Global & Cross-Border Insurance

EU AI Act, 2 August 2026: Transparency Duties Bit, High-Risk Rules Slipped to December 2027

The Digital Omnibus moved the EU AI Act's high-risk compliance date to December 2027, but Article 50 transparency duties applied on 2 August 2026 as scheduled. Indian GCCs and IT suppliers signed contracts against the original timeline, and the mismatch now runs through their warranties, indemnities, and tech E&O cover.

Sarvada Editorial TeamInsurance Intelligence
10 min read

Listen to this article

Audio version • 10 min read

EU AI ActGCCtech E&Ocontractual warrantiesAI liabilityIT services

Last reviewed: August 2026

One Deadline Moved. The Other Did Not.

For most of 2025, 2 August 2026 was the date Indian technology suppliers planned around. It was the day the EU AI Act's high-risk obligations were due to apply: conformity assessments, risk management systems, technical documentation, human oversight, the full Chapter III apparatus for systems listed in Annex III. Compliance programmes at Indian GCCs, IT services firms, and SaaS exporters were budgeted, staffed, and contractually promised against that date.

Then the date moved. The Digital Omnibus on AI, which entered into force in July 2026 after EU legislators agreed the delay, defers high-risk obligations for stand-alone Annex III systems from 2 August 2026 to 2 December 2027. For AI embedded in Annex I regulated products, such as medical devices and machinery, the date slips further, to 2 August 2028 (Gibson Dunn, 2026).

One set of obligations did not move. The Article 50 transparency duties were never part of the deferral and applied on schedule on 2 August 2026 (Certivo analysis, August 2026). A supplier that spent the year preparing for a high-risk cliff that receded is now, since three weeks ago, live on a different set of duties that received far less board attention.

The scale of the exposure is not small. India hosts 2,117 Global Capability Centres across 3,728 units, employing 2.36 million people, with estimated FY26 revenue of USD 98.4 billion (nasscom-Zinnov India GCC report, 2026). Many of those centres build, test, or operate AI systems whose output reaches EU users. Every one of them signed contracts, and many of those contracts name a compliance date that no longer means what it meant when the ink dried.

What the Digital Omnibus Actually Changed

The European Commission proposed the Digital Omnibus on AI on 19 November 2025 as a set of targeted amendments. The stated aim was to defer the highest-friction deadlines without reopening the Act's risk framework (Freshfields, 2026). The prohibited-practices rules, in force since February 2025, and the general-purpose AI obligations, applicable since August 2025, were untouched. So was the Act's basic architecture: risk tiers, Annex III's list of high-risk use cases, the conformity assessment machinery.

What changed is timing. The deferral splits into two tracks:

  1. Stand-alone high-risk systems under Annex III, such as AI used in recruitment, credit scoring, or insurance pricing, now face their obligations from 2 December 2027 instead of 2 August 2026.
  2. AI embedded in Annex I regulated products, where the AI Act piggybacks on existing product-safety regimes, moves to 2 August 2028.

For an Indian delivery centre, the practical effect is sixteen extra months, or two extra years for embedded systems, before the heavy obligations bind. That sounds like relief, and for compliance teams it is. For contract and insurance purposes it is messier, because the deferral was agreed in mid-2026, long after most of the client contracts now in force were drafted. A master services agreement signed in Bengaluru in early 2025 that warrants readiness for "all obligations applicable from 2 August 2026" was written for a world in which that phrase meant Chapter III. It now means Article 50, and the parties may not agree on what else it captures.

Article 50: The Duties That Applied on Schedule

Article 50 is short compared with Chapter III, but it is live law, and it touches systems that Indian suppliers run in volume. The core duties:

  • Providers of AI systems that interact directly with people, such as chatbots and voice assistants, must ensure users are informed they are dealing with AI, unless that is obvious from context.
  • Providers of systems generating synthetic audio, image, video, or text must ensure outputs are marked as artificially generated in a machine-readable format.
  • Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them.
  • Deployers of deepfake content must disclose that the content is artificially generated or manipulated.

The Act reaches non-EU operators. It applies to providers placing systems on the EU market wherever they are established, and to providers and deployers in third countries where the system's output is used in the EU. A Hyderabad centre operating a customer-service bot for a German retailer's EU users is inside that scope, whether the centre is characterised as provider, deployer, or as the contractor performing either role for its client.

Breaches carry penalties of up to EUR 15 million or 3% of worldwide annual turnover, the Act's middle penalty tier. That is smaller than the prohibited-practices tier, but it is not an exposure a mid-sized supplier absorbs comfortably, and it is now an exposure that exists today rather than in 2027.

The Exposure Runs Through Contracts, Not Brussels

For most Indian suppliers, the realistic path to a loss is not a fine from an EU market surveillance authority landing in India. It is the client contract.

Between 2024 and 2025, EU customers pushed AI Act language into their supplier agreements at speed. Three clause types recur in agreements now sitting in Indian legal departments:

  1. Compliance warranties. The supplier warrants that services and deliverables comply with the EU AI Act, often with the phrase "as applicable from time to time" but sometimes pinned to the August 2026 date, and occasionally warranting readiness for obligations that were then expected to apply and now do not.
  2. AI representations. Statements that the supplier's systems are not high-risk, or that high-risk obligations have been met, or that specific controls (logging, human oversight, documentation) are in place. Some of these representations describe Chapter III controls the supplier built early; others describe controls the supplier deferred when the deadline moved.
  3. Indemnities. The supplier indemnifies the client for losses arising from the supplier's non-compliance with applicable law, frequently with AI Act breaches carved out of the liability cap alongside data protection.

The timeline mismatch cuts both ways. A supplier that paused its Chapter III programme when the Omnibus passed may now sit in breach of a warranty that promised those controls by a contractual date, even though the regulation no longer requires them until December 2027. Conversely, a supplier that warranted only "compliance with applicable law" has a lighter burden than it budgeted for on high-risk systems, but is exposed on Article 50 from 2 August 2026, and a client who receives a regulator's question about an unlabelled chatbot will read the indemnity first.

This is the same structural problem Indian suppliers already know from GDPR and DORA exposure: the contract transmits EU regulatory risk to an Indian balance sheet regardless of whether the regulator could ever reach it directly.

Map Each Warranty to the Timeline It Was Written Against

The corrective work is contract review, and it is finite. For each EU-facing agreement, three questions:

Which regime does the warranty actually reference? Sort clauses into three buckets: those pinned to dated obligations ("obligations applicable on 2 August 2026"), those pinned to named obligations ("Chapter III", "Annex III conformity assessment"), and those that float with applicable law. Dated clauses are the dangerous ones, because the parties almost certainly had Chapter III in mind and the words no longer carry that meaning. Named clauses may now promise more than the law requires, which is still a binding promise. Floating clauses track the Omnibus automatically, and the live content of the promise today is Article 50 plus the prohibited-practices and GPAI rules already in force.

Does the delivery scope include Article 50 systems? Inventory the systems the centre builds or operates for EU-facing output: customer-facing conversational AI, content generation pipelines, anything producing synthetic media, any emotion or biometric analytics. For each, establish whether the disclosure and marking duties sit with the supplier or the client under the contract's allocation of provider and deployer roles, and whether they are actually being met in production.

What was promised for December 2027, and is the programme still funded? The deferral is a schedule change, and the high-risk obligations arrive on 2 December 2027 for Annex III systems. A supplier that reallocated its AI Act budget in July 2026 should check that no contract promises interim milestones, such as completed gap assessments or documentation packages, on dates that fall before then.

Where a clause is misaligned, the fix is an amendment or side letter recording the parties' shared reading of the Omnibus timeline. Clients have accepted these readily in 2026 because the ambiguity threatens them too. The suppliers in difficulty at renewal are the ones who cannot show underwriters they did this exercise.

Which Policies Respond When a Warranty Fails

When a client claims against a supplier for an AI Act-related failure, the claim usually arrives as a professional liability matter: the services were performed negligently, or a contractual promise about the services was broken. That routes it to the technology errors and omissions policy, and the policy's response turns on wording details that predate the AI Act.

The first issue is the contractual liability exclusion. Most tech E&O policies exclude liability assumed under contract beyond what the law would impose anyway. An indemnity for the client's regulatory fines, or a warranty of compliance with a regime that does not directly bind the supplier, is exactly the kind of assumed liability the exclusion targets. Suppliers should negotiate the exclusion at placement, disclosing their standard EU contract templates so the underwriter prices the real exposure.

The second issue is whether AI-specific failures are affirmatively covered or silently ambiguous. A chatbot that fails to disclose it is AI, or a generation pipeline that omits machine-readable marking, is a system behaving as designed; the defect is in compliance configuration, not code failure. Some wordings respond, some arguably do not, and the market's answer is the affirmative AI liability cover now offered as endorsements or stand-alone policies that name AI system failures, including regulatory transparency failures, as insured events.

The third issue is regulatory proceedings cover. Defence costs for an EU authority's inquiry, and fines where insurable in the relevant jurisdiction, sit in cyber and E&O policies with sub-limits. Wordings drafted for GDPR should be checked for language broad enough to include AI Act proceedings rather than enumerating data protection statutes only.

Underwriters have adjusted faster than many proposers expected. Renewal questionnaires for IT services professional liability now ask which AI Act obligations the insured is subject to as of the current date, which systems fall under Article 50, and what the December 2027 readiness plan is. An answer that says "the AI Act was delayed" signals that the proposer has not read past the headline, and it prices accordingly.

What a Bengaluru or Hyderabad Centre Should Do Before Renewal

The work splits into a compliance track and an insurance track, and both are smaller than the Chapter III programme that just moved to 2027.

On the compliance track: complete the Article 50 inventory, close the disclosure and marking gaps in production systems, and document the provider and deployer role allocation for each EU-facing system. Keep the high-risk programme alive on a December 2027 schedule with dated milestones, because sixteen months disappears quickly against conformity assessment lead times.

On the contract track: run the warranty mapping described above, prioritising agreements with uncapped AI Act indemnities and dated compliance warranties. Record agreed timeline readings in amendments.

On the insurance track:

  • Take the current tech E&O and cyber wordings and test them against one concrete scenario: an EU client is questioned by a regulator about an unlabelled AI interaction delivered by your centre, and invokes its indemnity. Trace which policy responds, through which insuring clause, and against which exclusions.
  • Check whether the professional indemnity limit still matches the largest AI Act carve-out from a liability cap in the client portfolio. Carve-outs negotiated in 2025 assumed a 2026 high-risk regime; some were sized against fine exposures that are now sixteen months away, but the contractual exposure exists now.
  • Ask the broker for AI-affirmative options at renewal rather than relying on silence. The cost of an AI endorsement on an Indian tech E&O placement is modest against the ambiguity it removes.
  • Prepare the underwriting submission to show the two-timeline analysis explicitly. A proposer that can state which obligations bound it on 2 August 2026, which bind it from December 2027, and how its contracts allocate each, presents as a materially better risk than one that cannot.

The Omnibus bought time on the hard obligations. It did not buy time on the contracts, and it did not buy time on Article 50. The suppliers who treat 2 August 2026 as a date that mattered, rather than a deadline that vanished, will have the cleaner renewal conversations this autumn.

Frequently Asked Questions

Did the EU AI Act's 2 August 2026 deadline apply to Indian companies or was everything delayed?
Part of it applied. The Digital Omnibus on AI, in force since July 2026, deferred the high-risk obligations for stand-alone Annex III systems to 2 December 2027 and for AI embedded in Annex I regulated products to 2 August 2028. The Article 50 transparency obligations were not part of the deferral and applied on 2 August 2026 as originally scheduled. An Indian supplier whose chatbots, content generation systems, or biometric analytics produce output used in the EU is within the Act's reach for those duties now, either directly or through its client contracts.
What does Article 50 of the EU AI Act require from an Indian GCC or IT services firm?
Article 50 requires that people interacting with an AI system are told it is AI unless that is obvious, that synthetic audio, image, video, and text outputs carry machine-readable marking as artificially generated, that people exposed to emotion recognition or biometric categorisation systems are informed, and that deepfake content is disclosed as manipulated. Which duty sits with the Indian supplier depends on whether it acts as provider or deployer for each system, an allocation that should be recorded in the client contract. Breaches carry penalties up to EUR 15 million or 3% of worldwide annual turnover.
Our client contracts warrant EU AI Act compliance by August 2026. Are we in breach now that the deadline moved?
It depends on the drafting. A warranty tied to obligations applicable from time to time tracks the Omnibus automatically, and its live content today is Article 50 plus the rules already in force. A warranty that names Chapter III controls or pins a dated readiness commitment may still bind you to the original schedule even though the regulation itself defers to December 2027. The practical fix is a contract review that sorts clauses by which regime they reference, followed by amendments or side letters recording the parties' agreed reading of the new timeline.
Will a standard tech E&O policy cover a claim arising from an AI Act transparency failure?
Not reliably without attention to two wording points. The contractual liability exclusion can remove cover where the loss flows from an indemnity or warranty that goes beyond what the law imposes on the supplier directly, which is common in EU client contracts. And a transparency failure is a compliance configuration defect in a system working as designed, which some legacy E&O wordings do not clearly capture. Suppliers should negotiate the exclusion at placement, check regulatory proceedings cover extends beyond data protection statutes, and consider affirmative AI liability endorsements that name AI regulatory failures as insured events.

Related Glossary Terms

Related Insurance Types

Related Industries

Related Articles

Sarvada Intelligence

Ready to see Sarvada in action?

Explore the platform workflow or start a product conversation with our underwriting automation team.

Explore the platform