EU AI Act August 2: What Developers Must Do Now The EU AI Act's Article 50 transparency obligations and GPAI enforcement powers will activate on August 2, 2026, unaffected by the Digital Omnibus extension that postponed high-risk AI deadlines. Developers must implement four distinct requirements under Article 50, including chatbot disclosure, machine-readable synthetic content marking, deepfake labeling, and AI-generated text disclosure, with no grace period for chatbot obligations. The EU AI Office gains enforcement powers over GPAI models, and deployers remain responsible for their own interfaces. Twelve days. That’s how long developers have before the EU AI Act’s August 2, 2026 deadline activates three major enforcement events at once. Most coverage has focused on what got extended — the Digital Omnibus agreement in May pushed several high-risk AI deadlines to 2027 and 2028. That news traveled fast. What didn’t travel as fast: Article 50 transparency obligations and GPAI enforcement were never in that extension. They go live August 2, on schedule, whether you’re ready or not. Three Things Activate on August 2 The Digital Omnibus https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/ moved the Annex III high-risk AI system requirements — covering biometrics, hiring tools, educational systems, and border control — to December 2, 2027. It did not touch the following: Article 50 transparency obligations. Any AI system interacting with people must disclose its AI nature at first contact. Any system generating synthetic audio, images, video, or text must mark those outputs in a machine-readable format. GPAI enforcement powers. GPAI model obligations have applied since August 2, 2025. The EU AI Office now gets the power to actually enforce them — demanding documents, auditing models, issuing fines, and pulling products from the EU market. Market surveillance authority. National authorities across EU member states gain active enforcement powers over AI systems. If you shipped an AI product and checked out when the Omnibus news dropped, you missed the part where your specific obligations were left untouched. Article 50: What You Actually Need to Implement Article 50 https://artificialintelligenceact.eu/article/50/ has four distinct requirements, not one. Developers treating “AI disclosure” as a single checkbox are going to get caught out. Chatbot and AI interface disclosure. If your system is designed to interact with people — customer service bot, virtual assistant, AI support agent — users must be informed they are interacting with AI. This notification must happen at or before the first interaction, not buried in a terms-of-service footer. The “obvious to a reasonable person” exception is narrow. Your AI-branded chatbot probably still qualifies. Machine-readable synthetic content marking. If your product generates synthetic audio, images, video, or text, outputs must carry a machine-readable mark. The EU Commission’s draft Code of Practice says no single technique meets the robustness requirement — expect a combination of watermarking, C2PA Content Credentials https://c2paviewer.com/articles/eu-ai-act-content-credentials , and fingerprinting or logging. C2PA is the favored standard; Adobe, Microsoft, Google, and OpenAI already support it. Deepfake labeling. AI-generated or manipulated representations of real people — faces, voices, likenesses — must carry a visible label disclosing their synthetic nature. This is separate from the machine-readable marking. AI-generated text disclosure. Systems generating large amounts of text for public information purposes must disclose that origin. One grace period worth knowing: if your generative AI system was already on the EU market before August 2, you have until December 2, 2026 to meet the machine-readable marking requirement. The chatbot disclosure and other obligations have no such grace period. GPAI Enforcement Is No Longer Theoretical If your product is built on a foundation model — GPT-4o, Claude, Gemini, Llama, Mistral — your provider carries the GPAI model obligations. Those have applied since August 2025. What activates on August 2, 2026 is the EU AI Office’s enforcement toolkit https://artificialintelligenceact.eu/implementation-timeline/ . The practical consequence for developers: you are a deployer, and deployers still carry Article 50 obligations for the interfaces they build. Your provider’s GPAI compliance does not cover the chatbot you built on top. You also need to verify that your foundation model provider is compliant — request their EU AI Act documentation now. If they can’t produce it, that is information you need before August 2. GPAI fines cap at 3% of global annual turnover or €15 million , whichever is higher. For a provider with $50 billion in annual revenue, that exposure reaches $1.5 billion. The EU AI Office has already signaled it does not intend to wait years before acting, as GDPR enforcement famously did. The Annex III Trap This is where developers get into trouble. The Omnibus extension of Annex III high-risk obligations is real — an AI-powered hiring tool doesn’t need its full risk management system, technical documentation, and conformity assessment until December 2, 2027. But that same hiring tool still needs to comply with Article 50 on August 2. A deferred compliance track is not a blanket exemption. You can delay the audit logs and the CE marking. You cannot delay the chatbot disclosure. Five Things to Do Before August 2 Audit every AI interface you’ve shipped. Does it tell users they’re interacting with AI at first contact? If not, fix it now. Inventory your generative AI outputs. If your product generates synthetic images, audio, video, or text for EU users, plan your C2PA or watermarking implementation. Request compliance documentation from your foundation model provider. Any provider that can’t produce GPAI compliance docs is a risk. Review your Annex III exposure. If your system touches hiring, education, biometrics, or law enforcement — December 2, 2027 is your hard deadline for full compliance, but Article 50 applies now. Check your deepfake exposure. If your product can generate or manipulate human likenesses, visible labeling is required August 2, no extensions. The EU AI Act’s penalty structure exceeds GDPR: up to €35 million or 7% of global annual turnover for the most serious violations. Twelve days is not a lot of runway. The good news: Article 50 compliance for most products is not a months-long undertaking — it’s a design decision and a few implementation hours. Make them count. Start with the official EU AI Act Service Desk guidance https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50 on Article 50.