Written by Jeremy Souffir Founder, JTS Tech Services

The short version: two different EU AI Act deadlines got tangled together in the coverage, and the wrong one stuck. The AI Omnibus, in force from 27 July 2026, did push the Act's high-risk obligations back — standalone high-risk systems to 2 December 2027, high-risk components embedded in regulated products to 2 August 2028. That was the headline. What did not move is Article 50, the transparency and information block, which became generally applicable and enforceable by national authorities on 2 August 2026, along with the enforcement powers over general-purpose AI and the penalty regime behind them. Article 50 does not care whether your system is high-risk. If you run a customer-facing chatbot, or you publish AI-generated content, it is aimed squarely at you, and it is live now.
We're engineers, not lawyers
Nothing here is legal advice, and the compliance call for your specific business belongs to counsel who can look at your actual footprint. What we can tell you is the engineering-and-inventory shape of the problem, because that is the part that reliably takes longer than anyone budgets and the part that is usually nobody's job. Get the inventory done first; it makes the legal conversation short and cheap instead of long and speculative.
What does Article 50 actually require?
Four duties, split between the people who build AI systems (providers) and the people who deploy them (deployers). Most businesses reading this are deployers using somebody else's model, which is a lighter load than it sounds — but not zero.
- Systems that interact directly with people must make clear the person is dealing with an AI, unless it's obvious from context — and the disclosure has to land at the latest at the first interaction, clearly and distinguishably, meeting accessibility requirements
- Systems generating synthetic audio, image, video or text must mark their outputs in a machine-readable format that's detectable as artificially generated
- Deployers must disclose deepfakes — artificially generated or manipulated content depicting real people, places or events
- Deployers of emotion-recognition or biometric categorisation systems must inform the people exposed to them, and stay compliant with EU data protection law
There is one carve-out worth knowing for the content duty: text published to inform the public on matters of public interest is exempt where it has undergone substantive human review and someone holds editorial responsibility for it. The word doing the work there is substantive. A human clicking approve on a queue of generated drafts is not the thing being described.

We're not in Europe. Does this reach us?
Probably, and this is where the Canadian and US businesses we talk to are most consistently wrong. The Act's obligations attach to putting an AI system on the EU market or to the system's output being used in the EU — not to where your company is incorporated. A Toronto brand with a support chatbot that answers a customer in Berlin is inside the scope of the first duty. A B2B company running AI-generated content that reaches EU readers is inside the scope of the second. "We don't have an EU entity" is not the test, and it has never been the test under this family of European regulation.
The reasoning that gets businesses caught
"The big AI Act deadline was delayed to 2027, so we've got time." Both halves of that are true and the conclusion is still wrong, because the delayed part and the applicable part are different parts. The businesses most exposed to this are the ones that moved fastest on AI — a support agent live in eight markets, a content pipeline producing hundreds of pages a month, an AI voice on the phone line. Every one of those is an Article 50 surface, and every one of them was shipped by a team who reasonably assumed the compliance conversation was scheduled for next year.
What are the penalties, really?
Breaches of the transparency obligations carry fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. We want to be honest about how that lands rather than use it as a scare: nobody expects a mid-market brand with an undisclosed chatbot to be the opening enforcement action. Regulators starting a new regime go after clear, visible, deliberate cases first. The realistic near-term risk for most readers isn't a headline fine — it's a customer complaint or a competitor's tip putting you into a national authority's process, and the cost being months of a founder's attention rather than a number on an invoice. That's still a bad outcome, and it's avoidable for a fraction of what avoiding it later costs.
What does the actual work look like?
Overwhelmingly inventory, then small fixes. The reason it stalls in most companies is that no single person can answer the first question — where is AI touching a human in our business? — because the answers were shipped independently by marketing, support, and whoever wired up a tool one afternoon.
- List every place AI output reaches a person: chat widget, in-app assistant, phone or voice bot, email autoresponders, help-centre answers, product descriptions, blog and social content, generated imagery
- Include the ones nobody registered as AI — the vendor feature that quietly turned on, the agent inside a SaaS tool your team enabled, the plugin somebody trialled and never removed
- For each, mark whether it interacts with people directly, generates synthetic content, or does both
- Fix the interaction disclosures first: they're the cheapest and the most visible. First interaction, plainly worded, not buried in a privacy policy nobody opens
- Work out who is provider and who is deployer for each system — with a third-party model you're usually the deployer, but check what your vendor contractually claims to handle for you
- For generated content, find out what marking your vendor already applies, and where your pipeline strips it out. Standardised marking is being worked out through an EU code of practice, so build for it to change rather than hard-coding today's answer
- Write down which content genuinely gets substantive human review with a named person responsible — and be honest about which doesn't
- Keep the inventory somewhere it stays current, with an owner. A snapshot that rots in six months is how you end up doing this twice

The genuinely good news
For most mid-market businesses this is a days-not-quarters job, and the hard part is knowledge rather than engineering. Once the inventory exists, the fixes are typically a line of disclosure copy on a chat widget, a vendor setting, and a decision about editorial responsibility. It also has a real side benefit: the same inventory answers the AI-governance questions your enterprise customers and insurers have started putting in procurement, and it's the artefact that turns "are you compliant?" from a stalled deal into a one-email answer.
Where we fit
The reason companies retain us for this rather than assigning it internally is that it is genuinely nobody's existing job. It isn't legal — counsel can rule on your obligations but can't find the eleven AI surfaces scattered across your stack. It isn't IT — they don't own the marketing content pipeline. It isn't marketing — they didn't wire up the support agent. It falls between chairs, which is exactly the gap our Fractional Head of AI & Digital engagement exists to fill: someone senior who owns the AI footprint across the whole business, does the inventory once and properly, makes the provider-versus-deployer calls with your counsel, gets the small fixes shipped, and leaves you with a live register rather than a slide. That role also keeps paying after this deadline, because this is the first of these rules to bite and it will not be the last.
Sources
- Goodwin — Not delayed, not deferred: EU AI Act transparency obligations are now in force (what became applicable on 2 August 2026, the Omnibus deferrals, and the penalty exposure)
- EU Artificial Intelligence Act — Article 50: transparency obligations for providers and deployers (the primary text of the four duties)
- EU Artificial Intelligence Act — The AI Act's transparency rules: a practical guide to Article 50 (provider vs deployer, chatbot disclosure timing, and the human-review carve-out)
- DLA Piper — The Digital AI Omnibus: proposed deferral of high-risk AI obligations (what moved to December 2027 and August 2028, and what didn't)
- European Commission — Code of Practice on transparency of AI-generated content (the marking and labelling approach being standardised)
- Travers Smith — The EU AI Act: the current state of play (a plain-English map of which obligations apply when)


