arrow_back All insights Both pillars

EU AI Act Article 50: the deadline that didn't move

By NovaVision AI·Compliance & AI·5 min read

In July, the EU pushed the AI Act's high-risk deadlines back by more than a year. Plenty of companies read the headline, concluded the Act had been postponed, and moved AI governance down the list.

That was the wrong conclusion, and it is no longer an academic point. Article 50 came into force on 2 August 2026. It is in active enforcement. Non-compliance runs to €15 million or 3% of worldwide annual turnover, whichever is higher.

Note: This is a practical overview, not legal advice. Obligations and guidance continue to evolve, so confirm your specifics against current official sources and, where the exposure is material, qualified counsel.

What actually moved

The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and entered into force three days later. It is law, not a proposal. Worth stating plainly, because a good deal of commentary written in the spring still describes it as provisional.

It deferred two things. Obligations for standalone high-risk systems under Annex III moved from 2 August 2026 to 2 December 2027. Obligations for high-risk AI embedded in products already covered by EU product-safety law, under Annex I, moved to 2 August 2028.

If you are building a system that screens job applicants, scores creditworthiness, or sits inside critical infrastructure, that is real relief. You have been handed fifteen extra months.

What did not move

Three things stayed exactly where they were.

Article 50 is the one that catches the most companies, because it does not care whether you consider yourself an AI company.

What Article 50 actually requires

Four situations trigger it.

The Commission has adopted guidelines for providers, deployers and national authorities, sitting alongside a Code of Practice on Transparency of AI-generated Content. The guidance exists. Nobody is going to accept ambiguity as a defence.

Who this catches that does not expect it

The high-risk category is narrow, and the companies inside it generally know who they are. Article 50 is broad, and it lands on organisations that do not think of themselves as building AI at all.

If you added a support chatbot last year, Article 50 applies to you. If your marketing team generates images or copy with a commercial model, it applies. If a product feature summarises, drafts or rewrites text for users, it applies.

Most of those teams are not tracking AI regulation, because they do not believe they are in scope. That is exactly the gap the deferral headlines widened.

Where the marking requirement actually bites

Of the four obligations, machine-readable marking is the one that needs engineering rather than a policy document and a disclaimer.

The marking has to be applied at generation, it has to be machine-readable, and it has to survive whatever your pipeline does next. Content gets resized, transcoded, cropped, pasted into a CMS, pushed through a CDN. Every one of those steps is a place a marking can be stripped.

Which makes this a data and pipeline problem rather than a legal one. Someone has to know where generated content enters your systems, what happens to it downstream, and where the marking survives or dies. In most organisations, nobody currently holds that map.

A short readiness check

Most of this fits in an afternoon.

  1. Inventory every AI-touching surface. Chatbots, generated copy, generated images, summarisation features, anything calling a model. Include the ones marketing set up without telling IT.
  2. For each, decide which of the four obligations applies. Most will be interaction disclosure or synthetic content marking.
  3. Check what marking your model provider already applies, and whether it survives your pipeline. Test it, do not assume.
  4. Confirm your chatbot discloses itself at the start of an interaction, not buried in a footer.
  5. Write down who owns this. Not a team. A person.

If step one takes longer than an afternoon, that is your actual finding. An organisation that cannot list its AI surfaces cannot evidence compliance for any of them.

For the wider picture of what the Act asks of engineering teams, our plain-English build checklist covers the risk tiers and the practices underneath them. If the inventory is the part you are stuck on, that is the kind of groundwork our data and analytics practice does as a matter of course.

The uncomfortable summary

The deferral was real, and it mattered for high-risk systems. It also gave a great many companies permission to stop paying attention to a regime that was already live, already enforced, and carrying penalties large enough to matter on a balance sheet.

If you relaxed in July, the question worth asking this week is a narrow one: what generates content in our product, and does anyone here know whether it is marked?

Not sure what Article 50 covers in your stack?

Book a free 30-minute call. We will walk your AI surfaces, flag what needs disclosure or marking, and tell you plainly what is already fine.