Lesson 1 of 5

The wrong unit of study

Somewhere in your organization right now, someone is planning around "the EU AI Act deadline" as if it's a single date on a single calendar. It isn't. In June 2026, the European Parliament and Council approved a Digital Omnibus package that pushed back a large chunk of the Act's requirements — and if the only thing you absorbed from that news cycle was "AI Act delayed," you're now carrying a dangerous half-truth into your compliance planning.

The danger isn't that you'll do too much. It's that you'll relax about the wrong things. Two obligation clusters that affect a huge share of teams building on top of AI — transparency disclosures under Article 50, and provider duties for general-purpose AI models under Chapter V — were explicitly left untouched by that delay. One of them has already been binding law for a year. This lesson exists to draw that line precisely, because getting it wrong in either direction costs you: panic about rules that don't apply yet, or blindness to ones that already do.

Scope

Why "the EU AI Act" is the wrong unit of study

The Act isn't one deadline — it's a staggered rollout spread across different chapters, each governing a different regulated actor, each with its own applicability date. Providers of high-risk systems answer to one set of rules and one timeline. Providers of general-purpose AI models answer to another, under a different chapter, on a different clock. Providers and deployers of systems that trigger transparency obligations — chatbots, deepfake generators, emotion-recognition tools — answer to yet a third.

Treating the Act as a monolith is exactly what produces the two failure modes you see in the wild: teams panicking about requirements that don't apply to them for another eighteen months, and teams tuning out obligations that are already live because "the Act got delayed" became the whole story. This course narrows deliberately to the two clusters most engineering teams building on foundation models or shipping AI-facing features actually need to act on soon — Article 50 transparency obligations, and GPAI provider obligations under Chapter V. Everything else in the Act, including the high-profile high-risk-system rules, is out of scope here on purpose.

The Digital Omnibus

What actually got delayed

The Digital Omnibus deferred the Annex III high-risk-system obligations — CE marking, conformity assessment, risk-management-system requirements for systems classified high-risk, things like hiring tools, credit scoring, and medical device software. Those requirements were originally set to apply from 2 August 2026. The Omnibus pushed that to 2 December 2027 for standalone high-risk systems, and 2 August 2028 for high-risk systems embedded in products already regulated under other EU law.

That's a real, substantial delay, and it's the headline most 2026 coverage led with. It's also the reason a lot of compliance content written before June 2026 is now quietly wrong: anything that still cites "2 August 2026" as the date high-risk obligations bind is describing a rule that no longer applies on that date. If you're auditing older internal documentation or a vendor's compliance claims, that's the first thing worth checking.

What Didn't Move

What did not move

The Digital Omnibus explicitly left two things alone. Article 50 transparency obligations still apply from 2 August 2026, with one narrow exception covered below. GPAI provider obligations under Chapter V — Articles 51 through 56 — have already been in force since 2 August 2025. That second point is worth sitting with: for most GPAI providers, this isn't a future deadline you're planning toward. It's a present obligation you may already be out of compliance with.

This is the single most valuable distinction in this course. Whoever conflates "the AI Act got delayed" with "Article 50 and GPAI got delayed" is simply wrong, and that conflation shows up often enough in circulating 2026 compliance content that correcting it earns a full lesson on its own. The delay was real, significant, and narrower than its headline suggested.

The One Grace Period

The one real grace period that does exist

Article 50 generally applies from 2 August 2026 — full stop, for most of its sub-obligations. But Article 50(2) specifically, the duty to mark AI-generated content as machine-readable and detectable, carries a narrow grace period to 2 December 2026, and only for AI systems that were already placed on the market before 2 August 2026. Content generated before the August date doesn't need retroactive labeling either. Every other Article 50 sub-obligation — identity disclosure, biometric-categorization notice, deepfake disclosure — has no grace period at all. Full applicability lands 2 August 2026, same day as everything else.

The catch: the GPAI applicability mechanic has two dates, not one, and it's easy to compress them into a false single deadline. GPAI provider obligations — documentation, training-data summaries, copyright policy — have applied since 2 August 2025. The Commission's own enforcement and fining power against GPAI providers, under Article 101, only becomes applicable 2 August 2026 — a genuine one-year gap between duty and enforceability. It's easy to state this sloppily as "GPAI compliance starts in 2026," which understates that the underlying duty has already existed for a year.

Two clocks, not one

Hold two facts at once: the highest-profile part of the AI Act, the high-risk-system rules under Annex III, moved out to late 2027 and 2028. But Article 50 transparency and GPAI provider obligations did not move — one is fully live from August 2026 with a narrow four-month carve-out for one sub-obligation, and the other has been binding law since August 2025. Neither of those facts is safe to round off.

In the next lesson, we'll get specific about the first of those two clusters — Article 50's disclosure obligations — starting with the requirement that shapes the most product surface area: telling people they're talking to an AI in the first place.

Introduction
0:00
9:00