From Ritu Raj | Product & Market Analysis
The EU AI Act Transparency Rules Landed on 2 August 2026. What Applies to You
On this page
The EU AI Act transparency rules applied from 2 August 2026, and the ceiling for breaching them is 15 million euros or 3% of worldwide annual turnover, whichever is higher. These are not the high-risk rules, which were pushed to December 2027. They catch ordinary software: chatbots, generated copy, synthetic images, AI-drafted commentary. Most of the companies now in scope never expected to be.
Key takeaways
- The transparency rules were not delayed. The high-risk rules were. The Digital Omnibus on AI entered into force on 27 July 2026 and moved Annex III high-risk obligations to 2 December 2027. Article 50 stayed exactly where it was.
- The duty splits by role, not by company size. Providers disclose and mark at design time. Deployers label at publication time. A 12-person firm running a support chatbot and publishing AI-drafted market notes is both at once.
- Marking synthetic content is the hard part, and the Commission concedes no single method works. The Code of Practice asks for at least two layers of machine-readable marking plus a detection route that outsiders can use.
- The gap is enforcement capacity, not law. Only 9 of 27 member states had designated both a market surveillance authority and a notifying authority as of 17 June 2026, almost a year after the deadline.
What changed on 2 August 2026, and what did not
Article 50 of the EU AI Act applied from 2 August 2026. It requires four disclosures. Tell people when they are talking to an AI. Mark AI-generated content in a machine-readable form. Say when emotion recognition or biometric categorisation is running. Label deepfakes and AI-written text published on matters of public interest.
The rules that did not arrive are the ones most compliance budgets were pointed at. The Digital Omnibus on AI was published in the Official Journal on 24 July 2026 and entered into force three days later. It deferred the Annex III high-risk obligations to 2 December 2027, and Annex I products to 2 August 2028. The sandbox deadline for member states moved to 2 August 2027.
Article 50 was left alone. A lot of teams missed that, because the July coverage was almost entirely about a delay. My view is that the coverage did active harm. It told companies with no high-risk system that they had another 16 months, when the obligation that applies to them arrived on schedule.
The one-year grace period that also closed
A second thing happened on the same date and drew less attention. The Commission's power to fine providers of general-purpose AI models became applicable.
Obligations on those providers have applied since 2 August 2025. Article 113 held back Article 101, the fining power, for a full year. That year is now over. Through the AI Office the Commission can issue requests for information, run model evaluations and demand access to a model. It can also impose fines of up to 3% of worldwide annual turnover or 15 million euros, whichever is higher.
If you build on somebody else's model rather than training your own, that is not your obligation. It belongs to your supplier, and it changes what you can reasonably ask them to put in writing.
| Obligation | Original date | Date now |
|---|---|---|
| Article 50 transparency obligations | 2 August 2026 | Unchanged |
| Commission fining power over general-purpose AI providers | 2 August 2026 | Unchanged |
| Machine-readable marking for generative systems already on the market | 2 August 2026 | 2 December 2026 |
| Annex III high-risk systems | 2 August 2026 | 2 December 2027 |
| High-risk AI embedded in regulated products, Annex I | 2 August 2027 | 2 August 2028 |
| Regulatory sandboxes in every member state | 2 August 2026 | 2 August 2027 |
Deferral dates from the Gibson Dunn analysis of the Omnibus agreement. The four-month extension on marking applies only to generative systems placed on the market before 2 August 2026. Anything shipped after that date had no transition at all.
The four duties, and which one is yours
The distinction that decides everything is provider against deployer. A provider develops an AI system and puts it on the market under its own name. A deployer uses one under its own authority. The same company is routinely both, and the two sets of obligations do not merge into one.
| Paragraph | What it requires | Who carries it | Main exemption |
|---|---|---|---|
| 50(1) | Tell people they are interacting with an AI system | Provider | Obvious to a reasonably well-informed, observant person |
| 50(2) | Mark generated audio, image, video and text in a machine-readable format | Provider | Assistive or standard editing that does not substantially alter the input |
| 50(3) | Inform people exposed to emotion recognition or biometric categorisation | Deployer | Systems permitted by law to detect or investigate crime |
| 50(4) | Label deepfakes, and AI text published to inform the public on matters of public interest | Deployer | Substantive human review with editorial responsibility assumed |
Obligations and exemptions are summarised from Article 50 of the Regulation and the Commission guidelines adopted 20 July 2026. The exemption column is compressed. Each one carries conditions that the guidelines read narrowly.
Article 50(1), the rule about chatbots and agents
Providers must design systems that interact directly with people so the person knows they are dealing with an AI. The disclosure has to arrive at the point of first interaction at the latest. It has to be noticeable, easy to understand and clearly separate from surrounding content. Burying it in terms of service or a layered settings menu does not meet the standard.
There is an exemption where the AI is obvious to a reasonably well-informed and observant person. The Commission guidelines apply an average-consumer benchmark, weighing the target audience, vulnerable groups and general digital literacy. Code assistants for professional developers and non-player characters in games may fall outside. Help desk chatbots, AI avatars and companion robots very likely do not.
This is also the paragraph that catches autonomous agents. If your product runs an agent that emails, messages or calls a customer, that customer has to be told. It is worth reading against what agent orchestration tools actually do once they reach production, because the disclosure point moves as the agent gains initiative.
Article 50(2), the rule about marking output
Providers of generative systems must mark synthetic audio, image, video and text in a machine-readable format, detectable as artificially generated or manipulated. The standard is the technical state of the art, tempered by cost and technical feasibility.
The guidelines make one point that small vendors will dislike. The standard is objective and does not scale with your resources. A 15-person company shipping an image generator is measured against currently available technology, not its own engineering budget.
The exemptions are narrow. Assistive and standard editing functions that do not substantially alter the input are outside scope, which covers grammar correction and similar tools. So are closed industrial settings where the risk of deceiving anyone is low.
Article 50(3), emotion recognition and biometric categorisation
Deployers must inform every natural person exposed to the system's operation, at the point of first exposure. Written notice, an icon or a spoken announcement are all acceptable. This duty is narrow in scope and wide in embarrassment. Interview scoring, sentiment analysis on recorded support calls and age estimation in retail all sit inside it.
Article 50(4), deepfakes and public-interest text
Deployers must disclose that a deepfake was artificially generated or manipulated. Whether the deployer intended to deceive anyone is irrelevant. The guidelines look instead at the likely composition of the audience, and the threshold drops noticeably where children or vulnerable groups are among them.
Content inside evidently artistic, creative, satirical or fictional work gets a lighter regime rather than an exemption. The Commission reads those categories strictly, and where a piece mixes informative and creative elements the informative character prevails.
The marking problem nobody has solved
The Commission published the final Code of Practice on Transparency of AI-generated Content on 10 June 2026. It runs in two sections: provenance measures for providers under Article 50(2), and labelling rules for deployers under Article 50(4).
The most useful sentence in the framework is an admission. No single marking technique satisfies all four criteria the law implies: effectiveness, interoperability, resistance to removal and reliability. The Code responds by asking for layers rather than one method.
Providers are asked to apply at least two layers of machine-readable marking where necessary. In practice that means embedded metadata alongside a watermark. They are also asked to publish a detection route so deployers, users, authorities, researchers and media organisations can check a file rather than trust the label.
Detection as an obligation is the sharpest design choice in the Code. Marking on its own is a claim. Marking with a public detection endpoint is a claim an authority can test.
Text is the weakest case in the set, and I would not build a compliance story on it. Metadata almost never survives a copy and paste. Text watermarks degrade under paraphrase, translation and reformatting. Deployer-side labelling in Section 2 is carrying more weight than the provenance layer.
Two practical consequences follow. The cost lands in cost of goods sold, not in a legal line item. That is where every other per-request AI cost lands, and it is worth reading against what AI cost of goods does to reported gross margin. Building marking yourself or taking your supplier's implementation is the same calculation as every other build against buy decision in this stack. The wrinkle is that liability does not transfer when the code does.
The rule that catches publishers who do not think they are publishers
The second limb of Article 50(4) is the one I expect to be breached most often. Deployers who publish AI-generated or AI-manipulated text to inform the public on matters of public interest have to disclose that it is AI-generated.
The guidelines define matters of public interest broadly. Politics, public administration, justice, public health, consumer safety, and cultural, financial or scientific developments open to public debate are all named categories.
That is a wide net for an ordinary B2B content team. A commentary on AI capital spending is a financial development open to public debate. An explainer about a new regulation is one as well. Neither reads like journalism to the person writing it, and neither has to.
There is an exemption, and it is narrower than it looks. No label is required where the text has had human review and someone has assumed editorial responsibility. The Commission wants deliberate examination of the substance by a person with relevant competence and professional judgement. Spell-checking, grammatical correction and cursory approval do not qualify.
A marketing team running a generation pipeline with a five-minute skim before publish is not obviously inside that exemption. Nobody on that team is reading the AI Act either, which is precisely why this obligation will be missed quietly and at volume.
The rule is not retrospective. Content generated before 2 August 2026 sits outside it. Text generated before that date but published after it sits inside, unless the editorial control exemption carries it.
The enforcement gap is real, and it is temporary
Member states had until 2 August 2025 to designate a market surveillance authority and a notifying authority. As of 17 June 2026, 9 of the 27 had designated both. Twelve had a pending legislative proposal, an announcement, or one of the two authorities. Six had neither.
No public penalty has been issued under Article 50. Three weeks in, with two thirds of the enforcement machinery half built, that is exactly what you would expect.
The Commission opened three reporting routes alongside the obligations. A general complaint tool for any person or company alleging an infringement. A whistleblower channel for people professionally connected to a provider. And a separate channel for downstream providers integrating somebody else's general-purpose model.
That third channel deserves a moment. Your customers and integration partners now have a formal, no-cost route to raise a compliance question about your product, and it does not pass through your account manager first.
I would not read the designation gap as a reprieve, and the reason is procedural rather than moral. Complaints filed now create a docket that outlives the gap. Authorities standing up in 2027 will inherit a queue, and the oldest entries in that queue will concern conduct from 2026.
Whether to sign the Code of Practice
The Code is voluntary. Signing it is the documented way to demonstrate compliance with the marking and labelling duties. Declining means demonstrating the same thing through alternative and equivalently adequate means, which in practice is a gap analysis you write, maintain and defend on your own.
By the end of July 2026 roughly 190 organisations had signed, split 82 to the provider section and 152 to the deployer section. About half were small and recent companies. The named list runs from Anthropic, Google, Meta, Microsoft and OpenAI through to Getty Images, Lenovo, Lufthansa, Bulgari and Iberdrola.
The guidelines indicate that signatories receive a focused compliance assessment and a degree of regulatory trust. Non-signatories have to prove the same position from scratch. For a small deployer with no in-house legal function, that asymmetry settles it. I would sign the deployer section and put the saved effort into the inventory instead.
Where this argument is weakest
Three places, and the first one undercuts the urgency in the headline.
The case that this is a modest labelling exercise
For most B2B software companies, the honest cost of Article 50 is a few engineering days, a policy page and a vendor questionnaire line. Presenting it as a compliance crisis oversells it. If you sell reporting software to accountants and your only generative feature drafts email replies, you have a disclosure to add and very little else. The reason to act quickly is that the work is small, not that the risk is large.
The guidelines are not binding
They are Commission guidance. They shape how national authorities are expected to read Article 50, and they bind neither a regulator nor a court. Twenty-seven authorities applying non-binding guidance to a young statute will produce divergent readings for several years. A firm that follows the guidelines closely is well positioned rather than safe.
Nobody has been fined yet
The 15 million euro figure is a ceiling under Article 99(4)(g), not an expected value. Article 99(6) caps fines for small and medium enterprises at whichever of the amount or the percentage is lower, which inverts the usual reading. Any vendor quoting the ceiling as your exposure is selling something. Until a national authority publishes a first decision, the real cost of non-compliance is genuinely unknown.
A checklist for a company that is not an AI lab
This is the version for a software or services business with fewer than a few hundred people. No high-risk system, and a normal amount of AI in the product and the marketing.
| Action | Owner | Evidence to keep |
|---|---|---|
| Inventory every AI feature you ship or use, and mark each one provider or deployer | Product | Dated register with system name, role and the Article 50 paragraph it touches |
| Add a first-interaction disclosure to every customer-facing chatbot, voice agent and avatar | Engineering | Screenshot or recording of the disclosure at first contact |
| Confirm your model and image suppliers mark output, and get the detection route in writing | Procurement | Supplier statement, or their Code of Practice signature reference |
| Decide whether your content review step is substantive, and label everything where it is not | Marketing | Named reviewer per published piece, with a date |
| Check any emotion, sentiment or biometric feature and notify the people exposed to it | Operations | The notice text, and where in the flow it appears |
| Decide on the Code of Practice, and record the reason either way | Founder | Signature confirmation, or the gap analysis that replaces it |
Two notes on running this. Do the inventory first, because most companies cannot answer the provider or deployer question about their own products without one. And keep evidence rather than intentions: a dated register and a screenshot are readable by an authority, a policy document nobody followed is not.
The wider point is that this is measurable work with a measurable cost, in the same category as every other AI line item. The discipline that applies to proving where AI return has actually shown up applies here too. Write down what you did, when you did it, and who checked it.
Frequently asked questions
Does the EU AI Act apply to companies outside the EU?
Yes, in three situations. Article 2 covers providers placing an AI system on the EU market, wherever they are established. It covers deployers located in the Union. It also covers providers or deployers in a third country where the output produced by the system is used in the Union. That last trigger is the broad one. Selling nothing into Europe does not settle the question if your output ends up being used there.
What are the EU AI Act transparency requirements from August 2026?
Article 50 sets four. Providers must tell people when they are interacting with an AI system, and must mark generated audio, image, video and text in a machine-readable format. Deployers must inform people exposed to emotion recognition or biometric categorisation systems, and must label deepfakes and AI-generated text published to inform the public on matters of public interest.
Do I have to label AI-generated text on my company blog?
Only if it is published to inform the public on a matter of public interest, which the Commission defines to include politics, public health, consumer safety and financial or scientific developments open to debate. No label is needed where the text has had substantive human review and a person has assumed editorial responsibility. Spell-checking and cursory approval do not count as review.
What are the fines for breaching Article 50 of the EU AI Act?
Up to 15 million euros or 3% of worldwide annual turnover for the preceding financial year, whichever is higher, under Article 99(4)(g). For small and medium enterprises, including start-ups, Article 99(6) caps the fine at whichever of those two figures is lower. National authorities set and impose these penalties, and no public decision under Article 50 had been published as of 21 August 2026.
Did the Digital Omnibus delay the August 2026 AI Act deadline?
Not for transparency. The Digital Omnibus on AI entered into force on 27 July 2026 and deferred the high-risk obligations for Annex III systems to 2 December 2027, and for Annex I products to 2 August 2028. Article 50 applied from 2 August 2026 as originally written. Generative systems already on the market received until 2 December 2026 for machine-readable marking.
Do I need to sign the Code of Practice on Transparency of AI-generated Content?
No. It is voluntary. Signing gives providers and deployers a documented route to demonstrate compliance with the marking and labelling obligations. Declining means showing compliance through alternative and equivalently adequate means, which you have to design and defend yourself. Around 190 organisations had signed by the end of July 2026, split across the provider and deployer sections.
Where to start this week
Pick your three most customer-facing AI features and answer one question about each. Are we the provider here, or the deployer? Write the answer down with a date on it. That single sheet is the input to everything else in the checklist, and most teams cannot produce it today.
Then look at your content pipeline. If any published text is drafted by a model and touches politics, public health, consumer safety or financial matters, decide this week whether your review step is substantive enough to carry the exemption. If you are unsure, label it. The label costs nothing and it removes the question permanently.
Related on the cost side
Marking, detection and disclosure are recurring per-request costs, not a one-off project. What that does to a software gross margin is worked through in the piece on AI cost of goods and real gross margin.
References
- European Commission, Guidelines on transparency obligations for providers and deployers of certain AI systems, adopted 20 July 2026. Used for scope, exemptions, disclosure timing and the human review test.
- European Commission, Code of Practice on Transparency of AI-generated Content, published 10 June 2026. Used for the layered marking requirement, detection mechanisms and deployer labelling.
- European Commission, Strong backing for the Code of Practice on Transparency of AI-generated Content, 31 July 2026. Used for the signatory counts and named signatories.
- European Commission, The enforcement framework of the AI Act. Used for AI Office powers over general-purpose AI models and the three complaint channels.
- Regulation (EU) 2024/1689, Article 50. Used for the four transparency obligations and their exemptions. Articles 101 and 113 used for the fining power and the application dates.
- Regulation (EU) 2024/1689, Article 99. Used for the penalty tiers and the small and medium enterprise cap in Article 99(6).
- EU AI Act, national implementation tracker, status as at 17 June 2026. Used for the designation counts and the named member states.
- Gibson Dunn, EU AI Act Omnibus Agreement, Postponed High-Risk Deadlines and Other Key Changes, 2026. Used for the deferred dates and the four-month marking transition.
The weakest link in this source base is the count of designated national authorities. It comes from a third-party tracker rather than a Commission register, it was last verified on 17 June 2026, and designations happen without announcement. Treat 9 of 27 as a floor for that date rather than a current figure, and check the tracker before quoting it.
Related reading