The European Commission published its final guidance on AI transparency requirements July 20, 2026 — one day ago — giving every company that runs a chatbot, generates AI images, or publishes AI-written content for EU audiences 11 days to comply or face fines that can reach €15 million or 3 percent of worldwide annual turnover, whichever is higher. The August 2 enforcement date is a Sunday. That will not delay it.
What the final guidelines add that the May 2026 draft did not is legal finality: an official Commission instrument that national market surveillance authorities across all 27 EU member states are expected to treat as the primary reference for Article 50 compliance assessments, according to William Fry’s analysis of the guidelines. There is also something the guidelines cannot add but the underlying technology still lacks — a reliable, universally accepted method of embedding machine-readable watermarks in AI-generated audio, images, video, and text that survives compression, social media re-upload, or screenshot. According to Natalia Garina, a legal researcher who analyzed the Code of Practice for Tech Policy Press, no single marking technology currently meets all four requirements Article 50 imposes: effectiveness, interoperability, robustness, and reliability. Common evaluation benchmarks for measuring compliance do not yet exist.
Companies that want documented regulatory cover face a more immediate date: July 22, 2026 at 6 p.m. Central European Summer Time — tomorrow afternoon. That is the deadline to submit a signatory form to the EU AI Office and appear on the initial list of Code of Practice signatories. Signing confers a presumption of regulatory conformity; it shifts the evidentiary burden toward regulators rather than companies. Missing it is not a violation, but non-signatories will face more frequent information requests and must demonstrate compliance on their own.
What Article 50 Actually Requires
Article 50 governs the “transparency risk” category in the EU AI Act’s four-tier framework — the class of AI systems that can deceive users about whether they are dealing with a machine or whether content they encounter was generated by AI. The guidelines clarify four concrete disclosure obligations.
Chatbot providers face the most visible requirement: any AI system designed for direct two-way interaction with a real person — chatbots, AI agents, and conversational avatars — must tell users from the very first exchange that they are talking to an AI. The guidelines define four criteria that must all be present before the obligation applies: the system must qualify as an AI system, it must be designed for genuine two-way exchange, the interaction must be direct rather than mediated by a human, and it must involve a natural person.
The “obvious exception” — cases where notification can be skipped because the AI nature of the interaction is self-evident — must be interpreted narrowly and cannot become a routine workaround, according to the guidelines. A branded robot avatar in a product interface may qualify, but implicit UI cues alone are unlikely to clear the bar where a user could reasonably believe they are speaking with a human.
Providers of generative AI systems bear the technical marking obligation under Article 50(2): audio, images, video, and text outputs must be embedded with machine-readable marks that allow detection as artificially generated or manipulated, per the guidelines. Short numerical sequences, source code, and content confined to closed industrial loops are excluded. Outputs generated by AI for minor assistive functions — spell-checking, grammar correction that does not substantially alter a document’s substance or meaning — are also exempt.
Deployers, meaning businesses or individuals who use AI systems within their own products or services, carry two additional obligations. They must visibly disclose any content meeting the legal definition of a deepfake — AI-generated or AI-manipulated image, audio, or video that resembles real people, objects, or places and could plausibly deceive a viewer — at first exposure, in a clear and perceptible manner, as set out in the guidelines. The guidelines state that providers’ machine-readable marks alone cannot discharge this obligation; the deployer must add its own visible label. The obligation applies regardless of whether any deceptive intent was present.
Deployers who use generative AI to produce or distribute text on matters of public interest — politics, public administration, law enforcement, public health, environmental protection — must clearly label that content unless it has undergone genuine human review, according to the guidelines. Spell-checking and formatting do not qualify as human review; peer review, professional validation, and editorial decisions made by a legally accountable editorial entity do.
What a Deepfake Legally Is
The guidelines’ three-part definition of a deepfake matters for deployers who need to know which of their AI outputs require a visible label. Three cumulative factors must be present: a high degree of resemblance to an existing subject; the existence or plausible existence of that subject in reality; and the capacity of the content to falsely appear authentic to a viewer.
AI-generated videos of politicians or celebrities, AI-generated voice clones, and AI-manipulated images placing real people in fabricated situations will most likely qualify, according to the Code of Practice analysis by Garina. Clearly fictional content that would not reasonably be perceived as authentic — talking animals, impossible imaginary scenes — falls outside the definition. Color correction, noise reduction, or compression does not trigger the obligation, though the assessment remains context-dependent.
Artistic and satirical works face a reduced obligation: disclosure is required in a manner that does not impair the enjoyment or display of the work, per the guidelines.
Why No Single Watermarking Tool Meets the Standard
The marking obligation under Article 50(2) is where technology and law most visibly diverge, and understanding that gap is essential for any compliance team, as Garina’s analysis explains.
Two primary approaches are in active deployment. The first, content provenance metadata embedding, uses the Coalition for Content Provenance and Authenticity (C2PA) standard — a cryptographically signed record of a file’s creation, editing history, and AI involvement, embedded in the file’s metadata. C2PA is co-developed by Adobe, the New York Times, Microsoft, BBC, and others, and is now built into camera firmware from Sony, Nikon, and Canon. Its fundamental limitation: C2PA metadata is easily stripped when a file is screenshot, re-uploaded to a social media platform, or converted between formats.
The second approach, imperceptible watermarking, embeds invisible patterns directly into pixels, audio samples, or text tokens. Google DeepMind’s SynthID is the most widely known implementation, using deep learning to embed markers that survive compression, cropping, and re-encoding better than metadata does. But watermarks can still degrade under aggressive image processing, and no independent standard exists for measuring their reliability across providers.
The Code of Practice acknowledges this directly: it mandates a layered approach combining metadata embedding, imperceptible watermarking, and logging — not because any one method works, but because each protects against failure modes the others cannot, as Garina’s analysis documents. Garina’s analysis notes the Code “sets out how to meet the transparency obligations before common evaluation standards have fully emerged,” which means companies must begin demonstrating compliance before the technical benchmarks for measuring compliance are established.
A separate academic critique published in the journal Computer Law and Security Review in July 2026 found that Article 50(1) — the chatbot disclosure obligation — insufficiently safeguards the rights of individuals, particularly vulnerable groups because of narrow content requirements, limited effective remedies, and broad exceptions for “obvious” AI interactions.
Who Faces Enforcement and How
Enforcement begins at the national level, with market surveillance authorities in each of the 27 EU member states responsible for monitoring compliance and initiating proceedings. The European AI Office holds a limited supervisory role covering systems built on general-purpose AI models where the same entity both develops the underlying model and deploys the system. The European Data Protection Supervisor handles cases involving EU institutions.
The extraterritorial reach follows the same logic as the GDPR: Article 50 applies to any provider or deployer whose AI system’s output is used inside the European Union, regardless of where the company is headquartered, incorporated, or where its servers are located, as Garina’s analysis confirms. A US startup whose chatbot is available to French or German users falls within scope beginning August 2.
Penalties for non-compliance with Article 50 can reach €15 million or 3 percent of total worldwide annual turnover for the preceding financial year, whichever is higher, per William Fry’s analysis. EU institutions that violate the obligations are subject to a separate ceiling of €750,000.
One specific obligation carries a targeted grace period. Providers of generative AI systems that were already on the EU market before August 2 have until December 2, 2026 to bring their machine-readable marking capabilities into conformity with Article 50(2), under the EU Digital Omnibus provisional agreement of May 7, 2026. Systems placed on the EU market on or after August 2 must comply from that date. All other Article 50 obligations — chatbot disclosure, deepfake labeling, AI-generated public-interest text labeling — apply from August 2 without exception. Content already in circulation before August 2 does not need to be retroactively labeled, though the Commission has said it encourages relevant deployers to do so where feasible, according to the guidelines.
The Code of Practice: How to Prove Compliance
The guidelines are accompanied by a separate voluntary Code of Practice on Transparency of AI-Generated Content, developed by independent experts and formally assessed as adequate by the Commission in July 2026. The AI Board’s formal endorsement is still required before the Code fully operates as a compliance instrument.
The Code is designed as a practical compliance demonstration specifically for the marking and labeling obligations under Articles 50(2), (4), and (5). Providers and deployers that sign the Code can point to their adherence as evidence of compliance, shifting regulatory scrutiny toward those who do not sign, as Garina’s analysis explains. Signing is partial participation by design: the Code consists of two independent sections, one for providers and one for deployers, which can be signed separately.
Signing by tomorrow’s 6 p.m. CEST deadline earns a place on the initial signatory list, which the AI Office will publish before August 2, per the signatory form page. Missing the deadline does not permanently exclude a company from signing later, but it does mean the company’s name will not appear on the initial published list when enforcement begins. The Commission’s adequacy opinion and the AI Board’s formal endorsement were both adopted on July 9, giving the Code full legal standing as a compliance instrument.
The Commission has also released a set of optional standardized EU icons — “AI” labels for English, “KI” for German, “IA” for French, and equivalents across all 24 EU languages — that deployers can use for visible content labeling. Use of these icons is voluntary; they provide a recognized shorthand but are not the only permissible form of disclosure.
The Code does not cover the chatbot disclosure obligation under Article 50(1), which is addressed exclusively in the guidelines. Companies with conversational AI deployments must implement compliant disclosure mechanisms on their own, informed by the guidelines’ criteria but outside the Code’s safe-harbor framework.
What Happens After August 2
The August 2 date begins enforcement, not perfection. The guidelines explicitly acknowledge that technical standards for measuring compliance with the watermarking obligation are still being developed through the Code of Practice and EU standardization work, according to the AI Act transparency guide. How individual market surveillance authorities interpret and enforce Article 50 in practice will shape the real compliance landscape more than the text of the guidelines alone.
One legal uncertainty remains outstanding: the EU Digital Omnibus package — which establishes the December 2 grace period for pre-existing generative AI marking — had reached a provisional agreement between the European Parliament and Council as of May 7, 2026 but had not been formally adopted in the Official Journal as of mid-July 2026, according to a compliance analysis published July 17. Until that publication occurs, the December 2 deadline extension is not yet legally binding, and companies should monitor the Commission’s AI Act regulatory page for the formal adoption notice before finalizing compliance timelines.
The guidelines are available for download on the European Commission’s digital strategy website.
Frequently Asked QuestionsDoes EU AI Act Article 50 apply to companies based outside Europe?
Yes. Article 50 follows the same extraterritorial logic as the GDPR: the trigger is market access, not physical location or legal incorporation. Any company whose AI system’s output is used by people inside the European Union falls within scope beginning August 2, 2026, regardless of where the company is headquartered, where its servers are located, or whether it has an EU legal entity. A US, UK, or Canadian startup with EU users must comply on the same timeline as a company incorporated in Berlin or Paris, as Garina’s analysis confirms.
What exactly must a chatbot say to comply with the disclosure requirement?
The guidelines do not mandate specific language, but they require that users be clearly informed they are interacting with an AI system at the very first exchange — not buried in terms of service or disclosed only on an “about” page. The notification must be clear and accessible, and must meet accessibility requirements for users with disabilities. The “obvious exception” — where no notification is needed because the AI nature is self-evident — is interpreted narrowly and must be assessed from the viewpoint of a reasonably well-informed, attentive user. A visually distinct robot avatar may satisfy this in some contexts; a chatbot with a human name and conversational style will almost certainly not, per the guidelines.
What is the watermarking requirement, and can any current technology actually meet it?
Article 50(2) requires that generative AI outputs — audio, images, video, and text — be marked in a machine-readable format that allows detection as artificially generated or manipulated. No single current technology fully meets all four statutory requirements: effectiveness, interoperability, robustness, and reliability. The C2PA content credentials standard can be stripped by a screenshot or social media re-upload. Imperceptible watermarks like Google’s SynthID survive more processing but are not universally robust. The voluntary Code of Practice therefore mandates a layered approach combining metadata, watermarking, and logging — and explicitly sets out requirements in advance of the industry benchmarks needed to measure them. Pre-existing generative AI systems have until December 2, 2026 to comply with this specific obligation, as Garina’s analysis details.
What is the Code of Practice, and does signing it guarantee compliance?
The Code of Practice on Transparency of AI-Generated Content is a voluntary compliance framework developed by independent experts and assessed as adequate by the European Commission. Signing it confers a presumption of regulatory conformity with the marking and labeling obligations under Articles 50(2), (4), and (5), meaning national market surveillance authorities are expected to treat signatories as compliant unless they find specific evidence otherwise. Signing does not guarantee compliance and does not remove other obligations under the AI Act for high-risk systems or general-purpose AI models. Non-signatories face the same underlying legal obligations but must demonstrate compliance independently, and can expect closer regulatory scrutiny, as Garina’s analysis explains.
