The Deadline That Didn’t Move

The Deadline That Didn’t Move

by Victor Angelier

The EU AI Act’s transparency rules arrive on 2 August 2026 and a disclosure label is not an output control

 

Overview

For most of the past eighteen months, 2 August 2026 was the date that organised enterprise AI planning. It carried the EU AI Act’s high-risk obligations, and with them a large share of the budget, roadmap attention and board time allocated to AI governance.

 

That date has now partly moved, and it has moved as hard law rather than as a negotiating text. Regulation (EU) 2026/1744, the Digital Omnibus on AI, dated 8 July 2026,  was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, three days later, under an urgency provision written into the regulation itself precisely because the deadline it amends was days away. It defers the high-risk regime for stand-alone Annex III systems to 2 December 2027, and for AI embedded in regulated Annex I products to 2 August 2028.

 

The temptation is to read this as a reprieve. It is not. What arrives on 2 August 2026 is the Article 50 transparency regime and unlike the high-risk rules, which capture a defined set of systems, the transparency rules reach almost every organisation putting generative AI near a customer, a candidate or a published word.

 

Whether you are reading this before or after 2 August, the gap this article describes does not close on that date. There is a second, quieter problem underneath the first. Article 50 obliges you to disclose that content is AI-generated. It does not oblige you to make sure it is correct. An organisation can be fully compliant on 2 August and still publish confidently wrong material, correctly labelled. For a CEO, that is the more expensive failure mode and the one no regulation currently closes for you.

 

What actually applies, and when

 

On 20 July 2026 the European Commission adopted the final version of its Guidelines on the implementation of the transparency obligations under Article 50, fifty-one pages, published less than two weeks before those obligations begin to apply. The Guidelines are non-binding, and only the Court of Justice can give an authoritative interpretation, but national market surveillance authorities and the AI Office can be expected to follow them. The Commission also confirmed that the accompanying Code of Practice on Transparency of AI-Generated Content has been assessed as adequate; external legal analysis of the final text reads it as the only EU-wide recognised route for demonstrating compliance with the marking and labelling obligations, though that characterisation comes from law-firm commentary on a non-binding instrument rather than from an authoritative Commission statement.

 

Four dates now matter, and they are routinely collapsed into one in board papers:

 

  • 2 August 2026 — the general Article 50 obligations. Informing people that they are interacting with an AI system; disclosing the use of emotion recognition and biometric categorisation; labelling deep fakes and AI-generated text published on matters of public interest. These fall substantially on deployers, not only on providers.

  • 2 August 2026 / 2 December 2026 — machine-readable marking under Article 50(2). Providers of systems generating synthetic audio, image, video or text must mark outputs in machine-readable form. Systems placed on the market on or after 2 August 2026 must comply from that date. Only systems already on the market before 2 August 2026 receive the grace period to 2 December 2026. This is a narrower concession than it is usually reported to be.

  • 2 December 2027 — high-risk obligations for stand-alone Annex III systems, covering areas including employment, education, critical infrastructure and law enforcement.

  • 2 August 2028 — high-risk obligations for AI embedded in regulated Annex I products.

The Omnibus also introduced a new prohibition, at the Parliament’s initiative, on AI systems generating non-consensual intimate imagery and child sexual abuse material, and softened the AI literacy duty under Article 4 to an obligation of measures rather than of outcome — organisations must document training and awareness, not certify individual competence.

 

One further point deserves attention from anyone sitting on a content backlog. On the reading offered by Bird & Bird in its first analysis of the final Guidelines, image, audio and video deep fakes generated before 2 August do not require retroactive labelling, because the relevant date is the date of generation; for text on matters of public interest the relevant date is the date of publication, so material drafted in July and scheduled for August falls inside the obligation unless the editorial-control exception applies. That reading is a law firm’s interpretation of a non-binding guideline rather than settled law, and organisations with large scheduled pipelines should take their own advice. If it holds, content calendars are now a compliance surface.

 

A note on preparation time, because it will come up in the room. The 2 August date for Article 50 is not new — it has been fixed since the AI Act entered into force in 2024, and no organisation can claim to have been ambushed by it. What arrived late was the interpretation: the final Guidelines on 20 July, thirteen days before application, and the Omnibus itself on 27 July, six days before.

 

Organisations that waited for authoritative guidance before starting are now in a genuinely compressed position. Market surveillance authorities will likely weigh that in early enforcement, but goodwill is not a legal position, and it is not a defence anyone should plan around.

 

Opposing views: stand down, or press on

 

  • View 1 – “The date moved, so the programme can breathe.” Some leadership teams read the Omnibus as evidence that Brussels blinked, and are rephasing AI governance spend into 2027. The argument is not unreasonable: harmonised standards are behind schedule, and building to a moving target wastes capital.

  • View 2 – “Nothing moved that touches our actual exposure.” Others note that most enterprises are deployers rather than providers of high-risk systems, and that the deployer obligations arriving on 2 August are precisely the ones affecting marketing, HR, customer service and corporate communications — the functions least likely to have a named AI governance owner.

The reconciliation is unglamorous: separate the clocks. Deferred high-risk obligations justify re-phasing conformity assessment and technical documentation work. They justify nothing at all in the disclosure, labelling and provenance workstream. And as the deferral’s own drafters were careful to note, the underlying obligations have not changed — risk management frameworks, technical documentation and governance structures still take considerable time to build.

The gap the regulation does not close

Article 50 is a provenance and disclosure regime. It asks whether a reader can tell that something was machine-generated. It does not ask whether it is true.

This reading follows from Article 50 as drafted; it has not been tested before the Court of Justice, and it is an analytical position rather than settled law. But it is the position a board should plan against, because the alternative is assuming a duty of accuracy that the text does not currently impose. That distinction is where governance work actually begins. NIST’s Generative AI profile under the AI Risk Management Framework is more direct on the point than the European texts: it recommends assessing accuracy, reliability and authenticity of generated output against known ground truth using multiple evaluation methods, and reviewing and verifying the sources and citations in the output — not once before deployment, but as continuous monitoring.

Nor is verification a solved engineering problem. Peer-reviewed work presented in 2026,  including fact-level, black-box detection methods that build knowledge graphs from a model’s own output to score individual claims, and formal multiple-testing frameworks for hallucination detection,  is simultaneously evidence that detection is improving and evidence that it remains an open research question, with competing methods and no settled benchmark. Any organisation relying on a single automated check to catch every error is overestimating the state of the art.

The practical consequence is that validation shifts from a question about the model to a question about the chain. Not “do I trust this answer?” but “can I show, step by step, where this came from and how it was checked?”

Opposing views: edge labelling vs. pipeline provenance

 

  • View 1 – Handle it at the edge. Legal and communications add a disclosure banner at the point of publication. This is fast, cheap and demonstrably compliant on the face of it.

  • View 2 – Build it into the pipeline. Provenance signals, model identity, prompt lineage and review status travel with the content from generation onward, through internal gateways and shared logging services.

Edge labelling satisfies the letter of the obligation and almost nothing else. It produces no evidence when a claim is later disputed, and it does not survive contact with agentic systems, where content is generated, transformed and acted upon several steps before any human sees it. We have argued elsewhere that agentic AI changes the governance question from what did we approve to what did it do, with the security exposure that follows. Provenance built into the pipeline is the same architectural instinct applied to content.

 

A practical blueprint for the C-suite

  1. Split the compliance register by date, not by regulation. One page: 2 August 2026, 2 December 2026, 2 December 2027, 2 August 2028. Most of the confusion in the current cycle comes from treating “the AI Act” as a single deadline.

  2. Establish where you are a deployer. Providers get the headlines; deployers get the August obligations. Inventory customer-facing chat, CV screening and candidate assessment, synthetic media in campaigns, emotion recognition in any form, and published text on matters of public interest.

  3. Check the marking obligation against your release dates. Anything placed on the market on or after 2 August 2026 does not get the December grace period. This is where the “we have until December” assumption most often fails.

  4. Make provenance a property of the pipeline. Abstract model access behind internal services so that marking, logging and review status attach at generation, not at publication. This is the same AI-agnostic architecture discipline that protects against vendor churn, applied to evidence rather than cost.

  5. Define what “checked” means, per use case, in writing. A tiered standard: unreviewed internal drafting; single-model output with human sign-off; multi-model cross-checking with source verification for anything carrying legal, financial or reputational weight. Ambiguity here is what produces the confidently wrong published document.

  6. Keep logs you would be willing to show. The high-risk logging duties under Article 12 have been deferred, but the evidentiary logic has not. In a dispute, model confidence proves nothing; a traceable trail proves something.

  7. Name the accountable role. Disclosure obligations that belong to “the business” belong to nobody. Compliance here is a person with a mandate, not a plugin.

Opposing views: cost of verification vs. cost of being wrong

  • View 1 – Verification is overhead. Running outputs through multiple models and human review multiplies token cost and latency, and slows the throughput that made AI attractive in the first place.

  • View 2 – Verification is insurance priced per document. The unit economics look different once a single unchecked output has produced a regulatory finding, a withdrawn publication or a professional liability claim.

Both are right at different points on the risk curve. The decision a CEO actually has to make is not whether to verify but where the threshold sits — and to set that threshold explicitly, rather than leaving it to whoever is closest to the deadline.

How TLA&C can help

TLA&C works with leadership teams to translate AI regulation into an operating model rather than a legal memo: mapping obligations to the systems and functions that actually carry them, designing provenance and logging into the architecture instead of bolting disclosure onto the publishing step, and setting verification thresholds that match commercial and reputational exposure. For CEOs, the value is not in reading the Guidelines. It is in knowing which of your workflows changed on 2 August, who owns them, and what evidence you could produce if you were asked.

See also our Data Compliance practice.

 

Bibliography