By Thorsten Meyer
For two years, 2 August 2026 sat in every compliance calendar in Europe as the day the AI Act would finally bite — the moment the high-risk regime became enforceable and every organisation running consequential AI had to show its work.
That is not what happened. The deadline arrived. It arrived carrying far less than planned — and, for a publisher operating across hundreds of properties, carrying the one thing that actually applies to nearly everyone.
The gap between those two facts is where a lot of people are about to make an expensive mistake. Some read the headlines about “AI Act deadlines being delayed,” concluded the pressure was off, and quietly stood their programmes down. They deferred the wrong obligation.
The AI Act’s 2 August deadline didn’t disappear — it split in two. The heavy high-risk regime slid past 2027. The transparency duties that apply to almost anyone touching generative AI landed exactly on schedule, with national enforcement behind them.
▲ Journalism, not legal advice · verify with counselThe Digital Omnibus cleaved one date into two speeds. If your mental model of “the deadline” was the high-risk regime, the pressure genuinely eased — but that was never the obligation most organisations actually had.
Not a high-risk provision, not tied to Annex III. It applies to specific categories of AI regardless of risk — in practice, to every business using generative AI to produce content or run a system that talks to users.
Three true stories collided and the headlines merged them into one false one.
Start with an inventory of every system that talks to a user or generates content on your behalf. Three duties are live today — not December.
you deferred the wrong obligation.
What everyone thought was coming
The original Regulation (EU) 2024/1689 entered into force on 1 August 2024 with a staggered timetable, and 2 August 2026 was meant to be the load-bearing date: the day the high-risk obligations under Annex III — the eight sensitive use-case categories including employment, education, essential services, biometrics, and law enforcement — became fully enforceable, with all the machinery that implies. Risk management systems, technical documentation, conformity assessment, human oversight, post-market monitoring, CE marking, EU database registration.
That is the regime people spent 2025 preparing for. And that is the regime that just moved.

AI for Nurses: The Practical Guide to HIPAA-Compliant AI Tools, Documentation Workflows, and Ethical Integration for Registered Nurses and Nurse Practitioners (AI for Professionals)
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
What actually moved, and how far
A late amendment package known as the Digital Omnibus on AI cleaved the date in two. The Commission proposed it on 19 November 2025; after a trilogue collapsed in late April, negotiators reached a provisional deal in early May; the European Parliament granted final approval on 16 June 2026 by a vote of 423 to 57, with 174 abstentions; the Council confirmed on 29 June; the text was signed on 8 July and awaits publication in the Official Journal.
The result splits the calendar into two speeds. The heavy high-risk regime slid more than a year:
- Stand-alone Annex III systems — recruitment tools, education scoring, essential-services eligibility — now have until 2 December 2027.
- AI embedded in regulated products under Annex I — medical devices, machinery, toys — has until 2 August 2028.
- Crucially, these application dates are no longer tied to the readiness of harmonised standards. That coupling was part of why the original timeline stalled: regulators were demanding conformity against benchmarks that did not yet exist.
If your entire mental model of "the AI Act deadline" was the high-risk regime, then yes — the pressure is genuinely off, for another sixteen to twenty-four months. But that was never the obligation most organisations actually had.

The Digital Transformation of Sustainability Reporting (Routledge Studies in Accounting)
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
What did not move — and applies to almost everyone
Here is the part the "delayed" headlines buried. Article 50 — the transparency obligations — was left out of the deferral entirely. It applies from 2 August 2026, exactly as written, and it sits in a class of its own: it is not a high-risk provision, it is not tied to Annex III, and it applies to specific categories of AI regardless of risk classification. In practice, it is relevant to every business that uses generative AI to produce content or runs a system that talks to users.
Article 50 covers four situations, split between providers who build systems and deployers who use them:
- AI-interaction disclosure. If a person is interacting with an AI system — a chatbot, a voice assistant — they must be told, unless it is obvious to a reasonably informed person.
- Synthetic content marking. Providers of generative systems must mark AI-generated or AI-manipulated output in a machine-readable way, so it can be detected as artificial downstream.
- Deepfake labelling. Deployers who publish AI-generated or manipulated image, audio, or video that resembles real people, objects, or events must disclose that it is artificial.
- AI-generated public-interest text. Deployers publishing AI-generated text to inform the public on matters of public interest must disclose it, subject to carve-outs.
And the enforcement layer arrived on the same day. Enforcement of Article 50 sits with national market surveillance authorities, not centrally with the EU AI Office, and that enforcement capacity took effect on 2 August 2026 — it was not postponed by the Omnibus. The Commission's power to investigate and fine GPAI providers also switched on. A rule that already existed on paper suddenly acquired teeth.

The AI Legal Handbook: A Guide to the Laws of Artificial Intelligence and the Future of Regulation
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
The one genuine piece of breathing room
There is exactly one Article 50 obligation that got extra time, and it is narrow. The machine-readable marking requirement under Article 50(2) — the watermarking-and-metadata duty on the provider side — carries a grace period to 2 December 2026, and only for generative systems already on the market before 2 August 2026. That is a four-month accommodation for legacy systems, shorter than the six months originally floated.
The limits matter. It does not extend to systems placed on the market on or after 2 August 2026 — those must comply now. It does not touch the deployer-facing duties: deepfake labelling and public-interest-text disclosure are live today. And content generated before 2 August 2026 does not need to be labelled retroactively. Treat 50(2) as a limited transitional accommodation, not a general postponement of Article 50.
There is also a new prohibition worth noting, added to Article 5 by the same package: AI-generated non-consensual intimate imagery is now banned outright, with the prohibited-practices regime applying on its original timeline.

AI Prompts for Safety Professionals: Save Hours on Risk Assessments, Incident Reports, Toolbox Talks, and Safety Documentation Using Artificial Intelligence
As an affiliate, we earn on qualifying purchases.
As an affiliate, we earn on qualifying purchases.
Why the coverage is a mess, stated plainly
Three true stories collided and the headlines merged them into one false one.
The first true story: the original Act made 2 August 2026 the marquee date for high-risk enforcement. The second: GPAI obligations had technically applied since August 2025, but without enforcement power — so the Commission's ability to actually fine, arriving in August 2026, reads like a new deadline even though the underlying rule was old. The third: the Omnibus itself was in political limbo for months, so anything written before the June votes had to hedge, and that hedging aged into apparent uncertainty.
Merge those three and you get the widely-circulated but wrong summary: "the big AI Act deadline was delayed." The accurate version is narrower and more useful: the deadline got smaller and sharper. The broad, heavy, expensive regime moved. The single most universally applicable duty in the entire Act did not.
For anyone relying on guidance published before July, the blunt consequence is that a large share of the "AI Act 2026" material online describes a legal position that no longer exists. This is exactly the failure mode the frontier-context piece warned about in a different register — stale rules confidently asserted. Here the stale rules carry fines of up to €15 million or 3% of global annual turnover.
What it means if you publish with AI in the EU
This is where it stops being abstract, because for a German-based operation running AI-assisted content across a large property portfolio, Article 50 is not a corner case — it is the operating condition.
The practical starting point is an inventory of every AI system that either talks to a user or generates content on the organisation's behalf: chatbots and assistants, image and video generators, and — the one publishers most often miss — generative AI used for externally published text. For each, the question is which of the four Article 50 situations it triggers, and whether you are acting as provider, deployer, or both.
Three obligations are live now, not in December. If a site runs a chatbot, interaction disclosure applies. If it publishes AI-generated or AI-manipulated imagery resembling real people or events, deepfake labelling applies. If it publishes AI-generated text on matters of public interest, that disclosure applies — and "AI Dispatch"-style coverage of real-world events sits closer to that line than a casual reading suggests, which is a determination worth making deliberately rather than by default. The Commission published a voluntary Code of Practice on AI-generated content in June 2026; following it is a way to demonstrate compliance on the marking duties, though it remains voluntary and the technical standards are still being finalised.
None of this is legal advice, and the provider-versus-deployer distinction genuinely changes what you owe — a publisher using a third-party model is usually a deployer, which shifts the marking burden upstream but leaves the labelling and disclosure burden squarely local. That determination is worth an actual lawyer, not a blog post, mine included.
The bear case on all of this is real and worth stating: enforcement by national authorities will be uneven at the start, the marking standards are not fully settled, and a first-mover who over-labels may simply train their audience to distrust content that a competitor publishes unmarked. The counter-argument is the one that usually wins in a regulated market — the cost of building disclosure in now is small, the cost of retrofitting it under an enforcement action is not, and "everyone else was unclear too" has never been a defence that survived contact with a market surveillance authority.
The dispatch in one line
The AI Act's 2 August deadline did not disappear — it got smaller and sharper. The heavy high-risk regime moved to late 2027 and 2028. The transparency duties that apply to almost everyone who touches generative AI landed exactly on schedule, with national enforcement behind them and one narrow four-month grace period for legacy watermarking. If you stood your programme down because you read "delayed," you deferred the wrong obligation.
Sources: Regulation (EU) 2024/1689; Digital Omnibus on AI (Parliament approval 16 June 2026, 423–57; Council 29 June; signed 8 July 2026, awaiting Official Journal publication); European Commission "Shaping Europe's Digital Future" FAQ on Article 50 and the June 2026 Code of Practice on AI-generated content; Cloud Security Alliance, Gibson Dunn, Winston Taylor, Dastra, and ComplianceHub analyses of the Omnibus split, checked 30 July–3 August 2026. Timelines and penalty figures are point-in-time and subject to Official Journal publication. This is journalism, not legal advice; the provider/deployer determination for any specific system requires qualified counsel. Point-in-time as of 3 August 2026.