A support bot on a Dublin storefront has been greeting customers for a year without once mentioning it is software. On Sunday that was a design choice. On Monday it became a gap in the file. And the operator running it almost certainly believes the EU AI Act got postponed, because that is the headline that ran everywhere in June.
TL;DR: 2 August 2026 was never cancelled. The high-risk rules moved to December 2027, but Article 50 transparency, general-purpose AI enforcement powers and the penalty regime all switched on as scheduled. If you run a customer-facing bot in the EU, the live obligation is yours.
Why the delay headline sent everyone to the wrong file
Two separate clocks got merged into one story. The Digital Omnibus on AI, tabled by the European Commission in November 2025 and given final Council approval on 29 June 2026, pushed the high-risk obligations back hard. Annex III systems (recruitment screening, credit scoring, education, essential services) now apply from 2 December 2027. Annex I systems, the ones baked into regulated products like medical devices and machinery, moved to 2 August 2028. That is a real reprieve, and teams that spent 2025 building conformity assessments earned it.
But the Omnibus left the other clock alone. Article 50, the transparency chapter, came into application on schedule. It is short, it is unglamorous, and it reaches far more businesses than Annex III ever did. People talking to an AI system have to be told they are talking to an AI system, unless that is obvious from context. AI-generated or manipulated content, deepfakes above all, has to be disclosed as such. AI-generated text published to inform the public on a matter of public interest has to be labelled unless a human editor takes responsibility for it. None of that requires you to be a model provider. It requires you to have a chatbot, or a content pipeline, and EU users.
The second live change is enforcement. General-purpose AI obligations have technically applied since August 2025, but with nothing behind them. The European Commission's AI Office can now compel documentation, run evaluations and issue fines against general-purpose model providers, and the ceiling it works with is the number worth internalising below. That matters to more than the frontier labs. If you fine-tune an open model, substantially modify one, or white-label it into the EU market, the provider classification question is suddenly worth an hour with a lawyer. Anyone who has read our breakdown of why cheap AI model API pricing will not survive the decade already knows the industry is being repriced from below. Compliance is now part of that price.
ENFORCEMENT DATE
2 Aug 2026
Article 50 and penalties
MAXIMUM GPAI FINE
15M euros
Or 3% of global turnover
WATERMARKING GRACE
4 months
Runs out 2 December 2026
ANNEX I SLIP
2 Aug 2028
AI inside regulated products
The four-month figure is the one people misread. Article 50 splits into a human-facing duty and a machine-readable one, and only the second got breathing room. Systems already on the market before this month get until early December before they have to embed provenance metadata and watermarks, because the technical standards for doing it are still catching up. The line your bot shows a customer got no such extension. Your disclosure text is due now. Your watermarking is due at the end of the year. Teams reading a single grace period into both halves are the ones who will be surprised. A 27 May 2026 Gibson Dunn client alert on the Omnibus agreement pinned the size of that reprieve at roughly 16 extra months for Annex III teams, and plenty of them have quietly stopped work rather than spending it. That instinct is understandable and it is a mistake, because the same AI inventory that satisfies a documentation request this year is the one those obligations will demand in 2027. If you are still budgeting agents as a line item rather than a governed asset, our look at the real costs and honest ROI of AI agents for small business is the cheaper place to start.
A ceiling set at three percent of global turnover is not a rounding error for anyone who fine-tunes a model and ships it into Europe.
Three regimes, three clocks
Most compliance confusion this summer comes from treating the AI Act as one deadline instead of three overlapping regimes with different owners, different evidence and wildly different exposure. Lay them side by side and the priority order stops being a debate.
| Dimension | Article 50 Transparency | GPAI Obligations | High-Risk (Annex III) |
|---|---|---|---|
| Applies From | Now, this month | Duties since 2025, fines now | December 2027 |
| Who It Binds | Providers and deployers alike | Model providers and modifiers | Providers, then deployers |
| Core Duty | Disclose AI, label content | Documentation, copyright, testing | Conformity assessment, oversight |
| Effort To Comply | Hours, mostly copywriting | Weeks, legal plus engineering | Quarters, with external audit |
| Evidence Needed | Screenshots of the disclosure | Training data summary, test logs | Full technical file, risk logs |
| Grace Period | Only for machine-readable marking | None remaining | Sixteen months of runway |
| First Regulator Move | A complaint from a user | A documentation request | Nothing yet |
| Best Suited For | Product and marketing, this week | Legal and engineering, jointly | A named owner with budget |
Read down the Effort To Comply row and the sequencing writes itself. The obligation that binds the most companies is also the cheapest one to satisfy, and it is the one that has had the least attention paid to it all year. That inversion is the whole story of this deadline.
The timeline above shows five application dates for the EU AI Act, running from entry into force in August 2024 through the deferred Annex III high-risk obligations in December 2027, with the current month marked as the transparency and enforcement milestone.
Where this goes wrong in practice
Enforcement capacity is the honest caveat. Several member states have still not stood up the market-surveillance authorities the Act assumes, so the first year is going to look uneven from the outside. My read, and it is a read rather than a fact, is that the gap closes faster than the optimists expect, because a documentation request costs a regulator almost nothing to send and is the standard opening move. The organisations that struggle will not be the ones with weak policies. They will be the ones that cannot answer a simple question inside a week: what AI is running here, who owns it, and what is it for.
There is a familiar shape to this. European regulators have run the same play on packaging, where extended producer responsibility rules turned a procurement detail into a balance-sheet item almost overnight, something we traced in our piece on how sustainable packaging technology is reshaping the supply chain. The pattern repeats: a quiet compliance clause, a slow start, then a sharp acceleration once the first penalties land and procurement teams start putting the question into their vendor questionnaires. Your customers will ask before your regulator does.
- Disclosure lands between legal, marketing and product, which in practice means it lands on nobody. Name one owner or it will not get done.
- Voice agents get forgotten. Teams patch the web chat widget and leave the phone system saying nothing at all.
- "Obvious from context" is doing heavy lifting in a lot of internal legal memos. It usually holds for an internal tool and rarely holds for anything a customer or applicant touches.
- Shadow AI breaks the inventory before it starts. The tools a team adopted without asking are exactly the ones missing from the sanctioned list.
- Non-EU businesses assume they are out of scope. Serving EU users is the trigger, not being established there.
Three changes that missed the coverage entirely
- A new Article 5 prohibition now bans AI systems generating non-consensual intimate imagery and child sexual abuse material, with a transitional period running to 2 December 2026. It reaches any general-purpose image or video tool where that output is a foreseeable, reproducible result without meaningful safeguards.
- The deadline for member states to establish national AI regulatory sandboxes slipped by a year, to 2 August 2027, which is part of why supervisory capacity is thin right now.
- The Article 4 AI literacy duty was softened. Providers and deployers must support the development of AI literacy among staff rather than guarantee a level of it, a wording change that quietly removes an unmeasurable standard.
Open your product this afternoon and find every place a machine talks to a human on your behalf: web chat, phone agents, automated email replies, generated blog copy. Add the sentence that says it is AI. Write down the date you did it and who signed off. That record is worth more in an inquiry than any policy document you could commission, and unlike the high-risk file, it is finished by Friday.
No comments:
Post a Comment