Your chatbot has a deadline. It's August 2.

If you read one headline about the AI Act this year, it was probably that the hard parts got pushed back. That is true, and it has left a lot of companies with the impression that nothing lands for another eighteen months.

Something lands on August 2, 2026. It is not the part anyone was preparing for, which is exactly why it is worth two minutes of your attention.

What moved, and what didn't

The obligations for high-risk AI systems were deferred. Rules for systems used in biometrics, critical infrastructure, education, employment, migration and border control now apply from December 2, 2027.

Article 50 did not move. The transparency obligations apply from August 2, 2026.

The difference matters because the two sets of rules target completely different companies. High-risk obligations catch a small number of organizations building consequential systems. Article 50 catches almost anyone who has shipped a chatbot, added an AI feature, or published content a model helped write.

That is a much larger group, and most of it is not watching.

The four obligations

Stripped to what they actually require:

Tell people they are talking to a machine. Anyone talking to an AI system has to know it is an AI. You only get to skip it when that is already obvious, and that bar sits higher than most companies assume: a widget branded as a bot is obvious, a chat window that sounds like a support agent is not.

Mark AI-generated content so a machine can read it. Anything AI makes (audio, image, video, text) has to carry a marking that shows it is artificial. Not a visible label for people. A signal software can read.

Disclose emotion recognition and biometric categorization. Does your system read emotions, or sort people by their face or voice? Then you have to tell them.

Label AI-generated text on matters of public interest. Publish AI-generated text on a matter of public interest and you have to say so. Unless a human reviewed it and holds editorial responsibility for it. The same goes for deepfakes, with an exemption for work that is clearly artistic.

How do you actually mark something?

Marking is the vaguest of the four obligations, so the Commission published a code of practice for it: the Code of Practice on Transparency of AI-generated Content, drawn up by independent experts through the AI Office. It covers the labeling and marking duties in Article 50(2), 50(4) and 50(5).

Are you a provider or a deployer?

This question gets skipped in most internal discussions. It decides which obligations are yours and which belong to someone else.

Two situations.

You buy a chatbot and put it on your site. You are using the system. In the regulation that makes you a deployer.

You build AI into your own product and sell it under your own name. You are supplying the system. In the regulation that makes you a provider.

Plenty of companies are both at once. You sell a product with AI in it, and meanwhile there is a bought-in chatbot sitting on your own website. Two roles, two sets of obligations, inside one company.

Why that matters: marking is the provider's job. They make sure AI-generated content is recognizable as AI-generated. Disclosure is the job of whoever puts the system to work. They tell the user they are talking to AI.

Sit in the wrong role and you are waiting on something nobody is doing. You assume the vendor handles it. The vendor assumes you disclose it. So nothing happens.

There are exemptions, but they apply less often than you think

Content where the AI interaction is genuinely obvious is exempt. So are short sequences, code, and machine-to-machine outputs. Closed-loop industrial development is out of scope, and there is a narrow business-to-business carve-out. Standard editing assistance does not count as generation. Text that went through real human editorial review and control is exempt from the labeling duty.

That last one is the exemption most publishers will reach for, and it is conditional on the review being real. Editorial control means someone is answerable for the output, not that someone skimmed it.

One date most coverage misses

There is a grace period. Systems already on the market before August 2 get until December 2, 2026 to meet the marking and detection obligations.

If you shipped an AI feature last year, you have four months. If you ship one next month, you do not.

What it costs to be wrong

Enforcement sits with national market surveillance authorities. Penalties for Article 50 breaches reach 15 million euros or 3% of total worldwide turnover, whichever is higher, with proportionality considered for smaller companies.

That figure is not the interesting part. The interesting part is that these obligations are visible from the outside. Anyone can open your product and see whether the chatbot introduces itself. Compliance here is not a document you produce during an audit. It is a property of the interface, checkable by anyone who cares to look, including a competitor.

What to do this week

List every place AI touches a user. Chat widgets, generated summaries, drafted emails, product descriptions, support macros, image generation. Most companies underestimate this list because the features arrived one at a time.

Decide provider or deployer for each one. Per feature, not per company. The answer varies inside a single product.

Check what your vendors have shipped. If you deployed someone else's model, the marking obligation is theirs. Whether they have met it is your exposure.

Write down which exemption you are relying on, if any. An exemption you have not stated is one you will not be able to defend.

The summary

The AI Act's headline deadlines moved. The transparency rules did not, and they apply to a far wider group of companies than the parts that were postponed.

None of this requires a compliance program. It requires knowing where AI touches your users, and being able to say who is responsible for telling them.

Building something?

Tell us what you're working on. We'll tell you straight if we're the right fit, what it'll take, and what it'll cost.

Our work