Two things are true at once about the EU AI Act this autumn. Since August 2, 2026, providers and deployers of AI systems that interact directly with people must meet the transparency obligations in Article 50, with fines of up to €15 million or 3% of worldwide turnover for non-compliance, as Cooley summarises. And the heavier obligations for high-risk systems have been pushed back.

What moved

  • Annex III high-risk systems (biometrics, critical infrastructure, employment, credit, public services): from August 2026 to December 2, 2027.
  • Annex I high-risk systems embedded in regulated products such as medical devices: to August 2, 2028.
  • Transparency labelling for AI-generated content: to December 2, 2026, a three-month postponement.
  • The SME relaxations (simplified documentation, proportionate penalties, lighter quality-management requirements) now extend to small mid-caps.

Travers Smith notes the provisional agreement still requires formal approval by the Council and Parliament, and that the fate of the general AI-literacy duty in Article 4 is not yet clear from the official statements.

What to do this quarter

DiscussHow do you disclose AI in a chat that hands off to a human? Compare notes in the discussion.

Do not treat the delay as a pause. The disclosure duty for customer-facing bots and agents is already in force, and one April 2026 estimate cited by Holland & Knight had 78% of organisations yet to take meaningful compliance steps. Inventory every system that talks to a person, confirm the disclosure is explicit, and use the extra time on the high-risk side to build the documentation you will need anyway.