What the EU AI Act requires from 2 August 2026
The delay everyone read about applies to one tier. It isn't the tier most companies are in.
If you run a customer-facing chatbot in the EU, generate synthetic images or video for EU campaigns, or publish AI-generated text, your obligations became enforceable five days ago and you may have read a headline telling you otherwise.
The Digital Omnibus on AI did delay part of the AI Act. It delayed the high-risk tier. It did not touch Article 50, and national enforcement started on schedule.
What the Commission's own timeline says
This is not a matter of interpretation. The European Commission's AI Act Service Desk publishes the implementation timeline, updated to reflect the Omnibus amendments. It reads:
2 August 2026 — the majority of rules of the AI Act come into force and enforcement starts for applicable rules. Transparency rules (Article 50) start to apply. Enforcement of the AI Act starts at national and EU level concerning general-purpose AI models, prohibitions, transparency rules and AI literacy.
The dates that moved are further out:
- 2 December 2027 — rules for high-risk AI systems under Annex III
- 2 August 2028 — rules for high-risk AI embedded in regulated products under Annex I
Both of those carry the Commission's own footnote marking them as amended by the Omnibus. Article 50 carries no such footnote, because it was not amended.
The misreading, and why it is easy to make
Coverage of the Omnibus compressed into "EU delays AI Act." That headline is accurate about the high-risk tier and wrong about everything else, and the distinction matters because most organisations are not in the high-risk tier at all.
Annex III high-risk covers a specific list: biometrics, critical infrastructure, education access, employment decisions, essential services, law enforcement, migration, justice. If you are not doing one of those, the December 2027 date was never yours. Your date was 2 August 2026, and it has passed.
There is a second, quieter misreading worth naming. A good deal of secondary coverage says general-purpose AI rules started in August 2026. They did not. The obligations for providers of general-purpose AI models — documentation, copyright policy, training-data summaries — took legal effect on 2 August 2025. What changed this month is that enforcement of them began.
What Article 50 actually asks for
Article 50 is a transparency provision, and unlike the high-risk regime it does not depend on a risk classification. It applies to AI systems generally, which is why it reaches more organisations than any other part of the Act.
In practice it comes down to disclosure in four situations:
Systems that interact with people. If someone is talking to an AI rather than a person, they have to be told, unless it is obvious from context. A support chatbot needs to say so.
Synthetic content. Providers of systems that generate audio, image, video or text must mark the output as machine-generated in a machine-readable form.
Deepfakes. Deployers of systems producing deepfake content must disclose that it has been artificially generated or manipulated.
Text published to inform the public. AI-generated text published on matters of public interest must be disclosed as such.
That fourth one carries an exception worth knowing: where the content has undergone human review and a natural or legal person holds editorial responsibility, the disclosure duty generally does not apply. If your content process already includes human review before publication, your gap is documentation rather than a new process — being able to show the review happened and name who is accountable for it.
The transition nobody mentions
There is one genuine piece of breathing room in Article 50, and it is narrow.
The Commission's timeline lists 2 December 2026 as a transitional deadline for certain providers of AI systems, including general-purpose AI systems generating synthetic content, that were already placed on the market before 2 August 2026, to comply with Article 50(2) — the marking and machine-readable detection requirement.
So: if your generative system was already in the market before 2 August, you have until December for the marking obligation specifically. If it launched after 2 August, you comply from launch. And the disclosure obligations under the other paragraphs of Article 50 are not covered by that transition at all.
The same date, 2 December 2026, also brings new prohibitions into force for AI systems generating non-consensual sexual deepfakes and child sexual abuse material.
What the exposure looks like
Article 50 non-compliance sits in the middle penalty tier — reported across legal trackers as up to €15 million or 3% of global annual turnover, whichever is higher, with the lower figure applying to SMEs and startups. The top tier, for prohibited practices, runs to 7%.
Worth putting in context: GDPR's maximum is 4% of global turnover. The AI Act's ceiling is higher.
But the enforcement risk is not the whole picture, and in my experience it is not the part that costs companies first. Auditors, cyber insurance underwriters and procurement teams are already asking deployer-side questions in supplier onboarding. A missing disclosure does not usually surface as a fine. It surfaces as a delayed contract.
What to actually do this month
Inventory where AI touches a person. Not every model you run — every point where an output reaches a human being, internal or external. That list is almost always longer than expected, because it includes tools individual teams adopted without telling anyone.
Check the disclosure on each one. Does a user of your chatbot know it is a chatbot? Is generated media marked? This is usually a small change and the reason it does not happen is that nobody owns it.
Write down who is accountable for published content. If you are relying on the editorial-responsibility exception, the exception depends on being able to show it. A named person and a review record is the whole requirement.
Ask your vendors. If you use someone else's generative system, their Article 50(2) marking obligations affect your output. Their transition date may differ from yours.
Do not assume buying keeps you a deployer. Under Article 25, putting your name or trademark on a high-risk system, modifying it substantially, or changing its intended purpose can move you into provider obligations. That question is worth asking before it is asked of you.
The part that is genuinely uncertain
The Commission has published draft guidelines on Article 50 for consultation and a Code of Practice on marking and labelling is in development. Final versions were expected ahead of the August deadline.
So the obligation is live while the detailed guidance is still settling. That is uncomfortable, and it argues for doing the obvious things now — disclose clearly, keep a record of who reviewed what — rather than waiting for a specification that resolves questions you may not have.
Common questions
Did the EU AI Act get delayed?
Partly. The Digital Omnibus on AI moved the high-risk deadlines: Annex III systems to 2 December 2027 and Annex I product-embedded systems to 2 August 2028. Article 50 transparency obligations were not amended and became enforceable on 2 August 2026.
What became enforceable on 2 August 2026?
According to the European Commission's own implementation timeline: transparency rules under Article 50, measures in support of innovation, and enforcement at national and EU level concerning general-purpose AI models, prohibitions, transparency rules and AI literacy.
Does Article 50 apply to my company?
It applies to AI systems generally rather than to a risk classification, which is why it reaches more organisations than any other part of the Act. If an AI system of yours interacts with people, generates synthetic media, produces deepfakes, or publishes text on matters of public interest, it applies.
Is there any transition period for Article 50?
One, and it is narrow. Providers of systems generating synthetic content that were already placed on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2), the marking requirement. Systems launched after 2 August comply from launch.
Do we have to disclose AI-generated text we publish?
Where the text concerns matters of public interest, yes — unless it has undergone human review and a natural or legal person holds editorial responsibility for it. If you already review content before publishing, the work is documenting that review and naming who is accountable.
What are the penalties for Article 50 non-compliance?
Reported across legal trackers as up to €15 million or 3% of global annual turnover, whichever is higher, with the lower figure applying to SMEs and startups. In practice the first cost is usually commercial rather than regulatory: procurement and insurance questionnaires now ask these questions.
Sources
- European Commission, AI Act Service Desk — Timeline for the Implementation of the EU AI Act, updated for the Digital Omnibus on AI
- Regulation (EU) 2024/1689, Article 25 (responsibilities along the AI value chain), Article 50 (transparency obligations), Article 99 (penalties)
More on this: emotion inference.
Scoring 40 AI use cases in a regulated enterprise — an AI governance framework built to survive security and risk review, with the reasoning written down beside every judgement.