The deadline that moved
was not yours.
The Digital Omnibus pushed the EU AI Act's high-risk deadline out by sixteen months. Article 50 — the plain disclosure rule covering your chatbot and anything you generate — stayed exactly where it was.
Sometime in late June you probably saw a headline that the EU had pulled back on AI regulation — a delay, a simplification, breathing room. If you build with AI and ship fast, you filed it under good news and moved on. Two weeks ago, on 2 August, a different clock ran out — the one nobody put in a headline. It's the rule that says a person talking to your chatbot has to be told they're talking to a machine, and it applies whether or not anything about your product is "high-risk" at all.
What the Digital Omnibus actually postponed.
Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was published in the Official Journal on 24 July 2026 and entered into force three days later, on 27 July. Read against the regulation itself, it pushes the application date for standalone high-risk systems under Annex III — credit scoring, employment screening — to 2 December 2027, and for AI embedded in regulated products under Annex I to 2 August 2028. Sixteen months of runway, for one specific category of system.
Article 50 sits outside that category. It's a transparency layer laid over the whole Act independently of risk classification — it asks only whether a person is talking to your system, or looking at something it made. Per the Commission's FAQ, it has applied since 2 August 2026, the date the high-risk deadline was originally meant to land. Article 50 binds providers and deployers directly, and the Omnibus left it untouched.
The three dates that actually decide this.
Two of these dates already govern your product; the third is the one people confuse them with. Per the Commission's FAQ, Article 50 has applied since 2 August 2026 — and the grace period it describes, for the marking duty alone and only for a feature already on the market that day, runs out on 2 December 2026. The Annex III deadline the Omnibus moved lands a year later, on 2 December 2027, for a different set of systems.
Whether Article 50 reaches your product.
Walked in order, these three conditions land on a yes or a no for whatever you've shipped.
- 01
Does anything talk back, or generate content a person could mistake for human-made?
A chat interface, a voice agent, or a feature that outputs audio, image, video or text is in scope the moment it exists — Article 50 never asks whether the system is classified high-risk. If neither is true anywhere in the product, the article has nothing to reach.
- 02
Did you build the behaviour, or put someone else's model in front of users?
Paragraphs 1 and 2 sit on providers; paragraphs 3 and 4 sit on deployers — running emotion recognition, publishing a deepfake, or putting out AI-generated text on a public-interest matter without editorial review. A product built fast can wear both hats on the same feature.
- 03
Does your case actually meet the narrow exemption, or do you just assume it does?
Article 50(1) only steps back when the AI is obvious to a reasonably well-informed person; 50(2)'s exemption is limited to assistive editing that leaves what a person supplied substantially unchanged. Neither exemption is automatic — each is a specific claim you'd have to defend.
Where the disclosure lives, and who wrote the date down.
State it before or at the first exchange, in the interface itself
Article 50(5) times the duty to the first interaction, so the natural place is a line in the chat window or voice greeting. Mark generated audio, image, video or text in a machine-readable format too, and carry the mark through the export to whatever a user downloads or shares.
Record the decision next to the feature it covers
For each AI-facing surface, write down the date it shipped, whether it makes you a provider, a deployer, or both, and which paragraphs of Article 50 apply — in whatever document already tracks decisions, so a feature from March and a feature from September aren't judged against the same clock.
This is a plain read of a public regulation, and it stops there — check Article 50 itself before relying on this one. Whether your own chat widget or export pipeline meets it is a question about your system, and it's checkable without anyone's permission but yours.
A line of copy, checked like the rest of the surface.
A missing disclosure line reads in a review the same way a missing security header does — something anyone can already see, on a surface you already control. With your permission, that check sits inside operations, alongside the other dated commitments a product picks up.