AI Governance · July 19, 2026 · 8 min de lecture
What the EU AI Act Delay Doesn't Delay
The headlines kept one word: "delay". But the delay only covers high-risk systems. Transparency obligations still apply on 2 August 2026.
The delay everyone reported is not the delay you got
On 16 June 2026, the European Parliament endorsed the AI Act simplification package. The Council gave its final green light on 29 June.
The headlines kept one word: delay.
What many teams concluded: "we have until 2027".
What is true: only for high-risk systems.
What applies in two weeks: the transparency obligations of Article 50.
The delay moved the part of the law few companies were applying. It left untouched the part that concerns all of them.
What was actually deferred
- Stand-alone high-risk systems (Annex III) → 2 December 2027
- AI embedded in already-regulated products (Annex I) → 2 August 2028
The reason is mundane: harmonised standards and national competent authorities were not ready. Brussels moved the deadline because the compliance tooling did not yet exist.
That deferral says nothing about the rest of the text.
What applies on 2 August 2026
Article 50 sets out four obligations. None was postponed.
1. Your conversational systems must declare themselves
Any AI interacting directly with a person must be designed so that the person knows they are dealing with a machine. A support chatbot, a booking assistant, a qualification agent on your website: all in scope.
2. Your generated content must be marked
Providers of generative systems must mark outputs in a machine-readable format, detectable as artificially generated. This is not a footnote on a page. It is technical marking inside the file.
One useful nuance: systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement.
3. Your deepfakes must be labelled
Any deployer publishing image, audio or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated.
4. Emotion recognition and biometric categorisation
Deployers must inform the people exposed. No exception, no transitional period.
Worth noting too: the June package introduced a new prohibition in Article 5 covering AI-generated non-consensual intimate imagery and child sexual abuse material.
The deadline nobody noticed
On 10 June 2026 the Commission published the Code of Practice on Transparency of AI-Generated Content. Signing it provides a documented route to compliance.
To appear on the initial list of signatories, the form must be submitted by 27 July 2026, 18:00 CEST.
That is eight days from the publication of this article.
Signing remains possible afterwards. But the initial list, the one published before the obligations enter into application, closes at the end of July.
What inaction costs
From 2 August 2026, national market surveillance authorities hold enforcement power over Article 50.
- Up to €15 million or 3% of total worldwide annual turnover, whichever is higher
- A separate €750,000 ceiling for EU institutions
Enforcement is decentralised: each member state acts through its own authority. Scrutiny will therefore vary considerably by country. That is not a reason to bet on your national regulator being lenient.
The real question isn't legal
Here is where most organisations solve the wrong problem.
They treat Article 50 as a compliance task: an audit, a line in a register, a vendor ticking boxes. Then they move on.
But all four obligations say the same thing: people have a right to know when a machine is talking to them, writing for them, or analysing them.
That is not a regulatory constraint. It is the precondition for using a technology your customers do not yet fully understand.
In the MAKIA method we call this useful transparency: transparency that informs a decision rather than covering a liability. It is built on four dimensions.
- Meaning — why does this AI exist in this customer journey? If you cannot say it in one sentence, no label will save you.
- Actors — who deploys, who answers, who decides? Article 50 distinguishes providers from deployers. Most companies are both, without having mapped it.
- Knowledge — do your teams know which tools generate what? This is the most common blocker, and it is not legal. It is documentary.
- Impact — what happens to the person once they know? If the answer is "they trust us less", the problem is not the label. It is the use case.
An organisation that cannot say where AI operates in its business does not have a compliance problem. It has a management problem.
Your checklist for the next two weeks
- Inventory. List every touchpoint where AI speaks to a human, generates published content, or analyses a person. Website, support, marketing, HR, sales.
- Qualify your role. Provider, deployer, or both, for each system. The obligations differ.
- Verify marking. Ask each vendor whether outputs are marked in machine-readable format, and from which version.
- Handle legacy systems. Those in production before 2 August have until 2 December 2026. Date them, or you won't know which are covered.
- Decide on the Code of Practice. Signing or not is a leadership decision, not a legal formality. Before 27 July if you want the initial list.
- Write the disclosures. They must be understandable by a customer, not by a lawyer. This is the most neglected and most visible deliverable.
What to take away
The delay bought time for companies building high-risk systems. There are not many of them.
For everyone else, those who plugged in a chatbot, automated content generation, or rolled out an internal assistant, nothing moved. The deadline is 2 August.
Transparency is not what you add to an AI system. It is what makes its use possible.