
Most enterprise AI teams built their 2026 roadmap around one date. In late July, that date changed for the obligations that mattered most, but not for all of them. Here is what still applies today, and what your agent architecture needs regardless.
How the timeline actually shifted
On July 27, 2026, the EU’s Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force, three days after publication in the Official Journal. It amends the AI Act’s rollout schedule directly.
The Commission’s stated reason for the delay: national competent authorities, notified bodies, and the harmonized technical standards that high-risk conformity assessments depend on were not ready. The Omnibus also expanded the AI Office’s supervisory powers and added a prohibition on AI-generated non-consensual intimate imagery, but the headline change for enterprise agentic AI is the eighteen-month reprieve on Annex III.
What still applies on August 2, 2026
Article 50 was left untouched by the delay, and it reaches further than most enterprises assume. It applies regardless of whether the underlying system is classified as high-risk, which means it catches most agentic AI even where Annex III does not, at least not yet.
From today, any AI system designed to interact directly with a person, an HR agent answering benefits questions, a customer-service agent, an IT service-desk agent, must make clear the person is talking to an AI, unless that is obvious from context. Content the agent generates or edits, images, audio, video, text, must be marked as AI-generated. Systems using emotion recognition or biometric categorization must disclose it. The duty sits on both the provider that builds the system and the enterprise that deploys it, so a purchased agent does not shift the obligation away from the deploying organization.
Penalties for non-compliance reach €15 million or 3% of global annual turnover, the same ceiling that applies to the delayed high-risk provisions.
For agentic AI specifically: what’s live, what’s not
Article 50 transparency
- Disclosure that a person is interacting with an AI agent
- Labeling of AI-generated or AI-edited content the agent produces
- Disclosure for emotion-recognition or biometric features
- Full penalty exposure: up to €15M or 3% of global turnover
High-risk system obligations
- Conformity assessments and CE marking
- Annex IV technical documentation
- Quality management system requirements
- Mandatory human-oversight design controls
- EU database registration
Why this isn’t a stand-down
Eighteen months sounds like a comfortable runway, until it is measured against the sectors where enterprise agentic AI concentrates: employment, financial services, life sciences. Two things argue against treating this as time off.
First, Article 50 disclosure obligations are live today, not in 2027, for any agent that talks to a person. Most enterprise deployments already qualify.
Second, retrofitting audit trails, human-oversight checkpoints, and disclosure into an agent architecture that was not designed for them is a materially harder engineering problem than building those capabilities in from the start. The enterprises using this delay well are treating it as implementation time for Annex III, not a reason to pause governance work altogether.
Where OnClik fits
OnClik UAA’s orchestration layer, Cortex, treats disclosure, human-in-the-loop checkpoints, and audit logging as native parts of how every agent operates, not a compliance layer added afterward. That means the Article 50 obligations in force today are already accounted for in how agents identify themselves and log their actions, and the Annex III groundwork due in December 2027 is largely in place rather than starting from a blank page.
Get an Article 50 readiness check
We’ll map your current agent estate against what’s live today and what Annex III will require in December 2027.
Book a demo


