The EU AI Act deadline that was not postponed: your chatbot has to say it is a chatbot, starting today
Two things are true at once on 2 August 2026. The high-risk rules moved to 2027 and 2028. Article 50 transparency did not move, and it applies today to ordinary products: chat interfaces, generated images, AI-written text. Here is which of the two describes your product, what the four obligations ask for in interface terms, and the second date in December that most teams have not put on the calendar.
If you followed the AI Act coverage over the last two weeks, you probably read that the deadline slipped. That is accurate. On 24 July the Digital Omnibus on AI was published in the Official Journal as Regulation (EU) 2026/1744, and it entered into force on 27 July. It moved stand-alone high-risk systems under Annex III from 2 August 2026 to 2 December 2027, and high-risk AI embedded in regulated products under Annex I to 2 August 2028.
It left Article 50 exactly where it was. The European Commission confirmed the date in its own announcement: from 2 August 2026, "chatbots and other interactive AI systems will have to tell users they are dealing with AI, not a human," deepfakes "will have to be labelled," and AI-generated or altered content "will also have to carry machine-readable marks so it can be detected more easily."
So the sentence "the AI Act was delayed" is true about the part that covers credit scoring, recruitment ranking, and medical devices. It is false about the part that covers a support widget, an image generator, and a blog post written by a model. The second group is much larger, and today is its date.
Which of the two deadlines describes your product
The postponement applies to classification, not to products in general. A system is high-risk because it falls into a listed use case under Annex III (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice) or because it is a safety component of a product already regulated under Annex I. If your product is not in one of those buckets, the postponement was never about you.
Article 50 works from the opposite direction. It does not care what sector you are in or how risky the system is. It attaches to four situations, and a perfectly ordinary SaaS product can hit three of them without anyone on the team thinking of the product as an AI-regulated system.
The four obligations, in interface terms
Direct interaction. Article 50(1) requires that systems interacting directly with people are designed so the person is informed they are interacting with AI. There is a real exemption, and it is narrower than teams tend to hope: the duty does not apply where the interaction is "obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect." A widget labelled "Assistant" with a robot icon is an argument. A widget that opens with "Hi, I am Sam from support" is not.
Machine-readable marking of generated output. Article 50(2) puts a duty on providers of systems generating synthetic audio, image, video, or text: outputs must be "marked in a machine-readable format and detectable as artificially generated or manipulated," with solutions that are "effective, interoperable, robust and reliable as far as this is technically feasible." Machine-readable is the operative phrase. A visible caption saying "AI-generated" is not the same thing as metadata a detector can read. The exemption covers assistive editing that does not substantially alter the input, and the Commission's Article 50 guidelines, adopted on 20 July, give spelling and grammar correction as the example of what does not trigger the duty.
Emotion recognition and biometric categorisation. Article 50(3) requires deployers of those systems to inform the people exposed to them. Small category, no ambiguity.
Deepfakes and AI text on public-interest matters. Article 50(4) sits with the deployer, not the provider. If you publish content that is a deepfake, you disclose it. If you publish AI-generated or manipulated text on a matter of public interest, you disclose that too, unless the text "has undergone a process of human review or editorial control" with a person or organisation holding editorial responsibility. Artistic, satirical, and fictional work gets a lighter form: disclose the existence of generated content "in an appropriate manner that does not hamper the display or enjoyment."
Article 50(5) governs the timing of all of it. The information has to be given clearly and distinguishably "at the latest at the time of the first interaction or exposure," and it has to meet accessibility requirements. A disclosure in your terms of service does not satisfy a rule about the first interaction.
Provider or deployer decides which of these is your problem
The split matters more than it looks. Article 50(2), the machine-readable marking, sits with the provider of the generative system. Article 50(4), deepfake and public-interest-text disclosure, sits with the deployer.
For a team building on a hosted model, that means the marking obligation for raw model output largely lives upstream with the model vendor, while the disclosure obligation for what you publish is yours and cannot be delegated to the vendor. Two different companies, two different duties, same piece of content. If your compliance conversation so far has been "our model provider handles that," you have answered half of it.
Where it gets less comfortable: if you fine-tune, wrap, or rebrand a generative system and place it on the market under your own name, you can be the provider of that system. That is a determination worth making explicitly rather than assuming.
Being outside the EU does not take you out of scope
Article 2(1)(c) extends the Regulation to providers and deployers established in a third country "where the output produced by the AI system is used in the Union." Article 2(1)(a) covers providers placing systems on the Union market "irrespective of whether those providers are established or located within the Union or in a third country."
A two-person company in Stockholm and a two-person company in Austin have the same obligations toward their EU users. The relevant question is where the output lands, not where the team sits.
The second date is 2 December 2026
The Omnibus did make one concession on transparency, and it is the part most likely to be missed because it reads as a footnote. Systems already placed on the market before 2 August 2026 get until 2 December 2026 for the machine-readable marking requirement in Article 50(2).
Read that carefully against your own roadmap. If your generative feature is already live, the marking work has four more months. If you ship a new generative feature next week, it does not inherit that runway. The transitional relief attaches to systems that were already on the market, not to the calendar.
Everything else in Article 50 applies from today, including to systems already live. The disclosure that your chat interface is AI has no transition period.
What non-compliance costs
Article 99(4)(g) covers "transparency obligations for providers and deployers pursuant to Article 50" and sets fines at up to EUR 15,000,000 or up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.
Article 99(6) changes the arithmetic for smaller companies: for SMEs, including start-ups, the fine is capped at the percentage or the amount, "whichever thereof is lower." For a company with modest turnover, the percentage is the binding number rather than the headline EUR 15 million.
Enforcement of Article 50 runs through national market surveillance authorities. Separately, and on the same date, the Commission's own enforcement powers over general-purpose AI model providers enter into application: requesting information, requesting access to a model for evaluation, requiring risk mitigation, imposing fines, and requiring that a model be restricted, withdrawn, or recalled.
The voluntary code, and what signing it buys
The Commission published the final Code of Practice on Transparency of AI-generated Content on 10 June, and roughly 190 companies and organisations had signed by the end of July. It is voluntary. The obligations underneath it are not.
What it offers is a documented route: adherence is a way of demonstrating compliance, and companies that do not sign have to show that whatever they built instead is adequate. The Commission also published a set of icons that deployers may use for labelling generated content, which removes one small design decision from the work.
Five things worth checking today
- Open your product as a first-time user. Does the AI-driven surface identify itself before the first exchange, or only in a settings page and the terms?
- List every place your product emits generated media or text to an end user. Chat replies, generated images, drafted emails, summaries. For each one, write down whether you are provider, deployer, or both.
- Ask your model vendor, in writing, what marking their output carries. You need a specific answer about metadata and detectability, not a link to a policy page.
- Put 2 December 2026 in the calendar with the name of every generative feature that was live before today, and confirm each one is in the marking work.
- Check whether you publish AI-drafted content on public-interest topics without a named human doing editorial review. If yes, either add the review or add the disclosure.
None of this requires a legal department to start. It requires knowing which of your surfaces produce or present machine-generated content, which is a question your team can answer this afternoon and a lawyer cannot answer without you.
Adjacent reading on AINews: what is safe to share with AI at work, the glossary entries on synthetic data and AI agents, and the tools directory if you are choosing where the generative surface in your product comes from.
Get the next post when it ships
One email on Sunday with the new post and a short list of what shipped that week — new guides, tool updates, and a couple of links worth reading.