Skip to content
Home Blog Compliance & Architecture

The Omnibus Deferred the High-Risk Duties. Article 50 Still Applies From 2 August.

The Digital Omnibus has been in force since 27 July 2026 and pushes the AI Act's high-risk duties back. Almost every headline says deferral. Article 50 is not covered by it and applies from 2 August 2026, six days after the deferral entered into force.

Fabian Weiss, founder of FW Delta Fabian Weiss
Jul 29, 2026 7 Min Read

Key Takeaways

  • Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.
  • High-risk duties now apply from 2 December 2027 for stand-alone systems and from 2 August 2028 for AI inside products that are already regulated.
  • Article 50 is unchanged and applies from 2 August 2026. Only the marking duty in paragraph 2 has a grace period to 2 December 2026 for older systems.

What the Omnibus deferred and what it did not

Regulation (EU) 2026/1744 of 8 July 2026 amends the AI Act. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.

The coverage was almost entirely about the new timeline for high-risk systems. Their duties now apply from 2 December 2027 for stand-alone systems and from 2 August 2028 for AI that sits as a safety component inside products that are already regulated, such as medical devices or machinery. For manufacturers of such systems that is genuine relief.

For everyone else the most important news is different: Article 50 was left untouched.

The transparency duties apply from 2 August 2026. That is six days after the deferral everyone wrote about entered into force. Anyone who read the news as “the AI Act has been postponed” has missed a deadline that lands within days.

The point in one sentence

The Omnibus of 27 July moves only the high-risk duties, while Article 50 applies unchanged from 2 August 2026 to providers and to companies that merely use AI.

Not legal advice

This text reflects the state of the published legal acts and the Commission's guidance. Whether and how a duty applies to your system depends on classifications that need a legal review. The text does not replace that review, it is meant to trigger it.

What Article 50 requires

On 20 July 2026 the Commission adopted its guidelines on Article 50 and explained the duties in a set of questions and answers. The article has four paragraphs. Two fall on providers, meaning the companies that develop an AI system or offer it under their own name. Two fall on deployers, meaning companies that only use a system.

Paragraph 1, direct interaction, falls on providers. People must know they are dealing with an AI system, unless that is obvious. The notice has to be clearly visible from the start of the first interaction.

Paragraph 2, marking of generated content, falls on providers. Generated audio, image, video and text content must carry machine-readable marks that show it was generated or altered by AI. For systems placed on the market before 2 August 2026 a grace period runs to 2 December 2026. It covers only this marking duty.

Paragraph 3, emotion recognition and biometric categorisation, falls on deployers. Anyone using such systems must inform the people affected.

Paragraph 4, deepfakes and AI text on matters of public interest, falls on deployers. Anyone publishing generated or altered images, audio or video that convincingly imitate real people or events must disclose that. Anyone publishing AI-generated text to inform the public on matters of public interest must label it as AI-generated. The exception: the text was reviewed by people and someone holds editorial responsibility.

Fines for breaches of these duties can reach 15 million euros or three percent of worldwide annual turnover, whichever is higher. For small and medium-sized companies the lower of the two applies.

Why this affects more companies than expected

The common assumption is that the AI Act concerns AI providers. But paragraphs 3 and 4 fall on deployers. A deployer under the regulation is any company that uses an AI system under its own authority, outside purely private use.

That captures a lot of unremarkable everyday cases. A chat window on a website that does not immediately look automated. An assistant on the service line. Blog posts on matters of public interest that were machine-generated and published without review. A product video with an AI-generated presenter. Systems that infer mood from camera images, which happens in shops and event venues more often than the operators realise.

None of these cases requires that you trained a model yourself. Using it is enough.

The part that is technology, not law

The four duties share one precondition that is rarely discussed: you have to know which AI systems run in your company, who uses them, what they output and where that output goes.

That sounds simple and is simple in almost no company. Over the last two years AI features did not arrive through IT procurement. They arrived as extensions to tools that were already in use. The CRM gets text suggestions, the ticketing system gets summaries, the editorial tool gets a draft generator. Nobody made a purchasing decision, because it was not a purchase. It was an update.

The practical task for the coming weeks is therefore an inventory, not legal work:

  1. Which systems generate content or talk to people? Including features that arrived as an update to existing tools.
  2. Which of those send something outward? To customers, to the public, to applicants.
  3. Where does marking already exist and where are you relying on the vendor to apply it?
  4. Who in the company decides when a vendor switches on a new AI feature? If the answer is nobody, that is the actual finding.

Point four matters beyond this deadline. Deadlines come and go and the next legal act will be cut differently again. What remains is whether a company knows what happens inside its systems or has to piece it together every time.

Why deferrals are the wrong planning basis

The Omnibus is the second major correction to the AI Act’s timeline. For the manufacturers concerned it is genuine relief and it would be unfair to play that down.

It still makes a poor planning basis. A deferral is not a repeal. It moves a requirement into a year in which other requirements also fall due. Booking the reprieve as time gained and pausing the work leaves you facing the same task in 2027 with less runway and more happening at once.

The same pattern shows up with the Cyber Resilience Act. Its reporting duties start on 11 September 2026, 15 months before the security requirements apply in full. There too the pulled-forward duty is the organisational one and there too many plan backwards.

We covered the Omnibus in detail elsewhere. The observation from then still holds: with every report of a postponement it pays to check exactly which article was moved and which was not. The answer is rarely in the headline.

What you can check in the next few days

The 2 August deadline can no longer be tackled with a project. What is still possible is an honest inventory. That is useful even when it stays incomplete.

  • Build the inventory, even roughly. A list with twelve entries beats a perfect list that does not exist.
  • Customer-facing cases first. Chat, assistants, published texts and videos. That is where the duty is most immediate and the fix simplest.
  • Ask vendors what they do about marking. For paragraph 2 the duty sits with the provider of the system. Whether your supplier meets it is something you have to ask. It does not answer itself.
  • Do not stretch the grace period to 2 December 2026. It covers only the marking duty in paragraph 2 and only systems placed on the market before 2 August. Everything else applies immediately.
  • Let lawyers do the legal classification. Above all, whether a system falls under paragraph 3 is not something to decide in passing.

The point behind the deadline

At its core Article 50 asks for something that fits in one sentence: people should know when they are dealing with a machine. It is one of the few rules in this field you can consider right even without a regulation behind it.

The effort almost never sits in the marking itself. A notice in a chat window is half an hour of work. The effort sits in knowing where the machines are in the first place. That capability is not a job for the legal department but a question of how you run your systems. It pays off independently of any deadline.

How to build automation so it stays traceable which step comes from a model and which is fixed code is described on our process automation page. The deadlines will keep moving. The question of whether you know what your system does will not.

Newsletter

Research for technical decisions

New reports, benchmarks and technical analyses on SaaS economics, AI engineering and owned infrastructure.

Original research Public sources No sales mail

By subscribing you receive new analyses and updates from FW Delta by email. You can withdraw your consent at any time. Further information is available in the privacy policy.

Newsletter

Research for technical decisions

New reports, benchmarks and technical analyses on SaaS economics, AI engineering and owned infrastructure.

Original research Public sources No sales mail

By subscribing you receive new analyses and updates from FW Delta by email. You can withdraw your consent at any time. Further information is available in the privacy policy.