The AI Act's August deadline moved. The part your customers see did not.
The EU delayed its high-risk AI rules by more than a year, and plenty of companies heard "the AI Act is postponed". The transparency rules for chatbots, synthetic content and AI-written text started applying on 2 August anyway.
2 August 2026 was the date when most of the AI Act, including the heavy rules for high-risk systems, was due to apply. Brussels has now moved part of it. The AI Omnibus, a package amending the Act, was published in the Official Journal on 24 July and entered into force on 27 July, six days before the deadline it was changing.
Many companies took that to mean the AI Act has been postponed. It has not, and the transparency rules that did take effect on 2 August carry fines of up to €15 million.
What the Omnibus pushed back
The big change is to high-risk systems. Stand-alone high-risk AI, the Annex III category covering uses such as CV screening, credit scoring and access to education, now has until 2 December 2027. AI that works as a safety component in products already covered by EU product law, such as machinery or medical devices, has until 2 August 2028.
The package also softened some obligations. The AI literacy duty, which required companies to ensure a sufficient level of AI knowledge among staff, now asks them to take measures to support it. Small and mid-sized companies get simpler technical documentation and lighter penalties. It also clarifies that an AI feature that assists a user or optimises performance does not automatically count as a safety component.
And it added to the Act. Using AI to generate child sexual abuse material or non-consensual intimate imagery is now a prohibited practice, and the Commission’s AI Office gets wider supervisory powers over general-purpose models and AI built into very large online platforms.
What started applying on 2 August regardless
Article 50, on transparency, stayed on its original schedule. It covers ordinary, low-risk uses of AI, so it applies to far more companies than the high-risk rules. As Jones Walker’s summary sets out, it now requires:
- telling people when they are interacting with an AI system, unless that is already obvious
- marking AI-generated or manipulated audio, images, video and text in a machine-readable way, where technically feasible
- informing people exposed to emotion recognition or biometric categorisation
- disclosing deepfakes, with an exception for clearly artistic, satirical or fictional work
- disclosing AI-generated text published to inform the public on matters of public interest, unless a human has reviewed it and taken editorial responsibility
There is one grace period. Generative systems already on the market before 2 August have until 2 December 2026 to add machine-readable marking. Breaches of the transparency rules can cost up to €15 million or 3% of worldwide turnover.
The same date switched on the Commission’s enforcement powers over the largest model providers. From 2 August the AI Office can request information, demand access to models, require risk mitigation, fine up to 3% of global turnover, and order a model withdrawn or recalled from the EU market. Those powers apply to OpenAI, Anthropic, Google and the other large model providers. Expect updated terms from your AI vendors this autumn as a result.
Who enforces it in Denmark
In Denmark the coordinating authority for the AI Act is Digitaliseringsstyrelsen, the Agency for Digital Government, with Datatilsynet and the sector regulators responsible within their own areas. No separate Danish AI law sits on top of the regulation, so the EU text is the rulebook.
Danish public bodies are about to deploy a lot of AI that falls under Article 50. The new government platform from June sets a goal of freeing at least 30,000 full-time positions in the public sector by 2035 through AI, and promises a general legal basis for public authorities to use AI. Much of that will be chatbots for citizens and tools for caseworkers, both covered by the disclosure rules. Suppliers to Danish municipalities and regions should expect the disclosure requirements to show up in tenders.
What to check this month
Start with an inventory. Many companies cannot list every place AI touches a customer, because the AI arrived inside other software, such as a support chat widget or a translation plugin. Each of those can carry an Article 50 obligation. The Act separates providers, who build a system, from deployers, who use it. Most businesses are deployers, and the disclosure duties for chatbots, deepfakes and published text sit with deployers.
Then look at what you publish. If your company uses AI to write public statements or news-style content, the text-disclosure rule applies unless a named person reviews the text and takes editorial responsibility for it. For most businesses the practical answer is a review step you can document.
Finally, keep working on the high-risk rules. December 2027 is sixteen months away, which is not long for a compliance project of GDPR’s size. If you use AI in hiring, credit decisions or access to essential services, the requirements for documentation, risk management and human oversight have not changed. Only the deadline has.
