Headlines in late June created a reasonable impression that the EU AI Act had been pushed to 2027. For many organizations that impression was wrong, and the obligations they actually face took effect on 2 August 2026, well before the dates the coverage emphasized.
The Digital Omnibus is real. Parliament adopted its position on 16 June 2026, the Council gave final approval on 29 June, and the amending instrument — Regulation (EU) 2026/1744, signed 8 July — was published in the Official Journal on 24 July and entered into force, in its own words “as a matter of urgency”, on 27 July. It genuinely does defer the high-risk obligations that most compliance teams had been building toward. But it left the transparency obligations under Article 50 exactly where they were: 2 August 2026.
That distinction matters more than it sounds, because the obligations that moved apply to a narrow set of systems, and the ones that stayed reach a much broader population, including plenty of teams who had concluded the Act was not their problem.
Last reviewed: 5 August 2026, after the Article 50 application date. This update reflects the Commission's final Article 50 Guidelines, the current implementation timeline, and the state of national enforcement capacity as of that review.
1. What changed
Two deferrals, both for high-risk systems, written into Article 113 of the AI Act as amended:
- Annex III standalone high-risk systems (employment, credit, education, essential services) moved from 2 August 2026 to 2 December 2027.
- Annex I high-risk systems embedded in regulated products moved from 2 August 2027 to 2 August 2028.
The stated rationale is that the supporting technical standards are not ready and organizations need time to build against a stable target. If you are deploying AI into hiring, lending, or access to essential services, you now have roughly sixteen additional months.
Those are the two changes to the high-risk application timetable. The Omnibus adjusted other things as well: regulatory sandbox timing, supervisory arrangements, sectoral overlap, transition relief for Article 50(2) marking, and a new set of prohibited practices, the last two of which come up below. What it did not move is Article 50’s general 2 August 2026 application date.
2. What did not change
Article 50 transparency obligations have applied since 2 August 2026. The Commission adopted its final Guidelines on those obligations on 20 July, only thirteen days before the application date. The Commission groups the requirements into four cases; operationally, they result in five duties split across two roles (its Article 50 quick facts provide the shortest authoritative summary):
If you are a provider — in shorthand, you place the system on the market or put it into service under your own name or trademark:
- AI-interaction disclosure. Systems that interact directly with people must make clear the person is dealing with an AI, unless that is already obvious from context.
- Synthetic content marking. Outputs of systems that generate or manipulate audio, image, video, or text must be marked in a machine-readable format and detectable as artificially generated, to the extent technically feasible.
If you are a deployer — in shorthand, you use the system under your own authority:
- Emotion recognition and biometric categorization notice. People exposed to these systems must be informed.
- Deepfake disclosure. AI-generated or manipulated image, audio, or video constituting a deepfake must be disclosed, with carve-outs for creative and satirical work.
- Public-interest text disclosure. AI-generated text published to inform the public on matters of public interest must be disclosed, unless it went through human review with editorial accountability.
Also unchanged: the obligations on providers of general-purpose AI models. Article 53 duties — technical documentation, information for downstream providers, a copyright policy, and a public summary of training content — have applied to models placed on the market since 2 August 2025, with Article 55 adding evaluation, adversarial testing, incident reporting, and cybersecurity duties for models classified as carrying systemic risk.
Two qualifications are important. Models placed on the market before 2 August 2025 have until 2 August 2027 to comply. Fine-tuning someone else’s model also does not ordinarily make an organization a provider: the Commission’s guidance uses an indicative, nonbinding criterion of modifications exceeding one third of the original model’s training compute, with case-by-case assessment still required. Most organizations building on foundation models are therefore downstream users rather than GPAI providers.
3. Why this catches organizations out
Most compliance programs organized themselves around risk classification. Teams spent a year asking “are we high-risk?”, and for the majority of companies the honest answer was no. A customer-support chatbot, a document summarizer, or a marketing copy generator is not high-risk merely because it uses AI, though Article 6 turns on intended purpose and Annex III use cases, so the same summarizer sitting inside a hiring or credit workflow may well be in scope.
Article 50 runs on a different axis. It attaches to the interaction pattern and the output, not the risk tier. A chatbot that never touches a protected decision still has to tell people it is a chatbot. A content tool that produces synthetic media still has to mark its output.
The scope is narrower than “all generative AI,” and each system requires an assessment against the applicable conditions and exemptions. Article 50(1) requires a genuine two-way exchange directly with a person; systems running in the background or communicating machine-to-machine fall outside it. Article 50(2) excludes several categories of output and use, including source code, standard editing, and certain closed-loop or business-to-business contexts. The Commission’s final Guidelines provide the necessary detail.
Even so, organizations that classified themselves out of the high-risk bucket and closed the file are the ones most exposed here, because they concluded the Act was largely someone else’s problem.
The second trap is the role split. Most enterprises are simultaneously providers and deployers: you build an internal assistant (provider) and you deploy a vendor’s system to your customers (deployer). The obligations differ by role, and a single program that only addresses one side leaves the other uncovered. The labels above are working shorthands; Article 3 carries the operative definitions, and the boundary has teeth: putting a vendor’s system on the market under your own name or trademark can make you the provider of it.
Ask which AI systems interact directly with European users. If the organization cannot produce that inventory quickly, leadership cannot assess its regulatory exposure with confidence.
That question belongs in a longer set a board should be putting to its executives, since exposure here is a symptom of an inventory problem instead of a legal one. The questions that make a missing answer visible cover the same ground for systems outside the EU perimeter.
4. Executive priorities for compliance and remediation
Article 50 compliance is now an active operating requirement, and the readiness-project framing no longer fits the situation. Any disclosure, marking, classification, or piece of evidence still missing today has become remediation, and it should carry an accountable owner, a target date, and a documented interim position for as long as it stays open. However, the working sequence is much the same as it was before the deadline, since the fastest items remain the disclosures that amount to a copy change and the slowest remain the marking and detection obligations that depend on tooling.
- Inventory EU-facing AI surfaces. Every system a person in the EU can interact with directly, plus every system that generates synthetic content reaching them. Vendor systems count.
- Add the disclosure where it is missing. Chatbots, voice agents, and assistants need a clear, up-front indication they are AI. This is usually a copy change, not an engineering project.
- Validate synthetic-content controls. Article 50(2) requires marking that is effective, interoperable, robust, and reliable, with output detectable as artificially generated. Provenance metadata and embedded watermarking have different limitations, and neither establishes compliance by itself. Assess the chosen approach against the Guidelines and the Code of Practice on Transparency of AI-Generated Content, then document the basis for the compliance decision. Signing the Code remains voluntary, however it carries a degree of presumption of conformity and a more favourable enforcement posture, which is worth weighing now that supervision has actually begun.
- Find your emotion recognition and biometric categorization. Both turn on inference from biometric data: facial-expression analysis in a video interview tool, voice-based emotion inference in a contact centre platform. Ordinary text-based sentiment scoring generally does not qualify, which is part of why the genuine cases get missed: they sit inside vendor features nobody classified as AI.
- Route AI-generated public content through human editorial review, or disclose it. Review with genuine accountability is the exemption; a rubber stamp is not.
- Document decisions and ownership. Maintain a dated assessment of each obligation, the conclusion reached, the evidence relied upon, and the executive accountable for remediation.
One narrow reprieve worth knowing: Article 50(2)‘s marking and detection obligations carry a transition until 2 December 2026 for generative systems placed on the market before 2 August 2026; note that the enacted text says placed on the market, without the broader “or put into service” that some Commission materials use. New systems get no such runway, and the transition covers Article 50(2) specifically — not the disclosure duties under 50(1), (3), and (4).
A second timing point, and an easy one to get backwards: the retroactivity exemption has two conditions, not one. Outputs falling under Article 50(2) and (4) escape retroactive marking or labelling only where they were both generated and already made available before 2 August 2026. Content generated in July but first published on or after the deadline does not qualify, and the same rule governs synthetic media and public-interest text alike. If you had a content queue scheduled across 2 August, that backlog is where to look first.
5. What is at stake
Transparency violations carry fines up to €15 million or 3% of total worldwide annual turnover, whichever is higher. That is the Act’s mid-tier penalty band, below the 7% reserved for prohibited practices but material for any organization with a meaningful EU business.
Enforcement responsibility is distributed. The Commission’s governance summary identifies national market-surveillance authorities as the primary supervisors for AI systems, the AI Office for systems under its supervision, and the European Data Protection Supervisor where EU institutions are providers or deployers. Organizations should identify the relevant national authority and sector regulator for each deployment rather than assume one EU-wide enforcement channel.
That capacity is unevenly distributed, which is a question of timing and not of reprieve. Member States were required to designate their market-surveillance and notifying authorities by 2 August 2025, and as of 17 June 2026 the national implementation tracker recorded only nine of the twenty-seven as having completed both designations, with twelve partway there and six having designated neither. The obligations bind providers and deployers regardless of whether the supervising authority in a given jurisdiction is fully stood up. Therefore the realistic exposure is enforcement that arrives late and unevenly, and an organization reading the designation gap as an informal grace period is accumulating a longer period of non-compliance to answer for, not avoiding one.
Regulatory enforcement is only one dimension of exposure. Enterprise buyers in the EU increasingly ask vendors to attest to their AI Act posture as a condition of contract. An organization that cannot explain its system inventory, role classification, and controls may face delayed procurement, additional contractual obligations, or lost revenue before it faces regulatory action.
6. Maintain the high-risk program
The deferral creates schedule capacity, and the high-risk program should absorb it as such for two reasons.
First, the new date is still a date. Annex III obligations arrive on 2 December 2027, and the work — conformity assessment, risk management systems, data governance, human oversight design, post-market monitoring — takes longer than teams estimate. Organizations that pause now will restart in mid-2027 having lost their institutional context.
Second, more is coming in the interim. The revised Article 5 prohibitions covering non-consensual intimate imagery and child sexual abuse material take effect 2 December 2026. That is a hard prohibition, not a documentation duty.
Organizations that use the deferral to sequence work, retain institutional knowledge, and validate controls will be better positioned for December 2027 than those that suspend the program and attempt to restart it later.
The pattern underneath
This reflects a recurring governance failure: organizations interpret a regulatory headline before mapping the underlying change to their own systems and roles. Most Omnibus coverage focused on high-risk provisions, while the more broadly applicable Article 50 deadline received less attention.
The durable fix is an AI inventory current enough that a regulatory change can be evaluated against it in an afternoon rather than a quarter. Most organizations cannot answer “which of our systems does this apply to?” quickly, and that latency — not the rules themselves — is what turns a manageable obligation into a scramble.
An inventory that answers a regulator is the same artifact that answers an engineer, which is why it is worth building once and keeping current as a standing operational record: what each system is, who owns it, what data and tools it reaches, and which approval let it ship.
The immediate task is Article 50 compliance and remediation. The durable executive priority is an inventory and accountability model that turns the next regulatory change into a days-long assessment.
This is analysis, not legal advice. National enforcement arrangements, sector-specific application, and implementation guidance may continue to develop. Confirm your specific obligations with counsel qualified in EU law before acting.
Counsel will tell you what applies. The harder part is usually knowing which of your systems it applies to, and building the inventory and ownership model that makes the next change a short assessment. That part is engineering, and I work with technology leadership on it. Get in touch.