Skip to content
Beyond Prompt AI Studio

Law & regulation

The EU AI Act duty nobody postponed

August 4, 2026 · 12 min read · Beyond Prompt AI Studio

EU AI ActLawComplianceChatbots

Since June it has been clear: the EU AI Act's high-risk obligations were postponed - to 2 December 2027 for standalone systems, to 2 August 2028 for systems embedded in products. We covered that here ourselves in July, and it still holds. What many companies turned it into since then does not hold: the reading that the AI Act as a whole is now on hold. On 2 August 2026, the opposite happened. Article 50 - the duty that people must be able to recognise when they're talking to AI or looking at AI-generated content - was not postponed and became enforceable that day. Several law firms specialising in the AI Act consider it the single most broadly applicable obligation in the entire regulation - likely affecting more companies than any high-risk rule ever would have. On the same day, Germany's Bundesnetzagentur took over as the responsible market surveillance and complaints authority. This article sorts out what's acute now, what has until December, and how a correct piece of news ended up being widely misread.

Key points at a glance

  • Two different things got conflated in the coverage: only the high-risk obligations (Annex III/I) were postponed, through the 'Digital Omnibus' - legally binding since Parliament (16 June) and the Council (29 June) approved it in 2026. Article 50's transparency duties were never part of that and have applied since 2 August 2026.
  • Article 50 requires four things: chatbots and voice assistants must identify themselves as AI no later than the first interaction; AI-generated content (text, image, audio, video) must carry a machine-readable mark; anyone using emotion recognition or biometric categorisation must inform the people affected; deepfakes and AI-generated text on matters of public interest must be labelled as such.
  • Only one sub-duty carries a transition period: machine-readable marking (Article 50(2)) for generative systems already on the market before 2 August 2026 - for those, it applies from 2 December 2026. Chatbot disclosure, deepfake labelling, and the emotion-recognition notice duty apply immediately, with no grace period.
  • The exemption from chatbot disclosure only applies where it is already obvious to a reasonably well-informed, observant person that they're talking to a machine - a narrow bar. Specialist lawyers advise documenting that assessment rather than silently relying on the exemption.
  • Enforcement power arrived the same day as the obligation: fines up to €15 million or 3% of worldwide annual turnover, whichever is higher. In Germany, the Bundesnetzagentur has been the responsible market surveillance and national complaints authority (under the KI-MIG) since 2 August - Germany was the last major member state to settle this.
  • In practice that means for most companies: don't wait just because the big deadlines were postponed - this week, answer exactly one question: which of your own chatbots, text generators, or AI-assisted content fall under Article 50, and is the required disclosure already built in.

What actually happened on 2 August

Worth a quick recap of what we wrote here in July: the EU AI Act's high-risk obligations - risk management, human oversight, conformity assessment for systems like automated candidate pre-screening or creditworthiness checks - were postponed through the so-called 'Digital Omnibus'. The European Parliament approved it on 16 June 2026, the Council gave final green light on 29 June, and publication in the Official Journal followed in July. For standalone high-risk systems (Annex III), 2 December 2027 now applies instead of 2 August 2026; for systems embedded in regulated products (Annex I), 2 August 2028. That was accurate, well-sourced reporting - and it still is.

The problem isn't that story, it's its generalisation. Several law firms specialising in the AI Act have independently described the same pattern since early August: companies that took the - accurate - headline 'deadlines postponed' and drew the - inaccurate - conclusion that their entire AI Act programme could pause. Exactly into that blind spot, on 2 August 2026, something else became enforceable: the transparency duties under Article 50. They were never affected by the Digital Omnibus, because they were never part of the high-risk obligations to begin with. One analysis put it plainly: the high-risk regime moved; transparency and enforcement did not.

What Article 50 actually requires

Article 50 bundles four separate duties that hit different actors. Important for your own assessment: having a use case in just one of the four categories is enough to be in scope.

  • Chatbots and voice assistants (Article 50(1)): anyone operating a system that interacts directly with people must make clear, no later than the first contact, that it's AI - a simple disclosure notice is usually enough.
  • AI-generated content (Article 50(2)): providers of generative systems (text, image, audio, video) must mark their outputs as machine-generated in a machine-readable way - technically robust and interoperable, not just a note visible to humans.
  • Emotion recognition and biometric categorisation (Article 50(3)): anyone deploying such systems must inform the people affected by them.
  • Deepfakes and AI text on matters of public interest (Article 50(4)): anyone publishing manipulated or AI-generated content on such matters must disclose it - unless a human has taken editorial responsibility and substantively reviewed it.

For the typical mid-sized company, that means: a support chatbot on your own website falls under paragraph 1. A tool that automatically generates product descriptions, images, or marketing copy falls under paragraph 2. Neither is a rare, specialised setup - both are standard use cases that have sprung up in many small and medium-sized companies over the past two years, often without anyone consciously classifying them as an 'AI system within the meaning of the AI Act'.

The one exemption that genuinely exists - and it's narrower than it sounds

Article 50(1) has an exemption: the disclosure duty falls away where it is already obvious to a reasonably well-informed, observant and circumspect person that they're interacting with a machine. That sounds like a convenient way out for obviously technical interfaces. In practice, specialist lawyers advise caution: the bar is narrow, and the assessment of whether a given chatbot clears it should be documented, not silently assumed. A plainly designed FAQ bot with no disclosure at all isn't automatically 'obvious' AI just because it looks like one.

Two deadlines inside one duty - where most overviews get imprecise

If your first read on Article 50 leaves you thinking there's still a grace period after all, you're not entirely wrong - it just applies to exactly one of the four paragraphs, and only to part of the systems affected there. The machine-readable marking duty under paragraph 2 received a four-month transition period, out to 2 December 2026 - but only for generative AI systems already on the EU market before 2 August 2026. New systems launched from 2 August onward must ship with marking immediately, no grace period at all.

That distinction has real practical consequences: a company that's been using an existing text-generation tool since early 2026 has until December on the marking question. The same company, if it rolls out a new tool in September, doesn't have that time. And chatbot disclosure under paragraph 1, deepfake labelling under paragraph 4, and the notice duty for emotion recognition under paragraph 3 have no transition period at all - they've applied since 2 August, regardless of how old the system in use is. Anyone who filed 'Article 50' under 'has until December' has misread three of its four duties.

Who checks this in Germany - and why that was only just settled

On enforcement: the same 2 August that the duties took effect, the responsible authorities gained the power to check and penalise them. In Germany, that's been the Bundesnetzagentur since that date - as the central market surveillance authority and simultaneously the national point of contact and complaints office under the AI Management and Implementation Act (KI-MIG). Worth noting on the side: Germany was the last major EU member state to settle this national responsibility at all - the assignment wasn't finalised until shortly before the deadline. For companies, that concretely means: since 2 August there's a named address for both oversight and complaints, with the same fine framework as at EU level - up to €15 million or 3% of worldwide annual turnover.

What this means in practice

The point of this article isn't to raise an alarm. Compared to the high-risk requirements, Article 50's disclosure duties are technically modest - a visible disclosure notice on a chatbot is usually a matter of hours, not months. The point is that 'postponed' and 'done' are two different words, and the past few weeks have shown how easily the two get confused. Three concrete steps for this week:

  • Inventory, not assumption: put together a short list of every chatbot, text generator, image/content tool, and any emotion-recognition or biometric system currently in use - most companies have more of these in production than they realise without doing this exercise.
  • Assign the right deadline per system: immediate (chatbot disclosure, deepfake labelling, emotion-recognition notice) or December 2026 (marking, but only for generative systems already deployed before 2 August).
  • Don't guess on the 'obviousness' exemption - briefly document why a given system meets it or doesn't. If the Bundesnetzagentur ever asks, a written rationale counts for more than a retrospective judgement call.

And for context against our own July article: what we wrote there about the postponement of the high-risk deadlines was accurate, and still is. It just answers a different question than the one that's been acute since 2 August. Anyone who keeps the two layers apart - the high-risk obligations that genuinely were postponed, and the transparency duties that never were - has a complete and accurate picture of where the AI Act currently stands, without letting an accurate headline lure them into the wrong kind of inaction.

Frequently asked questions about Article 50 and the deadline postponement

Wasn't the whole EU AI Act postponed?

No, only part of it. Only the high-risk obligations were postponed (Annex III to December 2027, Annex I to August 2028) through the Digital Omnibus. Article 50's transparency duties - disclosure for chatbots, AI-generated content, deepfakes, and emotion recognition - were never affected and have applied since 2 August 2026.

Does Article 50 also apply to small companies with a simple chatbot?

Yes. The duty applies regardless of company size to any system that interacts directly with people. A simple FAQ chatbot on your own website falls under Article 50(1) and must identify itself as AI at first contact, unless that's already obvious.

Do we have until December 2026 to adapt our systems?

Only for one sub-aspect: machine-readable marking of generative content under Article 50(2), and even that only for systems already on the market before 2 August 2026. Chatbot disclosure, deepfake labelling, and the emotion-recognition notice duty apply now, with no transition period.

Who checks this in Germany, and what are the consequences?

Since 2 August 2026, the Bundesnetzagentur has been the responsible market surveillance and national complaints authority under the AI Management and Implementation Act (KI-MIG). Fines reach up to €15 million or 3% of worldwide annual turnover, whichever is higher.

Want to know which of your AI systems fall under Article 50 - and what should be handled this week?