All posts

The AI Act got delayed. The part that hits you on 2 August did not.

The Digital Omnibus moved high-risk obligations to December 2027. Article 50 transparency duties still apply from 2 August 2026: chatbot disclosure, machine-readable marking of synthetic content, deepfake labelling. What that means for an ordinary GTM stack.

Since the Digital Omnibus, one sentence has been doing the rounds in European companies: “The AI Act is delayed, we have until 2027.” The first half is true. The second half is wrong for most companies, and from 2 August 2026 the mistake is worth up to €15 million.

This article separates the two cleanly: what was actually postponed, what starts on 2 August, and which five duties an average go-to-market stack has to meet from then on.

What comes into force on 2 August 2026

On 2 August 2026 the transparency obligations in Article 50 of the AI Act apply, and they apply regardless of risk class. They catch every AI system that talks to people or generates content: a support chatbot as much as a high-risk system, a text module you built into your CRM as much as a SaaS feature you bought.

That property is the whole story, and the reason the delay passes them by. Article 50 does not hang off a classification. There is no assessment that can end in “does not apply to us.” If your system interacts with a person or produces content, it is in scope.

What was postponed, and why it is a different subject

Only the high-risk obligations moved. The Digital Omnibus, proposed by the Commission on 19 November 2025 and formally adopted at the end of June 2026 after the provisional agreement of 7 May, pushes stand-alone Annex III high-risk uses back by 16 months to 2 December 2027. AI embedded in products already regulated under Annex I moves to 2 August 2028.

Annex III is the list many companies wrongly apply to themselves: biometric identification, critical infrastructure, education, recruitment and workforce management, access to essential services such as credit and insurance, law enforcement, migration, justice. It enumerates fields of use, not technologies. An agent that chases open quotes is not on it. A model that pre-sorts job applications is.

The delay only takes legal effect on publication in the Official Journal and entry into force three days later. Publication was expected during July 2026. If you are building a roadmap against the December 2027 date, look up the OJ reference yourself rather than trusting a summary.

Why it was postponed is worth knowing, because it says something about who was behind. It was not the companies. The harmonised standards were not finished, the notified bodies for conformity assessment were not designated, several national authorities were not operational. What got delayed was an inspection regime that could not yet inspect. Article 50 needs no inspection regime, because nothing there gets certified, which is exactly why it was not moved with the rest.

The five Article 50 duties, in plain language

Article 50 asks for five things, and each of them can be checked in one sentence.

One: anyone talking to an AI has to know it. A chatbot, a voice agent, an automated email responder has to disclose that there is no human on the other end. The exemption applies only where it is already obvious to a reasonably observant person from the context. “It says so in our terms” is not disclosure.

Two: AI-generated content has to be marked machine-readably. This duty falls on the provider of the system, not the deployer. Anyone generating synthetic audio, image, video or text must mark the output as artificially generated in a machine-readable format. In practice that means watermarks and metadata, not a line in a footer.

Three: emotion recognition and biometric categorisation have to be announced. Whoever deploys such a system informs the people exposed to it. This catches more companies than it sounds like, because several sales tools run sentiment analysis over call recordings.

Four: deepfakes have to be recognisable as such. Anyone generating or manipulating image, audio or video so that it appears authentic has to disclose it. A softened version applies to artistic and satirical work.

Five: AI-generated text on matters of public interest has to be labelled. The duty falls away where a human has taken editorial responsibility and reviewed the text. That exemption is why an edited blog article needs no label and a fully automated news feed does.

What this means for an ordinary GTM stack

For most mid-market companies exactly two of the five are relevant, and both are an afternoon’s work.

The chatbot disclosure catches every company with an assistant on its website or in a customer portal. If you answer inbound automatically, the pattern in our blueprint for an email triage agent, the disclosure belongs in the reply itself. A line in the signature is enough, but it has to be there, not only in the privacy notice.

Marking synthetic content usually does not catch you as a deployer: the duty sits with the model provider. It does catch you if you build a system that generates content for third parties, because in that relationship you are the provider. This is where the contract with your AI vendor earns its keep, since the split between provider and deployer is the same question you already have to answer for data processing under GDPR.

What you do not need: a conformity assessment, a notified body, a quality management system under Article 17. Those are high-risk obligations, and they moved. Anyone selling you a compliance programme of that size before 2 August is selling you something that falls due at the end of 2027.

Reading the fine schedule correctly

The €35 million figure that appears in almost every AI Act article applies to prohibited practices under Article 5, not to transparency breaches. Article 99 has three tiers, and confusing the top one with the middle one is the most common error in the coverage.

Prohibited practices under Article 5, such as social scoring or untargeted scraping of facial images: up to €35 million or 7% of total worldwide annual turnover. Breaches of the other obligations, Article 50 included: up to €15 million or 3%. Supplying incorrect information to authorities: up to €7.5 million or 1%.

For the first two tiers the higher of the two figures applies. For SMEs and start-ups it inverts: there the lower one does.

AI Act Article 99(3), (4) and (6)

That inversion is the most practically useful number in this article and it appears in almost no summary. For a company turning over €8 million it means the ceiling for a transparency breach is €240,000, not €15 million. That is still real money for a missing half-sentence in a chatbot, but it is not an existential question, and the difference decides whether a project gets set up out of fear or out of judgement.

The penalty framework itself has been in force since 2 August 2025. The Article 5 prohibitions and the AI literacy duty have applied since 2 February 2025. Anyone who thinks the AI Act starts now has missed eighteen months.

What is realistically doable before 2 August

Three things, in this order.

A list of every system that talks to people or generates content. Not of your AI systems in general, but of that intersection specifically. In most companies it is three to eight entries, and IT does not know about half of them because marketing bought them.

One line per entry: are we the provider or the deployer? Buy a system and put it to work and you are the deployer, owing the disclosure duties. Build it and make it available to others and you are the provider, additionally owing the machine-readable marking. For agents you build for your own use, you are both.

Put the disclosure where the interaction starts. Not in the terms, not in the privacy notice, but in the bot’s first message, in the subject line of the automated reply, in the voice agent’s opening.

Systems already in operation before 2 August 2026 get a narrow transition until 2 December 2026 for the marking duty. It is narrow, and it is not an extension for the chatbot disclosure.

In May 2026 the Commission put draft guidelines on Article 50 and a draft code of practice on content marking out for consultation. Neither is final as this is written. That changes nothing about applicability: the duty is in the regulation, the code only describes how to meet it cleanly.

Frequently asked questions

Does the AI Act apply to us if we only use ChatGPT internally?

For purely internal use of a bought-in assistant, the Article 50 transparency duties do not catch you, because you neither face customers with it nor generate content for third parties. As soon as an output goes outward (an automatically sent reply, for instance) you are a deployer and owe the disclosure.

Is a line in the privacy policy enough as disclosure?

No. Article 50 requires the information at the time of the interaction, in a form the affected person can perceive. A notice you only find by following a link does not meet it.

What about systems that went live before 2 August 2026?

For marking AI-generated content there is a narrow transition until 2 December 2026. The duty to disclose an AI interaction applies from 2 August with no transition.

Do we need a conformity assessment now?

Only if you operate a high-risk system under Annex III or Annex I, and even then not until 2 December 2027 or 2 August 2028 respectively. Article 50 involves no conformity assessment, no notified body and no certificate.

Who is liable if our vendor built the agent?

That follows the role, not the invoice. The deployer owes the disclosure duties towards its own users even when a third party built the system. Who implements the marking in the product is a contract question: settle it in writing, or you will settle it under time pressure.


Sources: AI Act Article 99, penalties, Gibson Dunn on the Omnibus agreement and the new deadlines, Jones Walker on what still applies on 2 August.

Related reading