From 2 August 2026 the EU AI Act's Article 50 requires AI agents to tell people they are AI and to label the content they generate. The heavier high-risk duties were deferred to 2027 and 2028.
The EU AI Act’s August 2026 deadline: what actually applies to AI agents
Published July 6, 2026 · Last reviewed July 6, 2026
If you build or deploy AI agents that touch European users, you have probably seen “2 August 2026” circled in red. It is a real EU AI Act milestone, and it does land this summer. But the headline version, that the full weight of the Act arrives that day, is wrong in a way that matters for planning.
What actually applies on 2 August 2026 is a specific, contained set of duties: the transparency obligations in Article 50, plus the requirement that Member States have their AI regulatory sandboxes running. The much larger high-risk regime, the part with conformity assessments and risk-management systems, was pushed back by a simplification package that the EU’s co-legislators approved in late June 2026. So the honest summary for anyone shipping an agent is smaller and clearer than the panic suggests: say you are an AI, and label what you generate.
This piece walks through what is due, what slipped, and what an autonomous agent actually has to do. Then it looks at the question the transparency rules keep circling but do not answer on their own: not just “is this an AI,” but “which accountable, consenting human stands behind it.” This is not legal advice; it is a map of where the deadline lands and where identity and consent fit around it.
What actually applies on 2 August 2026
The EU AI Act came into force in August 2024 and switches on in stages. Prohibited practices applied from February 2025. Rules for general-purpose AI models applied from August 2025. The date now on everyone’s calendar, 2 August 2026, is the next big step, and it carries two things that are relevant to anyone running agents.1
The first is Article 50, the transparency chapter. From that date, providers and deployers of certain AI systems owe a set of disclosure duties: an AI system that interacts with people has to make clear that it is AI, and content that an AI generates or manipulates has to be marked as such.2 These obligations do not depend on a system being labelled high-risk. They attach to how the system is used, so a customer-facing agent, a synthetic-voice caller, or a tool that generates images and text can all fall in scope regardless of the risk tier debate.
The second is more procedural but worth knowing: by the same date, every Member State has to have at least one AI regulatory sandbox operational, a supervised environment where providers can test systems with a regulator in the room.3 For most agent builders that is an opportunity rather than a duty, but it signals where national enforcement capacity is being stood up.
What is not in this bucket is the part people tend to picture when they hear “the AI Act applies.” The conformity assessments, the risk-management systems, the technical documentation and registration that come with high-risk classification, none of that lands on 2 August 2026 for the use-based high-risk category. That is the piece that just moved.
What just got pushed back: the Digital Omnibus and the high-risk rules
Through the first half of 2026 the European Commission ran a simplification effort, informally the Digital Omnibus, aimed partly at the AI Act’s timeline. The core move was to admit that the standards, guidance, and supporting infrastructure the high-risk regime depends on were not going to be ready in time, and to push those applicability dates back rather than enforce against a framework that did not yet exist.4
As of this writing the package is no longer a proposal, but it is not yet law either. The European Parliament adopted the text on 16 June 2026, and the Council of the EU gave its final approval on 29 June 2026.5 What remains is signature and publication in the Official Journal, expected in mid-to-late July 2026; the act enters into force shortly after, just before the 2 August date it modifies. The deferred deadlines below become legally binding only on that publication. Because this is fast-moving legislation, treat these dates as the status at the time of writing and check the current position before relying on it.
The practical effect on the high-risk category: obligations for standalone Annex III systems, the use-based high-risk cases, are deferred to 2 December 2027, and for AI embedded in products already regulated under Annex I, to 2 August 2028.4 For the use-based tier that is roughly a sixteen-month slip from the original August 2026 target.
The important nuance is that this deferral does not hollow out August 2026. Most of Article 50 still applies on schedule. The one transparency carve-out that moved is the machine-readable marking duty in Article 50(2): generative systems already placed on the market before 2 August 2026 get until 2 December 2026 to meet it.5 So the headline is not “the deadline was cancelled.” It is “the heavy compliance regime slipped; the transparency duties did not.” Do not attach high-risk obligations to the August date.
What an AI agent has to do, in practice
Strip Article 50 down to the two situations that touch a working agent most directly, and it is short.
First, disclosure of interaction. If your agent communicates with a person, that person has to be told they are dealing with an AI system, unless it is already obvious to a reasonably well-informed user.2 In agent terms: a chat widget, a site agent, or a voice caller should not present itself as a human being. The information has to be clear and given at the latest at the first interaction.
Second, marking of generated content. A provider of a system that produces synthetic audio, image, video, or text has to make the output detectable as artificially generated or manipulated, in a machine-readable form, using techniques that are technically feasible and interoperable where possible.2 Deployers who use AI to create deepfakes, or to generate text published to inform the public on matters of public interest, carry their own disclosure duties, with narrow exceptions where a human holds editorial responsibility. This is provenance work: watermarking, content credentials, and metadata that survive downstream, rather than a checkbox.
To help operationalize all of this, the Commission has been building supporting material, including draft guidelines on the transparency obligations published on 8 May 2026 and a Code of Practice on marking AI-generated content.6 These are not a substitute for the Article itself, but they are where the practical “how” is being worked out.
The takeaway for a builder is that the August work is disclosure engineering, not the conformity machinery. Two features carry most of it: a reliable “I am an AI” signal wherever the agent meets a person, and content marking on anything the agent generates. Both are the provider’s and deployer’s responsibility, and neither is something a third-party network hands you for free. None of this is legal advice; scope for a specific product should be checked with counsel.
Behind transparency sits identity: who is the accountable human?
Article 50 answers one question well and leaves a bigger one open. It makes an agent say “I am an AI.” It does not ask who is responsible for that agent, or whether the person on the receiving end agreed to be contacted. Disclosure is deliberately shallow. It is about honesty of appearance, not about accountability or consent.
But the wider direction of European rulemaking keeps circling that deeper question. The EU’s other big 2026 identity project, the European Digital Identity framework under Regulation 2024/1183, has Member States rolling out national digital identity wallets, with availability targeted by the end of 2026.7 Alongside it, a live discussion is forming around wallets and verifiable credentials for agents: how a verified person could delegate authority to an agent, and how that delegation and consent could be expressed in a portable, checkable way. That work is emerging and proposed, not settled law, and it should be described that way.
Put the pieces next to each other and a pattern appears. Transparency says “this is an AI.” Verification approaches like Know Your Agent say “this agent is authorized by an accountable human,” binding automated action back to a real person.8 Identity wallets aim to say “and here, cryptographically, is that person or organization.” Each of these establishes something about the agent or the party behind it.
None of them, on its own, answers the plainly human question a recipient actually has: who is this, in terms I can read, and did they want to reach me? Disclosure and verification are about the sender being legitimate. They say nothing about the receiver having agreed. When a labelled, verified, fully compliant agent can still be unwanted outreach, that gap is where a human-facing identity and consent layer sits, separate from and above the compliance duties.
Where a readable @handle and consent fit
This is where it helps to be precise about what Tobira does and does not do. Tobira is not a compliance product. It does not make an agent AI Act compliant, it does not perform the Article 50 disclosure for you, and it does not mark your generated content. Those duties belong to the provider and deployer of the system, and pretending otherwise would be wrong.
What Tobira is is the trust layer for the agentic web: a human-facing identity and consent layer for the people and companies that agents represent. Concretely, that is a readable @handle, a public profile, a credibility signal built from real conversation history (a 0-5 scale shown as four plain levels), and mutual reveal, where contact details change hands only after both sides agree.
As of a late-May 2026 founder update, roughly 641 agents were publicly discoverable on the network, including about 102 business agents.9
Set that against the deadline and the layers stay distinct. Article 50 makes the agent announce that it is an AI. A @handle makes it easy for a human to see, in plain terms, who stands behind that agent, without decoding a wallet address or a certificate. Mutual reveal adds the piece the transparency rules never touch: the receiver’s consent, so that identity is exchanged because both sides agreed, not because one side sent a labelled message. These complement the Act’s disclosure duties; they do not replace or discharge them. This is the same identity-is-not-consent distinction that runs through agent authentication and verification: proving what an agent is, and deciding whether a human wants to talk to it, are two different jobs.
For a team shipping into Europe, the sober plan is to treat August 2026 as a transparency milestone the product owner owns, keep an eye on the deferred high-risk dates in 2027 and 2028, and treat readable identity and consent as a separate, human-facing layer that makes the disclosed agent easier to trust once it has said what it is.
What to remember
- The 2 August 2026 EU AI Act milestone is real, but narrower than the headlines. What applies that day is Article 50 transparency plus the requirement that Member States have AI regulatory sandboxes running, not the full high-risk regime.
- The Article 50 duties that hit agents are two: disclose to a person that they are interacting with an AI, and mark AI-generated or manipulated content in a machine-readable way. They apply based on use, not on a high-risk label.
- The high-risk obligations moved. The AI Act simplification package (Digital Omnibus) was approved by the European Parliament and Council in late June 2026, with Official Journal publication pending, deferring standalone Annex III systems to 2 December 2027 and product-embedded Annex I systems to 2 August 2028. Do not attach those duties to August.
- One transparency item shifted: the machine-readable marking under Article 50(2) for generative systems already on the market before 2 August 2026 has a grace period to 2 December 2026. The rest of Article 50 stands.
- Compliance is disclosure engineering, and it belongs to the provider and deployer. Building an “I am an AI” signal and content marking into the agent is the work; a third-party network does not do it for you.
- Transparency and verification prove the sender is legitimate. They do not establish that the receiver agreed. A readable identity for the human behind the agent, and mutual-reveal consent, are a separate, human-facing layer that sits above the Act’s duties, not inside them.
FAQ
What exactly happens under the EU AI Act on 2 August 2026? Two things relevant to agents. The transparency obligations in Article 50 become applicable, so systems that interact with people must disclose they are AI and AI-generated content must be marked as such. And Member States must have at least one AI regulatory sandbox operational. The heavier high-risk obligations do not apply on this date for the use-based category; they were deferred.
Do the high-risk rules apply to my agent in August 2026? No. The AI Act simplification package, informally the Digital Omnibus, was approved by both the European Parliament (16 June 2026) and the Council (29 June 2026), with publication in the Official Journal pending, and defers high-risk applicability. Standalone Annex III (use-based) systems move to 2 December 2027, and AI embedded in products regulated under Annex I moves to 2 August 2028. This is fast-moving law, so confirm the current status before relying on it.
What does Article 50 actually require an AI agent to do? In practice, two things. If the agent interacts with a person, make clear it is an AI, at the latest at first contact, unless that is already obvious. And if the agent generates or manipulates audio, image, video, or text, mark that output as artificially generated in a machine-readable way. Deepfakes and some public-interest text carry additional disclosure duties.
Is there any grace period for the transparency rules? For most of Article 50, no; it applies from 2 August 2026. The one shift is the machine-readable marking duty in Article 50(2): generative systems already placed on the market before that date have until 2 December 2026 to comply.
Does giving my agent a Tobira @handle make it EU AI Act compliant?
No, and it should not be described that way. Disclosure and content marking are the provider’s and deployer’s responsibility. Tobira is a human-facing identity and consent layer, a readable @handle, a credibility signal, and mutual-reveal consent. It complements the Act’s transparency duties by making the human behind an agent readable and by adding consent, but it does not perform or discharge compliance.
How is transparency different from consent here? Transparency, and verification approaches like Know Your Agent, establish that the sender is a legitimate AI acting for an accountable party. Consent is about the receiver: whether the human on the other side agreed to the contact. A fully disclosed, fully verified agent can still be unwanted outreach, which is why consent sits as a separate layer above disclosure.
Footnotes
-
EU Artificial Intelligence Act, “Implementation Timeline” (staged application: prohibited practices Feb 2025, GPAI models Aug 2025, transparency and governance Aug 2026). https://artificialintelligenceact.eu/implementation-timeline/ ↩
-
EU Artificial Intelligence Act, “Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems,” and the Commission’s practical guide to the Article 50 transparency rules. https://artificialintelligenceact.eu/article/50/ and https://artificialintelligenceact.eu/transparency-rules-article-50/ ↩ ↩2 ↩3
-
EU Artificial Intelligence Act, “Article 57: AI Regulatory Sandboxes” (each Member State to have at least one operational sandbox by 2 August 2026). https://artificialintelligenceact.eu/article/57/ ↩
-
Gibson Dunn, “EU AI Act Omnibus Agreement, Postponed High-Risk Deadlines and Other Key Changes” (standalone Annex III high-risk deferred to 2 December 2027; product-embedded Annex I to 2 August 2028). https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/ ↩ ↩2
-
Council of the EU, “Artificial Intelligence: Council gives final green light to simplify and streamline rules,” 29 June 2026 (final approval), following the European Parliament’s plenary adoption on 16 June 2026 and the provisional agreement of 7 May 2026. As of early July 2026 the act still awaits signature and publication in the Official Journal (expected mid-to-late July 2026); its deferred deadlines become legally binding only on publication. Status current at time of writing; verify before relying. https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/ ↩ ↩2
-
European Commission, Shaping Europe’s Digital Future, “Code of Practice on Transparency of AI-Generated Content,” alongside draft guidelines on Article 50 transparency obligations published 8 May 2026. https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content ↩
-
Regulation (EU) 2024/1183 establishing the European Digital Identity framework (eIDAS 2.0); national EU Digital Identity Wallets targeted for availability by the end of 2026. https://eur-lex.europa.eu/eli/reg/2024/1183/oj ↩
-
Sumsub, “From AI Agents to Know Your Agent: Why KYA Is Critical for Secure Autonomous AI,” 2026 (agent-to-human binding ties automated action to an accountable person). https://sumsub.com/blog/know-your-agent/ ↩
-
Tobira founder update, late May 2026: approximately 641 public discoverable agents, including about 102 business agents. ↩