mtech labs ai
Eastbourne · UK
/ AI Consultancy / EU AI Act

The deadline moved. The other one didn't.

In the space of a week the EU deferred the AI Act's heaviest obligations to December 2027 — and brought its transparency rules into force. Most coverage reported the first half. Here's where the Act actually stands, and the short list of things a UK organisation should check now.

01/ The corrected timeline

What applies, and when.

The AI Omnibus — Regulation (EU) 2026/1744, in force 27 July 2026 — deferred the high-risk regime. It did not touch the transparency obligations, which have applied since 2 August 2026 and are being enforced by national authorities.

2 Feb 2025In forceProhibited-use provisions and the AI-literacy duty.
2 Aug 2025In forceObligations on providers of general-purpose AI models, plus governance and penalties.
2 Aug 2026In force — enforced nowArticle 50 transparency obligations. Explicitly not deferred by the Omnibus.
2 Dec 2027DeferredHigh-risk obligations for standalone Annex III systems. Moved from August 2026.
2 Aug 2028DeferredHigh-risk obligations for AI embedded in regulated products (Annex I).

Penalties for breaching the transparency obligations run to €15 million or 3% of worldwide annual turnover, whichever is higher.

02/ Article 50 — the part that applies now

If a person meets your AI, tell them.

The transparency obligations are far more widely applicable than the high-risk rules ever were. Annex III catches recruitment, credit scoring, education and essential services. Article 50 catches anyone who put a chatbot on their website.

Article 50

If it talks to people, say it's AI

Anyone interacting with an AI system must be told, clearly and distinguishably, at the latest at the first interaction. The only carve-out is where it would be obvious to a reasonably well-informed person. A chatbot with a human-sounding name is not obvious.
Article 50

If it generates content, mark it

Synthetic text, image, audio or video must be marked in a machine-readable format and detectable as artificially generated — so far as technically feasible, weighing cost and the state of the art. Document metadata is usually the proportionate answer; full provenance signing usually is not.
Article 50

If it reads emotion or biometrics, disclose it

Deployers of emotion-recognition or biometric-categorisation systems must inform the people exposed to them. Rarer, but absolute where it applies.
Article 50

Published text has an editorial carve-out

AI-generated text published to inform the public on matters of public interest must be disclosed — unless it went through human review and a person or organisation holds editorial responsibility. Most newsletters and blogs with a named editor sit inside that exemption.
03/ Does it reach a UK organisation?

Two questions, honestly answered.

Post-Brexit the UK is a third country. That doesn't exempt you, but the test is narrower and more mechanical than the headlines suggest.

  1. Do you place an AI system on the EU market?

    Selling it, licensing it, or otherwise making it available to users in the EU makes you a provider, whatever your postcode.

  2. Are the outputs used in the Union?

    The Act reaches third countries — which the UK now is — where the output produced by the system is used in the EU. This is the limb that catches people: it asks where the answers land, not where the company is registered.

  3. If both are no, you're out

    A genuinely UK-only, internal-only deployment is not the regulator's problem. Plenty of the firms who ask us this question get exactly that answer, and we'd rather say so than sell you a programme.

Worth knowing what is not caught: a system has to be an AI system. Our own schools assessment scores against a fixed rubric with no model involved anywhere — it is software, not AI, and the Act has nothing to say about it. Plenty of what gets called AI internally is the same. The inventory is worth doing precisely because it shrinks the problem.

04/ What we'd do about it

An afternoon, not a programme.

For the transparency obligations specifically, the work is small and the main risk is not knowing where your AI surfaces are.

  1. Inventory the places a person meets AI

    Website chat, phone triage, in-app assistants, automated replies. Usually shorter than feared and longer than expected.

  2. Check each one discloses, before first contact

    In the interface, in plain words — not in a privacy policy nobody opens.

  3. Mark what you generate

    Metadata on generated documents, images and audio where it's technically feasible. Proportionate, not gold-plated.

  4. Name an owner and a review date

    Models change, vendors change, and settings get flipped back. This is the step people skip.

We ran exactly this over our own estate and found a gap in our own chatbot. That's the honest argument for doing it: it catches ordinary, well-meaning setups, not just careless ones. If it's useful, the wider regime work sits in compliance and regulatory alignment, and stays current through Continuous Compliance.

This page is a plain-English summary written by a technology firm, not legal advice. Whether the Act applies to a particular workload is a question for your own advisers — we’re happy to do the technical groundwork that makes their answer a short one.

/ Start a conversation

Not sure whether any of this reaches you?

A short scoping conversation usually settles it — including, often enough, telling you it doesn't apply and you can stop worrying about it.