Short answer: the deadline you read about did move, but not the part that touches you first. Full compliance for Annex III high-risk systems now lands on 2 December 2027. The transparency duties in Article 50 started on 2 August 2026, and if you sell white label ICT software with AI features inside it, several of them are already yours to carry.
There’s been a lot of noise about this since the Digital Omnibus on AI was signed on 8 July 2026 and entered into force on 27 July. Most of the coverage landed on the headline: high-risk AI got a reprieve. That’s true, and for a lot of vendors it’s genuinely useful breathing room. The trouble is that plenty of resellers read “delayed” and filed the whole thing under next year’s problem.

The Omnibus shifted the high-risk deadlines and left the transparency rules where they were.
What actually changed, and what didn’t
The Omnibus pushed Annex III high-risk obligations from 2 August 2026 out to 2 December 2027. Annex III is the list of standalone use cases the regulation treats as consequential: biometrics, recruitment and employment decisions, education and exam scoring, credit scoring, essential services, law enforcement, border control. AI baked into regulated physical products under Annex I moved further still, to 2 August 2028.
Article 50 did not move. That’s the transparency chapter, and it has been in force since 2 August 2026. Three duties matter for most software vendors. Anyone interacting with an AI system has to be told they’re dealing with a machine rather than a person. Synthetic audio, image, video and text has to be disclosed as artificial. And deployers of emotion recognition or biometric categorisation have to inform the people exposed to it.
One more date sits between the two: 2 December 2026, when AI-generated output has to carry machine-readable marking. That’s four months away, and it’s the one I’d start scoping now, because it’s an engineering change rather than a copy change.
My honest read is that the Omnibus traded paperwork relief for reputational exposure. Conformity assessments, technical files and registration are what got deferred. The duty to be straight with people about what they’re talking to is what stayed. Those are very different kinds of obligation, and the second one is far easier for a customer or a journalist to check.
Why white label ICT software vendors sit in an awkward spot
Here’s the part that catches resellers out. The AI Act assigns duties by role, not by company size or by who wrote the code. A provider is whoever places the system on the market under their own name. A deployer is whoever uses it. Those are the two roles that carry almost all the weight.
Article 25 is where the white label model runs into that. Put your own name or trademark on a high-risk AI system already on the market, change what it’s meant to be used for, or modify it substantially, and you’re treated as the provider. The original vendor’s documentation stops being a shield at that point, because as far as the regulation is concerned the thing on the market is yours.

Rebranding is the trigger. If your logo is on the front and the AI is high-risk, the provider obligations follow.
This isn’t hypothetical for anyone selling communications software in Europe right now. AI answering, call summarisation, transcript analysis and automated agent assist have all become standard line items. If you’re reselling a white label PBX platform or a contact centre stack with those features and you’ve branded the whole thing as yours, you should assume the provider question is live rather than settled.
The good news is that most of these features aren’t Annex III high-risk to begin with. Summarising a call or drafting a reply doesn’t decide anything about a person’s rights. That keeps you out of the heaviest tier. It does not keep you out of Article 50.
The disclosures that apply to your product today
Start with the voice and chat layer, because that’s where the exposure is most obvious. If a caller reaches an AI agent, they need to know. A generic “calls may be recorded” line doesn’t cover it, and neither does burying it in terms of service. The disclosure has to reach the person at the point of interaction, in a way they’d actually notice.
The same applies to chat widgets, SMS auto-responders and email assistants. Anywhere a human might reasonably think there’s a person on the other end, say there isn’t. In practice this is a sentence of interface copy and a line in your onboarding script.
Synthetic voice needs its own treatment. Cloned or generated speech in an outbound campaign is exactly what the labelling rules were written for. If your platform lets customers upload a voice model, that’s a feature you now have compliance responsibility for, even though the customer is the one pressing send. Worth reviewing alongside how you handle consent on outbound campaign software, since the two obligations tend to land on the same team.
Emotion recognition deserves a flat recommendation rather than a balanced one: don’t ship it into workplace or education contexts at all. That use has been a prohibited practice since 2 February 2025, not a high-risk one, so there’s no compliance path and no delay to lean on. Sentiment scoring on support calls to grade agent performance is the version that gets vendors into trouble, and it’s a feature I’d cut rather than caveat. Elsewhere, if you do run emotion recognition, the people exposed to it have to be told from August 2026.
What to do in the next four weeks
Inventory first. List every place your product generates or interprets something with a model, including features your upstream vendor added that you inherited without asking for. Most resellers I’d expect to find two or three surprises in that list, usually in a component nobody on the commercial side thinks of as AI.
Then sort each item by role. For every AI feature, write down whether you’re the provider or the deployer, and why. If the answer is “it depends what the customer does with it,” that’s a contract question you want settled in writing before a regulator asks. Your reseller agreement should say who holds which obligation, and a surprising number of white label agreements written before 2025 say nothing at all.
Fix the interface copy after that. Disclosure notices are cheap, and they’re the single most visible thing an auditor or a customer can check in thirty seconds. Getting them wrong looks careless in a way that documentation gaps don’t.
Last, put the December 2026 watermarking date in your roadmap now rather than in November. Machine-readable marking of generated output touches storage and delivery, not just the front end. Teams that treat it as a labelling task tend to discover late that it isn’t one.
The commercial angle nobody mentions
There’s an upside here that’s easy to miss while everyone’s reading the regulation defensively. Your customers are asking the same questions you are, and most of them have no idea what the Omnibus changed. A reseller who can answer “which of these features is high-risk, and what do I have to tell my users” in plain language is doing something their competitors mostly can’t.
I’d go further. For anyone selling B2B software solutions in ICT into European accounts, compliance clarity has quietly become part of the product. Enterprise buyers are already writing AI Act questions into procurement, and the vendor who has documented answers wins deals against the vendor who improvises. That’s a better reason to do this work than fear of a fine that won’t arrive for another year.
Frequently asked questions
Did the EU AI Act get delayed or not?
Partly. The Digital Omnibus on AI moved Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028. Article 50 transparency duties still applied from 2 August 2026, and the prohibited practices have been in force since 2 February 2025.
Does the AI Act apply to me if my company is outside the EU?
If your software is used by people in the EU, generally yes. The regulation follows where the system is placed on the market and where the output is used, not where you’re incorporated. Non-EU providers may also need an authorised representative in the EU.
Am I a provider or a deployer when I white label someone else’s AI?
You’re a deployer if you use it as supplied. You become the provider if you put your own name or trademark on a high-risk system, change its intended purpose, or substantially modify it. Selling it on under the vendor’s brand without changing it usually keeps you a distributor.
Is an AI voice agent on a phone line high-risk under the AI Act?
Usually not on its own. Answering, routing and summarising calls doesn’t fall inside Annex III. It still needs Article 50 disclosure, so the caller has to be told they’re speaking to an AI system. The classification changes if the same system starts making decisions about employment, credit or access to services.
What are the penalties for getting transparency wrong?
Breaches of the transparency obligations can reach 15 million euro or 3% of worldwide annual turnover, whichever is higher. Prohibited practices carry the top tier at 35 million euro or 7%. The bigger near-term risk for most resellers is a customer audit rather than a regulator.
What should I ask my upstream AI vendor right now?
Ask for their role classification, their technical documentation, and a written statement of which obligations they carry versus which pass to you. If they can’t produce that, treat it as a signal about how ready they’ll be in December 2027.
Related resources
- White-Label ICT Software: Selling a Product Without Building One
- White-Label Software for ITSPs and MSPs in 2026
- Everyone Says the VoIP Market Is Too Crowded. For White-Label Resellers, That’s the Opportunity
- ICTCRM for white label resellers
- ICTCore communications framework
Where to go next
If you’re building a European reseller business on a rebranded stack, the roles question is worth settling before your next renewal cycle rather than after it. Have a look at the ICT Vision portfolio to see how the platforms fit together, or start with ICTPBX if multi-tenant PBX is the piece you’re adding next. Tell us what you’re planning to sell and we’ll help you work out which side of the provider line it puts you on. Open a ticket at service.ictvision.net.
