AI Act: the delay does not excuse you from Article 50

The delay to the AI Act's high-risk obligations travelled widely and created a largely unfounded sense of relief. Article 50 — the transparency obligations — does apply on 2 August 2026, and the Commission has just published its guidelines on it. For a Mauritian business working with Europe, the deadline falls in under two weeks.
Where the text actually stands
The "digital omnibus" regulation, which lightens and reschedules the AI Act, has run its full course: Parliament approval on 16 June 2026, final Council green light on 29 June, signature of the act on 8 July. It had not, however, been published in the Official Journal of the Union at the time of writing, and entry into force occurs on the third day following that publication.
The legal consequence is counter-intuitive and worth stating plainly: until publication happens, the original calendar remains the applicable law. The deferred dates are a planning horizon, not yet positive law. A business that reprioritised on the strength of press coverage alone has been reasoning from a text that was not yet in force.
That said, once published, the omnibus does defer the substance: stand-alone high-risk systems under Annex III move from 2 August 2026 to 2 December 2027, and AI embedded in regulated products (Annex I) from 2 August 2027 to 2 August 2028. These are real extensions on real constraints. They simply do not touch transparency.
What Article 50 requires, and from when
On 20 July 2026 the Commission adopted its guidelines on transparency obligations, stating unambiguously that these obligations apply from 2 August 2026. Four requirements structure the regime.
A system designed to interact directly with people must inform them that they are dealing with an AI, unless it is obvious to a reasonably well-informed person — the customer service chatbot case. Synthetic content — audio, image, video, text — must be marked in a machine-readable format and detectable as artificially generated or manipulated. Emotion recognition and biometric categorisation systems require informing the people exposed to them. And deepfake content must be disclosed as artificially generated or manipulated, with carve-outs for evidently artistic or satirical work.
The information must be given clearly and distinguishably, "at the latest at the time of the first interaction or exposure". A line buried in terms and conditions does not meet that standard.
The omnibus introduced one nuance, and it is narrow: the machine-readable marking obligation gets an extension to 2 December 2026, only for systems already on the market before 2 August 2026. Anything placed on the market from that date onward gets no grace period at all.
Why a Mauritian business can be caught
This is the most misunderstood point, and it does not depend on where you are established. Article 2 of the regulation opens three doors onto a Mauritius-based company.
The first: placing an AI system on the Union market, whether for payment or free of charge — the provider's place of establishment is explicitly irrelevant. The second, and by far the widest: being a provider or deployer established in a third country "where the output produced by the AI system is used in the Union". The system stays in Mauritius, is never marketed in Europe, but if its output is used in the Union, the regulation applies. The third: a European subsidiary using the system under its own authority becomes a deployer in its own right.
The second door points squarely at Mauritian business models built on service exports. A service centre that triages files, drafts customer replies or produces visuals for a European client is producing output used in the Union. Recital 22 of the regulation says so directly: the aim is to prevent circumvention through outsourcing to a third country. This extends what we set out on the AI Act and Mauritian businesses, and follows the same logic as NIS2's cascading requirements.
What transparency actually demands of your systems
Claiming Article 50 compliance is easy; demonstrating it is not. Marking content assumes you know which content was generated, by which system, on what date. Informing a user assumes the message survives interface updates. Answering a regulator assumes you kept the record.
This is where technical architecture meets compliance. An opaque public AI service leaves you without evidence: you depend entirely on what the vendor chooses to document. A private model hosted on your infrastructure produces logs you control and retain. Compliance stops being declarative and becomes verifiable — which is exactly the difference that matters on the day of an inspection.
Checklist before 2 August
- Inventory the AI uses actually in production, including those no manager ever approved.
- For each, ask the output question: is it used in the European Union, directly or through a client?
- Identify direct interactions with people: chatbots, assistants, automated phone systems.
- List generated content: text, images, voice, video — and where it is published.
- Add user disclosure at the first interaction, in plain sight and not in the terms.
- Check machine-readable marking with your generative AI vendors, and the date they comply.
- Separate legacy from new: systems in service before 2 August get until 2 December 2026 on that point alone.
- Keep the record of what was generated, by which system and when.
- Name an owner for the file and have your real exposure assessed if the perimeter is unclear.
How SOVALYX can help
SOVALYX helps you answer the only question that matters here: does your AI produce output used in the Union, and can you prove it? We inventory the AI uses actually running in production, identify those that trigger Article 50, and put in place user disclosure, content marking and the traceability behind them. Where the demonstration has to be solid, a private model hosted on your own infrastructure makes that traceability verifiable rather than declarative.
Talk private AI with an engineer🧰 The companion tool: Are you ready for the AI Act? — free · 2 minutes.
Reviewed and optimised by AI.