Home/Blog

EU AI Act, 2 August 2026: What Changes for Teams Shipping AI Features

Article 50 chatbot disclosure and AI content marking apply 2 August 2026; the Digital Omnibus moves high-risk rules to 2027 and 2028. Engineering checklist.

EU AI Act, 2 August 2026: What Changes for Teams Shipping AI Features

EU AI Act, 2 August 2026: What Changes for Teams Shipping AI Features

On 2 August 2026, eleven days from now, the bulk of the EU AI Act starts to apply. Article 113 of Regulation (EU) 2024/1689 sets that date as the general date of application, and it brings the Article 50 transparency rules with it: chatbots must tell people they are talking to an AI, generative systems must mark their output in a machine-readable way, and deepfakes must be labelled. What will not apply on that date, if the pending amendment lands in time, is the heavy high-risk regime. The "Digital Omnibus on AI" moves it to 2 December 2027 for stand-alone high-risk systems and 2 August 2028 for AI embedded in regulated products. If you run a chatbot, generate images, audio, video or text, or use AI to help make decisions about people, and any of that output reaches the EU, this post is for you.

This is engineering guidance, not legal advice. Where your product sits under the Act is a question for counsel who can see your contracts and your users.

Where the Digital Omnibus stands on 22 July 2026

The Commission proposed the Digital Omnibus on AI on 19 November 2025. According to the European Parliament's Legislative Train, the Council agreed its general approach on 13 March 2026. Negotiators reached a provisional agreement on 7 May, which the Council announced the same day. Parliament's plenary adopted the text on 16 June by 423 votes to 57, with 174 abstentions (Parliament press release). The Council gave its final approval on 29 June, and the act was signed on 8 July.

What remains is publication in the Official Journal. As of today it has not been published. The adopted text enters into force on the third day after publication. Plan on the new dates. Check EUR-Lex before you rely on them in a contract.

What the Omnibus actually defers

The dates below come from Parliament's 16 June press release and the Legislative Train entry.

ObligationOriginal date (Reg. 2024/1689)After the Digital Omnibus
Existing prohibited practices (Article 5) and AI literacy (Article 4)2 February 2025Already in application
New ban on AI that generates non-consensual intimate imagery or CSAMDid not existApplies from 2 December 2026
Article 50(1), (3), (4): chatbot disclosure, emotion recognition and biometric categorisation notices, deepfake and public-interest text labels2 August 2026Unchanged: 2 August 2026
Article 50(2) machine-readable marking, systems placed on the market before 2 August 20262 August 20262 December 2026
Article 50(2) marking, systems placed on the market on or after 2 August 20262 August 2026Unchanged: 2 August 2026
High-risk systems listed in Annex III (hiring, credit scoring, education, essential services and others)2 August 20262 December 2027
High-risk AI in products under Annex I sectoral law2 August 20272 August 2028

Read the marking row carefully. Parliament's release says the watermarking delay applies to "systems placed on the market before 2 August 2026". A generative feature you launch on 3 August gets no grace period. If you have a new image or voice feature on the roadmap for August, either the marking ships with it or the launch date moves before 2 August.

The Omnibus did not move the chatbot disclosure duty. "The AI Act was pushed to 2027" is true only for the high-risk regime, not for the part of the Act most SaaS products actually hit.

Who the regulation applies to, including outside the EU

Article 2(1) is the scope clause, and it is wide:

  • Providers that place AI systems on the EU market or put them into service there, "irrespective of whether those providers are established or located within the Union or in a third country".
  • Deployers established or located in the EU.
  • Providers and deployers in third countries "where the output produced by the AI system is used in the Union".

The two roles are defined in Article 3. A provider develops an AI system, or has one developed, and places it on the market or puts it into service "under its own name or trademark, whether for payment or free of charge". A deployer uses an AI system under its authority, unless the use is personal and non-professional.

For a typical startup, that means you are usually the provider of your product's AI features even if the model comes from someone else's API. You built the system around the model and ship it under your brand. The Commission's draft guidelines on Article 50, published for consultation on 8 May 2026, give exactly this example: the provider of an interactive AI system is the one that puts it into service in the Union under its trademark, "regardless of its place of establishment". Your B2B customers who switch on your AI features for their own workflows are likely deployers. Both roles can carry duties for the same feature.

An Indian, US or UK company with EU users is in scope for Article 50 on the same terms as a Berlin one.

Article 50, split by role

The Article 50 text assigns each duty to a specific role.

ParagraphWhoDutyMain exceptions
50(1)ProviderDesign the system so people are informed they are interacting with an AIObvious to a "reasonably well-informed, observant and circumspect" person; authorised law enforcement uses
50(2)Provider, including of general-purpose AI systemsMark synthetic audio, image, video or text in a machine-readable format, detectable as AI-generatedAssistive editing that does not substantially alter the input or its meaning; authorised law enforcement uses
50(3)DeployerInform people exposed to emotion recognition or biometric categorisationUses permitted by law for criminal investigation
50(4)DeployerDisclose deepfake image, audio or video; disclose AI-generated text published to inform the public on matters of public interestEvidently artistic or satirical work (lighter disclosure); text under human review with editorial responsibility
50(5)BothGive the information clearly, at the latest at the first interaction or exposure, meeting accessibility requirementsNone

Two details save arguments later. First, the "obvious" exception is narrow. The draft guidelines treat a code assistant sold only to professional developers as a candidate for it, and list chatbots in helpdesks and support tools, where users "may perceive" outputs as human, as examples that do not qualify. Second, the draft guidelines point out that EU consumer law can require disclosing an AI-driven service anyway, "irrespective of whether the interaction is considered 'obvious'" under the AI Act.

Non-compliance with Article 50 falls under Article 99(4): fines up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. For SMEs and start-ups, Article 99(6) flips it to whichever is lower. National market surveillance authorities enforce Article 50.

How marking is expected to work

Article 50(2) asks for marking that is "effective, interoperable, robust and reliable as far as this is technically feasible". The text does not name a technique. The Commission's Code of Practice on Transparency of AI-generated Content, published in final form on 10 June 2026, is where the specifics live. It is voluntary, and it is the most detailed statement so far of what the Commission expects a compliant marking setup to look like.

Section 1 of the code, for providers, asks for:

  • At least two layers of machine-readable marking for audio, images, video and containerised text, because no single technique yet meets all four Article 50(2) criteria.
  • Digitally signed metadata: a record in the file's metadata that the content is AI-generated or manipulated, signed and time-stamped in a tamper-evident way, with the signing keys protected.
  • An imperceptible watermark embedded in the content itself. For free-form text, which cannot carry metadata, the watermark alone is accepted, and text longer than 200 tokens still needs one.
  • Fingerprinting or logging as an optional extra layer, never the only one.
  • A detection mechanism for your own markings, with an interoperability solution for detection by 2 February 2027.

The code also says marking may be done upstream, by the model provider or a third-party vendor, "without prejudice to the Signatories' own responsibility". Your model vendor's watermark can be one of your layers. It does not shift the obligation off you.

Section 2, for deployers, covers labelling deepfakes and public-interest text, and the Commission has published EU icons deployers may use for those labels.

The engineering checklist

The first two rows are due on 2 August for most products.

#ItemDone when
1AI feature inventoryEvery feature that calls a model is listed with its role (provider or deployer), EU exposure, output type and Article 50 paragraph
2Chatbot disclosure UIEvery conversational surface says it is an AI before or at the first turn, and the notice stays visible
3Machine-readable markingGenerated images, audio and video carry signed metadata plus a watermark; text has a watermark or a documented plan
4Deployer labelsDeepfakes and published public-interest text carry a visible label
5Evidence loggingYou can show which disclosure and marking version applied to any output
6Vendor answersEach model provider has answered the questions below in writing
7High-risk triageFeatures touching hiring, credit, education or other Annex III areas are flagged for the December 2027 regime

1. Inventory. One row per feature: which model and vendor, what it outputs, who sees it, whether EU users or EU customers can reach it, and whether you ship it under your brand.

2. Disclosure UI for chatbots. The draft guidelines list concrete patterns: a first-turn greeting that says the assistant is AI, a plain-language banner such as "You are interacting with an AI system", a persistent badge near the input field, and a spoken statement at the start of voice calls. Audio cues alone "are not considered sufficient". Put the disclosure in the component, not in a prompt the model can drop. Test it with a screen reader: Article 50(5) requires accessible delivery. If you hand off from a bot to a human agent, make the switch visible both ways. Our post on AI-powered customer support covers the handoff design.

3. Machine-readable marking. Start with what your generation vendor already embeds, then add your own signed metadata at the point where you write the file. Keep the signing key in a KMS, not in the app. Remember the date split: features live before 2 August have until 2 December 2026, anything launched after has no grace period.

4. Deployer labels. If your customers publish what your product generates, give them a one-click label, and document that the choice is theirs. If you publish AI content yourself, you are the deployer.

5. Logging. Article 50 has no logging clause. The mandatory log retention in Article 26(6) (at least six months) is a high-risk deployer duty and is deferred with the rest of that regime. You still need evidence that your disclosures and marks were in place when an authority asks. A per-output record is enough:

{
  "output_id": "gen_01J8...",
  "feature": "support-chat",
  "created_at": "2026-08-02T09:14:03Z",
  "model": "vendor/model-name@version",
  "disclosure_version": "chat-banner-v3",
  "marking": ["signed-metadata-v1", "vendor-watermark"],
  "eu_exposure": true
}

Store no prompt or output content here unless you have a lawful basis for it under GDPR. The code itself warns that logging must not become "a general commitment to log, monitor, or retain" user data. For wider logging hygiene around agents, see securing AI agents in production.

6. Questions for your model providers. General-purpose model providers have had obligations since 2 August 2025. Article 53(1)(b) requires them to give downstream providers documentation that lets you "comply with their obligations pursuant to this Regulation". Ask for it:

  • Do you watermark outputs at the model level? For which modalities, and how is it detected?
  • Do you attach signed metadata, and in what format?
  • Have you signed the Code of Practice on Transparency of AI-generated Content?
  • Where is your Article 53 downstream documentation (the Annex XII elements)?
  • Does any API setting, such as a raw or unwatermarked mode, strip your marks?
  • Will you notify us before changing the marking scheme?

7. High-risk triage. "AI-assisted decisions" is where teams misjudge risk. Annex III covers AI used "to analyse and filter job applications, and to evaluate candidates", and AI used to "evaluate the creditworthiness of natural persons". If a feature does that, you now have until 2 December 2027 for the full regime of risk management, data governance, logging and human oversight. Our notes on bias and fairness in ML are a starting point for the data governance work.

Two misreadings to avoid

First, "everyone using AI must disclose it from 2 August". The chatbot disclosure in Article 50(1) is a provider duty, built into the system. Deployer duties under Article 50 are narrower: emotion recognition, biometric categorisation, deepfakes and public-interest text. Second, "the Omnibus is already law". As of 22 July it is adopted and signed, but it takes effect only after publication in the Official Journal. Until then, the high-risk date in force is still 2 August 2026.

If you want a second pair of eyes on your AI feature inventory before 2 August, get in touch.

Sources