On 2 August 2026 the EU AI Act stopped being a paper deadline. Article 50 transparency obligations now apply, the AI Office can fine general-purpose AI providers up to 3% of global turnover, and a little-noticed grace period closes on 2 December 2026.

The EU AI Act crossed from drafting into enforcement on 2 August 2026. Two distinct things happened on that date, and conflating them is the fastest way to misjudge your exposure.

The short answer: the Article 50 transparency obligations became directly applicable to providers and deployers, and the European Commission's AI Office acquired the power to investigate and fine providers of general-purpose AI models. The heavy high-risk regime did not arrive — the Digital Omnibus pushed it to December 2027 and August 2028. If you have been waiting for the high-risk deadline to start work, you have already missed a live obligation that applies to you regardless of risk tier.

What changed on 2 August 2026

Change Who it hits Legal basis Status
Chatbot / AI-interaction disclosure Providers Art. 50(1) Applies now
Machine-readable marking of synthetic content Providers of generative AI Art. 50(2) Applies now (grace period for pre-existing systems → 2 Dec 2026)
Emotion recognition & biometric categorisation notice Deployers Art. 50(3) Applies now
Deepfake and public-interest text labelling Deployers Art. 50(4) Applies now
Commission enforcement powers over GPAI models GPAI model providers Art. 88–94, 101 Applies now
Prohibited practices enforcement All Art. 5 Applies now

What did not change is as important: standalone Annex III high-risk obligations remain deferred to 2 December 2027, Annex I embedded AI to 2 August 2028, and the national regulatory sandbox obligation to 2 August 2027.

The enforcement shift nobody priced in

The GPAI obligations in Chapter V have been legally binding since 2 August 2025. What they lacked was a regulator with teeth. Until 2 August 2026 the AI Office could ask, publish guidance, and negotiate — it could not compel.

That asymmetry ended. The AI Office can now:

The Commission also opened the channels through which cases will actually reach it: an AI Act complaints tool, an AI Act Whistleblower Tool, and a dedicated complaints channel for downstream providers building on general-purpose models. That last one matters more than it sounds — it lets a company integrating a foundation model report the upstream provider's non-compliance directly to Brussels.

The four Article 50 obligations, precisely

Article 50 is the broadest-reaching provision in the entire Regulation, because it is risk-independent. It does not ask whether your system is high-risk. It asks what your system does.

1. Systems that interact with people (Art. 50(1)) — provider duty. Chatbots, voice assistants, AI agents and avatars must be designed so that a natural person is informed they are interacting with an AI system. The disclosure must be timely — before or at the start of the interaction. The only carve-out is where it is obvious to a reasonably well-informed person, plus the law-enforcement exemption.

2. Generative output marking (Art. 50(2)) — provider duty. Providers of AI systems generating synthetic audio, image, video or text must mark outputs in a machine-readable format, detectable as artificially generated or manipulated. The marking must be effective, reliable, robust and interoperable. This is the obligation with the December grace period.

3. Emotion recognition and biometric categorisation (Art. 50(3)) — deployer duty. Deployers must inform the natural persons exposed to the system, and comply with GDPR in parallel. Safety-protective uses such as drowsy-driver detection sit outside the disclosure duty.

4. Deepfakes and public-interest text (Art. 50(4)) — deployer duty. Deployers publishing deepfakes, or AI-generated text on matters of public interest, must disclose that the content is artificially generated or manipulated. Exemptions apply where content undergoes human editorial review with editorial responsibility, and for manifestly artistic, creative, satirical or fictional work — subject to proportionate disclosure that does not spoil the work.

Note the split: obligations 1 and 2 fall on providers, 3 and 4 on deployers. Most organisations are deployers, and most compliance programmes have been written as if the whole Article were a provider problem. See our breakdown of providers vs. deployers if you are unsure which you are.

The 2 December 2026 trap

The transitional period is the single most misread element of the August package.

The grace period until 2 December 2026 applies only to machine-readable marking, and only for generative AI systems already placed on the EU market before 2 August 2026.

Three consequences follow:

What non-compliance costs

Breach Ceiling Enforced by
Prohibited practices (Art. 5) €35M or 7% of worldwide turnover National authorities
Article 50 transparency €15M or 3% of worldwide turnover National market surveillance authorities
GPAI model obligations (Art. 101) €15M or 3% of worldwide turnover European Commission / AI Office
Incorrect or misleading information to regulators €7.5M or 1.5% of worldwide turnover National authorities / Commission

In each case the ceiling is the higher of the fixed sum and the percentage. For a company above roughly €500 million in turnover, the percentage is always the operative figure.

Full detail on the tiering and the SME caps is on our penalties page.

Who your regulator actually is

This is the practical question, and the answer is rarely Brussels.

Designation of those national authorities has been uneven across the 27 Member States. In practice this produces a patchwork: identical conduct may draw an inspection in one Member State and nothing in another, at least in the first enforcement cycle. That asymmetry is a reason to comply to the strictest national interpretation, not the most permissive — a single well-resourced regulator can set the de facto European standard, as happened repeatedly under the GDPR.

The Code of Practice: the closest thing to a safe harbour

The Commission published the Code of Practice on Transparency of AI-generated Content in June 2026 and confirmed it as an adequate means of demonstrating compliance with the Article 50 marking and labelling duties.

By the end of July 2026 roughly 190 organisations had signed. The Code has two sections:

Signing is voluntary and confers no legal immunity. But the asymmetry is real: a signatory implementing the Code has a documented, Commission-recognised compliance route. A non-signatory must construct and defend its own method in front of a market surveillance authority. Interoperable watermarking schemes such as Google's SynthID are the emerging technical baseline for Section 1.

What to do in the next 120 days

  1. Inventory by function, not by risk tier. List every AI system that talks to a person, generates content, or infers emotions. Risk classification is irrelevant to Article 50 scope.
  2. Split the inventory provider vs deployer. Obligations 1–2 versus 3–4 land on different legal entities, often within the same group.
  3. Date every generative system. On the EU market before 2 August 2026 → marking due 2 December 2026. On or after → due now. Record the evidence for the date.
  4. Ship the disclosures. In-interface chatbot notices, content labels, emotion recognition notices. These are already overdue if missing.
  5. Decide on the Code of Practice. Sign it, or document why your alternative method meets Article 50 to the same standard.
  6. Red-team against the new Article 5 prohibition before 2 December 2026 if you provide a generative image, video or audio model.
  7. Identify your national market surveillance authority in each Member State where you operate, and check whether it has published enforcement priorities.

Our compliance checklist covers the full obligation set, and the transparency obligations pillar goes deeper on Article 50 scope and exemptions.

The road after August 2026

Date Milestone
2 December 2026 Marking grace period closes; new Art. 5 prohibition (CSAM / NCII) enforceable
2 August 2027 Member States must have a regulatory sandbox operational
2 December 2027 Standalone Annex III high-risk obligations apply
2 August 2028 Annex I embedded high-risk AI obligations apply

The deferrals granted by the Digital Omnibus bought time on the high-risk regime — roughly sixteen months for Annex III, two years for Annex I. They bought no time at all on transparency. Organisations that read the Omnibus as a general reprieve have misread it: the Regulation's broadest obligation is live, enforceable, and carries a 3% ceiling.

For the full picture of what the Omnibus changed, see our Digital Omnibus analysis and the AI Act deadline tracker.

Official sources

Official AI Act Compliance Deadline Calendar

Updated · Sources: Regulation (EU) 2024/1689 and the 2026 Digital Omnibus on AI.

Obligation Applies to Original date New date Status Countdown Legal basis
Prohibited Practices (Art. 5) All providers and deployers active AI Act Art. 5
GPAI Rules (Chapter 5) GPAI model providers active AI Act Art. 51-56
Commission Enforcement Powers over GPAI GPAI model providers active AI Act Art. 88-94, 101
Transparency Obligations (Art. 50) Providers and deployers of chatbots, generative, emotion recognition systems active AI Act Art. 50
New Art. 5 Prohibition (CSAM / non-consensual intimate imagery) Providers and deployers of generative AI systems active AI Omnibus 2026 Art. 5
AI-Generated Content Marking (pre-existing systems) Providers of generative AI systems on the market before 2 Aug 2026 active AI Act Art. 50(2) — transitional
Regulatory Sandboxes National competent authorities deferred AI Omnibus 2026 Art. 57
High-risk AI — Annex III (standalone) Providers of standalone Annex III systems deferred AI Omnibus 2026 Art. 6(2)
High-risk AI — Annex I (embedded) AI embedded in Annex I regulated products deferred AI Omnibus 2026 Art. 6(1)

Download JSON · CC BY 4.0

Frequently Asked Questions

Two things changed. First, the Article 50 transparency obligations entered into application: chatbots must disclose they are AI, synthetic content must carry machine-readable marks, deepfakes must be labelled, and deployers of emotion recognition systems must inform the people exposed to them. Second, the European Commission's AI Office gained the power to actually enforce the general-purpose AI (GPAI) obligations that have been legally binding since 2 August 2025 but were previously unenforceable. Enforcement, not obligation, is the real change.

Yes. Fines for breaching Article 50 transparency obligations reach €15 million or 3% of total worldwide annual turnover, whichever is higher, and are imposed by national market surveillance authorities. The Commission can impose the same 3% / €15 million ceiling on GPAI model providers under Article 101. Breaches of the Article 5 prohibited practices carry the top tier: €35 million or 7% of worldwide turnover.

Only if the system was already on the EU market before 2 August 2026. The transitional period covers the machine-readable marking obligation for generative AI systems placed on the market before that date. Any system launched on or after 2 August 2026 must mark its outputs from day one. The other three Article 50 duties — chatbot disclosure, deepfake labelling and emotion recognition notice — apply now, with no grace period.

Yes, and this is the most common misreading. Article 50 is a risk-independent obligation. It attaches to what the system does — interacts with people, generates synthetic content, recognises emotions — not to whether it is classified as high-risk under Annex III or Annex I. A minimal-risk marketing chatbot is in scope; a high-risk CV-screening tool that never talks to a candidate may not be.

No. The Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27 July 2026 — deferred them. Standalone Annex III high-risk systems now apply from 2 December 2027, and AI embedded in Annex I regulated products from 2 August 2028. The obligation for Member States to run a regulatory sandbox moved from 2 August 2026 to 2 August 2027.

Both, on different targets. The Commission's AI Office is the exclusive enforcer for general-purpose AI model providers. Everything else — Article 50 transparency, prohibited practices, and later the high-risk regime — is enforced by national market surveillance authorities in each Member State. For most companies the relevant regulator is national, not Brussels.

It does not confer legal immunity, but it is the closest thing to a safe harbour available. The Commission has recognised the Code as an adequate means of demonstrating compliance with the Article 50 marking and labelling duties. Roughly 190 organisations had signed by the end of July 2026. A signatory following the Code has a documented, Commission-recognised compliance route; a non-signatory has to justify its own method.

2 December 2026. Three things land on that date: the machine-readable marking grace period closes for pre-existing generative AI systems, the new Article 5 prohibition on AI generating child sexual abuse material and non-consensual intimate imagery becomes enforceable, and the transitional arrangements introduced by the Digital Omnibus expire.

Stay ahead of AI Act changes

Get compliance alerts when deadlines or obligations change.

No spam. One-click unsubscribe.

Take compliance further with the AI Act Academy

Templates, training modules, and live Q&A — everything needed to implement AI Act compliance.