Skip to main content
EU AI Act Article 50 Is Now in Force. It Is the Deadline That Did Not Move.
All Insights
Regulatory Compliance·9 min read·

EU AI Act Article 50 Is Now in Force. It Is the Deadline That Did Not Move.

By Dritan Saliovski

On 2 August 2026, the EU AI Act's Article 50 transparency obligations became enforceable. From that date, an AI system that interacts directly with people must make its artificial nature clear unless that is already obvious, deployers of emotion recognition and biometric categorisation systems must inform the people exposed to them, and systems that generate synthetic audio, image, video, or text must mark their outputs in a machine-readable format and make them detectable as AI-generated. Deepfakes must be disclosed. None of this depends on whether a system is high-risk, and none of it depends on when the system was placed on the market.

When the Digital Omnibus deferred the AI Act's high-risk obligations to 2027 and 2028, we wrote that August 2 was not cancelled, only narrowed. That is now a description of the present rather than a forecast. And the pattern we warned about has largely played out: for a year the enterprise AI Act conversation was about the high-risk regime, and when that regime moved, many organizations stood their programs down entirely. The obligation that actually arrived on Sunday is the one that attaches by function rather than by risk classification, which means it reaches the systems almost every organization runs: the customer-facing chatbot, the voice assistant, the generative content pipeline. The distance between "we deferred our AI Act program" and "our chatbot has needed a disclosure since Sunday" is the subject of this piece.

Key Takeaways

  • Article 50 of the EU AI Act became enforceable on 2 August 2026. Four duty clusters apply: disclosure for AI systems interacting directly with people, information duties for emotion recognition and biometric categorisation, machine-readable marking and detectability for synthetic audio, image, video, and text, and disclosure of deepfakes and AI-generated public-interest text
  • The obligations apply regardless of high-risk status and regardless of when the system was placed on the market. Content generated before 2 August 2026 does not need retroactive labelling, though the European Commission encourages it voluntarily
  • One transitional carve-out survives: generative AI systems already on the market before 2 August have until 2 December 2026 to meet the Article 50(2) marking and detection obligation. New systems are bound in full now
  • The compliance path is published and final: the European Commission's Article 50 guidelines landed 20 July 2026, and the Code of Practice on Transparency of AI-generated Content (published 10 June, assessed adequate by the Commission on 8 July) had about 190 signatories by the end of July
  • Enforcement sits with national market surveillance authorities, with fines up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher, under Article 99(4)
  • The inventory Article 50 forces, every system that talks to people or generates content, is the same foundational register the deferred 2027 high-risk work requires. Compliance work done now is not throwaway
2 Aug 2026Article 50 transparency obligations apply, to in-scope systems regardless of when they were placed on the market and regardless of high-risk statusEuropean Commission, Article 50 transparency guidelines, 20 July 2026
2 Dec 2026Deadline for the machine-readable marking and detection duty for generative AI systems already on the market before 2 August 2026Regulation (EU) 2026/1744 (Digital Omnibus on AI)
€15M / 3%Maximum fine for breaching the Article 50 transparency obligations: EUR 15 million or 3% of total worldwide annual turnover, whichever is higherRegulation (EU) 2024/1689, Article 99(4)

What Took Effect on 2 August

Article 50 splits its duties between the organizations that build AI systems and the organizations that use them, and the split matters operationally because different teams own the fix.

Providers of systems that interact directly with people must design them so that the people concerned are informed they are interacting with an AI system, unless that is obvious "from the point of view of a natural person who is reasonably well-informed, observant and circumspect." That covers chatbots, voice assistants, and the growing population of AI agents that handle customer conversations end to end. The obviousness exception is a judgment call made in context, not a blanket pass: what is obvious in a labelled AI assistant embedded in a developer tool is not obvious in a natural-sounding voice agent answering a support line.

Providers of generative AI systems, including general-purpose AI, must ensure that synthetic audio, image, video, and text outputs are marked in a machine-readable format and detectable as artificially generated. This is a technical obligation that lives in the output pipeline: watermarking, metadata, provenance signals. Purely assistive uses, such as systems that do not substantially alter the input or its meaning, sit outside it.

Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. In workplace and education settings the question is mostly not disclosure but prohibition, since emotion recognition there sits in the Article 5 prohibited-practices list.

Deployers of deepfakes and of AI-generated public-interest text must disclose that the content is artificially generated or manipulated. Two calibrated exceptions apply: evidently artistic, creative, satirical, or fictional work needs only a disclosure that does not hamper its display or enjoyment, and AI-generated text published to inform the public escapes the duty where it has undergone human review or editorial control and a natural or legal person holds editorial responsibility. Systems authorised by law for detecting, preventing, investigating, or prosecuting criminal offences carry their own carve-outs across the article.

Legacy Systems Are In. Legacy Content Is Not.

Two scope rules decide most of the questions organizations are now asking, and they cut in opposite directions.

The first is that Article 50 applies to in-scope systems regardless of when they were placed on the market. There is no grandfathering for the chatbot launched in 2023. If it interacts with people today, the disclosure duty attached on 2 August.

The second is that content generated before 2 August 2026 does not need to be labelled retroactively. The obligation runs forward from the date. The European Commission encourages voluntary labelling of older material where feasible, but the legal duty covers what your systems produce from now on.

Between those two rules sits the one transitional carve-out that survived into the final timeline, and it is worth stating precisely because it is routinely overread. Generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) marking and detection obligation. That is the whole carve-out. It covers one duty, marking and detectability, for one population, systems that predate the deadline. The interaction disclosures, the emotion recognition information duties, and the deepfake and public-interest text disclosures all applied to those same legacy systems on 2 August. And a generative system placed on the market from 2 August onward gets no grace at all.

The December date deserves a double diary entry in any case: 2 December 2026 is also the day the Digital Omnibus's new prohibitions on nudifier and CSAM-generating systems take effect.

The Compliance Path Was Published Before the Deadline

An organization starting late has one genuine advantage: the guidance it needs is not in draft anymore.

On 10 June 2026 the Commission published the Code of Practice on Transparency of AI-generated Content, a voluntary instrument aimed at the marking, deepfake, and labelling duties. On 8 July the Commission concluded that the Code adequately covers the obligations in Articles 50(2), (4) and (5) and facilitates their effective implementation, with the AI Board's endorsement following on 9 July. And on 20 July, thirteen days before the deadline, the Commission published the final version of its guidelines on the Article 50 transparency obligations, developed with input from Member States, the AI Board, and other stakeholders through a public consultation. Neither document is a draft awaiting adoption; the interpretive groundwork enterprises spent 2025 waiting for is on the table.

The Code is gathering weight quickly. By the end of July 2026, about 190 organisations across sectors had signed it, per the European Commission, which describes signing as a streamlined and legally certain pathway to demonstrate compliance and has announced two signatory task forces for September 2026. The honest caveat travels with it: adherence is voluntary, an organisation can meet the obligations by other adequate means, and, as client guidance from law firm Faegre Drinker underlines, the Commission and the AI Board have each said that adherence serves as a guiding reference for demonstrating compliance and does not by itself discharge the statutory duty. Signing the Code is a sensible default for a content-generating estate; it is not a substitute for actually marking the outputs.

The Cost of Standing Down

The Digital Omnibus on AI entered into force on 27 July 2026 as Regulation (EU) 2026/1744, and the relief it granted is real: the heavy high-risk machinery now lands on 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in Annex I regulated products. We argued in July that the right response was to spend the extra time on classification, the foundational work the EU's draft high-risk guidelines exist to support, not to shelve the program.

What the stand-down misses is that Article 50 was never part of the bargain. It attaches by what a system does, not by what risk class it falls into, and for a typical enterprise estate that is a wider population of systems than the high-risk regime was ever likely to touch. A company with no Annex III exposure at all can still be running a dozen in-scope systems: the support chatbot, the sales voice agent, the marketing image pipeline, the internal comms drafting tool whose output goes out under the company's name.

Enforcement is now live to match. Member States lay down the penalty rules, national market surveillance authorities hold primary responsibility, and the AI Office takes a narrower slice for systems built on general-purpose AI models meeting specific conditions. The ceiling under Article 99(4), which names the Article 50 obligations expressly, is EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. How assertive the first months of enforcement will be is genuinely unknown, and early attention may well concentrate on visible consumer-facing failures rather than technical marking gaps. But that is a bet about enforcement posture, not about legal exposure, and the exposure attached on 2 August.

What This Changes for the Executive Team

Four moves follow, in order.

Inventory by function, this month. List every system that interacts with people, every pipeline that emits synthetic audio, image, video, or text, and every emotion recognition or biometric categorisation deployment, including the tools adopted without central approval. This is a faster exercise than full AI Act scoping because function is observable: you do not need to resolve Annex III interpretation questions to know that a chatbot talks to customers.

Treat disclosure and marking as product work, not legal boilerplate. The interaction disclosure is a UX decision governed by an obviousness test that depends on context, and the marking duty is an engineering task in the content pipeline. A compliance memo satisfies neither. The teams that own the chatbot and the generation pipeline own the fix, with legal review on the judgment calls.

Put 2 December 2026 in the diary twice. It is the marking and detection deadline for generative systems you were already running before 2 August, and it is the effective date of the new prohibitions the Omnibus added. Decide before then whether the organisation signs the Code of Practice or documents its alternative means, and verify the legacy systems' marking work is scheduled rather than assumed.

Reuse the register. The function-based inventory Article 50 forces is the starting asset for the Annex III classification work due by December 2027, and it feeds the same evidence base that shapes exposure across NIS2, DORA, and the Cyber Resilience Act, the cross-framework picture we mapped in Five Frameworks, One Vendor. Work done for the deadline that arrived is capital for the deadlines that moved.

How Innovaiden Approaches It

Innovaiden approaches Article 50 as the live edge of a larger program rather than a stand-alone labelling exercise. The work starts with the function-based inventory: which systems interact, which generate, which categorise, and what each one must now disclose or mark. It reviews disclosure UX against the obviousness test and output marking against the machine-readable requirement, settles the Code of Practice question deliberately, and puts the 2 December 2026 legacy-marking deadline on an owned plan. And it treats the resulting register as infrastructure for the deferred 2027 classification work, because the gap between stated commitments and demonstrable controls is where regulatory exposure actually lives, the argument we made in From AI Principles to Proof of Control. The organizations in the best position on 2 December will be the ones that treated this August as the start of the program, not a false alarm.

Work With Us

Find Out Which of Your Systems Article 50 Already Covers

Innovaiden maps your AI estate against the four Article 50 duty clusters: which systems interact with people, which generate content, what each must disclose or mark, and what the 2 December 2026 marking deadline means for systems you already run. The same register becomes the foundation for the deferred 2027 high-risk work. Reach out to scope it.

Get in Touch

Frequently Asked Questions

What exactly became enforceable on 2 August 2026 under the EU AI Act?

Article 50 of Regulation (EU) 2024/1689, the AI Act's transparency chapter. It creates four duty clusters. Providers of AI systems that interact directly with people, such as chatbots, voice assistants, and AI agents, must ensure people are informed they are dealing with AI unless that is obvious. Providers of generative systems, including general-purpose AI, must ensure synthetic audio, image, video, and text outputs are marked in a machine-readable format and detectable as artificially generated. Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. And deployers must disclose deepfakes, and AI-generated text published to inform the public on matters of public interest, subject to an exception where a person holds editorial responsibility. All of this applies regardless of whether a system is high-risk.

Do the transparency rules apply to AI systems deployed before 2 August 2026?

Yes. The obligations apply to in-scope systems regardless of when they were placed on the market. What is exempt is old content: material generated before 2 August 2026 does not need to be labelled retroactively, though the European Commission encourages voluntary labelling where feasible. The one transitional exception for systems is narrow: generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) machine-readable marking and detection obligation. Every other duty applied to them on 2 August, and systems placed on the market from that date are bound in full immediately.

What is the 2 December 2026 transitional deadline, and who gets it?

It covers one obligation for one population: the Article 50(2) requirement to mark generative outputs machine-readably and make them detectable, for generative AI systems placed on the market before 2 August 2026. It is the carve-out the Digital Omnibus on AI wrote into the transparency rules while leaving the rest of Article 50 on schedule. The date is worth a double diary entry, because 2 December 2026 is also when the Omnibus's new prohibitions on nudifier and CSAM-generating systems take effect. The high-risk deferral is separate: those obligations now land on 2 December 2027 for Annex III systems and 2 August 2028 for AI in Annex I regulated products.

What are the penalties for breaching Article 50, and who enforces it?

Article 99(4) of the AI Act lists the Article 50 transparency obligations expressly, with fines of up to EUR 15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. Member States lay down the applicable penalty rules, and enforcement sits primarily with national market surveillance authorities; the AI Office holds a narrower role for systems built on general-purpose AI models meeting specific conditions. The European Commission's guidance notes proportionality considerations for SMEs. How aggressively authorities will act in the first months is untested, but the legal exposure attached on 2 August.

We paused our AI Act program after the Digital Omnibus deferral. What should we restart first?

Start with a function-based inventory: every system that talks to a person, every pipeline that emits synthetic content, every emotion recognition or biometric categorisation deployment, including the ones adopted without central approval. That inventory tells you where disclosure UX and output marking are needed now, what the 2 December 2026 marking deadline covers in your estate, and whether to sign the Code of Practice on Transparency of AI-generated Content or document alternative means. It is also the same register the deferred Annex III classification work will need before December 2027, so restarting Article 50 compliance restarts the whole program at its foundation.

Subscribe