EU AI Act Transparency Rules Start 2 August 2026
What they actually ask of you, what moved, and three documents I built to work from
Hello everyone. Here is where the AI Act actually stands as of this week, and it is not where most of the plans I’m seeing assume it is.
The high-risk chapter moved out to 2 December 2027 and 2 August 2028. That part reached everyone.
What stayed exactly where it was is the transparency chapter. Article 50 applies from 2 August 2026, and it reaches further than most people assume.
Your system doesn’t have to be high-risk. Your company doesn’t have to be in Europe. Your model can be open source and it changes nothing.
If the output reaches someone in the EU, the duty is yours, and getting it wrong costs €15M or 3% of worldwide annual turnover.
I’ve put the whole of it into three documents, free, with the primary sources listed on every page.
The EU AI Act: Obligations from 2 August 2026, six pages. What applies and who carries it, twelve controls each with a named owner and one artefact, which of the three possible authorities supervises you, penalty ceilings, and a worked case study.
Proving Article 50, two pages. The four exceptions that hold, what the file has to contain for each, and the Code of Practice route.
The Omnibus amendments, one page. Nine changes, old text against new, with the operational consequence of each.
The rest of this is what I’m seeing on the ground, which worries me more than the deadline does.
Confidence arrived before the text did
I structure AI governance for global companies. I started in technology policy eight years ago, and for the last three this has been the day to day work.
Three months ago my calls were urgent. Teams were mapping systems they’d forgotten they were running, arguing about who owned what, asking for timelines they could take to a board. Then the Digital Omnibus meetings happened, the word postponement travelled, and the same teams came back confident. Some had already moved people off the work. Sixteen months had appeared on the calendar and it read as sixteen months of nothing needing to happen.
The work that takes time was never the compliance work. Writing a disclosure, marking an output, drafting a notice to people exposed to emotion recognition, those are weeks of effort by people who already know how to do them.
I keep finding the same thing in engagements. The decision was made properly, by people who understood the question, in a conversation that left no record, and an exception nobody can produce reasoning for is just an assumption. What takes time is settling five things that no deadline hands you.
Governance. Where AI decisions get made, and who answers for them.
Decision-making. Who is authorised to say an exception applies, against what threshold.
Risk. Whether a gap appears on the corporate risk register or only in the legal file.
Process. Whether the question enters the product workflow before launch or gets patched on afterwards.
Organisation. Which function owns the evidence, and whether that ownership survives a reorganisation.
In a company of any size, that is not a sixteen-month project. It runs longer, it needs executive attention rather than a workstream, and it competes with everything else on that agenda. The deferral bought time for the easy half.
Meanwhile the systems keep getting embedded, which is the pattern I see everywhere and it has nothing to do with Europe. The reasoning goes: it isn’t regulated yet, so we can do it, and the governance question can wait until someone makes us answer it. By the time a model sits under three business processes and a customer-facing product, you aren’t designing governance any more. You’re negotiating with something the company already depends on, and you’re negotiating against your own revenue. Every month of delay raises the cost of the same decision, because the thing you’re deciding about carries more weight.
If you’re working through this
My work is internal governance architecture, vendor and third-party AI risk, guardrail design, governance maturity assessment, corporate AI policy, and EU AI Act readiness including the Article 50 evidence regime. If your company builds AI, buys it, or has quietly ended up running it in a dozen places nobody has mapped, write to me at me@nesibekiris.com.
I work with executive teams, and I’m happy to talk before anyone commits to anything.
Common questions
Was the EU AI Act postponed? Partly. The high-risk obligations in Chapter III moved to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I. The transparency obligations in Article 50 were not deferred and apply from 2 August 2026.
Who does Article 50 apply to? Providers and deployers of AI systems whose output is used in the EU, regardless of where the company is established and regardless of whether the system is high-risk.
Are open-source AI systems exempt? No. There is no open-source exemption from the Article 50 transparency duties.
What are the penalties for breaching Article 50? Up to €15M or 3% of worldwide annual turnover, whichever is higher.
Which authority enforces it? The default is the national market surveillance authority. The AI Office holds exclusive competence in defined cases, and the European Data Protection Supervisor covers EU institutions and bodies.
One thing I’m watching
Agentic AI just appeared in binding EU law for the first time. Annex XIV, a code list for notified bodies. No definition, no criteria, no obligation attached. A placeholder in a statute is an invitation.
💬 Let’s Connect:
🔗 LinkedIn: [linkedin.com/in/nesibe-kiris]
🐦 Twitter/X: [@nesibekiris]
📸 Instagram: [@nesibekiris]
🔔 New here? Subscribe for weekly updates on AI governance, ethics, and policy! no hype, just what matters.



