On August 2, 2026, a Sunday, a specific set of EU AI Act rules takes effect regardless of the holiday calendar: any chatbot serving EU users must say it is a machine, and AI-generated deepfakes must carry a disclosure. Fines for getting this wrong reach €15 million or 3% of global turnover, whichever is higher.

Key Takeaways
  • Article 50 transparency rules apply from August 2, 2026, unchanged by the recent delay.
  • Most high-risk AI obligations were pushed to December 2, 2027 (Annex III) and August 2, 2028 (Annex I products).
  • Chatbots, deepfakes, synthetic media, and emotion-recognition tools all carry disclosure duties starting August 2.
  • Penalties reach €15 million or 3% of worldwide annual turnover, whichever is higher.

The slides embedded below walk through this same split in eight frames, a deck built with AskDeck from a short brief. Back to the substance: understanding which obligations actually apply this week is the part most compliance teams still get wrong.

Swipe or scroll sideways to flip through the 15-slide deck →

What changed with the Digital Omnibus, and what didn’t?

The Digital Omnibus on AI amends the EU AI Act to delay the heaviest compliance burden, not all of it. For standalone high-risk systems classified under Annex III, the deadline moves from August 2, 2026 to December 2, 2027, a roughly 16-month reprieve. Obligations for high-risk AI embedded in regulated products under Annex I, such as medical devices and machinery, move from August 2027 to August 2, 2028.

The Council gave its final green light to the package on June 29, 2026, after the Parliament’s endorsement earlier that month. The delay uses fixed calendar dates rather than a conditional trigger tied to whether technical standards are ready. Lawmakers had floated linking the new dates to standards availability, but dropped that in favor of dates companies can actually plan around, according to Pinsent Masons.

What does Article 50 actually require starting August 2?

Article 50 covers four distinct situations and applies broadly, not just to high-risk deployers. It reaches AI systems that interact directly with people, such as chatbots and voice assistants; systems that generate or manipulate synthetic audio, image, video, or text; emotion-recognition or biometric-categorization tools; and systems producing deepfakes or AI-written text published on matters of public interest, according to a breakdown from law firm Stibbe.

For chatbots, the disclosure has to be immediate and visible, not tucked away. A statement buried in terms and conditions, a metadata watermark alone, or a vague reference to an “assistant” doesn’t satisfy the duty; the notice has to be perceivable in the interaction itself. Providers of synthetic media must mark output so it’s detectable as artificial, and anyone using AI to create deepfakes of real people, places, or events must disclose the manipulation.

Emotion recognition works differently from the outright workplace ban already in force under Article 5, which covers only workplaces and schools. Outside those settings the practice is generally permitted, but deployers must tell the people being analyzed that it’s happening.

Who actually has to comply, and does location matter?

Article 50 follows the AI system’s output, not the company’s mailing address, so being headquartered outside the EU offers no shelter. If EU users interact with a chatbot, encounter AI-generated content from a product, or could be shown synthetic media a company generated, the obligation applies, per analysis from compliance publication CoderCops. There’s no small-business carve-out either: open-source projects aren’t automatically excused from marking outputs. Purely personal, non-professional use, like a household chatbot or a student’s essay, falls outside scope, as does AI built solely for research.

What happens if a company ignores these rules?

Non-compliance is expensive and scales with company size rather than sitting at a flat fee. Penalties for Article 50 violations reach €15 million or 3% of worldwide annual turnover for the preceding financial year, whichever is higher. That’s a lower tier than the fines tied to the AI Act’s outright-banned practices, but still meaningful exposure for any business with EU revenue.

The one real concession inside Article 50 concerns systems already on the market. Providers of generative AI sold or deployed before August 2, 2026 get until December 2, 2026 to bring machine-readable marking into line, four months rather than the six originally proposed. Anything newly released after August 2 must comply immediately, with no grace period. The Commission separately added a new prohibition on AI tools that generate non-consensual intimate imagery and child sexual abuse material, also effective December 2, 2026.

Common questions

Does the delay touch AI literacy requirements? No. The duty to ensure staff have adequate AI literacy has applied since February 2, 2025, and the Digital Omnibus leaves it untouched.

Is the AI content labelling Code of Practice mandatory? No. It’s voluntary guidance the Commission published to help structure marking and labelling decisions; the binding rules sit in Article 50 itself.

If an organization is still mapping which of these obligations apply to which systems, that mapping exercise, not the format it’s presented in, is the real work. The example deck below was built with AskDeck from a short brief on this same topic and it’s free to download and edit if a clean visual version helps make the case internally.

Download the editable slides (.pptx) →

Make your own deck with AskDeck →