What the EU AI Act actually asks of a 12-person team on 2 August
We sat down to write the "August deadline" post our own marketing plan called for, checked the current text first, and found the deadline had been amended out from under us. Here's what genuinely lands, what moved, and why the client questionnaire is the harder deadline anyway.
Our own marketing plan told us to publish this post in late July, to catch the 2 August deadline when the EU AI Act became "fully applicable." We'd written that line ourselves, in June, after reading a stack of coverage that all said the same thing.
We checked the current text before publishing, the way you're supposed to and mostly don't. The deadline had moved while we weren't looking.
Not the date — 2 August is still 2 August. What moved is what happens on it. A set of amendments known as the Digital Omnibus on AI cleared its final EU steps this summer, signed on 8 July 2026, and pushed the heavy obligations well into the future: stand-alone high-risk systems under Annex III now have until 2 December 2027, and AI embedded in regulated products until 2 August 2028 (Inside Global Tech's summary, Data Protection Report). A lot of what small businesses were told to fear in August isn't arriving in August.
What does land on 2 August
The transparency obligations in Article 50 (Commission FAQ, article text). In plain terms, they're about telling people when they're dealing with, or looking at, something a machine made.
For a small company using AI internally — drafting, summarising, coding, taking meeting notes — our read is that this lands lightly. Article 50 is aimed at systems that interact with people or generate synthetic content, not at whether your team used an assistant to write a proposal.
Three places it does bite, and the third is the one agencies should read twice.
If you ship a chatbot, people have to be able to tell it's a machine, unless that's obvious from context. And the Commission's guidance is explicit that this has to be perceivable in the interaction itself — buried in your terms, or a vague "assistant" label, doesn't do it.
If you generate images, audio or video of real people, the deepfake disclosure duty applies: the viewer needs to know it's artificial, in a way they can perceive without special tools, at first exposure.
If you publish AI-generated text to inform the public on matters of public interest, it needs disclosing — with a carve-out where a human has reviewed it and a named person or company holds editorial responsibility. Note the scope: routine promotional copy generally isn't "informing the public on matters of public interest," so most marketing text sits outside this particular duty. That distinction is doing a lot of work, and it's exactly the kind of line we'd want a lawyer to draw for a specific campaign rather than take from a blog post.
Two timing details worth knowing. On back catalogues: content generated and published before 2 August doesn't need retroactive labelling, but content generated before and published after that date is in scope. And the machine-readable marking duty in Article 50(2) — watermarking synthetic output — got a short reprieve of its own for systems already on the market at 2 August, moving to 2 December 2026; new systems comply when they're placed on the market.
There's also a Code of Practice on transparency of AI-generated content with practical guidance on how labels should look and where they go. It's voluntary, but it was assessed as adequate in early July, which makes adhering to it the recognised way to show you're meeting the marking and disclosure duties — not conclusive proof, but the closest thing on offer. Worth skimming if you produce synthetic content for clients. The Commission's final Article 50 guidelines landed on 20 July 2026 and run to about fifty pages; they're the reference national authorities are expected to work from.
The obligation that's been live for eighteen months
Article 4, on AI literacy, is the one small teams keep missing because it didn't come with a countdown. It's applied since February 2025 (text).
It asks providers and deployers to see to it that staff — and contractors operating systems on their behalf — have a sufficient level of AI literacy, judged against their technical knowledge, the context the tools are used in, and who the systems are used on. There's no small-business exemption. There is proportionality baked into the wording, which for a twelve-person agency means something much lighter than an enterprise programme.
The Digital Omnibus softened this too. The Commission had proposed deleting Article 4 outright; what survived instead is a lowered standard — supporting the development of AI literacy rather than ensuring a sufficient level of it. Effort rather than result. That's a meaningful legal change and, practically, it changes very little about what a sensible small team should do.
Here's the part we find genuinely useful: "AI literacy" sounds like a training budget, and for a small team it mostly isn't. It's whether the people using these tools know which ones are sanctioned, what data is safe to put in them, and who to ask. That's a document and a conversation, not a course.
The deadline that's actually harder than the regulation
So: less arrives in August than you were told, most of the rest is years out, and the piece most likely to apply to you has quietly applied since early 2025.
We'd still not treat that as permission to do nothing, and not because of fines. The realistic forcing function for a small company was never an EU regulator. It's the client who sends a security questionnaire with an AI section, the insurer whose renewal form grew new questions, or the enterprise prospect whose procurement team wants to know what happens to their data.
“Those arrive with a two-week deadline and no extension, and they don't care that Annex III moved to 2027.”
That's the honest case for doing the work now, and it's a smaller, calmer case than the one the compliance-marketing industry has been making. Around 77% of AI-using small businesses have no written AI policy at all — no approved-tools list, no data rules, no owner. The gap isn't a legal one. It's that nobody can answer basic questions about their own company.
Three things worth doing, regulation or not
None of this is legal compliance advice. It's the same short list we'd give someone who'd never heard of the AI Act, because it's just knowing what your company does.
- Write down which AI tools your team uses, including the ones nobody approved. Ask rather than detect; you'll get better data and keep the goodwill.
- Say what data may go into each one. Name actual documents — customer records, contracts, credentials, source code — not "sensitive information," which everyone interprets in their own favour at the end of a long day.
- Keep a dated record that people read the rules, and keep the old versions when the rules change. A message in a Slack channel proves a message was sent.
If you're producing AI-generated content for clients, add a fourth: work out now who the deployer is on each engagement — you or the client — because that determines who carries the disclosure duty. That's a contract question, and it's cheaper to answer before the campaign than after.
We build a small register for exactly this list — approved tools, data rules per tool, and acknowledgments recorded against a specific version of the policy. It isn't a compliance product and we'd distrust anyone selling you one at this size; it produces the artifacts, and whether they satisfy a given obligation is a question for your lawyer and your client's questionnaire. It's also not public yet, so this post isn't asking you for anything.
What we'd take from this
The version of this post we were planning to write in June would have been wrong, in the direction that sells better. That's worth sitting with, because a lot of what a small business reads about AI regulation is written by people with something to sell them, and the incentive points one way.
Check the date on anything you read about the AI Act, including this. The Omnibus amendments were signed in early July, the Commission's Article 50 guidance was approved on 20 July 2026, and plenty of guidance written before late 2025 no longer matches the text. If a post about a 2026 deadline doesn't link to the current article, it's describing a law that changed.
Sources are linked throughout, primary where possible. Everything here reflects the text as we read it in late July 2026 — not legal advice, just developers reading the regulation and showing our work.