What actually happened on August 2

The European Commission's AI Office, together with national authorities, started enforcing the AI Act's transparency requirements on August 2, 2026. These are the obligations set out in Article 50 - not the Act's headline "high-risk system" rules, but a narrower, more widely applicable set of disclosure requirements that catch far more companies than most people assume.

You do not need a "high-risk" AI system for Article 50 to apply to you. It applies the moment you run a customer-facing chatbot, publish AI-generated content, or produce deepfake imagery or audio - full stop. A three-person SaaS company with a support chatbot is in scope the same day as a bank.

The four situations Article 50 actually covers

The European Commission's own guidance and multiple legal trackers converge on the same four triggers. If any one of these describes something you ship, you have a disclosure obligation:

Chatbots and AI agents

Any system intended to interact directly with people - chatbots, virtual assistants, automated phone systems, AI agents - must be designed so users are told they're talking to AI, unless that's already obvious from context.

Deepfakes

Deployers generating image, video, or audio content that resembles a real person, object, or event must disclose it's artificially generated - even without intent to deceive, and even if no real individual is actually depicted.

Published AI-generated text

Text published to inform the public on matters of public interest, generated or manipulated by AI, must be disclosed as such unless a human has reviewed it and takes editorial responsibility for its accuracy.

Emotion recognition & biometric categorization

Systems that infer emotion or categorize people biometrically must inform the people exposed to them - a disclosure obligation distinct from, and in addition to, any separate high-risk classification.

Not sure where your product lands against these four triggers? Get a free AI Act scoping review - most teams are surprised by which of their features are actually in scope.

The disclosure has to be genuinely visible

One detail catches teams out: a hidden, machine-readable watermark added by the AI provider does not satisfy a deployer's disclosure obligation on its own. The AI origin has to be communicated through a label a person can actually see or hear, understandable without needing a separate detection tool. Burying an "AI-generated" flag in metadata nobody reads is not compliance - it's the same failure mode as a cookie banner nobody can find.

What's genuinely postponed, and what isn't

This is where a lot of coverage gets muddled, so worth stating plainly. The AI Act's separate, far more demanding "high-risk system" obligations - covering AI used in employment, education, biometrics, credit scoring, essential services, and migration/border management under Annex III - were due to apply from August 2 as well. Under the Digital Omnibus agreement reached by the Council and Parliament in May 2026 and in force since July 27, 2026, those Annex III obligations were pushed back to December 2, 2027.

Requirement Status as of Aug 2026 Applies to
Article 50 transparency obligations In force and enforced since Aug 2, 2026 Chatbots, deepfake generators, AI content publishers, emotion/biometric systems
Annex III high-risk system obligations Deferred to Dec 2, 2027 (Digital Omnibus) Employment, education, biometrics, credit scoring, essential services, border/migration systems
New prohibitions (non-consensual intimate deepfakes, CSAM) Added under the Digital Omnibus, in force Any AI system capable of generating this content
Regulatory detail worth double-checking with counsel before you rely on it: some legal trackers reported an earlier Omnibus proposal to also shift the transparency deadline itself to December 2026. The Commission's own August 2 press release confirms enforcement of the transparency rules began that day regardless - treat this piece as a starting map, not a substitute for a compliance sign-off on your specific product.

Why this reaches beyond EU-headquartered companies

The AI Act's extraterritorial reach is not a footnote. Any company whose AI systems or AI-generated outputs reach EU users - including US, Indian, or Singapore-based companies with European customers, partners, or website visitors - has to meet these obligations for that traffic. Building for a European market without a compliance review isn't a shortcut, it's a fine waiting to be discovered by the first regulator who checks.

Key takeaways

  • Article 50 transparency obligations are in force and being enforced as of August 2, 2026 - fines up to €15M or 3% of global turnover.
  • You're in scope with a customer-facing chatbot, published AI-generated content, or a deepfake-capable tool - "high-risk" classification isn't required.
  • A hidden machine-readable watermark alone does not satisfy the disclosure requirement; the label has to be genuinely visible or audible to users.
  • The much heavier Annex III "high-risk system" obligations were deferred to December 2, 2027 under the Digital Omnibus agreement.
  • The Act applies to any company reaching EU users, regardless of where the company itself is based.
This is general information, not legal advice - AI Act compliance details are still being finalized in places, and your specific obligations depend on exactly what you've built. A technical scoping conversation is the right next step before a legal one.