The Digital Omnibus delayed the AI Act. Boards heard the word delayed and eased off. The single duty most likely to touch an ordinary organisation was never in the delay.
AI Act transparency obligations under Article 50 still apply from 2 August 2026. The Commission published its guidelines on 20 July, days before the rules bite. Run a customer chatbot, generate synthetic content or publish AI-written material, and the date on your roadmap is wrong.
What the Omnibus moved, and what AI Act transparency kept
The simplification package was real. High-risk timelines shifted into 2027 and 2028, sandbox deadlines moved, and genuine pressure came off compliance teams. That relief was widely reported. The reporting is where the misreading started.
Article 50 is not a high-risk obligation. It is a separate layer, and it applies to specific situations regardless of how a system is classified. A chatbot that is minimal risk still carries the duty. That structural point is why the postponement never reached it. It is also why AI Act transparency remains a July problem rather than a 2027 one.
The one exception worth getting right
The AI Act transparency timeline does carry one narrow piece of relief, and it is easy to over-read. Providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement in Article 50(2). Systems placed on the market from 2 August mark from day one.
Read the boundary carefully. The transition covers the marking mechanism, on the provider side only. Deployer disclosure duties are untouched. Content generated before 2 August needs no retrospective labelling, though the Commission encourages it.
AI Act transparency reaches further than most inventories
Here is where organisations underestimate the scope. Article 50 covers four situations, and each catches ordinary commercial activity:
- systems that interact directly with people, which must make the interaction obvious
- generative systems, whose output must be machine-readable as artificial
- emotion recognition and biometric categorisation, which require notice to those exposed
- deepfakes and AI-generated text on matters of public interest, which must be disclosed
A marketing team drafting campaign copy with a generative model sits inside that list. So does a service desk running a chatbot. So does a communications team producing a synthetic voiceover. None of it requires a high-risk classification. The obligation attaches to the situation, not the risk tier.
Where the duty actually sits
The provider and deployer split does the heavy lifting here. Providers carry Articles 50(1), (2) and (5): build the interaction disclosure into the system, mark generated output and make that information clear at first contact. Deployers carry Articles 50(3) and 50(4): give notice before emotion recognition or biometric categorisation runs, and disclose the deepfake or the AI-written text published to inform the public.
Read that split twice, because the duty most people assume is theirs is not. Telling a user they are talking to a machine is built in by the provider. What a deployer owes is the notice, the disclosure and the evidence that both were live. Where you run a system on a customer’s behalf you carry both sets, and AI Act transparency then applies to you twice over. A deployer cannot contract the duty away, and the vendor’s compliance does not discharge it.
What the guidelines add
The guidelines on AI Act transparency clarify scope, exceptions and use cases rather than inventing new duties. They pin down who is in and who is out. That is the question stalling most implementation work right now.
Alongside them sits a voluntary Code of Practice on marking and labelling AI-generated content. Providers and deployers can use it to show they met the obligation in a recognised way.
Voluntary is doing real work in that sentence. The Code is not the law. Signing it does give you an evidence trail a regulator will recognise, and building your own equivalent will cost more than adopting it.
The evidence question nobody asks early enough
Disclosure is easy to demonstrate on the day someone complains. It is much harder to demonstrate for a Tuesday eight months ago.
So AI Act transparency is a documentation problem as much as a wording one. The practical work is not writing a disclosure line. It is deciding where that line lives, who owns it when the chatbot vendor changes and how you would prove it was there throughout. Organisations that treated the AI literacy duty under Article 4 as documentation rather than a training slide already know this shape.
Getting AI Act transparency ready before 2 August
Start with an inventory that answers a narrower question than the usual one. Not which systems use AI. Which systems put AI in front of a person, generate content or infer something about a person’s state. That is your AI Act transparency surface, and it is usually smaller and stranger than the full AI register.
Then map each one to a route and a role. Provider or deployer. Which of the four situations. Who owns the disclosure text and where it appears. What evidence exists that it was live. For generative systems, whether marking lands in August or December, which turns on when the system reached the market.
Finally, check the assumption underneath the exercise. If your roadmap says the AI Act moved to 2027, someone read the Omnibus headline and not the article numbers.
The organisations that find this straightforward are already treating governance as an operating discipline rather than a legal review. We traced that pattern in the three signals that reset the 2026 compliance roadmap. If your AI Act transparency surface has never been mapped, the week before August is a better time to find out than the week after.