Skip to content
RiskTemplates · The Daily Brief Friday, September 11, 2026
Wire SEC's $3.02M Doximity Insider Trading Judgment: The MNPI Control Test SEP 10

Feature AI Risk

EU AI Act in August 2026: Article 50 Is Live and Annex III Moved to 2027

Article 50 applies from August 2, 2026, while Annex III high-risk rules move to December 2, 2027 under final Regulation (EU) 2026/1744.

By Rebecca Leung · July 28, 2026 ·
Table of Contents

TL;DR

  • The Digital Omnibus is final Regulation (EU) 2026/1744, not a pending proposal.
  • Article 50 transparency duties apply from August 2, 2026.
  • A limited transition applies to certain pre-existing systems for machine-readable marking. It is not a universal Article 50 deferral.
  • The relevant Annex III high-risk-system requirements move to December 2, 2027.
  • Financial-services teams must classify entity role, system type, content, audience, and territorial scope before assigning a control.

August 17, 2026 Status Update

The legal timeline is now split:

RequirementStatus on August 17, 2026
Article 50 transparencyApplicable from August 2, 2026, subject to its role- and content-specific terms
Limited pre-existing-system marking transitionAvailable only where the final amendment’s conditions are met
Annex III high-risk-system requirements affected by the amendmentApplicable December 2, 2027
Digital OmnibusFinal Regulation (EU) 2026/1744

The AI Act and Regulation (EU) 2026/1744 control. Earlier articles describing a Commission proposal, political agreement, or possible delay are no longer adequate status sources.

Article 50 Is Not One Blanket Disclosure Rule

Article 50 allocates duties by role and function. A compliance inventory should distinguish at least:

  • a provider of an AI system intended to interact directly with natural persons;
  • a provider of an AI system that generates synthetic audio, image, video, or text content;
  • a deployer of an emotion-recognition or biometric-categorization system;
  • a deployer that generates or manipulates deepfake content; and
  • a deployer of AI-generated or manipulated text published to inform the public on matters of public interest.

Each category has its own wording, timing, exceptions, and technical requirements. “We added an AI disclaimer to our privacy policy” is not an Article 50 control assessment.

Direct interaction

For an AI system intended to interact directly with people, assess whether the relevant provider duty to inform the person that they are interacting with AI applies and whether an exception in the text is relevant. The notice should be tied to the interaction, not buried in general terms.

Machine-readable marking

Providers of systems that generate synthetic content must evaluate the technical marking requirements in Article 50(2). The final amendment includes limited treatment for certain systems placed on the market before August 2, 2026. Record the placement date, system version, role, technical feasibility, and exact provision relied on.

Do not turn that transition into a statement that all legacy systems can wait.

Deployer disclosures

Emotion-recognition, biometric-categorization, deepfake, and public-interest text use cases require separate deployer analysis. The content, context, audience, editorial control, and statutory exceptions matter.

The European Commission’s Article 50 guidance page should be read with the regulation. Guidance helps implementation; it does not replace the operative text.

Annex III Moved to December 2, 2027

The final amendment changes the application date for relevant Annex III high-risk AI systems to December 2, 2027. The Commission’s high-risk systems guidance provides current implementation context.

For financial services, potential Annex III analysis often begins with systems used to evaluate the creditworthiness of natural persons or establish a credit score. Do not assume that every fraud, AML, pricing, or analytics model is automatically high-risk. Apply the exact Annex III category, definitions, exclusions, intended purpose, and role.

A defensible classification record includes:

  • legal entity and territorial nexus;
  • system and version;
  • intended purpose and actual use;
  • provider, deployer, importer, distributor, or other role;
  • affected persons and decision consequence;
  • Annex entry considered;
  • exclusion or exception relied on;
  • accountable legal and business approvers; and
  • revalidation triggers.

What U.S. Fintechs Should Do Now

1. Confirm territorial scope

The AI Act has extraterritorial provisions, but “an EU user can see it” is not a complete legal test for every obligation. Map where systems are placed on the market, put into service, deployed, and where outputs are used, then obtain role-specific legal analysis.

2. Inventory Article 50 touchpoints

Review customer support, virtual assistants, voice systems, marketing media, training content, public-interest publications, and generated documents. Capture the system provider and deployer, model, interface, audience, content type, disclosure, marking method, and exception.

3. Test the live experience

Verify what a user actually sees or hears at first interaction and what metadata or label remains after content export, compression, reposting, or vendor handoff. Retain screenshots, sample files, metadata checks, and release approvals.

4. Document any transition

If relying on pre-existing-system marking relief, preserve the facts and exact legal basis. Assign an end date and engineering owner. Do not use “legacy” as a permanent exemption label.

5. Keep Annex III on a separate plan

Use the December 2027 date for applicable high-risk systems, while continuing inventory, risk management, data governance, documentation, logging, human oversight, accuracy, robustness, cybersecurity, and conformity-assessment planning as appropriate. These are implementation workstreams, not a claim that proposed or future duties already apply to every model.

Enforcement Timing Still Requires Precision

The Commission’s AI Act enforcement timeline summarizes staged application. Use that page for orientation, then cite the regulation for the legal obligation.

Avoid three common errors:

  • describing Regulation (EU) 2026/1744 as only a proposal;
  • saying all Article 50 obligations were deferred; or
  • saying the Article 50 marking transition postpones every transparency duty for every pre-existing system.

So What?

August 2, 2026 was a real Article 50 milestone. December 2, 2027 is the revised Annex III milestone. The hard part is assigning the right rule to the right role and system.

Run an Article 50 inventory now, document any narrow transition relied on, and keep high-risk classification and implementation on a separate, evidence-based track.

The AI Risk Assessment Template can structure system inventory and review. It does not replace the AI Act’s role, scope, and category analysis.


Primary sources: EU AI Act, Regulation (EU) 2024/1689 | Digital Omnibus, Regulation (EU) 2026/1744 | Commission Article 50 guidance | Commission high-risk systems guidance | Commission enforcement timeline

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

Is the Digital Omnibus still a proposal?
No. Regulation (EU) 2026/1744 is final law. It changed parts of the AI Act timeline, including the application date for Annex III high-risk-system requirements. Use the final regulation rather than older proposal or political-agreement summaries.
When did Article 50 begin to apply?
Article 50's transparency obligations apply from August 2, 2026. Duties vary by role and system: providers of certain AI systems, providers of systems generating synthetic content, and deployers of specified emotion-recognition, biometric-categorization, deepfake, or public-interest text systems do not all have the same obligation.
Is there any Article 50 transition relief?
The final amendment includes a limited transition for machine-readable marking obligations involving certain systems placed on the market before August 2, 2026. It is not a blanket delay for chatbot disclosure, deployer labeling, or every pre-existing AI system. Check the exact conditions against the system and role.
When do Annex III high-risk rules apply?
Regulation (EU) 2026/1744 moves the relevant Annex III high-risk-system application date to December 2, 2027. Creditworthiness and credit-scoring use cases may fall within Annex III, subject to the AI Act's definitions, exclusions, roles, and specific system facts.
What should a U.S. fintech do now?
Confirm territorial scope, identify its role for each system, inventory EU-facing AI interactions and generated content, map Article 50 duties, document any transition relied on, and maintain a separate Annex III plan for systems that may be high-risk. Do not apply one generic disclosure to every role and call the analysis complete.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.