A quieter deadline, a bigger immediate footprint
For eighteen months, August 2, 2026 was billed as the EU AI Act's real reckoning: the day the Annex III high-risk regime — covering AI used in hiring, credit scoring, education, and law enforcement — would start applying, with all the conformity assessments, technical documentation, and human-oversight obligations that entails. That deadline is gone. On July 8, 2026 the European Parliament and Council adopted the Digital Omnibus on AI, published as Regulation (EU) 2026/1744 in the Official Journal on July 24 and in force from July 27 (EUR-Lex). It pushes stand-alone Annex III high-risk obligations to December 2, 2027, and high-risk AI embedded in regulated products (medical devices, machinery, aviation) to August 2, 2028.
But August 2, 2026 still mattered, because the Omnibus left Article 50 alone. Its transparency obligations — the rules governing chatbots, deepfakes, emotion-recognition disclosure, and AI-generated public-interest text — took effect on schedule, and the European Commission's AI Office confirmed it began enforcing them that day (European Commission). For most companies actually operating in the EU, this — not the high-risk regime — is the rule they now have to live with.
What Article 50 actually requires
The Commission's own FAQ page breaks Article 50 into four buckets (European Commission). Providers of systems that directly interact with people — chatbots, AI agents, voice assistants — must design them so a user knows they're talking to a machine, unless that's already obvious. Providers of generative systems must mark synthetic audio, image, video, and text in a machine-readable format detectable as AI-generated. Deployers of emotion-recognition or biometric-categorisation systems must tell the people exposed to them. And deployers of deepfakes — content that resembles a real person, place, or event and would falsely appear authentic — must label it clearly at first exposure, with narrow carve-outs for obviously artistic or fictional works. AI-generated text published on matters of public interest, like politics or public health, needs a similar label unless it went through meaningful human editorial review.
The Omnibus did carve out one piece: the machine-readable watermarking obligation for generative systems already on the market before August 2 gets a four-month grace period, to December 2, 2026, so vendors have time to retrofit content-provenance tooling into existing products. Everything else in Article 50 — the disclosure duty for chatbots, the deepfake labeling requirement, the emotion-recognition and biometric-categorisation notice — applies now, with no phase-in.
The stakes, and the case for them
The strongest argument for Article 50 is straightforward: synthetic media is now cheap enough, and good enough, that the absence of a labeling default is itself a policy choice — one that favors deception. A user who can't tell whether they're arguing with a bot, or watching a fabricated video of a real official, has been deprived of information relevant to how much weight to give what they're seeing. Emotion-recognition and biometric-categorisation systems raise a parallel concern: people subjected to inference about their mood or demographic category from a camera or microphone typically have no way of knowing it's happening at all. A disclosure-first regime is a comparatively light intervention — it doesn't ban the underlying technology, just requires that people know when it's being used on them.
Where Article 50 strains is in the breadth of what counts as a violation and the size of the penalty attached to labeling failures rather than harmful conduct. Fines run up to €15 million or 3% of global annual turnover, whichever is higher — the same mid-tier penalty band that applies to more serious AI Act breaches (European Commission news; IBTimes UK). The deepfake definition under Article 3(60) applies regardless of intent to deceive, meaning a satirical edit or an obviously synthetic marketing clip can trigger the same labeling duty as a fraudulent one, with the artistic exemption doing the work of separating them. For a large platform with a legal team, that ambiguity is manageable friction. For a smaller EU-facing chatbot provider or an independent generative-media startup, it's a compliance cost — legal review of every user-facing disclosure, engineering time to build machine-readable marking — layered onto a product category that didn't previously carry this kind of regulatory surface, arriving well before the harmonized technical standards for machine-readable marking are fully settled.
The asymmetry that matters
The practical result of the Omnibus is a split timeline: the AI Act's most consequential compliance regime — the one governing whether an algorithm can be used to screen job applicants or set loan terms — is delayed to December 2027 while regulators and industry wait for standards and national enforcement infrastructure to catch up. The disclosure regime, which touches far more products with far less lead time, is live now, enforceable now, and carrying a penalty ceiling identical to rules the EU judged serious enough to warrant a sixteen-month deferral elsewhere in the same statute. That's not necessarily the wrong sequencing — transparency rules are lower-cost to implement than conformity assessments, which is presumably why the Omnibus left them in place. But it means the Act's first real enforcement test won't be a hiring algorithm or a credit-scoring model. It'll be whether a chatbot said it was a chatbot.