YARD Law Co. · Reviewed 19 August 2026 · YARD Law Legal Team
The obligations for high-risk AI systems were due to bite on 2 August 2026. Six days before that date, Regulation (EU) 2026/1744 postponed them. That is not the news that matters for most Bulgarian firms, however - because another part of the Regulation arrived exactly on schedule and is now enforceable.
The Regulation, known as the Digital Omnibus for artificial intelligence, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.
Two groups of obligations were deferred:
Annex III covers uses that look entirely ordinary. Recruitment is among them. If you use AI to screen CVs or to score candidates, you are operating in a sensitive area regardless of the size of your firm. The heavy obligations on that front genuinely have slipped. But the postponement moves the deadline, not the responsibility, and supervisory authorities name this very area among the first they intend to watch.
This is the more important part, and it gets missed because the July headlines were all about the delay.
The Article 50 transparency obligations apply from 2 August 2026. Chatbots must identify themselves as machines to the people they talk to. Deepfake-type content must be labelled as artificially generated or manipulated. The European Commission published its guidelines on the interpretation of Article 50 on 20 July 2026, less than two weeks before the deadline, accompanied by a Code of Practice on the marking and labelling of AI-generated content.
The obligations on providers of general-purpose AI models have applied since 2 August 2025, including the copyright policy and the training-data summary. What is new from 2 August 2026 is that the Commission now has powers to impose penalties.
The Article 5 prohibitions have applied since 2 February 2025, as has the AI literacy duty under Article 4.
The practical consequence: from 2 August 2026, breaches of the transparency requirements in force and of the general-purpose model obligations can be penalised, not merely noted.
Yes, but a partial one, and the distinction matters.
Article 50(2) requires providers of generative systems to embed machine-readable marking in synthetic text, audio, images and video - a technical signal allowing specialised software to establish reliably that content was created or substantially modified by AI.
For systems placed on the market before 2 August 2026, that specific obligation applies from 2 December 2026. For systems placed on the market after that date there is no grace period at all. In practice the transitional window covers almost every service in use today.
The reprieve is narrow in two further senses. It covers only the technical embedding by the provider - visible labelling and the disclosure duties are not deferred. And content generated before 2 August 2026 is not subject to retroactive marking, though the Commission encourages applying it backwards where that is practicable.
As a deployer you do not owe the embedding of a watermark. But nor should you strip embedded signals out of content you publish.
Regulation (EU) 2026/1744 does not only postpone. It widens the list of prohibited practices under Article 5 with effect from 2 December 2026, adding AI systems for creating non-consensual intimate content - so-called "nudify" applications - and for generating child sexual abuse material.
It also provides reliefs for small mid-cap enterprises, defined as companies with up to 750 employees, and a strengthened role for the European AI Office in relation to systems built on general-purpose models.
Picture a law firm or an accountancy practice of fifteen people. Nobody there develops an AI system. But half the team uses generative tools every day - for summaries, draft letters, research.
Such a business barely touches the postponed high-risk rules. It falls squarely within Article 4, because its people use AI in their daily work. The AI literacy duty has not been deferred and does not depend on the size of the firm.
If the firm runs a client-facing chatbot, it also falls within Article 50 from 2 August 2026. If it publishes generated content, it owes labelling under the same article.
Postponing the high-risk obligations gives time to prepare to those who genuinely fall within Annex III - in recruitment, for example. It does not give grounds to postpone the subject.
Here the position is less settled than at European level, and that should be said plainly.
The Regulation applies directly - being a regulation, it needs no transposition. Enforcement, however, is shared between the European Commission and the national supervisory authorities designated by the Member States. At European level, oversight of general-purpose models sits with the AI Office within the Commission.
The lead department for implementation in Bulgaria is the Ministry of e-Government. The Ministry's position is that supervision of high-risk systems should be assigned to existing specialised regulators rather than by creating new administrative structures. An interdepartmental working group was tasked with proposing a national legal framework by 31 March 2026.
The national supervisory and penalty layer is still being built. Before assessing a specific exposure, check against primary sources which bodies have been designated as market surveillance authority and notifying authority within the meaning of Art. 70 of Regulation (EU) 2024/1689, and whether a national penalty regime under Art. 99 has been adopted. This matters in practice: the European rules apply directly, but national enforcement depends on those decisions.
Penalty levels at European level are tiered: the highest threshold applies to breaches of the Article 5 prohibitions, while breaches of the transparency duties and of the obligations on providers of general-purpose models fall into a lower band. The specific thresholds in Art. 99 should be taken from the primary text of the Regulation as currently in force.
Three concrete steps, in order of urgency:
Only for high-risk systems. For Annex III the deadline is 2 December 2027, and for high-risk AI embedded in products under Annex I it is 2 August 2028.
The Article 50 transparency obligations and the powers to impose penalties, including in relation to providers of general-purpose AI models.
For systems placed on the market before 2 August 2026, the machine-readable marking under Article 50(2) applies from 2 December 2026. For newer systems there is no grace period.
Yes. The AI literacy duty under Article 4 has applied since February 2025 and has not been postponed.
At European level, general-purpose models sit with the Commission's AI Office. The national framework is still being built, with the Ministry of e-Government as lead department.
See also our note on watermarking in AI-generated text and Article 50 and our overview of the AI Act, plus our IT and technology law practice.
This article states the position as at 19 August 2026, following the entry into force of Regulation (EU) 2026/1744. It is general information and does not constitute legal advice. Prepared by the legal team at YARD Law Co., a law firm based in Sofia, Bulgaria.
Need your AI Act exposure assessed?
Article 4 and team training, Article 50 and labelling, an Annex III review and your contracts with AI suppliers.