The AI Act deadline everyone told you was delayed is the one that already applies to you
High-risk got pushed to December 2027 and the whole timeline read as "delayed." Article 50 didn't move. It applied on 2 August, it catches you if an EU user sees your output, and the ceiling is €15m or 3% of worldwide turnover.
Two and a half weeks ago a rule started applying to most people reading this, and the coverage around it said the opposite.
Here's what happened. The Digital Omnibus was published in the Official Journal on 24 July and entered into force on 27 July. It pushed the Annex III high-risk regime — hiring, credit scoring, education, essential services — from 2 August 2026 out to 2 December 2027, and high-risk systems embedded in regulated products to 2 August 2028. That is a real deferral and it got written up everywhere as the AI Act slipping.
Article 50 was not in it. The transparency obligations applied on 2 August 2026, on the original schedule, and they are now in force.
The reason this matters more to a solo maker than the high-risk delay ever did: Article 50 has nothing to do with being high-risk. It attaches to what your product does, not what category it falls in. And the scope is extraterritorial in the way people always underestimate — a provider outside the EU is in scope if the output of their system is used in the EU. You do not need EU customers on a plan. You need one EU user.
The four obligations, in plain language:
If your system interacts directly with people, you have to design it so they know they're talking to an AI. That's on you as provider, and the Commission's guidelines set out four cumulative criteria: it's an AI system, it's built for genuine two-way exchange rather than just collecting data, the interaction is direct rather than through a human, and it's with natural persons. Background and machine-to-machine systems are out.
If your system generates synthetic audio, image, video or text, the outputs have to be marked in a machine-readable format and detectable as AI-generated. Short strings, source code, and pure machine-to-machine outputs are excluded, and there's an exemption where the AI performs an assistive function for standard editing.
If you deploy emotion recognition or biometric categorisation, you have to tell the people exposed to it. Notably you don't have to explain the purpose — just the operation.
If you deploy a system generating deepfakes, you disclose. Same for AI-generated text published to inform the public on matters of public interest — unless it went through real human review with someone holding editorial responsibility. Spell-check doesn't count.
All of it has to be clear, distinguishable, and delivered at the latest at first interaction.
Now the part I'd actually flag, because it's the thing I see makers get wrong in both directions.
"Emotion recognition" under this Act is a term of art. Article 3(39) defines it as inferring emotions or intentions from a person's biometric data. If your product infers mood from typed text and nothing else, it is not an emotion recognition system under the AI Act, and Article 50(3) doesn't reach it. If you added a voice feature, or you read facial expression from a camera, you're squarely in. Same product, same feature description on your landing page, completely different obligation depending on the input channel. I've watched people assume sentiment analysis puts them in scope when it doesn't, and I've watched people ship a voice mode without noticing it changed their legal position.
Two more details worth having right. The grace period is narrower than the summaries suggest: it covers only the Article 50(2) marking and detection duty, only for systems placed on the market before 2 August 2026, and only until 2 December 2026. Everything else applied on the second. And the "unless it's obvious" exception in 50(1) is to be interpreted restrictively — the test is an average person who is reasonably well-informed, observant and circumspect. It is not a place to park the problem, which is exactly what I wanted to do with it.
Enforcement runs through national market surveillance authorities rather than the AI Office in most cases. Fines up to €15m or 3% of total worldwide turnover, with proportionality explicitly available for SMEs and small mid-caps. Nobody is going to make an example of a solo maker in week three. That's not the same as this not applying to you.
What I'd actually do, and it's an afternoon, not a quarter:
Write down every surface where your product talks to a user or produces content — onboarding, empty states, email, push, the export. The obligation is per-surface, and the one you forget is always the automated email.
Check your input channels, not your feature names. Text-only or biometric decides whether 50(3) is your problem.
Put the disclosure at first interaction rather than in the terms. That's what "clear and distinguishable at the latest at the time of the first interaction" means, and a link in the footer isn't it.
If you generate synthetic media, look at the Code of Practice on transparency of AI-generated content. It's voluntary, the Commission and the AI Board have assessed it as adequate, and adhering to it is the cheapest way to demonstrate compliance on the marking duties. Opting out means demonstrating compliance some other way and fielding more requests for information.
The Murror version: we infer emotional state from what people write, and nothing else, so 50(3) isn't ours. 50(1) is, and I don't get to lean on "it's obvious" — someone arriving from an ad in a bad week is not the reasonably well-informed observer that test imagines. The thing I keep turning over is that a disclosure at the top of a journaling session is not neutral. It changes what someone writes. That's a real product cost and I don't think it's an argument against doing it; I think it's an argument for writing that one sentence far more carefully than a compliance checkbox deserves.
I'm not a lawyer and this isn't legal advice. If you're at any scale, get someone who is. But "I thought it was delayed" is going to be a common sentence this year, and it's wrong about the half that most of us are actually in.


Replies