From the engineering desk
EU AI Act Deadlines for Device Makers: What Applies in 2026
High-risk obligations slipped to 2027–2028 — but Article 50 transparency lands 2 August 2026. Which deadline applies to your product, and what to build.
By Axon Labs Engineering

The EU just rewrote its AI Act calendar. In late 2025, the “Digital Omnibus” package pushed high-risk obligations back by more than a year — and a wave of headlines told device makers they could relax. They can’t. Article 50’s transparency rules still take effect on 2 August 2026, they apply to any product with a conversational or generative AI feature sold into the EU, and the engineering they assume can’t be retrofitted in a sprint. Here’s the calendar that actually applies to your device.
Key takeaways
- The Digital Omnibus moved Annex III high-risk obligations to 2 December 2027 and product-embedded (Annex I) AI to 2 August 2028 — but Article 50 transparency was not delayed and applies from 2 August 2026.
- From August 2026, devices with AI features that interact with people must disclose it at first interaction — burying it in the terms, or naming the feature “assistant,” doesn’t count. Generative outputs need machine-readable marking.
- Penalties scale to €35M or 7% of global turnover. Combined with the Cyber Resilience Act’s September 2026 reporting start, EU market access now assumes an architecture: disclosure, marking, logging, and secure updates.
What did the Digital Omnibus actually change?
What still lands on 2 August 2026?
- AI-interaction disclosure. Systems that interact directly with people must make clear they’re AI — at first interaction, in an accessible way. Per the Commission’s draft guidance, a line in the terms and conditions is not sufficient, watermarks alone are not sufficient, and even naming the feature “assistant” falls short (Greenberg Traurig). Think visible notices, audio cues, persistent indicators.
- Machine-readable marking of generative output. AI-generated audio, image, video and text must be marked as synthetic in a machine-readable, detectable format — watermarking, metadata, provenance signals.
- Emotion recognition and biometric categorisation. People exposed to these systems must be informed. Wearables inferring stress or mood sit close to this line.
- Deepfake labeling. Artificially generated or manipulated content depicting real people or events must be disclosed.
The full timeline, post-delay
Is your device high-risk under the AI Act?
| Your device’s AI feature | Route | Deadline |
|---|---|---|
| Voice or chat interface users talk to | Article 50 disclosure | 2 Aug 2026 |
| Generates audio, image, video or text | Article 50 marking | 2 Aug 2026 |
| Emotion recognition on users | Article 50 disclosure — and likely Annex III | 2 Aug 2026 / 2 Dec 2027 |
| Standalone Annex III use-case (biometrics, infrastructure…) | High-risk, Annex III | 2 Dec 2027 |
| AI as safety component in a regulated product (MDR, machinery, RED…) | High-risk, Annex I | 2 Aug 2028 |
| Social scoring, manipulative techniques, untargeted face scraping | Prohibited | Banned since Feb 2025 |
What does high-risk actually require — in engineering terms?
- Risk management → a living hazard analysis for the AI behavior, not a one-time document.
- Data governance → dataset provenance, representativeness checks, and versioning for whatever trained the shipped model.
- Automatic logging → the device records what the model decided and when — which presupposes storage, telemetry and privacy design.
- Human oversight → an override or review path that actually works at product speed.
- Accuracy & robustness → measured performance thresholds on target hardware, monitored for drift in the field — model validation as a phase gate, as we argued in the edge AI development guide.
Plan the AI Act and CRA as one architecture
What should device teams do this quarter?
- Inventory your AI features against the table above. One afternoon. Every feature gets a route and a date.
- Fix Article 50 items before 2 August 2026. Disclosure at first interaction in the onboarding flow; machine-readable marking on generated output; deepfake labels where relevant.
- Don’t stand down on high-risk work. Use the bought time to design in logging, oversight and data governance — retrofit economics are as brutal here as in security.
- Unify with your CRA program. Same telemetry, same update path, same documentation spine, one owner.
The delay bought time for paperwork, not for architecture.
The bottom line
- The delay is real — Annex III to December 2027, Annex I embedded AI to August 2028 — but Article 50 transparency still applies from 2 August 2026, and it touches any device that talks or generates.
- Disclosure and marking are product-design work: onboarding flows, UI states, output pipelines. Terms-and-conditions compliance is explicitly not compliance.
- High-risk readiness is an evidence trail that accumulates during development. Teams that pin AI Act artifacts to phase gates now will clear 2027–2028 without a re-architecture.
Frequently asked questions
When does the EU AI Act apply to my product?
Did the EU delay the AI Act?
Does my device’s voice assistant need an AI disclosure?
What makes a device high-risk under the AI Act?
What are the penalties under the EU AI Act?
Sources
- European Commission — AI Act — regulatory framework for AI (Regulation (EU) 2024/1689) · verified 19 July 2026
- AI Act Explorer — Article 50: Transparency Obligations for Providers and Deployers · verified 19 July 2026
- AI Act Explorer — The EU AI Act’s Transparency Rules: A Practical Guide to Article 50 · verified 19 July 2026
- Travers Smith — EU agrees to delay key AI Act compliance deadlines · verified 19 July 2026
- Cloud Security Alliance — EU AI Act High-Risk Deadline Pushed to December 2027 (Omnibus VII note) · verified 19 July 2026
- Greenberg Traurig — Deepfakes, Chatbots, AI-Generated Text: Commission Details Transparency Obligations · verified 19 July 2026
- European Commission — Code of Practice on marking and labelling of AI-generated content · verified 19 July 2026
- Technology.org — EU AI Act: What Actually Applies on 2 August 2026 · verified 19 July 2026
- Certivo — EU AI Act August 2026: Compliance Guide for Manufacturers Integrating AI Into Products · verified 19 July 2026
- Holland & Knight — U.S. Companies Face EU AI Act’s Possible August 2026 Compliance Deadline · verified 19 July 2026
If the product has to ship, talk to the team that builds for that outcome.
Senior engineer on the first call. NDA before technical detail. References available under NDA after qualification. Or start with a fixed-fee feasibility study.