Sebastien Rousseau

EU AI ACT

Your High-Risk Deadline Moved to December 2027. Your Chatbot's Did Not.

A compliance reading for heads of AI governance, digital channels and model risk: what the Omnibus deferred, what it left untouched, and why the obligation landing today sits in the customer app rather than the credit engine.

10 min read
Banner for: Your High-Risk Deadline Moved to December 2027. Your Chatbot's Did Not.

Nine days ago the AI Omnibus entered into force and gave banks sixteen months back. The high-risk obligations for Annex III systems — the ones covering creditworthiness assessment and insurance pricing, the provisions every bank's AI programme was built around — moved from today to 2 December 2027. Systems embedded in regulated products under Annex I moved to 2 August 2028. That is real relief on the most expensive part of the file. It is also the most dangerous kind of good news, because a deferral announced in one paragraph gets read as a deferral of everything. Article 50 did not move. Its transparency obligations apply from today, and they do not land on the credit engine. They land on the chatbot in the mobile app, the AI-drafted letter, and the synthetic voice in the contact centre.

Executive Summary

  • The relief is real and narrow. Sixteen months on Annex III is a material change to programme economics. It applies to the high-risk classification work, not to transparency.
  • Today is a live compliance date. Article 50 applies from 2 August 2026. There is no grace period in the text for systems placed on the market after the Omnibus agreement.
  • The transitional relief is narrower than it sounds. Generative systems already on the market before the Omnibus agreement have until 2 December 2026 for the machine-readable marking duty. New deployments do not inherit it.
  • This is a channel problem wearing a model-risk badge. Almost every affected surface is owned by digital, marketing or the contact centre — functions with no seat on the AI Act steering committee.

What Moved and What Did Not #

Precision matters here more than usual, because the headline and the operative text diverge.

The AI Act itself is Regulation (EU) 2024/1689. The simplification package known as the AI Omnibus was proposed in November 2025, reached political agreement in May 2026, and entered into force on 27 July 2026 — nine days before the date this article carries.

What it deferred:

  • Annex III high-risk obligations move to 2 December 2027. This is the bucket containing creditworthiness evaluation and credit scoring of natural persons, and risk assessment and pricing in life and health insurance. For most banks, this was the whole programme.
  • Annex I high-risk — systems embedded as safety components in products already covered by EU product legislation — moves to 2 August 2028.

What it did not defer:

  • Article 50 transparency obligations apply from 2 August 2026.

The gap between those two facts is the entire subject of this piece. A bank that has spent eighteen months building conformity assessment, technical documentation and registration capability for a credit-scoring model has just been handed sixteen months of slack on that work. The same bank very likely has a customer-facing assistant in its mobile app that acquired a legal obligation today, owned by a different director, funded from a different budget, and absent from the AI Act programme plan entirely.

The failure mode is not defiance. It is an org chart.

The Four Duties That Bite Today #

Article 50 is short, and it is worth being concrete about what it actually requires rather than paraphrasing it into vagueness.

Direct interaction. Providers must ensure that people are informed they are interacting with an AI system rather than a human, unless that is obvious to a reasonably well-informed person in the circumstances. For a bank, this is the app assistant, the web chat widget, and the voice bot that answers the phone before a human does.

AI-generated content. Providers of systems generating synthetic audio, image, video or text must mark outputs in a machine-readable format and make them detectable as artificially generated or manipulated. The techniques contemplated are watermarks, metadata, cryptographic provenance indicators and fingerprints.

Emotion recognition and biometric categorisation. Deployers must inform the people exposed to the system. Contact-centre sentiment analytics is the obvious candidate, and it is frequently procured as a quality-assurance tool rather than as an AI system.

Deepfakes and public-interest text. Deployers generating or manipulating image, audio or video constituting a deepfake must disclose it. Text published to inform the public on matters of public interest carries a disclosure duty too — which reaches further into corporate communications and research publication than most banks have modelled.

Table 1: Where each duty actually lands #

Duty Typical bank surface Who owns it today On the AI Act plan?
Disclose AI interaction App assistant, web chat, voice bot Digital channels Rarely
Machine-readable marking Marketing content, AI-drafted correspondence Marketing, operations Almost never
Emotion recognition notice Contact-centre sentiment analytics Customer operations No
Deepfake and public-interest text Corporate communications, research Communications No
High-risk conformity (deferred) Credit scoring, insurance pricing Model risk Yes — and it just moved

The pattern in the right-hand column is the finding. The one obligation that is live today is the one nobody is staffed for.

Machine-Readable Is Doing the Work #

Of the four duties, the marking requirement is the one that is an engineering programme rather than a copy change.

A visible caption reading "generated with AI" is a reasonable thing to do and does not satisfy a duty framed around machine readability. The point of the requirement is that a downstream system — a platform, a browser, a verification tool — can determine provenance without a human reading the page. Watermarking, embedded metadata, cryptographic provenance and fingerprinting are all named techniques, and they behave differently under the conditions content actually meets: re-encoding, cropping, screenshotting, format conversion, and passage through third-party platforms that strip metadata as a matter of course.

That means three questions a bank has to answer, none of which is a legal question.

Which content pipelines produce synthetic output at all — including the ones that emerged without governance, such as AI-drafted customer correspondence and marketing image generation. Which marking technique survives the distribution path each pipeline uses. And whether the tooling in the stack supports it, because a marking obligation is only as good as the weakest system in the chain that touches the asset after it is created.

There is a transitional provision worth reading carefully rather than optimistically. Generative systems already on the market before the Omnibus agreement in May 2026 have until 2 December 2026 to meet the machine-readable marking duty under Article 50(2). That is genuine breathing room for an incumbent deployment. It is not a general grace period, and it does not extend to something a bank stands up next month.

Provider or Deployer, and Why It Is Not the Vendor's Problem #

The obligations split by role, and the split is where procurement assumptions tend to fail.

Broadly, marking synthetic output at the point of generation falls on the provider — the party that develops the system and puts it on the market. Disclosure to affected people generally falls on the deployer — the bank using the system under its own authority. A bank that licenses a conversational assistant is a deployer. It may also become a provider if it puts its own name on the system or modifies it substantially, which is precisely what happens when an institution wraps a foundation model in its own branded assistant.

Two consequences follow.

A vendor attestation does not discharge a deployer duty. "Our platform is AI Act compliant" is a statement about the vendor's obligations, not about the bank's disclosure to its own customers in its own interface.

And white-labelling can move a bank across the line. The more thoroughly an institution makes a third-party system its own — its name, its tone, its fine-tuning — the more likely it is holding provider obligations it never contracted for.

Table 2: What to establish before the next release ships #

Question Why it decides your exposure
Which customer-facing surfaces involve an AI system at all? You cannot disclose on a surface nobody has inventoried
For each, are we provider, deployer, or both? Determines which duty attaches to you rather than the vendor
Does any pipeline emit synthetic content externally? Triggers the machine-readable marking duty
Does the marking survive our distribution path? A stripped watermark is not a marking
Was the system on the market before May 2026? Determines whether the 2 December 2026 transitional applies
Who signs off that a release meets Article 50? Absent a named owner, nobody does

The Number That Sets the Priority #

Non-compliance with Article 50 sits in the tier carrying administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher.

That figure deserves to be read next to the effort involved. Disclosing that a chatbot is a chatbot is a small piece of work. Marking synthetic content in a machine-readable way is a real but bounded engineering programme. Neither is comparable in cost to the conformity assessment regime that just moved to December 2027. The asymmetry between the exposure and the remediation cost is the argument for doing this now, and it is an unusually easy argument to take to a board.

The Operating Playbook #

Five moves, and the first one is not a legal review.

  1. Inventory the surfaces, not the models. Ask every customer-facing function what AI touches a customer. The AI Act register built by model risk will not contain the marketing image generator or the drafting assistant in the contact centre.
  2. Classify provider versus deployer per system. Do it per system rather than per vendor, because the same supplier can leave you in different roles depending on how far you have branded and tuned what they sold you.
  3. Test whether your marking survives. Take a marked asset through the actual distribution path — CMS, email platform, social channel — and check that the provenance signal is still there at the end. Most metadata does not survive that trip.
  4. Name a release gate owner. Article 50 compliance is a per-release property of a channel, not a one-off certification. Without a named approver it will regress the first time a team ships under deadline.
  5. Keep the deferred programme warm. Sixteen months is not a cancellation. Teams disbanded in August 2026 get rebuilt at higher cost in 2027, and the classification work that determines whether a system is Annex III at all has not become any easier.

Regulatory relief is rarely uniform, and it is almost never uniform in the way a headline implies. The institutions that will be embarrassed this year are not the ones that misread the law. They are the ones that heard "delayed", stood the programme down, and never checked which of their obligations was covered by the word.

Frequently Asked Questions #

Did the AI Act get delayed or not?
Partly. The AI Omnibus, in force since 27 July 2026, deferred the Annex III high-risk obligations to 2 December 2027 and the Annex I ones to 2 August 2028. It did not defer Article 50, whose transparency obligations apply from 2 August 2026.

We only use a third-party chatbot. Are we in scope?
Almost certainly, as a deployer. Deployer duties — including telling people they are interacting with an AI system — attach to the bank operating the system under its own authority, and are not discharged by a vendor's compliance statement. If you have branded the assistant as your own or substantially modified it, you may also carry provider duties.

Is a visible "AI-generated" label enough?
Not for the marking duty. Article 50(2) is framed around machine-readable marking so that downstream systems can detect synthetic provenance without human reading — watermarks, metadata, cryptographic provenance indicators, fingerprints. A visible caption is good practice on top of it, not a substitute.

What is the transitional relief for content marking?
Generative systems already on the market before the Omnibus agreement in May 2026 have until 2 December 2026 to meet the machine-readable marking requirement. It is specific to that cohort; a system deployed after it does not inherit the extra time.

Should we stand down the high-risk programme now that it moved?
No. Sixteen months of relief is an opportunity to do the classification work properly rather than a reason to stop. Determining whether a given system falls in Annex III at all is the part institutions consistently underestimate, and it has not been deferred in difficulty — only in deadline.

What does this cost if we get it wrong?
Breaches of Article 50 fall in the tier attracting administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher. Set against the remediation effort — disclosure copy and a content-marking pipeline — the ratio is the reason to move this quarter.

References #

  • European Parliament and Council of the European Union, 2024. Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act). Brussels: Official Journal of the European Union. Available at: European Parliament and Council of the European Union, 2024..
  • European Commission, 2026. Regulatory framework for artificial intelligence. Brussels: Directorate-General for Communications Networks, Content and Technology. Available at: European Commission, 2026..
  • European Commission, 2026. Guidelines on transparency obligations for providers and deployers of certain AI systems. Brussels: European Commission. Available at: European Commission, 2026..
  • European Commission, 2026. Code of Practice on Transparency of AI-generated Content. Brussels: European Commission. Available at: European Commission, 2026..
  • EU Artificial Intelligence Act, 2026. Article 50: Transparency obligations for providers and deployers of certain AI systems. Available at: EU Artificial Intelligence Act, 2026..

Last reviewed .

Syndicate this article

Format for Medium

# Your High-Risk Deadline Moved to December 2027. Your Chatbot's Did Not.

> Originally published at [https://sebastienrousseau.com/2026-08-02-ai-act-article-50-transparency-banks-omnibus-2026/](https://sebastienrousseau.com/2026-08-02-ai-act-article-50-transparency-banks-omnibus-2026/)

The AI Omnibus moved the high-risk deadline to December 2027. It did not move Article 50. Transparency obligations apply from today, and they land on the chatbot.

Read the full article on sebastienrousseau.com: https://sebastienrousseau.com/2026-08-02-ai-act-article-50-transparency-banks-omnibus-2026/

Format for Mastodon

Your High-Risk Deadline Moved to December 2027. Your Chatbot's Did Not.

The AI Omnibus moved the high-risk deadline to December 2027. It did not move Article 50. Transparency obligations apply from today, and they land on the chatbot.

https://sebastienrousseau.com/2026-08-02-ai-act-article-50-transparency-banks-omnibus-2026/

Copy formatted for LinkedIn

Your High-Risk Deadline Moved to December 2027. Your Chatbot's Did Not.

The AI Omnibus moved the high-risk deadline to December 2027. It did not move Article 50.

Here are the key strategic takeaways:

- Two deadlines moved and one did not. Reading "the AI Act was delayed" as a single fact is the error that will cost the most this quarter.
- Machine-readable is the hard word. A visible "generated with AI" caption does not satisfy a marking duty framed around watermarks, metadata, provenance signals and fingerprints. That is an engineering change to the content pipeline.
- The duty splits between provider and deployer. A bank buying a vendor assistant is a deployer, and deployer duties are not discharged by the vendor's compliance statement.
- The owners are in the wrong department. Article 50 obligations attach to customer-facing channels. The people staffed on the AI Act are usually sitting in model risk, working on the file that just moved.

What is your organisation's approach to the challenges outlined in this piece?

→ https://sebastienrousseau.com/2026-08-02-ai-act-article-50-transparency-banks-omnibus-2026/

#EuAiAct #Article50 #TransparencyObligations #AiOmnibus #Regulation(eu)20241689

Sebastien Rousseau | CC-BY-4.0
Cite this article

Your High-Risk Deadline Moved to December 2027. Your Chatbot's Did Not.

The AI Omnibus moved the high-risk deadline to December 2027. It did not move Article 50. Transparency obligations apply from today, and they land on the chatbot.

BibTeX

@online{rousseau2026your,
  author  = {Rousseau, Sebastien},
  title   = {{Your High-Risk Deadline Moved to December 2027. Your Chatbot's Did Not.}},
  year    = {2026},
  url     = {https://sebastienrousseau.com/2026-08-02-ai-act-article-50-transparency-banks-omnibus-2026/},
  urldate = {2026}
}

RIS

TY  - GEN
AU  - Rousseau, Sebastien
TI  - Your High-Risk Deadline Moved to December 2027. Your Chatbot's Did Not.
PY  - 2026
UR  - https://sebastienrousseau.com/2026-08-02-ai-act-article-50-transparency-banks-omnibus-2026/
ER  -

Vancouver

Rousseau S. Your High-Risk Deadline Moved to December 2027. Your Chatbot's Did Not.. sebastienrousseau.com. 2026 Aug 2. Available from: https://sebastienrousseau.com/2026-08-02-ai-act-article-50-transparency-banks-omnibus-2026/

Chicago

Rousseau, Sebastien. "Your High-Risk Deadline Moved to December 2027. Your Chatbot's Did Not.." sebastienrousseau.com. August 2, 2026. https://sebastienrousseau.com/2026-08-02-ai-act-article-50-transparency-banks-omnibus-2026/.

APA

Rousseau, S. (2026, August 2). Your High-Risk Deadline Moved to December 2027. Your Chatbot's Did Not.. sebastienrousseau.com. https://sebastienrousseau.com/2026-08-02-ai-act-article-50-transparency-banks-omnibus-2026/

Republish this article

Your High-Risk Deadline Moved to December 2027. Your Chatbot's Did Not.

The AI Omnibus moved the high-risk deadline to December 2027. It did not move Article 50. Transparency obligations apply from today, and they land on the chatbot.

This article is licensed under Creative Commons Attribution 4.0 International. Republication requires attribution to the canonical URL.

Your High-Risk Deadline Moved to December 2027. Your Chatbot's Did Not.

The AI Omnibus moved the high-risk deadline to December 2027. It did not move Article 50. Transparency obligations apply from today, and they land on the chatbot.

Originally published at https://sebastienrousseau.com/2026-08-02-ai-act-article-50-transparency-banks-omnibus-2026/ by Sebastien Rousseau.
Licensed under CC-BY-4.0.