The EU AI Act's August 2026 Deadline and AI Meeting Notetakers: What Employers Must Do Now

Published September 01, 2026

Key takeaways

Quick answer: As of 2 August 2026, the EU AI Act's Article 50 transparency rules and full penalty regime are enforceable, and workplace monitoring systems remain classified as high-risk under Annex III. Employers deploying cloud AI notetakers like Otter, Granola or Fireflies must disclose AI interaction to participants, document processing, and — where the tool scores or monitors workers — meet Article 26 deployer duties or face fines up to €15 million or 3% of global turnover.

Published September 1, 2026 · Basil AI Editorial

On 2 August 2026, the transparency obligations under Article 50 of the EU AI Act, the enforcement powers over general-purpose AI models, and the full penalty regime genuinely started to bite. For any company deploying AI meeting notetakers across the EU — Otter, Fireflies, Granola, Zoom's AI Companion, Microsoft Copilot, or dozens of smaller vendors — the compliance calculus fundamentally changed that day. This article is a plain-English, employer-facing map of what the law actually requires, where cloud AI notetakers create exposure, and what an on-device architecture removes from the risk picture.

What actually became enforceable on 2 August 2026

The most persistent misconception in the market is that the EU AI Act was "pushed back to 2027." That is partially true and mostly wrong. Under the Digital Omnibus package published on 19 November 2025 and the resulting Regulation, the stand-alone high-risk obligations under Annex III were deferred to 2 December 2027, and the embedded high-risk rules under Annex I to 2 August 2028. But as the Software Improvement Group's August 2026 update makes clear, the delay applies only to the heaviest conformity-assessment machinery — not to the transparency, GPAI, and penalty rules that took effect on schedule.

The Pearl Cohen guidance published ahead of the enforcement date is explicit: Article 50, which requires disclosure of AI interactions, labelling of synthetic content, and deepfake identification, became directly enforceable in August 2026. So did the transparency obligations that map onto every AI notetaker use case: users of an AI system that interacts with natural persons must be informed they are interacting with AI unless it is obvious from context.

The Digital Omnibus did not touch Article 50

According to the DLA Piper GENIE analysis, the second political trilogue on 28 April 2026 confirmed the deferral scope: high-risk stand-alone systems get more time, but organisations deploying AI in employment contexts should continue compliance preparation on the original operational assumptions. The Article 50 transparency layer, the general-purpose AI provisions, and the market surveillance and penalty framework all landed on 2 August 2026 without deferral.

Where AI meeting notetakers sit in the risk taxonomy

The AI Act is structured as a pyramid: prohibited practices at the top, high-risk systems below them, limited-risk (transparency-only) below that, and minimal risk at the base. AI meeting notetakers can sit in three of those four tiers simultaneously depending on how they are configured and deployed.

Prohibited: workplace emotion recognition

The rules banning unacceptable-risk AI have already been in force since 2 February 2025. The PeopleGrip HR compliance guide is blunt about the practical consequence: any AI tool that infers employees' emotional states from voice patterns, facial expressions, or physiological signals is prohibited in EU workplaces and educational settings. If your notetaker offers "sentiment scoring," "engagement analytics," or "mood detection" as a module, that module is now illegal in the EU — even as an optional feature.

High-risk: worker monitoring under Annex III

The Act classifies AI used for recruitment, candidate selection, performance evaluation, task allocation, monitoring of workers, and decisions on promotion or termination as high-risk. As HR Executive reported, this is precisely where AI notetakers with productivity scoring or sentiment analytics land — and multinational HR teams deploying them will inherit the deployer obligations under Article 26, even if the stand-alone conformity assessment is deferred to 2027.

Limited-risk: transparency-only transcription

A tool that only transcribes and summarises meetings, without behavioural inference, sits in the limited-risk tier — but still faces Article 50: participants must know AI is in the room. That is not an abstract obligation. It maps directly onto the same consent question at the heart of the U.S. wiretap cases discussed below.

The transatlantic parallel: Otter, Fireflies and Granola

European employers who think the AI notetaker consent problem is a purely EU story should read the U.S. docket. The consolidated In re Otter.AI Privacy Litigation (5:25-cv-06911-EKL, N.D. Cal.) bundles four putative class actions filed between August and September 2025. Otter's own December 2025 press release put the service at more than 35 million users and over a billion meetings processed — meaning the class is enormous and damages exposure is measured in the billions.

Then, on 30 July 2026, Granola was sued in the same Northern District of California in Chamberlain v. Granola, Inc., No. 3:26-cv-07926. The complaint attacks the "bot-free" model directly: Granola captures audio from both the microphone and the system audio output, transcribes everyone on the call in real time, and — per the filing — uses those captures for AI model training by default. As the National Law Review analysis notes, Granola's own privacy policy admits that data incorporated into models cannot be extracted once training is complete.

The plaintiff-side theory in these U.S. cases — that participants who never consented had their communications intercepted and repurposed for training — is a functional twin of the EU Article 50 disclosure duty. If you cannot lawfully record a Californian without all-party consent, you almost certainly cannot lawfully transcribe an EU participant without Article 50 disclosure either. Our deep dive on Chamberlain v. Granola traces the seven causes of action; the analysis of the May 2026 Otter hearing covers the wiretap theory.

Employer liability: why this is not just a vendor problem

The uncomfortable truth for HR and compliance leaders is that AI notetaker liability increasingly attaches to the deployer, not just the vendor. As the HR Executive analysis of Littler Mendelson's guidance notes, data transfer is a compounding issue because recordings processed by U.S.-based vendors must comply with international transfer mechanisms such as Standard Contractual Clauses. And in co-determination countries like Germany and France, deploying an AI notetaker may require works council consultation before rollout — a requirement multinational HR teams frequently overlook.

The SocialTalent overview of the consent-design theory adds another wrinkle: speaker-identification features that attribute transcript lines by voiceprint may separately trigger biometric privacy laws. In the EU, biometric identifiers fall under Article 9 GDPR as special-category data requiring explicit consent or another narrow lawful basis; in Illinois, they trigger BIPA at $1,000 for negligent and $5,000 for intentional violations. Either way, the employer signing the vendor contract sits in the liability chain.

Comparison: cloud AI notetakers vs on-device under the EU AI Act

Dimension Cloud notetaker (Otter, Fireflies, Granola, Zoom AI, Copilot) On-device (Basil AI on Apple Silicon)
Processing location Vendor servers, often outside EU Local device (iPhone, iPad, Mac)
Article 50 transparency duty Applies; often unmet for non-host participants Applies; disclosure is a workflow choice, not a vendor limitation
Standard Contractual Clauses required Yes, for US processing Not applicable — no cross-border transfer
Default training on customer data Granola alleged to train by default; Otter accused of same No cloud model to train — audio never leaves the device
Voiceprint / biometric exposure Yes if speaker ID is enabled Speaker labels processed locally; no biometric database
Works council consultation Typically required in DE / FR before rollout Still advisable but far narrower scope
Wiretap / CIPA / ECPA exposure Live litigation (Otter, Fireflies, Granola) No interception by a third party
Emotion recognition module Some vendors offer sentiment analytics — now prohibited in EU workplaces Not offered by Basil

Penalties: what non-compliance actually costs

The AI Act's penalty tiers are designed to make governance boards pay attention. Prohibited-practice violations — including deploying workplace emotion recognition — carry fines up to €35 million or 7% of global annual turnover, whichever is higher. Article 50 transparency breaches and most other general obligations carry up to €15 million or 3% of turnover. Providing incorrect information to regulators carries up to €7.5 million or 1% of turnover.

Those are the ceilings. The Cloud Security Alliance research note puts initial high-risk compliance investments at $8–15 million for large enterprises with $1–5 million in annual ongoing costs — a signal of how seriously European regulators expect the industry to take the framework, even before the ceiling fines land. Layered on top is GDPR exposure under Article 5 of the GDPR, which requires lawfulness, fairness, and transparency in any processing of personal data — a standard a silent cloud transcription bot makes structurally impossible to satisfy for non-consenting participants.

The employer checklist for AI notetakers, Q4 2026

  1. Inventory every notetaker in use, including shadow IT. The 2025 survey cited by HR Executive found one in five professionals frequently used AI to draft meeting notes — most without IT approval.
  2. Map each tool against Annex III use cases. If HR uses transcripts to evaluate performance, task allocation, or promotion, you are in high-risk territory even if the deferral pushes the conformity assessment to December 2027.
  3. Kill emotion recognition immediately. If any vendor offers sentiment scoring, disable it across the EU tenant. This is a prohibited practice, not a limited-risk one.
  4. Confirm Article 50 disclosure is built into the meeting flow. A one-time settings toggle at the account level does not disclose to a random external counterparty on a Zoom call.
  5. Check the training default. The Chamberlain complaint against Granola alleges training-on-by-default; check every current vendor's setting and turn it off, then paper the change.
  6. Consult works councils before EU-wide rollout. Germany, France, the Netherlands and others require it — and doing it late is worse than not doing it.
  7. Prefer on-device processing where the content is sensitive. For legal, HR investigations, board meetings and M&A, remove the cross-border transfer entirely.

For a wider vendor comparison, see our Granola vs Otter vs Basil privacy comparison. For the underlying architecture of what "compliant AI meeting notes" actually means as an evaluation framework, see our explainer on the four dimensions of compliant AI notes.

How Basil AI changes this analysis

Basil is an on-device AI voice recorder for iPhone, iPad, and Mac. It uses Apple's on-device Speech Recognition and the Apple Neural Engine to transcribe, summarise, and extract action items entirely on the user's device. There is no vendor server that holds the audio, no cross-border transfer, no default training pipeline, no voiceprint database, and no sentiment module. That architecture does not make Basil "AI Act compliant" — compliance is always the deployer's determination based on how the tool is used — but it removes multiple structural sources of exposure that cloud notetakers cannot remove without redesigning their product.

Specifically: because the recording never leaves the device, there is no Standard Contractual Clauses question for U.S. processing. Because there is no cloud model absorbing user meetings, there is no training-by-default problem of the kind alleged against Granola. Because speaker labels are processed locally and not stored as a persistent biometric template on a vendor server, the BIPA-style theory in the Fireflies and Otter cases does not attach in the same way. And because there is no vendor-side sentiment or engagement inference, the prohibited-practice risk under the EU AI Act's workplace emotion recognition ban is not on the table for Basil at all. Article 50 disclosure is still required — that duty attaches to the person recording, not the vendor architecture — but everything downstream of that disclosure becomes materially easier.

What to watch between now and December 2027

Three trajectories to track. First, the Judge Lee ruling in In re Otter.AI: if the motion to dismiss is denied, discovery opens and every cloud notetaker vendor inherits precedent that an AI bot can be treated as a separate party for wiretap purposes. Second, the Chamberlain v. Granola docket: the case tests whether "no bot" branding is itself evidence of deceptive design under CIPA and ECPA. Third, EU national implementing legislation — several member states are drafting AI Act supervisory frameworks that will overlay national data-protection authorities' enforcement priorities on top of the AI Act penalty regime.

The through-line across all three: the question of who consented to being recorded and analysed by AI is moving from a settings-page detail to a board-level compliance question. Employers that continue to rely on cloud notetakers with training-on-by-default settings and no built-in participant disclosure are running an uninsurable position across three legal systems at once.

Try Basil AI

Basil AI records, transcribes, and summarises meetings entirely on-device — no cloud, no training data, no voiceprint database. Try it free on iPhone, iPad, or Mac.

Download on the App Store Download on the Mac App Store

Frequently Asked Questions

Is an AI meeting notetaker a 'high-risk' AI system under the EU AI Act?

It depends on use. A tool that only transcribes is not automatically high-risk, but Annex III classifies AI used for worker monitoring, performance evaluation, or task allocation as high-risk. Vendors like Otter, Fireflies and Zoom that add sentiment analytics, productivity scoring, or speaker-attribution can push a deployment into Annex III territory, triggering Article 26 duties for the employer using them.

What changes for AI notetakers on 2 August 2026?

Article 50 transparency obligations became enforceable, requiring that people be told they are interacting with an AI system and that synthetic content be labelled. The full penalty framework and general-purpose AI enforcement powers also apply. High-risk obligations for stand-alone Annex III systems were pushed to 2 December 2027 under the Digital Omnibus, but transparency and penalty rules bite now.

Can employers in Germany or France just roll out Otter or Granola company-wide?

No. In co-determination jurisdictions like Germany and France, deploying an AI notetaker typically requires works council consultation before rollout — a step multinational HR teams frequently overlook. Layered on top are GDPR Article 5 lawfulness duties and Standard Contractual Clauses for U.S. data transfers, both of which cloud transcription vendors struggle to satisfy for silent third-party participants.

Does on-device transcription avoid EU AI Act obligations?

It reduces exposure but does not exempt you. Even a local tool must respect Article 50 transparency (tell participants AI is involved) and prohibited-practice rules (no workplace emotion recognition). But on-device processing removes the third-party data transfer, cloud retention, DPA and training-data problems that make cloud notetakers high-risk in worker-monitoring contexts. It also sidesteps the wiretap theories in Brewer v. Otter.ai and Chamberlain v. Granola.

What are the penalties under the EU AI Act for getting AI notetakers wrong?

Article 50 transparency and general obligations breaches carry fines up to €15 million or 3% of global annual turnover, whichever is higher. Prohibited-practice violations (like workplace emotion recognition) carry up to €35 million or 7% of turnover. Those sit on top of GDPR exposure — including CJEU-recognised damages for unlawful processing — and U.S. statutes like BIPA at $1,000–$5,000 per voiceprint.

What should HR and compliance leaders do this quarter?

Inventory every AI notetaker in use (shadow IT included), map each tool against Annex III use cases, confirm Article 50 disclosure is built into the meeting flow, and remove any emotion-recognition features immediately — those are now prohibited in workplace settings. Then check whether your vendor uses recordings for training by default, and whether an on-device alternative removes the transfer and retention risk entirely.