P.K. SHARMA

Cyber security intelligence, AI governance, practitioner analysis

The AI Act deadline landed on Sunday. Most people watched the wrong half

2 August 2026 arrived with the high-risk regime already moved to December 2027 by Regulation (EU) 2026/1744. What almost nobody prepared for is that Article 50 transparency was never postponed: it applies now, to systems most organisations do not classify as high-risk at all.

By Editorial Desk · · 6 min read

What actually changed, and when

For two years, 2 August 2026 was the EU AI Act date. It passed on Sunday. Most of what people were bracing for did not arrive with it, and one thing that did has been almost entirely ignored.

How the deferral became law

  1. 6 May 2026

    Political agreement reached

    Confirmed by the Council on 13 May 2026.

  2. 8 Jul 2026

    Regulation signed

  3. 27 Jul 2026

    Entry into force

    Six days before the deadline it amends.

  4. 2 Aug 2026

    The original deadline arrives

    Article 50 transparency applies. The high-risk regime does not.

  5. 2 Dec 2026

    Watermarking grace period ends

    Article 50(2) allowed four months for systems already on the market.

  6. 2 Dec 2027

    Annex III high-risk applies

    Moved from 2 Aug 2026. Sixteen months.

  7. 2 Aug 2028

    Annex I high-risk applies

    AI embedded in regulated products.

Regulation (EU) 2026/1744, the Digital Omnibus. Note the margin: entry into force six days before the deadline it was amending.

One detail in the Commission's original proposal is worth knowing because it did not survive: the deferral was going to be a conditional trigger, tied to harmonised standards being ready. The final text replaced that with fixed calendar dates. December 2027 is not contingent on anything. Nobody is going to move it again because a standard slipped.

What moved, and what did not

APPLIES AS ORIGINALLY SCHEDULEDProhibited practices2 Feb 2025GPAI model rules2 Aug 2025Article 50 transparency2 Aug 2026DEFERRED BY THE DIGITAL OMNIBUSHigh risk: Annex IIImoved to 2 Dec 2027High risk: Annex Imoved to 2 Aug 2028ISO/IEC 42001since Dec 2023Requirements unchanged throughout2025202620272028
Obligation dates after the Digital Omnibus. Three sets of duties are unchanged and in force now. Two moved, by sixteen and twenty-four months. The ISO 42001 line is on the chart because it is the only one that has never moved.

What applies now, and what moved

EU AI Act status as at 5 August 2026

ObligationApplies fromStatusReference
Prohibited AI practices2 Feb 2025In forceChapters I–II, Art 113(a)
AI literacy duty2 Feb 2025In forceArt 4
GPAI model obligations2 Aug 2025In forceChapter V, Art 113(b)
Penalties and governance2 Aug 2025In forceArts 99, 100
Article 50 transparency2 Aug 2026In force since SundayArt 50
Watermarking, systems already on market2 Dec 2026Grace period runningArt 50(2)
Annex III high-risk2 Dec 2027Postponed from 2 Aug 2026Art 6(2), Annex III
Annex I high-risk2 Aug 2028PostponedArt 6(1), Annex I
Existing GPAI providers2 Aug 2027TransitionalArt 111(3)
Public authority legacy systems2 Aug 2030TransitionalArt 111(2)
Application dates as amended by Regulation (EU) 2026/1744. Everything in the top half of this table is in force today, and none of it was postponed.

The obligation nobody staffed

Article 50 is the transparency regime, and it is deceptively broad. It is not about high-risk systems. It attaches to systems most organisations classify as ordinary:

What teams prepared for, and no longer need this year

  • Annex III classification work for HR, credit, biometrics, education and critical infrastructure systems.
  • Conformity assessment and technical documentation for high-risk systems.
  • Registration in the EU database ahead of 2 Aug 2026.

What applied on Sunday, and mostly has no owner

  • Telling people they are interacting with an AI system rather than a person, every customer-facing chatbot and voice agent.
  • Marking synthetic audio, image, video and text as artificially generated, in a machine-readable form.
  • Disclosure on deepfakes and on AI-generated text published to inform the public.
  • Emotion recognition and biometric categorisation notices.

The asymmetry is the story. High-risk work sits with a programme, a budget and a named owner. Article 50 obligations sit with marketing, customer service and whoever added a chatbot to the website in 2024, none of whom were in the AI Act steering group, and most of whom have never heard of Article 50.

The four-month watermarking grace to 2 December 2026 applies only to systems already on the market. Anything shipped after Sunday gets no grace at all.

Why paperwork is the right word

Calling this a paperwork phase sounds dismissive and is not meant to be. It is a description of what enforcement can actually reach right now.

A supervisory authority cannot yet assess a high-risk system against harmonised standards, because those standards are not finished. That is the stated reason the deadline moved. What an authority can do is ask an organisation what AI it operates, who owns it, what it decides and what happens when it is wrong, and read the answer. Those questions need no standard and no conformity assessment infrastructure. They need a document that either exists or does not.

Which is why the organisations that will struggle first are not the ones with the most exposure. They are the ones that cannot produce an inventory. A firm with three high-risk systems and a complete register is in a better position than one with none it can name.

The uncomfortable corollary for anyone who paused work when the deadline moved: the deferral removed a deadline for conformity, not the questions that come before it.

There is a second reason the word fits. Article 50 transparency applied on 2 August 2026 and did not move, and it is almost entirely a paperwork obligation in the sense that meeting it means disclosing rather than engineering. Tell people they are talking to a machine. Mark synthetic content so a machine can detect it. Neither requires a harmonised standard, and both are enforceable today against organisations still planning for 2027.

What to check this week

Take this with you

Article 50 exposure, in the order that finds problems fastest

  • List every customer-facing conversational interface: web chat, in-app assistants, voice IVR, WhatsApp and social channels. Each one needs to disclose that it is an AI system.
  • Find who publishes AI-generated content in your name: marketing copy, product imagery, synthetic voice-overs, translated video. That is the marking obligation, and it usually sits outside IT entirely.
  • Check whether your marking is machine-readable. A line of small print in the footer is not what Article 50(2) asks for.
  • Separate systems already on the market before 2 August 2026 from anything shipped since. Only the first group has until 2 December 2026.
  • Keep the Annex III classification work rather than shelving it. December 2027 is a fixed date now, not a conditional one, and the sixteen months are the entire budget.
  • Re-check prohibitions and GPAI obligations, which have been enforceable since 2025 and are unaffected by any of this.

The AI Act timeline tool tracks the amended dates, the risk classifier walks the Annex III test, and the AI literacy tool covers the Article 4 duty that has been live since February 2025.

Sources

  1. PrimaryRegulation (EU) 2024/1689 (the AI Act)EUR-Lexaccessed 2026-08-09
  2. PrimaryRegulatory framework for AI, including the application timelineEuropean Commissionaccessed 2026-08-09
  3. Reported byEU AI Act Omnibus agreement: postponed high-risk deadlinesGibson Dunnaccessed 2026-08-09

Share this briefing

Know someone who owns this problem? Send it to them.

Related briefings

The briefing, in your inbox

Practitioner analysis of cyber and AI security news. No vendor noise.

One email per briefing. Unsubscribe any time.