AI Act delayed? What has applied since 2.8.2026


The same sentence has been going round for weeks: “The AI Act has been delayed.” It is true and still misleading. What was delayed are the obligations for high-risk systems — the part of the regulation that does not directly concern most companies anyway. What became applicable on 2 August 2026 is the part that attaches to ordinary use: the chatbot on the website, the generated product shot, the text in the newsroom. Confuse the two movements and you end up waiting for December 2027 while overlooking that your own obligation has been running since August.
- Legal basis
- Regulation (EU) 2024/1689, amended by the AI Omnibus
- Applicable since
- 2 August 2026 (Art. 50)
- Postponed to
- 2 Dec 2027 / 2 Aug 2028 (high risk)
- Supervision in Germany
- Bundesnetzagentur (KI-MIG)
Has the AI Act been delayed?
Partly. The Digital Omnibus postpones the obligations for high-risk AI: Annex III systems only bite from 2 December 2027, Annex I systems from 2 August 2028. The transparency obligations in Art. 50 have applied unchanged since 2 August 2026, the prohibitions in Art. 5 since February 2025 — and on 2 December 2026 two new prohibitions are even added.
Implementing the AI Act: what to do now
The order is not arbitrary. Every obligation in the regulation hangs on a specific system and on your role with it — start with labelling and you are labelling blind. Three stages are enough for a solid position, and the first of them can be done in an afternoon.
Stage 1 — this week: the list and the roles
- Gather the systems, and not by a round-robin email. The three most productive sources: the list of SSO sign-ins from your identity provider, the subscription and credit card statements of the last twelve months, and the browser extensions on company devices. Whatever shows up there never came into the building through IT.
- Record four fields per system: name and provider, use case, output channel, responsible person by name. The first round needs no more than that — a spreadsheet with four maintained columns beats a tool with twenty empty ones.
- Determine the role per system: deployer (you use somebody else’s system) or provider (you place it on the market under your own name or substantially modify it, Art. 25). The role decides which paragraph of Art. 50 applies at all.
- Mark the output routes: website, newsletter, social media, advertising, service chat, quotes and candidate communication. The obligation arises where generated content leaves the building — not at the model.
Stage 2 — by month end: notices that actually hold
Art. 50(5) of the AI Act requires the information to be provided at the latest at the first interaction, to be clearly distinguishable and to be accessible. That is where most implementations fail — not on a missing notice but on where it sits.
Holds
- Chatbot: “You are chatting with an AI assistant.” as the first line in the chat window, visible before the first message is typed.
- Deepfake-adjacent images and video — depictions showing real people, places or events that could be taken for genuine: a visible notice on the medium itself, in the image frame or directly in the caption.
- Text on matters of public interest: either a notice on the text — or a documented editorial review with named responsibility, in which case disclosure falls away.
- Emotion recognition or biometric categorisation: informing the people affected before use, in addition to the data protection information.
Does not hold
- “This website uses AI” in the legal notice or terms of use — that is not the first interaction.
- A “Powered by AI” badge in the footer while the chat pops up in the top right.
- A notice that only appears in the alt text or metadata and stays invisible to sighted users — or, conversely, only visually, with no alternative for screen readers.
- A watermark as a substitute for disclosure: machine-readable marking and a human-readable notice are two different obligations.
The wordings are examples, not legal advice
Whether a specific piece of content falls under paragraph 2 or paragraph 4 is a legal assessment on the facts — particularly for images that show no real people. More important than the perfect wording is that your decision and its reasoning are recorded. A documented, traceable interpretation is worth considerably more to an authority than a notice nobody can justify.
Stage 3 — ongoing: the evidence that ages
- Obtain provider information under Art. 25 and record the process: when you asked, whom, and what came back. Even an unanswered request is a documented position — provided the date is written down somewhere.
- Evidence AI literacy under Art. 4: date, topic, duration, participants, person delivering it. The obligation was softened, not abolished — and a level of training nobody can evidence remains your problem in a liability case.
- Write down interpretation decisions: why do you not consider a particular text a “text on a matter of public interest”? That reasoning is, in case of doubt, worth more than the outcome.
- Set two reminders: 2 December 2026 for the expiring labelling transition period and the new prohibitions — and a fixed cycle in which the system list is reconciled against the subscription statement. AI enters the building faster than it gets inventoried.
What the Digital Omnibus actually changed
The Digital Omnibus (AI Omnibus) is an amending regulation to the AI Act. The European Parliament approved it on 16 June 2026 and the Council adopted it on 29 June 2026; according to the available reports it was published in the Official Journal on 24 July 2026 and entered into force three days later — just before 2 August. It amends over 40 articles of the AI Act, and its most visible part is the postponement of the application dates. The requirements for standalone high-risk systems under Annex III — biometrics, recruitment, critical infrastructure, education, creditworthiness — now bite from 2 December 2027. For high-risk AI embedded in regulated products (Annex I) the date is 2 August 2028.
Looking only at the dates means missing three substantive changes. First, the concept of high risk itself has narrowed: an Annex III system only counts as high risk where its failure can trigger real risks to health, safety or fundamental rights. Second, AI literacy under Art. 4 was softened — more on that shortly. Third, two new prohibitions arrive on 2 December 2026: AI systems generating realistic intimate depictions of identifiable people without their consent (so-called nudify apps), and systems for generating or manipulating depictions of child sexual abuse. Prohibitions are sanctioned with up to €35m or 7% of worldwide annual turnover.
Politically this was contested. The European Data Protection Board and the European Data Protection Supervisor argued in a joint opinion in January 2026 for the shortest possible postponement — simplification yes, but not at the expense of fundamental rights protection. For operational practice, though, the debate is secondary. What matters is the distinction: what exactly has been postponed, and what has not?
Postponed
- Annex III high-risk systems: obligations from 2 December 2027 instead of August 2026.
- Annex I high-risk AI in regulated products: from 2 August 2028.
- And with them the steps that hang off those: conformity assessment, technical documentation, EU database registration for these systems.
- Practically relevant for a small share of companies — namely those actually operating or providing an Annex III system.
Has applied since 2 August 2026
- The transparency obligations in Art. 50: notice of AI interaction, marking of synthetic content, disclosure for deepfakes and text on matters of public interest.
- The Commission’s enforcement and sanctioning powers over providers of general-purpose AI models (GPAI).
- Unchanged: the prohibitions in Art. 5, since 2 February 2025 — supplemented by two new prohibitions from 2 December 2026.
- Still in force but softened: AI literacy under Art. 4 — the deadline was not moved, but the obligation was downgraded from “ensure” to “promote”.
- Practically relevant for almost every company using generative AI in its external communications.
What became of AI literacy under Art. 4
Since February 2025 providers and deployers had to ensure a sufficient level of AI literacy among their staff — an obligation of result. The Digital Omnibus turned that into an obligation to promote: measures have to be taken that foster this literacy, without any particular level having to be guaranteed. The deadline was not postponed; the requirement was lowered.
In practice that changes less than it sounds. Since 2 August 2026 the national market surveillance authorities have been competent, and an AI failure traceable to missing training remains a liability risk — regardless of whether the obligation says “ensure” or “promote”. Anyone documenting training anyway loses nothing through the relaxation. Anyone who never documented it gains nothing either.
AI Act deadlines 2026 to 2028: the full timetable
Since the Digital Omnibus the AI Act deadlines apply in stages: AI literacy and the prohibitions since 2 February 2025, the obligations of GPAI providers since 2 August 2025, the transparency obligations in Art. 50 since 2 August 2026. Only the high-risk obligations were postponed — to 2 December 2027 for Annex III and 2 August 2028 for Annex I.
Art. 4 requires sufficient AI literacy among everyone involved with AI systems. The prohibited practices in Art. 5 have applied since then as well.
The obligations of providers of general-purpose AI models became applicable — technical documentation, information for downstream providers, copyright policy.
Art. 50 is applicable. At the same time the Commission can exercise its enforcement and fining powers over GPAI providers.
Generative systems that were on the market before 2 August 2026 have to have retrofitted machine-readable marking by then — the deadline applies to that alone. At the same time nudify apps and systems for abuse depictions are prohibited.
The obligations for standalone high-risk systems take effect — 16 months later than originally envisaged.
For high-risk AI embedded in already regulated products, the longest transition period ends.
Art. 50 in four sentences
The transparency obligations are split across two roles, and that is where most errors arise in practice. A provider is anyone who develops an AI system and places it on the market under their own name; a deployer is anyone using it under their own authority. Most companies are deployers — they buy in a model and use it.
- Para. 1 (provider): anyone interacting with an AI system has to be able to tell — unless it is obvious to a reasonably well-informed person.
- Para. 2 (provider): generated outputs — audio, image, video, text — have to be marked in machine-readable form as artificially generated or manipulated.
- Para. 3 (deployer): where emotion recognition or biometric categorisation is used, the people affected have to be informed.
- Para. 4 (deployer): deepfakes and AI-generated text on matters of public interest have to be disclosed — for text the obligation falls away where human review or editorial control took place and somebody bears responsibility for it.
The difference between paragraph 2 and paragraph 4 is technical, not linguistic: the provider obligation is a marking in the file that a machine can read. The deployer obligation is a disclosure that a human sees. A watermark satisfies no disclosure obligation, a visible notice no marking obligation. And under paragraph 5 the information has to be provided at the latest at the first interaction, be clearly distinguishable and be accessible — a sentence in the legal notice does not suffice.
What has time until 2 December 2026
For generative AI systems already on the market before 2 August 2026 a transition period runs until 2 December 2026 — exclusively for the machine-readable marking under paragraph 2. The deployer disclosure obligations in paragraphs 3 and 4 are not covered by it; they have applied since 2 August. Content published before that date does not have to be labelled retroactively.
Guidelines and Code of Practice: what exists since July 2026
The Commission published the final guidelines on implementing the transparency obligations under Art. 50 on 20 July 2026. They are not legally binding, but the market surveillance authorities will orient themselves by them — anyone documenting their own interpretation should hold it up against them. The Code of Practice on Transparency of AI-generated Content was finalised earlier, on 10 June 2026; by the end of July around 190 companies and organisations had signed it according to the Commission. Participation is voluntary and replaces no obligation, but it does buy a degree of legal certainty vis-à-vis member state authorities.
For a mid-sized company that matters less than the insight behind it: you are not the one building the machine-readable marking. That is the provider’s job — OpenAI, Google, Mistral, Microsoft. Your task is a different one: knowing which of these systems are running in your organisation, which role you occupy with each, and whether the provider’s information is on file. That is exactly what an authority asks about, and exactly what cannot be produced retroactively.
AI Act Art. 50: which exemptions apply
The regulation does provide exemptions, and they are narrower than many hope. No notice is needed where the AI interaction is obvious to a reasonably discerning person. Exempt from marking are short sequences, source code, purely machine outputs and assistive editing that does not substantially alter the input. For text on matters of public interest, disclosure falls away after editorial review with named responsibility; for artistic or satirical works it must not impair the performance.
What is not exempt is ordinary marketing. An AI-generated product shot, a chatbot in customer service, a synthetic voice in an ad — that is the standard case, not the edge case. Anyone needing the exemptions in the actual wording and the delineation per paragraph will find both in the in-depth article.
Talk to us
Art. 50 in detail
All four transparency obligations, the exemptions in the actual wording and the fine structure are set out in the in-depth article.
Go to the Art. 50 transparency obligationsGPAI enforcement: what the Commission may do since 2 August 2026
Since 2 August 2026 the Commission can exercise its enforcement powers over providers of general-purpose AI models: request documents, evaluate models technically, demand measures, restrict a model or withdraw it from the EU market — and impose fines of up to €15m or 3% of worldwide annual turnover. The obligations of GPAI providers themselves have applied since August 2025; what is new is that they can now be enforced.
That hits the model providers directly, not mid-sized companies. Indirectly it still lands with you: anyone using someone else’s foundation model depends on that provider’s information. If an authority requests documents from your provider, your documentation is where it becomes visible whether you ever obtained the same information. Art. 25 calls that due care in the value chain — in practice it is a question of date, recipient and answer.
Who supervises the AI Act in Germany
In Germany the Bundesnetzagentur is competent. The Act on Market Surveillance and Innovation Promotion for Artificial Intelligence (KI-MIG) was promulgated in the Federal Law Gazette on 28 July 2026 and entered into force on 29 July 2026 — four days before Art. 50 became applicable. The AI Act applies directly, but Germany had to regulate competences and procedures nationally.
The Bundesnetzagentur takes on market surveillance for prohibited practices, high-risk systems and transparency obligations and is at the same time the coordination point, contact point and complaints body; for certain high-risk applications a dedicated AI market surveillance chamber is being set up there. For practice that means: since the end of July there is a named address that competitors, customers or employees can turn to. That is how compliance issues usually enter the building — not through a spot check without cause.
Fines: three tiers, with an SME cap
Breaches of Art. 50 sit at up to €15m or 3% of worldwide annual turnover; for SMEs including start-ups the lower of the two figures applies. The full three-tier structure is set out in the article on the transparency obligations.
Does 2 August or 2 December 2026 apply to me?
For deployers 2 August 2026 applies — the disclosure obligations in Art. 50(3) and (4) have run since then with no transition period. 2 December 2026 concerns exclusively providers of generative systems that were on the market before 2 August, and even there only the machine-readable marking. If you buy AI rather than provide it, the later deadline is not yours.
Do I have to label old AI content retroactively?
No. Content published before 2 August 2026 does not have to be labelled retroactively; the Commission merely recommends it. But as soon as an old piece of content is regenerated, substantially reworked or republished, it is no longer legacy content — then the obligation applies as it would to any new content.
Does the AI Act concern me if we only use ChatGPT and Copilot?
Yes, as a deployer. The machine-readable marking is owed by the provider; disclosure to people is owed by you — everywhere generated content leaves your organisation. On top of that comes due care towards the provider under Art. 25 and evidence of AI literacy under Art. 4. None of that requires a high-risk system.
Do we need an AI inventory even though high risk is postponed?
Yes. Every obligation in the regulation hangs on the individual system and on your role with it — without a list, not one of them can be assigned. That holds regardless of the high-risk deadline: Art. 50, Art. 25 and Art. 4 all presuppose that somebody can say which AI is running in the building and who is answerable for it.
What Reguly takes on — and what it does not
The AI Act module in Reguly maintains the list everything hangs on. A role check of eight questions classifies you as provider, deployer, importer, distributor or GPAI provider and identifies an Annex III high-risk case. The AI inventory records per system the provider, area of use, categories of data processed and a responsible address. The risk wizard walks through prohibited practices, high risk, transparency and context — and stores not only the class but the trigger with an article reference. That is the difference between an opinion and a verifiable classification.
The remaining building blocks hang off that: GPAI requests log the due care under Art. 25 with status, deadline and response rate; the AI literacy tracker evidences the training under Art. 4 and speaks up when the last session is more than 180 days ago; evidence lands in the compliance vault, every change in the audit log. The limits are equally clear: Reguly gives no legal advice, does not technically mark content and reports nothing to authorities. It structures the classification; the assessment stays with you or your law firm.
What was postponed is the obligation many never had. What became applicable is the one almost everybody has.
Talk to us
Which AI Act deadline hits you first?
In 30 minutes we go through which tools are in use, which role you occupy with each and which of the four transparency obligations follows — with an AI inventory at the end, not a sales pitch.
Arrange a call



