The EU AI Act on 2 August 2026: What Actually Applies (and What the Omnibus Just Delayed)
TL;DR
- The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026. It delayed most of the high-risk obligations, but it did not touch the transparency rules.
- High-risk was pushed back: standalone Annex III systems now bind on 2 December 2027, and AI embedded in regulated products under Annex I (including medical devices) on 2 August 2028.
- Article 50 transparency and AI content-marking still apply on 2 August 2026. That is the obligation almost every company using a chatbot or generating AI content actually has to meet now.
- If your generative system was already on the market before 2 August 2026, you have a transition period and the marking duties bind you from 2 December 2026. New systems from 2 August 2026 are immediate.
- The penalty tier for transparency breaches is up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher (Article 99(4)).
- The most common mistake this week is assuming the Omnibus delay covers you. It delayed high-risk. It did not delay transparency.
What happened
For a year, the whole market planned around one date: 2 August 2026, when the bulk of the EU AI Act was due to apply, high-risk obligations included. On 24 July 2026 the Digital Omnibus on AI was published in the Official Journal, and on 27 July it entered into force. It is the first amendment to the AI Act since 2024, and it moved the deadlines that most compliance decks were built on.
Here is the part that matters: it moved the high-risk deadlines. It left the transparency obligations exactly where they were.
If your compliance work was driven by the high-risk cliff, you have real breathing room now. If it was driven by transparency, and for most SMEs shipping chatbots or AI-generated content it is, nothing changed. The clock still runs out on Sunday.
Is your AI system high-risk?
Find out in 2 minutes, free, no signup required.
Take the free assessmentWhat actually applies on 2 August 2026: Article 50
Article 50 is about one thing: people have a right to know when they are dealing with AI, or looking at AI-generated content. It splits into duties for the company that builds the system (the provider) and the company that uses it (the deployer).
1. Chatbots and AI assistants (Article 50(1)). If your product talks directly to people through an AI, you must tell them they are interacting with an AI, not a human. The disclosure has to be given at the first interaction, be clear and accessible, and appear in every language you serve. The only carve-out is where it is obvious from the context, and that exception is narrow. A support bot does not qualify. Full breakdown: Do I need to disclose my AI chatbot?
2. AI-generated content marking (Article 50(2)). If your system generates synthetic audio, image, video, or text, the output must be marked in a machine-readable format and detectable as artificially generated or manipulated. A visible label on the screen is not enough on its own. This is the obligation that maps to provenance standards like C2PA and watermarking, and it is the one most teams have not implemented, because it is a technical step, not a policy page.
3. Deepfakes and public-interest text (Article 50(4)). If you deploy a system that produces deepfakes (image, audio, or video that resembles real people or events), you must disclose that the content is artificially generated or manipulated. AI-generated text published to inform the public on matters of public interest must also be disclosed, unless a human reviewed it and holds editorial responsibility. Guide: Article 50 and deepfake rules
On 20 July 2026, the Commission adopted its final Article 50 guidelines (51 pages) that clarify the marking and labelling scope, and assessed the Code of Practice on Transparency of AI-Generated Content as adequate. If you read one thing beyond this post, read what those guidelines changed: The final Article 50 guidelines, what actually changes before 2 August.
Provider or deployer: which one are you?
Most SMEs are deployers and do not realise the duty still lands on them.
- You are a provider if you build or brand the AI system: your own chatbot, your own image or text generator. You carry the disclosure duty (50(1)) and the machine-readable marking duty (50(2)).
- You are a deployer if you use someone else's AI inside your product or site: a third-party chat widget (Intercom, Tidio, Crisp, Drift), an image or video generation API, a voice agent. You are responsible for the disclosure appearing on your surface (50(1)) and for labelling any deepfake or public-interest text you publish (50(4)).
"We just use a tool" is not a defence. If it faces your users, the notice has to be on your site.
The one date most people will get wrong
There are two dates now, not one.
- Systems placed on the market from 2 August 2026: transparency and marking apply immediately.
- Systems already live before 2 August 2026: a transition period applies, and per the Omnibus transitional provisions the marking and transparency duties bind them from 2 December 2026.
That four-month window is not a reason to wait. It is the time to implement. Anything you ship new from Sunday is in scope from day one. Before you rely on the December date for a specific system, read Article 50 and the transitional articles in the OJ text directly, linked below.
What to do this week
- Inventory every surface that talks to users or outputs AI content. Web chat is the obvious one. The ones teams miss: PDF exports, emails, generated images, product descriptions, embedded assistants.
- Add the "you are interacting with an AI" notice at first interaction, in every language you serve.
- Mark AI-generated media in a machine-readable format (C2PA or watermark), not only a visible caption.
- Label deepfakes and AI-generated public-interest text.
- Keep evidence. What you disclosed, on which surface, since when. Screenshots and logs are your proof if anyone asks.
- If a generative system was already live before Sunday, use the transition to 2 December 2026 to implement, and document that you are on track.
What not to do
- Do not assume the Omnibus delay covers you. It delayed high-risk conformity work. Transparency was not touched.
- Do not rely on a buried terms-of-service line, or a visible-only label where machine-readable marking is required. The two are different obligations.
How to get compliant fast
Legalithm's tooling is built for exactly this obligation, and it is free.
- Run the free AI Act assessment to see which Article 50 duties apply to your system, provider or deployer, in about ten minutes. No account needed.
- Generate your Article 50 disclosures with the no-account disclosure generator: ready-to-use notice copy for chatbots and AI-generated content.
- Download the Article 50 Disclosure Pack for the copy/paste templates, UX placement patterns, and the evidence fields to log.
- On WordPress, the EU AI Act plugin adds a compliant disclosure in minutes, running locally with no data leaving your site.
The high-risk cliff moved. The transparency deadline did not. If your product uses a chatbot or generates content, 2 August 2026 is your date.



