EU AI Act from 2 August 2026: what you must label and what got delayed
The short version. The date 2 August 2026 was mostly discussed in connection with high-risk systems, for which the EU reached political agreement on a delay in May 2026. What did not move are the transparency obligations under Article 50: people must know they are talking to a machine, and AI generated content has to be labelled. Penalties reach up to 35 million EUR or 7 % of global turnover.
What actually changed
The original timeline said obligations for standalone high-risk systems (Annex III) apply from 2 August 2026, and from 2 August 2027 for high-risk systems embedded in regulated products (Annex I).
On 7 May 2026 EU lawmakers reached political agreement on a revision pushing the high-risk deadline to December 2027. At the time of writing the formal adoption was still being completed, so do not treat it as settled.
The important part is what the delay left untouched. Article 50 transparency stayed on its original date of 2 August 2026, and that is the part affecting ordinary companies, not just those building models.
What it means for a normal business website
| Use case | What you have to do |
|---|---|
| Chatbot or AI assistant | the person must know they are writing to a machine |
| AI generated text, images, video | label the output as artificially created |
| Synthetic voice in a call or video | same, label it |
| Deepfake or altered footage of a real person | label clearly |
| Emotion recognition or biometrics | inform the people concerned |
The most common mistake we see is a chatbot with a human name and photo pretending to be support staff. The fix is trivial: one clear sentence in the opening message, not a note buried in the terms.
Provider versus deployer
- A provider develops the system and puts it on the market. Heavier obligations.
- A deployer uses it in their own operations. Fewer obligations, but not zero.
Most companies fall into the second group. If you have a business application built for you, settle contractually who handles documentation and labelling. It is cheaper at the start than during an inspection.
What I would do this week
- Inventory. Where do you use AI: chatbot, content generation, transcripts, email triage, product recommendations, CV screening.
- Label it. The chatbot gets a clear sentence. Generated content gets a note.
- Classify. For each item decide whether you are a provider or a deployer, and whether it touches a sensitive area such as HR, credit, education or biometrics.
- Supplier contracts. Who is responsible when the AI part is delivered by someone else.
- Write it down. One page is enough. In an inspection there is a difference between “we have thought this through” and “we do not know”.
FAQ
Do I have to label text that AI helped me write? The rule targets artificially generated published content. If you author and review the text yourself, that is a different situation. A transparent note still does not hurt.
We are small, does this apply to us? Article 50 has no size exemption. Scope depends on what you do, not how many people you employ.
Are fines in the tens of millions realistic? The ceiling targets the most serious breaches by large players. For a small company the realistic risk is a corrective order and lost customer trust.
Was everything delayed? No. The delay concerned high-risk obligations. Transparency stayed on 2 August 2026.
This summarises publicly available sources as of 28 August 2026 and is not legal advice. The formal adoption of the delay was still being finalised at the time of writing.