For the past few weeks two client questions have sounded almost identical and needed opposite answers. The first: "we heard the AI Act got delayed — can we drop it?" The second: "everything applies from August, are we in trouble?" Both premises are wrong, and getting it wrong in either direction costs you something: an unnecessary compliance project, or real exposure to a fine.
Here is where things stand on 11 August 2026. The heaviest block of obligations — the ones for high-risk systems — really was postponed, and only a few weeks ago. But what took effect on 2 August covers exactly the AI uses that are most common in small and mid-sized companies today: the chatbot on your site and generated content. And as of today, Poland's own AI systems act joins the picture.
What exactly did the Digital Omnibus move?
Two deadlines for high-risk systems — and nothing else. The deferral is not a rumour or a proposal, it is law in force: Regulation (EU) 2026/1744, the Digital Omnibus on AI, was endorsed by the European Parliament on 16 June 2026, approved by the Council on 29 June, published in the Official Journal on 24 July, and entered into force on 27 July 2026.
It moves two dates. Standalone high-risk systems under Annex III — AI in recruitment, creditworthiness assessment, education, access to public services — were to be covered from 2 August 2026. That deadline moved by 16 months, to 2 December 2027. High-risk AI under Annex I — embedded in products already covered by EU product-safety law, such as machinery, medical devices, or toys — had a 2 August 2027 deadline. It moved by 12 months, to 2 August 2028.
The reason is mundane and worth knowing, because it says something about what comes next: the harmonised standards companies were meant to demonstrate conformity against were not ready in time. It is hard to demand proof of conformity with a standard that does not yet exist.
Was Article 50 deferred too?
No — and this is where the misunderstanding lives. Article 50 — the transparency obligations — was excluded from the deferral and applies on the original schedule, from 2 August 2026. More importantly, it attaches not to a risk tier but to a system's function. You do not need a high-risk system for it to apply. A chatbot is enough.
Four duties, in practice:
Systems that talk to people. The provider must design the system so a person knows they are dealing with AI. This covers chatbots, voice assistants, agents, and avatars. The exception: cases where it is obvious to a "reasonably well-informed, observant and circumspect" person. Do not build a strategy on "but it is obvious" — one sentence in the interface costs less than an argument about what was obvious.
Synthetic content generators. A provider of a system generating text, image, audio, or video must mark the output in a machine-readable format so it can be detected as artificially generated or manipulated. The solution must be "effective, interoperable, robust and reliable as far as this is technically feasible" — that cautious wording is deliberate, because marking technology is still maturing. Exceptions: standard assistive editing functions, and cases where the input data is not substantially altered.
Emotion recognition and biometric categorisation. Here the duty falls on the deployer: inform the people exposed to the system, and stay compliant with GDPR.
Deepfakes and text on matters of public interest. Also a deployer duty. Generated or manipulated image, audio, and video must be disclosed. So must AI-generated text published to inform the public on matters of public interest. Two exceptions save the situation in practice: artistic, creative, satirical, and fictional work, where disclosure is limited to noting that such content exists without spoiling the work — and text that has been through human review, where a person carries editorial responsibility.
That last exception matters most in day-to-day work. If AI-generated content passes through a human who reads it, edits it, and stands behind it, the Article 50(4) disclosure duty does not arise. The condition: that responsibility has to be real and assigned to a named person, not written into a slide deck.
The form is regulated too. The information must be clear and distinguishable, at the latest at the time of the first interaction, and meet accessibility requirements. Buried in the terms of service does not count.
By when must AI-generated content be marked?
By 2 December 2026 — and that is the one concession the Omnibus granted inside Article 50, narrow and purely technical. The machine-readable marking duty for synthetic content got a four-month grace period. The rest of Article 50, including the entire "tell the human this is AI" layer, has applied since 2 August.
What to do with that time: check what your model vendor actually offers — C2PA metadata, a watermark, a file signature — turn it on, and test whether the mark survives your own publishing pipeline: conversion, compression, the crop to a social format. Then document the choice together with its limits. With wording like "as far as this is technically feasible", a documented, deliberate decision is your strongest position.
Can the Commission already fine AI model providers?
Yes — since 2 August 2026. That is the second thing that switched on that day: the rules got teeth. From that date the European Commission and its AI Office can exercise supervisory powers over providers of general-purpose AI models: request documentation, run technical evaluations of a model, order corrective measures, restrict or withdraw a model from the EU market, and impose fines — up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. The top tier, EUR 35 million or 7%, applies to the prohibited practices in Article 5 and has been in force since February 2025 — not to GPAI documentation.
If you build on someone else's model you are not a GPAI provider and those fines are not yours. But your vendor is one, and that changes two practical things. Their documentation, copyright policy, and training-data summary become available and checkable — worth actually reading before you pick a model. And your contract with the end client should say who is responsible for compliance at the model layer.
What does Poland's AI systems act change?
The regulation applies directly, but someone has to enforce it — and that is what Poland's act on artificial intelligence systems supplies. The President signed it on 24 July 2026, it was published on 27 July, and its core provisions — the organisation of supervision, notified bodies, and innovation-support measures — enter into force on 11 August 2026, the day this article is published.
The supervisory authority is KRiBSI, the Commission for the Development and Security of Artificial Intelligence: an independent collegial body supported organisationally by the Ministry of Digital Affairs. Its members come from institutions that already supervise their own markets: the President of the competition and consumer authority UOKiK, the Financial Supervision Authority, the National Broadcasting Council, and the President of the electronic communications office UKE. The chair is appointed by the Sejm with the Senate's consent for a five-year term; the appointment is expected in October 2026, with the Commission fully operational from November.
Two things are worth noting. First: KRiBSI can impose administrative fines from 28 October 2026, in three tiers — up to EUR 35 million or 7% of turnover for prohibited practices, up to EUR 15 million or 3% for other specified infringements, and up to EUR 7.5 million or 1% for supplying the authority with incorrect or misleading information. Second: during the parliamentary process, some of the Commission's harder enforcement powers, such as ordering a system's withdrawal, were removed from the act.
There is an upside that is easy to miss. The act provides the legal basis for regulatory sandboxes — testing AI systems under controlled conditions, with the authority involved, before full market deployment. For micro, small, and medium-sized enterprises, participation is free. If you are building something that brushes against high risk, that is cheaper than guessing.
| Date | What starts applying | Who it affects |
|---|---|---|
| 2 February 2025 | Prohibited practices (Art. 5) and AI literacy (Art. 4) | Everyone — providers and deployers |
| 2 August 2025 | Obligations for providers of general-purpose AI models (GPAI) | Model providers |
| 2 August 2026 | Article 50 transparency; Commission fining powers over GPAI | Chatbots, content generators, deepfakes, emotion recognition |
| 11 August 2026 | Poland’s AI systems act: supervision, notified bodies, sandboxes | The Polish market |
| 28 October 2026 | KRiBSI can impose administrative fines | The Polish market |
| 2 December 2026 | End of the grace period for machine-readable content marking | Providers of content generators |
| 2 December 2027 | High-risk systems, Annex III (after the deferral) | Hiring, education, credit, public services |
| 2 August 2028 | High-risk systems, Annex I (after the deferral) | AI embedded in regulated products |
What should you do this quarter?
1. Take inventory. Write down every place where AI touches a person: the chatbot on your site, the Telegram bot, the voice assistant, generated campaign copy and graphics, CV screening, customer scoring. Without that list you cannot assign obligations.
2. Add your role to each item. Provider or deployer — Article 50 splits duties exactly that way, and most companies are both at once: a deployer of someone else's model and the provider of their own chatbot.
3. Add disclosure at the first interaction. One sentence in the chat window, in the bot's description, and in the welcome message. Accessible and visible, not in the footer of your terms.
4. Turn on content marking and test it. Deadline: 2 December 2026. Check whether the mark survives your own publishing pipeline, and write down what you chose and where its limits are.
5. Assign editorial responsibility for content. Who — by name — reads and stands behind AI-generated text before it goes out. That is the exception that removes the Article 50(4) disclosure duty.
6. Close two backlog items. The AI literacy duty in Article 4 has applied since February 2025: a real, short team training and a record that it happened is enough. And define a serious-incident reporting procedure, so you are not improvising on the day you need it.
How does this look in our own products?
In Legalka KB, a relocation bot on Telegram, the fact that AI answers is stated in the bot's description and in its first message; every answer cites its sources, and when a question falls outside the knowledge base the bot declines instead of improvising. We did not build that for Article 50 — we built it so the answers would be correct, and the transparency requirement turned out to be a side effect of the same decision.
In eMarketing AI, content is produced with agents but reaches publication through a human who approves it — the point at which editorial responsibility exists. In Accounting AI Agent, answers rest on data from wFirma and the agent says plainly what it read. The conclusion from all three is the same: an architecture where the model always cites a source and always has room to say "I do not know" is also an architecture that is easy to demonstrate to a regulator.
Is this article legal advice?
It is not legal advice. It is a snapshot as of 11 August 2026 — and the dates in it already changed once, three weeks ago. Before you act, check the current text of the regulation in EUR-Lex and the Ministry of Digital Affairs' information on the AI systems act, and take your specific case to a lawyer. If the question is instead "are our chatbot and our content sound on the technical side" — that is a conversation we have every day.
Frequently asked questions
- Was the AI Act postponed?
- Partly. Regulation (EU) 2026/1744 — the Digital Omnibus on AI, in force since 27 July 2026 — deferred the high-risk obligations: Annex III systems from 2 August 2026 to 2 December 2027, and Annex I systems from 2 August 2027 to 2 August 2028. It did not defer Article 50 transparency, which applies from 2 August 2026 (apart from a four-month grace period for machine-readable content marking, through 2 December 2026), nor the Commission’s powers to fine providers of general-purpose AI models, which also apply from 2 August 2026. The Article 5 prohibited practices and the Article 4 AI literacy duty have applied since February 2025.
- Do I have to tell users they are talking to a chatbot?
- Yes. Article 50(1) of the AI Act, in force since 2 August 2026, requires systems that interact directly with people — chatbots, voice assistants, agents, avatars — to be designed so the person knows they are dealing with AI. The information must be clear and distinguishable, given at the latest at the time of the first interaction, and meet accessibility requirements; a line in your terms of service is not enough. The exceptions are cases where this is obvious to a reasonably well-informed, observant and circumspect person, and certain law-enforcement uses. The duty does not depend on the system being high-risk — it follows from its function.
- What is the penalty for not marking AI-generated content?
- Breaching the Article 50 transparency duties carries a fine of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. The machine-readable marking duty for synthetic content has a four-month grace period through 2 December 2026 — the rest of Article 50 has applied since 2 August 2026. In Poland, KRiBSI can impose administrative fines from 28 October 2026, in tiers of up to EUR 35 million or 7% of turnover for prohibited practices, up to EUR 15 million or 3% for other specified infringements, and up to EUR 7.5 million or 1% for incorrect or misleading information. In practice what matters is whether you can show the marking and disclosure were in place — which is why it pays to document the solution you chose and its limits.
- Does the AI Act apply to a small company that just uses ChatGPT?
- Yes, though in a narrower way. A company using an off-the-shelf model is a deployer, not a provider, so the GPAI provider obligations are not theirs. Still applicable: disclosing deepfakes and text published to inform the public on matters of public interest (Article 50(4) — except content reviewed by a human who carries editorial responsibility), informing people subject to emotion recognition, the Article 4 AI literacy duty in force since February 2025, and GDPR for personal data. If the company puts its own chatbot in front of customers, it becomes the provider of that system and the Article 50(1) disclosure duty is added. Poland’s act gives SMEs free participation in regulatory sandboxes.
- What is KRiBSI and when does it start operating?
- KRiBSI — the Commission for the Development and Security of Artificial Intelligence — is Poland’s AI market supervisory authority, created by the act on artificial intelligence systems whose core provisions entered into force on 11 August 2026. It is an independent collegial body supported organisationally by the Ministry of Digital Affairs; its members come from the competition and consumer authority UOKiK, the Financial Supervision Authority, the National Broadcasting Council, and the electronic communications office UKE. The chair is appointed by the Sejm with the Senate’s consent for a five-year term — the appointment is expected in October 2026, with the Commission fully operational from November 2026. It can impose administrative fines from 28 October 2026. During the parliamentary process some harder enforcement powers, such as ordering a system’s withdrawal from the market, were removed from the act.