A conversation about 2 August
Micheal Morrissey · 26 July 2026
Around the middle of May the headlines all said roughly the same thing, which was that Brussels had delayed the AI Act, and ever since then I have been having a version of the same conversation with people who read those headlines and quite reasonably concluded that August was off the table. It is not off the table. It got smaller, and it got quieter, and in my experience a quiet deadline is a good deal more dangerous than a loud one, because nobody puts a quiet deadline on the board paper.
The Digital Omnibus on AI is finished, and as of Friday it is law. Parliament adopted the agreed text on the sixteenth of June, the Council signed off on the twenty-ninth, the act was signed on the eighth of July, and it was published in the Official Journal on the twenty-fourth as Regulation (EU) 2026/1744. It enters into force tomorrow, on the third day after publication, and the regulation justifies that compressed timing as a matter of urgency because the date it is amending falls the following week.
The relief in it is genuine, which I want to be fair about, because a fair bit of commentary has treated the Omnibus as some sort of sleight of hand and it is nothing of the sort. The heavy high-risk regime for the Annex III categories, the one covering recruitment tools and credit scoring and insurance pricing and the rest of it, moves from the second of August this year out to the second of December 2027, and where the AI sits inside a product already governed by EU product safety law it moves further again to August 2028. Those are now fixed calendar dates rather than the conditional ones originally proposed, which is worth knowing, because the November draft tied them to a later finding that the standards were ready and the adopted text dropped that condition entirely.
What did not move is Article 50, and Article 50 applies from the second of August, which is a week from today.
Article 50 is the transparency layer and it has nothing to do with whether a system is high-risk, which is precisely why the deferral does not reach it. If you run a chatbot, the person on the other end has to be told they are talking to a machine. If you generate synthetic audio or images or video or text, the output has to be marked in a machine-readable form so it can be detected as artificial. If you produce a deepfake you have to disclose it, and if you publish AI-generated text to inform the public on a matter of public interest you have to disclose that too. That catches a marketing team drafting public copy, a service desk running a bot, and a communications function producing anything synthetic, none of which anybody would describe as a high-risk AI deployment, and all of which are squarely in scope.
The same date brings the enforcement machinery with it, which is the part that tends to get missed. From the second of August the Commission and the national market surveillance authorities have the power to fine, and the general-purpose AI provisions become enforceable. The obligation and the penalty arrive together, so there is no comfortable window in which the duty exists on paper and nobody can act on it.
There is one narrow piece of breathing room and it is worth understanding precisely how narrow it is. Generative systems already placed on the market before the second of August get until the second of December this year to meet the machine-readable marking requirement under Article 50(2). That is a provider transition for legacy systems and it is not a general pause, so the chatbot disclosure and the deepfake disclosure still land next week regardless. The second of December also brings the new prohibitions the Omnibus added to Article 5.
For the financial services firms I work with there is a second layer to this, because the AI system that decides something about a customer is almost always running on ICT that DORA already governs. The AI Act asks who signed off on the model and the DORA register asks who provides the service underneath it, and firms that answer those two questions separately end up doing the work twice and then answering inconsistently when somebody puts them side by side. It is the same inventory, the same owners and the same evidence trail, and it is considerably cheaper to build it once.
With a week left there is a short list that is worth a good deal more than a programme. Find every place your organisation puts AI output in front of a person or out into the world, which usually takes an afternoon and usually turns up two or three that nobody had written down. Check what the chatbot actually says when it opens a conversation. Check whether anything you publish that was drafted or generated by a model carries a disclosure. Ask your vendors in writing how they are meeting Article 50(2), because if you are deploying somebody else's generative tool then their marking is your exposure. And write down who owns the answer, because from next week the question stops being rhetorical.
None of that amounts to a compliance programme and I would not pretend otherwise. It is the difference between being able to answer the question and not being able to, which is generally where these things start.
If you want to know which of the two dates you are facing, the free assessment takes ten minutes and gives you a scored report.
Morclear Europe delivers AI-powered, expert-reviewed compliance services to mid-market regulated organisations across the EU. CORA™ (Compliance Operations & Risk Automation) is powered by the Anthropic Claude API, and every output is reviewed by a named compliance professional before it leaves us.
Primary sources: EU AI Act, Reg. (EU) 2024/1689. Digital Omnibus on AI, Reg. (EU) 2026/1744, OJ 24 July 2026. European Commission guidelines on Article 50, 20 July 2026. DORA, Reg. (EU) 2022/2554.
morclear.com · morclear.ai · hello@morclear.com