In two weeks, on 2 August 2026, another milestone in the European Union’s AI Act comes into effect. Most manufacturers skip the headline, reasoning that they are not an AI company. This round of rules, though, does not only bind the people who build AI — it binds the people who use it. A manufacturer running a chatbot on its support line, or generating product images and catalogue copy with AI, can fall within scope.
There is a second piece of news from the same period, and it takes some pressure off the first. The EU has pushed the heaviest part of the law — the obligations attached to high-risk systems — to a later date through a simplification package known as the Omnibus. So what begins in August is narrower than many expect. It is also closer than many expect.
What the law regulates, and who it binds
The EU AI Act classifies AI systems by risk level and attaches different obligations to each level. It entered into force on 1 August 2024 and applies in stages. Prohibited practices kicked in during February 2025, and the rules for general-purpose AI models followed in August 2025.
On scope, the deciding factor is not geography but where the output lands. The regulation covers not only companies established in the EU, but also providers and deployers in third countries whose systems are placed on the EU market or whose output is used within the Union. A company based in Türkiye serving an AI-assisted service to a customer in Germany can fall inside that definition. Run the assessment for your own case with legal counsel, since scope turns on the role your company plays — provider or deployer.
What starts on 2 August 2026: transparency
At the centre of this stage sits Article 50 of the regulation: transparency obligations for certain AI systems. The principle is straightforward — people should know when they are dealing with AI, or looking at content AI produced. It breaks into four headings:
- Systems that interact directly with people. A chatbot must be designed so the person on the other side understands they are talking to an AI. No notice is required where this is already obvious to a reasonably informed user.
- Marking generated content. Systems producing synthetic audio, image, video or text must mark their output in a machine-readable format as artificially generated. Assistive editing functions, such as grammar correction, fall outside this duty.
- Emotion recognition and biometric categorisation. Deployers of these systems must inform the people exposed to them.
- Deepfakes and text informing the public. Realistic content generated or manipulated with AI must be disclosed. The duty is lighter for artistic and fictional work, and an exemption exists for text that has gone through human review under editorial responsibility.
There is a transition period on the marking side: for generative systems already placed on the market before 2 August 2026, compliance with machine-readable marking is reported to run until 2 December 2026. The technical standards for marking are still maturing, so it is worth tracking European Commission announcements for the implementation detail.
High-risk systems: the Omnibus moved the clock
The costliest part of the law for businesses was always the high-risk tier: risk management, data governance, technical documentation and human oversight. Those duties were expected to begin on 2 August 2026.
On 19 November 2025 the European Commission published the Digital Omnibus package proposing a change to that timeline, citing delays in designating national competent authorities and in finalising the harmonised standards needed for compliance. The Parliament approved the text on 16 June 2026 and the Council on 29 June 2026; it enters into force during July 2026 following publication in the Official Journal.
| Obligation | Previous date | After the Omnibus |
|---|---|---|
| Transparency rules (Article 50) | 2 August 2026 | Unchanged — 2 August 2026 |
| Stand-alone high-risk systems (Annex III) | 2 August 2026 | 2 December 2027 |
| High-risk systems embedded in products (Annex I) | 2 August 2027 | 2 August 2028 |
The message in the table is clear enough: the delay sits on the high-risk side, not the transparency side. The headings a manufacturer meets in daily work — chatbots and generated content — take effect in August. Dates can still shift with the final text, so confirm against a current official source before committing to an investment or a contract.
Where a manufacturer in Türkiye fits
Take a concrete case. A fifty-person manufacturer sells machine parts into Europe. There is a chatbot on the website, product descriptions and marketing visuals are produced faster with AI, and a language model drafts text for quotations. This company is not an “AI company” — yet it has three distinct uses that fall under the transparency headings from August.
The work ahead is not a full compliance programme. It is knowing the answer to three questions: where do we use AI, does the output travel to the EU, and does the person using it understand they are dealing with AI? For many small and medium-sized businesses the fix can be as plain as adding a notice line to the chatbot and asking the vendor how generated content gets marked.
The real difficulty sits elsewhere. Many businesses do not know where AI already runs in their own processes. A tool marketing picked up, a plug-in finance is trialling, a quotation drafted in sales — all in separate corners, none of it written down in one place. Answering the scope question starts with pulling that list together.
Steps worth taking now
- Build an AI inventory. Which department uses which tool, and for what? Free plug-ins and browser-based tools included. A single-page list is enough to start.
- Establish your role. Are you building and supplying a system, or using an off-the-shelf tool? Provider and deployer duties differ, and you cannot prepare without knowing which side you are on.
- Add the notice if you run a chatbot. The cheapest and most visible step. Let the visitor see that they are talking to an AI.
- Ask your vendor. How does the provider of your tool handle marking of output? Raising it at renewal is cheaper than swapping systems later.
- Note the high-risk dates rather than forgetting them. The delay brought relief, not cancellation. If you run something like a recruitment screening system or a safety component, late 2027 is not as far off as it looks.
- Base decisions on the official text. The detail of the post-Omnibus regime is still settling; for critical steps rely on European Commission announcements and your legal counsel.
The layer underneath compliance: data
There is a familiar pattern here. With CBAM, with CSRD, and now with the AI Act — what the regulation really asks for is not the report or the notice, but the orderly data underneath it. If you cannot show what your systems do, which data they run on and where the output goes, no amount of delay will let you prepare.
This is where İkiz Eksen starts: making processes and data measurable on the ground, gathering them into a software layer, and turning that into a compliance output. The same chain runs whether you are putting AI to work on the digital transition side or reporting carbon data on the green transition side.
Behind that measure–software–comply chain sits Qera’s enterprise software track record: more than 550 customers across over 15 sectors, more than 100 ERP implementations, and a team of around 35 specialists. The infrastructure runs on Microsoft Azure, with an information security and quality framework backed by ISO/IEC 27001 and ISO 9001 certification. Steps that demand dedicated expertise — legal opinion, accredited audit — we run with solution partners, and we set out plainly who provides what on the solutions page. Our service scope covers Türkiye nationwide.
If you want to work out where AI already runs in your company and which heading that puts you under, get in touch.
Frequently Asked Questions
Why would a company based in Türkiye be subject to the EU AI Act?
The regulation sets scope by where the system is placed on the market or where its output is used, not by where the company is established. If you provide an AI-assisted service to a customer in the EU, you may fall within scope. The precise assessment depends on your role, so take legal advice.
What exactly begins in August 2026?
The transparency obligations in Article 50: chatbot disclosure, marking of AI-generated content, notification for emotion recognition systems, and deepfake disclosure. The heavier obligations for high-risk systems do not start on that date.
Why were the high-risk rules delayed?
The European Commission pointed to delays in designating national authorities and in preparing the harmonised standards needed for compliance. The Digital Omnibus package was approved by the Parliament on 16 June and the Council on 29 June 2026, moving the date for stand-alone high-risk systems to 2 December 2027.
I use an off-the-shelf AI tool — is the obligation still mine?
Provider and deployer duties are defined separately. Machine-readable marking of output sits on the provider side, for instance, while disclosure of deepfake content sits with the deployer. Asking your tool’s provider how they handle this is the first step of any preparation.
Where should compliance work start?
With an inventory of where AI is used inside the company. Without that list you cannot answer whether you are in scope. Once you have it, mark your role and where the output goes for each use — the substantive work follows from there.
