negocio · 4 min read
EU AI Act delayed, but transparency rules still start on 2 August
The EU has pushed the AI Act's high-risk obligations back to 2027, yet Article 50 transparency duties apply from 2 August 2026. What businesses must do now.
On 29 June 2026 the Council of the EU gave its final green light to the Digital Omnibus package, postponing the AI Act’s high-risk obligations to December 2027. The headline many executives took away — “Europe delayed the AI law, we can relax” — is wrong. The Article 50 transparency obligations were not touched, and they apply from 2 August 2026. If your company runs a customer-facing chatbot, generates images or copy with AI, or publishes synthetic content, you have less than four weeks to get compliant.
What Brussels actually approved
The European Parliament endorsed the package on 16 June and the Council adopted it on 29 June 2026, as reported by DLA Piper and Morgan Lewis. Two calendar changes matter for most businesses:
- Annex III high-risk systems (recruitment screening, credit scoring, education, critical infrastructure…) move from 2 August 2026 to 2 December 2027 — a 16-month reprieve.
- High-risk AI embedded in Annex I regulated products (medical devices, toys, radio equipment…) moves from 2027 to 2 August 2028.
The package also adds a new prohibited practice — AI systems that generate non-consensual intimate imagery or child sexual abuse material — as Gibson Dunn details.
If you use AI to screen CVs or assess credit risk, the deferral buys you genuine breathing room. It is, however, the only part of the timeline that moved.
What did not change: mandatory transparency from 2 August
Article 50 of Regulation (EU) 2024/1689 becomes applicable on 2 August 2026 exactly as planned. In practice, four duties:
Chatbots and virtual assistants
Any AI system that interacts directly with people must disclose that it is an AI, unless that is obvious to a reasonably informed person. The classic support bot with a human name and no disclosure stops being legal.
Synthetic content and technical marking
Systems that generate audio, images, video or text must mark their outputs in a machine-readable format so they are detectable as AI-generated. One concession: for systems already on the market before 2 August, this marking duty is deferred to 2 December 2026.
Deepfakes and informational text
Anyone publishing deepfakes or AI-generated text meant to inform the public on matters of general interest must say so, unless there is human editorial review and identified responsibility.
Emotion recognition and biometric categorisation
Companies deploying these systems must inform the people exposed to them, on top of GDPR compliance.
Fines up to €15 million — and a regulator already at work
Breaching Article 50 can cost up to €15 million or 3% of global annual turnover, whichever is higher, as Economist & Jurist notes. In Spain the supervisor is AESIA (the Spanish Agency for the Supervision of Artificial Intelligence, created by Royal Decree 729/2023 and based in A Coruña), working alongside the data protection authority and other sector regulators.
This is not a toothless future rule: the enforcement machinery exists and the date is firm.
What we would do this week (and do with our clients)
At Evicron, an AI and custom software studio in Barcelona, we have been building assistants and automations for companies across Europe since 2019 — and this month every client conversation lands on the same topic. Our practical checklist:
- Inventory every AI system that interacts with people or generates content: chatbots, voice assistants, image or copy generators.
- Classify which fall under Article 50 and which were high-risk (the latter now have until December 2027).
- Add the disclosures to your interfaces: a clear “you are talking to an AI assistant” in the first message solves most cases.
- Push your vendors for machine-readable marking (watermarking) of outputs and the documentation that proves it — and keep it on file.
- Train your teams in marketing, HR and product: most breaches come from people publishing content without knowing the rule exists.
We are not a law firm and this is not legal advice — the fine print of each case belongs to your lawyers. Our side is the technical one, and there we know the terrain: we audit systems through our AI consulting service, implement disclosures and marking in product via applied AI, and get teams ready with tailored AI training.
Four weeks is plenty — if you start today
Bringing a chatbot or a content pipeline in line with Article 50 is not a months-long project: once the inventory is done, most companies close it in days. The expensive scenario is discovering in September that your assistant has been non-compliant for weeks.
If you want us to review which of your systems are affected and how to adapt them in time, get in touch. The discovery session is free and we reply within 24 hours.