Disclosure is now a design requirement, not a courtesy
A chatbot bubble that doesn't say it's a bot. An AI-generated product photo with no marking anywhere near it. Neither of those used to be a legal question. As of August 2, 2026, in the EU, both of them are.
What actually changed on that date
The EU AI Act's high-risk system deadlines got pushed back this year, to December 2027 for most standalone systems and August 2028 for AI embedded in regulated products. That postponement is real, and it's easy to read as "the Act got weaker." It didn't, for the part that touches interface design directly.
Article 50 requires that a system built to interact directly with people ensure those people are told they're talking to an AI, that generative outputs be marked in a detectable, machine-readable format, and that deployers disclose deepfake content as artificially generated. Compliance trackers report those obligations, and national enforcement powers to act on them, became enforceable on August 2, 2026, untouched by the postponement.
Which parts moved and which did not:
| Obligation | Status |
|---|---|
| Article 5: subliminal manipulation and dark patterns banned | In force since 2 Feb 2025 |
| Article 50: chatbot disclosure, content marking, deepfake labeling | Enforceable from 2 Aug 2026 |
| High-risk standalone systems (Annex III) | Postponed to 2 Dec 2027 |
| AI embedded in regulated products | Postponed to 2 Aug 2028 |
The two rows that touch interface design directly are the two that did not move. The Act's separate ban on subliminal manipulation and dark patterns that exploit cognitive biases has been in force even longer, since February 2025.
Why this is a design problem and not just a legal one
A checkbox buried in a terms-of-service page technically discloses something. It doesn't disclose it in any sense a regulator focused on user-facing transparency is likely to accept, and it doesn't disclose it in any sense a real user actually absorbs either. The obligation is written as a legal requirement, but satisfying it well is a design problem: how do you make a disclosure both compliant and actually noticed, without turning every AI-touched surface into a wall of warning text nobody reads.
That's a genuinely hard design brief. Too subtle and it fails the spirit of the law, and arguably the letter of it. Too loud and heavy-handed, and you've traded a dark pattern of omission for a different dark pattern: disclosure theater designed to be skipped past rather than read.
The size of getting this wrong
The penalty ceilings attached to this enforcement window are not small: up to EUR 35 million or 7% of global annual turnover for the broadest violations, with a separate EUR 15 million or 3% ceiling specifically for general-purpose AI providers. Those numbers exist for the worst violations, not a badly-worded tooltip, but they establish that this category of compliance now has real financial stakes attached to it in a way it didn't twelve months ago.
The one-hour audit worth doing this week
Pick one surface in your product where a user interacts with an AI system, a chatbot, a generated image, a summarised result, and time how long it takes a first-time user to notice it's AI-generated at all. If the honest answer is "they wouldn't," that's the surface to redesign first, before a regulator or a user finds it for you. This is directional guidance, not legal advice: if you operate in the EU, the actual compliance requirement is worth a real conversation with counsel, not a blog post's best guess at the letter of Article 50.