The High-Risk AI Deadline Moved. Article 50 Did Not.
The European Union delayed major requirements for high-risk AI systems. It did not delay the transparency rules that already determine whether a chatbot must identify itself, whether synthetic output needs a machine-readable mark, and whether deepfakes or certain public-interest text must carry a disclosure.
Article 50 of the EU AI Act began applying on 2 August 2026. The same date activated enforcement powers for the relevant authorities. For security, privacy and procurement teams, the operational question is no longer whether a supplier has an AI policy. It is whether each feature has been classified, whether the required disclosure actually appears, and whether the evidence survives the product’s normal delivery chain.
This is not legal advice, and role classification can depend on the product and deployment model. It is a readiness problem that security teams can make concrete before the next vendor questionnaire or customer review.
The high-risk timetable moved to 2027 and 2028
Regulation (EU) 2026/1744, the Digital Omnibus on AI, changed the application timetable for high-risk systems. The rules for systems classified as high-risk under Article 6(2) and Annex III now apply from 2 December 2027. These include important use cases in employment, education, access to essential services and other listed areas.
High-risk systems embedded in products covered by the EU product-safety framework under Article 6(1) and Annex I move to 2 August 2028.
Those are consequential delays. They are also narrower than the phrase “the AI Act was delayed” suggests. The Omnibus preserved the 2 August 2026 application date for Article 50 transparency obligations.
Article 50 follows the behaviour of the system
Article 50 creates different duties for providers and deployers. A provider is generally the organisation that develops an AI system, has one developed, and places it on the EU market or puts it into service under its own name or trademark. A deployer uses an AI system under its authority in a professional context.
Providers of systems that interact directly with people must design them so users are informed that they are interacting with AI, unless that is obvious to a reasonably informed and attentive person in the circumstances.
Providers of systems that generate synthetic audio, images, video or text must also make the output identifiable as artificially generated or manipulated. Article 50 requires effective, interoperable, robust and reliable machine-readable marking, subject to defined technical and contextual exceptions.
Deployers have separate disclosure duties. They must inform people when emotion-recognition or biometric-categorisation systems are used on them. They must disclose deepfake audio, image or video. They must also disclose AI-generated or manipulated text published to inform the public on matters of public interest when it has not undergone human review or editorial control and no person holds editorial responsibility.
The distinctions matter in a supplier review. A visible chatbot notice does not prove that exported synthetic media carries a machine-readable mark. A model provider’s documentation does not prove that the company deploying the feature has met its own disclosure duty.
The four-month grace period is not a general extension
The Omnibus created a limited transition for generative AI systems placed on the market before 2 August 2026. Providers of those existing systems have until 2 December 2026 to comply with the machine-readable marking and detection obligation in Article 50(2).
The European Commission’s guidance is explicit that this grace period applies only to that marking obligation for systems already on the market. It does not move every Article 50 requirement to December. Interactive AI disclosures and deployer labelling duties began applying on 2 August.
Content generated before 2 August does not need to be labelled retroactively, although the Commission encourages voluntary labelling where possible.
A vendor questionnaire should ask for working evidence
Procurement teams often ask broad questions about AI governance, model risk and testing. Article 50 benefits from a more concrete evidence request.
- Feature inventory and role decision. Identify every interactive, generative, biometric, emotion-recognition and content-publication feature. Record whether the organisation acts as provider, deployer or both.
- Production disclosure evidence. Capture the actual user interface showing when and how a person is informed that they are interacting with AI. A design document is weaker evidence than a tested production control.
- Marking evidence. Document the machine-readable mechanism applied to synthetic output, its supported formats, robustness and known failure modes.
- Downstream preservation tests. Verify what happens when content is downloaded, compressed, copied, forwarded, re-rendered or processed by another service. A mark that disappears in the normal product workflow does not provide the same assurance as one shown only in a laboratory export.
- Deployer labelling workflow. Define how deepfakes and unreviewed public-interest text receive a visible or otherwise perceivable disclosure before publication.
- Human-review boundary. Record who performs editorial review, what that review covers and who retains editorial responsibility. A nominal approval button may not describe meaningful review.
- Model and provider register. List the general-purpose models behind each feature and retain the documentation supplied by those providers. The downstream product still needs its own role and control analysis.
- Control ownership. Assign an owner and a regression test. Interface changes, model swaps and new export paths can silently remove a disclosure that originally worked.
Security teams have a role even when legal owns the interpretation
Legal counsel should decide disputed questions of scope. Security and product teams are still responsible for the system facts on which that decision depends: which model is used, what data reaches it, what the feature produces, who sees the output, where disclosures appear, whether a mark survives transformation and who can change the control.
The Commission says national market-surveillance authorities will perform most enforcement, with the AI Office and European Data Protection Supervisor responsible for defined parts of the framework. Penalties for Article 50 violations can reach €15 million or 3% of worldwide annual turnover, subject to the Act’s proportionality rules.
That legal exposure is one reason buyers are likely to push the question through their supply chain. The more immediate commercial problem is simpler: a supplier that cannot explain which obligation applies to which feature forces the customer to carry uncertainty it may not accept.
The deadline question is now an evidence question
The Digital Omnibus gave high-risk-system providers more implementation time. It did not turn August 2026 into a regulatory pause for every AI-enabled product.
For vendor reviews, the durable answer is not a blanket statement that the AI Act was delayed or that the product is low risk. It is a mapped set of features, roles, disclosures, marking controls, exceptions and test evidence. The organisations that build that record now will be able to answer regulators and customers from the same operational truth.
Sources
- Regulation (EU) 2026/1744, Digital Omnibus on AI, adopted 8 July 2026.
- European Commission questions and answers on Article 50 transparency obligations, checked 25 August 2026.
- European Commission guidelines on transparency obligations, last updated 6 August 2026.
- European Commission announcement on enforcement and transparency requirements, published 31 July 2026; no publication time provided.
- European Commission overview of the AI Act enforcement framework, last updated 24 August 2026.


