BRUSSELS, 30 AUG 2026 — Four weeks ago the EU's high-risk AI obligations were due to apply. They were deferred, by up to 16 months. The transparency obligations were not deferred, and have been in force since 2 August.
What was deferred, and by how much
For a European legislative instrument, the Digital Omnibus on AI moved quickly. It was proposed by the Commission in November 2025, provisionally agreed between Parliament and Council on 7 May 2026, approved by Parliament 423 to 57 on 16 June, signed off by Council on 29 June, published in the Official Journal on 24 July and in force from 27 July.
It defers the high-risk regime on two tracks. Standalone Annex III systems — the list covering employment, education, credit, law enforcement and similar uses — now apply from 2 December 2027, a 16-month deferral. AI embedded in regulated products under Annex I moves to 2 August 2028, a 12-month deferral.
We reported in June that the EU was racing to delay its own high-risk rules before they took effect. It got there, with about five weeks to spare.
What actually took effect on 2 August
Article 50 is the transparency article, and it was untouched by the Omnibus. Since 2 August, providers and deployers operating in the EU have had to tell people when they are interacting with an AI system rather than a person, and to mark synthetic audio, image, video and text content in a machine-readable way.
That is a live legal obligation now, not a future one. An organisation that read the delay coverage and concluded the AI Act had been postponed is out of compliance today, and the class of organisation most likely to have made that error is exactly the one Article 50 applies to: anyone running a customer-facing chatbot.
A second date is close behind. From 2 December 2026, Article 50(2) reaches legacy systems that were already deployed, and a further set of prohibited practices applies.
What Article 50 actually requires
The phrase transparency requirements sounds broad. The obligations now in force are narrower and more practical than it implies.
A person interacting with an AI system must be informed of that, unless it is obvious from the circumstances. Synthetic audio, image, video and text must be marked in a machine-readable format that indicates it was artificially generated. Deep fakes must be disclosed as such. Emotion recognition and biometric categorisation systems must inform the people exposed to them.
The machine-readable requirement carries the engineering consequence. A line of small print will not satisfy it: the rule wants provenance metadata embedded in the file itself, and that metadata has to survive whatever a platform does to the file afterwards. Content-credential schemes are still working on that second half.
The exemptions matter too. Where AI performs an assistive editing function that does not substantially alter the input, or where use is authorised by law for detecting criminal offences, the marking obligation is limited. Those carve-outs are narrower than most vendors assume.
Why the deferral is not the scandal it was reported as
The delay was widely covered as Europe retreating under industry pressure, but a more prosaic explanation deserves equal weight.
High-risk compliance depends on harmonised standards that were not finished. Requiring conformity assessment against specifications that do not yet exist would have produced either paralysis or box-ticking, neither of which serves the regulation's purpose. Deferring a deadline because the standards are not ready is a different thing from deferring it because of lobbying, even if lobbyists were also asking.
That said, 16 months is a long deferral, and the burden is now on the standards bodies to use it. The second deferral, if one comes, will be much harder to justify on the same grounds.
Enforcement has not started either
An obligation in force is not yet an obligation being enforced, and the gap is wide.
National market surveillance authorities are the bodies that police the AI Act, and member states were required to designate them. Several have not completed that, and those that have are generally staffing rather than investigating. The AI Office at Commission level has capacity for systemic-risk models, not for a chatbot disclosure sweep across the single market.
So the realistic near-term exposure is not a regulator arriving. It is a complaint, a competitor, or a procurement questionnaire. The questionnaire is already happening: European buyers have started asking suppliers to attest to Article 50 compliance whether or not anyone is checking.
That is the pattern this desk has seen in every AI statute it has covered: Korea's AI Basic Act has been in force seven months with a maximum fine of about US$20,000, and enforcement capacity, not the text, has been the binding constraint everywhere.
What this means for organisations in this region
The AI Act applies extraterritorially: a provider outside the EU is in scope where the system's output is used in the Union. For a regional software company with European customers, the relevant compliance date just split in two.
The obligation you must meet now is transparency. If your product talks to European users, it has to say it is a machine, and anything it generates has to be marked. We have written about how C2PA and Article 50 interact and which regional tools implement it, and that guidance is now the operative one rather than a preview.
The obligation you have until December 2027 to meet is the heavy one: risk management systems, data governance, technical documentation, human oversight, accuracy and robustness testing. Sixteen extra months is breathing room for a small vendor. It is not an invitation to start in 2027; conformity assessment takes longer than the paperwork suggests.
The coverage encourages treating the AI Act as a single deadline that moved. The Act has several deadlines, and only some of them changed.