The short version: Europe's Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on July 24 and in force July 27 — pushed the AI Act's expensive high-risk obligations out to December 2, 2027 (standalone systems) and August 2, 2028 (embedded ones). But the Article 50 transparency duty — tell users they're talking to an AI, label what your model generates — still starts August 2, 2026, this coming Sunday-week. If you ship any AI feature to EU users, that is the deadline that applies to you, not the ones that just moved.

What moved, and what didn't#

For eighteen months, "the AI Act" has been founder shorthand for a wall of compliance arriving on August 2, 2026: risk-management systems, technical documentation, conformity assessments, post-market monitoring. The Digital Omnibus took that wall and slid most of it into 2027 and 2028.

That's real relief, and if you were bracing for a high-risk audit next week, you can exhale. But read the fine print on what stayed.

The part that still lands August 2: Article 50#

Article 50 — the AI Act's transparency layer — was not touched by the omnibus. It applies from August 2, 2026, on the original schedule. Two duties matter for almost every consumer-facing AI product:

  1. Disclosure. If a person is interacting with an AI system — a chatbot, a voice agent, an AI email responder — you have to tell them, unless it's already obvious. A visible "You're chatting with an AI" line satisfies this.
  2. Synthetic-media labeling. If your system generates or manipulates audio, image, video, or text, the output must be marked as artificially generated in a machine-readable way, and deepfakes must be disclosed. In practice that means C2PA content credentials or an equivalent watermark baked into the output, not just a caption a user can crop off.

The one concession: Article 50(2) watermarking gets a grace period. For AI systems already placed on the market before August 2, 2026, the machine-readable marking obligation is deferred to December 2, 2026 — four months to retrofit content credentials. The plain-language disclosure notice still starts August 2. So the grace period covers the harder engineering task, not the easy UI one.

The omnibus also quietly added a new Article 5 prohibition — AI-generated non-consensual intimate imagery ("nudifiers") and CSAM are now banned outright. That's not a compliance task for legitimate builders; it's a floor.

Why this is a trap for small teams#

The delay generates exactly the wrong headline for a solo founder: "EU delays AI Act to 2027." Read fast, you file the whole thing under later and move on. Then August 2 arrives and the part that actually applied to you — the chatbot with no AI disclosure, the image generator with no content credentials — is out of compliance while you were relaxing about an audit you were never going to trigger.

The asymmetry is the point. The obligations that got delayed are the ones most founders never had (you're probably not building a biometric hiring system). The obligation that didn't move is the one almost every AI product has (you almost certainly show users model output). The omnibus made the law less scary and more relevant at the same time.

This is the same seam we mapped in multi-region AI compliance: the EU keeps regulating the interface and the content, not the model weights — the same move China made when it regulated the AI persona, not the model. Two blocs, one pattern: the compliance surface is what your users see, not what you trained. We laid out the two governance blocs founders now build across in WAICO vs PAX Silica.

The one-week to-do list#

If EU users can reach your product, do these before August 2:

  1. Add the AI disclosure. One line in the chat UI or first agent turn: "You're talking to an AI assistant." Cheap, done in an afternoon.
  2. Turn on content credentials for anything you generate — images, audio, video, and increasingly text. C2PA support is now built into most generation SDKs; if yours shipped before August 2, you have until December 2 to finish the machine-readable mark, but wire it now.
  3. Label deepfakes explicitly. If your product produces realistic synthetic likenesses or voices, disclose it in the output, not just the terms of service.
  4. Skip the high-risk panic — unless you're actually high-risk. Check Annex III honestly. If you're a normal SaaS or agent product, you have until 2027+, and probably never trigger it at all.

The founder-grade summary of the AI Act as it now stands: the expensive part got a two-year snooze, and the cheap part is due next week. Ship the cheap part. For the fuller obligation map on agent products specifically, we kept the EU AI Act for AI agents and the AI companion compliance checklist current — and the broader "what a founder actually does when a rule drops" playbook is in our read on the White House 30-day frontier-model review.