ISHIGHRISK AI
The cornerstone question

What actually applies on 2 August 2026

Article 50 transparency still bites on 2 August 2026. Only the 50(2) marking duty and the high-risk regime moved. Here is the split, duty by duty.

Reviewed 22 July 2026Regulation (EU) 2024/1689, as amended by the Digital Omnibus
In short

Article 50 transparency applies on 2 August 2026 exactly as drafted: chatbot disclosure under 50(1), emotion and biometric notice under 50(3), deepfake and public-interest text disclosure under 50(4). AI Office enforcement begins the same day, against Article 99 penalty tiers that have been enforceable since 2 August 2025. What actually moved is narrower than the headlines: the 50(2) machine-readable marking duty to 2 December 2026 for systems already on the market, standalone Annex III high-risk obligations to 2 December 2027, and Annex I embedded products to 2 August 2028.

Why AI Act delayed is a half-truth

The Digital Omnibus on AI did not delay 2 August 2026. It split it. One date that used to carry both the transparency rules and the whole high-risk regime now carries only the transparency rules, and the high-risk regime has been pushed out by more than a year. Coverage compressed that into three words, and a lot of programmes were stood down on the strength of them.

If you read AI Act delayed and paused work, check what you paused against. Article 50 transparency applies on 2 August 2026 as written. It binds a far wider population than the high-risk regime ever did, and for most businesses it is the nearest hard cliff in the regulation.

The amendment itself has a documented path. The Commission proposal COM(2025) 836 landed on 19 November 2025, trilogue agreement followed on 7 May 2026, the joint IMCO-LIBE position on 2 June 2026, the European Parliament adopted on 16 June 2026 by 423 votes to 57 with 174 abstentions, the Council adopted on 29 June 2026, and it was signed on 8 July 2026. It was not yet published in the Official Journal at the review date on this page, and it enters into force on the third day after publication. The full chronology sits on the page on what the Digital Omnibus changed.

Until the Omnibus is published in the Official Journal, the unamended Regulation (EU) 2024/1689 is technically the baseline - and the unamended text puts the high-risk obligations on 2 August 2026, not 2 December 2027. The pending publication is an argument for keeping your programme running, not for standing it down.

What applies on 2 August 2026, duty by duty

Three of the four Article 50 limbs bite on the date, and they do not all land on the same party. One is a provider duty and two are deployer duties, which matters because a business buying a generative tool and a business building one owe different things. The fourth limb, the 50(2) marking duty, is also a provider duty, but it runs from 2 December 2026 for systems already on the market and from placement for anything launched from 2 August 2026.

2 Aug 2026Article 50(1) chatbot disclosure, 50(3) emotion and biometric notice, 50(4) deepfake and public-interest text disclosure. AI Office enforcement begins.

Article 50(1): the interaction disclosure is a design duty

Providers of systems intended to interact directly with natural persons must design them so that the person is informed they are interacting with an AI, unless that is obvious to a reasonably well-informed, observant and circumspect person. There is a law-enforcement exception. Note the shape of it: the obligation attaches to the design of the system, not to a line in your terms of service, and the obviousness test is measured against a general standard rather than against your most technical user. Art 50(1)

Article 50(3) and 50(4): the deployer duties

Deployers of emotion recognition and biometric categorisation systems must inform the natural persons exposed to them and process the personal data in line with the GDPR. Deployers of systems generating or manipulating image, audio or video that constitutes a deepfake must disclose that the content is artificially generated or manipulated; where the content is evidently artistic, creative, satirical or fictional, the disclosure is limited to a form that does not hamper enjoyment of the work. Separately, deployers publishing AI-generated or manipulated text to inform the public on matters of public interest must disclose it, unless the content underwent human review or editorial control and a natural or legal person holds editorial responsibility. Art 50(3) Art 50(4)

Article 50(5) and 50(6) then govern the manner. Disclosures must be clear and distinguishable at the latest at the first interaction or exposure, must meet accessibility requirements, apply cumulatively where more than one limb is engaged, and are without prejudice to the high-risk rules in Chapter III and to other transparency law. A single banner buried in a settings page does not discharge them. The full Article 50 breakdown works through each limb and the exceptions.

What moved, and the dates it moved to

Exactly three things left 2 August 2026, and one thing joined the calendar. Here is the whole split in one place.

ObligationArticleWho owes itApplies from
AI interaction disclosure (chatbots, voice agents)50(1)Provider2 August 2026
Emotion recognition and biometric categorisation notice50(3)Deployer2 August 2026
Deepfake disclosure50(4)Deployer2 August 2026
Public-interest text disclosure50(4)Deployer publishing the text2 August 2026
Machine-readable marking of synthetic audio, image, video, text50(2)Provider2 December 2026 for systems placed on the market before 2 August 2026; from placement for systems placed on or after that date
Prohibition on CSAM and non-consensual intimate imagery generationArt 5, new limbProvider and deployer2 December 2026
High-risk obligations, standalone Annex III systemsArticles 9 to 15, 43Provider, with deployer duties attached2 December 2027
High-risk obligations, Annex I embedded productsArticles 9 to 15, 43Provider or product manufacturer2 August 2028

The 2 December 2027 date for standalone Annex III systems is a seventeen-month extension from the original 2 August 2026. That is real relief, and it is the only part of the headline that survives contact with the text. The ninth prohibition, on systems generating child sexual abuse material or non-consensual intimate imagery, is new rather than delayed: it binds deployers as well as providers, and law-firm commentary reads the provider test as extending to any system where such generation is a reasonably foreseeable and reproducible outcome without significant technical modification, which is interpretation rather than settled text.

Nothing that was already in force moved. Article 5 prohibitions and the Article 4 AI-literacy duty have applied since 2 February 2025. GPAI model obligations, governance and penalties have applied since 2 August 2025. The complete application timeline lays out every date from February 2025 to August 2028.

Who Article 50 catches, and why it is a bigger population

Be blunt about the arithmetic. The high-risk regime reaches systems that fall inside eight listed Annex III areas or that sit inside an Annex I regulated product. That is a defined, checkable, comparatively small set. Article 50 has no list. It turns on what the system does to a person in front of it, which means it reaches ordinary commercial software that nobody thinks of as an AI compliance problem.

Article 50 transparencyHigh-risk regime
What triggers itInteraction with a person, synthetic output, emotion or biometric useAnnex III use case or Annex I product route
Population caughtAny chatbot, any generative content tool, any deepfake, any emotion recognition deploymentA defined set of eight listed areas plus regulated products
Nearest date2 August 20262 December 2027
Core costDisclosure design, marking, records of the reasoningArticles 9 to 15 system, Annex IV documentation, conformity assessment, registration
Penalty tier15,000,000 euro or 3 percent of worldwide turnover15,000,000 euro or 3 percent of worldwide turnover

Picture a mid-sized software company with no Annex III exposure at all. It has a support chatbot on the pricing page, a marketing team producing product imagery with a generative tool, and a customer-experience pilot that scores sentiment from recorded calls. The chatbot and the imagery tool sit outside Annex III; the sentiment pilot does not, because emotion recognition falls inside Annex III area 1 on biometrics and needs a classification assessment of its own. The chatbot owes the 50(1) disclosure on 2 August 2026, the generative imagery raises 50(2) marking, which falls on the provider of the tool and runs from 2 December 2026 or from placement, and the sentiment pilot owes the 50(3) notice on 2 August 2026. The pilot also needs a hard look at Article 5 before anything else: emotion recognition is a prohibited practice where it reads the emotions of workers or of students, subject to narrow medical and safety exceptions, and has been since 2 February 2025. A tool that scores the sentiment of the customer is outside that prohibition; one that scores the agent handling the call is inside it.

Two more traps. Article 50 applies regardless of risk tier, so a system that clears the Article 6(3) derogation and is properly classified as not high-risk can still owe a disclosure. And the reach is extraterritorial: you are in scope if the system is placed on the market, put into service or used in the EU, or if the output is used in the EU. Free and open-source AI systems are excluded under Article 2, but not where the system is high-risk, prohibited, or subject to Article 50.

What AI Office enforcement beginning actually means

Enforcement under the Act is split three ways. National market surveillance authorities supervise most systems. The AI Office supervises general-purpose AI models, and systems built on models from the same provider. The European Data Protection Supervisor covers the EU institutions. From 2 August 2026 the AI Office arm of that structure is operational, which matters most if you are a GPAI provider: supervision is centralised rather than routed through twenty-seven national regulators.

National capacity is uneven. Only 8 of 27 member states met the 2 August 2025 Article 70 deadline to designate their authorities, with DGCCRF in France, AESIA in Spain and the Bundesnetzagentur in Germany among the front-runners. Read that as uneven enforcement rather than absent enforcement. A designated, resourced authority in one member state is enough to create exposure for a product sold across the single market, and a complaint does not need a designated authority to become a problem.

The money is not new. The Article 99 tiers have been enforceable since 2 August 2025: 35,000,000 euro or 7 percent of total worldwide annual turnover for Article 5 prohibited practices, 15,000,000 euro or 3 percent for most other obligations including Article 50 and the high-risk regime, and 7,500,000 euro or 1 percent for supplying incorrect, incomplete or misleading information to authorities. For companies the higher of the fixed sum or the percentage applies. Under Article 99(6) SMEs and start-ups pay the lower of the two. The penalties and enforcement page works through which breach lands in which tier.

What to do in the weeks before 2 August 2026

Six things, in the order that removes the most exposure per hour spent.

  1. Build the wider inventory. Not your high-risk inventory. A separate list of every system that talks to a person, generates content, or reads emotion or biometric signals - including embedded vendor features you did not procure as AI.
  2. Decide the 50(1) obviousness question per surface. For each interactive system, record whether a reasonably well-informed, observant and circumspect person would already know it is an AI, and why. Where the answer is not clearly yes, ship the disclosure.
  3. Fix the timing and the form of every disclosure. Clear and distinguishable at the latest at the first interaction or exposure, accessible, and cumulative where more than one limb applies. Retrofitting this into a conversational flow after launch is harder than designing it in.
  4. Start the 50(2) marking work now. The Code of Practice on transparency of AI-generated content, final version published 10 June 2026, is voluntary but is the likely de facto route. It requires multi-layered marking - at least two layers where a single technique cannot meet the effective, interoperable, robust and reliable criteria - with exceptions for generative systems embedded in closed physical products and for free-form text, watermarking for free-form text longer than 200 tokens, and interoperable watermark detection from 2 February 2027. None of that lands in a pipeline in a fortnight.
  5. Check whether you are the provider rather than the deployer. Putting your name on a high-risk system already on the market, substantially modifying a high-risk system in a way that keeps it high-risk, or changing the intended purpose of any system, including a general-purpose AI system, so that it becomes high-risk, can flip you into provider status and the full Article 16 obligation set. The role determination and Article 25 flip page sets out the three triggers.
  6. Diary 2 December 2026 and keep the high-risk workstream running. That date carries both the 50(2) marking duty for systems already on the market and the new CSAM and non-consensual-imagery prohibition, which binds deployers too.

If you only do one thing before the date: run every customer-facing system through a scope check and write the answer down. The free AI Act triage classifier walks the same tests in order - scope, prohibitions, Annex III, the Article 6(3) derogation, GPAI, Article 50 and your role - and names the article each answer rests on.

What is still unsettled at the review date

Four things, and the conservative reading of each.

The Omnibus is not yet in the Official Journal. The amended dates are agreed and final, but the consolidated legal text and the final Regulation (EU) 2026 number will only be authoritative once published in the Official Journal, alongside the current text of Regulation (EU) 2024/1689. Entry into force is the third day after publication. Conservative reading: plan to the amended dates, but do not treat the relief as bankable enough to dismantle a programme, because the unamended text is harsher, not softer.

The Article 6 classification guidelines are late. The Commission missed its February 2026 statutory deadline, so there are few authoritative worked examples of a successful Article 6(3) derogation. Conservative reading: document the assessment before placing on the market, register even where you self-assess as not high-risk, and assume that profiling of natural persons forecloses the off-ramp entirely.

The Article 50 guidance is still bedding in. Draft guidelines were published on 8 May 2026 with consultation to 3 June 2026, and the Code of Practice followed on 10 June 2026. The Code is voluntary. Conservative reading: follow it anyway, because a regulator assessing whether your marking is effective, interoperable, robust and reliable has no other yardstick to reach for. The Commission publishes its current material on the European Commission AI policy pages.

National enforcement capacity varies. Only 8 of 27 member states met the Article 70 designation deadline on 2 August 2025. Conservative reading: the gap closes, and it closes faster than a compliance backlog does. Where your system would be high-risk, the high-risk classification guide is the right next read; where it is not, Article 50 is still the obligation with a date in front of it.

Check your own system

The free classifier walks the same tests in order and tells you which of them your system actually trips, with the article each answer rests on.

Run the triage →

Frequently asked questions

Was the EU AI Act delayed to 2027?

Only part of it. The Digital Omnibus on AI moved the high-risk regime: standalone Annex III systems now owe compliance from 2 December 2027 and Annex I embedded-product systems from 2 August 2028. Nothing else moved to 2027. Article 5 prohibitions and the Article 4 AI-literacy duty have applied since 2 February 2025. GPAI model obligations, the governance provisions and the Article 99 penalties have applied since 2 August 2025. Article 50 transparency still applies on 2 August 2026. Treating one delayed workstream as a delay of the whole regulation is the single most expensive misreading of the amendment.

What exactly applies on 2 August 2026?

Article 50 transparency, in three of its four limbs, plus the start of AI Office enforcement. Article 50(1) requires providers to design systems that interact directly with people so that those people are informed they are dealing with an AI. Article 50(3) requires deployers of emotion recognition and biometric categorisation systems to inform the people exposed to them. Article 50(4) requires deployers to disclose deepfakes, and to disclose AI-generated text published to inform the public on matters of public interest. Article 50(5) and 50(6) govern how: clear and distinguishable, at the latest at the first interaction or exposure, and accessible.

Does my chatbot need an AI disclosure on 2 August 2026?

Yes, unless it is obvious to a reasonably well-informed, observant and circumspect person that they are talking to an AI. Article 50(1) is a provider duty and it is a design duty, not a policy duty: the system has to be built so the person is informed. The obviousness carve-out is narrower than product teams assume, because it is judged against a general standard rather than against your most sophisticated user. A support widget branded with a human first name and a photograph is not obvious. Decide the question per surface, write down the reasoning, and keep the note.

Do I have to mark AI-generated images from 2 August 2026?

Not necessarily on that date, but the exposure starts sooner than most teams plan for. The Article 50(2) machine-readable marking duty applies from 2 December 2026 to generative systems placed on the market before 2 August 2026. Systems placed on the market from 2 August 2026 comply from the moment of placement, so a launch after that date carries the duty immediately with no grace at all. The marking has to be machine-readable and detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust and reliable.

What is the penalty for missing the 2 August 2026 date?

Article 50 breaches sit in the middle Article 99 tier: 15,000,000 euro or 3 percent of total worldwide annual turnover. For companies the higher of the two figures applies. Under Article 99(6) SMEs and start-ups pay the lower of the two instead. These tiers are not new on 2 August 2026 - the penalty provisions have been enforceable since 2 August 2025. What changes on 2 August 2026 is that the transparency duties they attach to become live obligations that a market surveillance authority can act on.

We are not established in the EU. Are we caught on 2 August 2026?

Probably, if EU users touch the system. The AI Act reaches systems placed on the market, put into service or used in the EU, and it also reaches you where the output of the system is used in the EU. That output hook is what catches a non-EU SaaS product with EU customers, and a non-EU content pipeline whose generated material is published to an EU audience. Being free and open-source does not rescue you either: the Article 2 open-source exclusion falls away where the system is high-risk, prohibited, or subject to Article 50.

Should we pause our high-risk work until closer to 2027?

No. The 2 December 2027 date is a compliance deadline, not a start date, and the work behind it is slow. Annex IV technical documentation has to be drawn up before market placement and kept current, conformity assessment and Article 49 registration sit on the critical path, and systems self-assessed as non-high-risk under the Article 6(3) derogation still have to be registered in the EU database. The Commission also missed its February 2026 statutory deadline for Article 6 classification guidelines, so worked examples of a successful derogation are scarce and the conservative reading is the safe one.

This page is triage guidance, not legal advice. It reflects Regulation (EU) 2024/1689 as amended by the Digital Omnibus, reviewed 22 July 2026, when the Omnibus was adopted and signed but awaiting Official Journal publication. Final classification for ambiguous cases needs qualified counsel.