BIA Ruling Means Advance Parole Travel Can Trigger a Re-Entry Bar

A decision by the Board of Immigration Appeals has removed a protection that many people relied on for more than a decade. From 13 August 2026, travel on advance parole counts as a departure from the United States for the purposes of the unlawful presence bars — meaning that leaving the country with a government-issued advance parole document can now trigger the three-year or ten-year bar to admission for someone who has accrued unlawful presence. The case is Matter of Delcarmen-Lara, 29 I&N Dec. 830 (BIA 2026), and it expressly overrules Matter of Arrabally and Yerrabelly, 25 I&N Dec. 771 (BIA 2012).

An aircraft in flight, illustrating how travel on advance parole can now trigger a US re-entry bar

The practical consequence is narrow but severe. It does not affect everyone who holds an advance parole document. It matters enormously for the subset who have periods of unlawful presence behind them and who assumed, correctly until this month, that authorised travel carried no re-entry penalty.

Why travel on advance parole now carries a bar risk

Section 212(a)(9)(B) of the Immigration and Nationality Act makes a person inadmissible for three years if they accrued more than 180 days of unlawful presence and then departed, and for ten years if they accrued a year or more and then departed. In 2012, Arrabally held that a temporary trip abroad on advance parole was qualitatively different, because it presupposed a return and the continuation of an adjustment application, and so was not the kind of departure that triggered the bar.

The Board has now rejected that reading. Its reasoning is textual: Congress used the word “departure” without defining it, did not write an advance parole exception into section 212(a)(9)(B), and elsewhere in the statute showed that it knew how to address advance parole expressly when it wanted to. The Board acknowledged that treating authorised travel as a triggering departure can produce a harsh result, but concluded the text did not permit an exception.

The decision directly concerns the ten-year bar at section 212(a)(9)(B)(i)(II). Because the same word “departure” appears in the three-year provision, and because agencies had applied the Arrabally rationale to both, commentators expect the reasoning to reach the three-year bar as well.

Who is most exposed to the change

The people with the most at stake are those whose route to a green card depended on the combination of an advance parole departure and a parole re-entry. Under section 245(a), an applicant for adjustment of status must have been inspected and admitted or paroled, and must be admissible for permanent residence. For someone who originally entered without inspection, returning on advance parole supplied the missing “paroled” element. After Delcarmen-Lara, that same trip may now create an inadmissibility problem that blocks the adjustment it was meant to enable.

Groups that should look closely include:

  • DACA recipients considering travel on advance parole. The respondent in the case had been granted DACA in 2013 and was paroled back into the country in January 2024.
  • Temporary Protected Status beneficiaries who travel on advance parole.
  • Adjustment applicants with any earlier period of unlawful presence, including those who entered without inspection.
  • Anyone whose longer-term immigration plan assumes a future advance parole trip will be consequence-free.

Equally important is who is not affected. If you have never accrued unlawful presence — because you were always in a period of authorised stay, or because any gaps were shorter than the statutory thresholds, or because time in certain protected categories did not count — the bars in section 212(a)(9)(B) are not triggered by a departure at all. The unlawful presence calculation is technical and highly fact-dependent, which is precisely why a case-by-case review with an immigration attorney matters more here than in most policy stories.

The ruling looks forward, not back

Because it was overruling long-standing precedent that people had relied on, the Board carried out a retroactivity analysis and held that the new rule applies prospectively. Advance parole travel completed before 13 August 2026 is not governed by Delcarmen-Lara; travel on or after that date is.

That limitation is meaningful for pending cases, and it preserves an argument that earlier trips should still be assessed under Arrabally. It is not, however, a guarantee. The exact scope of the prospective holding is the kind of question that gets refined through agency guidance and federal court litigation, and the immigration bar has already flagged it as unsettled. Commentators have also questioned whether the Board should be reworking its own favourable interpretations by invoking the Supreme Court’s move away from judicial deference, and note that federal courts remain free to read the statute independently.

What to weigh before booking a trip

There is no need for panic, and equally no room for improvisation. If you hold advance parole and have any history of unlawful presence, the sequence that makes sense is: establish the facts, get advice, then decide about travel — not the other way round.

That means building an accurate timeline of every period of status and every gap, identifying whether any gap crossed the 180-day or one-year thresholds, and checking whether periods such as deferred action or certain pending applications counted as authorised stay. A later period of authorised stay does not erase unlawful presence already accrued. Once the timeline is clear, an attorney can assess whether a departure would trigger a bar, whether a waiver route exists, and whether the trip is worth the risk. For urgent humanitarian travel the analysis may still favour going; for a holiday it rarely will.

Watch for two developments. USCIS guidance implementing the decision would clarify how officers treat both the three-year bar and pre-13 August travel. Federal litigation may test the Board’s reading of “departure” directly. Until either arrives, the safest working assumption is that the decision means what it says. The ruling itself is published by the Executive Office for Immigration Review, and a detailed practitioner analysis is available from Cyrus D. Mehta & Partners.

Reader questions answered

Does this affect everyone with advance parole?
No. It matters for people who have accrued unlawful presence. Without unlawful presence above the statutory thresholds, a departure does not trigger the three-year or ten-year bar.

What if I travelled on advance parole before 13 August 2026?
The Board held that the decision applies prospectively, so earlier trips are not governed by it. The precise scope of that holding may be clarified in later guidance or litigation.

Does the decision apply to the three-year bar as well as the ten-year bar?
The decision addresses the ten-year bar. Its reading of “departure” is widely expected to reach the three-year provision too, since agencies had applied the earlier precedent to both, but that has not been separately decided.

Can a bar be waived?
Waivers exist for the unlawful presence bars in some circumstances and depend on qualifying relatives and other criteria. Whether one is available is a case-specific legal question.

Should I cancel planned travel?
That is a decision to take with a licensed immigration attorney after reviewing your status history, not on the basis of a news summary.

Tamara News covers immigration policy across major destinations — see also our reporting on the UK’s Appendix FM family visa changes and New Zealand’s skilled migrant points settings.

USCIS Can Now Deny Applications Without Asking for Evidence

Filing an application with U.S. Citizenship and Immigration Services used to come with an informal safety net: if something was missing, officers would usually ask for it before refusing the case. That expectation no longer holds. Guidance issued on 5 August 2026 means a USCIS denial without RFE is now a realistic outcome whenever a filing arrives without the required initial evidence, or with evidence that does not establish eligibility. Officers may refuse the application or petition outright, with no Request for Evidence and no Notice of Intent to Deny first.

Documents being reviewed at an office desk, illustrating a USCIS denial without RFE under the 2026 guidance

The change came through Policy Alert PA-2026-05, which updates Volume 1, Part E of the USCIS Policy Manual. It took effect immediately and applies to benefit requests pending or filed on or after 5 August 2026, unless a regulation or another USCIS policy says otherwise.

How a USCIS denial without RFE now works

The underlying authority is not new. Regulations have long allowed officers to deny a filing that lacks required initial evidence. What changed is the instruction around that authority. Earlier policy encouraged officers to issue an RFE or a NOID before denying a case with an evidentiary gap. The revised guidance restores full discretion to deny first.

USCIS has explained the change as a response to frivolous, placeholder and substantially incomplete filings, which it says added to adjudication delays. The alert also restates a principle that has always applied but now carries more weight: the applicant or petitioner bears the burden of establishing eligibility at the time of filing and throughout the adjudication.

Three further adjustments in the same alert matter in practice:

  • Shorter response windows. Officers are not required to allow the customary maximum RFE response period and may set shorter deadlines, within the regulatory limits, case by case.
  • No extra fortnight for international mail. The previous practice of adding 14 days when a notice was mailed to someone outside the United States, or issued by an international office, has been removed. The general rule of a few additional days for service by mail applies instead.
  • Partial responses count as final. Sending back some but not all of what an RFE or NOID asked for will ordinarily be treated as a request for USCIS to decide the case on the record as submitted.

What the guidance leaves untouched

It is worth being precise about the limits of this change, because early commentary has sometimes overstated it.

RFEs and NOIDs have not been abolished. Officers keep the discretion to issue them, and practitioners expect them to remain common in complex employment-based filings where the question is one of degree rather than a missing document. The guidance does not create a new ground of ineligibility, and it does not change the substantive legal standards for any benefit. It also does not override situations where a regulation or a separate USCIS policy requires a notice before denial.

What it does remove is the assumption that a thin filing will be met with a request rather than a refusal. For applicants who submit complete, well-documented cases from the outset, the practical effect should be limited. For anyone who has treated the initial filing as a first draft, the risk profile has shifted considerably — and a denial costs the filing fee, the processing time, and in some categories the underlying status or work authorisation.

How filings should be prepared now

None of the following is legal advice for a particular case, and readers with anything unusual in their history should consult a licensed immigration attorney. But the general implications are straightforward.

  • Check the form instructions and the required initial evidence list for the specific edition of the form being filed, and include every listed item. Omissions that once drew a request may now draw a refusal.
  • Do not file to hold a place while documents are gathered. A placeholder filing is exactly what the guidance targets.
  • Explain the evidence rather than leaving officers to infer eligibility. Where a required document genuinely does not exist, address that in a cover letter with secondary evidence rather than staying silent.
  • If an RFE does arrive, read the deadline carefully rather than assuming the maximum period, and begin gathering material immediately. Applicants outside the United States should assume less mail time than before.
  • Respond in full. A partial response invites a decision on an incomplete record.

Documentary rigour is becoming the norm across major destinations, not only in the United States; readers comparing systems may find our explainer on proof of funds requirements in the UK, Canada and Australia a useful parallel, alongside our coverage of the UK’s Appendix FM family visa changes.

Where this leaves applicants and employers

The immediate effect is on filings already in the queue, because the guidance reaches benefit requests pending on 5 August 2026 as well as those filed afterwards. Anyone with a case in progress that was assembled on the older assumption may want to review it with counsel and consider whether to supplement the record before an officer reaches it.

For employers, the practical work is process work: build longer evidence-gathering time into filing calendars, avoid last-minute submissions timed to a deadline, and make sure someone is monitoring the post so a shortened RFE deadline is not missed. For individuals, the calculation is similar on a smaller scale. Watch, too, for how the guidance is applied in practice over the coming months — denial rates and the tone of adjudications will show whether this is a modest recalibration or a substantial tightening. The primary sources are the USCIS Policy Manual, Volume 1, Part E and the American Immigration Lawyers Association’s summary of the policy alert.

Common questions about the new guidance

When did the guidance take effect?
5 August 2026. It applies to benefit requests pending on that date or filed on or after it, unless a regulation or another USCIS policy provides otherwise.

Does this mean RFEs have been abolished?
No. Officers retain discretion to issue Requests for Evidence and Notices of Intent to Deny. The guidance removes the expectation that one will be issued before a denial.

Which filings are affected?
The guidance sits in the general evidentiary part of the Policy Manual, so it reaches benefit requests broadly rather than a single visa category, subject to any regulation or policy that requires notice in a specific context.

Can a denial be challenged?
Depending on the benefit type, options can include a motion to reopen or reconsider, an appeal, or refiling. Which of these is available and sensible is case-specific and worth discussing with an attorney promptly, because deadlines are short.

Has the RFE response deadline changed?
Officers may now set shorter response periods within the regulatory limits rather than defaulting to the maximum, and the extra 14 days previously allowed for notices sent internationally has been removed.

For more on how documentation rules are tightening elsewhere, see our coverage of Canada’s French-language Express Entry draws.

AI Infrastructure Debt Balloons as Chipmakers Turn to Bond Markets

AI infrastructure debt has become the default way to pay for the computing build-out, and August 2026 made the shift hard to miss. AMD priced the largest bond sale in its history. Broadcom entered talks for a financing package that people familiar with the discussions put at between 60 and 100 billion dollars. Nvidia announced arrangements with six of the world’s biggest banks and asset managers to mobilise more than 500 billion dollars of third-party capital. Taken together, the month marked the point at which chipmakers stopped funding AI capacity mainly out of retained earnings and started funding it in credit markets.

That change of funding source is not a technicality. It alters who bears the risk if demand for AI computing arrives later or smaller than the spending assumes.

How AI infrastructure debt became the default funding tool

For most of the past decade the largest technology companies were asset-light. Software and scalable cloud services required modest capital investment relative to the cash they generated, and buybacks rather than bond issues were the story investors followed.

Moody’s describes the current period as a transition from asset-light to asset-heavy models requiring unprecedented capital raising, and projects capital expenditure across the group reaching about 785 billion dollars in 2026 and approaching a trillion dollars in 2027.

Cash flow, however strong, does not stretch that far on that timetable, so the money is coming from bond markets. S&P Global counted 225 billion dollars of bonds issued by hyperscalers and related entities including Nvidia in the first half of 2026, a rise of roughly 974 percent, and put the group on pace for about 400 billion dollars across the full year.

S&P also flagged signs of indigestion: issuers are paying a wider premium over risk-free yields, and market participants are growing wary of quickly rising leverage from companies previously known for reliable cash flow.

The deals that reset the scale of borrowing

AMD priced 4.75 billion dollars of investment-grade notes on 13 August 2026, its largest dollar bond offering, across four tranches with maturities from three to ten years. It was more than triple the 1.5 billion dollars the company raised in March 2025. AMD has said the proceeds are for general corporate purposes, which may include repaying existing debt, rather than earmarking them for AI projects.

Broadcom’s financing is larger and less settled. Bloomberg reported on 20 August that the company was in talks with lenders to raise more than 60 billion dollars for an AI chip deal serving Anthropic and other customers, with Blackstone and Apollo among the asset managers involved. CNBC reported the next day that the package was expected to reach upwards of 70 billion dollars, with accounts of a junior tranche taking the total towards 100 billion. The figures come from people familiar with the talks; terms are not final.

Nvidia’s approach is different again. On 10 August the company announced memorandums of understanding with Apollo, BlackRock, Blackstone, Brookfield, Goldman Sachs and KKR to establish compute financing platforms intended to mobilise more than 500 billion dollars of third-party capital over time. This is Nvidia’s own description of arrangements still subject to final agreements. If executed, they would channel institutional capital towards buyers of Nvidia hardware rather than onto Nvidia’s own balance sheet.

Foundry spending follows the same logic. TSMC issued 18.4 billion New Taiwan dollars of unsecured domestic bonds in May 2026, against board-approved capital appropriations of about 21 billion dollars for advanced machinery and capacity.

Financial market trading screens tracking the bond issuance behind AI infrastructure debt

Where the risk sits

Three features of this wave concern analysts more than the headline totals.

The first is what does not appear as debt. A study by Nikkei found that so-called hidden debt at five large US technology companies has grown roughly eightfold in four years to 1.65 trillion dollars, exceeding the 1.35 trillion dollars sitting on their balance sheets. These are long-term purchase commitments for chips and servers, and leases with data centre operators. They are legitimate under accounting rules and usually disclosed in the notes to financial statements, and much will convert into recognised obligations as facilities open. Moody’s separately put such arrangements at about 1.2 trillion dollars, more than 820 billion of it tied to data centres still under construction.

The second is circularity. Moody’s has pointed to a loop in which large technology firms invest billions in AI labs that then spend heavily on cloud computing from those same investors, so reported backlogs partly reflect capital the seller supplied. The Bank for International Settlements named opaque circular financing, alongside an AI capital spending bust and sovereign debt fragility, among the pressures identified in its 2026 annual economic report.

The third is crowding. Borrowing on this scale competes with government issuance at a moment when the US federal deficit is heading towards roughly two trillion dollars and the Federal Reserve is no longer a large buyer of Treasuries. RSM chief economist Joseph Brusuelas wrote in July that demand for both kinds of debt remains strong, “yet that will not endure indefinitely,” and that “at some point, the rivers of capital financing private and government debt issuance will flow less freely.”

None of this amounts to a distress call. Moody’s has been explicit that hyperscalers still hold some of the most robust balance sheets in the corporate world and that their investment-grade ratings face no imminent risk. The change is in the shape of the exposure, not its immediate severity.

What comes next for lenders and investors

The mechanical difference between funding capacity from earnings and funding it with borrowings is timing. Retained earnings absorb a disappointing year quietly: spending slows, and nothing is owed. Debt offers no such flexibility. Coupons and maturities fall due on fixed dates whether or not the servers financed are earning their keep.

Depreciation is a second pressure. The useful-life assumptions applied to AI accelerators are a live debate, and shorter lives mean higher charges against earnings just as interest costs rise.

Watch three things over the coming quarters. Spreads on new technology issuance show whether investor appetite is holding. Quarterly filings show how fast purchase commitments and leases convert into recognised liabilities. And the terms emerging from the Broadcom and Nvidia structures will decide whether compute-backed lending becomes a standing asset class.

Further down the chain, the shift is felt as pricing: financing costs embedded in compute contracts eventually reach the businesses renting capacity, a consideration for firms weighing where to base operations, a theme examined in our guide to UAE free zone and mainland business structures. The spread of AI tools into everyday operations, covered in our reporting on AI customer support for small businesses, is what the borrowing is ultimately meant to serve.

Key questions about the borrowing wave

How much have chipmakers and hyperscalers borrowed for AI in 2026?

S&P Global counted 225 billion dollars of bonds issued by hyperscalers and related entities including Nvidia in the first half of 2026, and put the sector on pace for about 400 billion dollars for the full year.

What was AMD’s August bond sale?

AMD priced 4.75 billion dollars of investment-grade notes on 13 August 2026 across four tranches, its largest dollar bond offering and more than triple the 1.5 billion dollars raised in March 2025. AMD said proceeds are for general corporate purposes.

What is meant by hidden or off-balance-sheet AI debt?

Obligations that do not appear as debt on a balance sheet, such as long-term purchase commitments for chips and servers or leases with data centre operators. A Nikkei study put these at 1.65 trillion dollars across five large US technology firms.

Are credit ratings at risk?

Moody’s has said hyperscalers still hold some of the strongest balance sheets in the corporate world and that their investment-grade ratings are not facing imminent risk, while warning that the shift to asset-heavy models requires unprecedented capital raising.

Why does funding AI with debt change the risk?

Retained earnings absorb a downturn quietly. Debt does not. Coupons and principal fall due on fixed dates regardless of whether the capacity being financed is generating revenue, and refinancing depends on markets staying open at tolerable spreads.

For more on how financial documentation requirements are tightening globally, read our analysis of proof of funds rules in the UK, Canada and Australia.

AI Credit Scoring Rules Tighten in France as EU Deadline Shifts

France’s data protection authority has put AI credit scoring rules at the centre of its supervision of consumer lending, publishing a formal recommendation in May 2026 that tells banks, credit institutions and intermediaries how creditworthiness assessments must work when algorithms drive the decision. The move lands in an unusual regulatory moment: the EU AI Act classifies credit scoring as high-risk, but the obligations attached to that classification were postponed weeks before they were due to take effect, leaving data protection law carrying the weight for the next eighteen months.

The CNIL published its recommendation on assessing solvency in credit applications on 7 May 2026, after a public consultation the previous year and discussions with the banking members of its compliance club. It replaces AU-005, the single authorisation issued in 2008 that governed the area before the GDPR.

How France polices AI credit scoring rules today

The recommendation applies to private organisations that grant credit and to banking and payment services intermediaries. It covers consumer credit and mortgage credit governed by the French Consumer Code, and focuses on processing carried out to evaluate whether an applicant can repay.

Four themes run through the text. Data must be limited to what is relevant and strictly necessary. Past repayment incidents may be considered, but the recommendation specifies which data are relevant and strengthens what applicants must be told about how that history affects a new application. Retention periods are set for application data and records of past defaults. And the conditions under which a decision may rest on fully automated processing are spelled out, with safeguards of transparency, human intervention and explainability.

The final version also settled a legal basis question. Because the Consumer Code obliges lenders to assess solvency, institutions may ground the processing in legal obligation under Article 6 of the GDPR rather than relying on consent or legitimate interest.

The CNIL published an accompanying verification checklist for data protection officers and compliance teams, and said it will check compliance through its future inspection work. Credit scoring does not appear among its announced priority inspection themes for 2026, which are recruitment, the single electoral register and sports federations.

Automated loan application terminal, the kind of channel covered by AI credit scoring rules in Europe

The court rulings that reshaped automated lending decisions

The recommendation is built on two judgments of the Court of Justice of the European Union.

In Case C-634/21, decided in December 2023, the Court found that generating a probability value about a person’s ability to service a loan can itself constitute an automated individual decision within the meaning of Article 22 of the GDPR, where the recipient of that score draws on it in a determining way. The scoring entity, not only the lender acting on the score, is therefore in scope.

Case C-203/22, decided in February 2025, addressed what a data subject is entitled to know about the logic involved. The CNIL’s reading is precise and worth stating plainly: applicants have a right to an explanation after the decision, and the institution must make sure they understand their individual situation. That does not mean handing over a copy of the algorithm. It means a concise and comprehensible account of the mechanism that produced the outcome.

Why the AI Act’s documentation duties slipped to 2027

Annex III, point 5(b) of the EU AI Act classifies AI systems used to evaluate the creditworthiness of natural persons, or to establish their credit score, as high-risk. That classification carries a substantial package: risk management, data governance, technical documentation under Article 11, transparency towards deployers, human oversight, accuracy and robustness requirements, and registration in the EU database.

Those obligations were originally due from 2 August 2026. They no longer are. Regulation (EU) 2026/1744, the AI Omnibus, was published in the Official Journal on 24 July 2026 and entered into force on 27 July, moving standalone Annex III high-risk obligations to 2 December 2027 and Annex I embedded systems to 2 August 2028. The Article 50 transparency duties were not deferred and applied on schedule.

The practical effect for lenders is a sequencing problem rather than a reprieve. Technical documentation for a scoring model is not produced at the end; it depends on records of training data, validation results, performance monitoring and design choices captured while the model is built and run. Firms treating December 2027 as the start date will be reconstructing evidence retrospectively.

Meanwhile the GDPR obligations bind now, and they are not thin. Article 22, the transparency duties, data minimisation and the right to an explanation apply to automated scoring today, with or without the AI Act layered on top.

Who supervises what, and where the gaps are

France has not finished designating its AI Act authorities. A scheme published by the French directorates for enterprise and for competition, consumer affairs and fraud control proposes a decentralised model in which the DGCCRF serves as coordinating market surveillance authority and single point of contact under Article 70, with sectoral regulators including the CNIL and Arcom covering specific use cases. The proposal awaits adoption.

France is not unusual. Member states had to designate market surveillance and notifying authorities by 2 August 2025. As of mid-2026, on the Future of Life Institute’s tracker, nine had designated both, twelve had partial arrangements and six had designated neither.

Under the AI Omnibus, national authorities retain competence over AI systems used by financial institutions, so credit scoring supervision stays national.

What to watch over the coming months

Three dates shape the next phase. November 2026 brings the French legal authorisation for fully automated consumer credit decisions into application. December 2026 ends the AI Act’s marking grace period for generative systems already on the market. December 2027 is when the Annex III high-risk package, including Article 11 documentation, finally applies to credit scoring.

In between, the signal to watch is inspection activity. The CNIL has said it will verify compliance through its ordinary control work rather than a dedicated campaign, which means enforcement is more likely to surface through complaint-driven investigations and sanctions than through an announced sweep. Applicants refused credit by an automated process now have a clearly articulated right to an explanation, and complaints are the mechanism most likely to test it.

Lenders operating across borders face a further complication: the supervisory map differs by member state, so the same model may be examined by a data protection authority in one country and a market surveillance body in another. The same documentary discipline applies to anyone assembling financial evidence for regulated processes, a point covered in our guide to proof of funds requirements in the UK, Canada and Australia.

Questions readers are asking about automated lending

What did the CNIL publish on credit scoring in 2026?

On 7 May 2026 it published a recommendation on assessing creditworthiness in credit applications. It applies to private lenders and to banking and payment services intermediaries, covers consumer and mortgage credit under the French Consumer Code, and replaces the pre-GDPR authorisation known as AU-005.

Is credit scoring classified as high-risk under the EU AI Act?

Yes. Annex III, point 5(b) covers AI systems used to evaluate the creditworthiness of natural persons or establish their credit score. The obligations attached to that classification, including the Article 11 technical documentation duty, now apply from 2 December 2027.

What did the Court of Justice decide about automated credit decisions?

In Case C-634/21 the Court held that producing a probability score can itself amount to an automated decision under Article 22 of the GDPR where the score plays a determining role. Case C-203/22 addressed the right to an explanation of the logic involved.

Do applicants have a right to see the algorithm?

No. The CNIL is explicit that the right to an explanation does not mean handing over a copy of the algorithm. Institutions must give a concise, comprehensible explanation that lets the applicant understand their individual situation.

Which authority supervises AI systems in France?

France has not completed its designation. A published scheme proposes a decentralised model with the DGCCRF as coordinating market surveillance authority and single point of contact, and the CNIL and Arcom among sectoral authorities.

What changes for French lenders in November 2026?

The recommendation anticipates a legal authorisation, applying from November 2026, for fully automated decisions on consumer credit, together with the safeguards attached to it.

Related reading on European regulators acting against financial platforms is available in our coverage of the Noones shutdown and EU sanctions on user funds.

EU AI Act Transparency Rules Bite as High-Risk Deadline Slips

The EU AI Act transparency rules became enforceable across the European Union on 2 August 2026, requiring companies to tell people when they are dealing with a machine, to mark AI-generated audio, images, video and text in a machine-readable format, and to label deepfakes. The same date had long been billed as the moment the Act’s heavier obligations for high-risk systems would bite. That did not happen. A separate regulation adopted weeks earlier pushed those duties back by more than a year, leaving Europe with a narrower set of requirements that are nonetheless binding right now.

The distinction matters, because the two tracks are often described together and they have now separated. Disclosure duties apply today, to any provider or deployer within scope, regardless of how the underlying system is classified. The documentation, risk management and human oversight obligations attached to high-risk classification do not.

What the EU AI Act transparency rules actually require

Article 50 of the Act sets out three groups of duties, and none of them depend on a risk classification.

First, providers of AI systems designed to interact directly with people, such as chatbots and virtual assistants, must ensure that individuals are informed they are interacting with an AI system, unless that is obvious from the context to a reasonably well-informed person.

Second, providers of systems that generate synthetic audio, image, video or text must mark the outputs in a machine-readable format that allows them to be detected as artificially generated or manipulated. Deployers who produce or manipulate content that constitutes a deepfake of real persons, places or events must disclose that the content is artificial. A parallel duty applies to AI-generated or manipulated text published to inform the public on matters of public interest.

Third, deployers of emotion recognition and biometric categorisation systems must inform the people exposed to them and process any personal data in line with EU data protection law. Narrow exceptions apply where such systems are permitted by law to detect, prevent or investigate criminal offences.

Breaches fall under Article 99(4), which provides for administrative fines of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. Enforcement sits with national competent authorities rather than with Brussels.

Two supporting instruments arrived shortly before the deadline. The European Commission adopted final guidelines on transparency obligations on 20 July 2026. A voluntary Code of Practice on Transparency of AI-generated Content, published in June, was confirmed by the Commission and the AI Board as an adequate route to demonstrating compliance; the Commission has said roughly 190 organisations had signed it by the end of July. Signing creates no new legal duty and does not displace the obligation in the Regulation itself.

One narrow carve-out survives. Providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement in Article 50(2). Everything else applied on the day.

Why the high-risk deadline moved to December 2027

The instrument responsible is Regulation (EU) 2026/1744, known as the AI Omnibus. It was published in the Official Journal on 24 July 2026 and entered into force on 27 July, days before the deadline it amended.

The central change is timing. Obligations for standalone high-risk systems listed in Annex III, which cover recruitment, credit scoring, education, law enforcement, border control and critical infrastructure, now apply from 2 December 2027. High-risk AI embedded in products already regulated under Annex I product safety legislation, such as medical devices and lifts, applies from 2 August 2028.

The Omnibus made other adjustments. The AI literacy duty in Article 4 was softened, database registration was streamlined for systems assessed as not high-risk, and the post-market monitoring template became voluntary guidance. It also added a prohibition on AI systems generating non-consensual intimate imagery and child sexual abuse material, carrying fines of up to 35 million euros or 7 percent of worldwide turnover from 2 December 2026.

Governance shifted too. The European AI Office, rather than national regulators, now holds direct supervisory authority over AI systems built on general-purpose AI models by the same provider, and over AI features embedded in very large online platforms designated under the Digital Services Act.

Chatbot conversation on a smartphone screen, the kind of system covered by the EU AI Act transparency rules

Who is actually enforcing the new duties

Enforcement depends on national authorities, and the map is incomplete. Member states were required under Article 70 to designate a market surveillance authority and a notifying authority by 2 August 2025. Many did not.

According to the AI Act implementation tracker maintained by the Future of Life Institute, updated in June 2026, nine member states had designated both authorities, twelve had pending legislative proposals or had appointed only one, and six had designated neither. Fundamental rights authorities under Article 77 are in better shape: all 27 member states have published those.

France illustrates the pattern. A published scheme proposes a decentralised model, with the DGCCRF acting as coordinating market surveillance authority and single point of contact and sectoral regulators handling specific use cases. It has not completed its passage. Germany’s federal cabinet adopted a draft AI market surveillance bill in February 2026 naming the Bundesnetzagentur, but that text still requires approval by both chambers.

The obligations therefore bind companies everywhere in the single market from 2 August 2026, while the machinery for policing them is uneven. The Regulation is directly applicable, and where authorities exist they can act, so early enforcement is likely to be concentrated in the jurisdictions that finished their preparations.

Companies running customer-facing assistants are among the most immediately exposed, since chatbot disclosure is the simplest duty to check and the easiest to fail. Our earlier reporting on AI customer support on WhatsApp and Instagram sets out how quickly those tools have spread through small businesses.

The road ahead for AI compliance in Europe

The next fixed date is 2 December 2026. The marking grace period for pre-existing generative systems ends, so legacy tools must carry machine-readable provenance signals, and the new prohibition on nudification tools and CSAM-generating systems begins to apply at the Act’s highest penalty level.

After that, 2 August 2027 is the deadline for member states to establish AI regulatory sandboxes. Commission guidance on post-market monitoring is due by 2 September 2027. The deferred Annex III high-risk obligations arrive on 2 December 2027, and the Annex I obligations on 2 August 2028.

For businesses outside Europe, the reach is the familiar one. The Act applies to providers placing systems on the EU market and to deployers established in the Union, wherever the developer sits. A chatbot built anywhere that serves European users falls within scope.

Common questions about the new obligations

Which EU AI Act obligations became enforceable on 2 August 2026?

The transparency duties in Article 50. Providers of AI systems that interact directly with people must make clear users are dealing with a machine unless it is obvious from context. Providers and deployers of systems generating synthetic audio, image, video or text must mark those outputs in a machine-readable format, and deployers must disclose deepfakes of real people, places or events.

Did the high-risk AI system rules take effect on the same date?

No. Regulation (EU) 2026/1744, the AI Omnibus, entered into force on 27 July 2026 and moved the obligations for standalone high-risk systems listed in Annex III to 2 December 2027. High-risk AI embedded in products regulated under Annex I moves to 2 August 2028.

What are the penalties for breaching the transparency duties?

Article 99(4) sets administrative fines of up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher. National competent authorities enforce them.

Is there a grace period for existing generative AI systems?

A narrow one. Providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking obligation in Article 50(2). The other duties applied immediately.

Does signing the Code of Practice guarantee compliance?

No. The Code is voluntary and creates no new legal duties. The Commission and the AI Board have confirmed it is adequate for demonstrating compliance with Article 50, so following it is a recognised route, but the obligation sits in the Regulation itself.

For related coverage of how European regulators are applying digital and financial rules in practice, see our report on the Noones shutdown and the handling of user funds under EU sanctions.