Field note · AI & Technology

The AI Act Enforces Disclosure Before It Enforces Safety

The AI Omnibus deferred high-risk obligations to 2027 but left transparency enforcement on its August 2026 date. Disclosure comes before safety.

AP
Anuraag Paul
Co-Founder & Chief Sustainability Officer, Newtral
Published
August 5, 2026
Last reviewed
August 5, 2026
Read time
5 min · 943 words
Current

The EU AI Omnibus deferred the AI Act's hardest obligations - high-risk system conformity assessments, risk management, human oversight - by sixteen months. It left most transparency obligations on their original date. The first thing the regulation enforces, as of 2 August 2026, is not whether an AI system is safe or accurate. It is whether the deployer told the user they were interacting with one. That is a deliberate ordering, and it creates a gap between what deployers must disclose and what they must demonstrate.


On 27 July 2026, Regulation (EU) 2026/1744 - the Digital Omnibus on AI - entered into force across the EU, amending the AI Act (Regulation 2024/1689) for the first time since its adoption in June 2024. Six days later, on 2 August 2026, the AI Act's transparency obligations under Article 50 began enforcement, backed by fines of up to €15 million or 3% of worldwide annual turnover.

What the Omnibus changed is well reported. High-risk AI system obligations for Annex III use cases - credit scoring, insurance pricing, employment, education, biometric identification - were deferred from 2 August 2026 to 2 December 2027. High-risk systems embedded in physical products under Annex I were pushed to 2 August 2028. Simplified obligations were extended from SMEs to small and mid-cap companies. National regulatory sandboxes were given an extra year. The package was framed, and received, as timeline relief.

What the Omnibus did not change is the part worth reading twice.

01

What started on 2 August

Article 50 of the AI Act imposes transparency obligations on providers and deployers of certain AI systems. Three of its four operative provisions began enforcement on 2 August 2026 without deferral.

Providers of AI systems designed to interact directly with natural persons must ensure the system informs the person they are interacting with AI - unless the interaction is obvious from the circumstances and context of use. Deployers of emotion recognition systems or biometric categorisation systems must inform exposed natural persons that the system is operating. Deployers of AI systems that generate or manipulate content constituting a deepfake must disclose that the content has been artificially generated or manipulated.

A fourth obligation - the requirement under Article 50(2) for providers to mark synthetic content outputs in a machine-readable format detectable as artificially generated - received a limited deferral under the Omnibus. Providers of systems already placed on the market before 2 August 2026 have until 2 December 2026 to comply with the marking requirement. Systems placed on the market after 2 August must comply immediately.

The European Commission published its own guidelines on these transparency obligations on 20 July 2026 - one week before the Omnibus entered into force and two weeks before enforcement began.

02

The ordering is the argument

This is the article's central point, and it is a reading of the enforcement sequence rather than anything the Omnibus states about its own design: the EU chose to enforce transparency first and safety later. The first obligation the AI Act imposes on an organisation deploying AI is to tell the user that AI is present - not to demonstrate that the AI system is safe, accurate, robust, or subject to human oversight in a high-risk context.

The deferral did not remove the high-risk obligations. It delayed their first application by sixteen months. An organisation deploying an AI-assisted hiring tool, an insurance pricing model, or a credit-scoring system does not need to implement the AI Act's conformity assessment, risk management system, data governance requirements, or human oversight provisions until December 2027. But if that same system includes a conversational interface, an emotion-recognition component, or a biometric categorisation feature, the transparency obligations for those components are in force now.

The inference is the article's: the practical consequence is a period during which an organisation is legally required to disclose AI use in a context where the comprehensive safety and conformity requirements for that use do not yet apply. Being transparent about deploying an AI system and being compliant with the requirements designed for that system are two separate obligations - and for the next sixteen months, the first applies without the second.

03

What the deferral is not

This reading follows from the enforcement sequence, not from any single sentence in the Omnibus: an organisation that treats the Omnibus's timeline relief as sixteen months of breathing room has misread what the regulation did. It deferred the conformity assessment. It did not defer the obligation to be transparent about what the organisation is deploying.

Two specific misreadings are worth naming as things a well-run AI operation avoids.

Treating deferral as permission to wait. The high-risk obligations are deferred, not cancelled. The Omnibus moved the application date; it did not reduce the scope. An organisation that begins its conformity assessment in November 2027 has left itself one month to implement requirements that were designed to be prepared for over a two-year runway from the AI Act's entry into force in August 2024. The deferral bought time. It did not create it.

Treating transparency compliance as safety compliance. The Article 50 obligations require disclosure - telling the user that AI is present, labelling synthetic content, notifying people exposed to biometric categorisation. They do not require the deployer to demonstrate that the AI system is accurate, non-discriminatory, robust, or subject to meaningful human oversight. An organisation that complies with Article 50 and stops there has met the transparency standard. It has not met the safety standard that the same regulation applies to the same system in December 2027 - and the user it just told about the AI system has no reason to distinguish the two.

Noa · ESG compliance

Map your disclosures against AI & Technology.

Noa reads your disclosures, traces every number to its source, and flags what's missing.

Book a demo
AP
About the author
Anuraag Paul
Co-Founder & Chief Sustainability Officer, Newtral
View LinkedIn profile →