EU AI Act August 2026: What Changed and What Was Delayed

For most of 2026, the EU AI Act headlines have been about delay. The Digital Omnibus package pushed the regulation's high-risk regime back by more than a year, and many compliance programs quietly moved the AI Act down their priority list. That is a costly misreading of what happened. While the high-risk obligations moved, the transparency obligations in Article 50 did not, and they have applied since 2 August 2026. If your organization operates a customer-facing chatbot, produces synthetic media, or deploys emotion-recognition tools, you are already inside an enforceable regime with meaningful fines attached.
Here is what the simplification package actually changed, which duties took effect in August, and why the transparency rules land on the desks of security and awareness teams, not just in-house counsel.
What the Digital Omnibus Actually Postponed
The legislative sequence wrapped up at the end of June. The European Parliament endorsed the AI simplification package on 16 June 2026, and the Council gave its final green light on 29 June 2026. The changes take effect following publication in the Official Journal of the European Union.
The headline change is timing for high-risk AI. Obligations for standalone high-risk systems listed in Annex III, think recruitment screening, credit scoring, or biometric identification, are postponed to 2 December 2027. Obligations for AI embedded in products regulated under Annex I, such as machinery or medical devices, move further out to 2 August 2028.
Reading those dates, it is tempting to conclude that the whole regulation is on hold. It is not. The prohibitions on unacceptable-risk practices have applied since early 2025, the AI literacy duty in Article 4 still applies although the omnibus softened it into a best-effort obligation, and, most immediately, the Article 50 transparency obligations proceeded exactly on schedule.
Article 50 Applied on Schedule from 2 August 2026
Article 50 is the AI Act's transparency layer, and the European Commission has spelled out in detail how it expects these obligations to work in practice for deepfakes, chatbots, and AI-generated text. Three duties matter for most organizations:
- Chatbot disclosure (Article 50(1)). People interacting with an AI system must be informed that they are dealing with a machine, unless that is obvious from the context. Customer-service bots, virtual assistants, and AI agents embedded in your website or product all qualify.
- Emotion recognition and biometric categorisation notices (Article 50(3)). Organizations deploying systems that infer emotions or categorise people based on biometric data must inform the individuals exposed to them.
- Deepfake labeling (Article 50(4)). Deployers who generate or manipulate image, audio, or video content that would falsely appear authentic must disclose that the content has been artificially generated or manipulated.
These are not soft expectations. Breaches of the transparency obligations can draw fines of up to EUR 15 million or 3 percent of global annual turnover, whichever is higher, enforced by national market surveillance authorities.
One Grace Period: Machine-Readable Marking
There is a single carve-out worth knowing about. Article 50(2) requires providers of generative AI systems to mark AI-generated content in a machine-readable format so that it can be detected as synthetic. For systems already on the market, the omnibus grants a grace period until 2 December 2026 to implement that marking. Newly placed systems, and every other Article 50 duty, follow the August date.
To help organizations get the details right, the Commission has also published a Code of Practice on Transparency of AI-Generated Content, with 22 July 2026 as the deadline for the initial signatory list. Signing is voluntary, but the code is currently the clearest available signal of what regulators will treat as good-faith compliance with the marking and labeling duties.
Why This Is a Security Issue, Not Just a Legal One
It would be easy to file Article 50 under legal housekeeping. Security and awareness teams should resist that instinct, for three reasons.
First, your employees are now part of the control. Disclosure duties are operational, not contractual. The product manager configuring a chatbot, the marketing team publishing an AI-generated campaign video, and the HR analyst piloting an emotion-analytics tool each need to know the duty exists and how to satisfy it. If staff do not recognize when a system they deploy triggers a transparency obligation, no policy document will save you. That knowledge gap is exactly what structured security awareness training is designed to close, and it is worth adding an AI transparency module to your program now rather than after the first complaint.
Second, deepfake labeling cuts both ways. The law raises the baseline for legitimate content, but attackers do not label their deepfakes. Voice clones impersonating executives and fabricated video in business email compromise schemes remain among the fastest-growing social engineering vectors, and Article 50 does nothing to stop a criminal group that was never going to comply. Employees should be trained to treat labeling as a floor, not a guarantee: unlabeled content is not automatically authentic, and verification rituals for payment changes and urgent executive requests matter more than ever.
Third, transparency failures are reputational events. A chatbot that pretends to be human or an undisclosed synthetic ad is the kind of story that travels fast, and national authorities now have both a mandate and a fine framework to respond. The compliance evidence you keep, which systems were assessed, who was trained, when disclosures were implemented, will shape how any inquiry ends.
If you are building the broader picture of what the AI Act means for defenders, our earlier overview of the EU AI Act's implications for security teams covers the risk-tier structure that the omnibus has now reshuffled.
What This Means for Your Organization
- Do not stand down on the AI Act. The high-risk regime moved to December 2027 and August 2028, but Article 50 transparency has applied since 2 August 2026.
- Inventory your transparency triggers. List every chatbot, generative tool, emotion-recognition system, and synthetic-media workflow in use, including shadow deployments in marketing and HR.
- Implement disclosures now. Chatbot notices, deepfake labels, and emotion-recognition information duties are enforceable, with fines of up to EUR 15 million or 3 percent of global turnover.
- Use the grace period wisely. Providers with generative systems already on the market have until 2 December 2026 for machine-readable marking, and the Commission's Code of Practice shows what good looks like.
- Train for both sides of the deepfake problem. Employees must apply labels where the law requires them, and must never assume unlabeled content is real. Awareness training and documented completion records cover the compliance duty and the attack vector at the same time.


