What was delayed (the headline everyone repeats)
On May 7, 2026, the European Parliament and the Council reached a provisional agreement on the Digital Omnibus on AI, a package of amendments to the AI Regulation that got its final green light on June 29, 2026. Its goal was to give standards bodies (like CEN-CENELEC) more time to develop the technical standards underpinning several of the law's requirements.
What this agreement delays:
- High-risk Annex III systems (employment, education, biometrics, critical infrastructure, migration and border control, justice): delayed from August 2026 to December 2, 2027.
- High-risk AI embedded in regulated products (Annex I: medical devices, machinery, toys, etc.): delayed to August 2, 2028.
- Member states' obligation to set up a national regulatory sandbox: delayed by one year, from August 2026 to August 2027.
What was NOT delayed and takes effect on August 2, 2026
Here's the part most headlines get wrong: Article 50 transparency obligations still apply from August 2, 2026, unchanged. And unlike "high-risk," Article 50 isn't limited to specific sectors: it applies to virtually any company using generative AI or customer-facing chatbots.
Specifically, from August 2 you need to:
- Inform people when they're interacting with an AI system, unless it's obvious from context. A chatbot with its own name, avatar, or human-like conversational tone is unlikely to meet the "obvious" bar.
- Label synthetic content you generate (text, image, audio, video, including deepfakes) in machine-readable format, so it's detectable as AI-generated or manipulated.
- Disclose the use of emotion recognition or biometric categorisation systems, where applicable.
Non-compliance with Article 50 carries penalties of up to €15 million or 3% of global annual turnover.
Additionally, from August 2, 2026 the European Commission can start actively exercising its enforcement powers over general-purpose AI model providers (GPAI: ChatGPT, Claude, Gemini and similar) — requesting information, accessing models, or forcing their withdrawal from the market if they don't comply.
Summary: what applies and when
| Obligation | Applies from | Who it affects |
|---|---|---|
| Prohibited practices + AI literacy | Feb 2025 | All companies |
| GPAI obligations (foundation model providers) | Aug 2025 | Foundation model providers |
| Transparency (Article 50) | Aug 2, 2026 | Virtually any company with generative AI or chatbots |
| Enforcement powers over GPAI | Aug 2, 2026 | Foundation model providers |
| High-risk Annex III (standalone) | Dec 2, 2027 | Employment, education, biometrics, critical infrastructure... |
| High-risk Annex I (embedded in regulated product) | Aug 2, 2028 | Medical devices, machinery, toys... |
Does August 2 affect you even if you're not "high-risk"?
If your company does any of the following, Article 50 applies to you regardless of size or sector:
- You use a customer support chatbot (WhatsApp, web, social).
- You generate images, video or text with AI for marketing, social media, or external communication.
- You use any emotion recognition or biometric categorisation system.
The "the AI Act got delayed" confusion is making many SMEs let their guard down on exactly the part they still need to comply with in days. What got delayed is the most technically costly part (high-risk); what didn't get delayed is relatively cheap to comply with, but very easy to overlook out of unawareness.
How to prepare in the coming days: 4 actions
- Audit where you use generative AI or customer-facing chatbots. List every touchpoint: website, WhatsApp, social media, marketing.
- Add clear AI-interaction notices where it isn't obvious from context (name, avatar, chatbot welcome message).
- Label synthetic content you publish: AI-generated images, video or text, clearly and accessibly.
- Document the approach you took. You don't need a massive rollout, but you do need evidence you assessed where the rule applies and what you did about it.
Conclusion
The AI Act wasn't delayed: it was reorganised. The part that got delayed is the one requiring more technical standards development time (high-risk); the part that didn't get delayed is the cheapest to comply with, but the one most companies are ignoring because they assume "this is for Big Tech."
At Dataverse Solutions we offer a quick Article 50 compliance review so you know exactly where your company stands before August 2.