The EU delayed the AI Act rule that doesn't apply to you. The one that does went live in August.
The Digital Omnibus pushed high-risk obligations out to December 2027. Article 50 transparency was not pushed anywhere - it applies now. And if your generative feature shipped before 2 August, your marking deadline is 2 December, twelve weeks out.
Every summary I read of the Digital Omnibus said some version of "Brussels blinks, AI Act delayed." That's accurate about the part of the Act most small teams will never touch, and misleading about the part most of us are already inside. I went and read the Commission's own pages this week rather than the coverage, and the gap between the two is wide enough to be worth twenty minutes of your time.
Start with what actually moved.
Parliament approved the Digital Omnibus on AI on 16 June 2026, by 423 votes to 57 with 174 abstentions, after a trilogue deal on 7 May. It sets fixed later dates for the high-risk regime: 2 December 2027 for stand-alone Annex III systems, 2 August 2028 for high-risk AI embedded in regulated products. It extends some SME simplifications to small mid-caps, eases registration for non-high-risk systems, and adds a new prohibition on AI generating non-consensual intimate content and CSAM. That's the headline, and for a small subscription app it is almost entirely irrelevant, because you were probably never building an Annex III system.
Now what didn't move.
Article 50 - the transparency chapter - applies from 2 August 2026. The Commission's FAQ page on it was updated on 24 July 2026, after the Omnibus deal, and it says so plainly. There's exactly one carve-out: for AI systems placed on the market before 2 August 2026, the machine-readable marking obligation in Article 50(2) doesn't bite until 2 December 2026. Everything else in Article 50 has been live since August.
So the sentence to hold onto is: the delay was for the systems that assess people. The rules for the systems that talk to people are already running.
The two paragraphs that most likely apply to you.
Article 50(1): if your system interacts directly with people, you must design it so they're informed they're dealing with an AI. The Commission's guidance sets four cumulative criteria - it's an AI system, it's built for genuine two-way exchange, the interaction is direct, and it's with natural persons. Background and machine-to-machine systems are out. There's an exception where it's obvious to a reasonably well-informed, observant person, and the Commission says explicitly that this exception should be read restrictively, because it takes transparency away. Do not lean on "everyone knows it's AI." That's the argument that gets read narrowly.
Article 50(2): if your system generates synthetic audio, image, video or text, the outputs must be marked in a machine-readable format and detectable as AI-generated. Some things are out of scope - short sequences of letters or numbers, source code, outputs only ever passed machine-to-machine, and cases where the AI is doing assistive standard editing without substantially altering the input or its meaning. If you have a generative feature that shipped before August, this is your 2 December date.
Two things people get wrong about scope. First, it's extraterritorial: providers outside the EU are in scope if the output of their system is used in the EU. Being a solo dev in Toronto doesn't put you outside it. Second, Article 50 attaches regardless of risk tier - it isn't a consequence of being high-risk, so "we're not high-risk" is not an answer to it.
The definitional trap, which is the part I'd actually spend ten minutes on.
If your marketing says your product understands feelings, you might assume you're running an emotion recognition system. Under the Act you probably aren't, and the reason is one word. The definition in Recital 18 turns on inferring emotions "on the basis of their biometric data." Text someone typed is not biometric data. A journalling app that reads written entries and reflects a mood back is, on that definition, not an emotion recognition system, whatever the landing page says.
Here's the part that made me put my coffee down. Recital 18 names characteristics of a person's voice among the things that count when they're used to infer emotion. So the ordinary, reasonable feature request - let me record a voice note instead of typing - is potentially the thing that moves you across the line. On the other side of that line sit Article 50(3), which requires deployers to inform people exposed to the system, and Annex III point 1(c), which lists emotion recognition as high-risk. Those high-risk obligations are the ones now dated 2 December 2027. Which means the delay everyone reported as good news is, for that specific feature, just a longer runway on a bigger obligation.
That's a roadmap decision disguised as a UX request, and nothing in your backlog tool will flag it.
Enforcement, briefly. Mainly national market surveillance authorities, not the AI Office - the AI Office's role here is limited to systems built on general-purpose models where the same entity provides both, and AI inside very large platforms and search engines. Fines under Article 99(4) reach 15 million euro or 3% of worldwide turnover, whichever is higher, with proportionality available for SMEs and small mid-caps. There is a voluntary Code of Practice on transparency of AI-generated content; signing it gives you a defined route to demonstrating compliance with the marking obligations, and the Commission notes that non-signatories have to prove it some other way and may field more requests for information.
One practical warning. The Commission's own AI Act Explorer currently serves the Article 50 page with a banner saying the provision has been amended by the Digital Omnibus and the displayed text hasn't been updated yet. So the most official-looking source is knowingly stale. Read it with that in mind, and prefer the dated FAQ and guidance pages.
What I'd do this week, if you sell software to anyone in the EU.
Write down whether your product interacts directly with people, and if it does, find the exact screen where you say it's AI. If you can't point at one, that's this week's ticket. Then list every place you generate text, audio or images for a user, and check whether the feature shipped before 2 August - that's what decides whether your marking deadline was August or is 2 December. Then, if you infer anything about a person's state, write down what you infer it from. If the answer is text, you're outside the emotion recognition definition. If it's voice, face or anything physiological, you're in a different conversation and should have it with a lawyer rather than a forum post.
The Murror version is short. We're text-based, so on the definition we aren't an emotion recognition system, and we say we're AI in the first screen because a journal that pretends to be a person is a bad journal. What I got wrong was the frame. I read "AI Act delayed" in August and filed it as nothing to do, when the accurate read was that the deadline for people like us had already passed and the one still ahead was for a feature we've had requested three times. I'm a founder, not a lawyer, and none of this is legal advice - but the arithmetic of which paragraph applies to you is something you can do yourself in twenty minutes, and it's cheaper than the alternative.


Replies
I think ,the voice note request is carrying two obligations:
Your Recital 18 read is about what you infer from, and typed text isn't biometric. If a voice note ever comes back as a spoken reflection, that output is synthetic audio and lands in 50(2) instead, with its own deadline and no relation to risk tier.
The 50(2) half is the most interesting, 'cauz the marking has to survive leaving the product. I build a flashcard generator, and the text and the mp3 go out as a file the user imports into another app, so the screen where I say it's AI stays behind on my side. Audio at least has somewhere to put the mark, since the file carries metadata. Two words of generated text has nowhere, and whatever I do attach comes off the moment someone copies the card into their own notes.
But I still haven't solved the text half and I haven't signed the Code of Practice. What I did change is when the decision happens. Marking is an export-time decision rather than a UI one, and every file already out there predates whatever you decide
Murror
@siarheihamanovich The export-time framing is the part I hadn't worked through, and I think it's right. Marking in the UI marks the context; the artifact is what leaves, and it leaves without the context.
I don't have the text half solved either, and I'd be suspicious of anyone claiming they do. Audio and images have a container that can carry a mark. Short generated text has metadata only while it's sitting in a file, and copy-paste strips it by design. That reads to me like a gap in the available tooling rather than something you're failing to implement.
On the Code of Practice, I haven't signed either. The thing that moved it from "ignore" to "read properly" for me was the Commission's note that non-signatories have to demonstrate compliance some other way. Not a reason to sign, but a good reason to know what your other way is before someone asks you for it.
@monatruong_murror Every flashcard generation writes a record because that's how the billing works, so which model produced what, for which account, at what time is already in the database. Keeping the fields that also answer the provenance question costs nothing on top, and it means that if someone puts a card in front of me and asks whether we made it, I can answer instead of describing our process.
I don't want to oversell that, because it isn't 50(2). Marking is meant to let anyone holding the artifact detect it. A log on my side only answers for people who come and ask me. Those are different things, and I'd rather say so than let a good record stand in for a mark I can't actually produce
The voice note trap is such a good catch. Text feels safe voice flips the category entirely. Are you parking that feature for now or exploring a lawyer friendly implementation first?
Murror
@mikkellarsen Parked, but I want to be precise about why, because "legal risk" isn't quite it.
The honest reason is ordering. Voice notes are easy to build and hard to un-build. If we shipped it and then worked out what we were inferring from, we'd be doing the analysis with a live feature and real users attached to it, which is exactly when you talk yourself into the convenient answer. So it sits until I can write down, in one sentence, what the model reads and what it reads it from. If that sentence has "voice" in it as an input to a state inference rather than just a transcription step, we're in a different regime and I'd want a lawyer, not a forum thread.
There's a version I suspect is fine: transcribe on device or at the edge, throw the audio away, run the same text pipeline we already run. Then the voice is an input method rather than a signal. I haven't built it, so I don't want to promise it works, but that's the shape I'd explore first.
What I'd push back on gently is "lawyer-friendly implementation" as the framing. The thing that actually decides this is a product question you can answer yourself: what are you inferring, and from what. The lawyer is for after you've written that down.
I also filed the delay as good news until your post. It is sobering that Article 50 was already live. Could you share which screen you use for disclosure? I need a solid example to show our designer.
Murror
@jackthompson68 Happy to describe ours, with one caveat first: treat it as a design reference, not a compliance one. I'm a founder who read the guidance, not a lawyer, and nobody has audited our screen.
Ours is the first screen after sign-up, before the user writes anything. Plain sentence at the top saying an AI reads what you write and writes back, then two lines on what that means in practice, then continue. It isn't a modal over the journal and it isn't in the settings — both of those were versions we tried and both are worse, for the same reason: a disclosure you have to go looking for, or one you dismiss to get to the thing you came for, is a disclosure that competes with the user's intent. Putting it before the first entry costs one tap and nobody has complained about it.
Two things I'd tell your designer that took us a while to learn. Keep it away from the legal copy — ours used to sit next to the terms link and it inherited the "scroll past this" reflex from its neighbour. And write it in the product's voice, not a compliance voice; a sentence that sounds like it was written by counsel reads as boilerplate and gets skipped, which defeats the point.
The other half is that a disclosure at sign-up only covers the person who signed up. If your AI output ever shows up somewhere a second person sees it, that's a separate question and a different paragraph.