AI Act · July 2026

AI Act 2 August: what actually applies (and what slid to 2027).

For months, 2 August was "high-risk day". Not anymore: the Digital Omnibus pushed that to December 2027. But it left Article 50 intact — the one that forces your chatbots to identify themselves, your AI-generated content to carry a machine-readable mark, and your deepfakes to be labelled. If your product talks, writes or draws, it's time to land the technical side with EU AI Act compliance consulting.

8 min read AI Compliance

Regulation (EU) 2024/1689 — the AI Act — had its schedule moved a month ago and most of the market has yet to notice. The Digital Omnibus, approved by the Council of the European Union on 29 June 2026, pushed the Annex III high-risk obligations from 2 August 2026 to 2 December 2027. But Article 50 — transparency — kept its original date. In EU AI Act consulting we have been preparing this technical side since spring with clients who saw it coming.

The three dates that matter
2 Aug 2026Applies now
Article 50 · Transparency. Chatbots must identify themselves, AI-generated content must be marked machine-readable, deepfakes must be labelled. Fines up to €15M or 3% of global annual turnover.
2 Dec 2026This autumn
Article 5 · New prohibition. AI systems generating non-consensual intimate imagery are banned. Applies to every operator, regardless of the system's risk level.
2 Dec 2027+16 months
Annex III · High risk. HR, credit, biometrics, education, essential services. Deferred from 2 August 2026 by the Digital Omnibus.
01 · Context

What was supposed to happen on 2 August

Until 29 June, the AI Act calendar was known and boring: 2 August 2026 was the day the obligations for the systems under Annex III kicked in — biometrics, HR, credit decisions, formal education, critical infrastructure, law enforcement and essential services.

That meant, for any operator with a system classified as high risk, wiring up in production a nontrivial pile of things: risk management, data quality and bias governance, technical documentation, automatic event logging, user-facing transparency, effective human oversight, accuracy and cybersecurity, and post-market monitoring. All with technical evidence sitting on your own code and your own infrastructure.

None of that applies in August anymore. But part of what was expected — Article 50 — is still exactly on its original date.

02 · Digital Omnibus

What changed on 29 June

The Digital Omnibus is the digital simplification package that the Council of the European Union approved on 29 June 2026. It is an amendment to the AI Act itself. Its declared aim: ease the applicability calendar in the face of clear evidence that neither companies nor competent national authorities were going to arrive in August with the technical and supervisory structures ready.

The most visible measure: the Annex III high-risk obligations, originally due to enter into force on 2 August 2026, are deferred to 2 December 2027. Sixteen more months.

Not an amnesty

It's a deferral, not an exemption. Neither the substance of the regulation nor its obligations change. What changes is when they are enforceable. If your system classifies as Annex III high risk, the technical work is the same — you just have sixteen more months to make it presentable. That margin evaporates quickly once you open the code base.

What did not change with the Digital Omnibus matters just as much: Article 50 transparency keeps its original date. And the new Article 5 prohibition on non-consensual intimate imagery also stays on schedule, for 2 December 2026.

03 · Article 50

The three things that do come into force

Article 50 of Regulation (EU) 2024/1689 imposes transparency obligations on providers and operators (deployers) of AI systems — regardless of whether the system is high risk or not. Three blocks. Specific ones.

50 · 1

Chatbot identifies itself

AI systems designed to interact with people must inform the user that they are talking to an AI, unless it is obvious from context. Applies to customer support chatbots, conversational assistants, IVR with synthetic voice and in-app agents. UI translation: a clear opening message, not a footnote in the footer.

50 · 2

Marking of generated content

Providers of generative AI (text, image, audio, video) must mark their outputs in a machine-readable format so that they can be detected as artificially generated or manipulated. The obligation sits on the model provider, not on the end user asking for an image.

50 · 4

Labelled deepfakes

Deployers using AI to create deepfakes (image, audio or video that falsely resembles a real person, object or event) must label the content as artificially generated or manipulated. There are narrow exceptions for artistic, satirical or law enforcement use — not a blank cheque.

Extraterritorial scope

Article 50 applies to any AI system placed on the market or put into service inside the EU, regardless of when it was placed on the market or whether the provider is established in the EU. A model trained in California and offered via SaaS to European customers is in scope. Living outside the EU does not spare you the fine if your outputs reach us.

04 · Penalties

How much ignoring it costs

The AI Act orders penalties into three tiers (Article 99). Worth not mixing them because the big headline number circulates a lot.

€35M · 7%
Prohibited practices
(Article 5)
€15M · 3%
Article 50 and other
infringements
€7.5M · 1%
Incorrect information
to the authority

Article 50 infringements fall in the second tier: up to €15 million or 3% of the previous financial year's global annual turnover — whichever is higher. Supervision and sanctions are run by the national competent authority in each member state; the specific body (and its readiness) varies country by country.

05 · Quick check

Does Article 50 apply to you?

Three short questions and you will know whether you have work ahead or you can breathe until high-risk hits in 2027.

Three-click check

No telemetry, no cookies, nothing sent anywhere. Everything runs in the browser.

1. Does your product have a chatbot, conversational assistant or IVR with synthetic voice that talks to real people?

2. Does your product generate text, images, audio or video with AI that end users see or download?

3. Does your product create or distribute deepfakes — image, audio or video that resembles a real person, object or place?

Article 50 does apply — and on several fronts.

With two or three blocks ticked, you have obligations around chatbot disclosure, content watermarking and/or deepfake labelling. It's the densest scenario: UI to touch, generation pipeline to touch, auditable logs to leave behind. With focus and priority, a week is enough to land the minimum starting with what's most visible to the user.

→ AI Act assessment with SIXE

Article 50 applies in one specific block.

You have a clear obligation. If the yes was the chatbot, the heavy lifting is UX: a clear opening message plus a log. If it was content generation, the heavy lifting is technical: C2PA + watermark + logging. If it was deepfakes, the heavy lifting is process: systematic labelling in the publication pipeline.

→ AI Act assessment with SIXE

You can breathe on Article 50.

No chatbot, no user-facing AI-generated content and no deepfakes — this block does not apply. But careful: if your AI falls under Annex III (biometrics, HR, credit, education, critical infrastructure, essential services) you have a date with the high-risk obligations on 2 December 2027. And that, when you get into it, is much more work than a chatbot notice.

→ Review Annex III classification

06 · Watermarking

The real problem: no single tech does the job

Obligation 50(2) — marking AI-generated content in machine-readable format — sounds like a label problem. It isn't. The regulation asks for four properties at once that no known technology satisfies together: imperceptibility (don't degrade the content), robustness (survive compression, editing, screenshots), detectability (verifiable downstream) and traceability (identify generator and version).

The practical approach that serious providers are adopting is layered. Three layers, each covering the failure modes of the previous one.

Layer 1

C2PA metadata

Content provenance standard driven by Adobe, Microsoft, Sony and others. Cryptographically signs metadata that travel with the file: who generated it, with which model, when. Survives compression. Disappears with screenshots or re-encoding without signing — i.e. with almost any social post.

Layer 2

Imperceptible watermark

SynthID (Google DeepMind) for images and audio, similar techniques for text and video. Modifies the output imperceptibly so a detector can recognise it. Survives screenshots, but degrades under aggressive manipulation, heavy cropping or source mixing.

Layer 3

Generator-side logging

Audited log on the provider side: what was generated, when, with which prompt, model and version. The most boring, the most important, and the one that lets you respond to a request even after layers 1 and 2 have evaporated along the way.

SIXE angle

Layer 3 — generator-side logging — is where running AI on-premise becomes a real advantage rather than a marketing line. On your own inference stack you can log every prompt, every output, every model and every version without depending on a SaaS provider's audit trail that they show you when they feel like it. And in RAG with Docling, the traceability of which document fed which answer is part of the architecture by design.

07 · Checklist

The minimum to have in place

If the quiz said Article 50 applies to you, this is the checklist with the essentials. Tick what you already have. What remains unticked is your backlog — and what we build with clients in a kick-off consulting engagement.

Article 50 checklist · 7 items

0/7 done
  • "You're talking to an AI" notice on your chatbotsClear opening message, not a footnote in small print. Applies to voice assistants and synthetic IVR too.
  • Chatbot session logDate, system, model version, session ID. If the authority asks, you must be able to show that the disclosure went out.
  • C2PA on generated outputsCryptographically signed metadata on images, audio and video. Layer 1 of layered watermarking.
  • Imperceptible watermarkSynthID or equivalent for what C2PA loses when someone takes a screenshot and shares it on social media.
  • Generator-side loggingAuditable log of prompts, outputs, model and version on your side. Boring to implement, essential when it's time to demonstrate. On on-premise inference over Ceph, OpenStack or K8s it stays inside your perimeter.
  • Deepfake labelling in the pipelineIf you generate or distribute content that resembles real people, label it inside the publication flow itself. Don't leave it to the editor on duty. With safe AI agents labelling runs as policy, not as a reminder.
  • Internal conformity documentHalf a page explaining which obligations apply to which systems, who is accountable and where the logs live. This is where ISO 42001 chains naturally with the AI Act.
All seven ticked. If it's real and not vibes, your week is looking good. If any were missing, EU AI Act consulting starts from there.
08 · December 2026

The other date almost nobody is watching

Four months after the Article 50 deadline, on 2 December 2026, a new prohibition added by the Digital Omnibus to Article 5 takes effect: AI systems that generate non-consensual intimate imagery join the regulation's catalogue of prohibited practices.

Because it is a prohibition, it doesn't admit exceptions by size or by prior risk level of the system. It applies to every operator on the European market — providers, deployers, importers, distributors — no exception. No intermediate Annex, no additional grace period. Prohibited.

This hits products and services like generators of real-person imagery without consent, face-swap apps on intimate content and nudify tools that have proliferated in the last two years. General-purpose model providers are affected indirectly through foreseeable uses: if your model can be reasonably used for that, technical safeguards stop being optional.

09 · Architecture

Why on-premise makes the paperwork easier

None of the Article 50 obligations depend on where the AI runs — they apply to providers and deployers regardless of topology. But demonstrating compliance does depend. And that's where deploying on your own infrastructure plays in your favour for very practical reasons:

  • Generator-side logging (layer 3) lives in your system, with your retention policies, without third-party access agreements or SaaS dashboard export limits.
  • Technical documentation of the model — which if the risk tier climbs is demanded in detail — is under your control: weights, training data provenance, evaluations, version. Nothing depends on your cloud provider's goodwill.
  • Data governance is demonstrated on data that never left your perimeter. For healthcare, banking and public sector it is a de facto requirement — the AI Act just puts it in writing.
  • Auditable agents with OPA, LangChain or CrewAI fit naturally with the effective human oversight that high risk will require in 2027.
FAQ

Frequently asked questions

What comes into force under the AI Act on 2 August 2026?

The Article 50 transparency obligations. Chatbots must let users know they are talking to an AI; AI-generated content (text, image, audio, video) must be marked in a machine-readable format; deepfakes must be labelled as artificially generated or manipulated. Non-compliance is fined up to €15 million or 3% of global annual turnover, whichever is higher (Article 99.4).

Has enforcement for high-risk systems been delayed?

Yes. The Digital Omnibus, approved by the Council of the European Union on 29 June 2026, postponed the Annex III obligations (biometrics, HR, credit, education, critical infrastructure, law enforcement, essential services) from 2 August 2026 to 2 December 2027.

Article 50 has NOT been postponed and still applies on 2 August 2026.

What is the Digital Omnibus?

The digital simplification package approved by the Council of the European Union on 29 June 2026 that delays the applicability of several AI Act obligations and clarifies operational aspects of the regulation. Its most significant measure is deferring the Annex III high-risk obligations to 2 December 2027.

How much does breaching Article 50 cost?

Up to €15 million or 3% of the previous financial year's global annual turnover, whichever is higher (Article 99.4). It is the second tier of penalties. The first tier (€35M or 7%) is reserved for the prohibited practices under Article 5 — a separate matter.

How do you meet the machine-readable marking requirement?

With a three-layer approach: cryptographically signed C2PA metadata in the file; imperceptible watermark like SynthID for what C2PA loses on screenshots; and audited logging in the generator itself. No single layer covers the four requirements the regulation demands — imperceptibility, robustness, detectability and traceability.

What new prohibition comes into force on 2 December 2026?

Article 5 adds a new prohibition: AI systems that generate non-consensual intimate imagery. It applies to every operator regardless of the system's risk level.

Does the AI Act apply if my AI is on-premise?

Yes. The AI Act applies to any system placed on the market or put into service in the EU, regardless of where it is deployed or where the provider is established. Running AI on-premise does not exempt — but it makes the demonstrating side easier: logging, traceability and audit are yours, not a third party's.

Are AI Act, NIS2 and ISO 42001 the same thing?

No, but they support each other. NIS2 is the European cybersecurity directive — it forces you to manage risk and notify incidents. ISO/IEC 42001 is the international standard for AI management systems — a governance framework. The AI Act is European law with specific obligations by risk level. All three overlap in data governance, traceability and logging: doing one properly covers part of the next.

Technical compliance

Does your product talk, write or draw with AI?

We land which Article 50 obligations apply to your systems, review chatbots and generators, set up the inference pipeline with auditable logging and roll out layered watermarking. We handle the technical side; legal interpretation stays with your legal advisors.