Industry·6 min read·European Commission

Europe's AI Act Hits Its Big Deadline Today — After the EU Moved Most of It to 2027

From today, chatbots operating in the EU must tell users they are AI and deepfakes must be labelled, as Article 50 of the AI Act starts to apply. But the high-risk obligations the Act was built around were pushed to December 2027 by June's Digital Omnibus, and the machine-readable marking rule appears to carry a transitional period of its own until December. What actually changed today is narrower — and far more widely applicable — than the deadline suggests.

AI From today, it has to say so.
Share:

Today is 2 August 2026, the date the bulk of the European Union's AI Act was written to take effect. It arrives smaller than planned.

Six weeks ago the EU moved the centrepiece out by sixteen months. The Digital Omnibus — a simplification package the Parliament endorsed on 16 June and the Council waved through on 29 June — pushed the obligations on high-risk AI systems, the hiring screens and credit scoring and medical triage that the Act was largely built to govern, from today to 2 December 2027. Systems embedded in regulated products slipped further, to 2 August 2028.

What still starts today is Article 50, the transparency layer. It is narrower than the high-risk regime and much broader in reach: it applies to ordinary chatbots and image generators rather than to a defined list of sensitive uses. In plain terms — a chatbot has to tell you it is a chatbot, and a deepfake has to be labelled as one.

What applies from today

ProvisionWho it bindsThe duty
50(1)ProvidersSystems that interact with people must disclose that they are AI
50(3)DeployersTell people when emotion recognition or biometric categorisation is running on them
50(4)DeployersDisclose deepfakes; disclose AI-written text published to inform the public
50(2)ProvidersMachine-readable marking — see below

Article 50(5) sets the manner: the disclosure has to reach the person "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure," and meet accessibility requirements. A buried line in a terms-of-service page does not discharge it.

The marking rule has four more months

This is the part most summaries flatten. Article 50(2) — the requirement that generated audio, image, video and text be "marked in a machine-readable format and detectable as artificially generated or manipulated" — is the one obligation here with real engineering behind it, and it is not fully in force today.

Analyses from Gibson Dunn and White & Case both describe a transitional period running to 2 December 2026 for systems already on the market. Worth flagging the sourcing: the European Commission's own announcement of today's date lists machine-readable marking among the requirements that "will have to" apply, without noting the carve-out. We have not found the transitional text in a primary document we could read directly, so treat the December date as the reading of two law firms rather than as something the Commission has said plainly.

The distinction matters commercially. Visible disclosure is a UI change; machine-readable provenance is a pipeline change, which is why OpenAI adopted C2PA credentials and Google's SynthID watermarking back in May rather than waiting. Anyone who shipped an image model without provenance plumbing — and most Chinese labs did, including ByteDance's Seedream 5.0 Pro — has until December on existing systems.

What moved, and where it landed

ObligationWasNow
Article 50 transparency2 Aug 20262 Aug 2026 — today
High-risk, standalone (Annex III)2 Aug 20262 Dec 2027
High-risk in products (Annex I)2 Aug 20272 Aug 2028

The carve-outs decide how much this actually bites

Article 50 is written with exceptions that do a lot of work, and reading them is the difference between "everything changes today" and "not much does."

Disclosure is not required where the AI is obvious. 50(1) exempts cases obvious "from the point of view of a natural person who is reasonably well-informed, observant and circumspect." Whether a branded assistant on a company's own support page clears that bar is exactly the sort of question that will take a regulator or a court to settle.

Art gets a lighter touch. For deepfakes in "artistic, creative, satirical or fictional" work, 50(4) reduces the duty to disclosing that the content exists, in a way that does not hamper enjoyment of the work — not a label stamped across the frame.

Edited text is exempt. The rule on AI-generated text covers publication on matters of public interest, but falls away where the text underwent human review and a person or organisation holds editorial responsibility. That is a wide exemption for newsrooms, and it lands in a market where roughly one adult in ten already gets weekly news from a chatbot.

Law enforcement is carved out throughout, across 50(1) to 50(4), where use is authorised by law.

What non-compliance costs

Penalties sit in Article 99 and have been enforceable since August 2025. Breaching Article 50 falls in the middle tier: up to €15 million or 3% of worldwide annual turnover, whichever is higher. The top tier — up to €35 million or 7% — is reserved for the prohibited practices in Article 5. For SMEs and start-ups the cap is the lower of the two figures rather than the higher.

One thing got stricter, not looser

The Omnibus was not only a rollback. It adds a new prohibition to Article 5 covering AI systems that generate non-consensual intimate imagery or child sexual abuse material — moving that conduct into the €35 million tier. It carries its own transitional period to 2 December 2026.

Was the delay lobbying, or were the standards not ready?

The obvious read is industry pressure, and it is not wrong: the tech sector lobbied hard against the high-risk regime and got sixteen months. The EU spent this year visibly softening its posture toward large platforms even while pressing them hard on other fronts.

The less comfortable case for the delay is that the harmonised technical standards that high-risk compliance depends on were late. Telling companies to conform to standards that do not yet exist produces box-ticking, not safety. A rule that arrives with its standards finished is worth more than one that arrives on time — and that argument would carry more weight if the December 2027 date came with a published schedule for delivering them.

Both things can be true, and the test is observable: if the standards land well before December 2027, the delay was sequencing. If they slip again, it was an extension.

It is a striking contrast with Washington, where the threshold deciding which models face federal review was due yesterday and is classified. Europe's rules are published, mandatory and slipping; America's are voluntary, secret and nominally on time. Neither is obviously the better trade.

What to watch

Whether any chatbot visibly changes its greeting for EU users this week is the cheapest available signal, and the first enforcement action under 50(1) will show how the "reasonably well-informed" test is read in practice. On the marking side, the date to watch is 2 December, when the transitional period the law firms describe would end and provenance metadata stops being optional for systems already shipping. China, which forced its labs to strip humanlike behaviour from companion apps in July, took the blunter route to the same goal; the EU has bet on labelling instead.

Want AI news before everyone else?

The morning's most important AI stories, straight to your inbox. No fluff.

Related Articles