What Got Delayed, What Didn't

The 'Digital Omnibus' amendment the Council of the EU gave final approval on June 29 pushed the EU AI Act's high-risk system obligations back significantly. Standalone high-risk systems (Annex III) were originally due August 2, 2026, but that moved 16 months to December 2, 2027, and product-embedded high-risk systems (Annex I) shifted to August 2, 2028.

Article 50 transparency duties were carved out of that delay. The obligation for chatbots and voice agents to disclose that a person is interacting with AI took effect on schedule on August 2, and the AI Office's enforcement powers switched on the same day. Teams that only registered "high-risk rules got delayed" are likely missing an obligation that is live right now.

Three Disclosure Duties, In Practice

Three obligations actually took effect. First, unless it's obvious from context, people must be told they're talking to an AI system. Second, synthetic audio, images, video, and text must carry machine-readable markers identifying them as AI-generated. Third, deepfake content needs separate labeling.

A grace period applies only to the machine-readable marking and detection duty, and only for systems already on the market before August 2, 2026 — those get until December 2, 2026. The human-facing disclosure duty carries no such grace period and applies immediately. Penalties run up to 3% of global annual turnover or €15 million, whichever is greater, and enforcement can reach back to violations from August 2025.

The Post-Enforcement Checklist: From Disclosure Design to Audit Readiness

If your service reaches users in the EU market, this obligation applies regardless of where your company is headquartered, so no team gets a pass by default. Operations teams need pre-deployment targets pinned to numbers: 100% of conversation sessions must surface an AI-identity notice before the first response, the rate of users reporting they mistook the system for a human should stay under 1%, and translation gaps in the disclosure copy across every EU official language your service supports should hit zero.

The failure teams miss most often is a widget vendor's default script that ships without disclosure copy at all, or a single missing translation file that leaves one language's users without any notice. Catching this requires per-language snapshot tests in the deploy pipeline, with a rule that a failing test holds back only that language's rollout rather than blocking everything.

Synthetic-content marking fails differently. If a watermarking API has a brief outage, unmarked content can go out the door, so publishing should trip a circuit breaker on marking failure, retry three times, and route to a human review queue with an explicit backoff rule documented in your runbook.

Pre-launch validation should run scenario tests across three channels — multilingual text, voice, and image — and logs should carry standard fields for disclosure timestamp, user consent status, and watermarking success. Personal data captured in conversation logs should be masked before storage, so an audit request can be answered without exposing raw transcripts.

Audit readiness ultimately comes down to one log. Since the AI Office can request history back to August 2025 in a retroactive inquiry, keep disclosure and marking event logs for at least a year and explicitly exclude them from routine deletion batches.

The Annex III delay to December 2027 is no reason to stand down. Assign someone to track regulatory changes weekly, and each time a disclosure or marking violation case becomes public, log the fine amount and violation type separately to inform next quarter's compliance priorities.

Key Takeaways at a Glance

Even while high-risk system obligations sit delayed until December 2027 and August 2028, AI disclosure and synthetic-content marking for chatbots and voice agents have been live law since August 2. Human-facing disclosure applies now with no grace period; only machine-readable marking on pre-existing systems gets until December 2. With penalties reaching 3% of turnover, the priority is adding disclosure-exposure rate and translation coverage as deployment gate metrics and extending log retention first.

References

Council of the EU — Artificial Intelligence: Council gives final green light to simplify and streamline rules (2026-06-29)

European Commission — Transparency obligations under Article 50 of the AI Act