Hardware FixRecommendedDevice not working? Your driver may be the problemCheck updates for common hardware issues.Fix DriversOctober DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PC×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

The EU AI Act Is Already Official: What Changed on August 2, 2026?

The EU AI Act is not newly official: it entered into force in 2024. Here is what changed in 2026, the revised high-risk deadlines and a practical compliance triage.
From TheFinanceBase Team7 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The EU AI Act became law on August 1, 2024. August 2, 2026 is a major application and enforcement milestone—not the date the Act became official. Many transparency and broader framework rules now apply, but some high-risk obligations have later deadlines, and the rules that matter depend on what an AI system does, who supplies or uses it, and how it reaches the EU.

When did the EU AI Act become law?

Regulation (EU) 2024/1689 was published in the Official Journal on July 12, 2024, and entered into force 20 days later, on August 1, 2024. Political agreement, formal adoption, entry into force, application and enforcement are different milestones: the regulation was binding from its entry into force, while its duties have been phased in over time. The official regulation and the European Commission’s announcement establish the original legal text and entry date.

What are the key dates?

Date What it means
July 12, 2024 Regulation (EU) 2024/1689 was published in the Official Journal.
August 1, 2024 The Act entered into force.
February 2, 2025 Prohibitions on specified AI practices and general provisions, including AI literacy obligations, began applying.
August 2, 2025 Governance provisions and obligations for providers of general-purpose AI models began applying, along with relevant AI Office and national governance provisions.
August 2, 2026 The main general application milestone, including Article 50 transparency rules and Commission enforcement powers concerning general-purpose AI models, subject to exceptions and transitional rules.
December 2, 2026 Certain systems already placed on the market before August 2, 2026 may have until this date for the Article 50(2) marking and detection obligation for artificially generated or manipulated content.
December 2, 2027 Delayed deadline for high-risk systems classified under Annex III, including certain uses in employment, education, essential services, law enforcement, migration, justice and democratic processes.
August 2, 2028 Delayed deadline for high-risk AI embedded in products governed by Annex I sectoral legislation.

The EU’s implementation timeline, Commission overview and Council timeline reflect the changed timetable. In particular, the 2026 Digital Omnibus legislation moved the specified high-risk deadlines. Do not treat August 2, 2026 as a single switch that made every obligation applicable to every AI product.

What kinds of AI does the Act regulate?

The Act takes a risk-based approach. It does not ban AI as a category, and a system’s classification depends on its intended purpose, use context, and the provisions that apply to its provider or deployer.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
VeriMark™ IT 2.0 USB-C® Fingerprint Key - Windows Hello & Windows Hello for Business, 360° Fingerprint Reader, Password-Free Login K64705WW
  • Windows Hello and WebAuthn ready for password free login
  • Certified to Microsoft’s highest fingerprint security standards (ESS & SDCP) for robust, hardware-isolated authentication.
  • Windows Hello Enhanced Sign-in Security requires a PC running Windows 11 with the latest updates. Supports next-gen Windows features, including Copilot PC+ Recall. Supports Windows 11 on x86 and ARM architectures.
  • Match-in-Sensor with on-device biometric processing. 360° fingerprint sensor with AI-enhanced accuracy
  • Low False Rejection Rate (FRR) of 2.2% and a False Acceptance Rate (FAR) of 0.0001%

Prohibited practices

Article 5 prohibits specified practices, including certain forms of manipulation, exploitation of vulnerabilities, social scoring, and particular biometric categorisation or emotion-recognition uses. It is inaccurate to say that the Act bans all facial recognition; the scope and exceptions must be checked against the regulation’s specific provisions.

High-risk systems

High-risk categories include certain AI uses in employment and recruitment, education, critical infrastructure, access to essential private and public services, law enforcement, migration and border control, justice and democratic processes. Certain AI systems that are safety components of regulated products, or are themselves regulated products, can also qualify.

Rank #2
Thetis BIOFP Plus FIDO2 Fingerprint Security Key Hardware Passkey with USB Type C/Biometric/FIDO Certified, 2FA / MFA Authenticator App Device, Works for Window, macOS, Linux, Gmail, Github
  • FIDO2 Certified Passkey Authentication: Officially FIDO2 certified for secure, passwordless login on supported platforms. Use modern passkeys with hardware-backed protection. Please verify your intended service supports FIDO2 hardware keys before purchase.
  • Precision Fingerprint Sensor: Built-in high-accuracy biometric fingerprint sensor ensures fast, convenient authentication while preventing unauthorized access. No PIN reuse, no shared secrets—only your fingerprint unlocks the key.
  • Strong Hardware 2FA/MFA Security: Enhances account protection with physical-presence and biometric verification, helping defend against phishing, credential theft, and account takeovers.
  • USB-C Wired Compatibility (No NFC): Designed for stable USB-C authentication on desktops and laptops, including Windows, macOS, and Linux systems. Ideal for users and enterprises that prefer wired-only security keys.
  • Durable Aluminum Shield, Portable Design: Features the same precision aluminum protective shield for long-term durability. Compact, lightweight, battery-free, and network-free-built for everyday carry and professional environments.

Depending on role and system, requirements can cover risk management, data governance, technical documentation, record-keeping, human oversight, accuracy, robustness, cybersecurity, conformity assessment, registration and post-market monitoring. The relevant high-risk obligations do not all share one start date: the delayed deadlines for Annex III and Annex I systems are December 2, 2027 and August 2, 2028 respectively.

General-purpose AI models

General-purpose AI (GPAI) models can perform a wide range of tasks and may be incorporated into downstream systems. Provider duties can include technical documentation, information for downstream providers, copyright-policy measures and summaries of training content. Models presenting systemic risk face additional duties, including evaluation, risk assessment and mitigation. The Commission’s General-Purpose AI Code of Practice is a voluntary tool to help providers demonstrate compliance; it does not replace the binding regulation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #3
Kensington Upgraded VeriMark Desktop 2.0 USB Fingerprint Reader Supports USB-C and USB-A - Windows Hello with ESS, Windows 11 Fingerprint Scanner for PC, FIDO U2F, FIDO2, TAA Compliant (K64741WW)
  • Certified to Microsoft’s highest fingerprint security standards (ESS & SDCP) for robust, hardware-isolated authentication. Supports next-gen Windows features, including Copilot Recall and Windows Hello with ESS support.
  • Windows Hello ready for fast, password free fingerprint login to Windows and Microsoft 365 accounts
  • On device fingerprint storage keeps biometric data securely within the key. Supports privacy regulations (GDPR, BIPA, CCPA) through on device biometric processing; TAA compliant.
  • Reliable wired USB fingerprint authentication with USB C and USB A compatibility for desktop PCs.
  • Consistent, all condition 360° fingerprint recognition.

Transparency obligations

Article 50 covers specified situations involving AI interaction and artificially generated or manipulated content, as well as certain deepfakes and emotion-recognition or biometric-categorisation systems. The precise duty depends on the system, content, actor and applicable provision. It does not mean every AI-written email, image or piece of marketing copy must carry the same visible label. A transitional rule may give some pre-existing systems until December 2, 2026 for the Article 50(2) marking and detection obligation; check the system’s market-entry date and the relevant transition before relying on it.

Minimal- and limited-risk uses

Many familiar uses, such as spam filters and AI features in games, do not fall under the Act’s high-risk compliance regime. That does not make them legally unregulated: GDPR, copyright, consumer-protection, employment, product-safety and sector-specific rules may still apply.

Rank #4
imKey Pass S6 FIDO2 FIDO U2F Certified Fingerprint Security Key Biometric Authentication USB-C Fast Passkey Passwordless Login & Strong 2FA MFA Phishing-Resistant for Online Accounts
  • Passwordless Login with Fingerprint Security: imKey Pass S6 is a FIDO2-certified hardware security key designed for passwordless authentication. Simply plug in the device and verify with your fingerprint to securely sign in to supported services. This physical passkey protects your accounts from phishing, password leaks, and unauthorized access.
  • Strong Two-Factor Authentication (2FA) Protection: Supports FIDO2 and FIDO U2F protocols, allowing you to enable strong hardware-based 2FA on popular platforms including Google, GitHub, Amazon, X and Binance. Replace SMS codes or authenticator apps with a safer hardware login method.
  • Fingerprint + PIN Dual Protection: Built-in fingerprint sensor provides fast local identity verification, while an optional PIN adds an additional layer of protection. Even if the device is lost, unauthorized users cannot access your accounts without biometric verification.
  • Universal Compatibility with Modern Systems: Works with Windows, macOS, and major browsers including Chrome, Edge, Safari, and Firefox that support WebAuthn and Passkey authentication standards. A single key can secure multiple online accounts and services.
  • Compact, Durable & Easy to use: Designed as a portable USB-C security key that easily attaches to your keychain. No battery, no charging, and no software installation required. Just plug in and authenticate with a fingerprint.

Who can have obligations, including outside the EU?

The duties are not limited to the company that wrote the model. The regulation distinguishes roles such as provider, deployer, importer, distributor, product manufacturer and authorized representative. A provider develops an AI system and places it on the EU market or puts it into service; a deployer uses a system under its authority. Organizations may have responsibilities even when they bought the tool from a vendor rather than building it.

A company’s headquarters alone does not decide whether the Act applies. A non-EU organization should assess whether it places an AI system on the EU market, puts one into service in the EU, or supplies an output used in the EU where the relevant provision makes that connection material. The territorial trigger varies by actor and obligation, so “we have no EU office” is not a sufficient scope analysis.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Yubico - YubiKey Bio C (FIDO Edition) - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C, Biometric, FIDO Certified - Protect Your Online Accounts
  • FIDO-ONLY FUNCTIONALITY: Supports FIDO2 (passkeys) and FIDO U2F protocols for passwordless and second-factor authentication. Does not support OTP, TOTP, Smart Card (PIV), or other advanced features - upgrade to YubiKey 5 Series for extended functionality
  • SECURE AND CONVENIENT: Passwordless MFA login with the YubiKey Bio authenticator and biometric information using a fingerprint, with a PIN as a fallback. Simply plug in via USB and use your fingerprint to authenticate
  • DEVICE & OS COMPATIBILITY: Compatible with Windows, macOS, ChromeOS, and Linux. Works seamlessly with supported services like Google and Microsoft accounts, and major password managers. See the full compatibility list at "Works With YubiKey"
  • DURABLE & RELIABLE: Resistant to tampering, water, and crushing. No batteries or network connectivity required, offering dependable authentication without any downtime. Securely manufactured in USA & Sweden
  • Yubico Authenticator App - Fingerprint enrollment, passkey management and PIN configuration available via the app app - Upgrade to YubiKey 5 Series to generate one-time-passwords (OTP) via Yubico Authenticator and for advanced compatibility (OATH, PIV)
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What should a business do now?

Start with the actual systems and decisions in use, not a vendor’s general compliance claim. A workable triage is:

  1. Build an inventory. Record each tool or model, vendor and contracting entity, internal owner, use case, data processed, users affected, EU availability or deployment, content it generates, role in decisions about people, and whether it is part of a regulated product.
  2. Classify each use case. Check whether it is prohibited, potentially high-risk, subject to GPAI provider duties, covered by transparency provisions, or lower-risk under the AI Act but regulated elsewhere. Ask whether it ranks people, recommends or makes decisions, and whether a human reviewer genuinely evaluates its output.
  3. Check the applicable date and transition. Establish when the system or model entered the market, whether it is a pre-existing system, whether a significant design change has occurred, whether the high-risk route is Annex III or an Annex I product, and whether a specific Article 50 transition applies.
  4. Assign ownership. Set responsibilities among the vendor, product team, legal or compliance, security, data protection, HR or business owner, communications, and senior management. Contract terms should address documentation, model updates, incidents and cooperation.
  5. Keep evidence. Preserve classification decisions, risk assessments, vendor due diligence, system and model documentation, human-oversight procedures, testing and monitoring records, user notices, complaints and incident records, and AI-literacy training records where relevant.
  6. Run separate legal checks. Assess GDPR, employment, copyright, consumer-protection, product-safety, sectoral and cybersecurity obligations independently. AI Act classification is not a substitute for those analyses.

Examples to test against your own use

  • US retailer with an EU-facing chatbot: No EU office does not settle territorial scope. Check where the tool is offered and used, whether customers are told they are interacting with AI when required, and whether the chatbot is part of a high-risk use case.
  • Employer screening applicants: Recruitment is a high-risk area. A human reviewer does not automatically remove the system from scope, particularly if the reviewer simply accepts an AI ranking.
  • Publisher making synthetic images: Do not assume every image needs the same public label. Identify the content type, who generated or published it, the relevant Article 50 duty and any transition; also check copyright and advertising rules.
  • Startup fine-tuning and releasing a model: Modifying a foundation model may change the company’s responsibilities, but fine-tuning alone does not automatically make every company a GPAI provider. Assess what was changed, who places the resulting model on the market, and the applicable provider rules.
  • Hospital using diagnostic software: Determine whether the AI is part of a regulated medical product and whether the Annex I route applies; product-safety and health-sector requirements also matter.
  • Company summarizing customer emails with an LLM: Internal use is not automatically exempt. Review personal-data handling, confidentiality, vendor terms and whether the system influences decisions about customers or staff.

What the Act does not mean

  • It does not ban ChatGPT or AI generally.
  • It does not make every AI system high-risk or subject to identical labeling.
  • It does not mean all high-risk obligations began on August 2, 2026.
  • Human review or a vendor’s “AI Act compliant” badge does not by itself establish compliance.
  • It does not replace GDPR or other laws; an AI system can be low-risk under this Act and still create significant privacy, discrimination, copyright, employment or consumer-law exposure.

How enforcement and fines work

The regulation sets maximum fine ceilings by infringement category, not one universal penalty. For specified prohibited-practice violations, the ceiling is up to 7% of worldwide annual turnover or €35 million, whichever is higher. For other specified obligations, it is up to 3% or €15 million, whichever is higher; for supplying incorrect, incomplete or misleading information, it is up to 1% or €7.5 million, whichever is higher. These are ceilings under the regulation, subject to the infringement involved, the undertaking’s status, proportionality rules and applicable enforcement provisions—not an automatic fine for every breach.

For many organizations, the operational challenge is being able to show how they identified systems, chose a classification, assessed risks, assigned controls, monitored changes and retained evidence. A platform can help organize that work, but it cannot determine the legal status of every use case or transfer the organization’s responsibilities to a vendor.

Where to verify a specific obligation

Use the Regulation’s text for the controlling provisions, then compare dates and guidance with the AI Act Service Desk timeline, the Commission FAQ, its high-risk and Article 50 timing FAQ, and the GPAI FAQ. For a high-risk deployment, a system with a complex supply chain, or a cross-border use, confirm the interpretation with the competent national authority or qualified legal counsel.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Windows Errors? Fix Them Before They SpreadFree repair scan
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.