Europe spent the spring telling companies its hardest AI rules were slipping. That was true. It was also half the story.
On 24 July the Digital Omnibus on AI — Regulation (EU) 2026/1744 — was published in the Official Journal. It entered into force on 27 July, six days before the AI Act's 2 August compliance date, and it moved the deadlines everyone had been dreading. Obligations for stand-alone high-risk systems under Annex III — hiring tools, credit scoring, education, law enforcement, critical infrastructure — shifted from 2 August 2026 to 2 December 2027. AI embedded in regulated products under Annex I, such as medical devices, machinery and vehicles, went out to 2 August 2028.
Article 50 did not move. The AI Act's transparency obligations applied on 2 August 2026 exactly as originally written — and unlike the high-risk regime, they land hardest on companies that would never describe themselves as AI companies at all.
What actually took effect
Article 50 carries four duties, and none of them require a conformity assessment or a notified body:
- Tell people they are talking to a machine. Systems built to interact directly with humans — support chatbots, voice assistants, automated phone lines — must be designed so users know they are dealing with an AI.
- Mark synthetic output. Providers of generative systems must embed machine-readable markers in AI-generated audio, image, video and text.
- Disclose deepfakes. Deployers publishing artificially generated or manipulated content resembling real people, places or events must say so.
- Flag emotion recognition and biometric categorisation. People exposed to those systems have to be told.
Breaches sit in the AI Act's middle penalty tier under Article 99: up to €15 million or 3% of total worldwide annual turnover, whichever is higher. The headline €35 million / 7% tier is reserved for the prohibited practices in Article 5.
There is one piece of runway. Systems placed on the market before 2 August 2026 have until 2 December 2026 to satisfy the machine-readable marking duty in Article 50(2). The obligation to disclose that a user is talking to a bot comes with no such grace period.
Our take: The delay bought time for the compliance work most companies were never going to finish — technical files, CE marking, database registration. It bought nothing for the compliance work almost everyone needs: a line of text on a chatbot and a marker on generated content. If you run a support bot for European customers or push AI-made creative into the EU, your deadline was eight days ago. And the test is territorial — where the system is used, not where the company is registered. This is the same governance gap we keep finding inside companies, where nobody can name the owner of the agent already running in production.
The quieter changes
The Omnibus was not purely a reprieve. It added a prohibition to Article 5 covering AI systems that generate non-consensual intimate imagery or child sexual abuse material, with a transitional period running to 2 December 2026. For providers, the ban reaches past systems built for that purpose to any system where such output is a reasonably foreseeable and reproducible result and adequate safeguards are absent.
It also sharpened the enforcer. The EU AI Office picked up powers to run investigations, conduct on-site inspections, accept binding commitments and impose fines, plus exclusive competence over AI systems built on general-purpose models by the same provider and over systems embedded in very large online platforms. National authorities keep law enforcement, borders, courts and financial institutions. The Article 4 AI literacy duty was softened — firms must support staff literacy rather than guarantee a level of it — and the deadline for member states to stand up regulatory sandboxes moved to 2 August 2027, a year later than planned. That is a familiar pattern for a bloc that has been consistently outspent and outpaced on AI infrastructure while writing the rulebook everyone else has to read.
What to watch
- 2 December 2026 — the marking grace period closes for pre-August systems, and the intimate-imagery prohibition's transitional window ends the same day.
- The first Article 50 action, and whether a regulator opens on a large platform or a mid-market deployer. The first sets headlines; the second sets the real compliance bar.
- Whether the AI Office actually uses its new inspection powers in year one, or leaves the work to national authorities with thinner budgets.
- How disclosure duties interact with agent liability, after a US appeals court put the button-press on the user rather than the AI company.
- 2 December 2027 — Annex III high-risk obligations apply. Sixteen months, not a cancellation.
