The AI CEO Brief

AI ANALYSIS

The EU AI Act rule that applies to you right now, and the one that does not

Europe delayed its high-risk AI regime to 2027. It did not delay the transparency rules. If your product reaches an EU user from Singapore, Bangalore or Sydney, those rules have been live since 2 August 2026.

9-min readPublished 2026-08-11Updated 2026-08-11
By Prabjeet Singh Anand · CEO and founder · 20 years building APAC technology companies · 1,000+ businesses served · Singapore Entrepreneur 100 (2024)Sources: European Commission, Cooley, Gibson Dunn, Baker McKenzie
Share on LinkedIn

In late July the headlines were unambiguous. Europe was backing down. High-risk AI rules delayed to 2027 after Big Tech pushback. If you read that, filed it, and moved on, you did what most operators in this region did.

I did the same for about a day. Then I went and read what actually got delayed, and the answer is not what the coverage suggested.

What actually moved, and what did not

The Digital Omnibus agreement pushed the high-risk regime back. Stand-alone Annex III systems now have until 2 December 2027. AI embedded in regulated products under Annex I has until 2 August 2028. That is a genuine, significant delay, and for companies building recruitment scoring, credit decisioning or medical AI, it is real breathing room.

Article 50 was carved out. The transparency obligations came into force on 2 August 2026, on the original schedule, unchanged.

ObligationOriginal dateStatus now
Article 50 transparency2 August 2026Live. Not delayed.
Marking of existing generative output2 August 2026Grace period to 2 December 2026
Stand-alone high-risk (Annex III)2 August 2026Moved to 2 December 2027
Embedded high-risk (Annex I)2 August 2027Moved to 2 August 2028

The delay was real. It just was not the part that touches most mid-market software companies.

What Article 50 actually requires

Four categories, and they are simpler than the high-risk regime by a wide margin.

Systems that interact with people directly. If your product talks to a user, whether that is a support chatbot, a voice assistant or an in-app agent, the user has to be told they are dealing with AI. The disclosure has to be clear and it has to come at the point of interaction, not buried in terms of service.

Systems that generate synthetic content. If you produce images, audio, video or text with AI, that output needs machine-readable marking so it can be detected downstream. This is a technical obligation, not a labelling one. A visible watermark on its own does not satisfy it.

Emotion recognition and biometric categorisation. If your system infers emotional state or sorts people into categories using biometric data, the people subject to it have to be informed.

Deepfakes and AI-generated content on matters of public interest. Content of this kind requires disclosure, with a carve-out where the material has been through genuine editorial review.

Who is in scope, and this is the part people get wrong

Article 50 of Regulation (EU) 2024/1689 does not care where your company is registered.

It applies to providers, deployers, importers and distributors who place an AI system on the EU market, or whose system output is used within the EU. Your headquarters, your incorporation, your data centres and your team’s location are all irrelevant to the test.

So a Singapore SaaS company with EU customers is in scope. An Indian development agency shipping a client’s AI feature to European users is in scope. An Australian firm running a chatbot that a German visitor lands on is in scope.

The distinction that matters is provider versus deployer. If you built the system, you are the provider. If you took someone else’s model and put it in front of a user, you are the deployer, and deployer obligations are yours, not your vendor’s. Most mid-market companies in this region are deployers and have not thought of themselves that way.

Get this a week earlier

The AI CEO Brief goes out every Sunday to CEOs across Southeast Asia, India and Australia. One development that changes a decision, and what I would do about it. Free.

Subscribe free

What it costs to get this wrong

Up to 15 million euros, or 3% of worldwide annual turnover, whichever is higher.

That is the ceiling, not the expected outcome, and early enforcement in most regimes tends toward engagement before penalty. But note the base: worldwide turnover, not EU turnover. A company earning a small fraction of its revenue in Europe is exposed against its global number.

Two dates that buy you room

Two dates that buy you room

Generative systems already on the market when the rules took effect have until 2 December 2026 to implement marking and detection. That is roughly four months from now, not zero.

Content published before 2 August 2026 does not need to be retroactively labelled. You are not going back through your archive.

Neither of these applies to the disclosure obligation for systems that interact with users. That one has been live since 2 August with no transition.

What I would actually do

The compliance work here is small. Finding out what you have is the work.

Build the list first. Every AI feature in your product, and for each one, whether a user in the EU can currently reach it. Not a governance programme. A list. Most companies I talk to cannot produce this in under a week, and that is the actual finding.

Sort the list into the four categories. Interacts with a user, generates synthetic output, infers emotion or biometrics, produces public-interest content. Most features land in the first category and need a disclosure string, which is an afternoon of work.

Check whether you are the provider or the deployer for each one. This determines who carries the obligation and it is usually not what the vendor’s marketing implies.

Read your vendor contracts. Most AI vendor agreements signed before 2026 have nothing useful to say about who handles regulatory disclosure. If yours are silent, the obligation defaults to you.

Then decide about Europe. For some companies the honest read is that EU revenue does not justify the compliance overhead. Deciding that deliberately is a legitimate strategy. Discovering it during an enforcement inquiry is not.

Why this matters beyond Europe

Vietnam’s AI Law, whose high-risk system list took effect on 15 August 2026, borrows the EU’s risk-tier structure closely enough that Baker McKenzie describes it as a clear manifestation of the Brussels effect. India’s IT Rules amendments now mandate synthetic content labelling and three-hour takedowns. The direction of travel across this region is toward the same architecture.

Which means classification work you do for Europe is not wasted on Europe. It is the foundation for every regime that copies it, and several already have.

Who can genuinely ignore this

If no EU user can reach any AI feature you operate, and no output your systems generate is used in the EU, Article 50 does not apply to you.

Confirm that rather than assume it. In practice the companies that assume it are usually wrong about at least one integration, one embedded widget, or one customer’s end users.


Common questions

Does the EU AI Act apply to companies outside the EU?

Yes. The Act applies to providers, deployers, importers and distributors who place an AI system on the EU market or whose system output is used inside the EU, regardless of where the company is registered or where its infrastructure sits. A Singapore, Indian or Australian company with EU end users is in scope.

Was the EU AI Act delayed?

Partly. The Digital Omnibus agreement moved stand-alone high-risk obligations under Annex III to 2 December 2027 and embedded high-risk obligations under Annex I to 2 August 2028. Article 50 transparency obligations were not delayed and took effect on 2 August 2026 as originally scheduled.

What is Article 50 of the EU AI Act?

Article 50 sets the transparency obligations. Systems that interact directly with people must disclose that they are AI. Systems that generate synthetic images, audio, video or text must mark that output in a machine-readable way. Emotion recognition and biometric categorisation require notification, and deepfakes and AI-generated public-interest content require disclosure.

When did the EU AI Act transparency rules take effect?

2 August 2026, with no general grace period. Generative systems already on the market at that date have until 2 December 2026 to implement marking and detection. Content published before 2 August 2026 does not need retroactive labelling.

What are the penalties for breaching Article 50?

Up to 15 million euros or 3% of worldwide annual turnover, whichever is higher. The base is global turnover, not EU turnover, so a company earning a small share of revenue in Europe is still measured against its worldwide number.

Am I a provider or a deployer under the AI Act?

You are the provider if you developed the AI system and placed it on the market. You are the deployer if you use someone else’s system under your own authority and put it in front of users. Most mid-market software companies in Asia Pacific are deployers, and deployer obligations sit with them rather than with their model vendor.

Does the EU AI Act apply to a Singapore company?

Yes, if any AI system you provide or deploy reaches users in the EU, or if output from your system is used there. Singapore incorporation, Singapore hosting and a Singapore-based team make no difference to the test, which is about where the system or its output lands.

Do I have to label AI-generated content?

If your system generates synthetic images, audio, video or text and reaches EU users, yes. The obligation is machine-readable marking that allows the content to be detected as AI-generated. A visible watermark alone does not satisfy it. Systems already on the market at 2 August 2026 have until 2 December 2026.

Author

Prabjeet Singh Anand advises APAC CEOs on AI strategy and execution. Based in Singapore, he has spent two decades building technology businesses across the region. He writes The AI CEO Brief, a weekly newsletter for senior leaders navigating AI decisions across Southeast Asia, India and Australia.

Sources

  1. European Commission, Guidelines on transparency obligations under Article 50 of the AI Act
  2. Cooley, “EU AI Act: Transparency Obligations Take Effect 2 August 2026”
  3. Gibson Dunn, “EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes”
  4. Baker McKenzie, “Vietnam’s first standalone AI Law: an overview of key provisions”

One thing a week that actually changes a decision

No roundups. No tool lists. One development, decoded for people who have to act on it, every Sunday. Written by Prabjeet Singh Anand, who advises APAC CEOs on AI strategy and execution.

Subscribe free

Share this analysis

Weekly

Get the AI CEO Brief weekly

Sunday evenings. APAC AI intelligence in five minutes. No spin.

Subscribe free →

the-ai-ceo-brief.beehiiv.com · No spam, ever.

The AI CEO Brief is read by 1,000+ CEOs and senior leaders across Asia Pacific. Subscribe free at the-ai-ceo-brief.beehiiv.com →