This article may contain affiliate links. We may earn a small commission at no extra cost to you if you make a purchase through these links.
EU AI Act Article 50: What Actually Applied on August 2
The Digital Omnibus pushed the EU AI Act's high-risk rules to 2027 and 2028. Article 50 chatbot, deepfake and AI-content duties apply now.

On August 2, 2026, the EU AI Act's high-risk rules did not arrive, but its transparency rules did. The Digital Omnibus on AI moved stand-alone high-risk obligations to December 2, 2027 and product-embedded ones to August 2, 2028. Article 50 kept its date, so chatbot disclosure, deepfake labels and machine-readable marking of synthetic content are enforceable law in the EU today.
That split matters more than the headline delay. For most teams shipping generative AI — a support bot, an image feature, a voice agent, a marketing workflow that produces synthetic video — Article 50 is the part of the AI Act that governs their product right now. High-risk compliance programs got more time. Transparency did not. This guide sets out what changed, what applies as of September 2026, and what to do about it.
What did the Digital Omnibus actually change?
The European Commission proposed the AI Omnibus on November 19, 2025, as part of its wider digital simplification package. The Council and the European Parliament reached a political agreement on May 7, 2026, and the amending law entered into force on July 27, 2026, according to the Commission's announcement. The text is Regulation (EU) 2026/1744, and it amends the original AI Act, Regulation (EU) 2024/1689.
The timing was tight. The amendment took effect six days before the original August 2, 2026 high-risk deadline would have applied. The Commission lists the following changes:
- High-risk dates postponed. Rules for the stand-alone high-risk systems in Annex III (employment, education and similar uses) now apply from December 2, 2027. Rules for high-risk AI embedded in regulated products under Annex I, such as machinery, toys and lifts, apply from August 2, 2028.
- A new prohibition. AI systems that generate non-consensual sexually explicit and intimate content, or child sexual abuse material, are banned. The Commission's AI Act overview says this ban applies from December 2026, and the Gibson Dunn law firm and the independent AI Act Explorer put the exact date at December 2, 2026.
- AI literacy softened. The Commission describes the company-level AI literacy requirement as "simplified", with the Commission and member states taking a larger role.
- Relief for smaller firms. Simplifications that previously applied to SMEs now extend to small mid-cap companies. An EU-level regulatory sandbox and simpler database registration for exempted systems were also added.
- More AI Office enforcement power. The AI Office gets extended oversight of certain AI systems, including those built on general-purpose AI models and those embedded in very large online platforms and search engines.
What the Omnibus did not do is reopen the risk framework or move Article 50. The one concession on transparency is narrow, and it is covered below.
Which AI Act rules apply as of September 2026?
The AI Act is being phased in. The Commission's AI Act overview gives the current timeline:
| Obligation | Applies from | Status as of September 2026 |
|---|---|---|
| Act enters into force | August 1, 2024 | Done |
| Prohibited practices (Article 5) | February 2, 2025 | In application |
| General-purpose AI model rules | August 2, 2025 | In application |
| Article 50 transparency duties | August 2, 2026 | In application |
| Article 50(2) marking for generative systems already on the market before August 2, 2026 | December 2, 2026 | Grace period until December 2, 2026 |
| Stand-alone high-risk systems (Annex III) | December 2, 2027 | Postponed by the Omnibus |
| High-risk AI in regulated products (Annex I) | August 2, 2028 | Postponed by the Omnibus |
Read that table as a product roadmap, not a legal calendar. If your product talks to people, generates media, or reads emotions, the relevant row says "in application".
What does Article 50 require, duty by duty?
Article 50 contains four separate duties. Each is assigned either to the provider (whoever develops the system and places it on the EU market under its name) or to the deployer (an organization using the system in a professional capacity). The Commission's Article 50 FAQ says employees acting under their employer's instructions are not separate deployers. The company is.
1. Tell people they are talking to an AI (providers)
Systems designed to interact directly with people must inform them that they are dealing with an AI system. The exception applies only where this is obvious to a reasonably well-informed, observant and circumspect person, and the Commission's FAQ says that exception should be interpreted restrictively. Do not rely on "users know it's a bot". If your support agent, sales assistant or voice line could plausibly pass for a human, disclose it.
2. Mark synthetic output in machine-readable form (providers)
Providers of systems that generate synthetic audio, image, video or text must make sure outputs are "marked in a machine-readable format and detectable as artificially generated or manipulated." Assistive editing functions, and systems that do not substantially alter the input, are exempt. The Commission's FAQ also excludes source code, machine-to-machine outputs and closed-loop industrial use. This is the duty the Omnibus grace period touches.
3. Inform people about emotion recognition and biometric categorisation (deployers)
Deployers of emotion recognition or biometric categorisation systems must tell the people exposed to them, and must process the personal data in line with EU data protection law.
4. Label deepfakes and AI-written public-interest text (deployers)
Deployers must disclose deepfakes, and AI-generated or manipulated text published to inform the public on matters of public interest. Two exceptions carry most of the weight:
- Evidently artistic, creative, satirical or fictional works need only a disclosure made "in an appropriate manner that does not hamper the display or enjoyment" of the work.
- AI-assisted text under human review or editorial control, where a person or entity holds editorial responsibility, is exempt. The Commission's FAQ says this means substantive examination by someone with authority to approve or reject the content. Spell-checking and grammar correction do not count.
Across all four duties, the information must be given "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure", and it must meet accessibility requirements. A disclosure hidden in the terms of service does not meet that standard.
Is there any grace period for Article 50?
Yes, but it is narrower than many teams assume. Generative AI systems placed on the market before August 2, 2026 have until December 2, 2026 to meet the Article 50(2) marking obligation, according to the Commission's FAQ. According to Pinsent Masons, the negotiators shortened this window from an earlier proposal that ran to February 2, 2027.
Three limits apply:
- It covers machine-readable marking only. Chatbot disclosure, emotion-recognition notices and deepfake labels are not deferred.
- It covers legacy systems only. A generative feature launched on or after August 2, 2026 must mark its output from day one.
- It does not reach backwards: the Commission's FAQ says content generated before August 2, 2026 does not need to be labelled retroactively, though it encourages deployers to do so where possible.
If your image or video generator was live before August 2, 2026, December 2, 2026 is a hard stop. Integrating a watermarking or metadata-signing pipeline takes engineering time, so the work cannot wait for the next planning cycle.
What guidance has the Commission published?
Two documents now define how Article 50 will be read in practice.
The guidelines. On July 20, 2026, the Commission adopted guidelines on the transparency obligations for providers and deployers. They are non-binding, and only the courts can give an authoritative interpretation. National authorities are nonetheless likely to treat them as their main reference point, so a compliance position that contradicts them will be hard to defend.
The code of practice. The Code of Practice on Transparency of AI-generated Content is a voluntary tool. It covers both halves of the problem: provider-side machine-readable marking and deployer-side disclosure of deepfakes and public-interest text. The EU also published a set of icons that deployers of generative AI may use to label content. According to the Commission, the Commission and the AI Board have confirmed the code is "an adequate voluntary tool to demonstrate compliance", and about 190 companies and organizations had signed it by the end of July 2026.
The practical reading: signing the code is optional, but it is the cheapest route to showing a regulator you took the obligation seriously. For a generative AI provider, the code is effectively the implementation spec.
Who enforces Article 50, and what are the penalties?
According to the Commission's FAQ, national market surveillance authorities enforce Article 50 in most cases. The AI Office is competent only for AI systems built on a general-purpose AI model where the same company provides both the system and the model, and for systems integrated into very large online platforms or search engines. The European Data Protection Supervisor covers AI systems used by EU institutions, bodies and agencies. Breaching a transparency duty falls under the AI Act's middle penalty tier in Article 99: fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher. For SMEs, including start-ups, the cap is whichever of the two figures is lower. For comparison, violations of the prohibited practices in Article 5 reach €35 million or 7%.
Expect uneven early enforcement. The Omnibus exists partly because national authorities and standards were not ready for the high-risk regime. Transparency failures are the easiest AI Act violations to spot from outside, though: an undisclosed bot or an unlabeled deepfake is visible to any regulator, journalist or competitor with a browser. That makes Article 50 a likely place for early test cases.
What should your team do now?
Here is the minimum workable program for a company offering AI features to EU users, in priority order:
- Inventory every AI touchpoint. List every chatbot, voice agent, generator, summarizer and emotion or biometric feature that reaches EU users. For each, record whether you are the provider, the deployer, or both. Many companies are both: they build a feature on a third-party model and publish its output themselves.
- Ship disclosure in the interface. Put a clear AI notice at the start of every chat and voice interaction. It needs to be visible and accessible at first contact, not buried in a footer. Our breakdown of AI customer support agents shows how quickly these systems are replacing human-staffed first lines.
- Get marking in place before December 2. If you provide a generative system, wire machine-readable marking into the output pipeline and test that it survives your own export formats. If you rely on a vendor's model, get written confirmation of what marking the vendor applies. The tools covered in our AI image editing comparison are the kind of upstream systems whose marking behavior you should document.
- Set a deepfake and public-interest text policy. Marketing, communications and content teams need a rule for when synthetic media gets a visible label. Where you rely on the editorial-control exemption for AI-assisted text, name the person accountable and record who approved what.
- Read the guidelines and decide on the code. Map your controls against the July 20 guidelines. Then make an explicit decision on signing the code of practice, and record the reasoning either way.
- Keep the high-risk program moving. If any system could fall under Annex III, December 2027 is closer than it looks, and the Omnibus did not remove the conformity work. It only moved the deadline.
The larger takeaway: the EU has made transparency the first AI Act obligation most product teams will be tested on. Transparency is cheap to comply with, visible when it fails, and live today. The high-risk delay was a concession to how hard those rules are to implement. It was not a sign that the EU is backing off. Teams that treat the Omnibus as a general reprieve will have misread the calendar.
Frequently Asked Questions
Did the EU delay the AI Act's August 2, 2026 deadline?
Only partly. The Digital Omnibus on AI, Regulation (EU) 2026/1744, postponed the high-risk obligations to December 2, 2027 for Annex III stand-alone systems and to August 2, 2028 for AI embedded in regulated products. The Article 50 transparency obligations, covering chatbot disclosure, synthetic-content marking and deepfake labels, still applied from August 2, 2026.
Does Article 50 apply to companies outside the EU?
Yes, if they reach the EU market. Under Article 2, the AI Act covers providers placing AI systems on the EU market wherever they are established, and also providers and deployers outside the EU where their system's output is used in the EU. A US company offering a chatbot or image generator to EU users is in scope as a provider, and EU businesses that use those tools professionally carry the deployer duties, such as labelling deepfakes they publish.
Do I have to label AI-assisted blog posts or articles?
Not if a person with editorial responsibility substantively reviews and approves them. The duty covers AI-generated or manipulated text published to inform the public on matters of public interest. Text that has undergone human review or editorial control is exempt. The Commission's FAQ says spell-checking or grammar correction alone does not count as editorial control.
What is the December 2, 2026 deadline?
It is the end of a grace period for machine-readable marking under Article 50(2). It applies only to generative AI systems placed on the market before August 2, 2026. Systems launched after that date must mark their output immediately, and the other Article 50 duties, including chatbot disclosure and deepfake labels, have no grace period.
Is signing the Commission's code of practice mandatory?
No. The Code of Practice on Transparency of AI-generated Content is voluntary, but the Commission and the AI Board have confirmed it is an adequate tool for demonstrating compliance with the transparency obligations. According to the Commission, about 190 companies and organizations had signed it by the end of July 2026. Non-signatories must still meet Article 50 and show how they do it.
Enjoying this article?
Get more strategic intelligence delivered to your inbox weekly.
Enjoyed this article?
VentureBeast.Tech is independent and reader-supported. If this saved you time, you can buy us a coffee — it keeps the research deep and the site ad-light.
Support us on Ko-fi


Comments (0)
No comments yet. Be the first to share your thoughts!