← All posts / Policy

The EU AI Act's Transparency Rules Are Now Law: What Article 50 Enforceability Means

Chatbot disclosure, deepfake labels, and machine-readable AI marking became legally enforceable across the EU on August 2, 2026 — here's what Article 50 requires, what the AI Omnibus delayed, and what fines look like.

The EU AI Act's Transparency Rules Are Now Law: What Article 50 Enforceability Means

On August 2, 2026, the European Union crossed a line it drew for itself almost two years ago: the transparency obligations of Article 50 of the AI Act became applicable, and the EU AI Office formally took on its role of implementing, supervising, and enforcing the regulation, including the power to issue fines. Every chatbot serving EU users, every deepfake posted to a European audience, and every synthetic news article now falls under a legal disclosure regime with teeth — administrative fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.

It is the quietest big deadline in tech this year, and it landed while most of the industry was watching model releases. Here’s what actually changed, what got delayed at the last minute, and what companies need to do now.

What Article 50 actually requires

Article 50 of the AI Act imposes four families of transparency duties, and as of August 2 they apply to both providers (developers of AI systems) and deployers (companies operating them):

1. Chatbots must say they are chatbots. Any AI system that interacts with natural persons — customer support agents, voice assistants, conversational search — must inform users, clearly and at the first interaction, that they are talking to a machine unless it is obvious from the circumstances.

2. Deepfakes must be labelled. Deployers of systems that generate or manipulate image, audio, or video content (the “deepfake” category) must disclose that the content has been artificially produced or modified. There is a carve-out for evidently artistic, creative, satirical, or fictional work, but the disclosure obligation remains in a machine-readable form even when the visible label is not required.

3. AI-generated text on matters of public interest must be disclosed. Publishers using generative AI to produce text intended to inform the public on matters of public interest must label it — unless a human took editorial responsibility and the content went through human review. This is the clause aimed squarely at AI-generated news.

4. Emotion recognition and biometric categorisation systems must notify. Systems that infer emotions or categorise people by biometric data must inform the people exposed to them. Emotion recognition in workplace and education settings was already banned outright under the Act’s prohibited-practices tier in 2025.

The regime is extraterritorial. As several law firm analyses have pointed out, UK, US, and Asian companies serving European users are in scope — the trigger is placing systems on the EU market or their output being used in the EU, not where the company is incorporated.

The two-track duty: marking is not labelling

One of the most consequential clarifications came in the Commission’s Guidelines on transparency, finalised at the end of July 2026 and summarised by Paul Weiss on August 4. The AI Office made explicit that a provider’s machine-readable marking obligation does not discharge the deployer’s duty to label — and vice versa.

In practice, this creates a chain of custody for synthetic content. The model developer must embed machine-readable marks (watermarks, metadata, provenance signals) in outputs across all modalities — audio, image, video, and text. The deployer — the website publishing the content, the platform distributing the video, the app rendering the voice — must ensure humans are actually informed, usually through a visible label. A social platform cannot argue “the model watermark was there” if users never saw a disclosure. Both links are independently liable.

To make this operational, the Commission’s AI Office published the final Code of Practice on Transparency of AI-Generated Content in June 2026, opened for signature in late July. The Code details marking standards, detection mechanisms, and how signatories can demonstrate compliance. Signing it is voluntary, but adherence creates a presumption of conformity that regulators will weigh heavily — the same carrot-and-stick architecture used for the GPAI Code of Practice before it.

What the AI Omnibus delayed — and what it didn’t

The August 2 date almost didn’t hold. The AI Omnibus package — proposed by the Commission on 19 November 2025, politically agreed on 7 May 2026, and in force since late July 2026 — restructured the AI Act’s compliance calendar in response to industry and member-state pressure:

  • Annex III high-risk systems (AI in credit scoring, insurance pricing, hiring, education, and law enforcement) saw their obligations pushed to December 2, 2027. This is the delay that spared banks and insurers — the “credit-scoring AI” reprieve.
  • Annex I high-risk systems (AI embedded in regulated products like machinery and medical devices) move to 2027–2028 depending on sector legislation.
  • Generative AI systems already on the market before August 2, 2026 received transition relief for marking obligations, recognising that retrofitting watermarking into deployed models takes engineering time.

Crucially, the Omnibus did not touch Article 50. The transparency obligations took effect on August 2 as originally scheduled — the Commission explicitly kept them intact while conceding on the high-risk tier. Civil-society groups, including CDT, have criticised the Omnibus for diluting fundamental-rights protections, notably shifting the AI-literacy obligation away from providers and deployers. The compromise landed anyway, and transparency became the one pillar that arrived on time.

Enforcement: real, but not instant

Two enforcement realities temper the shock of the new regime.

First, national authorities and the AI Office are working with a grace period: with a recently agreed three-month buffer, enforcement activity is expected to begin in earnest around December 2, 2026 — the same date a new prohibition on AI systems generating non-consensual intimate imagery takes effect. That gives companies one working quarter to inventory their AI touchpoints.

Second, fines under Article 99 are tiered. Article 50 violations sit in the middle tier — €15 million or 3% of global turnover — while prohibited-practice violations reach €35 million or 7%. Supplying incorrect, incomplete, or misleading information to regulators carries its own penalties of €7.5 million or 1%.

What to do now

For any organisation touching EU users, compliance work in the next quarter should include: an inventory of every AI system that interacts with or generates content for users; visible disclosure flows for conversational interfaces; a labelling pipeline for synthetic media; verification that upstream model providers deliver machine-readable marks (and contractual indemnities where they don’t); and a decision on whether to sign the Code of Practice. Free-text approaches will not survive contact with regulators — the Commission has already published standard EU labelling icons for AI-generated content.

The broader signal matters more than any single clause. Europe’s AI rulebook has moved from debate to enforcement reality, and its first target is the one thing every AI company ships: output. Model capabilities keep compounding, but in the EU, an unlabelled synthetic video is no longer a policy question — it is a violation with a number attached.