...

There is a dangerous misreading circulating right now. Headlines in June said the EU delayed the AI Act, and many teams concluded they have until December 2027 to think about compliance.

Key Takeaways
  • Comply with Article 50 transparency: label chatbots, mark synthetic content, visibly disclose deepfakes, and notify emotion or biometric categorization exposures.
  • Respect prohibited practices: avoid social scoring, manipulative targeting, untargeted facial image scraping, emotion inference in workplaces, and non-consensual intimate imagery.
  • Prepare for high-risk compliance: inventory systems, implement lifecycle risk management, data governance, technical docs, human oversight, conformity assessment and registration.

That is true for one tier only. The high-risk obligations moved. The transparency obligations did not. Article 50 took effect on 2 August 2026 and is enforceable today, carrying fines up to €15 million or 3% of worldwide turnover.

This EU AI Act compliance checklist covers what actually applies now, what was deferred, and the concrete steps to take in each case.

This article is general information, not legal advice. The Act is complex and still generating guidance. Consult qualified counsel for your specific situation.

What Changed in 2026

The Digital Omnibus on AI, first proposed by the Commission in November 2025, had a fraught passage. Trilogue negotiations nearly collapsed in April 2026 before political agreement was reached on 7 May. The European Parliament approved the amendments on 16 June 2026 by 423 votes to 57 with 174 abstentions, the Council adopted on 29 June, and the changes entered into force on 27 July 2026.

The net effect: high-risk deadlines moved by 12 to 16 months. Transparency and general-purpose AI enforcement did not move at all.

Importantly, this is a deferral rather than a dismantling. The risk-based architecture, the governance structure, and the core obligations all remain intact.

Current Compliance Timeline

DateWhat AppliesStatus
2 Feb 2025Prohibited practices (Article 5)In force
2 Aug 2025GPAI model provider obligationsIn force
2 Aug 2026Article 50 transparency; GPAI enforcement powersIn force now
2 Dec 2026Article 50(2) marking for pre-existing systemsTransition ends
2 Dec 2027High-risk standalone systems (Annex III)Deferred
2 Aug 2028High-risk AI in regulated products (Annex I)Deferred

Checklist 1: Article 50 Transparency (Live Now)

This is the section most organizations underestimate. You do not need high-risk AI to be caught. Running a chatbot or publishing AI-generated content is enough.

Article 50 imposes four disclosure duties, split between providers who develop systems and deployers who use them.

  • Chatbots identify themselves as AI. Any system interacting directly with people must make clear the person is dealing with a machine, at the point of first interaction, in an accessible manner.
  • Synthetic content is machine-readable marked. Providers of generative systems must mark AI-generated audio, image, video, and text so it can be detected.
  • Deepfakes are visibly labelled. Deployers must disclose artificially generated or manipulated content on first exposure. Critically, you cannot rely on the provider’s machine-readable marking to satisfy this — the disclosure must be perceivable without special tools.
  • Emotion recognition and biometric categorisation are disclosed. Deployers must inform people exposed to these systems.
  • AI-written public-interest text is labelled, unless it went through human review with editorial responsibility.
  • Vendor contracts require compliance. If you deploy someone else’s system, your obligations do not transfer to them.

Three practical notes. Artistic, satirical, and fictional works get lighter treatment: disclosure must not hamper enjoyment of the work. Content generated before 2 August 2026 does not require retroactive labelling, since the generation date governs. And providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) marking requirements — a narrow transition that does not extend to deployer disclosure duties.

The Commission published final Article 50 guidelines on 20 July 2026 and confirmed the Code of Practice on Transparency of AI-Generated Content as adequate. The Code is voluntary; build your baseline from the Regulation itself and use the Code to structure implementation.

Checklist 2: Prohibited Practices (Live Since 2025)

These have been enforceable for over a year and carry the heaviest penalties: up to €35 million or 7% of global turnover.

  • No social scoring by or on behalf of public authorities.
  • No manipulative or exploitative techniques targeting vulnerabilities.
  • No untargeted scraping of facial images for recognition databases.
  • No emotion inference in workplaces or educational settings, outside narrow safety and medical exceptions.
  • No AI-generated non-consensual intimate imagery or child sexual abuse material. This prohibition was newly added to Article 5 by the Omnibus.

Checklist 3: General-Purpose AI Models

If you develop or fine-tune a general-purpose model, obligations have applied since August 2025, and the Commission’s enforcement powers activated on 2 August 2026.

  • Technical documentation maintained and current.
  • Information provided to downstream integrators.
  • Copyright policy in place, including respect for text and data mining reservations.
  • Training data summary published.
  • For models with systemic risk: evaluation, adversarial testing, incident reporting, and cybersecurity measures.

Checklist 4: High-Risk Systems (Prepare Now, Due 2027)

The deferral gives real headroom, but a compliance framework takes many months to build. Use the time rather than waiting for it.

Start by determining whether you are in scope. Annex III categories include biometrics, critical infrastructure, education, employment, access to essential services such as credit scoring and insurance, law enforcement, migration, and administration of justice.

  • Inventory every AI system in use across the organization and classify it by risk tier.
  • Establish a risk management system operating across the full lifecycle (Article 9).
  • Implement data governance covering training, validation, and testing datasets, including bias examination.
  • Prepare technical documentation to Annex IV specification.
  • Enable automatic logging for traceability.
  • Provide instructions for use enabling deployers to comply with their own duties.
  • Design human oversight that is genuinely effective, not nominal.
  • Meet accuracy, robustness, and cybersecurity requirements.
  • Complete conformity assessment, affix CE marking, and register in the EU database.
  • Deployers: assign competent oversight staff, monitor operation, keep logs, and inform affected individuals where required.

Does This Apply to Non-EU Companies?

Yes. Like GDPR, the AI Act has extraterritorial reach. What matters is whether the system’s output touches the EU in a meaningful way, through sales, access, or downstream integration.

A US or UK company running a chatbot available to EU users is within scope of Article 50 today, regardless of where it is established.

Penalties

ViolationMaximum Fine
Prohibited practices€35M or 7% of global turnover
High-risk or transparency non-compliance€15M or 3% of turnover
Supplying incorrect information€7.5M or 1% of turnover

Whichever figure is higher applies, except for SMEs and startups, where the lower figure applies. Penalties apply per infringement. Enforcement of Article 50 sits mainly with national market surveillance authorities.

A Sensible Order of Work

  1. Audit now. Inventory every AI system, including third-party tools your teams adopted without procurement review. You cannot classify what you have not found.
  2. Fix Article 50 immediately. It is live, it is comparatively cheap to comply with, and chatbot disclosure is often a one-line interface change.
  3. Check the 2 December 2026 transition if you provide generative systems that were already on the market.
  4. Assign ownership. Someone specific needs to own AI governance, not a committee that meets quarterly.
  5. Begin high-risk work in parallel. Conformity assessment and technical documentation for complex systems take many months.
  6. Track guidance. Commission guidelines and codes of practice are still emerging and materially affect interpretation.

Final Thoughts

The delay is real but narrower than the headlines suggested. High-risk teams got breathing room. Everyone running a chatbot, generating synthetic media, or publishing AI-written content got a live obligation on 2 August 2026.

The organizations that will handle this well are not the ones waiting for perfect clarity. They are the ones that inventoried their systems, closed the transparency gaps that were cheap to close, and started the harder documentation work while there was still time.

FAQs

Was the EU AI Act delayed?

Partly. High-risk obligations moved to December 2027 and August 2028, but transparency and GPAI enforcement began 2 August 2026 as planned.

What applies from August 2026?

Article 50 transparency duties covering chatbot disclosure, synthetic content marking, deepfake labelling, and emotion recognition notices.

Does the EU AI Act apply to US companies?

Yes. It has extraterritorial reach, so any system whose output meaningfully reaches EU users can be in scope.

What are the fines for non-compliance?

Up to €35 million or 7% of turnover for prohibited practices, and €15 million or 3% for transparency or high-risk breaches.

Do I need to label AI content created before August 2026?

No. Labelling obligations turn on the generation date, so earlier content is not caught retroactively.

How useful was this post?

Rated 0 / 5. Vote Count: 0

Be the first to rate this post.

We are sorry that this post was not useful for you!

Let us improve this post!

Tell us how we can improve this post?