The European Commission announced on 31 July that from 2 August its AI Office, together with national authorities, would begin enforcing the Artificial Intelligence Act. That date is today. On the same date, the transparency rules kick in: certain AI systems now have to tell users when they are dealing with AI, and when content has been generated or altered by it.
Concretely, that is Article 50. Chatbots and other interactive systems must disclose that they are not human. Deepfakes — images, video or audio edited or generated with AI — must be labelled. And AI-generated or altered content has to carry machine-readable marks so it can be detected downstream. Alongside the rules, the Commission published a first list of more than 180 organisations that have signed its Code of Practice on transparency of AI-generated content, the voluntary framework it and the AI Board have recognised as a way to demonstrate compliance. It also opened an AI Act complaints tool and a whistleblower tool.
Here is the part most companies missed. The Digital Omnibus on AI entered into force on 27 July and moved the obligations for stand-alone high-risk systems under Annex III from 2 August 2026 to 2 December 2027, with high-risk systems embedded in regulated products under Annex I pushed to 2 August 2028. Article 50 did not move. Two deadlines were stacked on the same day; one slid sixteen months and one did not, and the headline was “AI Act delayed.”
Our take: The delay was the story everyone read, and it is the wrong story for almost every company that read it. The high-risk regime touches a comparatively narrow set of builders — hiring, credit, biometrics, medical devices. Article 50 touches anyone who ships a chatbot, a support widget, a generated product photo or a synthetic voiceover to a European. That is a far bigger population, and it is the population most likely to have concluded from a fortnight of “Brussels blinks” coverage that it had until 2027. The compliance work is also not exotic: disclosure text, provenance marks, a labelling policy. It is unglamorous plumbing that takes weeks, which is precisely why it is the kind that gets deferred to a deadline that quietly never moved.
What being wrong costs
Under Article 99, breaches of the prohibited-practice rules in Article 5 carry administrative fines up to €35 million or 7% of total worldwide annual turnover, whichever is higher. Most other breaches — including the Article 50 transparency obligations and the general-purpose model rules — top out at €15 million or 3% of worldwide turnover, again whichever is higher. For a mid-sized SaaS business the percentage is irrelevant and the fixed number is not; for anyone above roughly €500 million in revenue, the percentage is the one that bites.
The timing rhymes with what is happening in the United States, which is what makes it awkward. California’s AI transparency law became operative on the same day, with its own provenance and detection-tool requirements for large generative providers. The federal posture, meanwhile, runs the other direction: the covered-frontier-model threshold that came due this weekend is voluntary and classified. Three regimes, one weekend, and only one of them will tell you in writing what it expects.
What to watch
- The first enforcement action, and who brings it. The AI Office has powers over general-purpose models; national authorities handle the rest. The first case shows whether this is centralised in Brussels or fragmented across 27 regulators.
- Whether the Code of Practice becomes the default. Signing is voluntary, but 180-plus signatories on day one is the beginning of a de facto standard. If it hardens, the practical question stops being “does Article 50 apply to us” and becomes “why did you not sign.”
- Whether machine-readable marking actually survives contact with the internet. Provenance metadata is easy to embed and easy to strip. A labelling rule that platforms silently erase on upload is a rule in name only.
- Whether December 2027 holds. The high-risk deadline has now moved once. Deadlines that move once are a different asset class from deadlines that never have — and Europe is simultaneously trying to build the compute base it wants to regulate.
