Regulation & Compliance

August 2 deadline: Which duties of the EU AI Act apply now — and which have been postponed

The AI Act postpones high-risk obligations to 2027 — Article 50 applies as of August 2, 2026. What banks must implement now regarding chatbots and AI content.

acceleraid Editorial Team

5 min read

Customer Lifecycle Management

Customer Lifecycle Management

Customer Lifecycle Management

01

Acquire

Recognize signals

02

Onboard

Control activation

03

Grow

Next Best Action

04

Retain

Reduce churn

05

Reactivate

Reclaim potential

Data → AI Score → Trigger → Channel → Feedback

Data → AI Score → Trigger → Channel → Feedback

Illustration: Chatbot erhält sichtbare KI-Kennzeichnung am Schalter

On July 27, 2026, the so-called Digital Omnibus on AI entered into force — as Regulation (EU) 2026/1744, published in the Official Journal of the European Union on July 24. Only six days later, on August 2, the next implementation phase of the EU AI Act becomes effective. This chronological proximity is no coincidence, but rather the heart of the matter: the legislator has split the AI Act compliance calendar into two parts. The complex high-risk obligations have been postponed, while the consumer-facing transparency obligations remain on schedule. Anyone who confuses the two risks a costly misjudgment.

What has actually been postponed

The most consequential change of the Omnibus concerns high-risk systems. The obligations for standalone high-risk AI under Annex III — explicitly including AI for creditworthiness assessment and credit scoring — now only apply from December 2, 2027, instead of August 2, 2026. For AI embedded in products that are already sectorally regulated (Annex I), the deadline is even postponed to August 2, 2028.

Important for context: this is a postponement, not a cancellation. The requirements for risk management, data quality, technical documentation, human oversight, and conformity assessment are coming — just later. Institutions using AI in credit assessment or risk pricing gain time for implementation, not the freedom to shelve the issue.

What applies from August 2

Article 50 of the AI Act — the transparency obligations for providers and deployers of certain AI systems — remains unchanged in the timeline. From August 2, 2026, the following essentially applies:

  • Disclosure for chatbots and AI assistants: Anyone deploying an AI system that interacts directly with humans must ensure that the individuals concerned can recognize that they are communicating with a machine — at the latest at the beginning of the first interaction, unless it is obvious.

  • Machine-readable labeling of synthetic content: Providers of generative systems must mark AI-generated audio, image, video, and text content in a machine-readable format. For systems that were on the market before August 2, 2026, there is a short grace period until December 2, 2026; new systems must comply with the obligation immediately.

  • Labeling of deepfakes and AI texts on matters of public interest: Deployers must disclose when content has been artificially generated or manipulated.

  • Information on emotion recognition and biometric categorization: Affected individuals must be informed about the use of such systems.

The enforcement powers for general-purpose AI models and the structures for market surveillance will also take effect starting August 2. Non-compliance with transparency obligations can be punished with fines of up to 15 million euros or 3 percent of global annual turnover.

The Commission's guidelines provide clarity

On July 20, 2026, the European Commission published guidelines on transparency obligations under Article 50, supplemented by an FAQ document and a Code of Practice on the labeling of AI-generated content. Among other things, these documents specify when an interaction can be considered "obviously AI", which technical methods are accepted for machine-readable labeling, and how the roles of provider and deployer are distinguished.

The question of roles is particularly central for financial institutions: most banks are deployers of AI systems that they obtain from technology partners — with their own clearly defined obligations. However, anyone who offers systems under their own name or significantly modifies them can slip into the role of provider, thereby assuming significantly more extensive obligations.

What banks should specifically implement now

For institutions with AI-supported customer communication, the deadline translates into a clear program of work:

  1. Create an inventory: Which systems interact directly with customers, and which ones generate content? These include service chatbots, AI assistants in online banking, generative tools in marketing, and automated text production.

  2. Design disclosures: The information that an AI is responding belongs at the beginning of the interaction — clear, understandable, and accessible. A note buried deep in the terms of use is not sufficient.

  3. Set up labeling processes: Anyone publishing AI-generated images, videos, or texts needs a process that reliably ensures labeling — also across agencies and service providers.

  4. Review contracts and responsibilities: The distinction between provider and deployer obligations should be reflected in contracts with technology partners.

  5. Establish auditability: As with all regulatory matters, the rule is: documentation is key. If you cannot prove implementation, you are assumed not to have implemented it.

Special case of marketing: AI-generated content in customer contact

Special attention should be paid to the marketing department, where generative AI has long been a part of daily routine — from product descriptions and newsletter variations to visual material for campaigns. The labeling obligation under Article 50 does not differentiate based on reach or channel: content in email campaigns, on landing pages, or in social media posts can also be affected if it has been artificially generated. At the same time, proportion is required: purely supportive use, where humans edit and take responsibility for texts, is to be evaluated differently from fully automatically published content. It is precisely for these distinctions that a look at the Commission's guidelines and Code of Practice is worthwhile.

For personalized customer engagement, this does not mean a ban, but rather a process requirement: institutions should know at which points of their customer journey generative systems produce content, and anchor the labeling where it is legally required — ideally automated within the production workflows rather than as manual individual checks.

Use the postponement instead of pausing

The delay of high-risk obligations invites a risky interpretation: wait and see. This would be wrong for two reasons. First, transparency obligations remain in place and affect exactly those systems that are most visible in customer interaction. Second, the new high-risk deadline of December 2027 is not a comfortable buffer for institutions with complex model landscapes, but rather a realistic project timeframe — especially when credit scoring models, documentation, and governance processes need to be made audit-proof.

There is also a strategic argument: transparency in AI use is not just an obligation, but a trust factor in the customer lifecycle. Institutions that communicate openly about where AI assists and where humans decide strengthen their relationships with customers — and gain a better starting position for the next stages of regulation. August 2 is therefore less of an end point and more of a starting signal: those who implement transparency obligations cleanly now have already completed half the groundwork for the high-risk requirements of 2027.

We use cookies 🍪

Strictly necessary cookies (e.g. Pipedrive forms) remain active. With your consent, we also use Google Analytics (analytics) and Leadfeeder (visitor identification). Learn more in our Privacy Policy.

Decline

Decline

Accept all

Accept all