The EU AI Act deadline that did not get delayed
Brussels delayed the AI Act's high-risk rules, but the August 2 transparency obligations and GPAI enforcement arrived on schedule, and they reach US software companies.
August 2 came and went this weekend, and with it a major EU AI Act enforcement milestone. If you run a SaaS or AI product and your takeaway from the June headlines was that Brussels delayed the whole law, you got half the story. The half that was not delayed applies to you now.
Here is what actually happened. In June, the EU approved its Digital Omnibus package, which pushes the AI Act’s high-risk system obligations out to December 2027 for standalone systems like hiring and credit scoring tools, and to August 2028 for AI embedded in regulated products. That is real relief if you sell into those categories. But the Article 50 transparency obligations were not part of the delay, and neither was the European Commission’s power to enforce the general-purpose AI model rules with fines. Both went live on schedule.
Article 50 is short, but it hits three things most software companies ship today. If your product includes a chatbot or any AI feature that interacts directly with users, users have to be told they are dealing with AI unless it is already obvious. If your product generates synthetic audio, images, video, or text, the output has to carry machine-readable marking identifying it as AI generated. And deployers of deepfake-style content have to disclose that the content is artificial. None of this requires an EU office to apply. If your system is offered in the EU market or its output is used there, you are in scope, and the penalty ceiling is 15 million euros or 3 percent of global revenue.
The operational reality for most US companies is that you are not the model provider. You are wrapping an API from OpenAI, Anthropic, Google, or someone else. That helps less than you might think. The disclosure duty for a user-facing AI feature is yours, and it is a product decision, not a legal memo: label the assistant in the interface and move on. The marking duty is trickier because it is an engineering question. The major model providers are increasingly embedding provenance metadata in generated content, but a surprising number of applications strip that metadata in their own pipeline when they resize images, transcode video, or copy text into a new document. Having written code before contracts, I can tell you this is exactly the kind of compliance failure that happens three layers down the stack while everyone above assumes the vendor handled it.
The concrete step for this quarter: inventory every user-facing AI feature that can reach an EU user and answer two questions for each. Does the user know it is AI, and does generated output keep its provenance marking end to end. Write the answers down in a one-page memo with an owner and a date next to each gap. If the December 2027 high-risk deadline is also on your horizon, note it, but do not let the delay you read about become the reason you missed the deadline that arrived on time.