On 27 July 2026, the Digital Omnibus on AI entered into force and pushed the EU AI Act's high-risk deadlines out by up to two years. Most product teams read that as a reprieve. It is not. The AI Act Article 50 transparency obligations still went live on 2 August 2026.
Those duties cover the AI features Proptech and Fintech teams ship most: chatbots, AI-drafted text, generated media, and emotion inference. If your product talks to users through a model, you now carry disclosure duties, and they are enforceable.
What the Digital Omnibus actually changed
The Omnibus, formally Regulation (EU) 2026/1744, amends the AI Act to buy time where standardisation is lagging. CEN and CENELEC have not finished the harmonised standards that high-risk compliance depends on, so the co-legislators moved those dates. The deferral is real, but it is narrow.
| Obligation | Was | Now |
|---|---|---|
| Stand-alone high-risk systems (Annex III) | 2 Aug 2026 | 2 Dec 2027 |
| High-risk AI in regulated products (Annex I) | 2 Aug 2026 | 2 Aug 2028 |
| Article 50 transparency duties | 2 Aug 2026 | 2 Aug 2026 (unchanged) |
| Enforcement and sanctions regime | 2 Aug 2026 | 2 Aug 2026 (unchanged) |
Two things did not move. The transparency duties apply now, and the sanctions regime that gives them teeth is active. Plan your engineering quarters around that fact, not around the deferred dates.
There is also a strategic reading. Teams that treat 2026 as a quiet year will restart compliance work in mid-2027 with the same staffing crunch everyone else faces. Teams that ship the transparency layer now bank evidence and reuse most of it for the high-risk work later.
One more thing the headlines buried. Obligations for general-purpose AI models have been live since August 2025, so your model vendors are already inside the regime. That matters for procurement: ask every vendor for their transparency documentation now, because you will need it to build your own disclosures.
Could the dates move again? Possibly: the Omnibus itself cites standardisation delays, and CEN and CENELEC delivery has slipped before. But the transparency duties were left untouched precisely because they need no harmonised standards to implement. Betting your roadmap on a second deferral is a gamble with poor odds.
External source
Digital Omnibus Regulation 2026/1744 Enters Into Force, Extending AI Act Compliance TimelinesLicentium
AI Act Article 50 transparency obligations, decoded
Article 50 has four practical duties. Each one maps to a concrete UI or pipeline change, not a legal memo.
- Tell users they are talking to a machine. Any AI system that interacts with people directly, such as a support chatbot or voice agent, must disclose that it is AI, unless that is obvious from the context.
- Mark synthetic content as machine-readable. Text, audio, image, and video generated or manipulated by AI must carry machine-readable marking, such as metadata or watermarking, where technically feasible.
- Label deepfakes visibly. Content that impersonates real people, places, or events must carry a clear, visible disclosure at the point of viewing.
- Disclose emotion recognition. Systems that infer emotions or biometric categories must inform the people exposed to them.
Watch the provider-versus-deployer split. Model providers must build the marking capability into their systems. Deployers, meaning you, must surface the disclosures to end users. If you fine-tune a foundation model or white-label it under your own brand, you can carry both roles at once.
The "obvious from the context" carve-out is doing heavy lifting in legal debates right now. Our reading: a chat window labeled "AI assistant" qualifies, but a WhatsApp flow that mimics a human agent does not. When in doubt, disclose. The cost of an extra label is trivial next to a supervisory complaint.
A fifth duty hides in the deployer obligations and catches publishers off guard. If you use AI to generate text that you publish to inform the public on matters of public interest, you must disclose that the content was AI-generated. For most product teams this is irrelevant, but for Fintech firms publishing market commentary or Proptech firms publishing area reports, it lands directly on the content pipeline.
Where Article 50 bites in Proptech and Fintech
The obligations sound abstract until you walk your own product surface. Four patterns keep showing up in the Proptech and Fintech products we audit.
- Tenant and buyer chatbots. Rental platforms and mortgage brokers run LLM agents on chat, email, and WhatsApp. Every one of those channels needs its own disclosure; a label on the website widget does not cover the WhatsApp flow.
- AI-drafted listing descriptions. If a model writes or rewrites property descriptions, the output counts as synthetic text. Portals that ingest your feed will increasingly expect machine-readable marking in the payload, not just a footnote on your site.
- Generated valuation and affordability summaries. Automated valuation model outputs turned into customer-facing PDFs are AI-generated documents. Marking them in metadata is cheap; retrofitting it across a document pipeline is not.
- Deepfake-adjacent marketing. Staged renovation renders and virtual staging that depict real properties sit close to the manipulation duty. A visible "virtually staged" label keeps you clear of it.
A concrete example: when we rebuilt the tenant-support copilot for a Dutch rental platform managing roughly 14,000 units, the disclosure work touched 11 distinct touchpoints. The chat widget and email auto-replies were the obvious ones. The WhatsApp flows and the maintenance-ticket summaries tenants receive after each interaction were not. The engineering took two weeks; the inventory of where the model actually speaks to users took longer than the labeling itself.
The Dutch market adds its own wrinkle. The ACM coordinates AI Act supervision in the Netherlands, and tenant-facing automation in housing is already a politically sensitive category after years of scrutiny on automated rent pricing. A rental platform that cannot show its disclosure evidence is one journalist's question away from a bad week.
A two-week Article 50 implementation plan
Here is the plan we run with client teams at SelectCursor, condensed. It assumes a mid-size product with one or two AI features in production.
- Days 1-3: inventory. List every AI touchpoint where a model interacts with a user or produces user-facing content. Record your role per touchpoint: provider, deployer, or both.
- Days 4-8: disclosures. Add standard wording at the start of every AI interaction: chat headers, voice greetings, email footers. Put an approval step for AI text into your publishing workflow.
- Days 9-10: marking. Turn on machine-readable marking for generated text and media. For documents, embed it in PDF or feed metadata. Store one export per content type as proof.
- Days 11-14: test and evidence. Run test cases across service, marketing, and sales flows. Log each system with its owner, label location, and approval timestamp.
| Duty | Touchpoint | Effort | Evidence |
|---|---|---|---|
| Chatbot disclosure | Support widget, WhatsApp | 2-3 days | Screenshot plus config log |
| Synthetic text marking | Listing feed generator | 3-5 days | Metadata sample export |
| Deepfake labeling | Marketing video pipeline | 2-4 days | Label in player UI |
| Emotion recognition | Not deployed | 0 days | Written policy note |
Budget 10 to 15 engineering days for a mid-size product, based on our delivery experience rather than any official benchmark. The long pole is never the label component. It is discovering that your support tool, CRM plug-in, and marketing automation all quietly added AI features this year.
Staffing is simple. One frontend engineer owns the disclosure surfaces, one backend engineer owns marking in the content and document pipelines, and a part-time compliance reviewer signs off the wording. If you run a lean team, this is a two-person job for a fortnight, not a programme.
Put numbers on it. At blended senior rates in the EU, 12 engineering days lands between 8,000 and 11,000 euros depending on whether you staff it in-house or bring in external engineers. That is an estimate from our project work, not an official figure. Compare it with the 15 million euro ceiling on a transparency fine and the business case writes itself.
Enforcement: fines and what auditors will ask for
Non-compliance with Article 50 sits in the middle tier of the AI Act penalty structure: fines of up to 15 million euros or 3 percent of global annual turnover, whichever is higher. Market surveillance authorities in each member state handle enforcement, and the sanctions regime started on 2 August 2026 alongside the transparency duties.
Expect auditors to ask for artifacts, not intentions. Keep an inventory of AI systems with owners, screenshots or recordings of disclosures in place, sample exports showing machine-readable marking, and the approval log for AI-generated content. If you cannot produce these in a week, you do not have them.
Do not assume enforcement starts with a regulator inspection. It usually starts with a complaint. A tenant who realises the "agent" on WhatsApp was a model, or a competitor who notices your unlabeled generated listings, can trigger the file that lands on a supervisor's desk.
One practical tip from our audits: store the evidence where it is produced. Screenshots belong in the release ticket, metadata exports in the pipeline artifact store, approval logs in the publishing tool. A compliance folder assembled the night before an audit reads exactly like what it is.
The Omnibus moved the hard deadlines. It did not move the visible ones. Article 50 is the part of the AI Act your users can actually see, and the part a regulator can check without opening your codebase.
Frequently asked questions
Does the AI Act apply to my chatbot if it uses a third-party model? Yes. Article 50 binds the deployer who puts the system in front of users, regardless of whose model runs underneath. If your customers interact with an AI through your product, the disclosure duty is yours. The model provider handles marking capability at the model level; you handle what users see.
What counts as machine-readable marking under Article 50? Metadata embedded in the file or feed payload, watermarking, or comparable techniques that let other systems detect AI-generated content automatically. A visible disclaimer alone does not satisfy the marking duty for synthetic content. Use the marking your model or media pipeline already supports before building custom schemes.
Did the Digital Omnibus delay the Article 50 transparency rules? No. The Omnibus deferred stand-alone high-risk obligations to December 2027 and embedded high-risk obligations to August 2028. The transparency duties and the sanctions regime remained fixed at 2 August 2026 and are in force now.
What are the fines for missing AI disclosure? Up to 15 million euros or 3 percent of global annual turnover, whichever is higher. That is the middle penalty tier. Prohibited-practice violations sit higher at 35 million euros or 7 percent, but transparency failures do not reach that band.
Do internal AI tools need Article 50 disclosures? Generally no, when only your own staff interact with the system inside your organisation. The duties target natural persons exposed to the system in a customer-facing context. The moment an internal tool's output reaches a customer, such as an AI-drafted email, the content-marking analysis applies again.
The bottom line
The AI Act Article 50 transparency obligations are live, enforceable, and cheap to satisfy if you move now. Inventory your AI touchpoints this week, ship disclosures and marking within two, and keep the evidence where an auditor can find it. The teams that treat this as a small engineering task will be done before summer ends. The ones that wait for the high-risk deadlines will discover those deadlines were never the urgent part.
If you need engineers who have already shipped disclosure and compliance flows under GDPR, DORA, and the AI Act, we can scope the work with you in a single call.
Written by Bart Korpershoek
Co-founder & Technical Lead
Part of the SelectCursor engineering team. We build lending platforms, property marketplaces, and fintech infrastructure for European companies.
Connect on LinkedInMore posts from our teamBuilding something similar?
Our team has shipped 50+ Proptech and Fintech platforms. Book a 25-minute call to discuss your architecture, team structure, or product roadmap.
Book a Call