Skip to main content
AI Tool Radar
DACH Focus

EU AI Act on August 2, 2026: What Actually Applies Now

The high-risk regime is postponed, but Article 50 transparency duties start August 2, 2026: chatbot disclosure, AI-content labeling, deepfake rules.

6 min read2026-07-30By Roland Hentschel
ai-acteuregulationarticle 50transparencycompliancedach

The short version#

August 2, 2026 arrives this weekend, and after a year of "will they delay it" coverage the answer is now settled: the high-risk regime is postponed, the transparency regime is not. The May 2026 AI Omnibus agreement moved the big Annex III high-risk obligations to December 2, 2027 (and August 2, 2028 for AI embedded in regulated products). But Article 50, the transparency rules covering chatbots, AI-generated content, deepfakes and emotion recognition, takes effect on August 2, 2026 essentially as written (Jones Walker, Sidley).

If you publish AI-generated content, run a customer-facing chatbot, or produce synthetic media for clients, this is the deadline that concerns you, not the high-risk one.

Our April overview of the AI Act for solopreneurs was written mid-negotiation, when the outcome was genuinely uncertain. This post is the update now that the dust has settled.

Not legal advice. For your specific situation, talk to a lawyer.

What changed since April: the Omnibus deal#

In April 2026 the trilogue on the Digital Omnibus had just collapsed and nobody could say whether the original August 2026 high-risk deadline would hold. In May 2026 the EU reached a provisional agreement (Latham & Watkins, Skadden). The result:

ObligationOld dateNew date
High-risk, stand-alone systems (Annex III: hiring, credit scoring, education, essential services)Aug 2, 2026Dec 2, 2027
High-risk, embedded in regulated products (Annex I)Aug 2, 2026Aug 2, 2028
Article 50 transparency dutiesAug 2, 2026Aug 2, 2026 (unchanged)
Machine-readable marking of synthetic media, for generative systems already on the market before Aug 2, 2026Aug 2, 2026Dec 2, 2026 (grace period)

Also unchanged from before: Article 5 prohibited practices and the AI-literacy duty have been binding since February 2, 2025, and the GPAI (foundation model) obligations since August 2, 2025.

Article 50: the five duties that start now#

Article 50 splits duties between providers (whoever builds or places the AI system on the market) and deployers (whoever uses it professionally). A small business can easily be both. The Future of Life Institute's Article 50 guide and Sidley's analysis break it down into five duties:

1. Chatbot disclosure (providers). If people interact directly with your AI system, they must be told they are talking to an AI, unless it is obvious from context. If your website has a support bot, it needs to say it is a bot.

2. Machine-readable marking of synthetic content (providers). Systems that generate audio, images, video or text must mark outputs as AI-generated in a machine-readable, detectable format. This is the one duty with the December 2, 2026 grace period, and only for systems already on the market before August 2.

3. Emotion recognition and biometric categorization (deployers). If you run such systems on people, you must inform them. Most readers of this site can simply confirm this does not apply and move on.

4. Deepfake disclosure (deployers). If you generate or manipulate image, audio or video content that resembles real people, places or events, you must disclose that it is artificial. For obviously artistic or satirical work the disclosure can be lighter, but it does not disappear.

5. AI-generated text on matters of public interest (deployers). Text published to inform the public about matters of public interest must be disclosed as AI-generated, with an exception where a human exercised editorial control and someone takes editorial responsibility.

What this means for a DACH solopreneur or small agency, concretely#

The pattern across the five duties: transparency about the fact of AI involvement, not restrictions on using AI. Nothing in Article 50 stops you from using ChatGPT, Claude or Midjourney commercially. The checklist for a typical one-person business:

  • You run a support/booking chatbot on your site: add a clear "You are chatting with an AI assistant" notice. This is the most common gap we see on small-business sites.
  • You publish blog posts drafted with AI, edited by you: the editorial-control exception in duty 5 is built for exactly this. Human review plus editorial responsibility means no labeling duty for that text. Document your editorial process.
  • You produce marketing images/videos with AI for clients: photorealistic depictions of real-seeming people or events need a disclosure. Stylized illustrations generally do not read as deepfakes, but when in doubt, label.
  • You build a product on top of a generative model: the machine-readable marking duty is primarily the model provider's job (OpenAI, Anthropic, Google and the image/video vendors have been shipping C2PA-style provenance metadata for months). Your job is not to strip that metadata in your pipeline.
  • You do none of the above: then August 2 changes nothing for you, and the next date that matters is December 2, 2027.

Enforcement reality check#

Member-state authorities are still staffing up, and several transparency-related codes of practice and standards are not final. That is not a reason to ignore the date: the duties apply from August 2 regardless of how quickly enforcement follows, and a visible chatbot notice or a disclosure line under synthetic media costs you an afternoon. Do the cheap, visible compliance now; track the standards work for the rest.

What this post does not cover#

The high-risk regime (now December 2027 and beyond), GPAI model-provider obligations, and the AI Act's interplay with the DSGVO are all out of scope here; the April post covers the broader map. We also do not cover national implementation specifics for Germany and Austria, because the supervisory-authority designations were still in flux at the time of writing. Penalty amounts are deliberately omitted: the fining framework for transparency violations is set by member-state law within EU-set caps, and quoting one number without that context would mislead.

Sources#


Roland Hentschel

Roland Hentschel

AI & Web Technology Expert

Web developer and AI enthusiast helping businesses navigate the rapidly evolving landscape of AI tools. Testing and comparing tools so you don't have to.

Tools Covered in This Post

More from the Blog