2 December 2026: the EU AI Act deadline most companies have not noticed
The coverage of 2 August 2026 was thorough: enforcement began, transparency duties landed, the AI Office got its fining powers. What got much less attention is that the Digital Omnibus also put two separate things on 2 December 2026 — one of them a deadline that a large number of companies are currently on the wrong side of without knowing it.
Both are in the text of Regulation (EU) 2026/1744. Neither featured in most of the August coverage, and AI Act reference pages that have not yet folded in the Omnibus amendments still display the pre-Omnibus text.
This is an information service to help you plan, not legal advice. For the obligations tied to your own AI use, see which apply to your company.
What lands on 2 December 2026
| What | Where it comes from | Who it reaches |
|---|---|---|
| Article 50(2) marking duty for pre-existing generative AI systems | New Article 111(4) | Providers of systems generating synthetic audio, image, video or text placed on the market before 2 August 2026 |
| Two new prohibitions | New Article 5(1)(ba) and (bb), with Article 5(1a) and (1b) | Providers and deployers of AI systems capable of generating the specified material |
The grace period nobody mentioned
Here is the provision, inserted into Article 111 by the Omnibus:
"Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026 shall take the necessary steps in order to comply with Article 50(2) by 2 December 2026."
Read that carefully, because it cuts both ways.
The good news: if your generative AI product was already on the market before 2 August 2026, you were not in breach of the Article 50(2) marking obligation on 2 August. You have until 2 December.
The bad news: most reporting flattened Article 50 into "applies from 2 August 2026." Teams that read it that way either believe they are already in breach when they are not, or — more dangerously — assumed the whole of Article 50 was covered by some general delay and have not started. There is no general delay. This transitional period is narrow: it covers Article 50(2) only, for pre-existing systems only.
Everything else in Article 50 applied on 2 August 2026 with no transition. That includes the Article 50(1) duty to inform people they are interacting with an AI system — the chatbot disclosure that most companies actually trip over. See what Article 50 requires for the full set.
What Article 50(2) asks for
It is a provider-side technical duty: outputs of systems generating synthetic audio, image, video or text must be marked in a machine-readable format and detectable as artificially generated or manipulated. Watermarking, metadata, cryptographic provenance signals — the Regulation does not mandate a specific technique.
The Commission published a voluntary Code of Practice on marking and labelling of AI-generated content in June 2026 to support this. Signing it is a route to demonstrating compliance; not signing means demonstrating equivalence yourself to a market surveillance authority. Article 50(7) — reworded by the Omnibus, which dropped the Commission’s power to formally approve the code — keeps the Commission’s long-standing backstop: if it deems the code of practice inadequate, it "may adopt an implementing act specifying common rules for the implementation of those obligations."
If you build generative AI and have not yet decided your marking approach, that is the thing to resolve this quarter — not next.
The two new prohibitions
The Omnibus inserted two new points into the Article 5 prohibited-practices list. One concerns non-consensual sexual imagery of identifiable real people; the other, child sexual abuse material:
- Point (ba) covers systems generating or manipulating "realistic images, videos, audio or similar material of an identifiable natural person's intimate parts, or of an identifiable natural person engaged in sexually explicit activities, without that person's freely-given, specific, informed, unambiguous and explicit consent for that generation or manipulation."
- Point (bb) covers systems generating or manipulating material or a performance within the meaning of Article 2, points (c) and (e), of Directive 2011/93/EU — the child sexual abuse material directive — subject to a "without right" defence under national law.
The threshold conditions matter, and they are the part general coverage omits. New Article 5(1a) narrows when the prohibition bites:
For placing on the market or putting into service, a system is prohibited only where either generating such material is the intended purpose of the system, or the system's "design, training, architecture, capabilities or user-facing functionalities make that generation or manipulation a reasonably foreseeable and reproducible outcome, without requiring significant technical modification" and the system lacks "reasonable and adequate technical safety measures and other safeguards to reliably prevent" it, accounting for foreseeable misuse and correcting reported misuse.
For use, the prohibition bites only where the deployer uses the system for that purpose.
Article 5(1b) adds that manipulation which "does not increase the exposure of any depicted intimate parts or alter the nature of any depicted sexually explicit activities" does not count as manipulation for point (ba).
Why this reaches more companies than it first appears. The second limb of the test is not aimed only at purpose-built tools. A general-purpose image or video generator can fall inside it if the output is a reasonably foreseeable and reproducible result and the safeguards are inadequate. In practice, that turns "do we have effective, maintained, tested guardrails, and do we act on abuse reports?" into a question with a prohibition attached — and Article 5 breaches carry the Act's highest penalty tier. See the fine structure.
If you operate a generative image, video or audio model with open-ended prompting, treat safeguard adequacy as a documented engineering obligation before December, not a policy statement.
Two dates, one calendar
| Date | What applies |
|---|---|
| 2 Feb 2025 | Original Article 5 prohibitions; Article 4 AI literacy |
| 2 Aug 2025 | GPAI model obligations |
| 2 Aug 2026 | General application; Article 50 transparency (except the 50(2) transition); enforcement and fining powers |
| 2 Dec 2026 | Article 50(2) marking for pre-existing generative systems; new Article 5(1)(ba) and (bb) prohibitions |
| 2 Dec 2027 | High-risk obligations, Annex III systems |
| 2 Aug 2028 | High-risk obligations, Annex I embedded systems |
| 2 Aug 2030 | Legacy high-risk systems used by public authorities |
The pattern worth internalising: the Omnibus did not simply push the AI Act back. It split the calendar — deferring the high-risk stack by more than a year while adding new near-term obligations that did not exist in the original text. A company tracking only the original deadlines is now wrong in both directions. For the full sequence, see the AI Act timeline.
What to do before December
- Determine whether your generative systems predate 2 August 2026. That single fact decides whether you are inside the transitional period or should already be marking.
- Pick and implement a marking method for Article 50(2). Machine-readable and detectable. Decide on the Code of Practice deliberately — signing or not signing is a tracked decision either way.
- If you run open-ended image, video or audio generation, document your safeguards. The Article 5(1a) test turns on foreseeability, reproducibility and the adequacy of prevention — all of which are evidenced, not asserted.
- Build an abuse-report response path and record that it works. The test explicitly references correcting "observed or reported misuse."
- Re-read Article 5 and Article 50 in the amended text, not on pages that still show the 2024 version.
To see which obligations and which dates apply to your own systems, answer a few questions about your AI use. To be told when a deadline moves or new guidance lands, join the waitlist.
The official text is Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. This article is an information service to help you orient — it is not legal advice.
Frequently asked questions
What happens on 2 December 2026 under the EU AI Act?
Two things. First, the transitional period ends for providers of AI systems generating synthetic audio, image, video or text that were already on the market before 2 August 2026 — they must comply with the Article 50(2) marking obligation by 2 December 2026. Second, two new prohibitions inserted into Article 5 by the Digital Omnibus take effect, covering AI systems that generate non-consensual intimate imagery of identifiable people and AI systems that generate child sexual abuse material.
Does my existing chatbot or image generator get extra time?
Only for the Article 50(2) marking obligation, and only if it was placed on the market before 2 August 2026. New Article 111(4) gives those providers until 2 December 2026 to comply. Systems placed on the market on or after 2 August 2026 had no grace period. The other Article 50 duties, including the Article 50(1) duty to tell people they are interacting with an AI system, applied from 2 August 2026 regardless.
What does Article 50(2) actually require?
Providers of AI systems generating synthetic audio, image, video or text content must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. It is a technical marking duty on the provider, distinct from the deployer-facing labelling duties elsewhere in Article 50.
Were the new prohibitions delayed, or are they in force now?
They are not yet in force. The Digital Omnibus amended Article 113 so that the new Article 5(1) points (ba) and (bb), together with the qualifying provisions in Article 5(1a) and (1b), apply from 2 December 2026 — unlike the original Article 5 prohibitions, which have applied since 2 February 2025.
See which obligations apply to your company → or join the waitlist
This is an information service, not legal advice.