โ† Agent Governance collection
Agent Governance Regulation Compliance

The AI Act Deadline That Didn't Move: Article 50 Is Live, Whether or Not Your Deployment Is "High-Risk"

The Digital Omnibus pushed high-risk AI Act obligations to 2027 and 2028. Nobody deferred Article 50. Disclosure, content marking, and deepfake labeling have applied since August 2026, and the relief headline is why most compliance teams haven't checked.

Christopher Wakare
Updated
8 min read
Agent Governance

The compliance memo went out in late July: the AI Act deadline moved, standalone high-risk systems now have until December 2027, embedded high-risk systems in regulated products until August 2028. Legal forwarded it to the business unit heads. Two years of runway, more or less. Nobody flagged that the memo covered one part of the regulation and left another part running exactly on schedule.

That second part is Article 50. It never depended on a high-risk classification in the first place, which is exactly why the deferral never touched it.

The reveal

Article 50 of the EU AI Act sets transparency obligations by output type, not by risk tier: disclosing an AI interaction to the person on the other end, marking AI-generated or manipulated content in machine-readable form, and labeling deepfakes and AI-generated public-interest text. None of that sits inside the Annex III or Annex I high-risk categories the Digital Omnibus deferred. It has applied since 2 August 2026 and applies today, regardless of whether a single system in your environment is classified high-risk.

Praxikon reports that Regulation (EU) 2026/1744, the Digital Omnibus, was published 24 July 2026 and entered into force three days later, on 27 July. It moved two dates that matter to a specific category of AI deployment: standalone high-risk systems under Annex III to 2 December 2027, and high-risk systems embedded in regulated products under Annex I to 2 August 2028. Both are real, both are welcome relief for anyone running a system that actually falls in those categories. Neither date has anything to do with Article 50.

Two tracks, one press cycle

The confusion is structural, not careless. The Digital Omnibus is one regulation. It amended one set of dates. But it landed in a news cycle that talks about "the AI Act deadline" as a single thing, and a single thing is easier to report than two tracks moving at different speeds.

Track Governs Original date Status after Digital Omnibus
High-risk, standalone (Annex III) Systems classified high-risk on their own: recruitment screening, credit scoring, and similar 2 August 2026 Deferred to 2 December 2027
High-risk, embedded (Annex I) High-risk AI embedded inside a regulated product, e.g. machinery or medical devices 2 August 2027 Deferred to 2 August 2028
Article 50 transparency AI-interaction disclosure, synthetic content marking, deepfake and public-interest text labeling 2 August 2026 Not deferred. In force since 2 August 2026
Article 50(2) legacy marking grace period Machine-readable marking format only, for systems already live before 2 August 2026 2 August 2026 Grace period extended to 2 December 2026

Read the third row again. Article 50's original date and its post-Omnibus date are the same date. That is not a rounding error in this article; it is the entire point. The obligation was never gated by high-risk status, so there was nothing in the Digital Omnibus's high-risk deferral mechanism that could reach it.

What Article 50 actually requires, independent of risk classification

Article 50 covers three distinct disclosure duties, and a manufacturer or distributor doesn't need a single Annex III or Annex I system in its environment to owe any of them.

  1. AI-interaction disclosure. A person interacting with an AI system (a chatbot fielding a supplier query, an AI-driven support line) has to be told they're talking to a system, unless it's obvious from context.
  2. Synthetic content marking. Content generated or manipulated by AI, whether audio, image, video, or text, has to carry a machine-readable marker identifying it as artificially generated.
  3. Deepfake and public-interest text labeling. Deepfakes, and AI-generated text published to inform the public on matters of public interest, need a disclosure that the content is artificially generated.

None of the three checks a risk tier. They check what the system does: does it talk to a person, does it produce synthetic media, does it publish AI-written text framed as informing the public. A Finance Director asked to evidence AI use across EU operations for an auditor or a customer's procurement questionnaire needs an answer to those three questions before touching the high-risk Annex III/Annex I classification exercise at all, because the classification exercise is the wrong first filter for Article 50 exposure.

The one date that did move, and exactly how far it moved

There is a real, narrow grace period inside Article 50, and it's worth being precise about its edges because the failure mode here is the same one that created the confusion in the first place: reading one accurate detail and generalizing it past where it applies.

Cloud Security Alliance Labs reports that Article 50(2)'s requirement for machine-readable marking of AI-generated content carries a grace period for systems already in operation before 2 August 2026: providers get until 2 December 2026 to bring the marking format itself into compliance. That is the only piece of Article 50 with a moved date. It covers the technical marking mechanism for pre-existing systems. It does not cover whether the disclosure obligation exists, and it does not cover new systems deployed after August 2026, which owe compliant marking from day one.

Scope check

2 December 2026 applies here only to the Article 50(2) machine-readable marking format for systems already live before 2 August 2026. It's the legacy-system grace period, not a new deadline and not a general extension. Any other obligation with the same date is outside what this article covers.

Why "the deadline moved" became "we have more time," full stop

Compliance teams didn't misread the Digital Omnibus by accident. The regulation's own framing, and the coverage of it, described a deferral of "the AI Act's" high-risk obligations. Reasonable shorthand for a journalist. Dangerous shorthand for a Head of Compliance building a Q4 action list, because it invites exactly the generalization this article is correcting: high-risk got relief, therefore the Act got relief, therefore Article 50 got relief.

The correction is not a technicality. A manufacturer running an AI-driven supplier chatbot, an internal document-drafting agent that produces text later shared externally, or a marketing function using generative tools for public-facing content has live Article 50 exposure today, independent of whatever else in its AI portfolio might or might not be high-risk. The classification question and the disclosure question are answered by different parts of the same regulation, on different timelines, and treating them as one timeline is the specific error the Digital Omnibus coverage set up.

What a Head of Compliance checks this quarter

Four questions separate a defensible position from an exposed one, and none of them require finishing a high-risk classification exercise first.

  1. Does any customer- or supplier-facing system involve a person talking to an AI without being told? If yes, that's live Article 50(1) exposure today, not a 2027 problem.
  2. Does any system produce synthetic audio, image, video, or text that leaves the organization? Marketing content, generated reports, synthetic voice for IVR: each needs a machine-readable marker.
  3. Was that system live before 2 August 2026? If yes, the marking format itself has until 2 December 2026. The disclosure obligation underneath it does not get that extension.
  4. Can you produce, on request, a record of which systems were assessed and when? "We have more time" is not evidence of compliance. A dated assessment is.

That fourth question is where this stops being a legal-reading exercise and becomes an operational one. An assessment that lives in someone's inbox from July isn't a record a Finance Director can hand to an auditor with a name and a timestamp attached. It's a memo. The gap between "we looked at this" and "here is who looked at this, when, and what they found" is the same gap that shows up everywhere else AI governance gets tested under scrutiny: a correct decision with no named approver is not a defensible one.

Free ยท 3 minutes
Is there a named owner behind every AI-driven decision?

An AI-driven exception approval and an Article 50 disclosure check are the same kind of unowned line item until someone assigns a name to it. The Decision Latency Diagnostic scores where that ownership gap sits, across Signal, Route, Approve, Execute, and Audit.

Take the diagnostic โ†’

Frequently asked questions

Did the EU AI Act deadline move in 2026?

Only part of it. Regulation (EU) 2026/1744, the Digital Omnibus, published 24 July 2026 and in force from 27 July 2026, deferred high-risk obligations: standalone high-risk systems under Annex III now have until 2 December 2027, and high-risk systems embedded in regulated products under Annex I until 2 August 2028. Article 50 transparency obligations were not part of that deferral. They have applied since 2 August 2026 and still apply today, regardless of whether a system is classified as high-risk.

What does Article 50 of the EU AI Act require?

Article 50 sets transparency obligations independent of high-risk classification: disclosing to a person that they are interacting with an AI system rather than a human, marking AI-generated or manipulated content (audio, image, video, or text) in a machine-readable format, and labeling deepfakes and AI-generated text published to inform the public on matters of public interest. These obligations attach to the type of system output, not to a risk tier, which is why the high-risk deferral never touched them.

What is the Article 50(2) grace period and who does it cover?

Article 50(2) requires machine-readable marking of AI-generated or manipulated content. For systems already in operation before 2 August 2026, providers have a grace period to add that machine-readable marking, extended to 2 December 2026. This grace period is narrow: it covers the marking format for legacy systems, not the underlying disclosure and labeling obligations, which have applied since 2 August 2026 regardless of when a system went live.

Does a manufacturer with no high-risk AI systems still have EU AI Act exposure?

Yes, if any AI-facing system interacts with a person, generates synthetic content, or produces text, audio, image, or video output that could be mistaken for human-created work. Article 50 applies by output type, not by risk classification, so a manufacturer with zero Annex III or Annex I systems can still carry live transparency obligations today. The Digital Omnibus deferral applies to a different set of rules and does not create a general compliance pause.

Ask whoever owns your AI compliance calendar which date they're tracking for Article 50. If the answer is 2027 or 2028, that's the gap this article exists to close.

An assessment nobody signed isn't evidence.

OpsGrid keeps the approval, the approver, and the record in one write path to Business Central, so an AI-driven exception is defensible the day it happens, not the day someone reconstructs it.

See the governance-first approach to BC AI

The Execution Edge

Monthly. For operations leaders building faster on AI. Real case studies, system blueprints, and tools, no fluff.

Your subscription could not be saved. Please try again.
Your subscription has been successful.