If you ask about the events of 2 August, you will receive two different explanations. Some people believe the Artificial Intelligence Act reached a major deadline and that every company selling software in Europe must now comply. Others believe that officials in Brussels reduced the requirements of the law and weakened its overall impact.
Both are half right.
What actually happened is that the expensive, ambiguous obligations to be imposed moved by sixteen months, and a cheap, unambiguous one arrived exactly on schedule. It applies to systems you have already placed on the market and it goes into effect on the 2nd December 2026. And because the compliance programme was built around the other date, most organisations have nobody assigned to the issue.
What moved, and by how much
On 24 July the Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal, and it entered into force three days later on 27 July. Six days before the deadline it amends. That timing tells you most of what you need to know about how comfortable anyone was with the original schedule.
It pushed the stand-alone high-risk obligations under Annex III - recruitment, credit scoring, education, essential services - from 2 August 2026 out to 2 December 2027. Product-embedded high-risk systems under Annex I moved to 2 August 2028.
Annex I didn’t slip from this August. Its original date was August 2027, so that’s a twelve-month deferral.
What arrived exactly on time
Meanwhile, the Commission began enforcing, and the Article 50 transparency obligations became applicable on the original date.
Under Article 50(1), if a user is interacting with an AI system rather than a person, they have to be told that up front. Chatbots, agents, avatars. Under Article 50(2), AI-generated or manipulated content has to carry machine-readable marks. Penalties are up to €15 million or 3% of total worldwide annual turnover, whichever is higher.
Note what kind of obligation that is. There’s no conformity assessment, no notified body, no risk management system to stand up, no technical documentation running to eighty pages. It’s a disclosure string and a content-marking pipeline.
It’s a fortnight of engineering work at most, but that’s actually a problem.
Before you file this under European
“We’re not in the EU” is probably giving a lot of unearned comfort in British boardrooms at the moment, so it’s worth being pointing out how this impacts UK companies.
Article 2(1)(c) catches providers and deployers established in a third country “where the output produced by the AI system is used in the Union”. Not where you’re incorporated. Not where you host. If you have EU users, your date was 2 August, same as a company in Munich. And when the Act says a system has been “placed on the market”, it means the Union market, not yours.
If you genuinely have no EU exposure, then nothing domestic replicates any of this. There’s no UK requirement to tell someone they’re talking to a machine, and none to mark synthetic content. The House of Commons Library put it flatly in January: there is no legislation requiring AI-generated content to be labelled. We went with a sector-regulator approach, but the statutory duty that approach was supposed to be enforced by never got created, and what actually binds you is a patchwork. UK GDPR on automated decisions. The unfair trading regime in the Digital Markets, Competition and Consumers Act 2024, which is the closest thing we have to a bot-disclosure rule and gets there only through misleading omission. The Online Safety Act, if you’re user-to-user. Your own regulator’s consumer duty, if you’re regulated at all.
So no deadline and no standard. Which sounds like a comfortable position but isn’t, because it means nobody will tell you when you were supposed to have started.
There’s a third route in, and it’s the one I’d actually plan around. Your enterprise customers who do sell into the EU will push content marking down the contract chain, because segmenting their own product is more expensive than making it your problem. Most UK firms will meet Article 50 as a procurement question long before they meet it through law.
The trap is organisational
Compliance programmes for the AI Act were built around the high-risk date, because that was the frightening one. That work went to legal, or to a cross-functional group with legal holding the pen, and quite right too. Classification under Annex III is a genuinely hard legal question, and getting it wrong is expensive.
So the deferral arrives on the desk of the people who owned the deadline. Legal reads the Omnibus, confirms the exposure moved to December 2027, and reports relief upwards to the board. Entirely correct, but entirely beside the point.
Because the obligation that actually went live is an engineering change. It needs someone to add a disclosure to a chat interface, and someone to work out how provenance marking gets applied to generated output across every interface. Neither of those people were in the compliance meeting. They were told the AI Act deadline had moved, which is true, and they moved on.
Who’s picking that up in your organisation?
Four months, for things you shipped years ago
Here’s the bit that catches people. Under the amended Article 111(4), systems generating synthetic audio, image, video or text that were placed on the market before 2 August 2026 have until 2 December 2026 to comply with the marking obligation.
Four months. Retrospectively. On software that is already out there and, in a good many cases, already sold to somebody with an indemnity clause.
The Commission originally proposed six months for this. So if you’re reading a countdown tracker that says six, or one that still shows Annex III applying this August, it was written before 27 July and it’s now wrong.
What “human editorial control” turns out to mean
Article 50(4) carries an exemption for AI-generated text on matters of public interest where the content has undergone human review and someone holds editorial responsibility. Everyone selling content tooling has seized on this, so it’s worth reading what the Commission actually published in its Article 50 guidelines on 20 July.
Human review means “the deliberate examination of the substance of the content by one or more natural persons possessing relevant knowledge and professional judgement pertaining to the subject matter”. Running a spellcheck over it doesn’t count. Neither does a cursory sign-off. Editorial responsibility means a named person or organisation holds ultimate legal responsibility for publication, and is identifiable, with contact details publicly accessible.
The phrase “Matters of public interest” is interpreted broadly to cover economic, political, scientific, and cultural developments that are relevant to society. The regulation applies based on the date of publication rather than the date of generation.
Which, if you follow it through, catches a great deal of ordinary business writing. If you publish AI-assisted commentary about, say, technology regulation, on a site accessible to an indefinite number of readers, you are closer to the scope of Article 50(4) than to the outside of it. The exemption is available. It just requires you to have actually read the thing and to put your name on it.
The guidelines are non-binding, incidentally. Only the Court of Justice can interpret the Act authoritatively. But they’re the clearest signal available about how the Commission intends to read the scope.
So what is sixteen months worth?
It’s worth a great deal. Annex III classification was the genuinely expensive, genuinely ambiguous obligation, and an extra sixteen months to work out whether your product is in scope is a real gift to anyone building in that space.
There’s also a issue that will surface later. Enforcement of Article 50 falls to national market surveillance authorities rather than the Commission’s AI Office, and member states were supposed to designate those authorities by August 2025. A lot of them didn’t. Germany only got there on 29 July this year, when its implementing act came into force and named the Bundesnetzagentur. So you probably have an obligation that’s live and enforceable, against a supervisory map that is still under construction.
Which makes the practical answer awkward rather than reassuring. The deadline that moved was the one you’d budgeted for. The one that didn’t move applies to what you’ve already sold, falls due in December, and is currently sitting in a gap between the lawyers who think it’s a technical change and the engineers who think it’s a legal one.
Four months. Somebody should probably take charge of it.