Geeks Invention
Back to Blogs

The EU AI Act Deadline That Wasn't Delayed

In late 2025 the European Commission proposed the Digital Omnibus, and the headline that reached most engineering teams was simple: the AI Act has been delayed. A lot of roadmaps quietly relaxed on the strength of that sentence.

Some of it was delayed. Not the part that applies to almost everybody.

2 August 2026 remained a live compliance date, and the obligations that landed on it — the Article 50 transparency rules — are the ones with the widest reach, because they do not depend on your system being high-risk. They apply to ordinary products: a support chatbot, a generated image, a synthetic voice, a marketing page written by a model.

What actually moved, and what didn't

The Omnibus agreement deferred the heavy conformity-assessment obligations for high-risk systems:

  • Annex III stand-alone high-risk systems — deferred to 2 December 2027.
  • Annex I AI embedded in regulated products — deferred to 2 August 2028.

These are the expensive ones: risk management systems, technical documentation, data governance files, human oversight design, conformity assessment. If you build credit scoring, recruitment screening, biometric identification, or AI inside a regulated medical or industrial product, you have received a genuine extension. Use it — the work is substantial and the extension is not generous relative to it.

What did not move:

  • Article 50 transparency obligations stayed on the original 2 August 2026 timeline.
  • A new Article 5 prohibition covering AI systems that generate non-consensual intimate imagery — including where such output is a "reasonably foreseeable and reproducible outcome" of normal operation — carries its own 2 December 2026 date and applies regardless of risk classification.
  • The prohibitions and AI-literacy duties that took effect in February 2025 have been in force throughout.

One more detail worth holding onto: the deferrals take legal effect only on formal adoption and publication in the Official Journal. The relief is real, but it is procedural, and it is narrower than "the AI Act has been delayed" suggests.

What Article 50 asks for

Article 50 is a disclosure regime rather than an engineering-controls regime. It is built on a simple principle: people should know when they are dealing with a machine, and know when content was made by one. Four duties matter in practice.

Tell people they are talking to an AI

Any system that interacts directly with a person must make that clear, unless it is obvious to a reasonably observant user. A chat widget labelled only with a friendly first name does not clear this bar. The disclosure has to be timely — at the start of the interaction, not buried in a policy page.

Mark synthetic content machine-readably

Providers of generative systems must mark outputs — audio, image, video, text — in a format that machines can detect, and that is robust enough to survive ordinary handling. In practice this means content credentials and provenance metadata rather than a visible watermark alone.

Disclose deepfakes and synthetic media

Deployers who publish AI-generated or manipulated image, audio or video resembling real people, places or events must disclose that it is artificial. There are carve-outs for obviously artistic and satirical work, but they are narrower than most marketing teams assume.

Disclose AI-written text on matters of public interest

AI-generated text published to inform the public on matters of public interest must be disclosed, unless a human took editorial responsibility for it. That last clause is the practical route for most publishers — but it requires a real review step and a named owner, not a nominal one.

A short audit you can run this week

Most teams are closer to compliant than they fear, and further than they think from being able to demonstrate it. The gap is usually documentation, not behaviour.

  • Inventory every surface where a model touches a user. Chat, email drafting, voice, generated imagery, product descriptions, translated copy, summaries. Assistants that grew out of a side project are the ones people forget.
  • Check the first screen of each conversational surface for a plain-language statement that the user is interacting with an AI system.
  • Check what your generation pipeline emits. If you produce synthetic media, is provenance metadata attached at generation, and does it survive your CDN, your image resizer and your social publishing path? Stripped metadata is the most common technical failure here.
  • Name the human editor for any AI-assisted public-interest content, and keep a record that review happened.
  • Write it down. A one-page register of AI-touching surfaces, the disclosure each carries and its owner is what turns "we comply" into something you can show.

If you are not in the EU

Territorial scope follows the user, not the company. If your system's output is used in the EU, you are in scope regardless of where you are incorporated — which is why US firms have spent much of 2026 mapping obligations they initially read past.

There is also a practical argument that outlives any single regulation. Disclosure is becoming the default expectation across jurisdictions, and provenance metadata is becoming infrastructure. The teams building it in now are doing one piece of work. The teams waiting are scheduling the same work later, under deadline, across more surfaces.

The takeaway

"The AI Act was delayed" is true of the obligations most companies do not have, and false of the obligations nearly all of them do. If your product talks to people or generates content, the relevant date has already passed — and the remediation is a week of disclosure work and documentation, not a compliance programme.

We help product teams inventory their AI surfaces, ship the disclosure and provenance layer, and document it well enough to show someone. Get in touch.

This article is a summary written by engineers, not legal advice. Confirm your specific obligations with counsel.