Reading time: about 7 minutes

2 August 2026 is not the day the whole AI Act arrives. What arrives are the Article 50 transparency obligations and the penalty rules, and those are the only new duties that touch a manufacturer from that date. The loudest part of the regulation, the high-risk obligations, has been pushed back: the Digital Omnibus on AI entered into force on 27 July 2026 and moved Annex III high-risk to 2 December 2027, and Annex I high-risk embedded in regulated products to 2 August 2028. Below we break it down: what applies from 2 August, what does not, what a mistake costs, and what to do this month. This is not legal advice, it is a map that makes the conversation with a lawyer and an AI vendor easier.

What actually starts on 2 August 2026

From 2 August 2026 the Article 50 transparency obligations and the penalty rules begin to apply. A Cooley analysis sorts them into four categories that matter to a manufacturer deploying AI:

  • Interactive systems (chatbots, voice assistants). If a person is talking to AI, they have to be told, unless it is obvious. The duty sits with the system provider, but you are responsible for how the system is deployed on your side.
  • Synthetic content. Material generated or altered by AI, meaning image, audio, video and text, has to carry machine-readable markings. Full marking of systems already on the market applies from 2 December 2026, but the direction is clear now.
  • Emotion recognition and biometric categorisation. If you deploy such a system, for example towards employees, you must inform the people affected. This duty sits with the deployer, meaning you.
  • Deepfakes and manipulated content published externally. You have to disclose that the material is artificially generated or altered, unless it went through substantive editorial review with a person taking editorial responsibility.

The key distinction across all of these is the role: you are a provider if you build and place the system yourself, and a deployer if you buy a ready solution and run it in-house. Most manufacturers are in the second role, which shifts part of the burden onto the vendor. Not all of it, though: informing employees about a biometric system stays on your side regardless of who built the tool.

One detail takes the pressure off: content published before 2 August 2026 does not need retroactive labelling. You do not have to go back through the archive, the duty runs forward from the threshold.

What does NOT start on 2 August, and what the Omnibus moved

This is the most common misunderstanding of recent weeks. Originally 2 August 2026 was meant to be the day most high-risk requirements land. The Digital Omnibus on AI changed that. The European Commission notice confirms the package entered into force on 27 July 2026 and moved the deadlines:

  • Annex III high-risk (recruitment, scoring, critical infrastructure, and more): from August 2026 to 2 December 2027.
  • Annex I high-risk embedded in regulated products, for example machinery, lifts, medical devices: to 2 August 2028.

The Council of the EU approved the Omnibus on 29 June 2026, so the new dates are not a forecast, they are the law in force. The takeaway for a manufacturer is counterintuitive: the postponement is real, but it is not a reason to sit down. December 2027 looks far away until you count how long risk classification, documentation clean-up and renegotiating a vendor contract actually take. Especially since part of the obligations, transparency and penalties, is live from 2 August 2026.

It is also worth remembering the Omnibus did not touch the earlier phases. Prohibited practices have applied since February 2025, and general-purpose AI (GPAI) obligations since August 2025, and those rules continue unchanged. If you use a large commercial model, the weight of GPAI documentation sits with its provider, but you should know the obligation exists and be able to point to it in a conversation with an auditor. In other words, the Omnibus simplified and shifted part of the calendar, it did not remove the foundation of the AI Act. Anyone who read the postponement as a "cancellation" misread the notice.

Article 50 in a manufacturer's practice

The theory says "transparency." On the shop floor it comes down to a handful of concrete situations. The table below maps typical AI uses to whether Article 50 applies to you and what to do about it now.

AI use Does Article 50 apply (from 2 Aug 2026) What to do now
Chatbot or voice assistant for customers or employees Yes, duty to disclose it is AI Add a clear notice "you are talking to an AI system"
Generating content published externally (offers, descriptions, graphics) Yes, synthetic-content marking (full from 2 Dec 2026) Label material as AI-generated, plan machine-readable marking
Internal document search (RAG), no external publication Usually not No marking required, but keep an audit trail for NIS2
Emotion recognition or biometric categorisation of employees Yes, duty to inform the people affected Inform employees, assess legal admissibility of the use
Deepfakes or manipulated content published publicly Yes, duty to disclose artificial origin Disclose, unless there is substantive human editorial review

The pattern is clear: the closer AI comes to an outside person or an employee, the more likely Article 50 is in play. Purely internal document search, with no content published externally, usually sits outside Article 50, but it is still worth keeping an audit trail, because NIS2 asks for one.

Penalties, or why this is not optional

Breaching the Article 50 obligations carries a fine of up to 15 million euro or 3% of worldwide annual turnover, whichever is higher. For a mid-sized manufacturer, 3% of turnover is a number that can exceed the entire AI deployment budget. That moves the transparency conversation from "we will get to it someday" to a line item in this quarter's plan. It is worth remembering the fine is a ceiling, not an automatic outcome: the supervisory authority weighs the severity of the breach and whether the company acted in good faith. Documented preparation works in your favour, even if something slips.

The AI Act calendar to 2028

To avoid the "they postponed it, so we are fine" trap, it helps to see the whole timeline, not just the nearest threshold:

Date What starts
2 August 2026 Article 50 transparency obligations and the penalty rules
2 December 2026 Full synthetic-content marking for systems already on the market, and the ban on AI generating non-consensual intimate material and CSAM
2 December 2027 Obligations for Annex III high-risk (recruitment, scoring, critical infrastructure, and more)
2 August 2028 Obligations for high-risk embedded in regulated products (Annex I)

The two December 2026 thresholds are already close: full marking of synthetic content for systems on the market, and the ban on AI generating non-consensual intimate material and CSAM. For a manufacturer the practical signal is this: if you generate marketing or product content with AI, the marking should be ready before December arrives, not only then.

Timeline of the AI Act phasing in from 2026 to 2028 across four thresholds The AI Act arrives in sequence: transparency and penalties in 2026, the December 2026 thresholds, then high-risk in 2027 and 2028.

What to do in August

A concrete list for this month, without waiting for December:

  1. Inventory where AI in the company meets a human: chatbots, content generators, any system showing something to a customer or an employee.
  2. For each of them, check whether the recipient knows they are dealing with AI. If not, add a clear notice.
  3. Settle with the vendor who is provider and who is deployer, and which Article 50 duty each side takes. Write it down, because the auditor will ask about the split of roles.
  4. Plan synthetic-content marking ahead of the 2 December 2026 threshold.
  5. Connect this to NIS2: if you are preparing for registration and an audit, treat AI as part of the same landscape, not a separate island.

The good news is that most of these steps are housekeeping, not a rebuild. You do not have to replace systems or pause AI deployments, you just need to know where AI meets a human and to close out the notices and the split of roles with the vendor. Companies that do this inventory now will walk into the December thresholds and the rest of the calendar without a scramble, and they will have material ready for a NIS2 audit, because it is largely the same set of questions. The cost of the inventory is low, and the risk of skipping it grows with every threshold.

If you want to compress this into a single conversation, our mini-audit walks through your AI uses and shows where Article 50 and NIS2 actually apply to you, before an auditor does. The full map of every AI Act phase and the list of questions for your vendor is in our guide to the AI Act in 2026.

Frequently asked questions

Does the whole AI Act start on 2 August 2026?

No. Only the Article 50 transparency obligations and the penalty rules start. Prohibited practices have applied since February 2025, general-purpose AI (GPAI) obligations since August 2025, and the high-risk requirements were moved to 2027 and 2028.

Does the high-risk postponement mean we are fine until 2027?

No. The calendar eases for high-risk systems, but not for transparency and penalties, which are live from 2 August 2026. On top of that, two thresholds land already in December 2026.

What penalties apply for breaching Article 50?

Up to 15 million euro or 3% of worldwide annual turnover, whichever is higher.

Does our internal AI assistant fall under Article 50?

It depends on whether it meets a human and whether it publishes content externally. Purely internal document search usually does not, a chatbot for employees or customers usually does.

Do we have to label content published before 2 August 2026?

No. The duty does not run backwards, content from before the threshold does not need retroactive labelling.