On 24 July 2026 the Digital Omnibus on AI was published in the Official Journal of the European Union as Regulation (EU) 2026/1744, entering into force on 27 July. The EU AI Act's obligations for high-risk AI systems no longer apply from 2 August 2026. Standalone Annex III systems now have until 2 December 2027, and high-risk AI embedded in Annex I regulated products until 2 August 2028.
That is a sixteen-month reprieve on the most demanding part of the Act. It is also the year's most misread development, for two reasons. Most of what was due on 2 August did not move. And the part that did not move, Article 50, is described almost everywhere as though it lands on anyone who touches AI. It does not. It allocates specific duties to specific roles.
The corrected timeline
- 2 August 2026. The Article 50 transparency obligations apply, and enforcement powers become operational alongside them.
- 2 December 2026. The Article 50(2) machine-readable marking duty catches up with generative systems already placed on the market before 2 August. The new prohibition on AI used to generate child sexual abuse material or non-consensual intimate imagery takes effect.
- 2 August 2027. Member States must have a national AI regulatory sandbox running.
- 2 December 2027. High-risk obligations apply to standalone Annex III systems: employment, education, credit scoring, critical infrastructure, law enforcement.
- 2 August 2028. High-risk obligations apply to AI embedded in Annex I products such as medical devices and toys.
The Omnibus also broadened the AI Office's supervisory powers, opened bias-detection processing of special-category data to all providers and deployers under a strict necessity test, carved machinery out of the high-risk regime, and kept the database registration requirement for systems self-assessed as not high-risk. The risk tiers, the conformity regime, the general-purpose AI obligations in force since August 2025 and the penalty framework are all unchanged.
Who Article 50 actually binds
Article 50 is the transparency chapter. It bites whether or not anything you run is high-risk, which is why it is the provision most likely to reach an ordinary South African software business. What it does not do is give everyone in the value chain the same obligation. It splits by role, between the provider of a system (you developed it, or had it developed, and place it on the market or put it into service under your own name or trademark) and the deployer (you use somebody else's under your own authority, professionally).
- 50(1), providers. Systems intended to interact directly with people must be designed so those people are informed they are dealing with an AI, unless that is obvious to a reasonably well-informed, observant and circumspect person in context. A design duty on the provider, not a signage duty on everyone running a bot.
- 50(2), providers, including of general-purpose AI systems. Systems generating synthetic audio, image, video or text must mark their output in a machine-readable format, detectable as artificially generated, as far as is technically feasible.
- 50(3), deployers. Running emotion recognition or biometric categorisation means informing the people exposed to it.
- 50(4), deployers, in two limbs. Deepfake image, audio or video content must be disclosed. Separately, AI-generated text published to inform the public on matters of public interest must be disclosed.
Disclosure under all four must be clear, distinguishable, no later than first interaction or exposure, and accessible. None of it displaces the high-risk obligations or other transparency law.
The exceptions carry as much weight as the duties. Article 50(2) does not apply where the system only assists standard editing, or does not substantially alter the input or its meaning; the Commission's guidance gives spelling and grammar correction as the example. The deepfake limb relaxes for evidently artistic, satirical or fictional work, narrowing to disclosing that generated content exists without spoiling the work. The public-interest text limb falls away where content has had human review or editorial control and someone holds editorial responsibility for it. All four carry law-enforcement carve-outs.
So, against the version of this you have probably read: using a third-party tool to draft marketing copy or generate a product image does not, on its own, create an Article 50 duty for you. Ordinary marketing copy is not public-interest text. A stock-style generated image is not a deepfake. The marking duty for that tool's output sits with the tool's provider. Other law, advertising rules included, may still apply.
The question that decides your exposure
Provider or deployer is decided per system, and for most software businesses the answer is both, for different systems. Two cases that look alike:
Build an assistant on a model API, wrap it in your product and ship it under your own brand, and on the ordinary reading you are the provider. The 50(1) design duty is yours.
Subscribe to a helpdesk product and switch on its AI agent, and you are the deployer. The 50(1) and 50(2) duties sit with the vendor. Get that in writing, because European customers will ask.
White-labelling, fine-tuning and material reconfiguration sit between the two, and that is where businesses get caught. Article 25 sets out when a deployer is treated as a provider, though its triggers are framed around high-risk systems; the more general route is the provider definition itself, which turns on whose name the system goes out under. This is the first of two places we would send you to a lawyer. Twenty minutes per system, on paper, is cheap next to discovering in a procurement review that you were the provider all along.
What the Commission published on 20 July
Four days ago, and it narrows the work rather than adding to it. The Commission adopted the final version of its Article 50 guidelines: fifty-one pages clarifying scope, definitions and exceptions, including confirmation that chatbots count as directly interactive systems. They are non-binding, and only the Court of Justice can interpret the Regulation authoritatively, but market surveillance authorities and the AI Office can be expected to follow them. Read them before you scope anything.
They also settle retroactivity, generously. There is no retroactive labelling duty under Article 50(4). For deepfakes the relevant date is the date of generation, so nothing made before 2 August needs labelling after the fact. For public-interest text it is the date of publication, so text generated earlier but published on or after 2 August does need disclosure unless an exception applies.
The accompanying Code of Practice on Transparency of AI-Generated Content, assessed as adequate by the Commission and the AI Board, offers a voluntary route to demonstrate compliance. It is not a presumption of lawfulness; the assessment still rests with the authorities.
What a breach actually costs
The figure quoted at you, up to €35 million or 7% of worldwide annual turnover, is the tier for the Article 5 prohibited practices. It is not the transparency tier. Article 50 breaches sit at up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.
Then the provision almost nobody quotes: for SMEs, including start-ups, each fine is capped at whichever of the amount or the percentage is lower, the exact inverse of the rule for everyone else. On three million euro of turnover, the transparency ceiling is nearer ninety thousand euro than fifteen million. Real money, worth avoiding, and not the existential threat the headline implies. Anyone selling you compliance work on the strength of the 7% number is quoting the wrong tier at the wrong company.
Nothing about POPIA changed
Nothing in the Omnibus touches South African law, and the two get conflated constantly.
Section 71 still provides that a person may not be subject to a decision which has legal consequences for them, or affects them to a substantial degree, where that decision is based solely on automated processing of personal information intended to provide a profile of them. Both qualifiers do work: a genuine human decision-maker takes you outside the prohibition, and so does automated processing that is not building a profile.
The exceptions run principally to decisions taken in connection with concluding or performing a contract, or governed by a law or code of conduct with appropriate safeguards. Where you rely on the route resting on appropriate measures to protect the person's legitimate interests, those measures must give them an opportunity to make representations about the decision, and must require you to provide sufficient information about the underlying logic of the processing so they can do so meaningfully. That is the source of the loosely quoted "right to an explanation". It is real, and narrower and more conditional than the shorthand suggests. This is the second place we would send you to a lawyer, because whether a decision of yours is "solely" automated and "intended to provide a profile" is precisely the question that decides the answer.
The uncomfortable symmetry: employment and credit scoring, the use cases the EU has just given itself sixteen more months on, are the ones Section 71 already reaches here, today, with no transition period.
Why this binds a South African business
The Act applies extra-territorially, as GDPR does, where the output of an AI system is used in the EU. No EU entity, office or staff required. EU users will do, or an EU customer whose own product embeds yours.
In practice the AI Act arrives at a South African supplier as a questionnaire from a client's legal team, not as a letter from Brussels. Being able to answer it accurately, including where the honest answer is "that duty sits with our vendor, and here is the clause", is a commercial asset.
What to do with the runway
Reallocating the budget and revisiting this in 2027 is the obvious move and the wrong one. The obligations did not change, only the date, and the work underneath them is slow.
1. Settle your role, per system, this month. Provider or deployer, and why. That answer decides which Article 50 paragraph is yours, and it is the first thing a client questionnaire asks. Where you are the deployer, get the vendor's position in writing.
2. Close out the Article 50 duties that are actually yours, and only those. Read the Commission's guidelines first; they will shorten the list.
3. Finish the inventory anyway. What AI you run, on what data, influencing what decisions, with who in the loop. It is what a regulator asks for first and a European client second, and it is the same data foundations work that makes any AI feature trustworthy.
4. Keep building for human oversight, and watch the harmonised standards rather than the headlines. Their absence is why the deadline moved; their arrival decides what compliance actually looks like.
The short version: the deadline that moved is the one most South African SMEs were not going to hit. The deadline that stayed is narrower than you have been told, and whether it reaches you turns on a role question you can settle in an afternoon. Settle that first, then do only the work that follows from it. If you want it mapped against your own systems rather than in the abstract, that is where our AI consulting work starts.
FAQ
Did the EU AI Act deadline change? Partly. Regulation (EU) 2026/1744, published on 24 July 2026, moved the high-risk obligations from 2 August 2026 to 2 December 2027 for standalone Annex III systems and to 2 August 2028 for AI embedded in regulated Annex I products. The Article 50 transparency obligations were not moved and apply from 2 August 2026.
What applies on 2 August 2026? The Article 50 transparency obligations, allocated by role. Providers must design directly interactive systems so people know they are dealing with AI, and must mark synthetic output in a machine-readable format. Deployers must disclose deepfakes and AI-generated text published to inform the public on matters of public interest, and inform people exposed to emotion recognition or biometric categorisation.
Do I have to label AI-generated marketing content? Generally not, on the strength of Article 50 alone. Ordinary marketing copy is not text published to inform the public on matters of public interest, and a generated image is not a deepfake unless it manipulates real people, places or events. Where a third-party tool generates the content, the machine-readable marking duty sits with that tool's provider. Other law, such as advertising rules, may still apply.
Am I a provider or a deployer? It is decided per system. Broadly, you are the provider if you develop a system, or have one developed, and place it on the market or put it into service under your own name or trademark, which typically covers building your own assistant on a model API. You are the deployer if you use somebody else's system under your own authority, such as switching on the AI feature in a product you subscribe to. White-labelling, fine-tuning and material reconfiguration sit in between and are worth legal review.
Does the EU AI Act apply to South African companies? Yes, where the output of your AI system is used in the EU. The Act applies extra-territorially in much the same way GDPR does, so you can be in scope without an EU entity. Most South African SMEs meet it first as a procurement questionnaire from a European client.
What is the fine for breaching Article 50? Up to €15 million or 3% of total worldwide annual turnover, whichever is higher. The widely quoted €35 million or 7% figure applies to the prohibited practices in Article 5, not to transparency. For SMEs and start-ups the calculation inverts, and each fine is capped at whichever of the amount or the percentage is lower.
Does this change my POPIA obligations? No. The Digital Omnibus amends EU law only. POPIA Section 71 on automated decision-making is unchanged and has no transition period.
References
- EU Law Live: Official publication: Digital Omnibus on AI Act and related sectorial legislation (Regulation (EU) 2026/1744, published 24 July 2026). https://eulawlive.com/official-publication-digital-omnibus-on-ai-act-and-related-sectorial-legislation/
- EUR-Lex: Regulation (EU) 2024/1689 (Artificial Intelligence Act), Article 50 (transparency obligations), Article 25 (responsibilities along the value chain), Article 99 (penalties). https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
- European Commission: Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems (press release, 20 July 2026). https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1653
- European Commission: Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act (final version, 20 July 2026). https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems
- European Commission: Code of Practice on Transparency of AI-Generated Content. https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
- Bird & Bird: European Commission adopts final Guidelines on AI Act Article 50 transparency obligations: first impressions (treatment of content generated before 2 August 2026). https://www.twobirds.com/en/insights/2026/european-commission-adopts-final-guidelines-on-ai-act-article-50-transparency-obligations-first-impr
- Winston Taylor: AI Act rules on high-risk AI delayed as AI Digital Omnibus agreed (the revised compliance timetable). https://www.winstontaylor.com/insights/ai-act-rules-on-high-risk-ai-delayed-as-ai-digital-omnibus-agreed
- Freshfields: EU AI Act unpacked #34: The final Digital Omnibus on AI (deferred deadlines, Article 50(2) transition, new prohibitions, AI Office powers, bias-detection data, Machinery Regulation, registration). https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/eu-ai-act-unpacked-34-the-final-digital-omnibus-on-ai-key-amendments-to-the-a-102nber
- South African Government / popia.co.za: Section 71: Automated decision-making. https://popia.co.za/section-71-automated-decision-making/
Written by JP, Sixees Labs. Last reviewed July 2026. This post is general information and not legal advice. Two things in particular need your own counsel rather than ours: which role you occupy under Article 50 for each of your systems, and whether a specific automated decision of yours falls inside POPIA Section 71. The Omnibus text is days old, the Commission's Article 50 guidelines are non-binding, and interpretation will move.