The AI Act Duties That Reach a Deployer on 2 August 2026
On 2 August 2026 the AI Act’s transparency rules start to apply. There are four of them. Two sit with whoever built the system and put it on the market. Two sit with whoever deploys it, and no procurement clause moves them. The high-risk regime that has filled the coverage since 29 June was postponed to December 2027, and most companies of this size were never inside it.
Our read is that companies are panicking about the visible “generated with AI” label and what it does to their image, while the expensive exposure has been sitting quietly since 2 February 2025 inside HR tools, workplace monitoring and processes where nobody has checked what the AI actually does. Emotion inference on employees is not a labelling problem. Article 5(1)(f) prohibits it outright, and it carries the 35 million euro or 7% tier under Article 99(3).
The Chatbot Notice Belongs to Your Vendor
Article 50 requires that a person is told when they are talking to a machine, that synthetic output is marked in machine-readable form, that people exposed to emotion recognition are informed, and that deepfakes are disclosed. The first two are the provider’s duty. Licence a chatbot from a vendor and both travel with the vendor.
The Omnibus the Council adopted on 29 June moves the Annex III high-risk regime to 2 December 2027. Annex III is HR screening, credit scoring, biometrics, critical infrastructure. A 200-person company that uses AI to draft emails and answer support tickets was never in it, so a sixteen-month reprieve from a regime you never triggered is not news you can use.
The Omnibus is also not law yet. It was signed on 8 July as LEX 00030/2026, was still not in the Official Journal on 14 July, and enters into force on the third day after publication. It has to be printed by 30 July in order to move 2 August. If it misses, 2 August stands, and there is nothing to do about that except watch it.
Articles 4 and 5 are the uncomfortable ones. They have applied since February 2025 and they force you to open the inventory, the HR tools, the shadow AI and what employees actually do with it. Everyone is talking about the future deadline because nobody wants to admit they are already late on the current one.
Emotion Inference on Staff Carries the 35 Million Euro Tier
Two of Article 50’s four duties land on the deployer. A third obligation reaches you from outside Article 50 entirely, and that is the expensive one.
Emotion inference aimed at your own staff has been prohibited outright since 2 February 2025 under Article 5(1)(f), and it sits in the same fine bracket as social scoring, at 35 million euro or 7% of worldwide turnover under Article 99(3). Nobody bought it under that name. It arrives as a sentiment feature bolted onto an HR platform or a call quality tool, switched on by default, and the invoice says productivity analytics.
The two Article 50 duties are narrower. Emotion recognition or biometric categorisation aimed at anyone else means you inform the people exposed to it, from 2 August. A deepfake image, audio or video that you publish means you disclose it, from 2 August.
The same sentiment feature is prohibited when it is pointed at your staff and merely disclosable when it is pointed at your customers. A call centre tool that scores the caller and the agent in the same recording is where that line gets tested, and nobody has tested it yet.
AI-drafted marketing copy, support replies, internal documents and blog posts reviewed by a person carry no disclosure duty at all. The text obligation reaches publications on matters of public interest, and human editorial review exempts even those. An AI policy that says only that the company labels its AI outputs has covered the duty that was never yours and missed the two that are. We took all four apart in AI Act transparency requirements.
The Value Chain Cap Is Real. It Arrives in 2028, Not for This Autumn’s Spreadsheet.
If your company has 1,000 employees or fewer and sits outside CSRD scope, you are getting a legal right to refuse most of the sustainability spreadsheet your customer sends you. You do not get it this year.
On 3 July the Commission adopted revised sustainability reporting standards and a voluntary standard for smaller companies that carries the cap. A company inside CSRD scope may not demand more sustainability information from a value chain company with 1,000 employees or fewer than the voluntary standard covers, and the cap reaches non-EU suppliers too.
Two limits before you cite it at a customer. It covers only the datapoints the voluntary standard marks as necessary, and it applies from financial years beginning on or after 1 January 2027. The delegated acts are still in a scrutiny window with Parliament and Council.
So the 200-line spreadsheet landing on your desk this autumn is not capped. The one landing in 2028 is. File the cap and answer the spreadsheet.
Eight Thousand Dutch Organisations Enter NIS2 Scope on 15 August
The Cyberbeveiligingswet passed on 7 July, takes effect on 15 August 2026 and pulls around 8,000 organisations into scope, and the national penalties arrive with it. Article 34 requires member states to provide floors of at least 10 million euro or 2% of worldwide turnover for essential entities and at least 7 million or 1.4% for important ones. What no member state has produced yet is a confirmed corporate fine, which is where our EU enforcement tracker still shows a zero.
A day later the Commission referred four member states to the Court of Justice for failing to notify transposition, twenty months after the 17 October 2024 deadline, and asked for a lump sum and daily penalties. Referrals for non-notification are usually withdrawn once the member state passes the law, so this reads as a schedule rather than an enforcement action. We covered it in the NIS2 referral.
Safe to ignore (Apple, AMLA)
Apple lost its gatekeeper challenge at the General Court on 8 July and the numbers in the coverage are large enough to look like news. The DMA binds seven designated gatekeepers across 23 core platform services and none of them is you.
AMLA delivered part of its technical standards in early July, the FIU cooperation formats on 3 July and the sanctions RTS on 8 July. They bind obliged entities, mostly finance and crypto, and they apply from 10 July 2027. If the AML file was not yours a fortnight ago, it is not yours now.
Coming up
30 July. The last day the Digital Omnibus on AI can appear in the Official Journal and be in force on 2 August. Everything postponed depends on it.
2 August. The three deployer duties above apply, and the Commission gains full enforcement powers over general-purpose AI models.
5 August. The EDPB consultation closes on the standard template for breach notification under Article 33 GDPR. If you have ever fought that form at hour 60 of a 72-hour clock, this is the fortnight to say so.
15 August. The Cyberbeveiligingswet takes effect in the Netherlands.
The EU Compliance Deadline Tracker carries every date in this issue and marks the ones still conditional on publication.
RegDossier
Making EU compliance almost enjoyable. Almost.
EU regulatory updates in your inbox every two weeks. Free.
Get the next briefing