August 2 Did Not Get Cancelled: What the Digital Omnibus Delayed and What Small US SaaS Companies Still Owe Under the EU AI Act
Executive Summary
- Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It delayed the high risk obligations of the EU AI Act. It did not delay the transparency obligations in Article 50.
- Article 50 still applies from 2 August 2026. If your product tells a user something that a machine generated, or talks to a person as though it were a person, you have work due in days, not years.
- The AI Act reaches companies with no European office. Article 2 covers providers who place AI systems on the Union market and providers located in a third country whose system output is used in the Union. There is no headcount or revenue threshold that exempts a small company.
- Breaches of Article 50 sit in the middle penalty tier under Article 99, which reaches up to 15 million euro or 3 percent of total worldwide annual turnover. For small and medium sized enterprises the Act caps the fine at whichever of those two figures is lower.
- What actually moved: standalone high risk systems under Annex III now apply from 2 December 2027, and AI embedded in regulated products under Annex I from 2 August 2028. Most small SaaS companies were never in that bucket anyway.
If you run a software company with European customers, you have probably read in the last few weeks that the EU AI Act got postponed. That reporting is accurate and it is also the most expensive half truth in the industry right now.
Something did get postponed, by a lot. But the piece of the AI Act that touches the largest number of small software companies was deliberately left alone, and it starts applying on 2 August 2026. This article explains exactly what moved, what did not, and what a company of thirty people with no compliance staff should do about it.
In this article
- What changed in the last four days
- Why “the AI Act got delayed” is the wrong takeaway for SaaS
- Does the AI Act apply to your 30 person software company
- Provider or deployer: the distinction that decides your obligations
- Article 50 read line by line
- What is due 2 August and what is due 2 December
- What actually moved, and what never moved at all
- Penalties, enforcement, and the small business cap
- The voluntary code of practice and whether to sign it
- A 30 day plan for a company with no compliance team
1. What changed in the last four days
On 24 July 2026, Regulation (EU) 2026/1744 was published in the Official Journal of the European Union. It entered into force on 27 July 2026, the third day after publication. Its formal title describes it as a regulation amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence. Everyone calls it the Digital Omnibus on AI.
Regulation (EU) 2024/1689 is the AI Act itself. The other two instruments are the basic aviation regulation and the machinery regulation, which matter to manufacturers rather than to software firms. The omnibus is the EU adjusting its own timeline because the harmonised standards and conformity assessment infrastructure the AI Act depends on were not ready.
The legislative path was quick by European standards. The European Parliament adopted the text on 16 June 2026 by 423 votes in favour, 57 against and 174 abstentions. The Council gave its final approval on 29 June 2026. The act was signed on 8 July 2026 and published sixteen days later.
The headline change is a delay to the high risk regime. The change that did not happen, and that most coverage skipped, is that the transparency obligations in Article 50 stayed exactly where they were.
2. Why “the AI Act got delayed” is the wrong takeaway for SaaS
The delay is real. Standalone high risk AI systems listed in Annex III, which had been due to comply on 2 August 2026, now have until 2 December 2027. AI systems embedded as safety components in products already covered by European product legislation, listed in Annex I, moved from 2 August 2027 to 2 August 2028.
Here is the problem with reading that as a reprieve. Annex III high risk is a specific list. It covers things like biometric identification, critical infrastructure, education and vocational training, employment and worker management, access to essential private and public services including credit scoring, law enforcement, migration, and the administration of justice. A twenty five person company selling project management software, a customer support platform, or a marketing analytics tool is almost never in that list.
What that same company almost certainly does have is a chatbot, an AI writing assistant, an automatic summary feature, or a support agent that drafts replies. Those are governed by Article 50, which is a transparency layer that applies regardless of risk classification. The omnibus left it untouched on purpose.
GOVERNANCE INSIGHT
The delay applied to the obligations you probably did not have. The deadline that stayed is the one you probably do.
The high risk regime is where the compliance cost is largest, which is why the postponement made headlines. Article 50 is where the compliance cost is smallest and the applicability is broadest. If your team read the news and stood down, you stood down from the wrong deadline.
3. Does the AI Act apply to your 30 person software company
Start with Article 2, which sets the scope. Article 2(1)(a) applies the regulation to providers placing on the market or putting into service AI systems, or placing general purpose AI models on the market, in the Union, and it says this applies irrespective of whether those providers are established or located within the Union or in a third country.
Article 2(1)(c) goes further. It applies the regulation to providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union. That is the provision that catches a company in Austin or Denver with no European entity, no European staff, and a handful of European customers.
Read those two subparagraphs again and notice what is missing. There is no revenue threshold. There is no employee count. There is no exemption for startups or for companies below a certain size. Size affects two things in the AI Act: it caps the fines, and it earns you some administrative simplification. It does not switch off the obligations.
The other threshold question is whether what you built counts as an AI system at all. Article 3(1) defines it as a machine based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment, and that infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions. A feature built on a large language model clears that definition comfortably. A deterministic rules engine generally does not.
4. Provider or deployer: the distinction that decides your obligations
Article 50 assigns different duties to providers than to deployers, so getting this classification right for each feature is the first real piece of work.
Under Article 3(3), a provider is a person or body that develops an AI system, or that has one developed, and places it on the market or puts it into service under its own name or trademark. Under Article 3(4), a deployer is a person or body using an AI system under its authority, outside of personal non professional activity.
The trap for software companies is the phrase “under its own name or trademark”. If you ship a support chatbot inside your product, you are the provider of that chatbot even though the underlying model belongs to OpenAI, Anthropic, Google, or whoever sits behind your API key. You did not train the model, but you placed the system on the market under your brand. Your customers, in turn, are deployers.
Most small software companies end up in both roles at once. You are a provider of the AI features inside your product, and you are a deployer of the AI tools your own team uses internally for support triage, sales research, or code review. The obligations differ, so inventory them separately.
5. Article 50 read line by line
Article 50 has four substantive duties plus two rules about how they are delivered. Most of the confusion in the market comes from people treating it as one undifferentiated “AI disclosure” requirement, when in fact each paragraph lands on a different party.
Article 50(1): tell people they are talking to a machine
Providers must ensure that AI systems intended to interact directly with natural persons are designed and developed so that the persons concerned are informed they are interacting with an AI system. The exemption is narrow: it does not apply where this is obvious from the point of view of a reasonably well informed, observant and circumspect natural person, taking into account the circumstances and context of use.
Do not lean too hard on the obviousness exemption. A widget labelled “Ask our assistant” in a corner of a help centre is arguably obvious. A support conversation that opens with a friendly first name and no indication that a model is generating the replies is not.
Article 50(2): mark synthetic output so machines can detect it
Providers of AI systems that generate synthetic audio, image, video or text must mark the outputs in a machine readable format and make them detectable as artificially generated or manipulated. The Act requires the technical solutions to be effective, interoperable, robust and reliable as far as this is technically feasible.
This is the paragraph that requires engineering work rather than copy changes. In practice it means provenance metadata, watermarking, or a comparable technique attached to generated output. Article 50(2) carves out systems performing an assistive function for standard editing, and systems that do not substantially alter the input data provided by the deployer or its semantics. Spell check is out of scope. A feature that drafts a whole customer email is not.
Two points of precision matter here. A visible label alone does not satisfy Article 50(2), because the obligation is to make the output detectable by a machine, so a badge in your interface saying “generated by AI” is a good practice that meets a different duty. And the standard of effective, interoperable, robust and reliable as far as this is technically feasible is still being worked out in practice. Until case law or formal guidance settles it, the code of practice discussed in section 9 is the clearest available statement of what regulators expect adequate marking to look like.
Article 50(3): emotion recognition and biometric categorisation
Deployers of an emotion recognition system or a biometric categorisation system must inform the natural persons exposed to it of the operation of the system, and must process personal data in line with European data protection law. Most business software will not touch this. If you have a sentiment feature that claims to infer emotional state from voice or video, look at it closely.
Article 50(4): deepfakes and published text
Deployers of an AI system that generates or manipulates image, audio or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated. There is a lighter disclosure route for evidently artistic, creative, satirical or fictional work.
The second half of Article 50(4) is the one that catches marketing teams. Deployers who use AI to generate or manipulate text that is published to inform the public on matters of public interest must disclose that the text was artificially generated. The exemption applies where the content has undergone human review or editorial control and a person holds editorial responsibility for the publication.
Article 50(5) and 50(6): how and when
Article 50(5) requires the information to be provided in a clear and distinguishable manner at the latest at the time of the first interaction or exposure, and to conform to applicable accessibility requirements. Article 50(6) confirms these duties sit on top of, not instead of, the requirements in Chapter III and other transparency obligations in European or national law.
6. What is due 2 August and what is due 2 December
The omnibus did make one concession inside Article 50. Machine readable marking under Article 50(2) gets a transitional period for systems that were already on the market before 2 August 2026, running to 2 December 2026. Everything else in Article 50 applies from 2 August 2026.
| Obligation | Who it lands on | Applies from |
|---|---|---|
| Article 50(1) disclosure that a user is interacting with an AI system | Provider | 2 August 2026 |
| Article 50(2) machine readable marking, systems placed on the market on or after 2 August 2026 | Provider | 2 August 2026 |
| Article 50(2) machine readable marking, systems already on the market before 2 August 2026 | Provider | 2 December 2026 |
| Article 50(3) notice for emotion recognition and biometric categorisation | Deployer | 2 August 2026 |
| Article 50(4) deepfake disclosure and public interest text disclosure | Deployer | 2 August 2026 |
| New prohibited practices added to Article 5, covering AI that generates child sexual abuse material or non consensual intimate content | Providers and deployers | 2 December 2026 |
The last row deserves a note even though it will not apply to most business software. Those two new prohibitions were inserted into the Article 5 list of prohibited practices rather than added as a transparency duty, which places them in the top penalty tier discussed in section 8 rather than the middle one.
Read the second and third rows together, because they decide how much time you actually have. If a generative feature is live in your product today, the marking obligation for it lands on 2 December 2026. If you ship a new generative feature next quarter, that feature has no transitional period at all.
7. What actually moved, and what never moved at all
Below is the practical view of the timeline after the omnibus. The first three rows are the changes. The last three are the dates that have been in force for months and that a lot of companies still have not addressed.
| Obligation | Old date | Date after the omnibus |
|---|---|---|
| Standalone high risk systems listed in Annex III | 2 August 2026 | 2 December 2027 |
| High risk AI embedded in products regulated under Annex I | 2 August 2027 | 2 August 2028 |
| National regulatory sandboxes to be established | 2 August 2026 | 2 August 2027 |
| Article 5 prohibited AI practices | 2 February 2025 | Unchanged, in force |
| General purpose AI model rules, governance, and penalties | 2 August 2025 | Unchanged, in force |
| Article 50 transparency obligations | 2 August 2026 | Unchanged, except 50(2) transition |
One more change is worth noting because it affects every operator. Article 4, the AI literacy duty, has been softened. The original text required providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among staff and others operating AI systems on their behalf. The amended version reframes that as a duty to support the development of AI literacy, which is an obligation of effort rather than a guaranteed outcome. The amended text applies from 27 July 2026.
Do not treat that as permission to skip training. AI literacy has been a live obligation since 2 February 2025, and the softened wording still expects you to do something and to be able to show it.
Getting your AI governance in order
Dynamic Comply helps small and medium sized businesses build a real AI governance foundation using the NIST AI RMF and ISO/IEC 42001, before regulation forces the issue.
8. Penalties, enforcement, and the small business cap
Article 99 sets three penalty tiers. The top tier, in Article 99(3), covers infringement of the Article 5 prohibited practices and reaches up to 35 million euro or 7 percent of total worldwide annual turnover for the preceding financial year, whichever is higher.
The middle tier in Article 99(4) covers most other operator obligations, and it explicitly includes the transparency obligations for providers and deployers under Article 50. That tier reaches up to 15 million euro or 3 percent of total worldwide annual turnover, whichever is higher. A third tier in Article 99(5) covers supplying incorrect, incomplete or misleading information to authorities and notified bodies, at up to 7.5 million euro or 1 percent.
Article 99(6) is the provision small companies should know by heart. For small and medium sized enterprises, including startups, each fine is capped at the percentage or the amount referred to in those paragraphs, whichever is lower. So the exposure for a small company is bounded by 3 percent of its turnover rather than by the headline figure of 15 million euro. That is meaningful relief. It is not immunity, and it does not cover the cost of a customer discovering the gap during procurement.
Enforcement is national rather than centralised for these obligations. Under Article 70, each Member State was required to establish or designate at least one notifying authority and at least one market surveillance authority by 2 August 2025, and to designate one of them as a single point of contact. The penalty provisions themselves have been applicable since 2 August 2025, so the enforcement machinery is already switched on and waiting for the substantive deadline to arrive.
GOVERNANCE INSIGHT
For most small SaaS companies the first cost of non compliance is commercial, not regulatory.
A national market surveillance authority is unlikely to open its enforcement campaign against a thirty person company. Your enterprise prospect’s procurement team, however, will ask how you comply with Article 50 during the next security review, and “we thought it got delayed” is not an answer that closes deals.
9. The voluntary code of practice and whether to sign it
On 10 June 2026 the European AI Office published the Code of Practice on Transparency of AI Generated Content, following a first draft issued on 17 December 2025. It gives providers and deployers of generative AI systems practical guidance on meeting the marking and labelling duties in Article 50(2) and the disclosure duties in Article 50(4).
Two things about it matter. First, adherence is voluntary. The code creates no obligations beyond the AI Act itself, and declining to sign it is not a breach of anything. Second, signing offers a streamlined way to demonstrate compliance with those specific obligations, which is worth something when a customer or an authority asks you to show your work. Signing is done through a signatory form authorised by a senior executive.
For a small software company the practical read is this. Follow the code as a technical specification whether or not you sign it, because it is the clearest available statement of what regulators consider adequate marking. Treat the signature itself as a commercial decision about how visible you want that commitment to be.
10. A 30 day plan for a company with no compliance team
You do not need a compliance department to be ready. You need someone who owns this, four weeks, and a written record at the end. Here is the sequence I would run with a client of this size.
Week one: inventory every AI touchpoint
List every feature in your product that uses a model, every AI tool your team uses internally, and every place AI generated text or media reaches a customer or the public. Include the marketing site, the help centre, the sales sequences, and the support macros. Most teams find twice as many touchpoints as they expected.
Week two: classify each touchpoint
For each item, record whether you are the provider or the deployer, whether the system interacts directly with a natural person, whether it generates synthetic content, and whether any European user could encounter its output. That last column is where the Article 2(1)(c) question gets answered concretely instead of theoretically.
Week three: ship the disclosures and start the marking work
The Article 50(1) work is usually small: interface copy, an onboarding message, a line in the chat header. Do it now, because it is cheap and the deadline is immediate. The Article 50(2) marking work is a real engineering task, so scope it this week and schedule it against the 2 December 2026 date for anything already live.
Week four: write it down
Produce a short internal record showing your inventory, your classification decisions and the reasoning behind them, the disclosures you shipped, and your marking roadmap with dates. Add whatever AI literacy activity you run for staff. This document is what you hand to an enterprise buyer, and it is the honest starting point for an ISO/IEC 42001 programme or a NIST AI RMF alignment later.
None of this is heavy. What makes it urgent is that the market spent July believing the deadline moved. The companies that read the omnibus carefully rather than reading the headlines have a genuine and temporary advantage in every procurement conversation they have this autumn.
Talk to Ross about your AI governance needs
Every business has different AI governance requirements. Let us talk about yours.
About the author
Ross J. is the founder of Dynamic Comply, an AI governance, compliance, and cybersecurity consulting firm based in Leesburg, Virginia. He brings more than 15 years of federal cybersecurity experience across the Department of State, the Department of Defense, and the Department of Homeland Security, and holds the CGRC certification along with credentials as a GSDC AI Compliance Lead Implementer and Auditor and Certified Ethical Hacker.
Related articles
- ISO/IEC 42001 Implementation for Sub 100 Person SaaS Companies: A Realistic Timeline and Cost Breakdown
- How to Answer Enterprise AI Questionnaires When You Are a 30 Person SaaS Company
- Model Cards and Transparency Documentation for Small AI Vendors: A Practical Template
- AI Vendor Management for Small SaaS Companies: Tracking OpenAI, Anthropic, and AWS Bedrock in Your Compliance Program
This article is provided for general informational purposes and reflects the state of the law as of July 2026. It is not legal advice. Regulations in this area are changing quickly, and guidance interpreting Regulation (EU) 2026/1744 is still developing. Confirm current requirements and consult qualified counsel before making decisions for your organization.