If you planned your AI roadmap around “EU AI Act enforcement, August 2, 2026,” that anchor has shifted — but not as far as most summaries suggest. It is worth being precise about what changed and what did not, because the two errors are symmetrical: treating August 2026 as a cliff for everything, or writing it off as a date that no longer matters. What moved was the high-risk regime. What landed on 2 August 2026 — and has applied since — is the Article 50 transparency regime, and that one reaches far more organisations.
The timeline, as it stands
What still applies today
Prohibited practices have applied since February 2025; General-Purpose AI (GPAI) model obligations and the governance framework since August 2025. Under the Digital Omnibus, the headline obligations for high-risk systems were deferred — stand-alone Annex III systems now apply from 2 December 2027, and AI embedded in regulated products from 2 August 2028. If your deployment touches the parts already in force, the obligations are real now — not in 2027.
The part of August 2026 that did not move
Article 50 transparency duties apply from 2 August 2026, and they are easy to miss because they sit outside the high-risk conversation entirely. They bind providers and deployers of ordinary AI systems in four situations: AI that interacts directly with people (chatbots, assistants, agents), generation of synthetic content, emotion recognition or biometric categorisation, and deepfakes or AI-generated text published to inform the public on matters of public interest.
Three things are worth underlining, because they are where organisations get caught out:
- They are not limited to high-risk systems. A perfectly ordinary internal assistant can trigger Article 50 without being high-risk at all.
- Open-source AI systems are not exempt. The open-source carve-out that appears elsewhere in the Act does not carry over to Article 50.
- “Clear and distinguishable” has teeth. A line in the footer, a sentence in the terms, or a label that flashes for an instant does not discharge the duty. The disclosure has to reach the person at or before the first interaction.
Systems already generating content before 2 August 2026 get until 2 December 2026 to meet the machine-readable marking requirement under Article 50(2). The Commission’s Code of Practice on Transparency of AI-generated content — assessed as adequate by the Commission and the AI Board in July 2026 — is voluntary, but signing it is the most direct way to show a market-surveillance authority how you intend to comply. Whether Article 50 applies to a given system, and whether you are the provider or the deployer of it, is a question for your counsel and not for a vendor’s blog post.
Why the deadline was never the point
See the 2026 obligation stack for how the AI Act sits alongside DORA and NIS2. This is general information, not legal advice.
Frequently asked questions
So is the August 2026 deadline gone?
Only the part of it that concerned high-risk systems. Those obligations were deferred to December 2027 (Annex III) and August 2028 (Annex I) via the Digital Omnibus. But 2 August 2026 was a real date, and it has passed: Article 50 transparency duties have applied since then to providers and deployers — telling people they are interacting with an AI, and marking AI-generated content — and the Commission's enforcement powers over general-purpose AI model providers are active. Prohibited practices (February 2025) and GPAI model obligations (August 2025) already apply.
Do the Article 50 transparency rules apply to open-source AI?
Yes. Article 50 makes no exemption for open-source AI systems, and its duties are not limited to high-risk systems — an ordinary internal assistant can trigger them. Whether a specific system is caught, and whether you are its provider or its deployer, is a question for your counsel.
What should we plan around instead?
Provable control. The deadlines move; the requirement to evidence how your AI behaves — to an auditor, a Datenschutzbeauftragter or a Betriebsrat — does not. Build the audit trail now.
Sources & further reading
- European Commission — Regulatory framework for AI — scope and application dates
- EU AI Act — Article 99 (Penalties) — the fine tiers
- EU AI Act, DORA and NIS2: the 2026 obligation stack — how the regimes fit together