The AI Act Blinks: What the Omnibus Delay Does and Doesn't Change
It is Friday 24 July 2026, and somewhere in Europe a compliance team is standing in front of a wall. On the wall is a countdown clock. It says 9 days, 14 hours. Next to it are eighteen months of work: the Annex III list, printed and laminated; a risk register with more tabs than a browser at 2 am; and a project plan called "Operation August", which somebody named in a meeting that ran long.
Then the Official Journal of the European Union publishes a document called Regulation (EU) 2026/1744. By Monday it is law.
Somebody reads it aloud. The clock is now wrong for the hiring tool. The clock is still right for the website chatbot. For the image generator, the answer depends on whether it was on the market before 2 August, which is a Sunday, which is a bold day to switch on a law. Someone suggests a second clock. Someone else points out that a new ban starts in December, so that needs a third. By lunchtime the wall has four clocks, a whiteboard of arrows, and a laminated sign that says "PLEASE CHECK THE BOARD FOR YOUR SERVICE". The team has accidentally built a railway station.
Sit down for a minute and put the kettle on. The work was not wasted, and the wall is not as mad as it looks. It is the correct shape for what happened.
On 16 June, the European Parliament voted 423 to 57, with 174 abstentions, to amend the EU's AI Act. The Council followed on 29 June. The result, the Digital Omnibus on AI, was published on 24 July and entered into force on 27 July: six days before the AI Act's main start date. It moves the rules for high-risk AI to December 2027 and August 2028. It does not move the rules that most businesses will meet first: telling people when they are talking to a machine, and marking or labelling content that a machine made. Those start on 2 August 2026. Breaking them can cost up to €15 million or 3% of worldwide annual turnover, whichever is higher.
So the headline "EU delays AI Act" is true in the way that "the trains are late" is true. Some of them are. The one you need tomorrow morning is on time.
Here is the plan. First, how an EU law actually switches on, because the Omnibus did not repeal anything; it edited a timetable. Then what moved, what did not, and what is new. Then we take Article 50, the transparency article, down to its bolts, including how a watermark can hide inside ordinary text. Then a (made-up) e-commerce manager in Tasmania works through her own list, and you get a checklist for the week before the deadline.
Let's get into it.
Part 1: How an EU Law Switches On
You already know the difference between signing something and starting it. You sign a lease in June and move in on 1 August. The lease is real from the day you sign it. The rent starts later. If you set fire to the kitchen in July, that is a different conversation, and not one the lease prepared you for.
EU law has the same two moments, with more formal names. A regulation enters into force on a set day after it appears in the Official Journal. From that day it exists and binds everyone. But it can apply, meaning its duties actually bite, from later dates. Those can be different for different parts of the law.
The AI Act is the extreme case. It entered into force on 1 August 2024, and its Article 113 then set a staggered list of application dates:
- the general rules and the bans on certain AI practices (Chapters I and II) from 2 February 2025;
- the rules for general-purpose AI models, governance and most penalties from 2 August 2025;
- most other things, including the high-risk rules for the Annex III list and the Article 50 transparency duties, from 2 August 2026;
- high-risk AI that is part of a regulated product (the Annex I route) from 2 August 2027.
That list is the departures board. Yes, this article is now a railway station, and it will stay one until the end.
The Omnibus is an amending regulation. It does not replace the AI Act. It changes specific sentences in it, the way a timetable change notice changes specific rows on the board. Its own Article 4 says it enters into force "on the third day following that of its publication". Friday 24 July plus three days is Monday 27 July. Recital 46 explains the rush in unusually plain words: it enters into force "as a matter of urgency" because the AI Act's general application was "imminent". If the change had landed after 2 August, the high-risk rules would already have applied, and nobody wanted to find out what un-applying a law looks like.
The mechanism is almost comically small. Point 40 of Article 1 rewrites points (a) and (c) of the third paragraph of Article 113 and adds a point (d). Those few lines are the delay. Everything else in the Omnibus is detail around them.

One more term before we look at the board. The AI Act gives most duties to one of two roles. A provider develops an AI system, or has one developed, and puts it on the market or into service under its own name. A deployer uses an AI system "under its authority" in a professional setting. Your company can be both. If you build a chatbot on top of someone else's model and put your name on it, you are a provider of that chatbot. If you switch on a vendor's chatbot on your site, you are probably a deployer. Hold on to this; it decides which Article 50 duty is yours.
Part 2: What Moved

The high-risk rules: 16 months and 12 months late
The big change is to Chapter III, Sections 1 to 3 of the AI Act: the classification rules, the requirements for high-risk systems (risk management, data quality, logging, human oversight, accuracy) and the duties of the people who make and use them. The new Article 113 says they apply:
- from 2 December 2027 for high-risk systems in the Annex III list;
- from 2 August 2028 for high-risk AI in products covered by the EU product laws in Annex I.
Annex III is the list most people mean when they say "high-risk AI". It names eight areas: biometrics; critical infrastructure; education; employment and worker management; access to essential services, including credit scoring and the pricing of life and health insurance; law enforcement; migration and border control; and the administration of justice and elections. A CV-screening tool, a credit-scoring model or a proctoring tool for exams sits here. That train was due on 2 August 2026. It now leaves 16 months later.
Annex I covers AI that is a safety component of a regulated product, such as a medical device, a toy or a lift. That train was already scheduled a year later, for 2 August 2027. It now leaves on 2 August 2028.
The deployer duties in Article 26 moved with the rest of Section 3. They include using the system as its instructions say, giving human oversight to people with the right training and authority, keeping logs for at least six months, telling workers before a high-risk system is used on them at work, and telling people when a high-risk system helps make decisions about them. None of those is a duty on 2 August 2026 any more.
Why: the standards were not on the platform
The Omnibus gives its reason in recital 40: "the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities". That sounds like throat-clearing. It is the mechanism of the whole high-risk chapter.
The high-risk requirements are written as outcomes: a system must have an "appropriate level of accuracy, robustness and cybersecurity", data governance "appropriate for the intended purpose", and so on. The AI Act expects technical standards to say what "appropriate" means in practice. Under Article 40(1), a system that meets a harmonised standard is presumed to meet the matching requirements, but only once that standard's reference is published in the Official Journal. Without the standard, every provider has to argue its own case from first principles, to authorities that did not all exist yet.
As of July 2026, the standards body was still at work. On 9 July, the joint CEN-CENELEC committee writing them, JTC 21, said that July would bring the "expected publication" of EN 18286, a quality management standard. The same post listed the drafts for risk management (prEN 18228) and cybersecurity (prEN 18282) as still open for public comment until 30 July. Publication by the standards body is also not the same as citation in the Official Journal, which is the step that gives the legal presumption. The platform, in other words, was still being poured when the train was due.1
The proposal that did not survive
The Commission's original idea was cleverer, and you will still see it quoted. In November 2025 it proposed linking the high-risk start to "the availability of support tools, including the necessary standards". The proposal's text said the rules would apply 6 months (Annex III) or 12 months (Annex I) after the Commission adopted a decision confirming that support measures were ready, with 2 December 2027 and 2 August 2028 as the latest dates.
Parliament and the Council kept the latest dates and threw away the trigger. I think that was the right call for everyone who has to plan. A date that depends on a future Commission decision is a train that leaves "when the driver feels ready". You cannot book a connection on that.
The grace period for systems already running
A second change is less visible and matters a lot to anybody who already sells a high-risk system. The AI Act always had a grace period in Article 111(2): high-risk systems placed on the market before the rules applied only have to comply if their design later changes significantly. The Omnibus ties that grace period to the new dates. Recital 39 then settles an argument about what "placed on the market" means. If one unit of a type and model was lawfully on the market before the date, other units of the same type and model can keep going on the market "without any additional obligations", as long as the design stays the same. Public-sector systems get no such rest: providers and deployers of high-risk systems for public authorities must comply by 2 August 2030.
My read, and it is my read, not the law's: this makes December 2027 a launch deadline as much as a compliance deadline. A system that is on the market before it, and is not changed significantly, sits outside most of the chapter.
The smaller delays
- Marking content from generative systems that are already on the market. Article 50(2) makes providers of generative AI mark its outputs so machines can detect them. A new Article 111(4) gives providers whose systems were on the market before 2 August 2026 until 2 December 2026 to comply. Recital 38 calls this "a transitional period of four months". The Commission had proposed 2 February 2027. More on this in Part 5, because it is the most misunderstood line in the Omnibus.
- Regulatory sandboxes. Each Member State had to have at least one AI regulatory sandbox running by 2 August 2026. That is now 2 August 2027.
- Machinery. The Omnibus removes the old Machinery Directive from Section A of Annex I and puts the Machinery Regulation in Section B. For AI in machinery, that means the AI Act's own high-risk requirements do not apply directly; they are to be built into the machinery rules instead.
Civil society groups did not accept the package quietly. Before the votes, EDRi, Access Now, ECNL and Amnesty International wrote that "Delaying safeguards is not a neutral administrative step", and objected that providers "will have to upload less information to the public database".
Part 3: What Did Not Move
This is the part the headlines skip.
The bans have applied since February 2025
Chapter II, the list of prohibited AI practices in Article 5, has applied since 2 February 2025. The Omnibus does not delay it. That matters most for the people who read "high-risk AI delayed to 2027" and relax about their HR tools. A CV screener is high-risk (delayed). A tool that infers the emotions of candidates in a video interview is in a different category: Article 5(1)(f) bans AI that infers emotions "in the areas of workplace and education institutions", except for medical or safety reasons. That ban did not move. It has been live for 18 months.
General-purpose AI models: already running, and fines from August
The rules for providers of general-purpose AI models, the big foundation models, have applied since 2 August 2025. Models already on the market before that date have until 2 August 2027. The Commission's own power to fine those providers, in Article 101, was held back until the general date. As Mayer Brown put it on 30 July, "From 2 August 2026, the Commission's enforcement powers are available, including the power to impose fines." The Omnibus does not change that date.
AI literacy: softer, but still yours
Article 4, the AI literacy duty, sits in Chapter I, so it has also applied since February 2025. The original text told providers and deployers to "take measures to ensure, to their best extent, a sufficient level of AI literacy" among their staff. The Commission proposed to move the duty off companies entirely and onto the Commission and Member States, who would only "encourage" it.
The final text split the difference. Providers and deployers must now "take measures to support the development of AI literacy" of their staff and others who operate AI for them, and the law adds that this "does not require providers or deployers to guarantee any specific level of AI literacy of any individual". Because Article 4 already applies, the new wording applies from 27 July 2026, not from August. You still owe the training. You no longer owe a guarantee that it worked, which, speaking as someone who has sat through mandatory training, is only fair.2
Article 50: on time
Article 50 is the transparency article. Its duties apply from the general date, 2 August 2026, and the Omnibus did not change that date. It changed paragraph 7, about how codes of practice are approved, and it added the narrow grace period in Article 111(4). That is all. The Parliament's co-rapporteur Arba Kokalari said during the debate, "we are pressing the pause button on the AI Act". Not every part of it was paused, though.
Part 4: What Is New
The Omnibus also added things, which is unusual for a simplification law.
- A new ban. New points (ba) and (bb) in Article 5 ban AI systems that generate realistic intimate images of an identifiable person without their explicit consent, and systems that generate child sexual abuse material. For providers, the ban covers systems built for that purpose, and systems where that output is "a reasonably foreseeable and reproducible outcome" with no "reasonable and adequate" safeguards. For deployers, it covers using a system for that purpose. It applies from 2 December 2026. This is the "nudifier" ban that co-rapporteur Michael McNamara said Parliament "fought for".
- A legal basis for bias testing. A new Article 4a lets providers of high-risk systems process special categories of personal data, such as ethnicity or health data, where strictly necessary to detect and correct bias, under a long list of safeguards. It also lets providers and deployers of other AI systems do the same. If you have read my piece on bias in AI, you know why this matters: you cannot measure bias against a group if you are not allowed to know who is in the group.
- More power for the AI Office. The Commission's AI Office gets exclusive competence over AI systems built on general-purpose models from the same provider, and new powers over AI in very large online platforms and search engines.
- Help for mid-sized companies. Several simplifications that were only for SMEs now also cover "small mid-cap enterprises" (SMCs), including simplified technical documentation and a rule that fines are capped at the lower of the percentage or the fixed amount.
Part 5: Article 50, Taken Apart

On 20 July, the Commission approved 51 pages of guidelines on Article 50, thirteen days before the duties start. The guidelines are non-binding; only the Court of Justice can give the final word. They are still the best map of how regulators will read the article, so this section leans on them heavily.
Article 50 holds four duties:
| Paragraph | Who | What |
|---|---|---|
| 50(1) | Provider | AI that interacts directly with people must be designed so they are told it is AI, unless that is obvious. |
| 50(2) | Provider | Generative AI must mark its outputs in a machine-readable format and make them detectable as AI-made. |
| 50(3) | Deployer | Tell people when you use emotion recognition or biometric categorisation on them. |
| 50(4) | Deployer | Label deep fakes, and label AI text published to inform the public on matters of public interest. |
Paragraph 5 adds the delivery rule: the information must be "clear and distinguishable", given at the latest at the first interaction or exposure, and must meet accessibility requirements. The guidelines say this adds no new accessibility rules of its own. But where an accessibility law such as the European Accessibility Act already covers your product or service, it covers your AI disclosure too. A label that a screen reader cannot read is not a label.


50(1): the chatbot must say what it is
The duty is on the provider, and it is a design duty: the system must be built so that people are told. The guidelines give a direct example of who counts as a provider: a company that "has developed an interactive AI system (e.g. chatbot) in-house and puts it into service in the Union for its own use and under its name or trademark". If your team wired a model's API into a support widget and gave it a name and a friendly avatar, that is probably you.
The exception is "obvious" interaction, judged from the point of view of a person who is "reasonably well-informed, observant and circumspect". The guidelines set the bar high. They say the exception should be limited to cases where "there is almost no doubt left" for an average person in the audience. Their "obvious" examples are narrow: code assistants used only by professional developers, internal assistants for trained staff, and AI characters in a single-player game. Their "not obvious" examples include "AI chatbots embedded in online platforms or assistance support tools (helpdesks)". The helpdesk chatbot, in other words, is the textbook case.
If that chatbot also has a personality problem, the transparency rule will not save you; that is a job for red teaming. But it will at least have to admit what it is before it tells your customer to go and live in a yurt.
AI agents get a paragraph of their own. The guidelines say an agent that books, negotiates, buys or writes emails for someone must be designed to disclose "both their artificial nature and the person on whose behalf they are acting". Where the provider cannot know in advance whether the agent will meet a human, it should disclose itself wherever that is "reasonably likely". An AI agent that phones a restaurant to book a table has to say so, and say for whom. I look forward to the first restaurant that asks the agent for a credit card and a reason.
50(2): the mark, and the detector
This is the paragraph with the most engineering in it, and the one the Omnibus touched. So we will take it down in steps.
Step 1: something you already use. Hold a banknote up to the light and you see a watermark. It is not there for you to read on an ordinary day. It is there so that anyone who wants to check can check. The artist's signature in the corner of a painting does a similar job for provenance: you do not need it to enjoy the picture, but it tells a buyer where the thing came from.
Step 2: name it. Article 50(2) wants the same pair for AI output. The outputs must be "marked in a machine-readable format and detectable as artificially generated or manipulated". The guidelines define machine-readable as marks "structured in a way that allows software applications to easily identify, recognise and extract them without human intervention". They then insist on both halves. A mark with no way for others to detect it "will not suffice".
Step 3: how a machine does it. The recital behind Article 50 lists the techniques: watermarks, metadata, cryptographic methods for proving provenance, logging, fingerprints, or a mix. They work at different depths:
- Metadata is a label attached to the file, like a tag on a suitcase. It is cheap and precise, and it falls off when someone takes a screenshot or a platform strips the file's metadata on upload.
- A watermark is woven into the content itself: into the pixels of an image, the waveform of audio or the choice of words in text. It survives more handling, and it is harder to build.
- A fingerprint or a log is kept by the provider: a record of what it generated, which a detector can check against.
The guidelines ask for technical solutions that are "effective, interoperable, robust and reliable" as far as technically feasible, and they want detection built on "publicly-available industry standard detection solutions" where they exist. A detector that only works on one vendor's content is a start, not the goal.
Step 4: the real mechanism, for text. Images have plenty of room for a hidden signal. Text looks like it has none: a word is a word. The trick that researchers found is to hide the signal in which words get picked. In a 2023 paper, John Kirchenbauer and colleagues showed how it works.
A language model writes one token (a word or part of a word) at a time, picking from a probability over its whole vocabulary. Before each pick, the watermarking system takes the previous token, runs it through a hash function, and uses the result to seed a random number generator. That generator splits the vocabulary into two halves: an allowed list and a banned list. The model then picks the next token only from the allowed list (or, in the softer version, is nudged towards it).
Now look at it from the detector's side. A detector that knows the hash function can rebuild the two lists for every position in a piece of text, without access to the model. A human writer knows nothing about the lists, so about half of their words land on the banned side by chance. Watermarked text almost never does. The paper turns that into a simple statistical test. With its threshold, 16 tokens of fully watermarked text are enough to detect the mark, with a false-positive rate of about 3 in 100,000. And it is stubborn: in their example, an attacker who changes 200 tokens in a 1,000-token text still leaves a signal that the test detects with a p-value of about 10⁻¹⁰.
That is the bread with a wax seal on the bottom, from the painting above. You cannot see it in a sandwich. A baker with a magnifying glass can find it every time.3
The guidelines also say what does not need a mark: short outputs such as "single words, image captions, alt-text" and UI labels, source code, and machine-to-machine output that no human sees. The last one matters for agents: the guidelines say an agent's "web request or browser action" is not synthetic content under 50(2), but text, audio, images or video it makes for a person to perceive are in scope. An email it writes to a person is text of that kind.
The Omnibus grace, precisely. The new Article 111(4) says providers of generative AI systems "placed on the market before 2 August 2026" must comply with Article 50(2) "by 2 December 2026". Three limits follow, and the guidelines spell out the third:
- It covers only 50(2), the marking duty.
- It covers only systems already on the market before 2 August 2026. A new system launched in September must mark from day one.
- A system that both chats and generates keeps its 50(1) duty on 2 August. In the guidelines' words, such systems "may benefit from this transitional period only with regard to the marking obligation", while the disclosure duty for direct interaction "must be ensured as of 2 August 2026".
50(3): emotion recognition and biometric categorisation
If you use a system that infers emotions or sorts people into categories from biometric data, and the use is lawful, you must tell the people exposed to it. Remember that inferring emotions at work or in education is banned outright under Article 5. So 50(3) applies to the lawful uses that are left, such as some safety uses or uses outside those two settings.
50(4): deep fakes and public-interest text
This duty is on the deployer, which makes it the one most likely to reach marketing teams. It has two halves.
Deep fakes. The AI Act defines a deep fake as AI-generated or manipulated image, audio or video that "resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful". The guidelines' examples are very useful for anyone who makes product images. An AI-generated product image "that can affect the audience's perception and mislead as to the actual product appearance" is a deep fake. A real car shown against an AI-generated background is not, "as long as the ad is not likely to mislead" about the car. And "AI-generated video of mice arguing in human language over the best type of cheese" is not a deep fake either, which I am glad somebody in Brussels had to write down.
Who counts as the deployer also has a clear answer. If an advertising agency uses AI to make your ad, the agency is the deployer. A company that "merely commissions" the agency, without deciding whether and how it uses AI, is not.
Public-interest text. AI-generated or AI-edited text "published with the purpose of informing the public on matters of public interest" must be labelled. The guidelines give a broad reading of "public interest": politics, public services, justice, fundamental rights, public health, consumer safety and "any economic, financial, political, scientific, or cultural development" worth public debate. Their examples inside the scope include an AI summary of a newspaper story about a town council, and AI-edited corporate reports with investor information. Outside the scope: fantasy novels, a chatbot summary that only the person who asked sees, and "AI-manipulated text that is part of a company's advertisement or product descriptions", unless it makes claims about health, consumer safety or sustainability.
There is an exception, and it has teeth. The label is not needed if the text went through human review or editorial control and a person holds editorial responsibility for it. The guidelines define review as a "deliberate examination of the substance", with fact-checking as a minimum. They rule out "spell-checking or grammatical correction", "the mere existence of an editorial policy" and "cursory editorial approval". If AI edits the text after sign-off, the exception is void. And the guidelines expect the person or role with editorial responsibility to be named somewhere easy to find, such as the site's legal pages.4
What about content made before August? The guidelines settle this. Deep fakes and other outputs "generated or manipulated before 2 August 2026 do not need to be marked or labelled retroactively". For public-interest text, the trigger is publication: text generated before 2 August but published on or after it "need[s] to be labelled". So the blog post you drafted with AI in July and schedule for 5 August needs either a label or a real editor.
The Code of Practice
Alongside the guidelines sits a voluntary Code of Practice on marking and labelling, finalised on 10 June 2026 after drafts in December and March. It covers 50(2), 50(4) and 50(5), and the Commission and the AI Board have confirmed it as an adequate way to show compliance. By the end of July, about 190 companies and organisations had signed it. Signing is optional. The Commission is clear that the Article 50 requirements themselves "are legal obligations".
Part 6: Beatrix's Week at the Honey Company

Meet Beatrix. She is made up. She runs e-commerce for a small Tasmanian company that sells leatherwood honey to customers in Germany and the Netherlands. She is in Hobart, which is a long way from Brussels, but the AI Act does not care. It applies to providers who put AI systems on the EU market "irrespective of whether those providers are established or located within the Union", and to deployers outside the EU where the output is used in the EU. The guidelines add that a deployer outside the EU is caught where it "foresees dissemination and use of the AI outputs in the Union". Beatrix ships honey to Utrecht. She foresees it.
It is Monday 27 July, the day the Omnibus enters into force. Beatrix has five days of work, and she goes through her AI tools one at a time.
Monday: the chatbot. The support widget on the European shop was built in-house last year on a model provider's API, and it is called "Bee". It answers questions about shipping and crystallisation. The company built it and runs it under its own name, so under the guidelines it is the provider of Bee, and 50(1) is its duty. Bee is a helpdesk chatbot: the guidelines' own example of "not obvious". Beatrix changes Bee's first message to say, in plain words, that it is an AI assistant, and adds a persistent "AI" badge next to the input box. She checks that a screen reader announces both. Deadline: 2 August. The Omnibus gives her no extra time here.
Tuesday: the product images. The design contractor uses an image generator to put real jars on AI-generated backgrounds: a eucalyptus forest, a breakfast table in soft morning light. The jars are real photographs. Under the guidelines, a real product on an AI background is not a deep fake as long as it does not mislead about the product. Then Beatrix finds one image where the AI has made the honey a deeper, glowing amber than the honey in the jar. That one could mislead as to the product's "appearance", so it is in deep-fake territory. She replaces it with a photo of the real honey. For the contractor's other work, she checks the contract: the contractor chooses and runs the tools, so the contractor is the deployer for those images. She asks the contractor to confirm how it will label anything that needs it.
Wednesday: the words. The product descriptions were drafted with AI and edited by Beatrix. Under the guidelines, product descriptions are outside 50(4), unless they make claims about "health, consumer safety or sustainability". One description says leatherwood honey is "good for your immune system". Beatrix removes that line. It was never her best line.
The company's newsletter is different. The August issue has an article on how honey's country of origin is shown on labels in the EU. She decides that counts as a matter of public interest, because it is about what consumers are told. Beatrix drafted it with AI in July, and it goes out on 6 August. The guidelines put the trigger at publication, so it needs a label or genuine editorial review. She chooses review. She checks every fact against the regulation, rewrites two paragraphs, and adds a line to the site's legal notice naming her role as editorially responsible. She does not use the AI to "tidy it up" afterwards, because that would void the exception.
Thursday: the hiring tool. The company is recruiting a warehouse coordinator in the Netherlands, through a platform that ranks CVs with AI. That is Annex III, point 4(a): high-risk. On 24 July, the provider and deployer duties for it were due to start in nine days. Now they start on 2 December 2027. Beatrix notes the new date in the risk register instead of deleting the row. Then she checks the platform's optional "video interview insights" feature. It claims to score candidates' "enthusiasm" from their facial expressions. She reads that as inferring emotions in the workplace, which has been banned since February 2025. She switches it off, and emails the platform to ask why it was on by default.
Friday: the list. Beatrix writes up what she did, which tools she checked, and who owns each duty. She schedules a review for October, when the company plans to launch an AI gift-message generator for the Christmas season. Because that tool will go on the market after 2 August 2026, the grace period in Article 111(4) does not cover its marking duty. If the company is its provider, it must meet 50(2) from launch. She books a call with the model vendor to ask what marking its API already applies, and how customers can detect it.
Then she finishes her tea, which has gone cold, like every cup during a compliance week.
Part 7: What to Check Before 2 August
If you read nothing else, read this. The steps are in the order I would do them.
- List every AI system that touches people or content in the EU. Include vendor tools that are switched on inside other products: helpdesk widgets, email assistants, image tools in your design software, CV ranking in your hiring platform.
- Mark your role for each one: provider, deployer or both. Built it or white-labelled it under your name: provider. Switched on someone else's: deployer. The guidelines' examples in paragraphs 11 to 15 are the quickest test.
- Chatbots and agents (50(1)): add the disclosure now. A first-turn message, a persistent label near the input, and an accessible version of both. For agents, disclose on whose behalf they act. No grace period.
- Generative systems you provide (50(2)): find your marking and your detector. Ask your model vendor, in writing, what marks it applies and what detection is available. If your system was on the market before 2 August 2026, you have until 2 December 2026. If it launches later, you have until launch.
- Deep fakes and public-interest text you publish (50(4)): set a rule. Decide which content gets a visible label and which gets documented human review. Name the role that holds editorial responsibility, and publish it. Watch the "published after 2 August" rule for anything drafted in July.
- Check for banned features. Emotion inference at work or in education has been banned since February 2025. Nudifier and synthetic child abuse generators are banned from 2 December 2026. Check the optional features in your vendors' products, not only the main ones.
- Keep the high-risk work going, on the new dates. Annex III systems: 2 December 2027. Annex I products: 2 August 2028. Keep the risk register rows. The work on data quality, logging and human oversight is still needed; it is simply due later. If you are in California as well as Europe, the CCPA's automated decision rules start on 1 January 2027, on their own timetable.
- Update your AI literacy record. The duty is now to "take measures to support" literacy. Write down what you did: who was trained, on which systems, and when.
- Consider the Code of Practice. If you provide generative AI or publish a lot of AI content, the Code is the clearest description of what regulators expect from marking and labelling, whether or not you sign it.
Final Thoughts
Back to the wall with the four clocks. It looked mad on Friday. By Monday it was the most accurate thing in the building. The AI Act did not blink all at once. It blinked for the heavy, standards-dependent parts, the ones that needed a platform that was not built yet, and kept its eyes open for the parts any company can do this week: say when a machine is talking, mark what a machine made, and label what might fool people.
Consumer groups are right that the delay has a cost. BEUC points out that companies using AI "in sensitive areas such as hiring, credit scoring or insurance" now "will not have to prove that their systems are safe until December 2027". That is a real gap, and the grace period for systems already on the market makes it wider. But if you are a business, that gap is not a holiday. It is 16 months to do the high-risk work properly, while the transparency work starts now.
The one takeaway: the high-risk train is late, and the transparency train is on time. Your next step is to make the list in step 1 and mark your role for each system before Sunday 2 August.
Now, if you'll excuse me, I have a kettle to see about, and it has never once run on time.
Notes
-
The Omnibus keeps one part of the high-risk section on the original timetable: Article 6(5), which obliged the Commission to publish guidelines on classifying high-risk systems by 2 February 2026. The Commission published a draft of those guidelines on 19 May 2026. The delay, in other words, applies to everyone's homework except the Commission's own, which was already late. ↩
-
The original Article 4 made no promise that training would work either, but "ensure, to their best extent, a sufficient level" sounded a lot like one. The new text says outright that nobody has to guarantee any individual's level of AI literacy, which is a relief to every trainer who has watched a colleague nod through a session while answering email. ↩
-
I have considered watermarking my tea. A marked cup would prove to any visitor that it was brewed by a human who cares, and that the milk was never allowed near it. The detector would be me, and the false-positive rate would be zero, because I would simply accuse every cup. ↩
-
The guidelines list, among texts outside the public-interest scope, "AI-manipulated text by a consultant for a client advice regarding measures to be taken for regulatory compliance". As a consultant who writes about regulatory compliance, I have chosen to read this as a personal note of encouragement from the European Commission. ↩


