On 2 August 2026 the European Commission's AI Office, together with national authorities, began enforcing the AI Act. Chatbots must say they are chatbots. Deepfakes must be labelled. AI-generated or altered content must carry machine-readable marks so it can be detected automatically.
Less discussed: the same legislative package pushed the high-risk system obligations out to 2 December 2027, and high-risk AI inside regulated products to 2 August 2028.
So the enforceable rule today is about disclosure. The rules about AI deciding who gets a loan, a job, or a place at a university are sixteen months further out than originally scheduled.
What became enforceable
Three obligations, all of them about telling people what they are looking at.
Interactive systems must identify themselves. If a person is talking to an AI system, the system has to make that clear, unless it is obvious from context. This covers support chatbots, voice agents, and anything conversational sitting in front of a customer.
Synthetic media must be labelled. Images, video and audio that were generated or edited with AI need a visible disclosure to the person viewing them.
Generated content needs machine-readable marks. Beyond the visible label, the content itself has to carry a marker that detection tools can read. Watermarking, metadata, provenance signals. This is the part most teams have not built.
The Commission also published a Code of Practice on transparency of AI-generated content, which more than 180 organisations had signed by the end of July 2026. Signing is voluntary. The obligation is not.
Penalties for breaching the transparency provisions run up to 15 million euro or 3 percent of global annual turnover, whichever is higher.
What moved, and by how much
The Digital Omnibus on AI, proposed in November 2025 and confirmed through 2026, deferred the high-risk timeline:
- Standalone high-risk systems under Annex III now apply from 2 December 2027, not 2 August 2026. Hiring and candidate screening tools, credit scoring, biometric identification, access to education and essential services. A sixteen month extension.
- High-risk AI embedded in regulated products under Annex I now applies from 2 August 2028. Medical devices, machinery, and other products already covered by EU product legislation. A twelve month extension.
Nothing in the obligations themselves changed. Documented risk management, data governance, technical documentation, automatic logging, human oversight, accuracy and robustness safeguards. The work is the same work. The date is later.
Deferral is also not repeal. Prohibited practices have been banned since February 2025, and general-purpose AI transparency requirements since August 2025. Both are already in force.
Why the split happened
This is not Brussels going soft. It is the predictable result of a regulation containing two very different kinds of obligation.
"Did you label it" is verifiable by an auditor in an afternoon. It is a product change with a clear pass or fail.
"Is your risk management system adequate for a model you cannot fully interpret" is a research problem wearing a compliance costume. It depends on harmonised standards that were not ready, on evaluation methods that are still contested, and on documentation practices most engineering teams have never had to produce.
Guess which one shipped on time.
What to do this quarter
The disclosure obligations are closeable now. Concretely:
- Inventory every customer-facing AI surface. Chat widgets, voice agents, email drafting that sends on your behalf, in-product assistants. Most companies find more than they expected, because several were added by different teams.
- Add the disclosure where it is first seen, not buried in a terms page. A line in the chat header does the job.
- Find every place you publish AI-generated or AI-edited media. Marketing assets, product imagery, avatars, synthetic voice. Label them, and set the provenance metadata your generation tool supports.
- Write down who owns this. Enforcement questions land on someone. Decide who before they arrive.
That is a few weeks of work for most organisations, not a programme.
What to start now for the harder deadline
December 2027 sounds distant. It is five quarters, and the obligations touch how you build, not just what you ship.
If you deploy AI anywhere near credit decisions, insurance underwriting, employment, or access to essential services, three things are worth starting while the deadline is still comfortable:
Logging and traceability. Automatic logging of system operation is required, and retrofitting it into a system that was never designed to record its own decisions is expensive. Building it in from the next release is close to free.
Data governance. Knowing where training and reference data came from, what is in it, and how it is maintained. This is the same work that makes a model better, which is the rare compliance requirement that pays for itself.
Overlap with what you already run. Documented risk management, access control, and change management overlap heavily with an ISO 27001 programme. Doing them together is materially cheaper than doing them twice. See ISO 27001, SOC 2 and the Rest for how those pieces sit together.
The short version
Do not budget as though your compliance work is finished because you added a banner. The disclosure obligations are the part you can close this quarter. The high-risk obligations are the part that will change how you build, and you now have a known date and no excuse for treating it as far away.
Which half is your roadmap actually planning for?
Sources: European Commission, "Commission starts enforcing AI Act rules and new transparency requirements", 31 July 2026; Cooley and other legal analyses of the Digital Omnibus on AI and the revised high-risk timeline. Accessed 2026-08-10. This is general information, not legal advice. Confirm your own obligations with qualified counsel.
Fares Aouani Cherif is managing partner at Qartmina, an AI and data consulting practice working across MENA and Africa.