP Author

About the Author

Paitoon Butri

Network & Server Security Specialist, Grand Linux Solution Co., Ltd.