AI-generated editorial note: This article was generated with AI from the official European Commission and EUR-Lex sources below. It has not received prepublication human editorial review or legal review. It is operational implementation commentary, not legal advice.
Operational takeaway: The EU AI Omnibus moved defined high-risk-system dates. It did not turn the August 2 transparency date into a wait-and-see date.
The EU's AI Omnibus entered into force on July 27, 2026. For high-risk systems covered by Article 6(2), the provisions in Chapter III, Sections 1 to 3—apart from Article 6(5)—now apply from December 2, 2027. For high-risk systems covered by Article 6(1), those provisions apply from August 2, 2028.
That is a real timetable change. It is not a blanket delay for the AI Act.
The European Commission's Article 50 overview, updated on July 28, links to Guidelines published on July 20 and says that transparency obligations for certain interactive and generative AI systems apply from August 2, 2026. The Commission's July 24 FAQ identifies one limited transition: providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content and placed on the market before August 2, 2026, must take the necessary steps to comply with Article 50(2) by December 2, 2026.
Operational leaders should not translate "high-risk rules were delayed" into "all AI work can wait." They should identify where people encounter AI or its outputs, determine which role and obligation applies with legal counsel, and put the approved control at that exact workflow boundary.
Disclosure is not a footer task. It is a system-design and release-control task.
What Article 50 means at the workflow level
Article 50 does not create one universal label for every AI use. It assigns different transparency duties to providers and deployers in defined situations, with scope tests, exceptions, and transition rules.
The Commission's guidance highlights several distinct boundaries:
| Workflow boundary | What the official guidance says | Operational question |
|---|---|---|
| An AI system directly interacts with a person | Providers must design the system so the person is informed from the start of the first interaction, unless the interaction is obviously with AI; Article 50 states a defined law-enforcement exception | Where does the first real two-way exchange begin across the website, portal, app, voice channel, or support flow? |
| A system generates synthetic text, audio, images, or video | Providers may have machine-readable marking and detectability obligations; Article 50 and the guidance describe exclusions, a defined law-enforcement exception, and a transition for qualifying pre-August 2 systems | Does the selected provider support the required marking, and does the mark survive editing, export, resizing, or channel delivery? |
| A deployer exposes people to emotion recognition or biometric categorisation | The people exposed must be informed of the system's operation, subject to a defined law-enforcement exception | Which camera, call, identity, workplace, event, or customer workflow creates the exposure, and who owns the notice? |
| A deployer publishes a deepfake | Subject to the defined law-enforcement exception, the disclosure must be clear and perceivable to people; a hidden machine-readable mark alone is not enough. Artistic, creative, satirical, fictional, or analogous works have a special disclosure regime | At what point will a visible or audible disclosure travel with the final content? |
| A deployer publishes AI-generated or manipulated text for the purpose of informing the public on matters of public interest | Subject to the defined law-enforcement exception, the text must be labelled unless it has undergone human review or editorial control, together with editorial responsibility for publication | Is there a competent reviewer with authority to change or reject the substance, and a person or entity that accepts editorial responsibility? |
These rows are a starting map, not a legal classification. The exceptions are obligation-specific and subject to conditions; they are not general carve-outs. A business can be a deployer in one workflow and take on a different role in another. Territorial reach, responsibility, exceptions, and the exact control require legal assessment.
The Commission's Guidelines are non-binding. They support implementation, but only the Court of Justice of the European Union can give an authoritative interpretation of EU law.
Why a policy page is the wrong layer
A general AI policy can explain principles. It cannot place a disclosure inside a live interaction or preserve one through an output pipeline.
Consider a customer-service assistant connected to a website, Zoho Desk, CRM, an order system, and a human handoff. The first AI interaction may start in a chat widget, continue in a portal, and later surface as a draft response for an agent. The notice, handoff language, transcript, role permissions, and escalation path live in different parts of the system.
Or consider AI-assisted product content. A model may generate a draft, a merchandiser may edit it, Shopify may publish it, marketplaces may syndicate it, and an ERP or product-information system may retain another version. A control added only at the first step can disappear after transformation or export.
The same issue appears in document and reporting workflows. An AI-generated summary may move from an intake queue into Zoho Creator, Odoo, a finance approval, or a management report. The Commission's FAQ says outputs exclusively exchanged and processed machine-to-machine without human exposure may fall outside one specific marking obligation. That does not justify treating an entire mixed workflow as machine-only when a later step shows the output to a person.
The useful artifact is an AI boundary register:
- the use case and business owner;
- the people or systems that receive the interaction or output;
- the organisation's role for that use case;
- the approved legal interpretation;
- the disclosure, marking, review, or exception relied on;
- the channel and exact point where the control appears;
- the evidence retained after testing.
That register turns a broad regulation into an implementation backlog.
An implementation checklist before August 2
Use this checklist to prepare a counsel-approved operational response. It is not a substitute for legal advice.
- Inventory workflows, not just vendors. List customer-facing agents, chatbots, content tools, support assistants, image and audio generation, analytics narratives, document intake, and internal systems that expose AI output to people. One vendor can appear in several materially different use cases.
- Assign a business and legal owner. Name the person who owns the workflow and the counsel or compliance owner who decides scope. Do not leave classification to a software administrator or model provider alone.
- Map provider and deployer roles per use case. Record who built or placed the system on the market, who operates it, who controls the output, and where the output is used. Avoid one organisation-wide label that ignores different roles.
- Locate the first human-facing boundary. For interactive AI, trace the first genuine two-way exchange. Check web, mobile, portal, voice, embedded widgets, authenticated and anonymous paths, and accessibility behavior.
- Verify provider capabilities. Obtain current documentation for machine-readable marking, export behavior, APIs, model versions, retention, and known limitations. Test whether the chosen control survives the transformations the business actually performs.
- Separate public-interest text from ordinary drafts. If counsel says Article 50(4) applies, either implement the required label or define human review or editorial control, together with editorial responsibility for publication. The Commission says spell-checking or grammatical correction alone is not substantive human review.
- Review generated media and sensitive-system exposure. Identify deepfake, emotion-recognition, and biometric-categorisation paths separately. Do not assume the same notice or exception applies across them.
- Make the control travel. Check copies, downloads, emails, social publishing, marketplace feeds, CRM attachments, ERP records, reports, and archived versions. A disclosure that vanishes on export is not an operational control.
- Design failure behavior. Decide what happens if a disclosure component fails, a provider stops supplying a mark, a channel strips metadata, or a reviewer is unavailable. Block, queue, label, or route the output according to the approved risk decision.
- Test representative journeys. Use realistic user roles, languages, devices, content formats, and downstream handoffs. Automated checks can confirm presence and persistence; a responsible person should confirm clarity, context, and the business outcome.
- Retain implementation evidence. As an operating recommendation, keep the owner, decision record, vendor documentation, configuration version, screenshots or samples, test result, approval, exception, and change history. Do not describe this evidence pack as a universal statutory checklist.
- Schedule re-review. Regulations, guidance, provider behavior, and business use cases change. Recheck the register after model, channel, workflow, or legal-guidance changes instead of treating August 2 as a one-time launch.
Risks and limits
- For Article 6(2) systems, the Omnibus moved the application of Chapter III, Sections 1 to 3—apart from Article 6(5)—to December 2, 2027; for Article 6(1) systems, it moved those provisions to August 2, 2028. It did not postpone every AI Act obligation.
- Article 50 does not apply identically to every AI system, output, provider, or deployer.
- The limited December 2 transition described by the Commission concerns a specific Article 50(2) marking and detection scenario for qualifying systems already on the market. It is not a general grace period.
- The Commission's Code of Practice is voluntary. Applicable Article 50 duties remain legal obligations whether an organisation signs the code or demonstrates its approach another way.
- Human review or editorial control, together with editorial responsibility, relates to the stated exception for qualifying public-interest text. It does not replace duties that may apply to direct AI interactions, machine-readable marking, biometrics, emotion recognition, or deepfakes.
- A visible notice does not fix inaccurate outputs, unsafe decisions, weak permissions, data leakage, bias, or poor escalation. Transparency is one control inside a wider operating system.
- AorBorC can implement a legally approved workflow design, integration, test, and evidence path. It does not provide legal advice or decide regulatory applicability.
Where the hype is not useful
The wrong responses sit at both extremes.
One is panic: place a generic "AI-powered" badge across every screen, rewrite every workflow, and call the work complete. The other is delay: assume the Omnibus moved all obligations and leave live customer interactions untouched.
Neither response starts with scope. Neither proves that the right control appears at the right moment.
Vendor claims are not enough either. A provider may support a machine-readable mark while the business strips it during editing or export. A chatbot platform may offer a disclosure component while a custom mobile route bypasses it. A human may click "approve" without reviewing the substance or having authority to reject it.
The implementation question is concrete: which person sees which AI interaction or output, in which channel, under whose responsibility, with what approved control and evidence?
AorBorC's implementation view
AorBorC would begin with one consequential AI workflow, not a company-wide compliance theatre project.
Map the interaction and output path. Separate legal classification from technical implementation. Identify the provider, deployer, channel owner, human reviewer, system of record, exception route, and downstream integrations. Then build and test the approved control where it belongs.
That can include customer-service assistants connected to Zoho, AI-generated catalog work moving into Shopify, document summaries entering Odoo or finance workflows, and custom applications that place a model between a user and a business decision. The platform changes; the discipline does not.
Our AI workflow automation service is built around bounded, human-accountable workflows. The AI in operations guide explains the wider review model, while Zoho QEngine implementation can support repeatable journey and integration checks where automation is useful.
Bring one live AI workflow, the systems it touches, the people who see its output, and your legal interpretation to Plan your project. The useful first result is an implementation map: boundaries, owners, controls, tests, exceptions, and evidence.
Business takeaway
The Omnibus moved defined high-risk-system dates. It did not remove the need to put transparency controls where people actually meet AI.
If your team cannot trace an AI interaction or output to its audience, channel, owner, review path, and approved control, it is not ready to make a defensible August 2 decision.
Sources checked
Checked July 28, 2026.
