Skip to content

Europe

Independent · Brussels & Berlin

Technology · Digital regulation

EU AI Act transparency rules take effect, but high-risk safeguards delayed until 2027

The latest phase of Europe's artificial intelligence law requires chatbots and deepfakes to be labelled, yet the strongest protections for vulnerable groups have been pushed back 16 months.

By , Technology Editor

Published

8 min read

When the European Union's Artificial Intelligence Act entered its next phase on 2 August 2026, the fanfare was modest and for good reason. The transparency obligations that kicked in this week are operationally significant but hardly radical: chatbots must tell users they are interacting with a machine, synthetic images and audio must carry machine-readable labels, and anyone subjected to emotion recognition or biometric categorisation must be informed. The provisions that would have mattered most, the ones governing high-risk deployments in migration, employment and essential services, are absent. They were postponed in May until December 2027.

What actually changed on 2 August

Article 50 of the AI Act is now enforceable. It imposes three distinct transparency duties. First, any AI system that interacts directly with people, a chatbot on a banking website, for instance, must disclose that the user is communicating with an artificial system, unless the context already makes that obvious. Second, providers of AI that generates or manipulates images, audio, video or text must ensure the output carries machine-readable markings where the Act requires them. Third, systems that recognise emotions or sort people by biometric data must tell individuals that such processing is under way.

These are disclosure rules, not prohibitions. The technology itself remains legal; what changes is the obligation to be open about it. Breaches carry administrative fines of up to 15 million euros or 3 per cent of a company's worldwide annual turnover, whichever figure is higher. Certain law enforcement activities are exempt from some of these requirements.

For most businesses, the immediate effect is compliance work rather than a strategic pivot. Companies do not need to scrap existing AI tools or seek regulatory approval before deploying them. The practical task is auditing where AI already sits inside products, customer-facing services and internal processes, including tools licensed from third parties, and making sure those systems meet the new labelling and disclosure standards.

The high-risk delay and how it happened

The bigger story is what did not happen this month. The AI Act's most consequential obligations, those covering systems deemed high-risk in areas such as biometric identification, hiring, education, critical infrastructure and migration and border management, were originally scheduled to take effect on 2 August alongside the transparency rules. In May, as part of a broader Digital Omnibus package, EU lawmakers pushed that deadline back by 16 months, to 2 December 2027.

The European Commission frames the postponement as an implementation adjustment, not a retreat. Henna Virkkunen, the Commission's Executive Vice President, said at the time that the goal was to make it easier to innovate without lowering the bar on safety, arguing that both companies and regulators needed clearer guidance, finished technical standards and better support tools before the most demanding obligations could fairly be enforced. The Commission also linked the change to its wider competitiveness agenda, invoking the 2024 report by former European Central Bank President Mario Draghi, which argued that regulatory burden was weighing on European growth, though Draghi did not single out AI regulation specifically.

European Parliament negotiators accepted the compromise on the basis that the technical standards underpinning compliance for high-risk systems were simply not ready in time. Without those standards, the argument went, companies could not know with certainty what compliance looked like, and regulators could not enforce it consistently.

Who gains from the postponement

The delay relieves immediate pressure on firms developing or deploying AI in recruitment, credit scoring, border management and similar fields. These organisations now have until late 2027 before they must meet the Act's requirements for risk management systems, documentation, data governance, traceability and human oversight. Existing laws, notably the General Data Protection Regulation and sector-specific rules, continue to apply in the interim. But those frameworks were not written with automated decision-making in mind, and campaigners argue they leave significant gaps.

Digital rights organisations have challenged the Commission's reasoning. They argue that reopening a recently adopted law, even to adjust a deadline, risks eroding protections and signals to industry that lobbying can soften enforcement timelines. Several groups have warned that the delay could set a precedent for further rollbacks across Europe's digital rulebook.

The gap at Europe's borders

The postponement bites hardest in the context of migration and border management. Annex III of the AI Act already classifies certain AI systems used in asylum processing, visa and residence decisions, and border surveillance as high-risk. That classification reflects the EU's own acknowledgment that people in these situations are particularly exposed to the consequences of automated decisions. Under the full regime, these systems would face additional safeguards around risk management, documentation, data quality, traceability and human oversight. None of those obligations will apply until the delayed deadline.

Stefi Richani, advocacy lead at the Equinox Initiative for Racial Justice, which coordinates with the EU-wide ProtectNotSurveil coalition, argues that the delay will have direct consequences. She says it will increase surveillance and discrimination, and could lead to asylum claims being unlawfully rejected on the basis of personal characteristics or racialised suspicion. For Richani, the problem runs deeper than timing. She contends that predictive and automated systems used in migration contexts should be banned outright rather than regulated, and that investment should instead go towards safe routes and social protection.

There is a further geographical limit to the Act's reach. The European Union funds migration and border surveillance technology that is deployed in third countries, at transit points along routes into Europe, for example. Those deployments fall outside the AI Act's jurisdiction regardless of when the high-risk rules take effect. The law's transparency provisions may well be adopted globally, as companies tend to apply a single standard worldwide rather than maintain separate compliant and non-compliant versions. But the strongest protections in the legislation stop at the EU's own perimeter.

The Brussels effect, in both directions

The comparison with GDPR is instructive even if it is not exact. The data protection regulation, which took full effect in 2018, shaped privacy practices far beyond Europe because multinational organisations found it simpler to apply one standard everywhere. The AI Act's transparency requirements are likely to produce a similar dynamic. Companies that build labelling and disclosure systems to satisfy EU regulators will typically deploy those same systems globally, since maintaining divergent versions adds cost and complexity.

Yet the Brussels effect cuts both ways on artificial intelligence. Where the EU's regulatory model spreads outward, its border surveillance funding does too. Technology procured by EU agencies and deployed in countries outside the bloc operates in a regulatory space the AI Act was never designed to reach. The result is an uncomfortable asymmetry: the disclosure and labelling rules may become a de facto global standard, while the safeguards meant for the most vulnerable people affected by these systems remain geographically bounded and temporally deferred.

The phased rollout so far

The AI Act has been rolling out in stages. Prohibited practices, covering a small number of uses such as social scoring by governments and certain types of biometric mass surveillance, have been banned since February 2025. Obligations for general-purpose AI models, the large systems that underpin tools like chatbots and image generators, followed in August 2025. The transparency provisions that took effect this week represent the third phase. The high-risk regime, now delayed, would have been the fourth and the one with the broadest practical impact on how organisations manage risk, document their systems and maintain human oversight.

Sources

  1. Al Jazeera

    aljazeera.com · 2026-08-06

People mentioned

  • Henna Virkkunen

    Executive Vice President, European Commission

  • Stefi Richani

    Advocacy Lead, Equinox Initiative for Racial Justice

Organisations

European Commission · Equinox Initiative for Racial Justice · ProtectNotSurveil coalition

Related analysis

Selected because they share topics with this article

The newsletter

One important European story. Explained properly.

Delivered to your inbox on the days we publish. No daily digest, no push notifications, no advertising.

We store your address only to send the briefing. Unsubscribe in one click.