What actually happened on 2 August
Worth a quick recap of what we wrote here in July: the EU AI Act's high-risk obligations - risk management, human oversight, conformity assessment for systems like automated candidate pre-screening or creditworthiness checks - were postponed through the so-called 'Digital Omnibus'. The European Parliament approved it on 16 June 2026, the Council gave final green light on 29 June, and publication in the Official Journal followed in July. For standalone high-risk systems (Annex III), 2 December 2027 now applies instead of 2 August 2026; for systems embedded in regulated products (Annex I), 2 August 2028. That was accurate, well-sourced reporting - and it still is.
The problem isn't that story, it's its generalisation. Several law firms specialising in the AI Act have independently described the same pattern since early August: companies that took the - accurate - headline 'deadlines postponed' and drew the - inaccurate - conclusion that their entire AI Act programme could pause. Exactly into that blind spot, on 2 August 2026, something else became enforceable: the transparency duties under Article 50. They were never affected by the Digital Omnibus, because they were never part of the high-risk obligations to begin with. One analysis put it plainly: the high-risk regime moved; transparency and enforcement did not.
What Article 50 actually requires
Article 50 bundles four separate duties that hit different actors. Important for your own assessment: having a use case in just one of the four categories is enough to be in scope.
- Chatbots and voice assistants (Article 50(1)): anyone operating a system that interacts directly with people must make clear, no later than the first contact, that it's AI - a simple disclosure notice is usually enough.
- AI-generated content (Article 50(2)): providers of generative systems (text, image, audio, video) must mark their outputs as machine-generated in a machine-readable way - technically robust and interoperable, not just a note visible to humans.
- Emotion recognition and biometric categorisation (Article 50(3)): anyone deploying such systems must inform the people affected by them.
- Deepfakes and AI text on matters of public interest (Article 50(4)): anyone publishing manipulated or AI-generated content on such matters must disclose it - unless a human has taken editorial responsibility and substantively reviewed it.
For the typical mid-sized company, that means: a support chatbot on your own website falls under paragraph 1. A tool that automatically generates product descriptions, images, or marketing copy falls under paragraph 2. Neither is a rare, specialised setup - both are standard use cases that have sprung up in many small and medium-sized companies over the past two years, often without anyone consciously classifying them as an 'AI system within the meaning of the AI Act'.
The one exemption that genuinely exists - and it's narrower than it sounds
Article 50(1) has an exemption: the disclosure duty falls away where it is already obvious to a reasonably well-informed, observant and circumspect person that they're interacting with a machine. That sounds like a convenient way out for obviously technical interfaces. In practice, specialist lawyers advise caution: the bar is narrow, and the assessment of whether a given chatbot clears it should be documented, not silently assumed. A plainly designed FAQ bot with no disclosure at all isn't automatically 'obvious' AI just because it looks like one.
Two deadlines inside one duty - where most overviews get imprecise
If your first read on Article 50 leaves you thinking there's still a grace period after all, you're not entirely wrong - it just applies to exactly one of the four paragraphs, and only to part of the systems affected there. The machine-readable marking duty under paragraph 2 received a four-month transition period, out to 2 December 2026 - but only for generative AI systems already on the EU market before 2 August 2026. New systems launched from 2 August onward must ship with marking immediately, no grace period at all.
That distinction has real practical consequences: a company that's been using an existing text-generation tool since early 2026 has until December on the marking question. The same company, if it rolls out a new tool in September, doesn't have that time. And chatbot disclosure under paragraph 1, deepfake labelling under paragraph 4, and the notice duty for emotion recognition under paragraph 3 have no transition period at all - they've applied since 2 August, regardless of how old the system in use is. Anyone who filed 'Article 50' under 'has until December' has misread three of its four duties.
Who checks this in Germany - and why that was only just settled
On enforcement: the same 2 August that the duties took effect, the responsible authorities gained the power to check and penalise them. In Germany, that's been the Bundesnetzagentur since that date - as the central market surveillance authority and simultaneously the national point of contact and complaints office under the AI Management and Implementation Act (KI-MIG). Worth noting on the side: Germany was the last major EU member state to settle this national responsibility at all - the assignment wasn't finalised until shortly before the deadline. For companies, that concretely means: since 2 August there's a named address for both oversight and complaints, with the same fine framework as at EU level - up to €15 million or 3% of worldwide annual turnover.
What this means in practice
The point of this article isn't to raise an alarm. Compared to the high-risk requirements, Article 50's disclosure duties are technically modest - a visible disclosure notice on a chatbot is usually a matter of hours, not months. The point is that 'postponed' and 'done' are two different words, and the past few weeks have shown how easily the two get confused. Three concrete steps for this week:
- Inventory, not assumption: put together a short list of every chatbot, text generator, image/content tool, and any emotion-recognition or biometric system currently in use - most companies have more of these in production than they realise without doing this exercise.
- Assign the right deadline per system: immediate (chatbot disclosure, deepfake labelling, emotion-recognition notice) or December 2026 (marking, but only for generative systems already deployed before 2 August).
- Don't guess on the 'obviousness' exemption - briefly document why a given system meets it or doesn't. If the Bundesnetzagentur ever asks, a written rationale counts for more than a retrospective judgement call.
And for context against our own July article: what we wrote there about the postponement of the high-risk deadlines was accurate, and still is. It just answers a different question than the one that's been acute since 2 August. Anyone who keeps the two layers apart - the high-risk obligations that genuinely were postponed, and the transparency duties that never were - has a complete and accurate picture of where the AI Act currently stands, without letting an accurate headline lure them into the wrong kind of inaction.