2 August 2026 was supposed to be the day the EU AI Act grew teeth. It was the date circled in every compliance calendar since 2024 — the moment the high-risk regime applied, the moment recruitment algorithms and law-enforcement AI and credit-scoring systems came under binding conformity requirements.
Five days before it arrived, it moved.
The Digital Omnibus on Artificial Intelligence — Regulation (EU) 2026/1744 — was published in the Official Journal and entered into force on 27 July 2026. The revised timetable was legally binding before the original deadline had a chance to land. The high-risk obligations for standalone Annex III systems now apply from 2 December 2027; for AI embedded in products already covered by EU product-safety law (Annex I), from 2 August 2028.
So the headline is “delayed.” The headline is wrong, or at least badly incomplete, because three significant things did become enforceable on 2 August and they are the ones that touch ordinary people most directly.
What Went Live: Article 50 Transparency
Article 50 is the AI Act’s transparency chapter, and as of 2 August it is enforceable. It contains three obligations that apply regardless of risk classification.
Chatbot disclosure. Providers must ensure that systems interacting directly with people are designed so that the person is informed they are interacting with an AI, unless it is obvious to a reasonably well-informed observer. No more customer service agents named “Sarah” who are not Sarah, without a label.
Synthetic content marking. Providers of generative AI must mark outputs — audio, image, video, text — in a machine-readable format detectable as artificially generated or manipulated. This is a provider-side obligation about watermarking and provenance metadata, and it is the technical backbone of everything else in the article.
Deepfake labelling. Deployers who generate or manipulate image, audio or video content constituting a deepfake must disclose that it is artificially generated. For text published to inform the public on matters of public interest, there is a parallel disclosure duty.
These are not risk-management paperwork. They are user-facing rules with a bright line, and they apply to consumer products that hundreds of millions of Europeans use daily.
The New Prohibition Almost Nobody Noticed
The Omnibus did not only delay. It added a prohibition to Article 5 — the list of AI practices that are banned outright, not regulated: AI-generated non-consensual intimate imagery.
This is a genuinely significant expansion, and it deserves more attention than a delay story gave it. Article 5 is the AI Act’s strictest tier. Practices there are not permitted with safeguards, conformity assessment, or documentation. They are prohibited, and they carry the top penalty band.
Set it beside the American approach and the contrast is instructive. The US TAKE IT DOWN Act works downstream: it obliges platforms to remove non-consensual intimate imagery quickly once notified. The EU has now added an upstream rule aimed at the generation side. Notice-and-takedown treats the image as the problem; a prohibition treats the generator as the problem. Both are needed, and only one of them scales.
What Else Was Already Live
Two things people frequently get wrong when reading the “delay” coverage.
The Article 5 prohibitions have been in force since 2 February 2025. Social scoring, manipulative techniques exploiting vulnerabilities, emotion recognition in workplaces and schools, untargeted scraping of facial images to build recognition databases, and real-time remote biometric identification in publicly accessible spaces for law enforcement (subject to narrow exceptions) have been banned for eighteen months. Nothing in the Omnibus touched that.
The general-purpose AI obligations have applied since 2 August 2025, and as of 2 August 2026 the Commission’s enforcement powers over GPAI providers are active, along with the full penalty regime — up to €35 million or 7% of global annual turnover for prohibited practices, with lower bands for other breaches.
So the accurate summary of the current state is: prohibitions live, GPAI live and now enforceable, transparency live, penalties live, high-risk deferred.
Why the Delay Happened, and What It Costs
The official justification was readiness. Harmonised standards for high-risk conformity assessment were not finished. Notified bodies were not in place in sufficient number. Companies would have faced a legal obligation with no compliant path to satisfying it — a real problem, not an invented one.
The unofficial pressure is not a secret either. Sustained lobbying from large technology providers and from several member state governments argued that the timeline threatened European competitiveness in AI. The Omnibus is, among other things, the outcome of that argument.
The cost is concrete and falls on identifiable people. The Annex III list is not abstract: it covers AI in employment and recruitment, education access, credit and insurance scoring, essential public services, migration and border control, and law enforcement. Those are the deployments most likely to make a life-altering decision about someone who has no idea a model was involved. For sixteen more months, the people subject to them have no AI Act right to conformity assessment, logging, human oversight, or documentation.
Deferred is not cancelled. But sixteen months is a long time in a domain where the technology re-bases annually, and there is a familiar dynamic in which a deadline moved once becomes a deadline that can be moved.
What This Means Outside Europe
The Brussels effect operates on transparency rules more efficiently than on risk-management rules. A conformity assessment is a jurisdiction-specific compliance artefact; a watermark is a property of the model output. If a provider must mark generated content in machine-readable form for EU users, the cheapest engineering decision is usually to mark it for everyone.
Which means Article 50 is quietly the most globally consequential thing that happened on 2 August. It creates a legal reason for provenance metadata to exist at scale — the infrastructure that content authenticity standards have needed and could not compel.
What To Do
-
In the EU, ask a chatbot whether it is a bot. Since 2 August, systems interacting with you must make that clear. Support “agents” with human names and no disclosure are now a reportable issue to your national market surveillance authority.
-
Check whether your generative AI tools mark their output. Provenance metadata is a feature you can now expect and ask for. It also matters for you: an unmarked model output is one you may later be unable to prove was synthetic.
-
Do not strip provenance metadata when you share. Most social platforms already do this on upload, which is a large hole in the system. Where you control it — direct file sharing, your own site — keep it.
-
If you are subject to an automated decision in employment, credit, or public services, remember your GDPR rights did not move. Article 22 rights around solely automated decisions with legal or similarly significant effects, and Articles 13–15 information rights, apply now regardless of what the AI Act defers.
-
If intimate imagery of you has been generated without consent, in the EU this is now a prohibited AI practice as well as a platform takedown matter, and in the US the TAKE IT DOWN Act’s platform obligations apply. Report to both the platform and the regulator; the two routes do different work.



