If you only read the headlines this summer, you will have come away believing the EU AI Act was postponed. Half of that is true, and it is the half that matters least to most businesses.
In short: The AI Omnibus, Regulation (EU) 2026/1744, came into force on 27 July 2026 and pushed the high risk obligations back to 2 December 2027. The transparency obligations in Article 50 were not deferred. They became generally applicable and enforceable by national authorities on 2 August 2026, and they apply to any system that interacts with people or generates content, whether or not it is high risk. Generative systems already on the market before that date have until 2 December 2026 to meet the machine readable marking requirement. If you are a UK business selling into the EU or serving EU users, the transparency duties are live now.
What was actually deferred, and what was not
Two things got merged in most of the coverage. Separating them makes the picture much simpler.
- Deferred. The obligations attached to high risk AI systems, the conformity assessments, risk management systems and technical documentation, were originally due on 2 August 2026. The Omnibus moved them to 2 December 2027.
- Not deferred. Article 50, the transparency and information duties, became applicable and enforceable on 2 August 2026 as planned.
The reason this matters is that high risk classification is narrow. Transparency is not. Most organisations were never going to be caught by the high risk regime, so the delay changes nothing for them. Almost everyone using generative AI in a customer facing way is touched by Article 50.

Who does Article 50 apply to?
The test is not how sophisticated your AI is or how much of it you built. It is what the system does in front of a person. Broadly, the duties bite in four situations:
- The system interacts directly with people, so they need to be told they are dealing with AI rather than a human, unless that is obvious from the context
- The system generates synthetic audio, image, video or text, which has to be marked in a machine readable way as artificially generated
- The system produces a deepfake, meaning content that resembles real people, objects or events, which has to be disclosed as such
- The system performs emotion recognition or biometric categorisation, where the people exposed to it have to be informed
Read that list again with your own website in mind. A support chatbot on your contact page is in scope. So is a marketing site generating product copy or imagery at scale, and so is an AI screening step in a recruitment funnel.
"Nobody is coming to inspect your model. They are going to look at your website and ask why the chatbot never says it is a chatbot."
Does this apply to a UK business?
The AI Act is EU law, but its reach follows the user rather than the office. If you place an AI system on the EU market, or the output of your system is used in the EU, you can be in scope even with no EU entity. For a lot of UK firms that means a single question: do EU based people use this thing?
Being outside scope entirely is a legitimate answer. The problem is that most organisations have never written the answer down, which means they cannot demonstrate it if asked. The work here is small and worth doing before somebody asks under time pressure.
The practical version
You do not need a compliance programme to make a sensible start. You need an inventory and four decisions.
- List every AI system that touches a customer or an employee. Include the ones you bought, the ones embedded in tools you already pay for, and the ones a team enabled without telling anyone. If you have not done a discovery pass, our guide to finding shadow AI in your business is the place to start.
- For each one, record whether it interacts, generates, impersonates or infers emotion. That single column tells you whether Article 50 is engaged.
- Fix the disclosure. Where a system talks to people, say so in plain language at the point of contact, not in a policy nobody opens. This is usually a copy change, not a project.
- Check the marking on anything you publish. If you generate content at scale with a third party tool, find out what it does about machine readable marking and get the answer in writing from the vendor.
Where this is heading
The deferral of the high risk rules to December 2027 is a reprieve, not a reversal. The direction of travel across the EU and the UK is the same: if a machine is making or shaping a decision about a person, that has to be visible and contestable. The UK is arriving at the same place by a different route, through the Data (Use and Access) Act and the ICO's work on automated decision making, which we cover in what changed for UK employers.
The organisations that will find 2027 comfortable are the ones that build the inventory now, while the stakes are low and the exercise is a spreadsheet rather than an audit. If you want a hand mapping where AI already sits in your estate and what it touches, that is part of our AI advisory and enablement work, and a good first step is our Copilot readiness assessment.



