AI Law · 2026-08-04 (Last updated: August 2026) · 14 min read
The AI Act Was Delayed, Your Obligations Were Not: What Has Applied to Chatbots, Voice Agents and AI Content Since 2 August 2026

Michael Kaiser
Co-Founder & Head of Systems, Vincency
The headline in late July was that the EU delayed the AI Act. That is true, and for most mid-market companies it is also the least useful sentence to act on. The Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I). It did not move Article 50, the transparency duties, which have applied since 2 August 2026. If you run a chatbot, a voice agent, or publish AI-generated media, the delay covers a regime you were probably never subject to, while the part that does bind you started this week.
What moved and what did not
| Date | What | Status after the Omnibus |
|---|---|---|
| 2 Feb 2025 | Prohibited practices (Art. 5), AI literacy (Art. 4) | applies; Art. 4 wording softened |
| 2 Aug 2026 | Transparency duties (Art. 50), general application | unchanged, in force |
| 2 Dec 2026 | Machine-readable marking (Art. 50(2)) for systems already on the market | transition granted by the Omnibus |
| 2 Dec 2027 | High-risk systems, Annex III | moved from 2 Aug 2026 |
| 2 Aug 2028 | High-risk AI embedded in regulated products, Annex I | moved |
Why the mid-market reads this backwards
The high-risk regime under Annex III covers systems that decide about people: creditworthiness, recruitment and worker management, access to essential public services, education, law enforcement, migration, the administration of justice. A machine builder, a wholesaler, a technical service provider or an engineering firm normally operates none of those. The relief that made the headlines therefore applies to obligations that most companies with 10 to 500 employees never carried.
Article 50 is the opposite. It attaches to the ordinary tools that arrived in these companies over the past two years: the assistant on the website, the voice agent that answers outside office hours, the image and video generator in marketing. That is why the reasonable-sounding conclusion, we have another year, is exactly wrong for the audience most likely to draw it. The rule that was postponed was never yours. The rule that applies now sits on the tool you introduced last year.
The four duties in Article 50, and who carries them
Article 50 is short, and the distinction that matters most is who it binds. Two paragraphs address the provider of the system, two address the deployer, meaning the company that uses it.
| Paragraph | Binds | Requirement | Typical mid-market case |
|---|---|---|---|
| 50(1) | Provider | People must be informed they are interacting with an AI, unless obvious | Website chatbot, voice agent |
| 50(2) | Provider | Synthetic output marked machine-readably as artificially generated | Image and video generators in your stack |
| 50(3) | Deployer | Inform people exposed to emotion recognition or biometric categorisation | Rare, but check any analytics on video or voice |
| 50(4) | Deployer | Disclose deepfakes, and AI text published to inform the public on matters of public interest | AI-generated imagery in campaigns |
A word on the provider and deployer split, because it is where responsibility gets dropped. Paragraphs 1 and 2 formally bind whoever supplies the system. But if you buy a chatbot and it ships without a disclosure, nobody at your supplier will be standing in your imprint when a customer or a competitor complains. Treat these as things to verify at procurement, in writing, rather than duties that are conveniently somebody else's.
The chatbot and voice agent case in practice
Article 50(1) contains an exemption that is doing a lot of work in a lot of wishful readings: the disclosure is not required where the AI nature is obvious to a reasonably well-informed, observant and circumspect person, taking the context into account. The question is therefore not whether your team knows it is a bot. It is whether an ordinary visitor would.
For a chat widget that greets people with a first name and writes fluent replies within a second, the honest answer is no. The same applies more strongly on the phone, where every visual cue is absent and current voice systems are convincing enough that people routinely do not notice. Article 50(5) settles the how: clear, distinguishable, and at the latest at the moment of first interaction. A line in the privacy policy does not satisfy that. A sentence at the top of the chat, or a short announcement at the start of the call, does.
There is a commercial argument for going slightly beyond the minimum, and it is not a compliance argument. In our own deployments, callers who are told at the start that an assistant is answering, and are given the route to a human, stay on the line more reliably than callers who work it out halfway through and then start over. Disclosure that arrives late reads as a trick; disclosure that arrives first reads as competence. We work through where each channel fits in chatbot versus AI voice agent.
AI content in marketing: narrower than most people think
This is the point most summaries get wrong, in the alarmist direction. Article 50(4) does not require you to stamp every AI-assisted sentence on your website. It covers text published with the purpose of informing the public on matters of public interest, and even there the duty falls away where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. A product description, a service page, a specialist article in your own marketing: normally outside the scope, and where it is close to the line, editorial responsibility resolves it.
Deepfakes are the genuinely strict part. AI-generated or manipulated image, audio or video content that resembles real people, objects, places or events and would falsely appear authentic must be disclosed. For a mid-market marketing department this is not exotic any more: a generated brand image with a photorealistic person in it is squarely in scope, whatever the intent behind it.
Article 50(2), the machine-readable marking of synthetic output, sits with the provider of the generating system rather than with you. Its practical relevance is the deadline: systems already on the market before 2 August 2026 have until 2 December 2026. That is the date by which the tools in your stack need to be delivering it, and it is a fair question to put to your vendors now rather than in November.
Article 4 became easier, not harder
One change runs against every expectation, so it is worth stating plainly. The Omnibus rewrote Article 4 on AI literacy. The original text obliged providers and deployers to ensure a sufficient level of AI literacy among their staff. The amended text obliges them to take measures to support the development of it. In legal terms that is a move from an obligation of result to an obligation of effort, with no prescribed level of competence to hit.
That is real relief, and it came from exactly the constituency reading this: smaller companies argued that a uniform, enforceable literacy standard was disproportionate given how differently organisations use AI. It is also not a reason to do nothing. Bitkom's 2026 survey found that 53 percent of companies name missing AI competence as the biggest hurdle to adoption. The legal duty got softer; the business problem behind it did not move at all. A half-day session plus a one-page usage policy still solves the same bottleneck it solved in July, and it now happens to exceed what the law asks.
What to do this month
- List the AI in the company. Chatbot, voice agent, generators in marketing, assistants in sales and support, anything embedded in a tool you licence. Most companies find two or three they had forgotten.
- Check the disclosure on every conversational system. Visible or audible, at first contact, without a click. This is a one-line change and the single cheapest item on the list.
- Ask your vendors about Article 50(2) in writing. Does the generator mark its output machine-readably, and by when. The 2 December 2026 date belongs in that email.
- Sort your visual material. Which campaign assets are AI-generated and photorealistic. Those need disclosure; abstract or clearly stylised material generally does not.
- Keep the training, drop the anxiety. Art. 4 is now an obligation of effort. Document what you did, once, and stop treating it as an exam.
- Name one person responsible. Not a department. The AI inventory needs an owner, or it is out of date by the next tool purchase.
Conclusion
The delay is real and it is not yours. Annex III moved to December 2027 and Annex I to August 2028, and neither is likely to have applied to a mid-market industrial, technical or professional services business in the first place. Article 50 did not move, and it is the one that touches the assistant on your website and the voice on your phone line. The work it demands is genuinely small: an inventory, a visible disclosure, a written question to two or three vendors, and clarity about which images are generated. The mistake worth avoiding is the comfortable one, which is to read a headline about postponement and conclude that it applies to you. If you want that inventory done against your actual systems rather than a checklist, that is what a first conversation is for, and the wider picture is in our overview of the 2 August 2026 milestone.
Frequently asked questions about the Article 50 labelling duties
Was the EU AI Act delayed or not?
Partly. The Digital Omnibus on AI appeared in the Official Journal on 24 July 2026 as Regulation (EU) 2026/1744 and has been in force since 27 July 2026. It moves the obligations for high-risk systems under Annex III to 2 December 2027 and those for high-risk AI in regulated products under Annex I to 2 August 2028. What it did not move are the transparency duties in Article 50: those have applied since 2 August 2026. For a mid-market company, that means the part which actually applies to it is precisely the part that went live.
Do I have to label my chatbot as AI?
Yes, unless it is obvious to the user anyway. Article 50(1) requires that people are informed they are interacting with an AI system, unless that is obvious from the perspective of a reasonably well-informed and observant person. A chat widget with a first name as the sender is not obvious. Under Article 50(5) the information must be clear, distinguishable and given at the latest at the time of first interaction. In practice one sentence at the start of the chat is enough, provided it is visible without opening a privacy page first.
Does this apply to an AI voice agent too?
Even more so. On the phone every visual cue is missing and modern voice systems sound human, so the exemption for what is obvious practically never applies. A short announcement at the start of the call stating that an AI assistant is answering, together with the route to a human, is the sensible implementation. It is also the point where law and conversion rate point the same way: callers who know early where they stand drop out less often than those who work it out mid-conversation.
Do I have to label AI-generated text on my website?
Usually not, and this distinction is frequently misrepresented. Article 50(4) obliges deployers to disclose text published with the purpose of informing the public on matters of public interest. A product description, a service page or a specialist article in your own marketing normally does not fall under it. The duty also falls away where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility. Deepfakes are different: AI-generated or manipulated image, audio and video content meant to appear authentic must be disclosed.
What does the 2 December 2026 deadline mean?
It concerns the machine-readable marking under Article 50(2), meaning the technical marking of AI-generated output within the file format itself. For systems already on the market before 2 August 2026, the Omnibus granted a transition until 2 December 2026. This duty falls primarily on the providers of the generating systems, not on every company that uses them. It still matters to you, because it determines whether the tools in your stack deliver in time.
What are the penalties for breaching Article 50?
Under Article 99(4) of the AI Act, up to EUR 15 million or 3 percent of worldwide annual turnover, whichever is higher. For small and medium-sized enterprises and start-ups, Article 99(6) reverses that: there the lower of the two amounts applies. Realistically, the risk for a mid-market company is not the maximum fine but a finding by the market surveillance authority or a competition-law warning letter from a competitor.
Sources, status and note: Primary sources: Regulation (EU) 2024/1689 (the AI Act), in particular Articles 4, 50 and 99, and the Digital Omnibus on AI, adopted as Regulation (EU) 2026/1744 (European Parliament 16 June 2026, Council 29 June, signed 8 July, published in the Official Journal 24 July, in force since 27 July 2026). Article texts: Article 50 and Article 4. Adoption context: Bitkom survey 2026, 53 percent name missing AI competence as the biggest hurdle. The observation on caller behaviour after an early AI disclosure is our own project experience, not an independent study. This article reflects the legal position as of 4 August 2026 and is a general overview, not legal advice; for binding information, consult a law firm specialising in IT and AI law. Transparency: Michael Kaiser is a co-founder of Vincency and the founder of ArkeonTech, and Vincency builds the kind of systems this article describes.
Related insights





