The short answer: the high-risk obligations were postponed to December 2027. The Article 50 transparency obligations were not. They apply from 2 August 2026, and they affect far more ordinary businesses than the high-risk rules ever would — anyone running a chatbot, publishing AI-generated images, or putting out AI-written content.
If you read a headline saying the AI Act was delayed and concluded you had another year, that conclusion is wrong for most small businesses. Here is the precise picture.
What the Digital Omnibus actually changed
The Digital Omnibus was provisionally agreed on 6 May 2026. It moved two things and softened a third:
- Standalone high-risk systems (Annex III) — moved from 2 August 2026 to 2 December 2027
- High-risk AI embedded in regulated products (Annex I) — moved from 2 August 2027 to 2 August 2028
- The Article 4 AI literacy duty — softened in wording, from guaranteeing a literacy level to "supporting the development of AI literacy" among staff
It did not touch Article 50. It did not touch the Article 5 prohibitions. It did not touch the GPAI obligations.
One caveat that matters. The Omnibus takes legal effect only when it is published in the Official Journal. Until then, the original schedule remains legally operative. Publication was expected before 2 August 2026, but if you are reading this and it has not happened, the postponements are not yet law.
The full timeline
| Date | What applies | Status |
|---|---|---|
| 2 Feb 2025 | Prohibited practices (Art. 5); AI literacy (Art. 4) | In force |
| 2 Aug 2025 | GPAI model obligations; penalties enforceable | In force |
| 2 Aug 2026 | Transparency obligations (Art. 50) | Now |
| 2 Dec 2026 | Watermarking grace period ends for pre-existing systems | Upcoming |
| 2 Dec 2027 | High-risk standalone systems (Annex III) | Postponed |
| 2 Aug 2028 | High-risk in regulated products (Annex I) | Postponed |
Does this reach you if you are not in the EU?
Possibly, and this catches people out. The Act applies if you place an AI system on the EU market or if the output of your AI system is used in the EU. A US company with European customers using its AI-powered product can be in scope without having any EU entity, office, or staff.
The practical test is not where you are incorporated. It is whether an EU person ends up on the receiving end of your AI.
What Article 50 requires, concretely
If you run a chatbot
People must be told they are dealing with a machine — clearly, and before they start, not buried in a policy page. There is an exception where it is obvious from context, but it is narrower than people assume and a single plain sentence costs nothing.
In practice: disclose before the user's first message, don't dress the bot up as a named human employee with a stock photo, and always provide a route to a person.
If you publish AI-generated images, audio, or video
Two separate duties, and most businesses only do the first. You need a visible label, and you need machine-readable marking — C2PA Content Credentials, IPTC metadata, or provider watermarking such as SynthID.
The trap: image pipelines routinely strip metadata on resize or export. You can implement the marking correctly and have your CMS silently remove it. Test it end to end after a publish, not just at generation.
Systems already on the market get a grace period to 2 December 2026 for the machine-readable part. The visible label does not benefit from that extension.
If you publish AI-generated text
This one only bites where the text informs the public on matters of public interest and no human reviewed it. Have a person genuinely review it and take editorial responsibility, and the obligation generally falls away. That is the better operating model anyway — but do not claim a review that did not happen.
The obligation almost everyone has already missed
Article 4 AI literacy has been in force since February 2025. It applies to essentially any business whose staff use AI tools — not just high-risk deployers. The Omnibus softened the wording, but the expectation that you can show something did not go away.
It is also the cheapest obligation in the entire Act to satisfy: write an acceptable use policy, run a session explaining what the tools do and how they fail, and keep an attendance log. An afternoon of work, and the log is the evidence.
What you probably do not need to worry about
Being honest about scope is more useful than manufacturing alarm. If you are an ordinary small business using AI tools as delivered — chat assistants, coding assistants, transcription, marketing copy — then:
- You are a deployer, not a provider. That is the lighter category by a wide margin.
- You are almost certainly not high-risk, unless you use AI to screen job applicants or assess creditworthiness.
- Your realistic obligations are: AI literacy, avoiding the prohibited list, and Article 50 transparency if you run a chatbot or publish generated content.
That is a manageable list. Anyone telling a ten-person company it faces existential fines is selling something.
The two prohibitions that do catch SMBs
Most businesses clear the Article 5 banned list easily. Two exceptions come up repeatedly:
Emotion inference at work. Sales-call sentiment tools, interview "enthusiasm" scoring, and employee productivity monitors frequently market exactly this. Inferring emotions in a workplace or educational setting is prohibited outright, with narrow medical and safety exceptions. A free trial still counts as deployment.
AI in hiring. Not prohibited, but squarely high-risk under Annex III — including features inside your applicant tracking system that you never deliberately switched on. Worth checking what your recruitment software actually does before the December 2027 deadline arrives, because the remediation work is measured in quarters.
Not sure which of these applies to you?
Ten questions, no signup, no email, nothing stored. You get a plain-English list of the obligations that apply to your business and the dates they bite.
Run the free readiness checkNot legal advice. This is a general explanation of a regulation, not an opinion on your circumstances. If you operate in a regulated sector, use AI in hiring or lending, or have heard from a regulator, speak to a qualified lawyer in your jurisdiction.