The European Commission’s A.I. Office and national market surveillance authorities began enforcing the Artificial Intelligence Act on Aug. 2, activating the Article 50 transparency regime that requires chatbots to identify themselves as machines, deepfakes to be labelled, and generative systems to embed machine-readable marks on their outputs. The activation is real, but its most consequential half isn’t. Six days earlier, on July 27, Regulation (EU) 2026/1744, the A.I. Omnibus, entered into force and slid the deadline for standalone high-risk systems listed in Annex III (employment, education, law enforcement, critical infrastructure) to Dec. 2, 2027. Requirements for high-risk A.I. embedded in regulated products moved to Aug. 2, 2028.

Sixteen months of delay on the provisions Brussels once cast as the whole point of the Act.

What survives the delay is disclosure. Emotion-recognition and biometric-categorisation deployers must now notify affected individuals. Generative systems already on the market have until Dec. 2, 2026 to comply with the marking-and-detection duty, and, per guidance the Commission adopted on July 20, content published before Aug. 2 doesn’t need to be retroactively labelled. Noncompliance carries fines of up to €15 million or 3 percent of worldwide annual turnover, whichever is higher.

Executive Vice-President Henna Virkkunen, who holds the Commission’s portfolio for tech sovereignty, security and democracy, framed the regime around systems that “create risks on an entirely new scale.” The Omnibus accelerated exactly one prohibition to match that rhetoric: from Dec. 2, 2026, A.I. nudification applications and systems capable of generating child sexual abuse material are banned outright, carrying the Act’s top penalty tier of €35 million or 7 percent of turnover.

The extraterritorial reach is broad. Per the guidance, the Act binds any provider, deployer, importer or distributor whose systems are placed on the E.U. market or whose outputs are used within the Union. Cooley, in an Aug. 3 client alert, flagged the global reach as the practical headline, and noted that signatories of the A.I. Office’s voluntary Code of Practice on Transparency of A.I.-Generated Content can expect “a more favorable enforcement posture.”

The distributional effect is odd. Small and mid-sized firms using productivity platforms like Glean, Dust, and LemonLime inherit the disclosure duty immediately, regardless of risk classification, because Article 50 applies to any generative deployment touching E.U. users. Meanwhile the frontier labs whose Annex III use cases the Act was drafted to police have another sixteen months to prepare, courtesy of the Omnibus. Goodwin Procter, in its own alert, laid out the revised timeline in the flat register of a firm briefing clients on facts, not politics.

Brussels enforced the visible layer on schedule. The binding layer, quietly, moved.

Sources