AI Governance Desk

What actually applies on 2 August 2026

Most coverage of the EU AI Act delay is half right, and the half it gets wrong is the half with a deadline this week.

The short answer: the high-risk obligations were postponed to December 2027. The Article 50 transparency obligations were not. They apply from 2 August 2026, and they affect far more ordinary businesses than the high-risk rules ever would — anyone running a chatbot, publishing AI-generated images, or putting out AI-written content.

If you read a headline saying the AI Act was delayed and concluded you had another year, that conclusion is wrong for most small businesses. Here is the precise picture.

What the Digital Omnibus actually changed

The Digital Omnibus was provisionally agreed on 6 May 2026. It moved two things and softened a third:

It did not touch Article 50. It did not touch the Article 5 prohibitions. It did not touch the GPAI obligations.

One caveat that matters. The Omnibus takes legal effect only when it is published in the Official Journal. Until then, the original schedule remains legally operative. Publication was expected before 2 August 2026, but if you are reading this and it has not happened, the postponements are not yet law.

The full timeline

DateWhat appliesStatus
2 Feb 2025Prohibited practices (Art. 5); AI literacy (Art. 4)In force
2 Aug 2025GPAI model obligations; penalties enforceableIn force
2 Aug 2026Transparency obligations (Art. 50)Now
2 Dec 2026Watermarking grace period ends for pre-existing systemsUpcoming
2 Dec 2027High-risk standalone systems (Annex III)Postponed
2 Aug 2028High-risk in regulated products (Annex I)Postponed

Does this reach you if you are not in the EU?

Possibly, and this catches people out. The Act applies if you place an AI system on the EU market or if the output of your AI system is used in the EU. A US company with European customers using its AI-powered product can be in scope without having any EU entity, office, or staff.

The practical test is not where you are incorporated. It is whether an EU person ends up on the receiving end of your AI.

What Article 50 requires, concretely

If you run a chatbot

People must be told they are dealing with a machine — clearly, and before they start, not buried in a policy page. There is an exception where it is obvious from context, but it is narrower than people assume and a single plain sentence costs nothing.

In practice: disclose before the user's first message, don't dress the bot up as a named human employee with a stock photo, and always provide a route to a person.

If you publish AI-generated images, audio, or video

Two separate duties, and most businesses only do the first. You need a visible label, and you need machine-readable marking — C2PA Content Credentials, IPTC metadata, or provider watermarking such as SynthID.

The trap: image pipelines routinely strip metadata on resize or export. You can implement the marking correctly and have your CMS silently remove it. Test it end to end after a publish, not just at generation.

Systems already on the market get a grace period to 2 December 2026 for the machine-readable part. The visible label does not benefit from that extension.

If you publish AI-generated text

This one only bites where the text informs the public on matters of public interest and no human reviewed it. Have a person genuinely review it and take editorial responsibility, and the obligation generally falls away. That is the better operating model anyway — but do not claim a review that did not happen.

The obligation almost everyone has already missed

Article 4 AI literacy has been in force since February 2025. It applies to essentially any business whose staff use AI tools — not just high-risk deployers. The Omnibus softened the wording, but the expectation that you can show something did not go away.

It is also the cheapest obligation in the entire Act to satisfy: write an acceptable use policy, run a session explaining what the tools do and how they fail, and keep an attendance log. An afternoon of work, and the log is the evidence.

What you probably do not need to worry about

Being honest about scope is more useful than manufacturing alarm. If you are an ordinary small business using AI tools as delivered — chat assistants, coding assistants, transcription, marketing copy — then:

That is a manageable list. Anyone telling a ten-person company it faces existential fines is selling something.

The two prohibitions that do catch SMBs

Most businesses clear the Article 5 banned list easily. Two exceptions come up repeatedly:

Emotion inference at work. Sales-call sentiment tools, interview "enthusiasm" scoring, and employee productivity monitors frequently market exactly this. Inferring emotions in a workplace or educational setting is prohibited outright, with narrow medical and safety exceptions. A free trial still counts as deployment.

AI in hiring. Not prohibited, but squarely high-risk under Annex III — including features inside your applicant tracking system that you never deliberately switched on. Worth checking what your recruitment software actually does before the December 2027 deadline arrives, because the remediation work is measured in quarters.

Not sure which of these applies to you?

Ten questions, no signup, no email, nothing stored. You get a plain-English list of the obligations that apply to your business and the dates they bite.

Run the free readiness check

Not legal advice. This is a general explanation of a regulation, not an opinion on your circumstances. If you operate in a regulated sector, use AI in hiring or lending, or have heard from a regulator, speak to a qualified lawyer in your jurisdiction.