Exactly what starts tomorrow
From 2 August 2026, five separate transparency duties under Article 50 become enforceable. None of them is technically hard — but their absence is visible. A regulator can evidence a breach with a screenshot.
1. AI-interaction disclosure. A person using a chatbot or voice assistant must know they are not talking to a human. The exception is narrow: the situation must already be obvious to a reasonably well-informed, observant and circumspect person.
2. Marking of generated content. Providers of systems producing synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. A visible caption does not satisfy this; the marking must be embedded in the output itself.
3. Emotion recognition and biometric categorisation notice. Deployers must inform the individuals exposed to such systems.
4. Deepfake disclosure. Deployers generating or manipulating image, audio or video must disclose it, with an exception for creative and satirical works.
5. Public-interest text disclosure. Where AI-generated text is published on matters of public interest, this must be disclosed — unless the content underwent human review or editorial control.
One narrow transition exists: providers of systems placed on the market before 2 August 2026 have until 2 December 2026 to implement the technical marking solution. This applies only to provider-side marking, not to the other four duties.
Most guidance online is now out of date
A large share of the compliance material circulating today still says high-risk obligations begin on 2 August 2026. That is no longer correct.
The Digital Omnibus was approved by the European Parliament and the Council in June 2026 and enters into force three days after publication in the Official Journal. It moved stand-alone high-risk systems (Annex III) to 2 December 2027 and high-risk AI embedded in regulated products (Annex I) to 2 August 2028.
This is not relief — it is a price difference. Organisations that leave conformity work to the end of the runway buy the same documentation in a market with scarce assessors and scarce auditors, at several times the cost. Organisations that start now produce it at their own pace with their own people.
Why it binds a company in Türkiye, the Gulf or anywhere else
The Act's scope is not geographic; it follows the output. A provider established outside the EU falls within scope where the output of its system is used inside the European Union.
In practice: any company selling software to a European customer, serving a European parent, or opening a product to the European market is addressed by these duties — even if its own jurisdiction has no AI legislation at all.
There is a second, quieter effect. European buyers are pushing these duties into supplier contracts. So even where the Act does not apply to you directly, it reaches you through your customer's paperwork: tenders now ask suppliers for technical documentation, data-governance records and a defined human-oversight arrangement.
Penalties
Breach of the transparency duties carries a ceiling of €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. SMEs and start-ups face the lower of the two ceilings.
For comparison, prohibited practices reach €35 million or up to 7% of turnover. The GDPR ceiling was €20 million or 4%. This is among the heaviest penalty regimes Europe has enacted.
The same date also activates market-surveillance authority powers and penalty powers over general-purpose AI models. From 2 August there is both a rule and a body to enforce it.
Four things to do first
Inventory. Which AI systems are actually running in the organisation, including purchased tools? Most organisations that build this list find roughly twice what they expected — generative tools in marketing, a bot in the call centre, screening software in HR.
Classification. Which risk tier does each system fall into? Do this against the Act's own criteria, not by intuition.
Transparency gap. Does every customer-facing system disclose? Is generated content machine-readably marked?
Ownership. Who owns this file by name? A compliance programme without a named owner is not a programme.
Who must do what, and by when
| Date | What becomes enforceable | Who it binds |
|---|---|---|
| 2 August 2026 | Transparency duties (Art. 50) | Anyone generating AI content or interacting with users via AI |
| 2 December 2026 | Technical marking transition ends | Only providers of systems placed on market before 2 Aug 2026 |
| 2 December 2027 | Annex III high-risk obligations | HR, education, credit, insurance, law enforcement, critical infrastructure |
| 2 August 2028 | Annex I high-risk product obligations | AI embedded in products subject to third-party conformity assessment |