← All posts / Policy

The EU AI Act Just Went Live: What Article 50 Transparency Rules Mean for Every AI Product in Europe

On 2 August 2026 the EU began enforcing Article 50 of the AI Act — chatbot disclosure, deepfake labelling and machine-readable marking of synthetic content — with fines up to €15M or 3% of global turnover.

The EU AI Act Just Went Live: What Article 50 Transparency Rules Mean for Every AI Product in Europe

What happened

On 2 August 2026, the European Commission began enforcing a major new layer of the EU AI Act: the Article 50 transparency obligations, along with the general application of the rest of the regulation (with one big exception explained below). After two years of phased rollouts that mostly concerned prohibited practices and AI literacy, this is the moment the AI Act starts touching everyday digital products — chatbots, image generators, synthetic media, and any customer-facing system that pretends to be human.

The Commission marked the date with an official announcement titled “Safer and more transparent AI”, confirming that national regulators across all 27 member states are now empowered to enforce the new rules, with fines reaching €15 million or 3% of worldwide annual turnover, whichever is higher.

If that sounds like it only concerns Brussels lawyers, think again. Article 50 applies to providers (developers of AI systems) and deployers (companies operating them) alike — meaning a startup in Berlin running a support chatbot, a media company in Madrid publishing AI-generated illustrations, and a platform in Paris hosting synthetic audio all fall under the same regime.

What Article 50 actually requires

The transparency rules boil down to three concrete duties:

1. Disclose that users are talking to an AI

Any system that interacts with humans — chatbots, virtual assistants, customer service agents — must clearly inform users they are communicating with an AI system, unless it is obvious from the context to a reasonably informed user. The exemption is intentionally narrow: burying “AI-powered” in a terms-of-service page will not qualify as disclosure.

2. Label deepfakes and AI-manipulated content

Content that manipulates images, audio, or video to resemble real persons, objects, places, or events — what the regulation calls deepfakes — must be disclosed as artificially generated or manipulated. The disclosure must be made at first exposure and in a way appropriate to the format: a visible label on a video, an audible announcement for synthetic audio, and so on.

3. Machine-readable marking of synthetic content

Beyond human-visible labels, providers of generative AI systems must mark synthetic audio, image, video, and text output in a machine-readable format — think invisible watermarks, metadata signatures, or cryptographic provenance markers such as C2PA. This is the requirement with the deepest technical implications, because it pushes labelling into the model layer itself rather than leaving it as an afterthought at the application layer.

The Omnibus twist: what got postponed, and what didn’t

The story of the August deadline is inseparable from the Digital Omnibus agreement reached in May 2026. In response to intense lobbying from European industry — with executives from Airbus, ASML, Lufthansa, Mistral, and TotalEnergies publicly calling for simplification — the EU postponed the compliance date for high-risk AI systems (Annex III categories like CV screening, credit scoring, and biometric identification) from 2 August 2026 to 2 December 2027. High-risk AI embedded in regulated products (Annex I) received an even longer runway, to August 2028.

Critically, the Omnibus did not postpone the transparency rules. Article 50, the GPAI model obligations, and the general application date all survived intact. There is one grace period: generative AI systems that were already on the market before the obligations took effect have until 2 December 2026 to achieve full compliance with the marking and labelling requirements — a recognition that retrofitting provenance signals into deployed models takes engineering time.

The Commission has also published a Code of Practice on Transparency of AI-generated Content, a voluntary framework that helps companies demonstrate compliance with the marking and labelling duties. Adherence to the code creates a presumption of conformity — an important legal safe harbour for providers who adopt it.

Why it matters now

For AI labs. Every foundation model provider serving EU users — OpenAI, Google, Anthropic, Meta, Mistral, and the open-weight ecosystem — now faces a hard requirement to make their outputs detectable. Google has shipped visible SynthID-adjacent labelling in some products; Anthropic recently introduced invisible watermarks in Claude outputs; and C2PA content credentials have become the de facto industry standard for provenance. But “some visible labelling somewhere” is no longer the test — machine-readable marking across modalities is.

For every company deploying AI. The obligation lands on deployers too, not just model builders. Any business operating a customer-facing chatbot without clear AI disclosure is, as of this month, exposed to enforcement. Legal teams across Europe spent July running emergency audits of AI touchpoints; expect the rest of Q3 to be dominated by compliance sprints.

For the open-source ecosystem. Machine-readable marking is philosophically awkward for open-weight models: anyone can fine-tune away a watermark, and the provider of the original weights arguably cannot control downstream deployments. How regulators treat open-weight models under Article 50 is one of the sharpest open questions in the rollout, and the banks’ recent open letter arguing for lighter treatment of open-weight AI shows the pressure is only growing.

For enforcement reality. The prohibitions in Article 5 (social scoring, manipulative AI, untargeted facial scraping) have been enforceable since February 2025, but enforcement against small operators has been sparse. The August date changes the calculus: transparency violations are comparatively easy to detect — a regulator can simply interact with a chatbot or inspect an image’s metadata — making Article 50 likely the most actively enforced part of the Act in its first year.

What comes next

The compliance calendar from here is now clear:

  • 2 December 2026 — legacy generative systems must complete marking/labelling compliance; new prohibitionsagreed in the Omnibus also take effect on this date.
  • 2 August 2027 — GPAI model providers must finalise training-data transparency and copyright policy compliance.
  • 2 December 2027 — high-risk system obligations (risk management, data governance, human oversight, conformity assessment) finally apply.

In the short term, expect a first wave of Article 50 enforcement actions to target the most visible violations: unlabelled deepfakes during election cycles and customer-facing chatbots that hide their AI nature. National authorities in France, Germany, and Spain have signalled they will prioritise consumer-facing complaints.

The bigger picture: with the US favouring a light-touch, innovation-first approach and China regulating by sector-specific decree, the EU has doubled down on transparency as its regulatory signature. Whether that becomes a global standard — as GDPR did — or a competitive handicap, as its critics warn, will depend on what happens in the next twelve months of enforcement.