← All guides

AI Act Article 50: what applied on 2 August 2026 and what did not

The transparency obligations were not postponed. What applies now, what slips to December and only for whom, and the three tests to see if it touches you.

· 9 min

On 2 August 2026 the transparency obligations of Article 50 of the AI Act became applicable. In the weeks before, I kept hearing a wrong version of the news, and I still hear it: "they postponed everything anyway". They did not. The Digital Omnibus postponed a fair amount, but not this, and the part it did postpone is narrower than the way it gets told.

This guide separates the two, because the confusion is expensive in opposite directions. People who think everything slipped do nothing and find themselves non compliant. People who think everything landed at once start marking files and labelling everything, spending time on an obligation that for them arrives in December or does not arrive at all.

What actually applied on 2 August

Article 50 sets out four obligations, and they fall on different parties. Two sit with the provider, meaning whoever develops the system and places it on the market under their own name. Two sit with the deployer, meaning whoever uses that system in their professional activity.

First, provider: say it is an AI. If your system interacts directly with people, chatbot, assistant, agent, automated voice, you must design it so the user knows. The information must be given at the latest at the first interaction, clearly and distinguishably, and in line with accessibility requirements.

Second, provider: mark synthetic outputs. Generated text, images, audio and video must carry a machine readable mark that makes them detectable as artificial. This is the piece with a different date, covered below.

Third, deployer: disclose emotion recognition and biometric categorisation. If you use systems that recognise emotions or categorise people biometrically, those exposed must be informed.

Fourth, deployer: label deepfakes and public interest text. Anyone publishing a deepfake must disclose it. Anyone publishing AI generated text for the purpose of informing the public on matters of public interest must disclose it, unless the human review exemption applies.

One thing worth saying up front: these obligations are not limited to high risk systems. They apply to any AI system used in one of those four situations. You can have nothing high risk and still carry full Article 50 obligations. That is exactly the position of most small companies using generative AI to produce content.

The one thing that did not apply, and for whom

This is the piece almost everyone gets wrong.

The machine readable marking of Article 50(2) has a grace period until 2 December 2026. But that grace period applies only to systems already placed on the market before 2 August 2026. If you place a generative system on the market from 2 August onwards, you get no window at all: marking is required immediately.

In operational terms: if your generative product was already live in July, you have until December to implement marking, and in the meantime every other Article 50 obligation already applies to you. If instead you are about to launch something new in the autumn, that window does not exist and it belongs in the development plan now.

There is also good news, worth stating because it saves pointless work. Content generated before 2 August 2026 does not need retroactive labelling. The Commission encourages it where possible, but it is not an obligation. If you have an archive of articles or images produced in past years, you do not need to go back over it.

The three tests that decide whether an obligation touches you

In practice almost every real question reduces to three assessments. They are the same ones I applied to my own assets.

Test 1: is it obvious this is an AI?

The obligation to inform the user does not apply where it is obvious. The exception exists, but the Commission says explicitly that it must be interpreted restrictively, because it deprives people of transparency.

The yardstick is not you, who built the product. It is an average person, reasonably well informed, observant and circumspect, belonging to the audience the system addresses. If your product is openly named and presented as a generative AI tool, obviousness holds. If your chatbot has a human name and a tone that imitates a human agent, it does not, and leaning on obviousness is the fastest way to get this wrong.

A useful detail: the obligation is triggered by genuine two way exchange with a natural person. A system running purely in the background, or talking only to other machines, stays outside.

Test 2: is it a deepfake?

The definition has three criteria, and all three are needed together. The content must resemble something, what it resembles must exist or plausibly could exist, and it must falsely appear authentic.

The third criterion does the work, and it is the one most often skipped. A clearly fantastical illustration is not a deepfake, even if it depicts a person: if the context and the audience do not expect the thing to be authentic, no deception is possible. The guidelines go as far as saying that background scenes, special effects and technical pre and post processing normally do not make content falsely appear authentic.

This matters in domestic cases too. If you extend the background of your own photo to fit a format, the subject stays authentic and you are asserting nothing false about anyone. If instead you generate the face of a real person in a situation they were never in, you are squarely inside, and the fact that you meant no deception does not help.

One precision that costs people dearly: if you are the deployer, you cannot rely on the technical marking embedded by the provider. That serves machines. What you need is a disclosure perceivable by a person, at first exposure, without requiring special tools to uncover it.

Test 3: is it text published to inform on matters of public interest?

Again the criteria are cumulative. The text must be published, must inform the public, and must concern a matter of public interest. The Commission lists politics and democratic processes, public administration, justice, fundamental rights, public security, health, environment, consumer safety, and economic, financial, scientific or cultural developments that may be a relevant subject of public debate.

A product page or a sales email does not qualify. An explanatory piece on a regulation, on health, or on information security qualifies easily. It is worth being honest here rather than hunting for loopholes: if you write content that explains rules to the public, you are inside.

There is however a real exemption, and it pays to know it well, because it is how most small publishers resolve this without labelling anything.

The human review exemption, and why it is not a rubber stamp

AI generated text does not need labelling if it has undergone human review or editorial control, and if a natural or legal person carries editorial responsibility for it.

Those three terms deserve to be taken seriously.

Human review means deliberate examination of the substance of the content, by someone with relevant knowledge and professional judgement on the subject matter. Editorial control means there is a responsible party with authority to approve, alter or reject the text on substantive grounds, including fact checking and source reliability. Editorial responsibility means someone holds ultimate legal responsibility for publication.

Here is the part that makes the exemption fragile if handled lightly: the Commission states expressly that superficial, purely formal or procedural checks do not count. A spell checker is not human review. A distracted read before hitting publish is not editorial control.

If your newsroom is one person, the exemption remains perfectly valid, provided that person actually reads the substance and puts their name to it. If review is a ritual, the exemption is paper, and when someone asks there is nothing to show.

The most common mistake: labelling everything to be safe

The defensive reflex in front of a new rule is to mark everything. It is a mistake, for two reasons.

The first is substantive. If you declare a text AI generated when you actually wrote it yourself, you are making a false statement on the very page where you promise transparency. That is not an elegance issue: it undermines the credibility of the human review the exemption rests on. Better no label than a wrong label.

The second is about effectiveness. A label everywhere stops meaning anything. The rule asks for clear and distinguishable communication, not uniform noise, which is the same reason the guidelines explicitly reject the fake solutions: a tiny line buried in a footer, a faint label on an image, a warning flashing for an instant in a video, or a disclosure hidden in terms and conditions.

On this site I took this route: the transparency line appears at the foot of content actually drafted with AI, and does not appear on content written by hand. It is a per content field, not a global switch. It costs a few minutes more and has the advantage of being true.

Who enforces this and what mistakes cost

Enforcement sits mainly with national market surveillance authorities. The AI Office has a limited role, focused on systems built on general purpose models where the same entity provides both model and system, and on systems integrated into very large platforms and search engines designated under the Digital Services Act.

Penalties for breaching Article 50 reach up to 15 million euro or 3% of worldwide turnover for the preceding financial year. For small and medium enterprises proportionality is taken into account, which is a real mitigation but not a free pass.

The Code of Practice: voluntary, and the choice deserves thought

There is a Code of Practice on the transparency of AI generated content, assessed as adequate by the Commission and the AI Board. It is voluntary and covers the marking and labelling obligations, meaning Article 50(2), (4) and (5).

Signing brings a concrete benefit: you can rely on an approved instrument to demonstrate compliance, with greater legal certainty and predictability, regardless of which authority is competent.

Not signing does not make you non compliant, and this is the part most often told badly. The legal obligation is identical either way. What changes is how you prove it: those who do not sign must demonstrate compliance through other adequate means, and may receive more requests for information, because there is less transparency about how they comply.

Translated into a decision: if you generate synthetic content at scale, signing removes friction. If your volume is small and your review chain is documented, staying out is a legitimate choice, as long as you know the burden of explaining yourself remains yours.

What I would do on Monday morning

If I were starting from zero, in order, and without building anything before understanding what is actually needed.

Map where AI touches a person. Not your systems in the abstract: the points where a human being meets an output or an interface. Chatbots, assisted forms, published content, images, email to third parties.

For each point, run the three tests. Obviousness, deepfake, public interest text. Most points will fall outside scope, and that is as useful a result as discovering an obligation.

Where you are inside, choose between label and exemption. For text you have a choice: label, or document a human review that is real. You do not need both.

Mark the December date only if it concerns you. Machine readable marking is genuine technical work. If you have systems already on the market, it is a roadmap item due 2 December. If you are launching now, it is work to do immediately.

Write down what you decided and why. The most underrated part. When the question arrives from an enterprise client during due diligence, and it arrives long before any authority does, the difference is having a page that explains the reasoning rather than scrambling.

Where to go deeper in the rest of the cluster

If you need the full picture of the dates and not just Article 50, the guide on AI Act and DORA for AI agent builders holds together the calendar, the DORA perimeter and the questions that show up in tenders.

If the point is instead proving what happened inside your system, which is what actually matters when someone asks, the piece on audit ready logging and incident response is the natural follow up.

And if you are designing right now, least authority for AI agents is the architectural choice that removes the most risk surface for the least work.

An honest closing note

This guide explains a rule, it does not replace legal advice on your case. Assessments of obviousness, deepfake and public interest depend on context, audience and the specific content, and are exactly the kind of judgement that has to be made on concrete facts.

What I can tell you with confidence is that most of the work is not technical. It is deciding honestly which of the three cases you are in, and writing it down.

FAQ

Did the Digital Omnibus postpone the AI Act Article 50 transparency obligations?

No. Article 50 applies from 2 August 2026 and the Digital Omnibus did not move that date. The postponement concerns high risk systems, which are a different matter. The only timing exception inside Article 50 concerns the machine readable marking of Article 50(2), which has a grace period until 2 December 2026 and only for systems already placed on the market before 2 August 2026.

If I launch a generative AI product in September 2026, do I have until December for marking?

No. The grace period until 2 December 2026 applies only to systems already on the market before 2 August 2026. A system placed on the market from 2 August onwards must meet the Article 50(2) marking obligation immediately, with no transitional window.

Do I need to retroactively label AI content published before 2 August 2026?

No, it is not an obligation. The Commission clarifies that content generated before 2 August 2026 does not need retroactive labelling, while encouraging it where possible because it contributes to the goals of Article 50.

When does AI generated text not need to be labelled?

When it has undergone substantive human review or editorial control and a natural or legal person holds editorial responsibility for it. Note that superficial, purely formal or procedural checks are not enough. A spell checker or a quick read does not constitute human review under the rule.

Is an image with an AI extended background a deepfake?

As a rule no. A deepfake requires three cumulative criteria: resemblance, real or plausible existence of the subject, and false appearance of authenticity. The Commission guidelines indicate that background scenes, special effects and technical pre and post processing normally do not make content falsely appear authentic. If the subject stays authentic and nothing false is asserted, the definition is not met.

Is signing the Code of Practice on transparency mandatory?

No, it is voluntary. Signatories can rely on an approved instrument to demonstrate compliance, with greater legal certainty. Non signatories are not non compliant, but must demonstrate compliance through other adequate means and may receive more requests for information.

What are the penalties for breaching Article 50?

Up to 15 million euro or 3% of total worldwide turnover for the preceding financial year. For small and medium enterprises proportionality is taken into account. Enforcement sits mainly with national market surveillance authorities.