The second of August 2026 came with no fireworks, no press conference and no panic. It still moved the compliance line for every company that put an AI chat in front of a customer or publishes text a model wrote. The transparency duties in article 50 of Regulation 2024/1689 started applying and, unlike the high risk requirements, they were not pushed back.
Here is what you actually have to do, and what you do not, whatever the training market is telling you.
The timetable, so the regimes do not blur
| Date | What starts applying |
|---|---|
| 2 February 2025 | Prohibited practices under article 5, AI literacy under article 4 |
| 2 August 2025 | Obligations for providers of general purpose AI models |
| 2 August 2026 | Transparency obligations under article 50 |
| 2 December 2027 | Requirements for annex III high risk systems |
The most common mistake in a compliance conversation is that somebody hears “the AI Act”, pictures conformity assessment, technical documentation and registration in an EU database, decides it is too big and puts the whole thing off. All of that belongs to high risk systems, which a typical company does not operate. An assistant that drafts emails is not one.
Four situations that require you to speak up
Talking to a machine. An AI system interacting directly with a person must inform them that they are dealing with a system, unless that is obvious to a reasonably well informed person. The notice has to arrive at the first interaction, not in terms nobody opens. The obviousness exception is narrow and a poor thing to build a policy on.
Marking the output. A provider of a system that generates audio, images, video or text must ensure the output is marked in a machine readable format and detectable as artificially generated. That is a design duty, so if you buy a platform it sits with the vendor. Check it before you sign, because the question comes back at the first audit.
Emotion recognition and biometrics. A deployer of emotion recognition or biometric categorisation informs the people exposed to it. In practice that is recruitment, voice analytics in customer service and workplace systems, which are areas where you are already talking to your data protection officer.
Deepfakes and public interest text. A deployer publishing a deepfake, or generated text that informs the public on matters of public interest, discloses its artificial origin. There is a door here worth using: the duty does not apply to text a human reviewed and took editorial responsibility for.
Provider against deployer
The regulation consistently separates the provider, who builds the system and puts it on the market, from the deployer, who uses it under their own authority. A company buying an AI platform is usually the deployer.
The split looks like this:
| Duty | Provider | Deployer |
|---|---|---|
| Telling a person the counterpart is an AI | yes | no |
| Machine readable marking of generated output | yes | no |
| Informing about emotion recognition | no | yes |
| Disclosing deepfakes and public interest text | no | yes |
| AI literacy of the people using it (article 4) | both | yes |
Put that split in the vendor contract. Not because a regulator will ask to see the contract, but because when a label is missing somebody has to say whose duty it was, and nobody wants that conversation to start with interpretation.
What to do this week
Three things carry most of the weight for the least effort.
First, a notice in the chat interface. One sentence, visible before the first message, in the language of the interface, without legal register. “You are talking to an AI assistant” is enough.
Second, a written editorial rule: anything published externally passes a human who takes responsibility for it. That removes the article 50(4) labelling duty and is usually what the marketing team wanted anyway.
Third, literacy. Article 4 has applied since February 2025 and requires a sufficient level of AI knowledge among the people using AI on the company’s behalf. There is no certificate to collect. A documented internal session and a list of who attended is the shape of it.
What the Act does not require
It does not require consent to use an assistant. It does not require registering an ordinary chat anywhere. It does not require conformity assessment or technical documentation for a tool that summarises meeting notes. It does not ban models from outside the Union either, although that question turns up in public procurement for reasons that have nothing to do with the AI Act.
Worth remembering, though, that article 50 transparency is the statutory floor and not the ceiling. When a customer asks which parts of an answer came from their documents and which from the model, that is a question about trust, not compliance. “We give citations with page numbers” lands better than “we comply with the regulation”.