AI regulation
The EU AI Act Deadline Everyone Thinks Was Delayed Is Two Days Away
High-risk rules were deferred. Article 50 transparency was not cancelled. The first live transparency obligations begin Sunday, with fines of up to €15 million or 3% of global turnover.

Analysis
On Sunday, August 2, 2026, the European Union’s AI Act Article 50 transparency obligations come into application. National market surveillance authorities gain enforcement powers. The Commission’s AI Office moves from guidance and Code of Practice preparation into live implementation of the transparency regime. Penalties of up to €15 million or 3% of global turnover become available.
Many companies operating in or selling into the European market appear to believe this deadline was cancelled. It was not. What actually happened over the past six weeks has been misread across most of the AI compliance discussion, and the misreading is now a business exposure for the enterprises that acted on it.
What was actually deferred, and what was not.
On June 29, 2026, the Council of the European Union gave final approval to the Digital Omnibus on AI. On July 8, the Digital Omnibus was signed. The reforms deferred the compliance deadlines for high-risk AI systems. Systems classified under Annex III, which cover stand-alone high-risk applications like biometric identification and critical infrastructure, were pushed from August 2, 2026, to December 2, 2027. Systems classified under Annex I, which cover product-embedded AI in regulated sectors like medical devices and automotive, were pushed to August 2, 2028.
The headlines that followed described this as the EU AI Act being “delayed” or “watered down.” Many enterprises reading those headlines paused their compliance work. Some stood down entirely.
The high-risk system compliance obligations were deferred. Article 50 transparency obligations were not.
Article 50 covers a specific and different set of requirements: AI systems that interact directly with humans (like chatbots) must disclose that they are AI. AI-generated synthetic content (like generated images, audio, or video) must be machine-readable as AI-generated. Deepfakes and AI-generated text on matters of public interest must be labeled. Emotion recognition and biometric categorization systems must inform the individuals subject to them.
None of that was cancelled. All of it comes into application Sunday. One narrow transition applies: providers of AI systems already placed on the market or put into service before August 2, 2026 that generate synthetic audio, image, video, or text have until December 2, 2026 to comply with the machine-readable marking obligation under Article 50(2). Every other Article 50 obligation begins Sunday.
The Code of Practice question.
On July 8, the European Commission concluded that the Code of Practice on Transparency of AI-Generated Content adequately covers key Article 50 obligations for marking, labelling, and disclosure of AI-generated content. Signatories may rely on the Code’s measures to demonstrate compliance and may benefit from a more predictable, EU-wide implementation framework.
But that is not the same thing as immunity.
The Code does not replace the AI Act. It does not replace the Commission’s Article 50 guidelines. And adherence to the Code does not constitute conclusive evidence of compliance. It creates a recognized compliance pathway, not a shield from examination.
That distinction matters. Companies that treat Code signature as the end of compliance are likely to be exposed when authorities look for actual implementation: AI interaction disclosures, machine-readable marking, deepfake labels, public-interest text disclosures, accessibility, timing, and evidence that the notices were clear and distinguishable at first interaction or exposure.
Who this affects and how.
The Article 50 obligations apply to any provider or deployer of an AI system that reaches EU users, regardless of where the company is based. A US company selling a chatbot product used by European customers is subject to Article 50. A US company deploying AI-generated content that reaches European audiences is subject to Article 50. The territorial scope is deployment, not incorporation.
The enforcement mechanism operates through national market surveillance authorities in each EU member state. Fines are set at up to €15 million or up to 3% of global annual turnover, whichever is higher. For a company with €500 million in global revenue, the headline fine tier reaches €15 million. For companies above that revenue level, the potential maximum scales with global turnover.
Enforcement is not going to be immediate for every non-compliant deployment. National authorities will prioritize investigations, and the first cases will likely target visible violations in high-attention sectors. But the enforcement infrastructure activates Sunday, and the evidentiary record of non-compliance begins accumulating at the same moment.
The distinction that will matter.
The pattern that is going to shape enforcement in the next twelve months is the pattern that has shaped every regulatory enforcement cycle before it: administrative pathways are stress-tested first.
Companies that signed the Code of Practice and treated it as sufficient will discover, when their compliance is examined, that a recognized pathway is not the same as documented, reviewable evidence of implementation. Companies that additionally maintained independent verification of their Article 50 practices, including documentation of AI system labeling, content marking implementation, and user disclosure mechanisms, will have evidence that survives the examination.
The Code creates a market position. Independent verification creates evidentiary weight. Enforcement will distinguish between them.
What this means for the next enforcement cycle.
The Article 50 deadline landing this Sunday is the first live transparency test of what EU AI Act enforcement will look like in practice. It is not the biggest test. The high-risk system deadlines in December 2027 and August 2028 will produce much larger enforcement stakes, because the systems covered are more consequential and the penalties for non-compliance under those provisions will be more severe.
But Sunday is when the enforcement muscle first activates. The AI Office begins operating. National authorities gain formal powers. The first investigations can begin. Informal warnings may follow. Formal enforcement actions will come after that.
Companies operating in the European market that spent the last six weeks assuming the deadline was cancelled will discover in the next six weeks that it was not. Companies that took the Digital Omnibus as an opportunity to strengthen their compliance infrastructure will have documented, defensible evidence when the first examinations begin. Companies that treated it as an opportunity to stand down will not.
A recognized compliance pathway is not the same as evidence of implementation. The market is about to learn the difference.