What actually happened on August 2
The European Commission's AI Office, together with national authorities, started enforcing the AI Act's transparency requirements on August 2, 2026. These are the obligations set out in Article 50 - not the Act's headline "high-risk system" rules, but a narrower, more widely applicable set of disclosure requirements that catch far more companies than most people assume.
The four situations Article 50 actually covers
The European Commission's own guidance and multiple legal trackers converge on the same four triggers. If any one of these describes something you ship, you have a disclosure obligation:
Chatbots and AI agents
Any system intended to interact directly with people - chatbots, virtual assistants, automated phone systems, AI agents - must be designed so users are told they're talking to AI, unless that's already obvious from context.
Deepfakes
Deployers generating image, video, or audio content that resembles a real person, object, or event must disclose it's artificially generated - even without intent to deceive, and even if no real individual is actually depicted.
Published AI-generated text
Text published to inform the public on matters of public interest, generated or manipulated by AI, must be disclosed as such unless a human has reviewed it and takes editorial responsibility for its accuracy.
Emotion recognition & biometric categorization
Systems that infer emotion or categorize people biometrically must inform the people exposed to them - a disclosure obligation distinct from, and in addition to, any separate high-risk classification.
Not sure where your product lands against these four triggers? Get a free AI Act scoping review - most teams are surprised by which of their features are actually in scope.
The disclosure has to be genuinely visible
One detail catches teams out: a hidden, machine-readable watermark added by the AI provider does not satisfy a deployer's disclosure obligation on its own. The AI origin has to be communicated through a label a person can actually see or hear, understandable without needing a separate detection tool. Burying an "AI-generated" flag in metadata nobody reads is not compliance - it's the same failure mode as a cookie banner nobody can find.
What's genuinely postponed, and what isn't
This is where a lot of coverage gets muddled, so worth stating plainly. The AI Act's separate, far more demanding "high-risk system" obligations - covering AI used in employment, education, biometrics, credit scoring, essential services, and migration/border management under Annex III - were due to apply from August 2 as well. Under the Digital Omnibus agreement reached by the Council and Parliament in May 2026 and in force since July 27, 2026, those Annex III obligations were pushed back to December 2, 2027.
| Requirement | Status as of Aug 2026 | Applies to |
|---|---|---|
| Article 50 transparency obligations | In force and enforced since Aug 2, 2026 | Chatbots, deepfake generators, AI content publishers, emotion/biometric systems |
| Annex III high-risk system obligations | Deferred to Dec 2, 2027 (Digital Omnibus) | Employment, education, biometrics, credit scoring, essential services, border/migration systems |
| New prohibitions (non-consensual intimate deepfakes, CSAM) | Added under the Digital Omnibus, in force | Any AI system capable of generating this content |
Why this reaches beyond EU-headquartered companies
The AI Act's extraterritorial reach is not a footnote. Any company whose AI systems or AI-generated outputs reach EU users - including US, Indian, or Singapore-based companies with European customers, partners, or website visitors - has to meet these obligations for that traffic. Building for a European market without a compliance review isn't a shortcut, it's a fine waiting to be discovered by the first regulator who checks.
Key takeaways
- Article 50 transparency obligations are in force and being enforced as of August 2, 2026 - fines up to €15M or 3% of global turnover.
- You're in scope with a customer-facing chatbot, published AI-generated content, or a deepfake-capable tool - "high-risk" classification isn't required.
- A hidden machine-readable watermark alone does not satisfy the disclosure requirement; the label has to be genuinely visible or audible to users.
- The much heavier Annex III "high-risk system" obligations were deferred to December 2, 2027 under the Digital Omnibus agreement.
- The Act applies to any company reaching EU users, regardless of where the company itself is based.
Zetrixweb