BLOG

The EU AI Act's Two Deadlines: 2 August 2026 and December 2027

Updated 30 July 2026

The EU AI Act's Two Deadlines: 2 August 2026 and December 2027

The EU AI Act’s high-risk deadline was pushed back sixteen months, to 2 December 2027, but that delay covers only Annex III “high-risk” systems such as hiring tools, credit-scoring models, and biometric identification. Article 50, the rule requiring any chatbot or voice AI to tell people they’re talking to a machine, was never part of that delay. It still takes effect on 2 August 2026, regardless of how a system is classified.

Most of the coverage this summer got one part of the story right and skipped the part that actually lands this week.

In late June, the Council of the EU gave its final sign-off to the so-called Digital Omnibus on AI, and the resulting headlines were accurate as far as they went: the toughest obligations in the EU AI Act, the ones for “high-risk” systems like hiring algorithms, credit-scoring models, and biometric identification, won’t apply until 2 December 2027 instead of 2 August 2026. Sixteen months of breathing room, and CX, compliance, and procurement teams everywhere understandably exhaled.

Except Article 50 was never on that list. It sits in a different part of the regulation, covering a different problem, and the Omnibus didn’t touch it. If your organisation runs a chatbot, a voice assistant, or anything that talks directly to customers, the transparency duty in Article 50, telling people they’re dealing with AI, still takes effect on 2 August 2026. That is not a typo, and it is not next year’s problem.

Here’s what the Digital Omnibus actually changed, what Article 50 actually requires, where the emotion-recognition rules get misread even by people who’ve read the regulation closely, and what that means for a customer service organisation checking its own AI stack this week.

What the Digital Omnibus Actually Delayed

The Digital Omnibus on AI is now law. The European Parliament and Council reached political agreement on 7 May 2026, the Council gave its final approval on 29 June, and the European Commission confirms the text was published in the Official Journal on 24 July as Regulation (EU) 2026/1744, entering into force three days later on 27 July, five days before the original 2 August deadline it was designed to soften. You can read the consolidated AI Act text on EUR-Lex directly.

Here is what actually moved, and what didn’t:

ObligationOriginal dateNew dateStatus
Annex III high-risk systems — hiring & worker management, credit scoring, biometric identification and categorisation, law enforcement, migration, education, essential services2 August 20262 December 2027Delayed 16 months
Annex I high-risk systems — AI embedded in already-regulated products (medical devices, machinery, toys)2 August 20272 August 2028Delayed 12 months
Article 5 prohibited practices — manipulative AI, social scoring, workplace emotion inference, and more2 February 2025UnchangedIn force; a new ban on AI-generated CSAM and non-consensual intimate imagery was added, with its own transition to 2 December 2026
Article 4 AI literacy2 February 2025UnchangedIn force; the duty was softened from guaranteeing a literacy level to “supporting” AI literacy among staff
Article 50 transparency obligations — chatbot/voice disclosure, deepfake labelling, emotion-recognition disclosure2 August 2026UnchangedNot part of the Omnibus
Machine-readable marking of synthetic content already published before 2 August 2026Grace period to 2 December 2026A narrow technical carve-out, not a delay of the disclosure duty itself

Law firms tracking the Omnibus in real time reach the same conclusion. Gibson Dunn’s analysis describes the transparency rules as “largely unaffected,” noting that 2 August 2026 “remains a live compliance date.” The only concession inside Article 50 itself is that four-month grace period for machine-readable marking of synthetic content already in circulation, not for the underlying duty to tell someone they’re talking to AI.

Article 50, in Plain Language: What Actually Has to Happen on 2 August

Article 50 covers four distinct situations, and at least two apply to almost any organisation running AI in customer service today. The full legal text is on the EU’s AI Act Service Desk; here’s what it means in practice.

  • Direct interaction (Article 50(1)). Any system designed to interact with people, chatbot, voice agent, IVR replacement, has to make clear that the user is talking to AI, “unless this is obvious from the point of view of a natural person who is reasonably well-informed.” In practice: don’t lean on “obvious.” Say it, before or at the start of the conversation.
  • Generated content (Article 50(2)). Text, audio, image, or video generated by AI needs a machine-readable mark identifying it as artificial, wherever that’s technically feasible.
  • Emotion recognition and biometric categorisation (Article 50(3)). If a system infers emotion or sorts people into biometric categories, the people exposed to it must be told, on top of whatever the organisation already owes them under GDPR.
  • Deepfakes and synthetic public-interest text (Article 50(4)). Manipulated audio, image, or video must be labelled as such; AI-generated text published to inform the public needs the same treatment, unless a human has reviewed it and takes editorial responsibility.

None of this is gated behind a risk classification. A “limited-risk” chatbot has always had to meet Article 50 on the same 2 August 2026 timeline as everything else, because the Annex III delay was never a delay it qualified for in the first place. That’s the detail a lot of this summer’s coverage compressed into “the AI Act got pushed back.”

The Emotion-Recognition Nuance Even Careful Readers Get Wrong

This is a point worth correcting properly, including in our own earlier coverage of this topic, rather than quietly.

The AI Act does flatly ban emotion recognition in one specific setting. Article 5(1)(f) prohibits inferring the emotions of employees in the workplace, and of students in education settings, full stop, with a narrow carve-out for genuine medical or safety purposes. That prohibition has been in force since 2 February 2025, well before this week’s deadline.

It does not ban inferring a customer’s sentiment on a support call. The European Commission’s own guidance on Article 5 gives a call centre tracking customer emotion through voice analysis as a specific example of a practice that is not prohibited, precisely because the workplace ban protects employees, not the people they’re serving. What customer-facing sentiment analysis does trigger is Article 50(3): deployers have to disclose it, and the underlying voice data is still subject to ordinary data-protection rules.

Employee versus customer, flatly banned versus legal-with-disclosure, is the distinction compliance teams blur most often. It has a practical edge for anyone running speech analytics, too: what matters under Article 50(3) is whether a model is inferring sentiment at all, not whether that inference was sold as a named feature. End-to-end voice models can surface emotional signals as a by-product of architecture nobody explicitly designed for that purpose. “We didn’t build it to do that” isn’t a defence if it’s doing it anyway.

What to Actually Check Before 2 August

  • Every AI system that talks to a customer directly, voice, chat, or hybrid, discloses that fact clearly, before or at the very start of the interaction. Not buried in a footer or a terms page.
  • Anything inferring sentiment, mood, or emotional state from a customer’s voice or text is identified and disclosed, not waved off as “obvious.”
  • Nothing in the stack infers emotion from your own agents or employees. That’s prohibited outright under Article 5(1)(f), not a disclosure question.
  • Disclosure copy is genuinely accessible. Article 50(5) requires this explicitly, not as an afterthought.
  • Every vendor has confirmed, in writing, whether AI disclosure ships on by default or is something you have to configure yourself. The answer says a lot about how seriously they’ve taken this.
  • The above is documented. Annex III paperwork can wait until 2027. A dated record of your Article 50 review can’t, and it’s the difference between a good-faith gap and a violation if a regulator ever asks.

What Non-Compliance Actually Costs

The AI Act’s penalty structure, set out in Article 99, runs in three tiers. Breaching the Article 5 prohibitions, the workplace emotion-recognition ban among them, carries the steepest exposure: up to €35 million or 7% of global annual turnover, whichever is higher. Article 50 transparency breaches sit in the middle tier: up to €15 million or 3% of turnover, the same bracket as most other provider and deployer obligations. Supplying incorrect or misleading information to a regulator is the lightest tier, up to €7.5 million or 1%. Small and medium-sized companies are capped at the lower of the euro figure or the percentage, not the higher.

National market surveillance authorities are the ones who will actually levy these fines, and several member states are still building out that enforcement machinery, a fair reason for patience on Annex III. It’s a much weaker reason for patience on Article 50, where the obligation itself, not just the apparatus behind it, has had a fixed date on the calendar since the Act was adopted in 2024.

Key Takeaways

  • The Digital Omnibus delayed Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028. It left Article 50 untouched.
  • Article 50 transparency obligations, AI-interaction disclosure, deepfake and synthetic-content labelling, emotion-recognition disclosure, apply from 2 August 2026 regardless of a system’s risk tier.
  • Emotion recognition is banned outright only for employees and students (Article 5(1)(f)). Customer-facing sentiment analysis is legal but must be disclosed under Article 50(3).
  • Article 50 breaches carry fines up to €15 million or 3% of global turnover; Article 5 breaches, the workplace emotion-recognition ban included, up to €35 million or 7%.
  • Check disclosure wording and timing now. Annex III paperwork can wait; Article 50 cannot.

Frequently Asked Questions

Does the December 2027 delay push back chatbot disclosure rules too? No. The delay applies only to Annex III high-risk systems, hiring, credit scoring, biometric identification, and similar categories. Article 50, which requires chatbots and voice AI to disclose that a user is talking to AI, keeps its original 2 August 2026 date.

Is it illegal to analyse customer sentiment during a support call? Not under the AI Act. The prohibition on emotion recognition (Article 5(1)(f)) applies to employees in the workplace and students in education settings, not to customers. Analysing customer sentiment is legal but must be disclosed to the customer under Article 50(3), on top of ordinary GDPR obligations.

What exactly does an AI voice agent have to say to be compliant? The regulation doesn’t mandate specific wording. It requires that a reasonably well-informed person clearly understands they’re interacting with AI, disclosed before or at the very start of the interaction, in a way that is clear, distinguishable, and accessible (Article 50(1) and 50(5)).

What are the penalties for failing to disclose AI interaction? Article 50 breaches fall into the middle of three penalty tiers under Article 99: up to €15 million or 3% of global annual turnover, whichever is higher, compared with €35 million or 7% for the more serious Article 5 prohibited practices.

Checking your disclosure copy takes an afternoon. Building an Annex III compliance programme doesn’t, which is exactly why that part got delayed and this part didn’t.

← Back to blog