HomeBlog

Plain-English Briefing

The AI deadline on Sunday — and why you probably think it was cancelled

By Charlie Essex · 30 July 2026 · 5 minute read

Europe’s AI rules were all over the news in the spring for being delayed. Most of them were. One part was not, it starts on 2 August, and it is the part that touches ordinary businesses rather than technology companies.

What happened

The EU AI Act was passed in 2024 and switched on in stages. The big, expensive stage — the rules for “high-risk” systems like AI used in recruitment, credit scoring or medical devices — was due to land on 2 August 2026.

In the spring the EU agreed a package of amendments (the “Digital Omnibus”) which pushed that high-risk stage back to December 2027 and August 2028. The coverage was accurate and everybody relaxed. Boards heard “delayed” and filed the whole regulation under next year.

But the Act has a separate, smaller layer called Article 50, and Article 50 is not a high-risk rule. It is a transparency rule, it applies regardless of how risky the system is, and the amendments deliberately left it alone. It still starts on 2 August 2026.

The part that was hardest to engineer, for the largest number of companies, is the part that stayed on schedule.

What Article 50 actually asks for

Stripped of the legal language, it is about telling people when they are dealing with AI. Four situations:

There is one narrow bit of slack. Providers of generative systems also have to embed machine-readable markers — watermarking — in what their systems produce. Systems already on the market before 2 August have until 2 December 2026 for that one requirement, and only that one. That obligation sits with whoever built the AI, though: if you use somebody else’s tool, it is their engineering problem, not yours.

“We’re in the UK, so this doesn’t apply to us”

This is the assumption I hear most, and it is the one worth checking rather than accepting. The Act keys off who your AI reaches, not where your office is. If you have customers in the EU, or your website serves people there, it can reach you — and after Brexit a great many Sussex firms still sell into Europe without thinking of themselves as doing anything international.

I am not going to tell you whether it applies to your business, because I do not know and neither does anybody who has not looked at your specific setup. What I would say is that “we’re not in the EU” and “we’re not high-risk” are both reasonable-sounding sentences that do not settle the question, and both are the reasons people give for not having checked.

The penalties attached to the transparency duties run to €15 million or 3% of worldwide turnover. For a firm of ten people that figure is not the realistic risk — regulators have limited attention and bigger targets. The realistic risk is a customer, a prospect or a competitor asking a question you cannot answer.

What this means for a normal business — honestly

I sell AI systems for a living, so assume I am biased and read accordingly. Here is my honest read.

For most small businesses this is a short piece of admin rather than a project. If you have a chatbot, label it. If you publish AI-written or AI-generated material where a reader would reasonably assume a person made it, say so. Write down which AI tools you use and what they touch. That is most of it.

What it is not is a reason to panic-buy anything, including from me. Nothing about a server in your building makes a disclosure duty go away — if your chatbot needs a label, it needs a label whoever hosts it. Anybody selling you software as a way to satisfy a regulator is selling you something that does not exist.

Where the two do genuinely connect is duller: every one of these duties starts with knowing what AI is in use across your business and what it is doing. That is the same list you need for a policy, for an insurance form, and for a customer’s procurement questionnaire. Most businesses cannot produce it, which is why the first ten minutes of any audit I run is spent making one.

And there is a wider point that outlasts this particular date. Regulation is drifting towards being able to show what your AI did and why. Systems that can point at where an answer came from are easier to explain than systems that cannot. That is worth knowing when you choose tools, and it has nothing to do with Sunday.

Worth doing this week, whatever you buy (including nothing)

  1. Look at your website for anything that answers questions. A chat widget, a help assistant, an automated reply. If a visitor might take it for a person, say plainly that it is not.
  2. Ask where AI-written content goes out under your name. Marketing copy, product descriptions, generated images. You do not need a banner on everything — you need to know where it is.
  3. Write down which AI tools your team actually uses. Not the approved list — the real one. Almost every business I ask is wrong by two or three tools.
  4. If you sell into the EU, put it in front of whoever does your contracts. Half an hour of proper advice now is cheaper than the alternative, and this article is not that advice.

Our free AI policy pack builds the tools register, use policy, staff agreement and incident plan for you — personalised in about two minutes. No email, no catch, and nothing you type leaves your browser.

Get your free AI policy pack

Where this came from

The obligations are in Article 50 of Regulation (EU) 2024/1689. The amendments that moved the high-risk deadlines, and pointedly did not move this one, are the Digital Omnibus on AI agreed in May 2026 and approved in June. The European Commission has published draft guidance and a voluntary Code of Practice on transparency of AI-generated content. I have linked the Act itself rather than a summary, because on a question like this you want the primary source.