The AI Act starts enforcing today, and it lands on your chatbot first
Today, 2 August 2026, the phase of the AI Act everyone has pointed at for two years begins. The expectation: a mountain of paperwork around high-risk systems. Reality turned out differently. Six days ago the Digital Omnibus entered into force and pushed exactly that paperwork to December 2027 and August 2028. What lands today is the part that touches almost every company: transparency.
That flips the picture. The rules starting today apply to anyone with a chatbot on their site or a marketing team generating images. The rules postponed with much noise applied mainly to builders of recruitment, credit and healthcare software.
What the Digital Omnibus changed
Regulation (EU) 2026/1744 entered into force on 27 July 2026, five days before the original deadline. Brussels created room because technical standards lag behind: without harmonised standards a company lacks the yardstick to assess its high-risk system. The new dates:
- Stand-alone high-risk systems (Annex III), such as AI for recruitment, examination, credit scoring and access to essential services: 2 December 2027.
- High-risk AI inside regulated products (Annex I), such as medical devices, machinery and toys: 2 August 2028.
- National AI regulatory sandboxes where companies experiment safely under supervision: 2 August 2027.
- Marking of AI content by systems already on the market: 2 December 2026, four extra months.
- A new prohibition on AI generating child sexual abuse material or non-consensual intimate imagery: 2 December 2026.

The rest of Article 50 stays on today. That choice deserves attention: Brussels deferred the obligations that require standards and audits, and kept the obligation that requires honesty.
Article 50: four duties starting today
Article 50 applies to every AI system, whatever its risk class. A simple customer service bot falls under it, as does an image generator in your content process. The European Commission published guidelines on 8 May 2026 with a strict reading. Four duties:
- Disclose that the visitor interacts with AI. At first contact, in plain language. A line in the terms of service falls short here. This duty sits with the provider of the system.
- Mark synthetic content in a machine-readable way. Images, audio, video and text from a generative model carry a technical marker so other systems recognise the origin. This duty also sits with the provider, and the large model builders handle it inside their product.
- Label deepfakes visibly. Realistic AI imagery of people or places gets a label at first display. The Commission reads this broadly: intent to deceive plays no role. Clearly fantastical imagery with dragons or flying people stays outside scope. This duty sits with you as deployer.
- Label AI text on matters of public interest. Publishing AI text about politics, justice, public health, environment or consumer safety calls for a label. Genuine human editorial review with an identifiable responsible person grants an exemption. A spell check falls short here.

What this means for a service business
Translate it to an average SME with a website, a customer service bot and a marketing calendar. Four practical moves:
- Add an AI disclosure to your chatbot. One opening line does it: "You are talking to an AI assistant from [company]. For a person, I will connect you." Five minutes of work.
- Audit your image library. Any AI portraits of customers, staff or locations on your site or socials? Give them a visible label in the caption.
- Document your editorial process. Publishing AI-assisted articles on topics of public interest? Record who reviews the piece on substance. That record earns the exemption.
- Select vendors on their AI Act declaration. Ask every AI tool you buy for its conformity declaration and its output marking. That shifts part of your risk to the provider.
Penalties and supervision
The penalty provisions have applied since 2 August 2025. Breaching Article 50 costs up to 15 million euro or 3 percent of worldwide annual turnover, whichever is higher. For SMEs and start-ups the calculation reverses: there the lower amount applies. Breaching the prohibited practices in Article 5 runs up to 35 million euro or 7 percent.
Dutch supervision is still taking shape. In April 2026 the government opened a consultation on a bill giving the Data Protection Authority and the Radiocommunications Agency a coordinating role, with sector regulators in their own domain. The consultation closed on 1 June 2026. Practical consequence: in the first months supervisors focus on visible breaches and on guidance. That room gives you time to put your house in order.
The opportunity behind the rule
Transparency about AI reads as an obligation and works as a sales argument. Study after study shows customers accept AI in service delivery as long as they know where they stand. A bot that introduces itself and hands over to a human scores higher on trust than a bot imitating humanity.
Companies arranging this now buy two things: calm around enforcement, and a credible story for customers wondering how you handle AI. Preparing for December 2027 starts with the same inventory: which AI touches my customers, and what do I tell them about it.
Curious which AI in your organisation falls under Article 50? In the AI strategy and awareness workshop we map it in half a day, along with the opportunities underneath.
Sources
- Regulation (EU) 2026/1744, Digital Omnibus on AI, Official Journal of the EU
- European Commission, Transparency obligations under Article 50 AI Act
- European Commission, Guidelines on transparency obligations for providers and deployers of certain AI systems
- Future of Privacy Forum, The AI Act implementation timeline: what changes under the AI Omnibus
- Freshfields, The final Digital Omnibus on AI: key amendments to the AI Act
- Gibson Dunn, EU AI Act Omnibus agreement: postponed high-risk deadlines and other key changes
- Rijksoverheid, Kabinet zet stap met toezicht op Europese AI-regels
- EU Artificial Intelligence Act, The transparency rules of Article 50