AI
EU AI Act Transparency Rules Are Now Live
As of 2 August 2026, Article 50 of the EU AI Act has been binding. Companies that deploy or provide AI systems in the European single market must now disclose when users interact with AI, mark AI-generated content in machine-readable form, label deepfakes, and inform individuals exposed to emotion recognition or biometric categorisation systems. The European Commission's AI Office, together with national market surveillance authorities, has begun enforcement, and penalties reach up to €15 million or 3% of worldwide annual turnover (European Commission).
For regulated industries, this is not a future concern. It is an operational requirement that depends on architecture: where your AI runs, who controls the logs, and whether AI-generated outputs can be traced back to their source.
What Changed on 2 August 2026?
Three things took effect simultaneously:
Article 50 transparency obligations became enforceable. These are among the first substantive duties under the AI Act to apply, ahead of the high-risk system rules, which were delayed to 2 December 2027 under the Digital Omnibus on AI, adopted by the Council on 29 June 2026 and entering into force in July 2026 (Freshfields).
Enforcement powers switched on. The European Commission's AI Office can now open investigations, demand documentation, compel model evaluations, and levy fines against general-purpose AI model providers (Gibson Dunn).
The Code of Practice on Transparency of AI-Generated Content is formally adequate. The Commission and the AI Board confirmed the voluntary Code as sufficient for demonstrating compliance with Article 50's marking and labelling duties. Approximately 190 organisations have signed it, including OpenAI, Google, Anthropic, Meta, Microsoft, and Mistral (CADE).
On 20 July 2026, the Commission also published its final Guidelines on Transparency Obligations under Article 50, the primary reference document that national authorities will use when assessing compliance (Faegre Drinker).
The split calendar
The Digital Omnibus on AI created a staggered timeline. Transparency stayed on the original date. High-risk obligations moved.
Milestone | Date |
|---|---|
Article 50 transparency obligations enforceable | 2 August 2026 |
Grace period for machine-readable marking (systems on market before 2 Aug 2026) | 2 December 2026 |
High-risk AI system obligations (Annex III) | 2 December 2027 |
High-risk AI in regulated products (Annex I) | 2 August 2028 |
Sources: European Commission, Gibson Dunn
The Four Transparency Duties
Article 50 is not a universal "label everything" rule. It establishes four distinct obligations, each triggered by specific use cases and assigned to a specific role provider or deployer.
A provider develops an AI system (or has one developed) and places it on the market under its own name or trademark. A deployer uses an AI system under its own authority in a professional capacity. The Commission's Guidelines clarify that "authority" means assuming responsibility over the decision to deploy the system and over its actual use technical control is not required (Travers Smith).
Duty | Responsible party | Trigger | Required action |
|---|---|---|---|
AI interaction disclosure | Provider | AI system conducts a genuine two-way exchange with a person | Inform the person from the first interaction, unless obvious from context |
Machine-readable marking | Provider | AI system generates synthetic audio, image, video, or text | Mark outputs in a machine-readable format detectable as artificially generated |
Emotion recognition / biometric categorisation | Deployer | System analyses emotions or categorises individuals biometrically | Inform each person exposed, before processing begins |
Deepfake and public-interest text labelling | Deployer | Deepfake or AI-generated text on matters of public interest published without human editorial review | Clearly disclose that content is AI-generated or manipulated |
Source: Article 50, EU AI Act
A horizontal requirement runs across all four: information must be provided in a clear and distinguishable manner, at the latest at the time of first interaction or exposure, and must conform to applicable accessibility requirements. Information that can easily be overlooked, forgotten, or buried does not meet the standard.
Who Is Affected?
Article 50 applies extraterritorially. If your AI outputs reach the EU users regardless of where your company is headquartered you are in scope.
Providers
Companies that build AI systems and place them on the EU market. This includes providers of generative AI models, chatbot platforms, and synthetic content tools. These firms must now build machine-readable marking (watermarks, metadata, provenance signals) directly into their products.
Deployers
Organisations that use AI systems professionally. This is the category that catches most enterprises. Marketing teams using AI-generated copy, HR teams using AI screening tools, customer support running chatbots, and media outlets publishing AI-assisted articles all fall within scope.
Non-EU companies
US-headquartered businesses whose AI outputs reach EU users are caught. The Act defines "intended" as foreseeable use not incidental or unauthorised downstream use. For deployers, Article 50 applies where the deployer foresees that outputs will be disseminated or used in the EU, such as posting deepfake content on a globally accessible platform (Travers Smith).
A critical nuance: when a deployer becomes a provider
The organisations that customise, rebrand, or substantially modify an AI system can be reclassified from deployer to provider. This pulls the full compliance burden including machine-readable marking requirements onto them (Bird & Bird).
What Companies Should Do Now
1. Map your AI use cases
Identify every place AI is used in your organisation: chatbots, content generation, emotion recognition, biometric categorisation, deepfake creation, AI-assisted publishing. Most companies underestimate how many touchpoints exist across marketing, HR, customer support, and internal operations.
2. Determine your role for each use case
For each AI system, establish whether you are the provider, the deployer, or both. If you customise or rebrand an AI tool, you may have shifted into the provider role. This classification determines which obligations apply to you.
3. Implement user-facing disclosures
If users interact with an AI system (chatbot, virtual assistant, AI agent), disclosure must happen at the point of first interaction. It must be clear, distinguishable, and accessible. A buried footer link does not qualify.
4. Add machine-readable provenance
For AI-generated audio, images, video, and text, implement technical marking: digital watermarks, signed metadata, C2PA-style provenance, or downstream detection mechanisms. The Code of Practice recommends multilayered marking that is both embedded and externally detectable.
5. Log AI outputs and publication workflows
Maintain records of what was AI-generated, when it was created, which model produced it, and whether the required disclosure was applied. This is your audit trail. National market surveillance authorities can request it.
6. Review vendors and contracts
If you depend on third-party AI providers, confirm in writing that they have implemented Article 50(2) machine-readable marking. Ensure contracts allocate transparency responsibilities clearly between provider and deployer.
7. Prepare audit evidence
Document your compliance approach. If you have not signed the Code of Practice, you must document alternative technical measures and be prepared to demonstrate their equivalency to national authorities.
Why Infrastructure Matters
Here is the practical challenge that Article 50 creates: companies must be able to prove where AI was used, what generated the output, whether the correct disclosure was applied, and whether the output can be traced.
When AI runs through scattered SaaS tools a marketing team using one cloud API, HR using another, customer support running a third transparency becomes a manual, error-prone process. Logs live in different systems. Disclosures are applied inconsistently. Audit trails are incomplete.
A sovereign AI control plane changes this. When prompts, outputs, logs, and model routing stay inside infrastructure you control, transparency becomes enforceable rather than manual. You can:
Route all AI traffic through a single gateway with consistent disclosure rules
Log every prompt and output centrally, with model, timestamp, and user attribution
Apply disclosure policies at the infrastructure layer, not per team or per tool
Produce audit evidence on demand, from a single source of truth
For regulated enterprises, the question is no longer only which model to use. It is where the model runs, who controls the logs, and whether AI-generated outputs can be traced.
For Regulated Industries
Article 50 hits regulated sectors first and hardest, not because they have special obligations, but because they have the most AI touchpoints and the lowest tolerance for compliance gaps.
Banking and finance
AI is already used in customer support chatbots, automated reporting, and marketing content, each of these triggers disclosure or marking duties. Financial institutions also face parallel obligations under MiFID II, DORA, and GDPR, and regulators will expect AI transparency to be demonstrable, not claimed.
Healthcare
Hospitals and insurers using AI for patient communication, clinical documentation, or administrative content must ensure that AI-generated outputs are marked and that patients are informed when interacting with AI systems. The intersection of Article 50 and patient data protection creates a particularly high bar for auditability.
Public sector
Government agencies deploying chatbots, automated communication, or AI-assisted document generation must comply with Article 50 alongside public procurement and administrative law requirements. The EU's push for sovereign AI infrastructure in public administration makes architectural control a procurement criterion, not just a compliance preference.
Media
Publishers using AI for content generation, especially text on matters of public interest, must label AI-generated output unless a human has exercised meaningful editorial review. The Guidelines clarify that routine touch-ups are exempt, but altering content to present a materially different reality is not (Addleshaw Goddard).
Industrial and manufacturing
Companies using AI for internal documentation, training materials, or operational reporting must assess whether these outputs trigger marking or disclosure duties, particularly when they reach their external audiences.
Frequently Asked Questions
Do all AI-generated texts need a label?
No. Article 50 does not require labelling every AI-assisted output. The duty applies specifically to AI-generated text on matters of public interest published without meaningful human editorial review, and to AI-generated synthetic content (audio, image, video, text) that must carry machine-readable marking. Routine AI assistance (spell-checking, grammar correction, formatting) does not trigger a disclosure obligation (European Commission).
Does Article 50 apply outside the EU?
Yes. The AI Act applies extraterritorially. Non-EU companies whose AI outputs are intended for use in the EU (meaning foreseeable use, not incidental downstream use) are subject to Article 50. For the deployers, the rule applies where the outputs are foreseen to be disseminated or used in the EU.
What is the fine for non-compliance?
Violations of Article 50 transparency duties can trigger fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. More serious breaches involving prohibited practices can reach €35 million or 7% of global turnover (Stibbe).
What is the December 2026 grace period?
Under the Digital Omnibus on AI, general-purpose AI systems already on the market before 2 August 2026 have until 2 December 2026 to implement the Article 50(2) machine-readable marking requirement. Systems placed on the market after 2 August 2026 receive no grace period marking must be implemented from day one (Faegre Drinker).
What is the difference between AI Act transparency and high-risk obligations?
The transparency obligations under Article 50 are broad, near-term, and apply regardless of whether your AI system is classified as high-risk. They focus on disclosure, marking, and labelling. High-risk obligations under Annex III (covering recruitment tools, credit scoring, biometric identification, and other specified use cases) involve conformity assessment, risk management, documentation, and human oversight. Those obligations were delayed to 2 December 2027 by the Digital Omnibus on AI.
Is the Code of Practice mandatory?
No. Adherence to the Code of Practice on Transparency of AI-Generated Content is voluntary. However, signatories benefit from a presumption of conformity with Article 50 marking and labelling duties, streamlined compliance, and greater legal certainty across EU member states. Non-signatories must document alternative technical measures and demonstrate their equivalency to national market surveillance authorities (EU AI Act Service Desk).
Moving From Uncontrolled AI to Sovereign AI Infrastructure
Article 50 is the first hard deadline companies feel under the AI Act, but it will not be the last. High-risk obligations arrive in December 2027. GPAI enforcement is already live. The regulatory direction is clear: companies will need to prove, not promise, that their AI use is transparent, traceable, and auditable.
For regulated industries, this makes infrastructure a compliance decision. When AI runs through a sovereign control plane on your hardware, behind your firewall, with logs that never leave your network transparency is not a manual checklist. It is a property of the system.
On-prem AI infrastructure helps reduce the blind spots created by fragmented SaaS AI usage. It centralises routing, logging, and disclosure enforcement. And it keeps the audit evidence where it belongs: inside your organisation.
Want to assess your AI transparency readiness? Contact Xinity to map your AI use cases against Article 50 obligations and learn how a sovereign AI control plane makes compliance operational.
This article was drafted with AI assistance and reviewed, fact-checked, and edited by the Xinity team, which takes full editorial responsibility for its content.