Overview
Quick answer: since 2 August 2026, the transparency duties in Article 50 of the EU AI Act apply and national authorities can enforce them. The obligations for high-risk AI systems, long pencilled in for that same date, did not arrive. Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It moved standalone high-risk systems under Annex III to 2 December 2027 and AI embedded in regulated products under Annex I to 2 August 2028.
That split matters more than the headlines suggested. "The EU delayed the AI Act" is the version most people heard, and it is wrong in a way that costs money. If your compliance work was built around the high-risk cliff, you have real breathing room. If your product talks to users or produces text, images, audio or video, you are inside a live obligation right now, and the grace period that exists is narrower than most summaries admit.
There is a second problem worth naming early. A large share of the guidance published before July 2026 describes a legal position that no longer exists. Checklists, webinars and vendor decks still say the full framework switches on in August 2026. Check the date on anything you are relying on.
This guide is general information, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Always check the consolidated text and take qualified advice for your own situation.
What actually applied on 2 August 2026
Four things happened on that date, and none of them were deferred.
Article 50 transparency became applicable. If your system interacts directly with people, generates synthetic content, recognises emotions, categorises people using biometrics, or produces deepfakes, you owe disclosure duties now. These apply whatever risk tier your system sits in, so a simple customer service chatbot is caught even though nothing about it is high-risk.
Enforcement started. National competent authorities can now act on the parts of the Act already in force: the Article 5 prohibitions, the general-purpose AI model rules that began in August 2025, the AI literacy duty, and the new transparency obligations. Before this date much of the framework existed on paper without a supervisor able to act on it.
The Commission gained its enforcement powers over general-purpose AI model providers. The substantive GPAI obligations have applied since 2 August 2025. What changed is the ability to enforce them.
Guidance arrived just in time. The Commission adopted guidelines on the Article 50 transparency obligations on 20 July 2026, alongside a code of practice on marking AI-generated content. If you are deciding what a compliant disclosure looks like in your interface, that is the document to work from rather than a generic template.
What the Digital Omnibus moved
The Digital Omnibus on AI started life as a Commission proposal on 19 November 2025. Parliament and Council reached a provisional agreement on 7 May 2026, Parliament endorsed the text on 16 June, the Council approved it on 29 June, and it was published on 24 July. It is now law, not a proposal, which is the single most important correction to make to any older briefing note.
Here is what it did.
- High-risk obligations for standalone Annex III systems move to 2 December 2027. That covers recruitment and worker management, credit scoring, biometrics, education, essential services, law enforcement, migration and the administration of justice.
- High-risk obligations for AI embedded in regulated products under Annex I move to 2 August 2028. Medical devices, machinery, vehicles, toys and the rest of the product safety family.
- Deployer duties follow the systems they attach to. Article 26 obligations, fundamental rights impact assessments under Article 27, and the individual right to an explanation under Article 86 are tied to high-risk systems, so they land on the same later dates rather than now.
- Machine-readable marking gets a four month transition, but only for existing systems. Providers of generative systems already placed on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2). A generative product launched on or after 2 August 2026 needed the marking in place from day one.
- Two new prohibitions were added to Article 5, covering AI systems used to produce non-consensual intimate imagery, including so-called nudifier tools, and AI generating child sexual abuse material. These apply from 2 December 2026.
- National regulatory sandboxes are due by 2 August 2027, with each Member State required to have at least one operating.
What did not change is the architecture. The risk tiers, the conformity assessment route, the GPAI track and the role of the AI Office are all intact. The reason given for the deferral was practical rather than political: the harmonised standards from CEN and CENELEC were not finished, and several Member States had not designated their competent authorities. Buying time to build the machinery is not the same as removing the obligation.
The full EU AI Act timeline at a glance
The Act entered into force on 1 August 2024 and phases in as follows. Dates below reflect Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744.
| Date | What applies | Status |
|---|---|---|
| 2 February 2025 | Prohibited practices under Article 5, AI literacy under Article 4 | In force |
| 2 August 2025 | Obligations for general-purpose AI models, governance structures, national penalty rules | In force |
| 2 August 2026 | Article 50 transparency duties, enforcement by national authorities, Commission enforcement powers over GPAI providers | In force |
| 2 December 2026 | Article 50(2) marking for generative systems on the market before 2 August 2026, plus the two new Article 5 prohibitions | Next deadline |
| 2 August 2027 | At least one AI regulatory sandbox operating in each Member State | Upcoming |
| 2 December 2027 | High-risk obligations for standalone Annex III systems | Upcoming |
| 2 August 2028 | High-risk obligations for AI embedded in regulated products under Annex I | Upcoming |
One nuance that catches people out: content generated before 2 August 2026 does not have to be marked or labelled retroactively. The duty runs forward, not backward.
Article 50 in practice: the four duties that bind you today
Article 50 is short, and it is the part of the Act most businesses actually have to satisfy. It covers four situations.
1. Systems that interact with people
If a person is dealing with an AI system, they have to be told, unless it is obvious to a reasonably well-informed person in the circumstances. In practice this means a visible statement at the point of interaction, not a clause buried on page nine of your terms of service. A chatbot that opens with a human name and no disclosure is the textbook failure case.
2. Synthetic content has to be marked
Providers of systems that generate synthetic audio, image, video or text must mark the output in a machine-readable format so it can be detected as artificially generated. Visible labelling and machine-readable marking are two different obligations, and satisfying one does not satisfy the other. This is the duty with the transition to 2 December 2026 for systems already on the market.
3. Emotion recognition and biometric categorisation
Deployers must inform the people exposed to the system, and process any personal data in line with EU data protection law. Narrow exceptions exist where the system is used to detect, prevent or investigate criminal offences, subject to safeguards.
4. Deepfakes and public interest text
Deployers who generate or manipulate content depicting real people, places or events must disclose that it is artificial. The same applies to AI-generated text published to inform the public on matters of public interest, unless a human has reviewed it and someone holds editorial responsibility.
Two practical notes. Article 50 does not care whether your system is high-risk, so the December 2027 deferral gives you nothing here. And the information you provide has to reach the person at the first interaction, in a clear and distinguishable way. If you have received a question about your labelling from a customer or an authority, our Article 50 transparency response letter covers the structure that works.
Who must comply, and why location does not save you
The Act assigns obligations by the role you play, not by what you call yourself internally.
- Provider. You develop an AI system, or have one developed, and place it on the market or put it into service under your own name. Providers carry the heaviest obligations.
- Deployer. You use an AI system under your own authority in a professional context. Deployers have their own duties, particularly around disclosure, human oversight and using systems as instructed.
- Importer and distributor. You bring systems into the EU market or make them available, with verification and record-keeping duties attached.
A single organisation often wears two hats. If you buy a generative model and ship it inside your own product under your own brand, you are likely a provider of that product even though you did not train anything.
The Act also has extraterritorial reach, and the Omnibus left that untouched. If your system, or its output, is used in the European Union, the Act can apply to you regardless of where the company sits. Having no EU entity is not a defence. What matters is whether the system touches people in the EU.
What counts as a high-risk AI system
This is the category whose deadline moved, so it is worth being precise about what falls inside it.
Two routes lead to a high-risk classification. The first is AI used as a safety component of, or as, a product already regulated under EU product safety law, listed in Annex I. That route now runs to 2 August 2028. The second is the list of standalone uses in Annex III, now running to 2 December 2027, which includes:
- employment, recruitment and worker management, for example CV screening or ranking tools,
- access to essential private and public services, including creditworthiness and credit scoring,
- biometrics and biometric categorisation,
- education and vocational training, for example exam scoring or admission decisions,
- critical infrastructure, law enforcement, migration and border control, and the administration of justice.
If you are in one of these areas, the useful way to spend the extra sixteen months is on the parts that take longest: data governance evidence, a risk management file that reflects what the system actually does, logging that can later produce an individual explanation, and a human oversight arrangement with a named person who has the authority to overrule the output. Standards work is expected to conclude around late 2026 and early 2027, which leaves a narrow window if you wait for it.
The penalties, and which ones are live
Article 99 sets a tiered structure, and the tier that applies to you depends on which rule you broke.
Breaching the Article 5 prohibitions carries fines of up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher.
Most other breaches, including provider obligations under Article 16, deployer obligations under Article 26, importer and distributor duties, and the Article 50 transparency obligations, carry fines of up to EUR 15 million or 3% of total worldwide annual turnover. This is the band that now bites for undisclosed chatbots and unmarked synthetic content.
Supplying incorrect, incomplete or misleading information to notified bodies or national authorities in reply to a request sits in its own band: up to EUR 7.5 million or 1% of worldwide annual turnover. It is worth noticing that a careless answer to a regulator is itself a finable act. For SMEs and start-ups, the lower of the amount or the percentage applies.
Finally, the AI Act does not displace the GDPR. Where personal data is processed, both regimes run at the same time and data protection authorities keep their jurisdiction over the personal data side. Two supervisors, two sets of paperwork.
How to respond to an AI Act compliance request
Now that enforcement has started, the volume of requests has gone up. They arrive from national market surveillance authorities, from the EU AI Office on general-purpose model matters, from customers running procurement due diligence, and from complainants who have filed something against you. A weak or late answer is what turns a routine question into an investigation.
1. Identify the request precisely
Date, sender, reference number, and exactly what was asked. This creates the paper trail and shows you read it properly.
2. State your role under the Act
Provider, deployer, importer or distributor, and which system you are talking about. Every obligation flows from that, so getting it wrong contaminates everything after it.
3. Answer point by point
Take the questions in the order they were asked and answer each with facts. Where the Act expects documentation, describe what you hold and reference the enclosures rather than promising to send it later.
4. Be candid about gaps
If something is missing, say so, say what you are doing, and give a date. A documented remediation plan reads far better than silence, and materially better than an answer that turns out to be inaccurate.
5. Close with a contact and a next step
Name a responsible person, confirm you will provide further information, propose a concrete next step, and list the enclosures.
DocuGov.ai builds this structure into jurisdiction-aware letters, so a request that lands on a Friday afternoon does not consume your weekend. Start from the AI Act compliance response generator, or browse the full set of AI Act compliance letters.
What individuals and affected people can do
The Act is not only a corporate compliance exercise. It gives people things they can use.
If you think a system uses a banned practice, such as social scoring or emotion recognition in the workplace, you can report it to your national market surveillance authority. Our guide to filing a prohibited AI practice complaint sets out what to include. From 2 December 2026 that list also covers AI used to produce non-consensual intimate imagery.
Separately, and available today rather than in 2027, the GDPR gives you rights over automated decisions. You can demand human intervention and contest a decision taken solely by automation with a GDPR Article 22 objection, and you can ask for meaningful information about the logic involved with a right to explanation request. The AI Act right to an explanation under Article 86 arrives with the high-risk regime in December 2027, so until then the GDPR route is the one that works.
These letters succeed when they are specific. Name the decision, the date, the system if you know it, and exactly what you want the organisation to do, with a deadline.
Common mistakes to avoid
Reading the delay as a general pause. The deferral covers the high-risk chapter. Transparency, the prohibitions, GPAI rules and AI literacy were not touched and are enforceable now.
Assuming the December 2026 grace period covers you. It applies only to generative systems placed on the market before 2 August 2026, and only to the machine-readable marking duty in Article 50(2). Anything launched since then had to comply from day one.
Treating a terms of service clause as disclosure. The duty is to inform the person at the point of interaction, in clear and distinguishable form.
Confusing visible labels with machine-readable marking. They are separate requirements and most watermarking solutions only address one of them.
Working from pre-July 2026 guidance. Consolidated texts and third-party trackers were slow to reflect the amendment. If a checklist tells you Annex III applies in August 2026, it predates Regulation (EU) 2026/1744.
Answering a regulator informally. An unstructured email with no documents invites a follow-up, and an inaccurate one carries its own penalty band.
Forgetting the GDPR. If personal data is in play, you are running two compliance regimes at once.
Key takeaways
- Article 50 transparency has applied since 2 August 2026, and national authorities can enforce it.
- Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and amended the AI Act for the first time.
- High-risk obligations moved to 2 December 2027 for standalone Annex III systems and 2 August 2028 for Annex I embedded systems.
- The next deadline is 2 December 2026: machine-readable marking for generative systems already on the market, plus the two new Article 5 prohibitions.
- Article 50 breaches sit in the EUR 15 million or 3% band, while Article 5 breaches reach EUR 35 million or 7%.
- Location does not decide scope. If the system or its output is used in the EU, the Act can apply.
- Answer requests formally, point by point, with documents. DocuGov.ai can generate that letter in minutes.

