The EU AI Act deadline that actually landed this month is not the one most organisations spent the year preparing for. On 2 August 2026, the transparency obligations under Article 50 became applicable across the European Union. The high-risk obligations under Annex III, the ones that filled compliance roadmaps and budget lines through the spring, moved to 2 December 2027 under the Digital Omnibus agreement. So the requirement that arrived on schedule is the one that touches your CRM most directly, and it happens to be the most achievable obligation in the entire Act.
That is a genuinely good position to be in. Article 50 asks for honesty about what is machine generated, not for a conformity assessment, a risk management system, or a technical file. Most of the work is configuration and copywriting rather than re-architecture. Teams that treat it as a design brief rather than a legal checkbox tend to finish quickly and come out with something customers actually like.
What actually changed on 2 August 2026?
Article 50 sets out transparency duties rather than engineering requirements. From 2 August 2026, providers must inform people when they are interacting with an AI system, unless that is already obvious from the context, and must mark synthetic content so it is machine readable and detectable as artificially generated. Deployers carry their own duties: disclosing deepfakes, telling people when emotion recognition or biometric categorisation is running, and flagging AI generated text published to inform the public on matters of public interest. Systems already on the market have until 2 December 2026 to meet the content marking rules. Assistive editing and human reviewed content sit outside the scope.
The Commission has done more than publish a rule here. It released a set of voluntary transparency icons, and a Code of Practice on Transparency of AI-Generated Content gives implementation guidance for the marking requirements. For once, the regulator shipped the pattern library alongside the obligation. Organisations that adopt the common icons get recognisable signals rather than a bespoke disclosure nobody understands.
Which parts of your CRM does Article 50 actually touch?
The honest answer is narrower than most compliance memos suggest, and that is where the opportunity sits. Customer facing conversational surfaces are clearly in scope: website chat, service deflection bots, voice agents that answer inbound calls, and any agent that resolves a case without a person reading the reply. If a customer could reasonably think they are talking to a colleague of yours, they need to be told otherwise.
Much of the rest of the CRM AI stack falls outside. A sales representative who asks Copilot or Agentforce to draft an email, reads it, edits it, and sends it is doing assistive editing with a human in the loop. Meeting summaries reviewed before they are shared, lead scores that inform a person’s judgement, next best action suggestions a seller can ignore: none of these trigger a disclosure duty on their own. The boundary is not the technology, it is whether a person meaningfully reviews the output before it reaches someone outside the organisation. Mapping that boundary across your instance is a week of work, and it is worth doing precisely because it usually shrinks the compliance surface rather than expanding it.
The edge cases are where the judgement calls live, and they are worth settling now rather than during an audit. Automated nurture sequences generated once by AI and approved by a marketer before they ever send are reviewed content. The same sequence, if an agent rewrites each message at send time based on account signals, is not, because no person sees the final text. Similarly, an AI drafted knowledge base article that a support lead publishes unchanged still counts as human reviewed, since a person made the decision to publish. Writing these distinctions down as a short internal standard costs an afternoon and saves the same argument being relitigated in every team.
Why disclosure is the cheapest compliance win available this year
Compared with everything else in the Act, Article 50 is inexpensive. There is no conformity assessment, no notified body, no post market monitoring plan. The deliverables are a line of copy in a chat header, a machine readable marker on generated content, and an accurate inventory of where AI touches a customer. Most CRM platforms already expose the settings needed to do this, so the constraint is decision making rather than engineering capacity.
It also tends to pay for itself. Labelling an assistant honestly, and pairing that label with an obvious route to a human, generally holds conversion steady rather than damaging it, because the people who wanted a person were going to find out anyway. The version that hurts trust is the bot that pretends to be Sarah from customer success until the customer works it out three messages in. Article 50 removes the temptation to run that pattern, which is a favour to the brand as much as to the regulator.
There is a service design benefit hiding in the obligation as well. Once an assistant introduces itself honestly, the sensible next question is what it should do when it reaches the limit of what it can handle. Organisations that answer that question properly, with a clean handover that carries the conversation history to a person, see fewer repeat contacts and better first contact resolution. The disclosure requirement forces a conversation about escalation design that many teams had been deferring, and the operational gain usually outlasts the compliance milestone that prompted it.
What is shadow AI, and why does it widen the transparency gap?
Shadow AI is any artificial intelligence tool used inside an organisation without the knowledge, approval, or oversight of IT and data governance. It covers personal assistant accounts used for customer correspondence, browser extensions that draft replies, unsanctioned automation connected to the CRM through an API key, and AI features quietly switched on inside sanctioned SaaS products. It grows because the tools are useful, cheap, and available before procurement finishes evaluating them.
Article 50 turns this into a practical problem rather than a theoretical one, because you can only disclose what you know about. If a support agent is generating customer replies through a tool nobody has registered, no disclosure will ever be applied to that output. The organisations in the strongest position this month are the ones that built an AI inventory earlier, not because they predicted the regulation, but because they wanted to know what was running. That inventory is now the single most valuable compliance asset they own, and building one is the first thing to do if it does not exist yet.
Why CRM data quality decides whether your disclosure holds up
CRM data quality matters here because disclosure is a claim about provenance, and provenance depends on records. Saying that a message was AI generated, or that a human reviewed it, is only defensible if the system logged which model produced the draft, who approved it, and when. Where ownership fields are empty, activity logging is inconsistent, or integrations write to the CRM through a shared service account, the audit trail dissolves. Accurate data is what converts a policy statement into evidence.
This is where accumulated CRM technical debt shows up as a compliance cost rather than an engineering annoyance. Years of duplicated automation, undocumented flows, and legacy integrations make it genuinely hard to answer a simple question: which of these outbound messages was machine generated? Teams that have kept their automation inventory tidy can answer in an afternoon. The useful reframing is that this work was always going to pay off in forecast accuracy and adoption, and the Act has simply given it a date.
The move to December 2027 is runway, not a reprieve
The Digital Omnibus agreement pushed Annex III standalone high-risk obligations from 2 August 2026 to 2 December 2027, and Annex I embedded systems from 2027 to 2 August 2028. Formal legal effect depends on publication in the Official Journal, so the safest planning assumption is that the direction is settled even while the paperwork completes. For CRM leaders, that is roughly sixteen additional months for the obligations most likely to catch recruitment tooling, credit related decisioning, and anything touching essential services.
Sixteen months is enough to build a governance layer deliberately, which almost never happens under deadline pressure. It is enough to define which agents are permitted to act without review, to give each one an owner, and to instrument the logging that a future conformity assessment will need. It is also enough to get adoption right, and adoption is what determines whether governance survives contact with a quarter end. Rules that sellers understand and can follow inside their normal workflow hold up. Rules that live in a policy document do not. Teams that spend this runway on clarity rather than documentation will find the 2027 deadline unremarkable when it arrives.
The Sirocco perspective
We think the most useful thing an independent CRM partner does in a moment like this is separate the obligation from the anxiety. An independent CRM partner is a consultancy that implements and advises across multiple platforms without reselling any single vendor’s licences, which means the recommendation is shaped by what an organisation needs rather than by what a vendor needs to sell. When a regulatory deadline lands, that independence matters, because vendors have a commercial interest in framing their own governance module as the answer. Frequently the answer is a decision about where human review sits, and it costs nothing.
Our experience across Salesforce, HubSpot, and Dynamics 365 is that clients who mapped their customer facing AI surfaces before August found the transparency work small and quick. The ones still discovering unregistered tools are doing two jobs at once. Both groups get to a good place, but the first group gets there without a fire drill, and they end up with an inventory that keeps paying back long after the disclosure copy is written.
The capability in these platforms is real and improving fast, and the compliance picture is more favourable than the headlines suggested. The harder question is whether your organisation knows, today, every place an AI system speaks to a customer in your name. If you want a second opinion on where that line sits in your instance, schedule a consultation and we will work through it with you.
Get in Touch
If you are working out which parts of your CRM now need an AI disclosure, and which sit safely outside Article 50, a short conversation will usually settle it faster than another round of internal legal review.
