2 August 2026 was, for two years, the date on every AI governance roadmap in Europe. It was understood as the moment high-risk AI systems came fully into scope and the AI Act became a live regulatory constraint rather than a planning exercise.

That is not what happened, and organisations that built their programme around the original reading now need to re-sequence it โ€” in both directions. Some obligations they were preparing for have moved out by sixteen months or more. Others they may have deprioritised are enforceable today.

The Digital Omnibus provisional agreement replaced the Actโ€™s original high-risk trigger mechanism with fixed, later dates:

  • Annex III stand-alone high-risk systems โ€” recruitment, credit scoring, law enforcement, education, border control โ€” now 2 December 2027.
  • Annex I embedded high-risk systems โ€” AI in regulated products such as medical devices, machinery, and vehicles โ€” now 2 August 2028.

What remains at 2 August 2026 is narrower but real, and it comes with teeth.

What switched on

1. Enforcement powers over general-purpose AI

The substantive obligations on providers of general-purpose AI models have been in force since 2 August 2025. What arrived on 2 August 2026 is the Commissionโ€™s and AI Officeโ€™s power to act on them: to investigate, to conduct inspections, to accept binding commitments, and to impose fines of up to โ‚ฌ15 million or 3% of total worldwide annual turnover, whichever is higher, under Article 101.

This is the distinction that matters. A year of obligations without enforcement produced a predictable range of compliance postures, from full Code of Practice signature to quiet non-engagement. From 2 August 2026, the second posture carries a quantified downside.

We set out the GPAI obligations themselves โ€” technical documentation, the training-content summary, copyright policy, and the additional systemic-risk tier duties โ€” in our GPAI enforcement readiness guide. Everything in that piece is now enforceable rather than prospective.

2. Article 50 transparency obligations

This is the provision most likely to catch organisations that classified themselves as out of scope because they build nothing high-risk.

Article 50 applies regardless of risk classification. It attaches to specific system behaviours, not to a risk tier, and it reaches ordinary commercial deployments that no one thought of as โ€œAI systemsโ€ in the regulatory sense.

Article 50(1) โ€” disclosure of AI interaction. Providers must ensure that AI systems intended to interact directly with natural persons are designed so that the person is informed that they are interacting with an AI system, unless this is obvious from the circumstances to a reasonably well-informed and observant person.

In practice: customer support chatbots, voice agents in call handling, AI-driven sales assistants, conversational interfaces in apps. The โ€œobvious from contextโ€ carve-out is narrower than product teams assume. A chatbot in a branded widget named after a person, replying in natural language without disclosure, is not obviously an AI system to a reasonably observant user โ€” and the more capable the model, the weaker the argument that it is obvious.

Article 50(2) โ€” marking of synthetic content. Providers of AI systems generating synthetic audio, image, video, or text must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The obligation runs to the provider and must be technically effective, interoperable, robust, and reliable as far as technically feasible.

Article 50(3) โ€” emotion recognition and biometric categorisation. Deployers must inform the persons exposed to the operation of such systems, and process personal data in accordance with the GDPR and the Law Enforcement Directive.

Article 50(4) โ€” deepfakes and text. Deployers of AI systems generating or manipulating image, audio, or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated. For text published to inform the public on matters of public interest, deployers must disclose artificial generation unless the content has undergone human review or editorial control with a natural or legal person holding editorial responsibility.

The Article 50(4) exceptions matter: where content forms part of an evidently artistic, creative, satirical, or fictional work, the disclosure obligation is limited to disclosure in an appropriate manner that does not hamper the display or enjoyment of the work.

The grace period. Systems placed on the market before 2 August 2026 receive a four-month grace period for the watermarking requirements, extending to 2 December 2026. This applies to the marking obligations specifically, not to the interaction-disclosure duty under Article 50(1).

3. The penalty framework becomes operative

Member State national competent authorities and market surveillance authorities gain operative enforcement capacity. The tiers under Article 99:

  • Up to โ‚ฌ35 million or 7% of total worldwide annual turnover โ€” infringement of the Article 5 prohibited practices.
  • Up to โ‚ฌ15 million or 3% โ€” non-compliance with obligations on providers, importers, distributors, deployers, notified bodies, including the Article 50 transparency obligations.
  • Up to โ‚ฌ7.5 million or 1% โ€” supplying incorrect, incomplete, or misleading information to notified bodies or national authorities.

For SMEs and start-ups, the applicable figure is the lower of the percentage and the fixed amount, rather than the higher.

The 3% tier is the one that applies to an undisclosed chatbot. That is a proportionality question a national authority will weigh, but the ceiling is not theoretical.

4. A new prohibition

The Omnibus adds a prohibition on AI systems generating non-consensual intimate imagery or child sexual abuse material, with a transitional period until 2 December 2026. This sits with the Article 5 prohibited practices, which means it attracts the 7% / โ‚ฌ35 million tier once the transition ends.

What moved, and what that changes

The postponement is genuine relief for organisations building Annex III systems โ€” HR screening tools, credit decisioning, educational assessment, biometric identification in law enforcement contexts. The conformity assessment, quality management system, technical documentation, logging, human oversight, and accuracy/robustness obligations under Articles 8 to 27 now bind from 2 December 2027.

Three cautions before anyone stands down a programme.

First, the dates bind only on publication. The Omnibus deadlines take legal effect upon formal adoption and publication in the Official Journal. Until that is complete, the original text governs. Organisations relying on the extension should confirm publication rather than assume it.

Second, the extension applies to the high-risk obligations, not to everything. Article 50 is unaffected. A recruitment tool that is Annex III high-risk and also interacts directly with candidates through a conversational interface has an Article 50(1) duty today and Articles 8โ€“27 duties in December 2027. The classification does not exempt it from the transparency layer.

Third, other Omnibus changes broaden rather than narrow scope. Bias detection obligations are expanded to all AI systems, not only high-risk ones. The regulatory sandbox establishment deadline moved to 2 August 2027. And the AI literacy obligation under Article 4 was softened โ€” from guaranteeing specific literacy levels to supporting their development โ€” but not removed.

The practical gap

Article 50 exposure is concentrated in systems that no one assigned to the AI governance function, because they were procured as features rather than as AI:

  • The support chatbot the customer experience team bought from a SaaS vendor
  • The voice agent in the contact centre IVR
  • The AI-generated product descriptions on the commerce site
  • The synthetic voiceover in marketing video
  • The AI-assisted drafting in customer-facing communications
  • The AI note-taker joining external meetings
  • The emotion or attention analytics embedded in a retail or workplace deployment

Each of these is capable of triggering Article 50. None of them typically appears on an AI inventory built around risk classification, because the inventory was designed to answer โ€œwhich of our systems are high-risk?โ€ and Article 50 does not ask that question.

There is also a provider/deployer split that determines who owes what. Article 50(1) and 50(2) bind the provider โ€” the entity that develops the system or has it developed and places it on the market under its own name. Article 50(3) and 50(4) bind the deployer โ€” the entity using the system under its own authority.

This matters because an organisation using a third-party chatbot is typically a deployer, and the machine-readable marking duty under 50(2) sits with the provider. But if you deploy that system under your own brand and name, you may have become the provider under Article 25, which treats a distributor, importer, or deployer as a provider where they put their name or trademark on a high-risk system, make a substantial modification, or modify the intended purpose. Assess this before assuming the vendor carries the obligation.

What to do now

1. Re-inventory against behaviour, not risk tier. Ask three questions of every deployed system: does it interact directly with a natural person; does it generate synthetic audio, image, video, or text; does it perform emotion recognition or biometric categorisation. Any yes puts Article 50 in scope. This will surface systems your risk-classification inventory missed.

2. Fix interaction disclosure first. It is the cheapest and most visible obligation. Every conversational interface should state, before or at the outset of interaction, that the user is dealing with an AI system. Do not rely on the โ€œobvious from contextโ€ exception unless you can articulate why a reasonably observant user would know.

3. Establish the marking position for generated content. Determine, per system, whether the provider implements machine-readable marking โ€” C2PA content credentials, watermarking, or equivalent โ€” and obtain that in writing. Where you are the provider, you own the implementation. The four-month grace period for pre-2 August systems ends 2 December 2026.

4. Write the deepfake and public-interest-text policy. Define what your organisation classifies as a deepfake, who approves its publication, and what disclosure accompanies it. Separately define whether any AI-generated text you publish concerns matters of public interest, and if so, whether it passes through documented human editorial control โ€” because that is the exception you will rely on.

5. Confirm your GPAI position. If you fine-tune, substantially modify, or place a general-purpose model on the EU market under your own name, you may be a GPAI provider with documentation and copyright-policy duties that are now enforceable. Modification of an existing model is the route most organisations become providers without intending to.

6. Re-baseline the high-risk programme rather than pausing it. Sixteen additional months is not a reprieve; conformity assessment, notified body engagement where required, and quality management system build-out are multi-year efforts. The organisations that used previous AI Act extensions to stop work are the ones now furthest behind.

7. Record the Article 4 AI literacy position. Softened, not removed. Document what you do to support AI literacy among staff operating AI systems.

Conclusion

The date most organisations circled turned out to mean something different from what they planned for, and the mismatch runs in both directions.

The heavy engineering obligations โ€” conformity assessment, technical documentation, quality management systems for high-risk AI โ€” moved to December 2027 and August 2028. Programmes calibrated for an August 2026 cliff have room they did not expect.

But Article 50 is live now, it applies without regard to risk classification, it carries a 3% of global turnover ceiling, and it lands on chatbots, voice agents, synthetic media, and AI-generated public-interest text that most AI inventories never captured โ€” because those inventories were built to answer a question about risk tiers that Article 50 does not ask.

The organisations most exposed on 2 August 2026 are not the ones building high-risk AI. They are the ones who concluded, correctly, that they build none โ€” and stopped there.

This article is provided for informational purposes only and does not constitute legal advice.