For two years, 2 August 2026 was the date every AI compliance plan revolved around. The Digital Omnibus, adopted by the European Parliament on 16 June and by the Council on 29 June, sets 2 December 2027 for the high-risk obligations applying to Annex III systems and 2 August 2028 for those applying to AI embedded in regulated products. As of 18 July 2026, the amending regulation awaited publication in the Official Journal and would enter into force on the third day after publication.
The common misreading is to treat that as a pause. Article 50 was not postponed. From 2 August 2026, providers of AI systems intended to interact directly with natural persons must ensure those persons are informed unless the interaction is obvious. Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text must make outputs machine-readable and detectable as artificially generated or manipulated. That marking duty is limited by technical feasibility, the characteristics and limitations of the content, implementation costs and the generally acknowledged state of the art; it does not apply to standard assistive editing, systems that do not substantially alter the deployer's input or its meaning, or qualifying law-enforcement uses. Deployers must disclose deepfakes and certain public-interest text, subject to the regulation's scope and exceptions.
The duty therefore depends on the organisation's role and the output, not merely on whether it uses AI. The Commission's voluntary Code of Practice on marking and labelling, published on 10 June 2026, can support compliance with specified Article 50 duties. It does not replace the regulation or the need to analyse the use case.
Article 50 duties become enforceable on 2 August 2026. Breaches can attract administrative fines of up to 15 million euro or, for undertakings, 3 percent of total worldwide annual turnover, whichever is higher; SMEs are subject to the lower of those caps. Depending on national law, competent courts or other bodies may impose the fine. Two December transitions are narrower than a general pause: providers of AI systems, including general-purpose AI systems, that generate synthetic content and were placed on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2); specified prohibitions on provider and deployer practices involving non-consensual intimate material and child sexual abuse material also apply from 2 December 2026.
The AI Act's original Article 5 prohibitions and the AI literacy duty have applied since February 2025. Chapter V has applied to general-purpose AI models since August 2025, while providers of models placed on the market before 2 August 2025 have until 2 August 2027 to comply. The voluntary GPAI Code of Practice can help providers demonstrate compliance.
For a legal team, three moves before the date. First, inventory every AI surface that talks to people or publishes outward, including marketing, customer service and product features. Second, map the output and the applicable disclosure or marking rule, including any exception. Third, record whether the organisation acts as provider or deployer for each surface. Offering a vendor tool under your own name may affect that role analysis. Once in force, the adopted text gives high-risk work more time. It does not postpone transparency.
Sources
- European Commission, AI Act policy page (application timeline), July 2026
- Council of the EU, final green light to the Digital Omnibus on AI, 29 June 2026
- European Commission, Code of Practice on Transparency of AI-Generated Content, June 2026
- EUR-Lex, Regulation (EU) 2024/1689 (AI Act), Articles 50, 99, 111 and 113
- Council of the EU, adopted Digital Omnibus on AI text, PE-CONS 30/26, June 2026
Next: AI citation errors: a verification protocol for legal teams →