As of August 2, 2026, the European Commission's AI Office and national competent authorities gained enforcement powers for the provisions that have become applicable, while the Act's new Article 50 transparency obligations also started applying.
The timing is particularly significant for organiz
ations using Microsoft 365 Copilot, Azure AI, Microsoft Foundry, Copilot Studio agents, and other generative AI services across their workforce.
But there's an important distinction to get right: August 2, 2026 is not the date when all high-risk AI obligations suddenly became enforceable. Following the EU's AI Omnibus, many high-risk obligations have been pushed to 2027 and 2028. What's arrived now is a combination of enforcement powers, transparency requirements, and continued obligations around prohibited AI practices and General-Purpose AI (GPAI).
For organizations running Copilot, the practical question isn't simply "are we compliant with the AI Act?" It's: where are we using AI, what role does each system play, and what obligations apply to that particular use case?
What Changed on August 2, 2026
The EU AI Act entered into force on August 1, 2024, but its requirements were deliberately phased. The major milestones:
- February 2, 2025: Prohibited AI practices and AI literacy obligations began applying
- August 2, 2025: Governance provisions and obligations for providers of General-Purpose AI models began applying
- August 2, 2026: The Act's general application date arrived — enforcement powers became operational for applicable provisions, and Article 50 transparency obligations began applying
- December 2, 2027: High-risk AI systems under many Annex III use cases — employment, education, biometrics, critical infrastructure — become subject to high-risk requirements, per the AI Omnibus timeline
- August 2, 2028: High-risk AI systems embedded in regulated products under Annex I receive their extended transition period
The European Commission's July 2026 guidance makes an important distinction here: the AI Act is now in its enforcement phase, but not every obligation applies today. That's a far more accurate way to describe the August 2026 milestone than "everything just became mandatory."
Article 50: The Transparency Rules That Matter Now
The most visible change is Article 50, introducing transparency requirements for certain AI systems. The European Commission published its final guidelines on July 20, 2026, shortly before the obligations began applying.
1. People must know when they're interacting with AI Providers of AI systems designed to interact directly with people must design them so individuals are informed they're dealing with an AI system, not a human. This matters most where AI-powered assistants are exposed directly to customers, employees, or citizens.
2. AI-generated and manipulated content must be identifiable Providers of systems that generate or manipulate synthetic content must implement machine-readable marking so the artificial origin can be detected — covering images, audio, video, text, and other synthetic content under Article 50. In most scenarios, this obligation sits with the provider through metadata or technical markers, not a visible label on every piece of content. Systems already on the market before August 2, 2026 get an extended compliance window until December 2, 2026 for this specific marking obligation.
3. Deepfakes must be disclosed Deployers must disclose when people are exposed to AI-generated or manipulated image, audio, or video content that constitutes a deepfake — relevant to marketing material, training content, corporate communications, and synthetic media.
4. Certain AI-generated public-interest text requires disclosure This is not a blanket rule requiring every piece of Copilot-assisted writing to carry an AI label. There's an important exception where content has undergone appropriate human review and a person assumes editorial responsibility. That distinction matters for everyday Copilot usage — rewriting an email, summarizing meeting notes, or improving a document doesn't automatically require an AI-generated label. Context and the nature of the AI's contribution matter.
What Does This Mean for Microsoft 365 Copilot?
This is where the AI Act's risk-based structure becomes important. Copilot is not automatically "high-risk" simply because it's an AI system. Classification depends on the AI system and, critically, how it's used.
For ordinary workplace activities — drafting emails, summarizing meetings, creating document outlines, generating first drafts, finding information across permitted organizational content — the use case will generally not become high-risk merely because Copilot is involved.
The situation changes when AI is incorporated into a regulated or high-impact decision process:
- Recruiting or candidate evaluation
- Employee selection or promotion
- Worker performance or employment-related decisions
- Access to essential services
- Creditworthiness or credit decisions
- Other Annex III use cases
Calling the technology a "copilot" doesn't remove the regulatory obligations — the use case matters more than the marketing name. And per the Commission's updated timeline, many Annex III high-risk requirements are now scheduled for December 2, 2027, not August 2026.
Key takeaway: don't classify the product — classify the use case. The same Copilot that drafts an email may be low-risk, while an AI-driven hiring workflow may fall into a regulated category with additional obligations.
Microsoft, Copilot, and the GPAI Responsibility Split
Another area worth getting the wording right on: the relationship between Microsoft, Copilot, and the underlying AI models.
Microsoft provides AI systems and services and, in relevant circumstances, may also carry obligations as a provider of General-Purpose AI models — but it's too simplistic to say "Microsoft is the GPAI model provider behind Copilot" and leave it there. The AI Act creates responsibilities across the entire AI value chain, and depending on the service and architecture, different organizations can carry responsibilities as model providers, AI system providers, deployers, downstream providers, distributors, or other actors.
For an enterprise using Microsoft 365 Copilot, the organization is generally acting as the deployer of the AI system within its own environment. That means Microsoft cannot simply be expected to solve the customer's entire AI Act compliance challenge. Customers still need to understand:
- What is Copilot being used for?
- Who is affected by its outputs?
- Is it involved in a regulated decision?
- What human oversight exists?
- What information is being processed?
- Can the organization demonstrate how the system is governed?
What This Means for Large Enterprises
For large enterprises, the immediate priority isn't rebuilding Copilot deployments. It's understanding where AI is influencing decisions, documenting those use cases, and ensuring appropriate governance, transparency, risk management, and human oversight controls are in place — not just for Microsoft 365 Copilot, but also Copilot Studio agents, autonomous AI agents, Azure AI services, Microsoft Foundry solutions, third-party AI platforms, and custom-developed AI applications.
Organizations that understand their AI estate today will be significantly better positioned as additional AI Act obligations begin applying in 2027 and 2028.
What Should Microsoft 365 Administrators and Compliance Teams Do?
1. Build an AI inventory Identify where employees are using Microsoft 365 Copilot, Copilot Studio agents, Azure AI/Microsoft Foundry, third-party GenAI services, custom AI applications, and AI-powered business processes. The goal is understanding where AI exists in the business — not just which AI products were purchased.
2. Map AI to business processes The next question: what is the AI actually doing? A Copilot used to summarize a meeting is very different from an AI system used to rank job candidates. Map deployments against business processes and identify whether any fall within regulated or potentially high-risk use cases.
3. Strengthen human oversight For important decisions, define where human judgment is required. AI output shouldn't automatically become a business decision simply because it came from a trusted enterprise platform — particularly in employment processes, financial decisions, and other customer-impacting workflows.
4. Use Purview and Microsoft 365 governance capabilities Microsoft Purview can play an important supporting role in a broader governance architecture — Data Classification, Sensitivity Labels, DLP, Audit, Insider Risk Management, Data Lifecycle Controls, Information Protection, and AI-related Activity Monitoring. These controls don't, by themselves, make an organization compliant with the EU AI Act, but they provide important security, governance, auditability, and evidence around how AI is being used.
5. Establish an AI literacy program Employees using Copilot should understand what it can and cannot do, hallucination and accuracy risks, appropriate handling of confidential information, human review requirements, bias and fairness considerations, and when AI output shouldn't be trusted. The AI Act's AI literacy requirement has applied since February 2025 — this isn't new, but it deserves continued investment.
Bottom Line
The EU AI Act has now entered a significant new phase. August 2, 2026 is real, but it is not the date when every AI system suddenly became high-risk. What changed is that the AI Act's enforcement framework is now operational for applicable provisions, while Article 50 transparency requirements have begun applying. At the same time, the AI Omnibus has extended the timeline for many high-risk AI obligations into 2027 and 2028.
For Microsoft 365 Copilot customers, the practical lesson is straightforward: don't classify the product, classify the use case. Copilot used for everyday productivity is very different from Copilot or an AI agent embedded into recruitment, employee evaluation, financial decisions, or another regulated process.
The organizations best prepared won't necessarily be the ones with the most AI policies — they'll be the ones that can answer three simple questions: Where are we using AI? What decisions or content does it influence? Can we demonstrate that we are governing it appropriately?
That's the real shift happening with the EU AI Act in 2026.
Read here to know more: Safer and more transparent AI – European Commission
Also review: EU AI Act Compliance – Microsoft Trust Center
And: AI Act | Shaping Europe's Digital Future – European Union
Stay tuned for more updates on Microsoft, Copilot, Purview, AI governance, and the rapidly evolving regulatory landscape...

.png)

.png)
.png)

.png)








