Since the June vote, one sentence has been circulating in newsletters and LinkedIn feeds: the AI Act has been pushed to 2027. It is accurate for part of the text, and misleading for the part that concerns the largest number of organisations. The 2 August 2026 deadline has not moved for the regulation's most transversal obligation.
The calendar was settled late: the amending text entered into force on 27 July, three days before the date it was meant to clarify.
What Regulation 2026/1744 changed, and when
The Digital Omnibus on AI — formally Regulation (EU) 2026/1744 of 8 July 2026 — was published in the Official Journal on 24 July and entered into force on 27 July 2026, on the third day following publication. That accelerated entry is deliberate: the calendar had to be settled before the AI Act became generally applicable.
It is the first formal amendment to the AI Act since its adoption in 2024. The consolidated timeline:
- 2 August 2026 — transparency (Article 50), penalties, national supervisory authorities. Not deferred.
- 2 December 2026 — marking of synthetic content (Article 50(2)) for generative systems already on the market; two new prohibited practices take effect.
- 2 December 2027 — high-risk obligations for Annex III systems, instead of 2 August 2026.
- 2 August 2028 — AI embedded in products already covered by EU product safety legislation (Annex I).
The reason for the deferral is less about lobbying than about a practical finding: harmonised standards were not finalised and several Member States had not designated their competent authorities. It is hard to require compliance when the measuring tools do not yet exist. A deferral is not a repeal, however — high-risk requirements still need preparing, with sixteen extra months of runway.
What applies on 2 August: Article 50
Article 50 rests on one idea: a person should be able to tell that they are dealing with a machine, or with content produced by one. It covers four distinct situations.
Interaction with an AI system. Users talking to a chatbot, a voice assistant or a conversational agent must be informed — unless it is obvious to a reasonably observant person. The wording matters: this is information given at the point of contact, not a clause buried in the terms of use.
Marking synthetic content. Providers of systems generating text, image, audio or video must apply a machine-readable mark enabling detection that the content was artificially generated or manipulated. An exception applies to systems performing a standard editing assistance function that does not substantially alter the input data or its semantics — a spell checker is out of scope.
Deepfakes. Content resembling real people, places or events must be disclosed as artificial.
Published information texts. Certain AI-generated content published to inform the public on matters of public interest also falls within scope.
The grace period matters: generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the marking obligations. Deepfakes produced before that date need not be labelled retroactively.
Penalties become effective on the same date
2 August is not only an application date: it is also when the penalty regime and national supervisory authorities become operational.
Article 99 sets three tiers. Prohibited practices under Article 5 sit in the highest band — EUR 35 million or 7 % of worldwide turnover. Breaches of the Article 50 transparency obligations sit in the middle band: EUR 15 million or 3 % of total worldwide annual turnover, whichever is higher. Supplying incorrect or misleading information to authorities falls under a lower third band.
These are maxima, not tariffs. The regulation requires penalties to be effective, proportionate and dissuasive, and lists the factors to weigh: size of the operator, whether the breach was intentional or negligent, degree of cooperation, technical and organisational measures already in place, corrective action taken. The situation of SMEs and start-ups must be explicitly considered.
Article 4 was rewritten — in your favour
Largely missed in the coverage of the deferral, Article 4 on AI literacy changed nature. In its version applicable since February 2025, it required operators to ensure a sufficient level of competence among those operating AI systems. Since 27 July 2026 it requires them to take measures supporting the development of that competence.
Moving from a duty of result to a duty of effort shifts the burden of proof. You still document what was done — training sessions, role-based guidance, distribution records — but no longer demonstrate that a threshold was met. For roughly eighteen months, operators were bound by a stricter rule than the one now in force.
What to have done before Sunday
For an organisation that uses AI without developing it, four actions cover the essentials:
- Inventory. A register of AI systems in use: which one, for what, on what data, in which department, under whose responsibility. Without that map, no obligation can be assessed — and it is the first document you will be asked for.
- Disclose interactions. Every conversational touchpoint must state the nature of the system. One sentence at first contact is enough; it has to be visible, not buried.
- Handle generated content. Identify what is produced or substantially edited by AI and distributed, and plan for marking. The December grace period covers systems already in service, not what you publish now.
- Document awareness efforts. Under the new Article 4: what was offered to teams, to whom, and when.
For an SME this is not a multi-month programme. It is a few days of work — provided you start with the inventory rather than the paperwork.
Compliant is not the same as secure
One final distinction, frequently blurred. Article 50 mandates transparency: say what you use, mark what you produce. It says nothing about the robustness of the system you deployed.
A perfectly compliant assistant — disclosure banner in place, content marked, register up to date — can still have its system prompt extracted in three messages, reveal an API key that was pasted into it, or trigger a tool call outside its intended scope. None of these is an AI Act infringement. All of them are security incidents, with the usual consequences: data exposure, reputational damage, chained exploitation if the agent holds rights on other systems.
The two are handled separately, in that order: compliance has a legal deadline, security has a deadline set by the attacker. That is exactly how the AI Red Team offering is structured — Article 50 compliance on one side, offensive testing of agents on the other.
Comments