On 2 August 2026, the EU AI Act’s biggest compliance wave was supposed to arrive: the full high-risk regime for systems listed in Annex III. Plenty of vendor marketing still talks as if it did. It didn’t. Nine days before the deadline, the EU published the Digital Omnibus on AI in the Official Journal, deferring those obligations to December 2027 — while leaving the rules that actually bite AI sales agents fully in force. If your team runs AI agents that call, message or email EU prospects, this post separates what is binding law today from what has genuinely been pushed back.
The short answer (as at 8 August 2026): the EU AI Act’s Annex III high-risk obligations did not take effect on 2 August 2026. The Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July 2026 — deferred them to 2 December 2027 (and to 2 August 2028 for AI embedded in Annex I regulated products). What does apply to AI sales agents right now: Article 50 transparency (from 2 August 2026 — people interacting with an AI system must be informed, unless it’s obvious), the Article 4 AI literacy duty and the Article 5 prohibitions (both since 2 February 2025), and general-purpose AI model obligations (since 2 August 2025).
The deferral is law, not a proposal — here’s the paper trail
Because this is exactly the kind of claim that gets garbled in vendor blogs, here is the primary-source chain. The European Commission proposed the Digital Omnibus on AI on 19 November 2025. The final act — Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026, amending the AI Act (Regulation (EU) 2024/1689) and two related regulations — was published in the Official Journal of the European Union on 24 July 2026 and entered into force on 27 July 2026, the third day following publication. In other words, the deferral became binding law six days before the original 2 August 2026 deadline. There is no legal limbo here: the old date is off the books.
What the regulation actually moved:
- Annex III stand-alone high-risk systems (biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, justice): the classification and compliance obligations now apply from 2 December 2027 instead of 2 August 2026.
- Annex I product-embedded high-risk AI (AI safety components in regulated products such as machinery and medical devices): now 2 August 2028.
- A transitional window for content marking: providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to comply with the machine-readable marking duty in Article 50(2).
- A new prohibition on AI systems used to generate non-consensual intimate imagery or child sexual abuse material, applying from 2 December 2026.
Equally important is what the Omnibus did not touch: the Article 50 transparency obligations still applied from 2 August 2026 as originally scheduled, and the prohibitions, AI literacy duty and GPAI model obligations that were already in force stayed in force.
Obligation by obligation: original date, current date, who it hits
| Obligation | Original date | Date after Digital Omnibus | Who it hits in a sales-agent context | Status source |
|---|---|---|---|---|
| Prohibited practices (Art. 5) — e.g. manipulative or exploitative techniques | 2 Feb 2025 | Unchanged (in force) | Everyone deploying AI in the EU market | Reg. (EU) 2024/1689, Art. 113 |
| AI literacy duty (Art. 4) | 2 Feb 2025 | Unchanged (in force) | Providers and deployers — including sales teams operating AI agents | Reg. (EU) 2024/1689, Art. 113 |
| General-purpose AI model obligations | 2 Aug 2025 | Unchanged (in force) | Model providers (relevant to your vendor’s stack, not usually to you) | Reg. (EU) 2024/1689, Art. 113 |
| Transparency for AI interacting with people (Art. 50(1)) | 2 Aug 2026 | Unchanged — applies now | Providers of voice/chat sales agents; disclosure reaches every EU prospect conversation | Reg. (EU) 2026/1744 (not deferred) |
| Machine-readable marking of synthetic content (Art. 50(2)) | 2 Aug 2026 | Applies now; systems on market before 2 Aug 2026 have until 2 Dec 2026 | Providers of generative systems, incl. synthetic audio | Reg. (EU) 2026/1744 |
| Annex III high-risk regime (incl. employment/recruitment uses) | 2 Aug 2026 | 2 Dec 2027 | Recruitment screening and other Annex III uses — not typical sales outreach | Reg. (EU) 2026/1744 |
| Annex I product-embedded high-risk AI | 2 Aug 2026 / 2027 | 2 Aug 2028 | AI safety components in regulated products — rarely sales tech | Reg. (EU) 2026/1744 |
| New prohibition: non-consensual intimate imagery / CSAM generation | — (new) | 2 Dec 2026 | All providers and deployers | Reg. (EU) 2026/1744 |
What you must actually do today if your AI agents contact EU prospects
1. Disclose that it’s an AI — Article 50(1)
This is the provision written for AI sales agents. Providers must ensure that AI systems intended to interact directly with natural persons are designed so that those people are informed they are interacting with an AI system — “unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect”. A cold call from a voice agent, an SMS thread, a WhatsApp conversation: none of these can rely on “the prospect probably guessed”. The practical move is an explicit disclosure at the start of the interaction, which also happens to be where US regulators are heading with AI call disclosure — designing one honest opening line addresses the same expectation in more than one jurisdiction. Breaching Article 50 carries fines of up to €15 million or 3% of worldwide annual turnover under Article 99(4).
2. Mind the marking duty for synthetic audio — Article 50(2)
If your stack generates synthetic audio — cloned voices included — the provider of that system must mark outputs as artificially generated in a machine-readable format. The Omnibus gave systems already on the market before 2 August 2026 until 2 December 2026 to comply, so this duty may currently sit in its transitional window for existing systems. It is a provider obligation first, but deployers should know where their vendor stands on it.
3. Train your people — Article 4
The AI literacy duty has applied since 2 February 2025 and covers deployers, not just vendors: organisations must take measures to ensure, to their best extent, a sufficient level of AI literacy in staff operating AI systems. For a sales team, that means the people configuring campaigns, reviewing transcripts and handling escalations understand what the agent can and cannot do. Pairing literacy training with written guardrails for your autonomous agents and a clear human-in-the-loop escalation path is the most defensible way to evidence it.
4. Stay clear of the prohibitions — Article 5
In force since 2 February 2025, with penalties up to €35 million or 7% of worldwide turnover: no purposefully manipulative or deceptive techniques that materially distort behaviour, and no exploiting vulnerabilities of specific groups. High-pressure persuasion scripts aimed at vulnerable audiences are where sales automation could conceivably brush against this — a reason to review scripts, not just models.
Is your sales agent “high-risk”? Probably not — with one important exception
Annex III does not list sales or marketing outreach. It covers employment, education, credit and essential services, biometrics, law enforcement and similar domains. An AI agent that qualifies leads, books meetings and follows up with prospects is, on the face of it, not an Annex III system — which means the headline high-risk obligations were never the main event for sales outreach, deferred or not.
The exception worth a careful look is recruitment. Annex III point 4 expressly captures AI systems “intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications, and to evaluate candidates”. If your organisation uses AI agents for candidate outreach and screening, the use case — not the vendor’s product category — determines classification. Those obligations now arrive on 2 December 2027, which is preparation time, not exemption. Classification is fact-specific; get counsel’s view on your actual deployment rather than relying on any vendor’s characterisation, including ours.
Why “our AI is high-risk-compliant” vendor claims deserve scrutiny right now
A vendor claiming AI Act high-risk compliance in August 2026 is claiming conformity with obligations that are not yet applicable, against harmonised standards that the EU deferred the deadline partly because they weren’t ready. Treat the phrase as a marketing signal, not a legal one. Better questions to put to any vendor — Zian included — are factual:
- How does the agent disclose that it is an AI at the start of an interaction, per channel and per language?
- Is synthetic audio output marked in a machine-readable way, and what is the vendor’s Article 50(2) timeline?
- Where does the model run, and who can see the data? (For some teams, private model deployment on your own infrastructure simplifies the data-governance side of the conversation.)
- What human oversight and escalation controls exist, and can you evidence them in an ADM transparency statement?
Whether any given deployment satisfies Article 50 — or any other legal requirement — is a question for your counsel, not for a vendor’s marketing page. What a vendor can legitimately show you is features and configuration: disclosure lines in scripts, oversight hooks, deployment options, audit trails.
The calendar from here
- Now: Article 50 transparency, Article 4 literacy, Article 5 prohibitions, GPAI model obligations — all live.
- 2 December 2026: end of the Article 50(2) marking transition for pre-existing systems; new prohibition on non-consensual intimate imagery and CSAM generation applies.
- 2 December 2027: Annex III high-risk regime applies — recruitment-screening deployments should be well into gap analysis by mid-2027.
- 2 August 2028: Annex I product-embedded high-risk obligations apply.
FAQ
Did the EU AI Act’s high-risk obligations take effect on 2 August 2026?
No. Regulation (EU) 2026/1744 (the Digital Omnibus on AI) was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, deferring the Annex III high-risk obligations to 2 December 2027 before the original date arrived. The full text is on EUR-Lex.
Do I have to tell prospects they’re talking to an AI sales agent?
Yes, in almost all cases. Article 50(1) of the AI Act, applicable since 2 August 2026, requires providers to ensure people interacting directly with an AI system are informed of that fact, unless it is obvious to a reasonably well-informed, observant and circumspect person. The full article text is available via the AI Act Explorer. For voice and messaging outreach, an explicit disclosure at the start of the interaction is the safe design.
When do the deferred high-risk obligations now apply?
Annex III stand-alone high-risk systems: 2 December 2027. AI embedded in Annex I regulated products: 2 August 2028. The European Commission’s AI regulatory framework page reflects the updated timeline.
Are AI sales agents classified as high-risk under the AI Act?
Typical sales outreach — lead qualification, appointment booking, follow-up — is not listed in Annex III, so most sales agents are unlikely to be high-risk systems. The notable exception is recruitment: Annex III point 4 covers AI used to recruit or select people, including filtering applications and evaluating candidates. Classification depends on the actual use case, so confirm with counsel.
What are the penalties for breaching the transparency rules?
Under Article 99(4), non-compliance with Article 50 transparency obligations can attract administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher. Prohibited practices under Article 5 carry up to €35 million or 7% of turnover.
Does the AI Act apply to companies outside the EU?
It can. The AI Act applies to providers placing systems on the EU market and to providers and deployers outside the EU where the system’s output is used in the Union. An Australian or US company running AI agents that call or message EU prospects should assume the transparency and prohibition rules reach those conversations.
Did the Digital Omnibus change the AI literacy or GPAI obligations?
No. The Article 4 AI literacy duty (applicable since 2 February 2025) and the general-purpose AI model obligations (applicable since 2 August 2025) were not deferred and remain in force.
Building AI outreach for a disclosure-first world?
Zian’s AI sales agents run live phone, SMS, email and WhatsApp outreach in 30+ languages, with human-in-the-loop controls, CRM integrations and private model deployment on your own infrastructure for teams that need tighter data governance. If you’re evaluating AI outreach with regulation on your checklist, we’d like to talk. Apply For Partnership