Ship the chatbot notice. The Omnibus delay does not cover Article 50.

Date: 27 August 2026
For: Founders and operators of a SaaS product with an AI assistant or generative output that people in the EU can reach
Decision: Wait because high-risk rules were postponed, or treat 2 August 2026 as live and ship disclosure now?
Not legal advice. Operator memo from official EU pages. Get counsel if classification or a fine is on the line.

Recommendation

Ship a first-interaction notice this week if you have not already: the person is talking to an AI system, not a human. Put it in the product, not in a privacy policy.

Do not read the Digital Omnibus as a pause. Regulation (EU) 2026/1744 moved the high-risk stack. It did not move Article 50. The Commission said so on 31 July 2026. Its enforcement page, last updated 24 August 2026, still lists chatbot disclosure, deepfake labels, and machine-readable marks among the rules that became enforceable on 2 August.

Split the work. This week: the Article 50(1) notice, plus any deployer labels you already owe (deepfakes; emotion recognition or biometric categorisation; unreviewed public-interest AI text). By 2 December 2026: machine-readable marking under Article 50(2) if the generative system was on the market before 2 August 2026. Later launches do not get that grace period. Not this quarter unless you are actually in Annex III: high-risk rules apply from 2 December 2027 for stand-alone Annex III systems, and from 2 August 2028 for high-risk AI inside Annex I products.

A US, Canadian, or UK headquarters does not take you out. Article 2 of the AI Act covers providers who place a system on the Union market wherever they sit, and providers in a third country whose output is used in the Union.

Evidence

The AI Act entered into force on 1 August 2024. The general application date was always 2 August 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was adopted on 8 July 2026, published on 24 July, and entered into force on 27 July. Recital 40 moves Annex III stand-alone high-risk use cases (employment, education, credit, essential services, certain biometrics) to 2 December 2027, and high-risk AI inside Annex I products to 2 August 2028, because standards and national authorities were not ready. It keeps the general application date at 2 August 2026.

Recital 38 is the only Article 50 concession: four extra months, only for providers who had already placed a generative system on the market before 2 August, and only for the marking duty in Article 50(2). The Commission’s Article 50 FAQ (updated 24 July 2026) repeats that split. Content generated before 2 August does not have to be labelled retroactively. If your team saw “high-risk delayed to 2027” and closed the ticket, they read the wrong article.

The FAQ and the 20 July 2026 guidelines set out four live duties. Providers must design the system so people are informed they are interacting with AI, unless that is obvious to a reasonably well-informed person in that context (Article 50(1)). The FAQ’s tests: it is an AI system; it is built for a genuine two-way exchange; the AI itself talks to the person; the other party is a natural person. Background or machine-to-machine systems are out. The “obvious” exception is to be read narrowly. Notice must land at the start of the first interaction. Providers must also mark synthetic audio, image, video, or text so it can be detected as AI-generated (Article 50(2)), with carve-outs for short codes, source code, output that never reaches a person, and assistive standard editing that does not substantially change the input.

Deployers have separate duties. Tell people exposed to emotion recognition or biometric categorisation that the system is running (Article 50(3)). Label deepfakes on first exposure with a label a person can see or hear (Article 50(4)). A hidden watermark from the model vendor is not enough. Artistic or satirical work still needs a disclosure. Label AI text published to inform the public on a public-interest topic unless someone with judgement reviewed the substance and an editor takes responsibility. Spell-check is not review. Do not assume a vendor’s mark covers your UI.

From 2 August the AI Office and national authorities have their powers. National market surveillance authorities handle most Article 50 cases. The AI Office handles GPAI models, systems from the same provider or group as the underlying model, and systems inside designated very large platforms or search engines. A public complaints tool is live. Article 50-type fines can reach €15 million or 3% of worldwide turnover, whichever is higher.

More than 180 organisations had signed the Code of Practice on Transparency of AI-generated Content by the 31 July press note (the code page says about 190 by late July). On 8 July the Commission found the code adequate for Articles 50(2), (4), and (5). Signing is voluntary and is not conclusive proof of compliance. It also does not operationalise the Article 50(1) chatbot notice.

Risks

Waiting because “the Act was delayed” is the failure this memo exists to kill. High-risk moved. Transparency did not. A footer or a line in the Terms will not match “first interaction, clear and distinguishable.” A product named “AI Copilot” is not automatically obvious if a careful person could think they reached support staff.

Treating 2 December as the only date is the other common miss. That date is the grace period for legacy generative systems on machine-readable marks. Chatbot notice and deepfake labels are already due. Marks on systems launched on or after 2 August are already due. The opposite error is building a full Annex III programme for a support bot. Hiring tools, credit scoring, and education scoring are the high-risk list. Confirm classification. Wrapping a frontier model does not label your first message.

What I could not verify. No official announcement, as of 27 August 2026, of a first Article 50 fine or a named investigation against a specific startup. I did not recount the live signatory list (Commission figures: more than 180 / about 190). I did not fetch the full consolidated Article 50 and Article 99 texts from EUR-Lex HTML; duties and fine ceilings come from the Commission FAQ, the enforcement page, and the Omnibus recitals. I cannot judge whether your UI is “obvious.”

What to do this week

  1. Inventory. Every EU-reachable surface that talks back, generates media, scores a person, or infers emotion or a biometric category. Mark provider vs deployer; shipped before or after 2 August; likely 50(1), 50(2), 50(3), 50(4), or Annex III. Unsure plus EU users: assume Article 2(1)(a) or (c).
  2. Ship the 50(1) notice. First message or persistent chrome: “This is an AI assistant. You are not speaking with a person.” Visible without a click. Keep a dated screenshot and the commit hash.
  3. Label what you publish. AI image, audio, or video that could pass as real needs a human-readable label on first view. AI-written public-interest text with no editor on the substance needs a label too.
  4. Open a 2 December ticket for marks. If you generate user-facing content and the system was on the market before 2 August, assign an owner. Decide this month whether to sign the Code of Practice or document an equivalent method.
  5. Skip the high-risk build unless the inventory says Annex III. Hiring, education access, or credit is a 2027 programme and a lawyer, not this week’s ship.
  6. Write the buyer answer. Article 50 in force since 2 August 2026; high-risk Annex III from 2 December 2027; you disclose AI interaction in-product; legacy marking is scheduled by 2 December 2026.

The cheap move is a notice and a screenshot. The expensive move is explaining why you thought 2027 applied to a chatbot.

Sources

  1. European Commission, enforcement framework of the AI Act, updated 24 August 2026. https://digital-strategy.ec.europa.eu/en/policies/enforcement-ai-act
  2. European Commission, enforcement starts 2 August, 31 July 2026. https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august
  3. European Commission, Article 50 FAQ, updated 24 July 2026. https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
  4. European Commission, Article 50 guidelines, 20 July 2026. https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems
  5. European Commission, Code of Practice on Transparency of AI-generated Content, updated 31 July 2026. https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
  6. European Commission, Code of Practice adequacy opinion, 9 July 2026. https://digital-strategy.ec.europa.eu/en/library/commission-opinion-assessment-code-practice-transparency-ai-generated-content
  7. Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L 2026/1744, 24 July 2026. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32026R1744
  8. AI Act Service Desk, Article 2 (scope). https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-2
# Ship the chatbot notice. The Omnibus delay does not cover Article 50.

**Date:** 27 August 2026  
**For:** Founders and operators of a SaaS product with an AI assistant or generative output that people in the EU can reach  
**Decision:** Wait because high-risk rules were postponed, or treat 2 August 2026 as live and ship disclosure now?  
**Not legal advice.** Operator memo from official EU pages. Get counsel if classification or a fine is on the line.

## Recommendation

Ship a first-interaction notice this week if you have not already: the person is talking to an AI system, not a human. Put it in the product, not in a privacy policy.

Do not read the Digital Omnibus as a pause. Regulation (EU) 2026/1744 moved the high-risk stack. It did not move Article 50. The Commission said so on 31 July 2026. Its enforcement page, last updated 24 August 2026, still lists chatbot disclosure, deepfake labels, and machine-readable marks among the rules that became enforceable on 2 August.

Split the work. This week: the Article 50(1) notice, plus any deployer labels you already owe (deepfakes; emotion recognition or biometric categorisation; unreviewed public-interest AI text). By 2 December 2026: machine-readable marking under Article 50(2) if the generative system was on the market before 2 August 2026. Later launches do not get that grace period. Not this quarter unless you are actually in Annex III: high-risk rules apply from 2 December 2027 for stand-alone Annex III systems, and from 2 August 2028 for high-risk AI inside Annex I products.

A US, Canadian, or UK headquarters does not take you out. Article 2 of the AI Act covers providers who place a system on the Union market wherever they sit, and providers in a third country whose output is used in the Union.

## Evidence

The AI Act entered into force on 1 August 2024. The general application date was always 2 August 2026. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was adopted on 8 July 2026, published on 24 July, and entered into force on 27 July. Recital 40 moves Annex III stand-alone high-risk use cases (employment, education, credit, essential services, certain biometrics) to 2 December 2027, and high-risk AI inside Annex I products to 2 August 2028, because standards and national authorities were not ready. It keeps the general application date at 2 August 2026.

Recital 38 is the only Article 50 concession: four extra months, only for providers who had already placed a generative system on the market before 2 August, and only for the marking duty in Article 50(2). The Commission’s Article 50 FAQ (updated 24 July 2026) repeats that split. Content generated before 2 August does not have to be labelled retroactively. If your team saw “high-risk delayed to 2027” and closed the ticket, they read the wrong article.

The FAQ and the 20 July 2026 guidelines set out four live duties. Providers must design the system so people are informed they are interacting with AI, unless that is obvious to a reasonably well-informed person in that context (Article 50(1)). The FAQ’s tests: it is an AI system; it is built for a genuine two-way exchange; the AI itself talks to the person; the other party is a natural person. Background or machine-to-machine systems are out. The “obvious” exception is to be read narrowly. Notice must land at the start of the first interaction. Providers must also mark synthetic audio, image, video, or text so it can be detected as AI-generated (Article 50(2)), with carve-outs for short codes, source code, output that never reaches a person, and assistive standard editing that does not substantially change the input.

Deployers have separate duties. Tell people exposed to emotion recognition or biometric categorisation that the system is running (Article 50(3)). Label deepfakes on first exposure with a label a person can see or hear (Article 50(4)). A hidden watermark from the model vendor is not enough. Artistic or satirical work still needs a disclosure. Label AI text published to inform the public on a public-interest topic unless someone with judgement reviewed the substance and an editor takes responsibility. Spell-check is not review. Do not assume a vendor’s mark covers your UI.

From 2 August the AI Office and national authorities have their powers. National market surveillance authorities handle most Article 50 cases. The AI Office handles GPAI models, systems from the same provider or group as the underlying model, and systems inside designated very large platforms or search engines. A public complaints tool is live. Article 50-type fines can reach €15 million or 3% of worldwide turnover, whichever is higher.

More than 180 organisations had signed the Code of Practice on Transparency of AI-generated Content by the 31 July press note (the code page says about 190 by late July). On 8 July the Commission found the code adequate for Articles 50(2), (4), and (5). Signing is voluntary and is not conclusive proof of compliance. It also does not operationalise the Article 50(1) chatbot notice.

## Risks

Waiting because “the Act was delayed” is the failure this memo exists to kill. High-risk moved. Transparency did not. A footer or a line in the Terms will not match “first interaction, clear and distinguishable.” A product named “AI Copilot” is not automatically obvious if a careful person could think they reached support staff.

Treating 2 December as the only date is the other common miss. That date is the grace period for legacy generative systems on machine-readable marks. Chatbot notice and deepfake labels are already due. Marks on systems launched on or after 2 August are already due. The opposite error is building a full Annex III programme for a support bot. Hiring tools, credit scoring, and education scoring are the high-risk list. Confirm classification. Wrapping a frontier model does not label your first message.

**What I could not verify.** No official announcement, as of 27 August 2026, of a first Article 50 fine or a named investigation against a specific startup. I did not recount the live signatory list (Commission figures: more than 180 / about 190). I did not fetch the full consolidated Article 50 and Article 99 texts from EUR-Lex HTML; duties and fine ceilings come from the Commission FAQ, the enforcement page, and the Omnibus recitals. I cannot judge whether your UI is “obvious.”

## What to do this week

1. **Inventory.** Every EU-reachable surface that talks back, generates media, scores a person, or infers emotion or a biometric category. Mark provider vs deployer; shipped before or after 2 August; likely 50(1), 50(2), 50(3), 50(4), or Annex III. Unsure plus EU users: assume Article 2(1)(a) or (c).
2. **Ship the 50(1) notice.** First message or persistent chrome: “This is an AI assistant. You are not speaking with a person.” Visible without a click. Keep a dated screenshot and the commit hash.
3. **Label what you publish.** AI image, audio, or video that could pass as real needs a human-readable label on first view. AI-written public-interest text with no editor on the substance needs a label too.
4. **Open a 2 December ticket for marks.** If you generate user-facing content and the system was on the market before 2 August, assign an owner. Decide this month whether to sign the Code of Practice or document an equivalent method.
5. **Skip the high-risk build unless the inventory says Annex III.** Hiring, education access, or credit is a 2027 programme and a lawyer, not this week’s ship.
6. **Write the buyer answer.** Article 50 in force since 2 August 2026; high-risk Annex III from 2 December 2027; you disclose AI interaction in-product; legacy marking is scheduled by 2 December 2026.

The cheap move is a notice and a screenshot. The expensive move is explaining why you thought 2027 applied to a chatbot.

## Sources

1. European Commission, enforcement framework of the AI Act, updated 24 August 2026. https://digital-strategy.ec.europa.eu/en/policies/enforcement-ai-act
2. European Commission, enforcement starts 2 August, 31 July 2026. https://digital-strategy.ec.europa.eu/en/news/commission-starts-enforcing-ai-act-rules-and-new-transparency-requirements-2-august
3. European Commission, Article 50 FAQ, updated 24 July 2026. https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
4. European Commission, Article 50 guidelines, 20 July 2026. https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems
5. European Commission, Code of Practice on Transparency of AI-generated Content, updated 31 July 2026. https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
6. European Commission, Code of Practice adequacy opinion, 9 July 2026. https://digital-strategy.ec.europa.eu/en/library/commission-opinion-assessment-code-practice-transparency-ai-generated-content
7. Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L 2026/1744, 24 July 2026. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex%3A32026R1744
8. AI Act Service Desk, Article 2 (scope). https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-2