All insights

From the engineering desk

Insight10 min read20 July 2026

EU AI Act Deadlines for Device Makers: What Applies in 2026

High-risk obligations slipped to 2027–2028 — but Article 50 transparency lands 2 August 2026. Which deadline applies to your product, and what to build.

By Axon Labs Engineering

The EU just rewrote its AI Act calendar. In late 2025, the “Digital Omnibus” package pushed high-risk obligations back by more than a year — and a wave of headlines told device makers they could relax. They can’t. Article 50’s transparency rules still take effect on 2 August 2026, they apply to any product with a conversational or generative AI feature sold into the EU, and the engineering they assume can’t be retrofitted in a sprint. Here’s the calendar that actually applies to your device.

Key takeaways

  • The Digital Omnibus moved Annex III high-risk obligations to 2 December 2027 and product-embedded (Annex I) AI to 2 August 2028 — but Article 50 transparency was not delayed and applies from 2 August 2026.
  • From August 2026, devices with AI features that interact with people must disclose it at first interaction — burying it in the terms, or naming the feature “assistant,” doesn’t count. Generative outputs need machine-readable marking.
  • Penalties scale to €35M or 7% of global turnover. Combined with the Cyber Resilience Act’s September 2026 reporting start, EU market access now assumes an architecture: disclosure, marking, logging, and secure updates.

What did the Digital Omnibus actually change?

In late 2025, the EU’s Digital Omnibus simplification package delayed the AI Act’s two heaviest deadlines: standalone high-risk systems under Annex III moved from August 2026 to 2 December 2027, and AI embedded as a safety component in regulated products (Annex I) moved to 2 August 2028 (Travers Smith; Cloud Security Alliance).
What didn’t move matters more for most device makers. The prohibitions have applied since February 2025. General-purpose AI model rules have applied since August 2025. And Article 50’s transparency obligations still take effect on 2 August 2026 (Technology.org). If your product talks, generates, or reads emotions, that’s your deadline — two weeks after this article’s publication date.

What still lands on 2 August 2026?

Article 50 of Regulation (EU) 2024/1689 imposes four duties, and each maps to a product feature device makers ship today (AI Act, Article 50).
  • AI-interaction disclosure. Systems that interact directly with people must make clear they’re AI — at first interaction, in an accessible way. Per the Commission’s draft guidance, a line in the terms and conditions is not sufficient, watermarks alone are not sufficient, and even naming the feature “assistant” falls short (Greenberg Traurig). Think visible notices, audio cues, persistent indicators.
  • Machine-readable marking of generative output. AI-generated audio, image, video and text must be marked as synthetic in a machine-readable, detectable format — watermarking, metadata, provenance signals.
  • Emotion recognition and biometric categorisation. People exposed to these systems must be informed. Wearables inferring stress or mood sit close to this line.
  • Deepfake labeling. Artificially generated or manipulated content depicting real people or events must be disclosed.
A Code of Practice on marking and labelling — with a taxonomy separating “fully AI-generated” from “AI-assisted” content and technical standards for watermarking — was finalized ahead of the deadline (European Commission). For a device with a voice interface, the practical question is concrete: where, in your onboarding flow and UI, does the user unambiguously learn they’re talking to AI? If the answer is “the manual,” you have August work to do.

The full timeline, post-delay

In 2026, the sequencing is the strategy: transparency now, high-risk conformity in stages through 2027–2028 — with the Cyber Resilience Act’s reporting obligations arriving in between, on 11 September 2026. Teams that treat these as one program, not three, do the work once.

Is your device high-risk under the AI Act?

Two routes lead to high-risk classification, and they carry different deadlines. Route one: your AI is a safety component of — or is itself — a product covered by EU harmonised legislation (machinery, medical devices, radio equipment, toys, vehicles). That’s Annex I, now due 2 August 2028 (Certivo). Route two: your system lands in an Annex III use-case — biometrics, critical infrastructure, employment, essential services — due 2 December 2027.
Your device’s AI featureRouteDeadline
Voice or chat interface users talk toArticle 50 disclosure2 Aug 2026
Generates audio, image, video or textArticle 50 marking2 Aug 2026
Emotion recognition on usersArticle 50 disclosure — and likely Annex III2 Aug 2026 / 2 Dec 2027
Standalone Annex III use-case (biometrics, infrastructure…)High-risk, Annex III2 Dec 2027
AI as safety component in a regulated product (MDR, machinery, RED…)High-risk, Annex I2 Aug 2028
Social scoring, manipulative techniques, untargeted face scrapingProhibitedBanned since Feb 2025
Classification is a claims-and-function question, not a marketing one — the same discipline as the medical-vs-wellness decision in health wearables: decide the tier deliberately, then engineer to it.

What does high-risk actually require — in engineering terms?

When the high-risk deadlines do arrive, the obligations read like the CRA’s Annex I with an ML supply chain attached: a documented risk-management system, data governance for training and test sets, technical documentation, automatic logging, human oversight, and accuracy, robustness and cybersecurity safeguards — then conformity assessment, an EU declaration of conformity, CE marking and registration in the EU database (Legal Nodes).
  • Risk management → a living hazard analysis for the AI behavior, not a one-time document.
  • Data governance → dataset provenance, representativeness checks, and versioning for whatever trained the shipped model.
  • Automatic logging → the device records what the model decided and when — which presupposes storage, telemetry and privacy design.
  • Human oversight → an override or review path that actually works at product speed.
  • Accuracy & robustness → measured performance thresholds on target hardware, monitored for drift in the field — model validation as a phase gate, as we argued in the edge AI development guide.

Plan the AI Act and CRA as one architecture

For a connected, intelligent device, the two regulations overlap on purpose: the CRA wants secure updates, logging, and vulnerability handling; the AI Act wants logging, robustness, cybersecurity and an updatable model with documented behavior. Built separately, that’s two compliance programs. Built once, it’s one architecture: a root of trust, signed OTA for firmware and models, security and decision telemetry, and one documentation spine feeding both conformity files.
The dates interleave — Article 50 in August 2026, CRA reporting in September 2026, Annex III in December 2027, Annex I in August 2028. Teams sequencing a product through EVT, DVT and PVT should pin each regulatory artifact to a phase gate now, while the architecture is still cheap to change.

What should device teams do this quarter?

  • Inventory your AI features against the table above. One afternoon. Every feature gets a route and a date.
  • Fix Article 50 items before 2 August 2026. Disclosure at first interaction in the onboarding flow; machine-readable marking on generated output; deepfake labels where relevant.
  • Don’t stand down on high-risk work. Use the bought time to design in logging, oversight and data governance — retrofit economics are as brutal here as in security.
  • Unify with your CRA program. Same telemetry, same update path, same documentation spine, one owner.
The fines get the headlines, but as with the CRA, the sharper lever is market access: an EU order that can’t ship is a supply-chain event, not a legal one.
The delay bought time for paperwork, not for architecture.

The bottom line

  • The delay is real — Annex III to December 2027, Annex I embedded AI to August 2028 — but Article 50 transparency still applies from 2 August 2026, and it touches any device that talks or generates.
  • Disclosure and marking are product-design work: onboarding flows, UI states, output pipelines. Terms-and-conditions compliance is explicitly not compliance.
  • High-risk readiness is an evidence trail that accumulates during development. Teams that pin AI Act artifacts to phase gates now will clear 2027–2028 without a re-architecture.
Engineering guidance, not legal advice — deadline facts verified July 2026. If your roadmap puts an intelligent device into the EU market, start with a discovery & feasibility phase — we’ll map your features to their regulatory routes while the architecture can still absorb them cheaply.

Frequently asked questions

When does the EU AI Act apply to my product?

In stages. Prohibitions have applied since February 2025 and GPAI rules since August 2025. Article 50 transparency applies from 2 August 2026. High-risk obligations were delayed by the Digital Omnibus: Annex III systems to 2 December 2027, and AI embedded in regulated products (Annex I) to 2 August 2028.

Did the EU delay the AI Act?

Partly. The late-2025 Digital Omnibus pushed high-risk deadlines to December 2027 (Annex III) and August 2028 (Annex I product-embedded AI). It did not delay Article 50: chatbot disclosure, machine-readable marking of generative output, and deepfake labeling still apply from 2 August 2026.

Does my device’s voice assistant need an AI disclosure?

If it interacts directly with people, yes — from 2 August 2026 users must learn they’re dealing with AI at first interaction, accessibly. Commission guidance says terms-and-conditions mentions, watermarks alone, and even the name “assistant” are insufficient; visible notices and audio cues are the recommended pattern.

What makes a device high-risk under the AI Act?

Two routes: the AI is a safety component of a product under EU harmonised legislation — machinery, medical devices, radio equipment, toys, vehicles (Annex I, due August 2028) — or it serves an Annex III use-case such as biometrics, critical infrastructure or employment screening (due December 2027).

What are the penalties under the EU AI Act?

Up to €35 million or 7% of worldwide annual turnover for prohibited practices; up to €15 million or 3% for most other violations, including Article 50 transparency and high-risk obligations; and up to €7.5 million or 1% for supplying misleading information to authorities.

If the product has to ship, talk to the team that builds for that outcome.

Senior engineer on the first call. NDA before technical detail. References available under NDA after qualification. Or start with a fixed-fee feasibility study.