The EU’s AI Rules Arrived on Saturday. Did Your NGO Notice?
What the AI Act means for civil society from 2 August 2026 —
and why the first step is counting, not panicking
AI4NGO · For people working in civil society
Reading time: 6 minutes
Autor: Kate LUKIEN
This is the third article in an AI4NGO series for civil society. Article 1 covered adopting AI without an IT team; Article 2 covered the human skills that grow more valuable as AI arrives. This one is about the rules — because as of last Saturday, some of them apply to you.
You may have heard that the EU AI Act was delayed. That is just half of the story. In June, the EU moved the high-risk obligations — recruitment, credit scoring, education — to December 2027. Compliance projects across Europe were quietly parked, and everyone exhaled.
But on 2 August 2026 — which at the time of writing means last Saturday — a different part of the Act began to apply exactly on schedule. It concerns transparency: making sure people know when they are dealing with AI. And it applies to every organisation operating in the EU — the Act has no exemption for nonprofits.
Nothing dramatic happened on Saturday. No letters arrived, no inspectors called. That silence is exactly why this article exists – to make sure you know the new rules that will apply to your organisation.

What applies now — three things
- Article 50, the transparency rules — anyone interacting with an AI system must be able to know it is AI. Deepfakes and AI-generated text published on matters of public interest must be disclosed — unless a human has reviewed the text and carries editorial responsibility for it. Hold that last clause; it matters more to NGOs than anyone else.
- Enforcement powers over general-purpose AI models go live — the obligations for model providers have existed since 2025; the teeth arrived now.
- The penalty layer: national enforcement frameworks, with fines up to €15 million or 3% of worldwide turnover for transparency violations.
And the delayed part has a date, and it concerns our sector directly: the high-risk rules land on 2 December 2027 — covering areas like education, access to essential services, and migration and asylum. Many NGOs work exactly there. If your organisation uses AI anywhere near decisions about who receives support, sixteen months is your runway. A runway is for building, and never for waiting.
Why this concerns an NGO
more than a corporation
Map Article 50 onto a typical NGO, and three surfaces light up.
- Anything that chats. The assistant on your website, the WhatsApp bot answering beneficiary questions, the automated donor helpdesk. From Saturday, the people on the other side have a right to know they are talking to AI. The fix costs one sentence: “You are chatting with an AI assistant.”
- Anything you publish. Here is the clause built for civil society: AI-generated text on matters of public interest must be disclosed. Advocacy is, by definition, a matter of public interest. The campaign post, the policy statement, the appeal — if AI drafted it and nobody reviewed it, it needs a label.
- Anything synthetic. AI-generated images and video in campaign materials — the “what this crisis could look like” visual — must be marked as artificially generated. For organisations whose currency is bearing witness, unlabelled synthetic imagery risks far more than a fine.
Now read the escape clause again: AI-written text needs no AI label if a human has reviewed it and takes editorial responsibility. If you read our previous article on human skills, this will sound familiar. The human reviewer — the colleague who reads the draft and asks is this true, and is it us? — has been good practice all along. Since Saturday, that person also changes your legal obligations. The regulator, it turns out, agrees with us about who stays at the centre.

The count your organisation probably can’t produce
Ask how many AI tools are in use across your organisation, and you will get a confident answer: the official ones. In practice the real number is far higher, and it splits into three layers.
- The sanctioned tools — the Copilot licences, the approved chatbot. Known, listed, easy.
- The half-sanctioned — the AI inside tools you already use: the design app that now generates images, the grant-writing service one team quietly pays for, the automation flow a volunteer built. Useful, invisible, and uncounted.
- The shadow layer — free chatbots on personal accounts, sometimes carrying beneficiary details in the questions people paste in. Nobody approved it and nobody is watching it.
Each tool in each layer can be a disclosure surface, a data risk, or both. One more thing: the Act splits duties between providers (who build AI systems) and deployers (who use them). Using ChatGPT or Copilot off the shelf keeps you a deployer, with lighter duties. But when someone in your team builds a bot — names it, feeds it your documents, points it at beneficiaries — your organisation starts sliding toward the provider side for that system, with heavier duties attached. It happens one enthusiastic afternoon at a time, and it never looks like building software.
Funders are starting to notice too. AI questions are appearing in due-diligence checklists, and “we don’t really know what we use” is an answer that costs trust with the people who fund you.
Practical action —
count first
Skip the gap assessment and the policy retreat for now. Start with a number. One week, four steps:
- 1 → Ask everyone. A 15-minute survey to all staff and regular volunteers: which AI tools do you use for work — free or paid, on any device? Promise amnesty and mean it. You are counting, and nobody is being punished.
- 2 → Walk your public surfaces. Website, social channels, WhatsApp, newsletters. Where does AI talk to the public, and where does AI-made content get published? Each spot needs either a label or a human editor.
- 3 → Give every tool a passport. One line each: what it is, who owns it, what data it touches, who it talks to. A tool with no name next to it is your first fix — the same rule we gave for AI use cases in Article 2.
- 4 → Add the two sentences. “You are chatting with an AI assistant” wherever a bot meets a person. And a human review step before AI-drafted text goes public — which, under Article 50, also removes the labelling duty. Two sentences of effort, most of the compliance.
In our experience, the number does the persuading for you. A leadership team that discovers the organisation runs thirty AI tools, five of them with owners, does not need a second workshop on why governance matters.

In closing
For a company, the worst case on Saturday’s rules is a fine. For an NGO, the worst case arrived earlier and costs more: the beneficiary who discovers the “counsellor” was a bot, the donor who learns the appeal was machine-written and unread by any human. Regulation sets the floor here — the sector’s own standard of trust sits higher, and it always did.
The deferral bought organisations sixteen months on the high-risk rules. The transparency rules are already here, and they are the cheapest compliance your organisation will ever do: a sentence on your chatbot, a human before the publish button, a one-page list of what you actually use.
Don’t panic. Don’t relax either. Count.
This is practitioner analysis, not legal advice — for your organisation’s specific obligations, involve counsel.
How AI4NGO can help
If your organisation wants a hand with any of this, two offers from our portfolio map directly to it: the P2 Leadership Workshop, where your leadership team decides where AI belongs and where the human decision stays in the room, and G4 Steering & Ownership, a light governance model that names an owner, a purpose and a review rhythm for every AI use case — the “passport” from this article, done properly.
Reach out at info@ai4ngo.org or visit advisory.
Sources referenced in this article
- Regulation (EU) 2024/1689 (AI Act) — EUR-Lex
- Council of the EU, 29 June 2026 — final approval of the Digital Omnibus
- Article 50 — full text, AI Act Explorer
- EC AI Act Service Desk — implementation timeline
- Jones Walker — Yes, August 2 Still Matters: transparency obligations remain
- McCann FitzGerald — Article 50 transparency compliance analysis
- European Commission — AI Act policy page
