The next major phase of the European Union’s AI Act began applying on August 2, 2026: Article 50 transparency rules now cover certain chatbots, synthetic content and biometric systems. The EU’s Digital Omnibus has separately delayed dedicated obligations for many high-risk AI systems until December 2, 2027, with another deadline of August 2, 2028 for high-risk AI embedded in regulated products.
For companies, the immediate change is mainly operational. They must identify AI systems used in customer interactions, content production and biometric processing, then provide the required disclosures. They do not generally need prior approval to deploy those systems or abandon them simply because Article 50 applies.
At a glance:
- Article 50 transparency rules started applying on August 2, 2026.
- Direct-interaction AI systems generally must tell people they are interacting with AI unless that is obvious.
- Synthetic audio, images, video and text must be marked in a machine-readable way where the Act requires it.
- High-risk rules for Annex III systems moved to December 2, 2027; high-risk AI embedded in regulated products moved to August 2, 2028.
| Original timetable | Current timetable | |
|---|---|---|
| Article 50 transparency rules | Due to apply on August 2, 2026 | Apply from August 2, 2026 |
| High-risk AI systems listed in Annex III | Due to apply on August 2, 2026 | Apply from December 2, 2027 |
| High-risk AI embedded in regulated products | Due to apply on August 2, 2026 | Apply from August 2, 2028 |
What Article 50 requires now
AI systems intended to interact directly with people must disclose that the user is dealing with AI, unless that is obvious from the context. Providers of systems that generate synthetic audio, images, video or text must ensure outputs are identifiable through machine-readable marking, subject to the Act’s technical and other exceptions.
People exposed to emotion-recognition or biometric-categorisation systems must generally be informed that the system is operating. Deployers must also disclose when image, audio or video content is an AI-generated or manipulated deepfake, while AI-generated text published to inform the public must be disclosed in the circumstances set out by the Act.
- Some law-enforcement uses are exempt from particular transparency duties when authorised by law and accompanied by safeguards.
- The information must be provided clearly and accessibly, no later than the first interaction or exposure.
- A limited transition for certain synthetic-content systems already placed on the market before August 2, 2026 runs until December 2, 2026.
What was delayed
The Digital Omnibus changed the timetable for the AI Act’s most demanding operational requirements. Rules for high-risk systems listed in Annex III now apply from December 2, 2027. High-risk AI embedded in regulated products covered by Annex I has a later application date of August 2, 2028.
Those requirements cover areas such as employment, education, essential services, biometrics, law enforcement and migration, asylum and border management. Once applicable, they will add duties involving risk management, documentation, data governance, traceability and human oversight. Existing obligations under the GDPR and national or sector-specific law continue to apply during the delay.
EU institutions describe the timetable change as an effort to give companies and regulators more time for technical standards, guidance and implementation. Digital-rights groups have criticised the postponement, arguing that it delays stronger safeguards for people affected by automated decisions, especially migrants and asylum seekers.
- The delay is not a suspension of all AI regulation.
- Article 50 transparency obligations remain applicable from August 2, 2026.
- The AI Act’s rollout began earlier: prohibitions and AI-literacy rules applied from February 2, 2025, while general-purpose AI obligations applied from August 2, 2025.
Why the change matters beyond the EU
Companies that sell or operate AI products internationally may choose to use the EU’s disclosure and labelling practices across their services rather than maintain separate systems for European and non-European users. That could give the transparency rules influence beyond the bloc, much as the GDPR shaped global privacy compliance.
The strongest high-risk protections have a narrower reach. The AI Act’s delayed safeguards apply to qualifying systems within its legal framework, while technology funded or deployed outside the EU’s jurisdiction, including some migration and border-surveillance systems in third countries, is not automatically covered by those rules.
- Businesses should inventory both internally developed AI and tools bought from vendors.
- The key near-term compliance question is whether a system creates a transparency duty, not whether the business must obtain general pre-approval.
Questions readers ask
Does the August 2 deadline ban chatbots or generative AI?
No. Article 50 primarily requires disclosure and labelling for specified uses. It does not create a general ban on chatbots or synthetic-content tools.
When do the EU’s high-risk AI rules apply?
For high-risk systems listed in Annex III, the application date is December 2, 2027. For high-risk AI embedded in regulated products covered by Annex I, the date is August 2, 2028.
What should companies do first?
They should map where AI is used, including third-party tools, determine which Article 50 duties apply and check that disclosures and synthetic-content markings are clear, accessible and provided at the required point of interaction or exposure.
Related coverage:
No comments yet. Start the discussion.