The Deadline Moved. The Duty Did Not.
On 27 July 2026 the European Commission moved the AI Act deadline that everybody was watching. Six days later, on 2 August, the one nobody was watching applied exactly as written. If your organisation puts a chatbot in front of EU users, publishes AI-generated text or imagery, or ships a tool that produces synthetic content, you have been under a legal duty for six weeks. The penalty band is the same one that covers high-risk systems: up to 15 million euros or 3% of worldwide turnover.
The AI Act has been read, correctly, as a phased regulation with its heaviest obligations arriving in August 2026. That reading produced a widespread and reasonable conclusion inside UK boardrooms: there is time.
Then the Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force on 27 July, six days before the deadline it was amending. High-risk obligations for stand-alone Annex III systems moved to 2 December 2027. High-risk obligations for AI embedded in regulated products under Annex I moved to 2 August 2028. The headlines said the AI Act had been delayed.
The AI Act was not delayed. One part of it was.
What happened
- 19 November 2025The European Commission proposes the Digital Omnibus on AI, a package of targeted amendments. The stated reason is readiness: neither industry nor the harmonised standards bodies, CEN and CENELEC, would have the standards in place, and the conformity assessment infrastructure the Act assumes would exist had not matured.
- 24 July 2026The Digital Omnibus on AI is published in the Official Journal.
- 27 July 2026It enters into force, six days before the original high-risk deadline.
- 2 August 2026Article 50, the transparency obligations, applies on its original schedule. Unchanged.
- 2 December 2026The narrower grace period closes. Machine-readable marking of synthetic content, for systems already on the market before August, must be in place.
- 2 December 2027Deferred high-risk obligations for stand-alone Annex III systems apply.
- 2 August 2028Deferred high-risk obligations for AI embedded in Annex I regulated products apply.

Why this one is different
The delay and the duty were separated, and almost nobody separated them. The Omnibus reopened the deadlines that carried the heaviest compliance machinery: conformity assessment, technical documentation, registration. It did not reopen the substantive risk framework, and it did not touch transparency. Article 50 landed on time, into an audience that had spent a week reading that the AI Act had been postponed.
Article 50 catches organisations that have no high-risk AI at all. This is the part that matters commercially. A firm can be entirely outside Annex III, with nothing resembling a high-risk system anywhere in the business, and still carry four duties:
A chatbot or virtual assistant interacting directly with people must be designed so that a person is informed they are dealing with an AI. That obligation sits with the provider.
Synthetic content, meaning AI-generated or manipulated audio, image, video or text, must be marked in a machine-readable format. Provider again.
A deepfake, meaning content that appreciably resembles real people, objects or events, must be disclosed as artificially generated. That obligation sits with the deployer, and the disclosure must be a visible or audible label a person can understand without using a detection tool.
AI-generated text published to inform the public on matters of public interest must be disclosed as such. Deployer again.
The split between provider and deployer is where organisations get caught. Marking the output is the tool builder's job. Disclosing the deepfake, and disclosing published AI-assisted text, is the job of whoever put it in front of an audience. A marketing team using a commercial image generator is a deployer. A communications team publishing AI-drafted commentary is a deployer. Neither is likely to have read the Act, and neither is likely to be on the compliance function's radar.
It reaches UK organisations directly. The UK is outside the AI Act in the same way it is outside the Cyber Resilience Act, and with the same practical consequence: the obligations follow the market, not the registered office. A UK firm putting an assistant in front of EU customers, or publishing AI-generated content read in the EU, is in scope. We covered the identical mechanism in Aware Is Now A Legal Term, where a reporting duty that began on 11 September reached UK software vendors selling into Europe.
The commercial exposure for UK organisations
Regulatory. Article 50 breaches sit in the middle penalty tier of Article 99: up to 15 million euros or 3% of total worldwide annual turnover, whichever is higher for an ordinary undertaking. The percentage is calculated on worldwide turnover, not EU turnover and not the revenue of the product concerned. For SMEs and start-ups the lower of the two figures applies, which is a meaningful concession and the only one available.
Financial. The remediation cost is modest and the discovery cost is not. Adding an AI disclosure to a chatbot is an afternoon. Establishing which chatbots, content pipelines and generative tools exist across a business that has been adopting them departmentally for two years is a project, and it is the project nobody has scoped because the duty was assumed to be a 2027 problem.
Contractual. Enterprise customers with EU operations will start asking. The question will not be "are you AI Act compliant", which is unanswerable. It will be "is your assistant disclosed and is your generated content marked", which is a yes or no with evidence attached. Suppliers who can answer it quickly will find it becomes a differentiator for roughly one procurement cycle, after which it becomes a hygiene factor and only the absence is noticed.
Governance. The board question is not whether the organisation is compliant. It is who owns the inventory. Article 50 is an accountability problem wearing a technical costume: the duties are simple, the enforcement is real, and the only genuinely hard part is knowing what you have.

What leaders should do now
- Establish the inventory, and accept it will be incomplete. Every customer-facing assistant, every generative tool in marketing, communications, product and support, every place synthetic media reaches an audience. Ask departments rather than the IT asset register, because the register will not have most of it.
- Split the list by provider and deployer. For each item, record whether the organisation built it or deployed somebody else's. The duty differs, and getting this wrong means fixing the wrong thing.
- Disclose the assistants this month. Any AI interacting directly with people needs to say so. This is the cheapest item on the list and the most visible if missed.
- Put 2 December 2026 in the risk calendar. Machine-readable marking for systems already on the market before August is due then. Confirm with each vendor, in writing, that their output carries it. A vendor who cannot answer that question by November is a procurement decision, not a technical one.
- Give it an owner with a name. One accountable person for the inventory and the disclosures, in the same way the Cyber Resilience Act needs a named person who declares awareness. Regulations that turn on organisational knowledge fail when knowledge is everybody's job.
Three questions for the board
- Do we place any AI system, or any AI-generated content, in front of users in the European Union, and who has written down the answer?
- For each such system, are we the provider or the deployer, and does the person responsible know which duty that creates?
- What have our generative AI vendors confirmed, in writing, about machine-readable marking of their output before 2 December 2026?
The strategic takeaway
The Digital Omnibus was a rational response to an infrastructure problem: standards bodies were not ready, so the obligations that depend on standards moved. That is competent regulation adjusting to reality, and it deserves less cynicism than it received.
What it also did, unintentionally, was create a false signal. A regulation reported as delayed is a regulation that leaves the risk register, and Article 50 left with it despite never having moved. The organisations that will have a problem in 2027 are not the ones that read the Act badly. They are the ones that read the headline and stopped.
There is a broader pattern worth noticing. Both the Cyber Resilience Act and the AI Act now place duties on UK organisations through the market rather than the border, and both put the obligation at the point of knowing rather than the point of failing. Nobody has to be breached, and nothing has to go wrong. The duty attaches to what you are doing already and whether you can describe it. That is a governance capability, and it is the same capability in both cases.
Confidence note
Confirmed. The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. High-risk obligations for stand-alone Annex III systems are deferred to 2 December 2027 and for AI embedded in Annex I regulated products to 2 August 2028. Article 50 transparency obligations applied from 2 August 2026 on the original schedule, with a grace period to 2 December 2026 for machine-readable marking of systems already deployed. The Article 99 penalty structure is three tiers, with transparency and high-risk breaches in the middle tier at up to 15 million euros or 3% of total worldwide annual turnover, higher of the two for ordinary undertakings and lower of the two for SMEs and start-ups. These are from the Official Journal, the European Commission's Article 50 guidance and the Act itself.
Reported. The Commission's stated reasoning about CEN and CENELEC standards readiness and conformity assessment infrastructure is as characterised in the Commission's own communications and in legal commentary on the Omnibus package; we have not reviewed the impact assessment.
Assessment. The claim that UK boards widely read the Omnibus as delaying the AI Act generally, and the argument that Article 50 consequently dropped off risk registers, is our assessment from conversations and market commentary, not a surveyed finding. The provider and deployer split described here follows the Commission's guidance; specific allocation in a given supply chain is a legal question and should be taken to counsel. This briefing is not legal advice.
Who owns the AI inventory in your organisation?
Garzon Cyber Solutions is built to put regulation on the risk register, map what supervisors and enterprise customers will actually ask for, and place the people who own the answer. Cybersecurity, compliance and talent, delivered in that order, as one capability.
Start the Conversation →Regulation (EU) 2024/1689 (Artificial Intelligence Act), Articles 50 and 99 · Digital Omnibus on AI, Official Journal of the European Union, 24 July 2026, in force 27 July 2026 · European Commission, transparency obligations under Article 50 of the AI Act · European Commission, Digital Omnibus on AI proposal, 19 November 2025