top of page

The EU AI Act deadline nobody postponed

Aug 8
5 min read

As of Sunday, 2 August 2026, the EU AI Act's transparency obligations apply.

I keep having the same conversation. Someone tells me their AI Act work is on hold because "the deadline moved." And they're not wrong, exactly — a deadline did move. Just not theirs.


Here is what actually happened. The Digital Omnibus on AI — Regulation (EU) 2026/1744 — was published in the Official Journal on 24 July and entered into force on 27 July, three days later, in a deliberate sprint to beat the 2 August date. It pushed the high-risk regime under Chapter III back substantially: stand-alone Annex III systems (employment, education, creditworthiness, access to essential services) now apply from 2 December 2027, and high-risk AI embedded in regulated products under Annex I from 2 August 2028.


That was the headline. Article 50 was not in it.


Transparency obligations landed on schedule, and they are by far the most widely applicable part of the AI Act — because they bind not just providers who build systems, but deployers who merely use them. If you have a chatbot on your website, or you publish anything generated with AI, you are in scope. Open-source licensing does not exempt you.


So here's the self-check I've been running with clients this summer.


1. Do your customer-facing chatbots tell users they're talking to AI?


Article 50(1) requires providers to design interactive systems so that people are informed they're dealing with an AI system — unless it's obvious to a reasonably well-informed person in the circumstances.


Do not lean on that exception. It's narrow, and it's assessed from the perspective of the person on the other end — not from the perspective of the team that built the thing and finds it self-evident. A support widget with a human-sounding name and a stock photo avatar is the opposite of obvious. If you're arguing the point internally, you've probably already lost it.


The practical fix is trivial: a clear line at the start of the interaction. The hard part is inventorying where these things actually live. Most organisations I work with underestimate this. The chatbot on the main site is known. The one procurement bolted onto the careers page in 2024 is not.


2. Is your synthetic content marked in a machine-readable way?


Article 50(2) requires providers of systems generating synthetic audio, image, video or text to mark outputs in a machine-readable format and make them detectable as artificially generated. This is provenance plumbing — watermarking, metadata, embedded signals — not a visible label.


This is the one place the Omnibus did touch. Providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the marking obligation. That's the full extent of the reprieve. Note what it does not cover: it is limited to Article 50(2), it applies only to providers, and only to legacy systems. Everything else under Article 50 applies now.


Four months, not four years. And if you're buying generative AI rather than building it, this is a supplier question — ask now, because the answer determines whether you can meet your own obligations downstream.


One piece of relief worth knowing: content generated before 2 August 2026 does not need to be labelled retroactively. You are not going back through the archive.


3. Are your deepfakes and AI-generated public-interest text visibly labelled?


Article 50(4) is a deployer obligation, and it applies from 2 August with no grace period at all.


Two limbs. If you deploy an AI system to generate or manipulate content that resembles real people, objects, places or events and would appear authentic to a viewer — a deepfake — you disclose that it's artificially generated. And if you publish AI-generated or AI-manipulated text to inform the public on matters of public interest, you disclose that too, unless a human has reviewed it and someone holds editorial responsibility for it.


That second limb catches more organisations than they expect. Corporate communications on regulated topics, public sector information, advocacy content, sustainability claims. If your comms team is running drafts through a model and publishing on public-interest questions, the editorial responsibility carve-out is doing real work — so make sure someone can actually point to who holds it.


4. Emotion recognition and biometric categorisation


Article 50(3): if you deploy these, you inform the people exposed to them. Less common, but worth a look if you're anywhere near HR tech, retail analytics or access control.


What the Commission has published, and why it's worth reading


Two documents, and they do different jobs.

The Commission adopted Guidelines on the transparency obligations under Article 50 on 20 July 2026, following a draft that went out for consultation in May. These are the interpretive layer over Article 50's famously open-ended drafting — scope, worked examples, the provider/deployer split. This is the document to read first.


Separately, there's the Code of Practice on Transparency of AI-generated Content, drawn up by independent experts in a process facilitated by the AI Office. The Commission concluded on 8 July that it adequately covers the obligations in Article 50(2), (4) and (5), and the AI Board endorsed that assessment. It's voluntary. Adherence helps you demonstrate compliance; it isn't conclusive proof of it. But if you're a provider trying to decide between signing up and defending a bespoke approach to a regulator, the Code is the more predictable path.


Both are genuinely readable. Between them, an hour of your time.


The Finnish layer


Worth remembering that the supervisory structure here has been live since 1 January 2026, when the national implementing legislation on competent authorities' powers entered into force. Supervision is distributed across fifteen authorities. Traficom is the national single point of contact and coordinates implementation; the Data Protection Ombudsman supervises prohibited practices centrally, alongside its GDPR role.


Distributed supervision means the question "who would even enforce this against us?" has a sectoral answer, not a single one. It also means the answer may be an authority that already knows your organisation.


The number, and the thing that's actually more likely to happen


Infringements of Article 50 carry fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. That's the number everyone quotes.


But I'd put the near-term risk elsewhere. Enforcement takes time, resources and a complaint. A screenshot does not. The realistic failure mode for most companies is not a supervisory authority proceeding — it's a customer working out mid-conversation that "Emma from customer service" was never a person, posting it, and the post travelling. Article 50 is unusual among AI Act obligations in that compliance and basic decency toward your customers point the same direction. Telling people they're talking to a machine costs you a line of text and earns you a bit of trust you'd otherwise have to buy some other way. Very little else in this regulation is that cheap.


So: has your organisation checked its Article 50 exposure? Or is this the first you're hearing that it wasn't postponed?


Sources: Regulation (EU) 2024/1689 (AI Act) as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI, OJ 24.7.2026); European Commission Guidelines on the transparency obligations under Article 50 (20.7.2026); Code of Practice on Transparency of AI-generated Content; Traficom on national implementation.


Requirements for AI transpa
Requirements for AI transpa

 
 
bottom of page