The EU AI Act Deadline That Did Not Move
On 2 August 2026 the EU AI Act's transparency obligations became enforceable. Four days ago. Many teams do not know, because the news that reached them was the other one: in June the Digital Omnibus pushed the high-risk regime back by more than a year, and a great many compliance programmes quietly stood down on the strength of it.
The delay is real. The stand-down was a misreading, and it is the kind that only becomes visible when someone asks a question you cannot answer.
What moved, and what did not
Delayed by the June 2026 Digital Omnibus:
- The high-risk regime for Annex III systems — employment, creditworthiness, education, access to essential services — from 2 August 2026 to 2 December 2027.
- High-risk AI embedded in regulated products (Annex I) to 2 August 2028.
Not delayed, and in force since 2 August 2026 — the Article 50 transparency duties:
- Tell people they are talking to a machine. Providers must ensure users know they are interacting with an AI system, unless that fact is already obvious.
- Mark synthetic content machine-readably. AI-generated or manipulated audio, image, video and text must be marked in a machine-readable format, to the extent technically feasible.
- Disclose deepfakes. Deployers of artificially generated or manipulated image, audio or video content must say so.
- Notify on emotion recognition and biometric categorisation. People exposed to these systems must be informed.
- Label AI-generated text on matters of public interest, with an exception where the content had human review or editorial control.
Penalties for Article 50 breaches run to €15 million or 3% of total worldwide annual turnover, whichever is higher, with lower ceilings for qualifying SMEs.
Why the misreading is so easy
“The AI Act high-risk deadline moved to 2027” is a true sentence. It is also, for most organisations, the only sentence that travelled — because it is the one that sounds like relief, and relief propagates faster than nuance.
The trap is that the delayed obligations are the heavy ones — conformity assessment, risk management systems, technical documentation, post-market monitoring. Those are programmes. The obligations that landed are light by comparison: mostly disclosure and labelling. So the mental arithmetic goes “the big thing moved, therefore the work moved”, and the small thing that did not move is exactly the sort of thing nobody assigns an owner to.
It is also the sort of thing anyone can check from outside. Whether your risk management documentation is adequate takes an audit. Whether your chatbot says it is a chatbot takes ten seconds and a browser.
What to actually check, this week
- Every chat interface you operate. Support widgets, in-product assistants, voice bots, WhatsApp and SMS flows. Does a first-time user learn they are talking to a machine before they start telling it things? “It is obvious” is a defence you have to be willing to argue, not assume.
- Anything you publish that a model wrote. Marketing copy, documentation, support articles, social posts. The public-interest text duty is narrower than “all AI text”, and the human-review carve-out is genuine — but you need to know which of your content passes through review and which does not, and most teams have never drawn that line.
- Generated media. If you produce AI images, audio or video for any public-facing purpose, machine-readable marking is now the expectation. Check whether your tooling emits provenance metadata and whether your pipeline strips it — image processing very often does, silently.
- Any emotion or biometric inference. Sentiment scoring on calls, attention tracking, face-based categorisation. These carry notification duties and people underestimate how often a vendor feature quietly does one.
- Write down who owns this. If the answer is “legal will tell us” and legal's answer is “engineering will implement it”, the obligation currently has no owner, which is the state most of these are in right now.
The honest scope note
This is not the wave of enforcement actions that the high-risk regime will eventually bring, and pretending otherwise would be scaremongering. Article 50 is a narrow set of duties, several have real carve-outs, and “to the extent technically feasible” is doing visible work in the synthetic-content marking requirement.
What makes it worth an afternoon is the asymmetry: the checks are cheap, they are externally observable, and the failure mode is a complaint from someone who noticed rather than a finding from an audit you were preparing for. Cheap to fix, easy to spot, and enforceable is an unusual combination and it is why this one deserves attention out of proportion to its weight.
Related reading: the Cyber Resilience Act obligations arriving on 11 September — a second European deadline in the same quarter, and one that does land on engineering rather than on disclosure.
