The August 2 Deadline Is Real: What SMBs Must Do Before the EU AI Act Kicks In
The EU AI Act transparency deadline is August 2, 2026. Learn what Article 50 requires, what the Omnibus delayed, and how SMBs can comply before fines kick in.
The headlines said everything was delayed. The Digital Omnibus pushed high-risk obligations into 2027 and beyond, and plenty of businesses breathed a sigh of relief. But if you stopped reading there, you missed the part that matters most: Article 50 transparency rules still go live on August 2, 2026. For most small and medium businesses (SMBs), that is the only deadline that actually applies right now. National regulators can levy fines from day one. There is no grace period.
If you use a chatbot on your website, generate images or video with AI, or serve customers in the EU from outside Europe, the clock is real and it is running out.
What the Digital Omnibus Delayed — and What It Didn’t#
The Digital Omnibus on AI entered into force on July 27, 2026. It deferred two major categories of high-risk obligations:
| AI System Type | Original Deadline | New Deadline |
|---|---|---|
| Stand-alone high-risk AI (Annex III) | August 2, 2026 | December 2, 2027 |
| Product-embedded high-risk AI (Annex I) | August 2, 2027 | August 2, 2028 |
These deferrals give genuine breathing room to companies building hiring tools, credit scoring systems, educational AI, and medical devices. But the relief stops there. General-purpose AI (GPAI) enforcement powers, Article 50 transparency obligations, AI literacy requirements, and prohibited practices all remain on their original timelines. The most dangerous thing an SMB can do right now is assume “everything was postponed.” It was not.
Practical takeaway: Check your internal project tracker. If you parked compliance work because of the Omnibus headlines, reopen it immediately. The high-risk clock moved; the transparency clock did not.
Article 50: The Transparency Rules That Actually Apply to SMBs#
For the typical SMB, Article 50 is the August 2 obligation that matters. It is not about being a “high-risk” operator. It applies to ordinary, customer-facing AI use. The four disclosure duties are:
-
Chatbot Disclosure (Article 50.1): Any AI system that interacts directly with people must disclose that it is AI no later than the first interaction. A line buried in terms of service does not satisfy this. The disclosure must be clear, distinguishable, and accessible. If a visitor lands on your site and your support chatbot greets them, it must say it is AI before or during that first message.
-
Machine-Readable Marking (Article 50.2): AI-generated or AI-edited audio, image, video, and text must carry machine-readable metadata. The European Commission’s Code of Practice on Transparency of AI-Generated Content, published June 10, 2026, specifies C2PA Content Credentials or IPTC provenance metadata as acceptable formats. Systems already on the market before August 2, 2026 get a grace period until December 2, 2026. New systems must comply from day one.
-
Emotion Recognition Notice (Article 50.3): People exposed to emotion-recognition or biometric-categorisation systems must be informed the system is in operation.
-
Deepfake and Public-Interest Labels (Article 50.4): Deepfakes must be visibly disclosed as artificially generated. AI-generated text published on matters of public interest must also be disclosed.
Practical takeaway: Walk through every customer-facing AI touchpoint your business operates. For each one, ask: “Would a regulator looking at this on August 2 see the required disclosure?” If the answer is no, fix it before the deadline.
GPAI Enforcement: What It Means If You Use ChatGPT, Claude, or Gemini#
The heavy GPAI obligations — model documentation, copyright policies, systemic-risk testing — fall on the providers of models: OpenAI, Anthropic, Google, and similar companies. If you are an SMB using these models through an API or subscription, you are a deployer, not a provider. Your obligations are narrower.
Deployer obligations center on three things: Article 50 transparency (covered above), AI literacy (in force since February 2025), and documenting your own use cases. The one GPAI-specific task worth doing before August 2 is vendor due diligence. Confirm your model provider is meeting its obligations and keep that confirmation on file. If a regulator asks, “What did you do to ensure your AI vendor was compliant?” you want a dated email or contract clause to show them.
Practical takeaway: Open your inbox or contract folder right now. If you do not have written confirmation that your AI vendor is compliant with GPAI obligations under the AI Act, request it today. File the response with your compliance records.
Penalties Are Real: What Fines Look Like Starting August 2#
The AI Act’s penalty structure has three tiers, and all of them become enforceable on August 2, 2026:
| Violation Category | Maximum Fine |
|---|---|
| Information and transparency obligations | Up to $7.5M or 1% of global annual turnover |
| Provider or deployer obligations | Up to $15M or 3% of global annual turnover |
| Prohibited AI practices | Up to $35M or 7% of global annual turnover |
Article 50 violations fall into the first tier. That may sound modest compared to the $35M cap, but for an SMB with tight margins, a $7.5M fine is an extinction-level event. More importantly, Article 50 is enforceable from day one with no separate enforcement grace period. High-risk systems at least had a preparation runway. Transparency obligations do not.
SMBs are not fully exempt, either. Small and medium enterprises receive lighter supporting measures and a lower fine cap, but that cap is the lower of the fixed amount or percentage. It is not a pass on compliance.
Practical takeaway: Treat August 2 as a hard enforcement date, not a soft launch. Assign someone to own compliance documentation now, not after the first regulator inquiry.
The Hidden Traps SMBs Keep Walking Into#
Even well-intentioned companies stumble over predictable misconceptions. Here are the ones to eliminate before August 2:
-
Assuming the vendor handles everything. If you run a third-party chat widget, the vendor is the provider. But how that widget is configured and presented on your site is your deployment responsibility. “The vendor handles it” is worth confirming, not assuming.
-
Machine-readable metadata gets stripped. Image pipelines and content delivery networks (CDNs) routinely strip C2PA and IPTC metadata during optimization. Content that left the generator properly marked can arrive on your website unmarked. Test your pipeline end-to-end.
-
“We are too small to matter.” There is no general small-business exemption from Article 50. SMEs get lighter supporting measures and a lower fine cap, not a free pass.
-
Extraterritorial reach for non-EU companies. The AI Act covers providers and deployers outside the EU whenever the AI system is placed on the Union market, put into service in the Union, or its output is used in the Union. A US company selling chatbots to EU customers, a UK SaaS provider with EU users, or a global model provider placing models on the EU market is in scope. Non-EU providers of GPAI models must appoint an authorised representative in the Union.
Practical takeaway: Schedule a 30-minute internal audit this week. Walk through each assumption above and produce one piece of documentation that disproves or confirms it for your business.
A Five-Day Compliance Sprint for August 2#
If you are reading this with the deadline days away, here is a focused checklist:
- Day 1: Audit all customer-facing AI touchpoints. List every chatbot, image generator, video tool, and automated system that interacts with users or produces content they see.
- Day 2: Verify chatbot disclosures are visible on the first interaction. Test from an incognito browser. If the disclosure appears only in terms of service, rewrite it.
- Day 3: Test image and video pipelines for C2PA or IPTC retention. Upload a marked file, run it through your production pipeline, and verify the metadata survives.
- Day 4: Document vendor compliance confirmations. Collect emails, contract clauses, or security whitepapers that demonstrate your AI vendors are meeting their obligations.
- Day 5: Brief staff on AI literacy requirements. Article 4 has been in force since February 2025. Document who received training and when.
Practical takeaway: Even if you cannot complete every step perfectly before August 2, documented good-faith effort matters if a regulator comes knocking. Partial compliance with a clear remediation plan beats silent non-compliance.
What Happens After August 2: The December 2026 Prohibition#
The Omnibus expanded Article 5’s prohibited practices. From December 2, 2026, the Act bans AI systems that generate child sexual abuse material and “nudifier” applications — AI that creates or manipulates sexually explicit images, video, or audio without consent.
For most SMBs this is not a daily compliance burden. But if you build or deploy any image- or video-generation feature, confirm now that it cannot be misused this way. Addressing this in your terms of service and content moderation policy is a sensible forward step.
Practical takeaway: Add a calendar reminder for November 2026 to review any generative media features your business offers. A 15-minute policy check then can prevent a much larger problem later.
The Bottom Line#
The high-risk clock now runs to December 2027, but the transparency clock runs to August 2, 2026. Most SMBs have been watching the wrong clock. The companies that come out of August 2 in the strongest position will not be the ones that read “delay” and stopped. They will be the ones that closed transparency gaps, ran vendor due diligence, and documented their AI use cases in these final days.
Compliance is not a project you finish. It is a practice you maintain. Start with August 2, build the habit, and you will be ready for every deadline that follows.
“Ready to implement this?” Get the templates, checklists, and step-by-step guides at Rozelle.ai ↗ — everything you need to move from reading to doing.
Sources#
- EU AI Act: 7 Weeks to August 2 — What the Omnibus Delayed and What Still Applies ↗
- Digital Omnibus on AI Explained. Final Text and New Dates ↗
- EU AI Act Digital Omnibus Explained ↗
- The Digital Omnibus on AI Enters into Force Today ↗
- The AI Act and the Digital Omnibus: The New High-Risk Timeline ↗
- What if You Do Not Comply with Article 50 ↗
- EU AI Act Article 50, Explained ↗
- How the EU AI Act Reaches Companies Outside the EU ↗