The EU AI Act Transparency Rules Went Live on August 2, 2026: What Changed
The heavy high-risk rules slipped to 2027. The disclosure rules did not slip at all, and they are the ones that touch normal teams using normal AI tools.

TL;DR
- Article 50 transparency duties, general-purpose AI enforcement powers, and the penalty regime became applicable on 2 August 2026.
- The AI Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, pushed Annex III high-risk duties to 2 December 2027 and Annex I embedded systems to 2 August 2028.
- Four disclosure duties matter to ordinary teams: chatbot disclosure, machine-readable marking of synthetic media, emotion and biometric notice, and deepfake labeling.
- Ceiling for a transparency breach is 15 million euro or 3 percent of worldwide turnover, whichever is higher.
What Became Applicable on 2 August 2026
Three things switched on: the transparency obligations in Article 50, the Commission's enforcement powers over providers of general-purpose AI models, and the penalty regime that gives those rules teeth. General-purpose AI obligations themselves had already applied since 2 August 2025, but until this month there was no enforcement machinery behind them.
For a company that builds nothing and only uses AI tools, the practical change is narrower than the headlines suggest, and real. If an AI system in your product talks to a person, that person has to be able to tell it is AI. If your system generates synthetic media, the output has to carry machine-readable marking. Those are engineering tickets, not policy papers.
What the Digital Omnibus Pushed Back
The AI Omnibus, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, moving the heaviest deadlines out by more than a year. Stand-alone high-risk systems under Annex III, which covers hiring, credit scoring, education, law enforcement, and critical infrastructure use cases, now apply from 2 December 2027. AI embedded in products already regulated under Annex I product safety law, such as medical devices and machinery, moves to 2 August 2028.
Do not read the omnibus as a pause on AI regulation in Europe. It deferred the compliance-heavy conformity assessment work. It left the transparency layer on its original schedule, which is exactly the layer most companies interact with.
Article 50 in Plain Language
Article 50 creates four disclosure duties, split between providers who build systems and deployers who put them into use. First, systems that interact directly with people must inform those people that they are dealing with AI, clearly and in a way that is distinguishable, unless it is obvious to a reasonably observant person. Second, providers of generative systems must mark synthetic audio, image, video, and text in a machine readable format that marks it as artificially generated.
Third, deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. Fourth, deployers who publish deepfakes must disclose that the content is artificially generated or manipulated, and text published to inform the public on matters of public interest carries a similar disclosure duty unless a human holds editorial responsibility for it.
Who owes what
If you build the system
- Tell users they are talking to AI
- Mark synthetic output machine-readably
- Make the marking robust and interoperable
- Document it before launch, not after
If you only deploy it
- Disclose deepfakes you publish
- Notice for emotion or biometric tools
- Disclose AI text on public-interest topics
- Keep a record of which tools touch customers
The Penalties Are Turnover-Based
A transparency breach can reach 15 million euro or 3 percent of worldwide annual turnover, whichever is higher. Prohibited practices, which are a separate and much narrower category, run to 35 million euro or 7 percent. Giving incorrect or misleading information to authorities runs to 7.5 million euro or 1 percent, with lower caps available for small and medium enterprises.
Enforcement will not start with a small team that forgot a chatbot banner. It will start with visible systems at scale. That is a reason to fix the cheap things now rather than a reason to assume nobody is looking.
This Applies to Companies That Never Trained a Model
Deployer duties attach to organisations that put AI systems into use inside the EU, and to non-EU companies whose AI output is used in the EU. Buying ChatGPT Enterprise or wiring Claude into a support flow does not move the disclosure duty onto Anthropic or OpenAI. The model provider owes its obligations, and you owe yours for how you deploy it.
In practice, the exposure for most teams is three surfaces: a customer-facing chatbot, an AI-assisted content pipeline, and any screening or scoring tool touching people. The first two are Article 50 territory today. The third becomes high-risk territory in December 2027.
The Checklist for This Quarter
Five items cover most of the exposure for a normal team. Inventory every AI system that touches a customer or an employee, with an owner name against each. Add a visible AI disclosure to any chatbot or voice agent, in the first message, not in a footer. Decide and document your policy on publishing AI-generated text and media, including who takes editorial responsibility. Check whether your generation vendors emit machine-readable provenance, and ask them in writing if the documentation does not say. Keep prompt and output logs for anything customer facing, because you cannot evidence a process you did not record.
That is a week of work for most companies, not a program. The logging item is the one people defer and later regret, since it is also what makes debugging and quality review possible. It pairs naturally with the practices in AI security and privacy for multi-provider workflows.
What This Means If You Run Several Providers
Multi-provider workflows raise the documentation bar, not the legal bar. The duties attach to the system and its use, not to how many models you route through, so running ChatGPT, Claude, and Gemini in parallel does not multiply your obligations. It does mean your inventory has more rows, and your provenance answer differs per vendor, since marking implementations are not uniform across providers.
Practically: record which provider produced which customer-facing output. If your tooling keeps side-by-side answers in one place, that record is a byproduct of the workflow. If your tooling is six browser tabs, it does not exist. That is the unglamorous compliance argument for a single hub over scattered tabs.
One Caveat
This is a practitioner summary, not legal advice, and the AI Act is being amended while it is being applied. The omnibus changed dates that had been fixed for two years, and guidance from the AI Office continues to land. Use this to scope work and brief your team, then confirm anything with money attached to it with counsel who follows the file.
FAQ
What changed in the EU AI Act on 2 August 2026?
Article 50 transparency obligations became applicable, enforcement powers over general-purpose AI providers began, and the penalty regime took effect.
Were the high-risk obligations delayed?
Yes. Regulation (EU) 2026/1744 moved Annex III stand-alone high-risk duties to 2 December 2027 and Annex I embedded systems to 2 August 2028. Transparency duties were not delayed.
Does this apply if we only use ChatGPT or Claude?
It can. Deployer duties attach to how you put AI into use in the EU, including customer-facing chatbots and published synthetic content, regardless of whose model sits underneath.
What are the penalties?
Up to 35 million euro or 7 percent of worldwide turnover for prohibited practices, up to 15 million euro or 3 percent for most other breaches including transparency, and up to 7.5 million euro or 1 percent for misleading information to authorities.
Do I have to label AI-generated blog posts?
Synthetic output must be machine-readably marked by the provider of the generative system. As a publisher, disclosure is required for deepfakes and for public-interest text unless a human takes editorial responsibility for the piece.