4 days to comply, β¬15M of exposure β how the EU AI Act reached our Singapore product team on 2 August

William
Product & Engineering Advisor, APAC Β· August 6, 2026
Most of the coverage in late July said the EU had delayed the AI Act. That was true, and it was also the most expensive half-sentence of the summer. The high-risk obligations moved to December 2027. The transparency obligations landed on schedule, on 2 August 2026 β and they apply to us, from Singapore.
TL;DR
- β’ On 2 August 2026, the EU AI Actβs Article 50 transparency obligations became generally applicable and enforceable by national authorities.
- β’ The same date gave the Commission and AI Office enforcement powers over general-purpose AI, with fines up to β¬15 million or 3% of worldwide annual turnover, whichever is higher.
- β’ The AI Omnibus (in force 27 July 2026) deferred high-risk Annex III obligations to 2 December 2027 β that is the part that was delayed, and only that part.
- β’ For Singapore teams: scope follows the EU market, not your registered address. If your product talks, generates or infers for EU users, you are in.
What actually applies now β the split that matters
The AI Act was always going to arrive in layers. What made this summer confusing is that two of those layers moved in opposite directions within a single week.
Deferred: the AI Omnibus came into force on 27 July 2026 and pushed obligations for standalone high-risk systems in Annex III use cases β employment and worker management, creditworthiness assessment, education, and access to essential services β from 2 August 2026 out to 2 December 2027.
Not deferred: Article 50. From 2 August 2026, if your system interacts with people, generates image, audio, video or text, or infers emotions or biometric categories, the disclosure duties apply β regardless of whether the system is classified high-risk. National competent authorities across the Union can enforce them now.
Alongside that, the Commission and the AI Office acquired their powers over general-purpose AI obligations on the same date: to investigate, to conduct inspections, to accept binding commitments, and to impose fines of up to β¬15 million or 3% of total worldwide annual turnover, whichever is higher.
Expert view 1 β scope follows the market, not your address
The first question every Singapore founder asks is whether this reaches them at all. It does, on the same principle that made GDPR a Singapore problem a decade ago: the regulation attaches to placing a system on the EU market or to output used within the EU, not to where the provider is incorporated.
In practice that means the trigger is your customer list, not your company registration. If you have European users on a product with a chat interface, a generative feature, or anything that scores or categorises people, you are in scope for the Article 50 duties as of last week.
What being outside the Union changes is enforcement practicality, not legal applicability. That is a genuinely different risk profile, and it would be dishonest to pretend a Singapore SME faces the same near-term enforcement probability as a Frankfurt one. But the exposure is real, it is contractual as much as regulatory, and it surfaces the moment an EU enterprise customer sends you a vendor questionnaire.
Expert view 2 β this is an engineering task, not a legal one
The instinct when a regulation lands is to route it to legal or to buy a compliance platform. Article 50 resists both, because the obligations are discharged in the product interface.
Three concrete implementations cover most of it. Disclosure on interaction: a user talking to an AI system must be able to know that. Marking of synthetic content: generated image, audio, video and text must be marked in a machine-readable way, which is a format and pipeline decision, not a policy one. Notice for emotion and biometric inference: people subject to it must be informed.
Each of these is a ticket in your backlog. None of them can be satisfied by a document. And the one that consistently takes longest is machine-readable marking, because it touches every generation path in the product β including the ones nobody remembered existed, like the summary text in email notifications.
The fourth piece is evidence: logging that shows the disclosure was actually presented. Without it you can be compliant and unable to demonstrate it, which in a customer audit is nearly the same as not being compliant.
Need engineers who can ship disclosure, not just document it?
We place Singapore-based engineers with practical AI governance experience β people who have implemented content marking and audit logging in a live product, not read about it.
Letβs talkExpert view 3 β the hiring consequence is specific, and it is not "hire a compliance person"
Singapore market reporting through 2026 has consistently flagged growing demand for AI governance and cybersecurity capability alongside conventional software engineering. This regulation is one of the concrete mechanisms behind that trend, but the demand it creates is narrower than the phrase "AI governance" suggests.
What teams actually need is an engineer who can hold two things at once: the product surface where disclosure has to appear, and the evidence trail that proves it did. That person sits in the engineering team, not next to it. Hiring a compliance specialist without that engineering counterpart produces a well-written policy and an unchanged product.
The wider context here is that Singaporeβs tech labour market has been restructuring rather than simply contracting β August 2026 layoff tallies were modest at around 155 employees across 5 companies, against a much heavier July, with restructuring concentrated in engineering and product. In that environment, capability that is newly scarce and clearly scoped gets absorbed fast. Regional teams face the same pull: colleagues at HireDeveloper.ae report it in the UAEβs AI ecosystem buildout, and JapanDev sees comparable demand for engineers who can work across product and governance in Tokyo.
What we did in four days, and what we left
Day one: inventory the generation paths. We found eleven places the product produces text or images for a user. Four were undocumented. This is the step that takes longest and the one you cannot skip.
Day two: interaction disclosure. Straightforward β a persistent label in the chat surface and in two embedded assistants. Half a day of work, most of it design review.
Day three: logging. We added an event recording that the disclosure was rendered, tied to session and version. Unglamorous, and the thing an EU customerβs auditor will ask for first.
Day four: marking, partially. We covered the primary generation paths and documented the remaining three as a scheduled item rather than pretending they were done. Writing down what is not yet covered β with a date β is a materially better position than an unqualified claim of compliance.
Frequently Asked Questions
Does the EU AI Act apply to a company based in Singapore?+
What exactly became applicable on 2 August 2026?+
Were the high-risk obligations not supposed to start on the same date?+
Does this change what engineers a Singapore team should hire?+
"The AI Act was delayed" cost teams four days of notice.
If your product ships AI features into Europe from Singapore, we can put engineers on your team who have already implemented this β disclosure, marking and the audit trail behind it.
Letβs talk