← Back to all posts
August 5, 2026TechRevati

The AI Act deadline that moved, and the one that didn't: what applies from 2 August 2026

The Digital Omnibus pushed Annex III high-risk obligations to December 2027 — and left Article 50 transparency in force on 2 August 2026 exactly as scheduled. Which of your systems just came into scope, which marking duty lands on 2 December 2026, and what the extra sixteen months are actually for.

  • compliance
  • ai
  • eu-ai-act
  • transparency

"The EU delayed the AI Act" is half true, and the wrong half to plan on

On 27 July 2026 the Digital Omnibus entered into force, three days after publication in the Official Journal. It moved the deadline most teams had circled: the obligations for stand-alone high-risk systems in Annex III — employment, education, credit, essential services — went from 2 August 2026 to 2 December 2027. High-risk AI embedded in regulated products under Annex I went from 2 August 2027 to 2 August 2028.

That is a genuine sixteen-month reprieve, and it was widely reported as the story. The part that got much less coverage is that Article 50 — the transparency obligations — did not move. It applied on 2 August 2026, on the original schedule. If you shipped anything that talks to a person, generates content, reads emotions or publishes machine-written text, your obligation started three days ago while your compliance programme was being re-planned around a 2027 date.

This is engineering and practitioner guidance on how teams meet these obligations, grounded in production delivery of retrieval and agent systems. It is not legal advice, and it is not a compliance guarantee. Dates and scope here reflect the Omnibus text as published; confirm your own classification, obligations and deadlines against the Official Journal text and your own counsel. Nothing below transfers your accountability to a vendor.

What applied on 2 August 2026

Article 50 is short, and it binds two different parties in different paragraphs. Getting that split right is most of the work.

Providers must disclose the machine (Art. 50(1)). An AI system intended to interact directly with people has to make it apparent that it is an AI system — unless that is obvious to a reasonably well-informed, observant and circumspect person. A support chatbot behind a human-sounding name is squarely in scope. The practical test is not whether your team knows it is a bot; it is whether a first-time visitor under time pressure would.

Providers must mark synthetic output machine-readably (Art. 50(2)). Systems generating synthetic audio, image, video or text must mark their outputs as artificially generated or manipulated, in a machine-readable format, with solutions that are effective, interoperable, robust and reliable. A visible "made with AI" line in your UI does not satisfy this on its own — it is not machine-readable. This is the paragraph that needs engineering rather than copywriting: content credentials, embedded provenance metadata, or watermarking, applied at generation time. Assistive editing that does not substantially alter the input data is out of scope.

Deployers must disclose emotion recognition and biometric categorisation (Art. 50(3)). If you run such a system, the people exposed to it must be informed of its operation — and the personal-data processing still has to stand on its own GDPR basis. These two are separate duties; satisfying one does not satisfy the other.

Deployers must disclose deepfakes and public-interest AI text (Art. 50(4)). Image, audio or video that is an artificial or manipulated likeness has to be disclosed as such. Separately, AI-generated or AI-manipulated text published to inform the public on matters of public interest must be disclosed as AI-generated — with an explicit exemption where the content underwent human review and a natural or legal person holds editorial responsibility.

That last exemption deserves a moment, because it is the one most organisations touch without noticing. A company blog, a newsroom, a public-sector notice: if the text is machine-written and nobody with a name took editorial responsibility for it, you owe a disclosure. The way out of the disclosure is not a clever label — it is a human review and a named owner. Anyone running an "AI writes and publishes to your site daily" tool is, from 2 August 2026, either producing disclosed AI content or producing undisclosed AI content in scope of this paragraph.

And the timing rule (Art. 50(5)): the information has to be given clearly and distinguishably at the latest at the first interaction or exposure, and it has to meet accessibility requirements. A disclosure in a footer or a policy page reached later is not first-interaction disclosure.

What falls due on 2 December 2026

Two things, and both are easy to lose in the noise of the 2027 date:

  • The machine-readable marking grace period ends. Article 50(2) gave systems already on the market before 2 August 2026 until 2 December 2026 to comply. If you have a generative feature that predates the deadline, that is your date, and it is four months out — not sixteen.
  • The new prohibitions bite. The Omnibus added prohibited practices covering non-consensual intimate imagery and child sexual abuse material, with the transitional period ending on the same date. Prohibitions sit in the top penalty band — up to €35 million or 7% of worldwide annual turnover.

What the sixteen months are actually for

If you deploy an Annex III system, the temptation is to file the work under 2027 and move on. Two arguments against that, both practical rather than moral.

First, the obligations that were deferred are the ones with the longest lead time: a risk-management system, technical documentation, logging with defensible retention, human-oversight design, post-market monitoring, and — for providers — a conformity assessment involving a third party in some cases. None of that is a quarter of work. Teams that start in mid-2027 will be assembling evidence about decisions they made in 2025 and cannot reconstruct.

Second, the deferral applies to the high-risk regime, not to everything else you are already subject to. GDPR did not move. DORA did not move, if you are in financial services — we wrote a build checklist for bringing an AI system under DORA that reads each pillar as an engineering task. Article 4 AI-literacy duties and the Article 5 prohibitions have applied since February 2025. The GPAI obligations have applied since August 2025. The Omnibus rescheduled one layer of a stack that is otherwise already live.

The productive reading of the delay: you now have time to do the deferred work properly and to do it as engineering rather than as documentation written after the fact. Concretely, in the order that survives an audit —

  1. Classify honestly, and write down why. Which of your systems are Annex III, which are Annex I, which are neither. The reasoning matters more than the verdict, because the verdict will be challenged.
  2. Instrument before you document. Structured logs of inputs, model and version, retrieval sources and outputs, with a retention period you can defend, are the evidence every later obligation is written from. Retrofitting logging is how compliance programmes slip.
  3. Design the human oversight, don't assert it. "A human reviews the output" is not oversight unless that human can see what the system used, has the authority to override it, and has time budgeted to do so.
  4. Do the Article 50 work now regardless of classification — it is in force, it is comparatively cheap, and it is visible to your customers in a way that the rest of the Act is not.
  5. Know where inference runs. Deferred deadlines do not defer data-transfer questions. Where the model runs, who operates it and which jurisdiction reaches it are the questions that shape the architecture — and they are the hardest to change late. That is the subject of our security and compliance pages.

A note on Article 27, since it comes up

The fundamental rights impact assessment under Article 27 is narrower than it is often described. It binds deployers that are public bodies or private entities providing public services, and deployers of certain Annex III systems used for creditworthiness and life/health insurance risk assessment. A private company deploying an Annex III system outside those categories is not obliged to produce a FRIA — though the exercise is a reasonable governance practice, and much of its content overlaps with what Article 26 requires you to be able to show anyway.

Do not let a vendor sell you a FRIA template as if the obligation were universal. Check whether it binds you first.

Where we stand on this ourselves

We publish an AI-generated audio overview on every podcast episode, and every episode carries a disclosure badge saying so — on the episode page, on the episode index, and in the RSS feed at both channel and item level, rather than in a policy elsewhere on the site.

Our written posts are drafted with AI assistance from our own engineering notes, then reviewed and published under the editorial responsibility of TechRevati d.o.o. — the legal person named in our legal notice. That is the arrangement Article 50(4) contemplates when it exempts content that has undergone human review and for which a natural or legal person holds editorial responsibility. We would rather write that down than rely on the reader assuming it.

We did not add that badge because Article 50(4) was coming. We added it because a company selling compliance-grade AI systems that quietly ships undisclosed synthetic content has already lost the argument it is trying to make. The deadline simply made a practice we had into a duty everyone has.

If you are working out which of your systems just came into scope, or what evidence the deferred obligations will eventually ask you to produce, that conversation is a short one to start.