Skip to main content
Blog
Artificial Intelligence··11 min read

The EU AI Act: what already applies to you and what got pushed to 2027

Carlos Dodero
Founder of Elevatec · AI lecturer on the UAX AI degree and master's programs

The short answer

Since 2 August 2026, the transparency obligations in Article 50 of the EU AI Act apply to any organization operating in the European Union, whether or not it runs high-risk systems. In practice they mean two things: a system that talks to people must say it is an AI, and any synthetic content you generate must be marked in a machine-readable format. The Omnibus Regulation (EU) 2026/1744, published on 24 July 2026, pushed the high-risk obligations in Annex III to December 2027 and those in Annex I to August 2028, but left transparency untouched. Breaching Article 50 can cost up to 15 million euros or 3% of worldwide annual turnover, and for SMEs the lower of the two figures applies.

What changed on 2 August, in two sentences

On 2 August 2026 the transparency obligations in Article 50 of the EU Artificial Intelligence Regulation started to apply. They cover any organization operating in the European Union or serving European users, regardless of size and regardless of whether it runs systems classed as high risk.

A week earlier, on 24 July, the Omnibus Regulation (EU) 2026/1744 was published, and it delayed the high-risk part: the Annex III obligations move to December 2027 and the Annex I obligations to August 2028.

That is where the confusion of this summer comes from.

The misunderstanding: not everything was delayed

August brought a lot of headlines along the lines of "Brussels delays the AI law". That is half true, and the missing half is the one that touches more companies.

What got delayed affects few companies, very demandingly: high-risk systems, meaning recruitment, credit scoring, insurance, healthcare, education, biometrics, critical infrastructure, justice, migration and essential public services.

What did not get delayed affects almost everyone, quite simply: transparency. That came into force with no extension.

If your company does not do credit scoring or automated CV screening, you probably assumed none of this was about you. If you have a chatbot on your website, it has been about you for a month.

If you have a chatbot, this applies to you today

Article 50 says systems that interact directly with people must tell the user they are dealing with artificial intelligence. The exception is where it would be obvious to a reasonably well-informed and observant person.

That exception is the trap, and it is narrower than it looks. An assistant that introduces itself as "I'm the [company] assistant" is not saying it is an AI: it is saying it is an assistant, which is exactly what a person on the support team would also say.

We checked our own website while writing this. Our chatbot opened with "Hi, I'm the Elevatec assistant." Right in tone, not enough in substance. We have already changed it.

The fix takes two minutes and does not require filling the interface with legal notices. The first sentence just has to say it plainly.

  • Say it in the first message, not in a footer. The notice has to arrive before the person starts explaining their situation, not after.
  • In plain language. "I'm an AI assistant" is understood. "Automated natural language processing system" informs nobody.
  • And offer the way out to a human. Article 50 does not require it, but a chatbot that knows when to hand over converts better and generates fewer complaints.

AI-generated content has to be marked

The second half of Article 50 is the one almost nobody has looked at yet. Anyone generating synthetic audio, image, video or text content has to mark those outputs in a machine-readable format.

Machine-readable is the important part. Writing "image generated with AI" under the photo is not enough: the marking has to sit in the file metadata, so a system can detect it without reading the page.

This catches more people than you would think. If you generate images for social media, blog illustrations, voiceovers or video with AI tools, you are in scope.

The good news is that serious tools already do it: the major ones embed content credentials in the metadata. The bad news is that plenty of workflows strip them, because resizing an image or running it through a compressor wipes metadata without warning.

What it costs to get this wrong

Breaching Article 50 can reach 15 million euros or 3% of worldwide annual turnover.

And here is the detail almost no article gets right, because it changes the whole conversation inside a smaller company. Article 99(6) sets a specific regime for small and medium-sized enterprises and for start-ups: the fine is calculated on the lower of the two figures, not the higher.

So a company turning over two million euros is not exposed to fifteen million. It is exposed to 3% of two million, which is sixty thousand euros.

Sixty thousand is still a lot of money for not having written one sentence into a chatbot. But it is a number you can take to a board, and it is the correct one.

Why the delay is bad news if you use it as an excuse

This is the uncomfortable part.

High risk moving to December 2027 sounds like sixteen months of breathing room. For a company using AI in recruitment or in credit decisions, it is not.

The Annex III obligations are not paperwork you clear in the final quarter. They ask for technical documentation of the system, event logging, effective human oversight, quality management of the training data and a conformity assessment. None of that can be improvised on top of a system already in production that nobody designed with it in mind.

We saw the same pattern with GDPR: the companies that handled it in the architecture paid a fraction of what the ones rebuilding systems afterwards paid. Rebuilding always costs more than designing.

So the delay is not free time. It is the room you have to do it properly instead of in a hurry. If your company falls under Annex III and you have not started, you have already spent one month of the sixteen.

What to check this week

None of this needs a project or a committee. For most companies it is an afternoon's work.

  • Open your own website and talk to your chatbot. Does it say it is an AI in the first message? If it just says "assistant", change it today.
  • Inventory where you use AI facing customers. Chatbots, automated email replies, WhatsApp support, avatars, voiceovers. There is usually more of it than you remember.
  • Check the metadata on an AI-generated image you have published. If your workflow resized it, the content credentials have probably been stripped.
  • See whether any of your systems falls under Annex III. Recruitment, credit, insurance, healthcare, education, biometrics. If the answer is yes, you have until December 2027 and it is worth starting now.
  • Write down what you checked and when. Traceability is half of compliance, and it costs one document.

If you would rather we looked at it

At Elevatec we implement artificial intelligence inside companies and design compliance into the architecture, not as a legal review at the end. It is cheaper and it turns out better.

If you have a chatbot, generate content with AI, or think one of your systems might fall under Annex III, book a thirty-minute call and we will go through it with you. No strings attached: in half an hour you will know whether you have anything to fix and how much work it is.

And if it turns out you have nothing to fix, that is a useful answer too.

Sources

This article draws on the following publications, consulted in September 2026:

Frequently asked questions

The Article 50 transparency obligations trigger when an AI system interacts with people or generates content you publish. If your use is purely internal, drafting or summarizing documents that never leave the company, you are not in scope. The moment that content is published or the system talks to a customer, you are. The line is not the tool, it is whether someone outside is on the other end.

You do not need a legal notice or a long text. Article 50 requires you to inform people that they are interacting with artificial intelligence, and one sentence in the first message covers it. "I'm an AI assistant" is enough. What is not enough is introducing it only as an "assistant", because a person would say that too.

Up to 15 million euros or 3% of worldwide annual turnover. For SMEs and start-ups, Article 99(6) applies the lower of the two rather than the higher: a company turning over two million is exposed to sixty thousand euros, not fifteen million. The authority also weighs severity, duration and how far the company cooperated.

Only if your company falls under Annex III, and even then it is unwise. The high-risk obligations call for technical documentation, event logging, human oversight and a conformity assessment, and none of that can be improvised on a system already running in production. What was delayed was the date, not the work. And transparency was not delayed at all.

Yes, recruitment and human resources management sit in Annex III. That covers automated CV screening, ranking candidates by score and tools that assess people during a process. Their obligations moved to December 2027, but if the system also converses with candidates, transparency has applied to it since August 2026.

AESIA, the Spanish Agency for the Supervision of Artificial Intelligence, based in A Coruña. It is the national market surveillance authority for the regulation. Where personal data is involved it overlaps with the Spanish Data Protection Agency, so in practice it is worth reviewing the AI Act and GDPR together rather than separately.

AI ActcompliancetransparencychatbotGDPR

Ready to work together?

Schedule a meeting or tell us about your project. We respond quickly, no strings attached.