The AI Act was postponed? Not the part that affects you

The headlines from June this year left businesses with a dangerous impression: that Europe had postponed the Artificial Intelligence Act by a year and a half. Only the heaviest part was postponed — the rules for high-risk systems. The transparency obligations became applicable on 2 August 2026 and reach a far wider circle of organisations: every company or public body operating a chatbot on its website or publishing AI-generated content.

What was actually postponed — and what was not

Regulation (EU) 2024/1689 (the Artificial Intelligence Act) entered into force on 1 August 2024 with a staggered application schedule. In November 2025 the European Commission proposed the Digital Omnibus on AI (COM(2025) 836) — a package of targeted amendments driven by the reality that the compliance infrastructure the Act relies on was not ready: the CEN-CENELEC harmonised standards were running behind, the Commission's guidelines were still in draft, and many Member States had not designated or resourced their market surveillance authorities.

The European Parliament endorsed the final text on 16 June 2026, and the Council of the EU gave its final approval on 29 June 2026. Obligations for stand-alone high-risk systems under Annex III are deferred to 2 December 2027, and for AI embedded in regulated products under Annex I, to 2 August 2028.

That is the good news. The bad news lies in what remained unchanged. The transparency obligations under Article 50 were not part of the deferral and apply from 2 August 2026. On 20 July 2026 the Commission adopted its final guidelines on Article 50 and confirmed the Code of Practice on the transparency of AI-generated content as adequate.

The distinction matters. The high-risk rules concern a comparatively narrow set of applications — recruitment systems, credit scoring, biometric identification. Article 50 concerns anyone who puts artificial intelligence in front of a human being.

The four obligations already in force

Article 50 requires four types of disclosure, split between the provider, which develops the system, and the deployer, which uses it under its own authority:

  • Interaction with people. A chatbot, virtual assistant or automated telephone system must be designed so that the person on the other side understands they are dealing with an AI.
  • Generated content. Synthetic text, images, audio and video must carry machine-readable marking indicating that they are artificially generated.
  • Emotion recognition and biometric categorisation. The deployer must inform the people exposed to the system.
  • Deepfakes and AI-generated text on matters of public interest. Published content must be clearly disclosed as artificially generated or manipulated.

For generative systems already placed on the market before 2 August 2026, a transition period for machine-readable marking runs until 2 December 2026. In other words, even organisations covered by that exception have only a few months.

The penalty is not symbolic: non-compliance carries fines of up to EUR 15 million or 3% of total worldwide annual turnover. Separately, Article 4 — the duty to ensure a sufficient level of AI literacy among staff — has applied since 2 February 2025, does not depend on the risk tier, and was not postponed. A single onboarding video does not discharge that duty.

Why this is more of a Bulgarian problem than it looks

Here are the figures that should change the conversation. According to Eurostat, in 2025 20.0% of EU enterprises with 10 or more employees used at least one artificial intelligence technology — up 6.5 percentage points from 13.5% in 2024. The highest shares were in Denmark (42.0%), Finland (37.8%) and Sweden (35.0%), while at the other end were Romania (5.2%), Poland (8.4%) and Bulgaria (8.5%). Bulgaria's trajectory is upward — 3.61% in 2023, 6.47% in 2024 and 8.55% in 2025.

It is tempting to read these numbers reassuringly: if few companies use AI, few companies have obligations. That reading is wrong, for two reasons.

First, the most widespread applications are precisely the ones Article 50 regulates. The most commonly used technology in the EU is the analysis of written language (11.75%), followed by the generation of images, video and audio (9.55%) and the generation of written or spoken language (8.76%). A marketing department producing visuals with a generative tool, and a website with a customer-service chatbot, are textbook Article 50 cases — even though no one in the company thinks of them as "deploying artificial intelligence".

Second, the statistics count only enterprises with 10 or more employees. Micro-enterprises — the backbone of tourism, logistics and services in Bulgaria's South-East region — are outside the sample but fully within the scope of the Regulation.

Institutional uncertainty compounds this. The Ministry of e-Government has been designated as the lead authority for implementing the Act in Bulgaria, while the national framework — the designation of market surveillance authorities, the sanctions regime and the national register of AI systems — is still being built. For business, this means one thing: the absence of a fully operational supervisory system does not remove the obligation; it merely delays the moment at which it will be checked.

Getting started is simpler than it sounds

For the vast majority of small and medium-sized enterprises, complying with Article 50 requires neither software development nor external certification. It begins with an inventory: where in the organisation AI is being used, who introduced it, what content it works on, and where that content reaches an external audience. Three concrete actions follow — a disclosure notice at first contact with the chatbot, a policy for labelling generated content, and a documented training plan for teams under Article 4.

The difference between organisations that will pass through this without disruption and those that will experience it as a crisis is whether they started mapping before anyone asked them to.

Regulatory clarity is part of technological readiness

This work — turning a European regulatory framework into a list of executable steps for a specific enterprise — sits at the core of what the DINT Foundation and the Southeast Digital Innovation Hub (DIGIHUB), of which the Foundation is a founding member, actually do. As a European Digital Innovation Hub holding a Seal of Excellence and an Enterprise Europe Network node in Burgas, DIGIHUB works with SMEs and public organisations across the region under the EDIH DIGIHUB project (BG16RFPR002-1.002-0004-C01, "Research, Innovation and Digitalisation for Smart Transformation" Programme), precisely so that digital transformation does not remain a matter of guesswork. Dialogue with institutions on improving the regulatory climate has been one of the four axes of DINT's mission since its establishment in 2018.

Not sure whether your chatbot or your marketing tools fall within the scope of Article 50? Contact the DIGIHUB team at www.digihub.bg for an initial consultation — mapping the AI you already use takes less than a working day and is the cheapest step you can take before 2 December 2026.

Sources: Regulation (EU) 2024/1689; Digital Omnibus on AI, COM(2025) 836; European Commission guidelines on Article 50 of 20 July 2026; Eurostat, dataset isoc_eb_ai, 2025 reference year.

Subscribe to our newsletter