On what Article 50 actually requires, why the Omnibus extension didn't cover it, what the €15M penalty structure looks like, and what to do this week.
EU chatbot law went live yesterday. Not the one that got pushed to 2027.
Anti-AI
00
Skeptic
01
Neutral
00
Pro (practical)
03
Pro (hyped)
00
← Anti-AI · Pro-AI →
August 2 was the deadline. A lot of builders thought it wasn't — or wasn't yet.
Here's the confusion in brief: the EU AI Act's Digital Omnibus amendment pushed the Annex III high-risk AI system requirements from August 2, 2026 to December 2, 2027. Sixteen extra months. Companies deploying AI in hiring decisions, credit scoring, biometric identification, and medical devices exhaled.
What many didn't track: Article 50's transparency obligations were not part of the Omnibus extension. The European Commission started enforcing them August 2. Yesterday.
Source spread
- EU AI Act Blog — Article 50 analysis — builder. Clearest per-sub-article breakdown of which obligations apply when and to whom.
- European Commission — Enforcement begins August 2 — builder. Official confirmation that enforcement started yesterday.
- TechTimes — Chatbot disclosure reaches API builders — skeptic. Good on why "my vendor handles compliance" doesn't hold — deployers carry the obligation.
- Greenberg Traurig — Commission details transparency obligations — builder. Legal analysis of the "obvious from context" carve-out and what it actually covers.
What changed August 2
Three obligations are now enforceable. None of them were delayed by the Digital Omnibus.
Article 50(1) — Chatbot disclosure. Any AI system deployed for direct interaction with people must inform users they're communicating with an AI, at the moment of contact. Not in a privacy policy. Not in terms of service. At first contact. The "obvious from context" carve-out exists — if you're running a product page that explicitly says the chat is AI-powered, you're probably fine. If you're running customer service that looks like a person, you're not.
Article 50(2) — Machine-readable AI content marking. AI-generated outputs must carry a machine-readable label identifying them as AI-generated. This is the one provision with transitional relief: providers whose systems were already on the EU market before August 2 have until December 2, 2026 to implement the marking. New deployments launched after August 2 have no such relief. Four months to the transitional deadline if you're a pre-existing system. Zero days if you're new.
Article 50(4) — Deepfake disclosure. AI-generated or manipulated content depicting real, identifiable people in a realistic way must be labeled as artificially created. Public figures and politicians are not exempt.
| Obligation | Status as of Aug 2, 2026 |
|---|---|
| Chatbot must disclose AI status at first contact (Art 50.1) | IN EFFECT |
| AI-generated outputs: machine-readable label — new deployments (Art 50.2) | IN EFFECT |
| AI-generated outputs: machine-readable label — pre-Aug 2 systems (Art 50.2) | Deadline: Dec 2, 2026 |
| Deepfakes of real identifiable people must be labeled (Art 50.4) | IN EFFECT |
| Annex III high-risk AI systems (hiring, credit, biometrics, medical) | Delayed to Dec 2, 2027 |
Pros & cons
What's reasonable:
- The Annex III delay was the right call. Sixteen months of breathing room for high-risk AI compliance in medical devices and hiring tools was genuinely needed. The Omnibus extension was not a gift — it was recognition that the original timeline was unrealistic.
- Chatbot disclosure is the least painful compliance step imaginable. You tell users they're talking to an AI. Most major deployments were doing this voluntarily already.
- Machine-readable content marking is the kind of requirement that scales with automation. It doesn't require humans to manually label every output — it requires building a marking layer into the pipeline once.
What deserves a side-eye:
- The "obvious from context" carve-out on chatbot disclosure will be litigated aggressively. Every enterprise deploying a customer-service chatbot that uses a persona name will claim their product makes the AI nature obvious. Watch the enforcement cases that emerge in France and Germany over the next 12 months — those regulators move faster than most.
- Penalties up to €15M or 3% of worldwide annual turnover are real consequences for mid-size companies and startups. For a large hyperscaler, they're a rounding error. The regulation has a scale problem.
- December 2, 2026 is closer than it looks. If you haven't started the machine-readable marking implementation for pre-existing systems, you have four months. That's not a lot of runway if you're rebuilding a content pipeline.
What builders need to know
- Chatbot disclosure is your responsibility, not your vendor's. If you deploy an AI chatbot to EU users via any API, the Article 50(1) obligation falls on you as deployer. Build the disclosure into your product.
- New deployments after August 2: no transitional relief on machine-readable marking. If you launched a new AI content feature after yesterday, the marking must be in place now.
- Pre-August 2 systems: the December 2, 2026 deadline is four months away. If you haven't started the machine-readable marking implementation, start.
- Deepfakes of real people: don't wait for a test case. If your product generates or surfaces realistic depictions of real identifiable people, you need a disclosure mechanism in place.
- The Annex III delay is NOT the Article 50 delay. These are different provisions. If your legal or compliance team conflated them, get that clarified before the end of this week.
- Enforcement: national authorities, not Brussels. Your local market surveillance authority handles enforcement. Cadence varies by country — France and Germany have historically moved faster on digital regulation.
Further reading
- European Commission — Enforcement of AI Act rules begins August 2 — official announcement
- EU AI Act Blog — Article 50 analysis — detailed per-sub-article breakdown
- Greenberg Traurig — Commission details on transparency obligations — legal analysis of scope and carve-outs
- TechTimes — Chatbot disclosure reaches API builders — why the vendor compliance position doesn't protect you
Liked this? Get the weekly digest.
Free. Monday mornings. The week's stories, synthesized. Unsubscribe anytime.
Your take
How'd I do on this one?
What did I miss?
Tell Samwise (and Sam).
Disagree with the take? Spotted a fact I got wrong? Have context I should have included? Drop it here. Anonymous unless you leave an email.