1. What starts on August 2
Article 50 transparency duties apply from August 2, 2026. They cover four paths: telling people when they directly interact with AI; machine-readable marking of synthetic output; notice when people are exposed to emotion recognition or biometric categorisation; and clear disclosure of deepfakes and certain public-interest text.
This is not a ban on synthetic media or a pre-approval regime. It is intended to let people know when a machine is interacting with them or shaping what they see. The duty depends on role: a “provider” develops a system and places it on the market under its name, while a “deployer” uses it under its authority in a professional context. One company can occupy both roles.
2. Provider versus deployer: the responsibility map
A provider of a chatbot, agent or avatar designed for direct interaction must make the experience disclose AI involvement from the start of the first interaction, unless that fact is genuinely obvious. The Commission says the “obvious” exception should be interpreted restrictively, not treated as a convenient design assumption.
A provider of a generative system must enable synthetic audio, image, video and text to be detected through effective, reliable, robust and interoperable machine-readable marks. A professional deployer—such as a media group, agency or public body—owns a different layer: perceptible deepfake disclosure, labels for certain public-interest text, and notice when emotion-recognition or biometric-categorisation systems are used.
- Interactive interface: disclosure from the first interaction, clearly and accessibly.
- Synthetic output: a technical mark supplied by the provider for detection.
- Deepfakes: a human-perceivable disclosure; hidden metadata alone is insufficient.
- Professional use: the legal person remains the deployer when staff or contractors operate the system.
3. Not every AI-assisted text needs a visible label
The most common confusion is between a provider’s technical-marking duty and a deployer’s visible-label duty. AI-generated or manipulated text falls into the latter when it is published to inform the public on a matter of public interest and has not undergone human review or editorial control. Public interest can include politics, public services, health, security, the environment, consumer safety, and economic, financial, scientific or cultural developments relevant to public debate.
Human review is not a one-click approval. The Commission says a person with relevant knowledge and professional judgement must examine substance, or a responsible editorial entity must have practical authority to alter, reject and fact-check it. Spelling, grammar or purely procedural checks do not qualify. A person or entity must also hold ultimate legal responsibility for publication.
4. Technical marking is not visible disclosure
Article 50 requires providers to enable detection of synthetic output through machine-readable marking. Implementations may involve provenance data, watermarks or interoperable detection techniques. But when a deployer publishes a deepfake, disclosure must reach the person by first exposure in an understandable and perceivable form without a special tool. Metadata hidden inside a file does not replace the human-facing label.
The rules allow proportionate treatment of artistic, fictional and satirical work so disclosure does not ruin the experience. They also narrow or exclude standard editing assistance, source code, some machine-only outputs and closed industrial workflows. These boundaries depend on function, context and final output; they are not a blanket B2B exemption.
5. Why companies outside Europe should care
The Commission says a provider outside the EU can still be covered when the output of its AI system is used in the Union. A Saudi company selling an agent platform to a European client—or a content tool used by European teams—therefore needs a flow map: who markets the product under its name, who operates it, where people encounter the output, and who controls publication.
The operational priority is not merely translating a privacy policy. Disclosure must work in the market’s language and the same channel—text or voice—and provenance should survive export, editing and publication. Contracts should identify who preserves the mark, who applies the visible label, and who retains evidence supporting human-review or other exceptions.
6. The code: a voluntary route to a mandatory duty
The Commission published a transparency code of practice and, with the AI Board, assessed it as an adequate tool to facilitate compliance. July 27 at 18:00 CEST was the deadline to appear among initial signatories, but organisations may sign later. Not signing is not a violation: Article 50 is mandatory, while the code is a recognised way to demonstrate it.
A non-signatory can use equivalent alternative measures, but must document them and may face more information requests. A signatory receives no immunity either: the Commission’s opinion says adherence is not conclusive proof of compliance. Google’s July 24 statement about signing and using SynthID and C2PA illustrates the implementation direction; it does not make one technology the only legal standard.
7. A practical first-week compliance plan
Start with systems and outputs, not model names. Classify each use as direct interaction, content generation, emotion or biometric use, or deepfake/public-interest publication. Then assign provider and deployer roles and test whether disclosure and marking survive copying, editing and channel changes.
The Commission describes a limited transition to December 2, 2026 for marking and detection in some systems placed on the market before August 2, but its signing FAQ ties that grandfathering rule to adoption of the AI Omnibus amendment. Do not treat it as a general or final extension for all Article 50 duties. Obtain case-specific legal advice and preserve the product-release history and basis for any transition decision.
- Build a matrix of system, role, EU user, output type and disclosure channel.
- Separate provider-side technical marking from the label a person can perceive.
- Document substantive editorial review and the party with final responsibility.
- Test languages and accessibility from the first interaction.
- Update contracts, publishing policies and incident response for lost marks or failed disclosure.
8. Enforcement: a fine ceiling is not a risk plan
The Commission says enforcement will mainly sit with national market-surveillance authorities, with the AI Office and European Data Protection Supervisor responsible in defined areas. Company penalties can reach €15 million or 3% of total worldwide annual turnover for the preceding financial year, with proportionality for smaller businesses.
The earlier risk may be operational and reputational: a customer unaware they are speaking to a machine, a video stripped of provenance, or public-interest text without an accountable editor. Good compliance turns Article 50 into an auditable record: who built, who deployed, what mark, what disclosure, who reviewed and who approved.