EU AI Act: enforced from 2 AugustTrain your team in under 1 hour, recording includedGET COMPLIANT NOW →
THE FINE PRINT

The AI Act Changed On 27 July. Beauty's Deadline Did Not.

By The Beauty Insider · 30 July 2026
The AI Act Changed On 27 July. Beauty's Deadline Did Not.

From Sunday 2 August 2026, a beauty business that runs an AI chatbot, publishes AI-generated imagery or lets a model write customer-facing copy is obliged to say so. Europe amended its AI law three days ago and moved almost every date in it. It did not move that one.

Regulation (EU) 2026/1744, the Digital Omnibus on AI, came into force on 27 July. It postponed the high-risk regime by up to sixteen months and rewrote the AI literacy duty in softer language. Article 50, the transparency article, it left alone.

Who this applies to

Not only European companies. The obligation follows the content and the audience, not the head office. A brand in Dubai, Seoul, Tokyo, Casablanca or London that publishes AI-generated campaign imagery to European audiences, or runs a chatbot serving European customers, is inside Article 50. So is a distributor placing AI-assisted content into European markets on a brand's behalf. It applies irrespective of when the system was first put on the market, so an older chatbot is not exempt.

What moved, and what did not

The deferrals are real but narrow. High-risk systems move to December 2027 and August 2028, and for most beauty companies none of that was ever in scope. That is why the relief is being misread as a general delay.

The Commission published its final Article 50 guidelines on 20 July, nine working days before the article applies.

One transitional window exists and it is narrower than the commentary suggests. Generative systems already on the market before 2 August have until 2 December 2026 to add machine-readable marking. That covers the marking duty in Article 50(2) and nothing else. Telling a person they are speaking to a machine does not move for anyone.

The relief was granted to the high-risk tier. The transparency tier was left alone, and the transparency tier is the one beauty sits in.

What you have to do

Four uses are in scope, and they carry different weights.

Chatbots and AI beauty advisers are the clearest. A person must be told they are interacting with an AI system at the first interaction, unless it is already obvious. The guidelines read that exception strictly. A line in terms and conditions does not count; a visible sentence before the conversation opens does.

AI-generated imagery is where the judgement sits, and where beauty has been most anxious. The test turns on content that resembles real people, objects, places or events and would falsely appear authentic. In practice, ordinary post-production is outside it: clipping, background removal and colour correction do not trigger the duty, and there is no blanket requirement to mark every image an AI tool has touched. A fully generated background behind a real product is a different matter, and so is a synthetic person presented as a model who was on set.

Who carries the marking duty turns on one word. Most beauty brands buy their generation, try-on and skin analysis as third-party APIs, which makes them a deployer: the job is to check the tool marks its output, and that the mark survives the crop and the resize. Build the feature in-house and you are the provider of that system, and the duty is your own. Worth establishing which you are before Sunday, because the answer is different per tool.

Skin analysis, virtual try-on and shade matching fall under Article 50(3), which covers emotion recognition and biometric categorisation. Where such a system is applied to a person, the deployer is obliged to tell them. The detail worth reading twice: a system that infers sensitive attributes, including racial or ethnic origin, from biometric data triggers the duty whether that inference is the purpose of the tool or a by-product of it. Shade matching sits close to that line. The industry is already circling this ground from the privacy side, validating try-on accuracy across ethnicities and asking for explicit consent before analysing a customer photo. Article 50(3) adds a plainer duty on top: tell them the tool is doing it.

AI-written copy is the narrowest. Disclosure bites only on text published to inform the public on matters of public interest, and only where no human took editorial responsibility. Product description sits outside it. Copy straying into health or sustainability claims sits closer, and a named human signing it off settles the question. "AI-generated copy, chatbot responses, and personalized recommendations can, at times, unintentionally exaggerate efficacy, imply scientific support that is not well substantiated, or blur the line between aspirational branding and measurable performance," said Ceren Canal Aruoba, managing director at BRG. Cosmetic claims law already governs that ground, and it did not move either.

The duty that got lighter

The amendment rewrote Article 4. Where providers and deployers previously had to ensure a sufficient level of AI literacy among staff using AI on their behalf, the text now asks them to take measures to support the development of it, and adds: "This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual."

An obligation of result became an obligation of effort. The duty still applies. What has gone is the implication that a company must prove a standard was reached.

Six things to do before Sunday

  1. Write down every place AI touches a customer: chat, imagery, video, voice, generated copy, personalisation, skin analysis, virtual try-on.
  2. For each one, decide whether you are the provider or the deployer. If you built it, the marking duty is yours.
  3. Put a visible line on any AI chat interface, before the conversation opens, not in the small print.
  4. If you run skin analysis, virtual try-on or shade matching, tell the customer the tool is analysing them, at the moment they use it.
  5. Ask each image and video vendor two questions in writing: does your tool apply machine-readable marking that survives export and resizing, and can that marking still be detected afterwards. The Code of Practice expects at least two layers where needed, usually embedded metadata plus a watermark.
  6. Date a one-page AI literacy note for the team using these tools, and keep a record of who read it. The bar is lower than it was. It is not zero.

What is settled, and what is still moving

Settled: Article 50 applies from 2 August 2026, enforced by national market surveillance authorities and the AI Office, with fines under Article 99(4)(g) reaching EUR 15 million or 3 percent of worldwide annual turnover, whichever is higher. Settled too: the high-risk deferrals, and the softer wording of Article 4.

Still moving: exactly where the line falls in advertising. The guidelines are guidance, not law. There is now a set of official EU icons for labelling AI-generated content, and the voluntary Code of Practice published on 10 June is a route to demonstrating compliance rather than a definition of it. Neither has been tested on a beauty campaign.

The next date is 2 December 2026, when the marking grace period ends.

The Beauty Insider tracks the rules reshaping the business of beauty. This article is general information, not legal advice; confirm your own obligations against the official EU AI Act text and your national authority.

If your team would like the plain-English version of what applies on 2 August, AICO runs an EU AI Act session for beauty companies in under an hour. See the EU AI Act training for beauty, book a live session, or get in touch at ag@linguabeauty.com.
Disclosure: The Beauty Insider is published by AICO, which sells AI content services and EU AI Act training for beauty brands. This piece refers to services AICO provides. Our editorial judgements are our own and are not conditional on any commercial relationship.
More from The Beauty Insider ↗