The Omnibus Moved High-Risk, Not Article 50: Transparency Duties Arrived on Schedule
Regulation (EU) 2026/1744 pushed the AI Act's high-risk deadlines to December 2027 and August 2028. Article 50 applied on 2 August 2026 as written. Who each paragraph binds, the one four-month carve-out, and a builder's checklist mapped to the text.
This week the EU moved the AI Act's high-risk deadlines and left its transparency deadline alone. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on Friday 24 July and entered into force on Monday 27 July. Today, Sunday 2 August, Article 50 applies on the date set back in 2024. The short version travelling this week is that the AI Act has been delayed. For anyone shipping a chatbot, a voice agent or generated media, that version is wrong.
This is an engineering reading of a legal text and not legal advice. Dates, amounts and quotes come from the regulation on EUR-Lex and from the Commission's own pages. Law-firm notes appear only as commentary, and we name them where we use them.
What moved, and what stayed put
The regulation is dated 8 July 2026 and amends the AI Act, Regulation (EU) 2024/1689. Its final article says it enters into force "on the third day following that of its publication", which made it law on the Monday before the old deadline. Two application dates moved.
- Annex III · stand-alone high-riskThe obligations in Chapter III, Sections 1 to 3 now apply from 2 December 2027. They were due on 2 August 2026. Sixteen months later.
- Annex I · AI inside regulated productsNow 2 August 2028, previously 2 August 2027. Twelve months later.
Recital 40 gives the reason in one line: "the delayed availability of standards, common specifications, and alternative guidance and the delayed establishment of national competent authorities". The standards were not ready, and neither were the regulators.
The rest of the calendar held. The bans on prohibited practices have applied since 2 February 2025. Obligations for general-purpose AI models and the governance rules have applied since 2 August 2025, and the Omnibus did not touch that point of Article 113. From 2 August 2026 the Commission can also fine GPAI providers, and its news item of 31 July says the AI Office, "together with national authorities, will begin enforcing" the Act from that date. Member States still owed the designation of their market-surveillance and notifying authorities by 2 August 2025. The tracker at artificialintelligenceact.eu counted nine Member States with clear designations, twelve partial and six unclear on 17 June 2026.
The penalty ceilings in Article 99 did not change either.
A breach of Article 50 falls under Article 99(4), point (g): up to €15,000,000 or 3% of worldwide annual turnover. For SMEs, Article 99(6) already capped each fine at the percentage or the amount, "whichever thereof is lower". The Omnibus adds a paragraph 6a that gives small mid-cap companies the same cap for paragraphs 4 and 5. That covers transparency breaches and leaves prohibited practices out.
Two smaller changes matter to builders. Article 4 on AI literacy was rewritten: providers and deployers now "take measures to support" staff literacy, and the text adds that this "does not require providers or deployers to guarantee any specific level of AI literacy of any individual". Article 5 gained two bans, on AI that generates non-consensual intimate imagery of an identifiable person and on AI that generates child sexual abuse material. Both apply from 2 December 2026.
Article 50, paragraph by paragraph
The Commission's FAQ puts it without qualification: "Article 50 of the AI Act applies as from 2 August 2026. From that date onwards, providers and deployers of AI systems must comply". The paragraphs bind different parties, and that split decides who in a supply chain does the work.
- 50(1) · providerSystems "intended to interact directly with natural persons" must be designed so that people "are informed that they are interacting with an AI system". The FAQ names "chatbots, AI agents, and avatars", and says the exception for obvious cases "should be interpreted in a restrictive manner".
- 50(2) · providerProviders of systems that generate synthetic audio, image, video or text "shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated". General-purpose systems are included.
- 50(3) · deployerWhoever runs an emotion-recognition or biometric-categorisation system "shall inform the natural persons exposed thereto of the operation of the system".
- 50(4) · deployerDeepfakes must be disclosed as "artificially generated or manipulated". So must AI-generated text "published with the purpose of informing the public on matters of public interest", unless a human reviewed it and someone holds editorial responsibility.
- 50(5) · bothThe information arrives "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure", in an accessible form.
There is one carve-out, and it is narrow. The new Article 111(4) reads: "Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026." Recital 38 calls it "a transitional period of four months". It covers generators already on the market, and only the marking duty. A chatbot launched in 2025 owed its users the 50(1) disclosure on 2 August like everyone else. The FAQ adds that content generated before that date "does not need to be labelled retroactively".
The same FAQ draws the edges of 50(2). Out of scope: "a short sequence of numbers, symbols or letters", "source code", and outputs passed machine-to-machine "without any exposure to humans". It describes "a narrow exemption" for business-to-business and industrial contexts, under conditions set in the guidelines. It reaches providers outside the EU "if the output of their AI system is used in the EU". And it closes a shortcut: deployers "cannot simply rely on the machine-readable marking embedded in the content by the provider" to meet their own duty under 50(4).
Two support documents arrived before the date. The Commission adopted its final guidelines on Article 50 on 20 July 2026, less than two weeks before the duty applied. The Code of Practice on Transparency of AI-generated Content was finalised on 10 June, in two sections: marking and detection for providers, labelling of deepfakes and text for deployers. The Commission says it and the AI Board "have confirmed that the code is an adequate voluntary tool". It counted "more than 180" signatories on 31 July and "about 190" by the end of the month.
Signing is voluntary. The duty is not. A non-signatory has to "demonstrate compliance through alternative adequate means" and, in the Commission's words, "may be subject to more requests for information". No code exists for 50(1) and 50(3); there, providers and deployers "can determine adequate compliance measures themselves". Enforcement sits mainly with national market-surveillance authorities. The AI Office steps in only where one entity provides both the general-purpose model and the system, or where the system sits inside a very large online platform or search engine.
A builder's checklist, mapped to the paragraphs
None of this needs a lawyer to implement. It needs a product decision, an output layer and a log. What we would check, in the order the article asks for it:
- 50(1): disclose in the first turn, inside the product. The duty is on how the system is "designed and developed", so a line in the terms of service does not meet it. A voice agent says it aloud. An e-mail or outbound agent says it in the first message. Faegre Drinker's note on the final guidelines reads them as requiring an agent to identify "both its AI nature and the person or entity on whose behalf it is acting". That is a law firm's summary; we did not read the guideline PDF.
- 50(2): mark at your own output layer. If you ship under your own name, you are the provider, whichever model answered. A router that sends one request to a closed API and the next to an open-weight model on-prem cannot count on either to mark the result. The marker belongs in the gateway both paths pass through.
- 50(2): decide scope per output channel. Code and machine-to-machine payloads are out. A generated report that a customer's employee reads is not obviously out, and the Commission calls the B2B exemption narrow. Write the decision down per channel.
- 50(2): plan for plain text. As Faegre Drinker summarises the Code, signatories "must generally implement both digitally signed metadata and imperceptible watermarking", with simplified requirements where content "(such as free-form text) cannot carry embedded metadata". For text-heavy systems the practical control is a provenance record on your side: what was generated, by which model version, under which policy.
- 50(3) and 50(4): deployer notices are visible, and they are yours. A label at first exposure for deepfakes, a notice to people exposed to emotion recognition. The provider's machine-readable marker discharges neither.
- Log that you did it. A non-signatory demonstrates compliance to each national authority separately. The evidence is a log line per output: model, version, policy, marker applied, disclosure shown. It is the same call log a buyer should already be asking for.
- Legacy generators: 2 December 2026 is a build date. It is four months away.
Our read
The Omnibus bought time for the part of the Act that depends on standards bodies and notified bodies. It bought none for the part that depends on you. A support bot, a voice agent or a document generator was an Article 50 subject on 2 August and was never likely to be an Annex III subject first. For that kind of team the relevant calendar did not move by a day.
The calendar that moved was the one most B2B teams were never on.
The obvious counter-argument is that a duty without an enforcer is soft. In Slovakia that was true on 2 August and it is still true today. We would not plan around it. The date is fixed, the ceiling is set at EU level, and a procurement questionnaire moves faster than a ministry. The second limit is ours: we read the regulation and the Commission's pages, not the guideline and Code PDFs, so the technical measures quoted above are a law firm's summary until you check them yourself.
The provider and deployer split is the part we would spend time on. It is an architecture question before it is a legal one. Whoever puts their name on the system owns disclosure and marking, and whoever publishes the output owns the visible label. If your system routes across several models, none of them will do either job for you.
Disclosure in the first turn, a marker in the output path and a call log that proves both are things Sebrona designs in next to the routing policy, before the first user sees the system. If you run a generator or an agent in front of EU users and want a second pair of eyes on which paragraph binds which component, write to info@sebrona.com.
Reading
Where the dates, amounts and quotes come from. The regulation was read in full on EUR-Lex; the law-firm notes were read through summaries and are used as commentary only.
- Regulation (EU) 2026/1744Title and date, entry into force, the new Article 113 dates, Article 111(4), recitals 38 and 40, the rewritten Article 4, the Article 5 additions, Article 99(1) and (6a).
- AI Act, Articles 50 and 99 (consolidated)The wording of Article 50(1) to (5), the three fine ceilings, point (g) of Article 99(4), and the SME rule in 99(6).
- Transparency obligations under Article 50: FAQThe application date, the grace-period wording, no retroactive labelling, scope exclusions, the B2B exemption, the deployer shortcut, enforcement split, non-signatory consequences.
- Code of Practice on Transparency of AI-generated ContentFinalised 10 June, two sections, adequacy confirmation, "about 190" signatories by the end of July.
- Commission starts enforcing AI Act rulesThe 2 August enforcement start and the "more than 180" signatory count.
- National implementation plansThe 9 / 12 / 6 count of Member State designations and the Slovak entry naming an Office for Digital Integrity.
- Mayer Brown, EU AI Act newsCommentary: the 20 July adoption date of the final Article 50 guidelines.
- Faegre Drinker on the Code and guidelinesCommentary: the agent-identification reading, signed metadata plus watermarking, the free-text simplification, the 2 February 2027 interoperability date.