For over a year, August 2, 2026 was the cliff. The day the EU AI Act’s high-risk regime would bite. Board decks were built around it. Compliance budgets were justified by it. An entire advisory industry priced its urgency against it.
Then, on June 29, 2026, the Council of the EU gave final approval to the Digital Omnibus on AI — and the cliff moved. High-risk obligations for stand-alone Annex III systems are deferred sixteen months, to December 2, 2027. High-risk AI embedded in regulated products moves to August 2, 2028.
If you stopped reading there, you’d conclude the deadline is dead and stand down. That conclusion is wrong on the facts and expensive in practice — because the Omnibus left most of the Act’s Article 50 transparency obligations exactly where they were. Chatbot disclosure. Machine-readable marking of AI-generated content. Deepfake labeling. Disclosure rules for AI-generated text published on matters of public interest.
Those still apply eleven days from now.
This is the Reality Check: the deadline everyone prepared for moved, and the deadline almost nobody prepared for is arriving on schedule.
The cliff moved.
The deadline didn’t.
On June 29, 2026 the EU deferred the AI Act’s high-risk regime to 2027/28. But Article 50 transparency obligations still apply August 2, 2026 — chatbot disclosure, AI-content marking, deepfake labels, and disclosure rules that cut straight through the publishing industry.
- Dec 2, 2027 — high-risk obligations, stand-alone Annex III systems (employment, credit, education, essential services)
- Aug 2, 2028 — high-risk AI embedded in Annex I regulated products
- 16 months of genuine relief — for the classification and documentation work most organizations haven’t finished
- Art. 50 — chatbot disclosure to users
- Art. 50 — machine-readable marking of AI-generated content (new systems)
- Art. 50 — deepfake labeling; emotion-recognition notices
- Art. 50 — disclosure for AI-generated public-interest text
The redrawn compliance calendar
Article 50 is five obligations, not one
Different actors, different exceptions — conflating them produces both over- and under-compliance. Penalties for transparency violations: up to €15M or 3% of worldwide turnover (Art. 99).
Self-hosting is not an exemption. Article 50 duties are use-based — a chatbot on your own hardware needs the same disclosure as one on a cloud API. Local inference simplifies data-governance documentation; it does not waive transparency.
It nearly went the other way. The April 28 trilogue collapsed; for days, the original deadline stood with no harmonised standards finished. The deferral fixed the calendar — the near-miss is the verdict on the implementation.
Beratervorsicht, both directions. Pre-Omnibus urgency was inflated; post-Omnibus “you have until 2028” relief is equally imprecise. Obligations land in five waves — the first is next week.

Smart Labels QR Code Stickers with AI Photo Analysis App – Auto-Creates Item Descriptions – No Typing – Made in USA – QR Code Labels for Storage & Inventory Tracking, Organization & Moving, Pack of 48
- Color-Coded QR Code Organization: Seamless storage management with color codes
- AI Photo-Based Item Descriptions: Auto-creates descriptions from photos, no typing
- Mobile App Compatibility: Manage labels via iOS and Android devices
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
How we got here — dates that matter
The AI Act (Regulation 2024/1689) entered into force August 1, 2024, applying in stages: prohibitions and AI literacy on February 2, 2025; general-purpose AI obligations on August 2, 2025; and the big one — high-risk system requirements — scheduled for August 2, 2026.
By late 2025, implementation was visibly off track. Harmonised standards weren’t finished. National competent authorities weren’t designated. Notified-body capacity didn’t exist. So on November 19, 2025, the Commission tabled the Digital Omnibus on AI, proposing to defer the high-risk deadline.
It was not a smooth ride. The first political trilogue on April 28, 2026 collapsed without agreement — for a few days, the original deadline standing unamended was a live scenario, with compliance advisories warning clients to plan against the date in the law, not the date in the proposal. Negotiators returned and reached provisional agreement on May 7; Parliament endorsed on June 16; the Council gave final approval on June 29. Publication in the Official Journal is expected imminently — reporting through early July anticipated it within weeks — with entry into force on the third day after publication.
Worth pausing on: the EU came within one failed negotiation of enforcing a high-risk regime with no harmonised standards in place. That near-miss, not the deferral, is the honest verdict on how this implementation has gone.

Artificial Intelligence: Made Easy w/ Ruby Programming; Learn to Create your * Problem Solving * Algorithms! TODAY! w/ Machine Learning & Data … … engineering, r programming, iOS development)
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
What moved
The new compliance calendar, per the agreed Omnibus text:
| Date | What applies |
|---|---|
| August 2, 2026 | Article 50 transparency obligations (with one legacy carve-out below) |
| December 2, 2026 | Article 50(2) marking for systems already on the market at Aug 2; new Article 5 prohibitions incl. non-consensual intimate imagery (“nudifier”) and CSAM generation systems |
| August 2, 2027 | Member States must have at least one national AI regulatory sandbox; Commission deadline for Annex I delegated acts |
| December 2, 2027 | High-risk obligations for stand-alone Annex III systems (employment, creditworthiness, education, essential services…) |
| August 2, 2028 | High-risk obligations for AI embedded in Annex I regulated products |
Beyond timelines, the Omnibus made two substantive changes worth knowing. It added a new prohibition to Article 5 covering AI systems for generating non-consensual sexual imagery and child sexual abuse material — arguably the most significant new element, applying from December 2, 2026. And it introduced a narrow GDPR-side allowance for processing special-category data for bias detection — headline-grabbing, but hedged with safeguards and usable only in limited circumstances. Anyone telling you it’s a general license to mine sensitive data for AI training hasn’t read the conditions.

New AI tool detects deepfakes by analyzing light reflections in eyes: New AI tool detects deepfakes by analyzing light reflections in eyes
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
What didn’t move: Article 50, unpacked
Here is where the under-preparation lives. “Article 50” gets discussed as if it were one disclosure rule. It is at least five distinct obligations, binding different actors, with different exceptions — and conflating them produces both over- and under-compliance:
Chatbot disclosure. Providers of AI systems that interact directly with people must ensure users know they’re talking to a machine, unless it’s obvious from context. If you operate an EU-facing assistant, support bot, or conversational interface: this is yours, August 2.
Provider-side content marking. Providers of generative systems must ensure synthetic audio, image, video, and text output is marked in a machine-readable format as artificially generated. This is a technical obligation — watermarking, metadata, provenance signals — not a visible label. The one legacy concession: systems already on the market on August 2 get until December 2, 2026 to implement marking.
Emotion recognition and biometric categorization notices. Deployers must inform people exposed to these systems. Niche for most readers, real for some.
Deepfake labeling. Deployers of systems generating or manipulating image, audio, or video that appreciably resembles real persons, places, or events must disclose the artificial origin — with carve-outs for evidently artistic, satirical, or fictional work.
AI-generated text on matters of public interest. Deployers publishing AI-generated text to inform the public on matters of public interest must disclose the artificial generation — unless the content has undergone human review and a natural or legal person holds editorial responsibility for its publication.
machine-readable AI marking devices
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
The one that hits publishers
That last obligation deserves its own section, because it lands directly on anyone running editorial properties — this site included.
Read the structure carefully: the disclosure duty applies to AI-generated public-interest text, and the exemption runs through human review plus editorial responsibility. A publication where a named person reviews the content and stands behind it editorially is treated fundamentally differently from an unattended content pipeline pushing model output straight to WordPress.
That is, quietly, a regulatory line drawn through the middle of the content industry. The programmatic-SEO operations publishing thousands of unreviewed AI articles a month are on one side of it. Publications with human editorial workflow — review, judgment, a name on the masthead taking responsibility — are on the other. The Act doesn’t ban the first model; it requires it to say what it is.
The honest practitioner reading: if your editorial process already involves genuine human review and accountable editorship, August 2 mostly codifies what you do. If your “editorial process” is a cron job, you have eleven days to add either disclosure or an editor. And the machine-readable marking obligation sits upstream of all of it — the provider of the generative system carries the marking duty, which for self-hosted open-weight deployments raises a question the guidance so far handles only partially: integrate a model into your own product and you can inherit provider-grade obligations. That deserves specific legal advice, not a blog paragraph — this is analysis, not counsel.
Does self-hosting change any of this? Mostly no — and that’s worth saying plainly
The local-first argument gets misused here, so let’s not. Article 50 obligations are use-based. They attach to what your system does and who it faces — not where the weights run. A chatbot on your own hardware needs the same disclosure as one on OpenAI’s. A deepfake generated on a Mac in Bavaria needs the same label as one from a cloud API.
What self-hosting genuinely helps with lives elsewhere in the compliance stack: data-governance documentation is simpler when data never leaves your infrastructure; no processor chain to map; no third-country transfer analysis feeding your AI documentation. Real advantages, honestly bounded — local inference is a data-protection simplification, not an AI Act exemption.
Reality Check: the compliance industry’s mistimed year
Here’s the uncomfortable ledger. Through 2025 and early 2026, an enormous volume of advisory work was sold against August 2, 2026 as the high-risk cliff — gap assessments, conformity readiness programs, documentation sprints, all priced against a date that has now moved sixteen months. Beratervorsicht applies to the projections in both directions: the pre-Omnibus “comply by August or face €35M fines” urgency was inflated, and the post-Omnibus “you now have until 2028” relief being marketed today is equally imprecise — as the table above shows, obligations land in five separate waves between now and 2028, and the first wave is next week.
The steelman for the early spend: classification work — determining which of your systems fall into Annex III at all — was never wasted, and the deferral explicitly signals that implementation efforts are expected to be already underway. The Omnibus bought time to do the hard obligations properly, against standards that actually exist. It did not buy permission to stop.
And enforcement is not hypothetical: the Act’s penalty architecture (Regulation 2024/1689, Art. 99) backs transparency violations with fines up to €15M or 3% of worldwide annual turnover. Whether national authorities open with fines or with warnings in month one is genuinely unknown — most Member States’ supervisory machinery is itself behind schedule, which cuts enforcement risk in the short term and is also precisely why the deferral happened. Betting your compliance posture on continued regulatory unreadiness is a strategy; it is not a good one.
Bottom line
August 2, 2026 stopped being the high-risk cliff and became something more interesting: a filter for who actually read the law. The organizations that stand down entirely because “the AI Act got delayed” will walk into transparency obligations that never moved. The ones that panic-spend against the original framing are paying for sixteen months they now have.
The accurate posture takes one afternoon to establish: inventory which Article 50 categories touch your products — chatbot, generative marking, deepfake, public-interest text — and confirm disclosure and marking for those by August 2. Log the December 2, 2026 legacy-marking and new-prohibition dates. Then use the sixteen months of genuine relief to do the Annex III classification and documentation work properly, against finished standards.
The high-risk regime will arrive in December 2027 whether the standards are ready or not. We’ve already watched, this April, how close “or not” can get.
Sources
- Regulation (EU) 2024/1689 (AI Act) — entry into force Aug 1, 2024; staged application Art. 113; penalty architecture Art. 99
- European Commission, Digital Omnibus on AI, proposal published November 19, 2025
- DLA Piper, “The Digital AI Omnibus: Proposed deferral of high-risk AI obligations under the AI Act (update)” (June–July 2026) — trilogue of April 28, 2026 ended without agreement; Council final approval June 29, 2026; original deadlines would have applied absent adoption
- Modulos, “Is the EU AI Act Delayed? 2026 Status Check” (May 7, 2026) — post-trilogue-failure status; deadline remained legally in force pending adoption
- Gibson Dunn, “EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes” (May 2026) — provisional agreement May 6–7; Annex III → Dec 2, 2027; Annex I → Aug 2, 2028; new Art. 5 prohibition on NCII/CSAM generation systems
- Covington, Inside Privacy, “EU AI Act Update: Timeline Relief, Targeted Simplification, and New Prohibitions” (May 18, 2026) — two-tier deferral detail, 16-month Annex III deferral
- Hogan Lovells, “EU legislators agree to delay for high-risk AI rules” (May 7, 2026) — provisional agreement; expectation that implementation efforts continue
- Winston Taylor, “AI Act rules on high-risk AI delayed as AI Digital Omnibus agreed” (2026) — full revised timetable incl. Art. 50(2) legacy transition to Dec 2, 2026, sandbox deadline Aug 2, 2027, OJ publication expected by July 2026; GDPR bias-detection safeguards
- Jones Walker, “Yes, August 2 Still Matters” (July 2026) — Parliament/Council approval; Article 50 obligations unchanged for Aug 2, 2026; five-obligation breakdown; narrow December transition
- Innovaiden, “The EU AI Act’s August 2 High-Risk Deadline Just Moved. Here Is What Actually Comes Due.” (June–July 2026) — Council approval June 29, Parliament June 16; “not cancelled” framing; classification work continues
- ComplianceHub.Wiki, “EU Digital Omnibus: What the Digital Omnibus Actually Changed” (June 10, 2026) — obligations that moved vs. did not; new prohibitions applicable Dec 2, 2026
This article is analysis for practitioners, not legal advice. Scope questions — particularly provider-status for integrated open-weight deployments — warrant counsel.