EU AI Act: a delay does not remove responsibilities
Article 50 has applied since August 2026. Wipro’s Ivana Bartoletti explains how later high-risk deadlines can help build lasting AI governance.
On 2 August 2026, Article 50 of the European Union’s AI Act brought stronger transparency requirements for the use of artificial intelligence into force. At the same time, many applications classified as high-risk will only become subject to stricter regulation under the framework in December 2027 or August 2028.Companies could treat the extra time as a breather, or use the 16 months they have gained to build governance that is sustainable in the long term.
Key takeaways
- Transparency applies now.Since 2 August 2026, Article 50 has required information about AI systems; synthetic content and deepfakes need machine-readable labelling. Existing systems have until 2 December 2026 to implement this labelling.
- High-risk obligations come later.They only take effect in December 2027 or August 2028; the necessary governance structures cannot be established overnight.
- Resilience is the realistic goal.The ability to switch technologies and providers, sovereign-by-design and building employees’ skills deliver more in the long term than simply managing deadlines.
Related:Kubermatic CEO Scheele: Run AI models like software / Google hands over Sovereign Cloud to Thales
What already applies: the most recent changes have chiefly introduced stronger transparency obligations. Users interacting with an AI-based system must be clearly informed that they are doing so. The same applies to synthetically generated content and its more extreme forms, such as deepfakes.
The regulation also requires AI-generated formats to carry appropriate machine-readable labelling to prevent consumers from being deceived. Systems already on the market before 2 August 2026 have an extended deadline of 2 December 2026 for this requirement. Clear advance notification is also essential when emotion recognition or biometric categorisation methods are used.
For functions beyond this, longer preparation periods certainly do not remove responsibility. The necessary structures take time and cannot be established overnight.
- Users must know when they are interacting with an AI system
- Synthetic content and deepfakes need machine-readable labelling
- Emotion recognition and biometric categorisation must be indicated in advance
- High-risk obligations only take effect in December 2027 or August 2028
- Many organisations lack an inventory of all AI use cases across the value chain
- Human-in-the-loop roles and questions for suppliers need binding answers
Laying the right foundations
The fact that AI, including AI agents, is already used by a large share of companies shows that robust safeguards cannot wait until 2027. Internally, the first step should therefore be an honest assessment of the applications and contexts in which Article 50 applies, and whether the obligations are being met. In many organisations, this first requires a consolidated overview of every use case arising across the value chain.
Once the inventory is in place, a tiered approach based on the risk profiles of different use cases can follow. Particular attention should go to cases where user data is especially sensitive, regulatory requirements are very strict or subject to tight deadlines, and operational needs are high. AI technologies also require a thorough assessment of their potential impact on the privacy of the people concerned. Another decisive point, often a source of failure, is the seamless integration of new or external technologies into existing workflows, including a useful and practical definition of human-in-the-loop functions.
Nevertheless, on closer examination and with sufficient preparation, the additional challenges of the AI Act appear manageable, especially for companies that have consistently given existing regulations such as the GDPR the attention they deserve. Proper implementation of existing data-protection rules provides a solid foundation for meeting the changed requirements too.
Governance as a lasting capability
Transparency is not a tick on a checklist, but a governance decision. Such decisions are most effective when woven into processes as early as possible. An uncoordinated approach with little guidance demonstrated in practice will not stop employees from using AI. Instead, an informal AI culture of practices and habits will emerge that becomes difficult to shape and bring together later.
Companies should think in terms of building long-term capabilities, rather than deadlines. Legal requirements will continue to evolve, probably no more slowly than they do today. What will endure are investments in employees’ AI skills, enabling them to respond flexibly and resiliently to emerging requirements and other external challenges.
This gives companies an opportunity to rethink digital sovereignty. Full sovereignty over computing capacity remains out of reach for most, but organisations can strengthen their resilience by avoiding excessive dependence on individual providers. They should seek genuine alternatives: the ability to switch technologies, providers or approaches without losing control of critical processes. A sovereign-by-design approach should therefore be a fixed part of every AI governance strategy. Sovereignty must not be an afterthought once technological decisions have been made. It needs to inform decisions about data architecture, provider selection and risk management from the outset.
This tension is directly visible in the German cloud market. Initiatives such as Gaia-X, SAP Sovereign Cloud and Deutsche Telekom/T-Systems’ sovereign cloud offering illustrate the point: even flagship sovereign-cloud projects rely substantially on hyperscaler infrastructure in practice. This is not a failed ambition; it reflects the same reality seen in state-funded AI programmes in the Gulf and in Europe’s cloud strategy. Complete independence is rarely achievable without qualification. Resilience, rather than absolute sovereignty, is therefore the realistic and defensible goal.
Responsibility certainly does not stop at the company gate. Organisations using third-party models and training data, for example, should still consider their origins and possible biases. To determine whether a model is reliable in a particular situation, whether its results can be adequately questioned during interaction, or whether an automated process is biased against particular social groups, users must ask their suppliers the right questions. How were the datasets collected? How are changes to services and models communicated? Is incident response in place for unexpected events? What approach to transparency does the provider take?
Users also directly influence how data is reused internally. This includes data maintenance, deriving synthetic data, appropriate technical safeguards and use for training purposes in accordance with strict privacy principles.
Europe’s window for action
The debate about artificial intelligence can be expected to continue developing considerably, including on regulation. This makes it essential for companies to work on long-term resilience and build capabilities critical to their future. Otherwise, they will constantly be driven by new legal deadlines and other external influences instead of helping to shape them. The extra time the EU AI Act gives organisations using AI must not be confused with these applications becoming less relevant. The relaxed deadline is chiefly meant to let them understand and address the full picture of its complexity, rather than simply act later.
More than ever, the key today will be corporate sovereignty and the ability to adapt to new market conditions in the shortest possible time. The organisations that use this window to build resilience rather than wait will be the ones shaping the next regulatory cycle instead of falling behind it.
An internationally recognised thought leader in privacy, AI governance and responsible technology, Bartoletti serves as an expert for the Council of Europe and co-authored a landmark study on the impact of artificial intelligence on gender equality.
Frequently Asked Questions
What is the EU AI Act?
The EU AI Act is the European Union’s first comprehensive framework for artificial intelligence. It classifies AI applications by risk and imposes obligations on providers and deployers that take effect through transition periods extending to 2027 and 2028.
Which AI obligations have applied since August 2026?
Article 50 introduces transparency obligations: users must know when they are interacting with an AI system. Synthetic content and deepfakes must be labelled as such and in machine-readable form. People affected by emotion recognition and biometric categorisation must be informed in advance. AI systems already on the market before 2 August 2026 have an extended deadline of 2 December 2026 for machine-readable labelling.
When do high-risk obligations take effect?
For many high-risk applications, the EU extended the deadlines to December 2027 or August 2028. The time is intended for establishing application inventories, tiered risk assessments and privacy assessments.
What does sovereign-by-design mean?
Sovereignty is considered from the outset in decisions about data architecture, provider selection and risk management. The aim is to have genuine alternatives: switching technologies and providers without losing control of critical processes.
Editor's Picks
cloudmagazinFrank Karlitschek: Ten Years of Nextcloud Without Venture CapitalcloudmagazinDownloadable Doesn’t Mean DeployablecloudmagazinConfidential Computing: Protecting Data During ProcessingMore from the MBF Media Network
MyBusinessFutureThe AI oversight in Germany now has an addressDigital ChiefsAI Governance 2026: Only 14% Have Clarified Who Is ResponsibleSecurityTodayA CISO does not take responsibility away from company leadershipImage source: AI-generated (August 2026)
Translated from the German original using artificial intelligence. The German version is authoritative.

