On 2 August 2026, the transparency obligations set out in Article 50 of the EU AI Act (Regulation 2024/1689) become applicable, together with the full sanctions regime. The date does not, however, bring the wave of high-risk obligations many organisations had been bracing for: those have been pushed back by the so-called Digital Omnibus.
Two different clocks, one date that stays fixed
The AI Act entered into force in August 2024 and was always designed to apply in stages. Prohibited practices and AI-literacy duties became binding on 2 February 2025. Rules for general-purpose AI (GPAI) models, along with the governance architecture and the sanctions framework, followed on 2 August 2025. The date of 2 August 2026 was originally meant to be the point at which the bulk of the regulation, including the demanding requirements for high-risk systems listed in Annex III, came fully into force.
That plan changed with the Digital Omnibus, the simplification package the European Commission presented on 19 November 2025. A provisional agreement between Council and Parliament reached on 7 May 2026, with formal adoption expected by July 2026, moved the Annex III high-risk obligations from 2 August 2026 to 2 December 2027. For AI embedded in products already covered by other EU safety legislation (Annex I), the deadline shifts further, to 2 August 2028.
What has not moved is Article 50. Transparency duties, the sanctions regime under Articles 99 and 101, the operational start of national supervisory authorities, and the requirement for each member state to run at least one AI regulatory sandbox all remain anchored to 2 August 2026.
What Article 50 actually requires
The obligation splits into two strands. The first concerns interaction: any organisation that makes an AI system available to converse with people, a chatbot on a public-facing website, for instance, must ensure the person knows they are talking to a machine, unless that is already obvious from context. The second concerns content: images, audio, video and text generated or substantially altered by AI must carry a machine-readable marking, whether through metadata, watermarking or cryptographic identifiers, provided the method is technically robust and interoperable.
Two categories carry an explicit disclosure duty rather than a technical one. Deepfakes must be declared as such to whoever is exposed to them. Text published to inform the public on matters of general interest must be labelled as artificially generated, unless it has passed through human review or editorial control. Systems that perform emotion recognition or biometric categorisation require prior notice to the people who will be exposed to them, regardless of whether the underlying system is classed as high-risk.
These duties apply irrespective of a system’s risk tier under the Act. A company that runs a customer-service chatbot or produces marketing images with a generative tool is inside this perimeter from 2 August 2026, whether or not any of its systems are classified as high-risk.
Who is responsible: provider and deployer
The regulation assigns duties to two roles that frequently coexist in the same organisation. The provider is whoever develops a system or places it on the market under its own name; the provider’s job, under Article 50(2), is to build the machine-readable marking into the system so it is applied automatically. The deployer is whoever uses that system professionally; the deployer’s job is to make the disclosure visible to the end user, declare deepfakes, and label AI-generated public-interest text. An organisation that substantially modifies a third-party system, or rebrands it as its own, can find itself reclassified as a provider, with the fuller set of obligations that follow.
This distinction matters in practice because responsibility does not sit with one party alone. A supplier can embed the technical marking correctly and a client can still fail its own disclosure duty toward its audience, or vice versa.
Penalties, and where the sources disagree
The sanctions regime becomes fully enforceable on the same date, and national authorities gain the power to act on breaches. The exact ceiling cited for penalties varies depending on the source consulted: one account puts the maximum at up to €35 million or 7% of global annual turnover for the most serious violations, while another cites a ceiling of 3% of global turnover specifically for transparency breaches. The discrepancy likely reflects the fact that the AI Act sets different penalty tiers for different categories of infringement, and it is a reminder that the enforcement detail is still settling as authorities begin to apply it. What is not in dispute is that GPAI obligations, including technical documentation, training-data summaries and copyright compliance, have been in force since August 2025, with a transitional window until 2 August 2027 for models placed on the market before that date.
DIVE’s reading: what this means for immersive and AI-driven projects
This regulation is not an abstract compliance exercise for the sector DIVE operates in. XR studios routinely build the exact things Article 50 targets: conversational guides and virtual assistants in museums, synthetic narration and cloned voices for exhibitions, AI-generated visuals for scenography, and, in a growing number of installations, gaze-tracking or biometric sensing used to adapt content to a visitor in real time. Every one of these falls somewhere inside the perimeter described above.
The practical consequence is that labelling and disclosure can no longer be treated as an afterthought bolted on before launch. If a museum commissions an AR guide voiced by a synthetic character, the marking of that content needs to be part of the technical brief from the first design meeting, not something added when a legal team flags it months later. The same applies to any installation using emotion recognition or gaze-based biometric categorisation to personalise a scene or measure engagement: visitors need to be told before they are exposed to it, and that notice has to be built into the visitor journey, not buried in a consent form nobody reads.
There is also a contractual question that public and private clients should raise early. On most XR projects, the studio building the system is the provider and the museum, agency or company deploying it is the deployer. Both carry obligations, and neither should assume the other has covered them. A contract that does not specify who applies the machine-readable marking, who issues the visitor-facing disclosure, and who documents the AI components used in a given experience leaves both sides exposed, particularly once national supervisory authorities are operational and able to act on complaints.
For public procurement specifically, this is worth watching closely. Once compliance becomes routinely enforceable, it is a reasonable expectation that public tenders for AI-enabled or immersive experiences will start asking bidders to demonstrate how transparency obligations are met, not just describe the creative concept. Studios that can show, concretely, how their pipeline generates and labels synthetic content, and how their systems disclose AI interaction to end users, will have an easier time in that kind of evaluation than those that treat it as paperwork to sort out after the contract is signed.
The postponement of high-risk obligations to December 2027 does buy time on the heaviest requirements, and that is genuinely useful for anyone planning multi-year cultural or training programmes involving biometric or high-risk classification. But it should not be read as a reason to delay building disclosure and labelling practices into current work. The transparency duties are narrower in scope than the high-risk regime, but they apply now, to a much wider range of everyday AI use than most organisations commissioning immersive content probably assume.