Article 50 of the EU AI Act applies from today, August second, and it is the part of the law that lands in application code rather than in a compliance binder. If your product talks to people, generates images, audio, video or text, reads emotions, or publishes synthetic media, you now owe a disclosure and, in the generative case, a machine readable mark on the output itself. The heavier high risk regime did not arrive with it. A late amendment package pushed those obligations out to December second, 2027. What is live today is narrower, cheaper to implement, and backed by fines of up to fifteen million euros or three percent of worldwide turnover.
The short answer
The EU AI Act's transparency article applies from today. Four situations are covered: systems that interact directly with people, systems that generate synthetic audio, image, video or text, emotion recognition and biometric categorisation, and deepfakes plus AI generated text on matters of public interest. Providers owe a disclosure and a machine readable mark on generated output. Deployers owe notice to the people exposed. A voluntary Code of Practice published on June tenth gives one route to showing compliance, with around 190 signatories. The high risk regime was pushed to December second, 2027, so today is the narrow deadline, not the wide one.
Most regulation reaches a development team as a document somebody else reads. This one reaches it as a ticket. Article 50 of the EU AI Act is the transparency article, it became enforceable today, and every duty in it terminates in something you either render on screen or write into a file header.
The four situations, and which one you are in
The article does not ask whether your system is high risk. It asks what your system does, and it names four cases.
The first is direct interaction. If a person is interacting with an AI system, they have to be informed of that, unless it is obvious to a reasonably well informed person in context. Chatbots, voice agents, automated support flows.
The second is generation. Providers of systems that produce synthetic audio, image, video or text have to mark the output in a machine readable format, detectable as artificially generated or manipulated.
The third is emotion recognition and biometric categorisation. Deployers have to inform the people exposed to the system.
The fourth is deepfakes and public interest text. Deployers publishing AI generated or manipulated image, audio or video that resembles real people, places or events have to disclose that it is artificial. The same goes for AI generated text published to inform the public on matters of public interest.
Note who owes what. The marking duty falls on the provider, the entity that builds the system and puts it on the market. The disclosure duties in cases three and four fall on the deployer, the entity that uses it. If you ship a product built on somebody else's model, you are probably both, in different places.
Marking output is the engineering problem
The disclosure duties are cheap. A line of text near a chat input, a notice on a page, a label under a video. You can ship those this week.
Machine readable marking is the part that touches architecture. The requirement is that generated output be detectable as artificial by a machine, using solutions that are effective, interoperable, robust and reliable as far as technically feasible. That last clause is doing real work: the law knows that a text file has nowhere obvious to put a durable mark, and that any mark survives only until somebody re encodes the asset.
The Commission published a Code of Practice on Transparency of AI generated Content on June tenth, 2026. It is voluntary, it is built around the existing provenance and watermarking approaches rather than a new EU format, and around 190 companies and organisations had signed it by late July. Signing is not compliance in itself, but it is the offered route to demonstrating it, and the alternative is arguing your own scheme is equivalent in front of a national authority. There is also a supplementary set of icons for labelling AI generated content, which is worth pulling into a design system rather than inventing a badge.
The practical order of work for a product team looks like this. Find every surface where a model output reaches a user. Add the interaction disclosure where a human could plausibly think they are talking to a person. Then, for anything generated, decide where the mark lives: metadata for images and video, and an honest assessment for text, where the state of the art is weakest and the exemption language is most relevant.
The exemptions are narrower than they look
Four carve outs exist, and they are specific rather than general.
Disclosure is not required where the AI use is obvious to a reasonably well informed person given the circumstances. It is not required where the system is authorised by law to detect, prevent, investigate or prosecute criminal offences. It is relaxed for artistic, creative, satirical or fictional work, where the disclosure has to exist but in a manner that does not spoil the work. And the marking duty does not bite where the system performs an assistive function for standard editing or does not substantially alter the input data.
That last one is the exemption most teams will reach for, and it is the one to read carefully. A model that removes noise from a photo is standard editing. A model that replaces the background, changes the subject's expression or extends the frame is not obviously doing so, and the burden of that argument sits with you.
What did not arrive today
It is worth being precise, because the two speed calendar is now the main source of confusion.
The Annex III high risk regime, the one with risk management systems, data governance, technical documentation, logging, human oversight and conformity assessment, was moved by the Digital Omnibus on AI from August 2026 to December second, 2027. Article 50 was left out of that deferral. So a team that budgeted a large compliance programme for this summer has an extra sixteen months for the heavy part, and no extra time at all for the disclosure and marking part.
The penalty ceiling for Article 50 breaches is 15,000,000 euros or 3% of total worldwide annual turnover, whichever is higher for an undertaking, and whichever is lower for SMEs and startups. Enforcement runs through national market surveillance authorities, which means the first year of practice will look different in different Member States.
Sources and further reading
- Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems
- The EU AI Act's transparency rules: a practical guide to Article 50
- European Commission: Code of Practice on Transparency of AI generated Content
- Article 99: Penalties
- Sidley: EU AI Act transparency obligations, preparing for compliance by 2 August 2026
- Stibbe: the AI Act's transparency obligations, rules, scope and timeline
Frequently asked questions
Does Article 50 apply to my company if we are not based in the EU?
Very likely yes. The AI Act binds providers who place an AI system on the EU market or put it into service in the EU, whatever country they are established in, and it reaches providers and deployers outside the EU when the output of the system is used inside the EU. In practice that means a US or UK SaaS product with European customers is in scope on the same day as a French one. The obligations attach to roles rather than to postcodes: you are a provider if you develop the system and put it on the market under your own name, and a deployer if you use one under your own authority. Most product teams are both, for different systems in the same stack.
What does machine readable marking actually mean in practice?
The text asks providers of generative systems to mark outputs in a machine readable format, so the content is detectable as artificially generated or manipulated, with solutions that are effective, interoperable, robust and reliable as far as technically feasible. It does not name a technology. The Code of Practice on Transparency of AI generated Content, published on June tenth, 2026, is the route the Commission offers for showing you meet the bar, and it points at the established provenance and watermarking approaches rather than inventing a new one. Signing the Code is voluntary. Around 190 companies and organisations had signed by late July. If you do not sign, you have to show on your own that whatever you built is equivalent.
Do we have to label AI generated text as well as images?
Only in a specific case, and the exemption matters. The deployer duty covers text published to inform the public on matters of public interest. If that text was generated or manipulated by AI, its origin has to be disclosed. The exemption applies where the content went through human editorial review and a natural or legal person holds editorial responsibility for the publication. So an internal knowledge base, a product description or a support reply is not what this clause targets. A newsroom pipeline that drafts public interest articles with a model and ships them without a named editor is. Note that provider side marking of synthetic content is a separate duty and is not limited to public interest topics.
What are the fines, and who issues them?
Breaches of the Article 50 transparency obligations carry administrative fines of up to 15,000,000 euros or up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher for an undertaking. For SMEs and startups the calculation flips to whichever of the two is lower, which is a meaningful difference at small revenue. Enforcement sits with national market surveillance authorities designated by each Member State rather than with a single central regulator, so the practical experience will vary by country in the first year. The figures above are the ceiling the law allows, not a tariff, and penalties are meant to take into account the nature and gravity of the breach.
What did the Digital Omnibus postpone, and does it touch Article 50?
It does not touch Article 50. The amendment package known as the Digital Omnibus on AI moved the standalone high risk system obligations, the Annex III regime, from August 2026 to December second, 2027. That is the heavy part of the Act: risk management systems, data governance, technical documentation, logging, human oversight, conformity assessment. Article 50 was deliberately left on its original date, which is why the calendar now runs at two speeds. The practical read for a product team is that the disclosure and marking work is due now, and the documentation heavy compliance programme has another sixteen months, assuming no further amendment.