On 2 August 2026, the transparency obligations in Article 50 of the EU AI Act began to apply. Relative to Article 50, the EU Digital Omnibus (which amended the EU AI Act) only deferred certain specific obligations. As such, the bulk of the Article 50 obligations are already applicable to organizations subject to the EU AI Act.
Below is a high-level overview. An upcoming accompanying LawFlash will examine the obligations and exceptions contained in Article 50, the Commission’s Guidelines, and the Code of Practice referenced below in more detail.
What Does Article 50 Cover?
Broadly, Article 50 requires organizations subject to the EU AI Act to, in certain circumstances, disclose to individuals when they are interacting with AI, when emotion-recognition or biometric-categorisation systems are used in relation to them, and when certain content has been generated or manipulated by an AI system.
Importantly, an organisation’s obligations depend on its role within the relevant AI “ecosystem,” namely whether it is a “provider” or “deployer” of the relevant AI system. Broadly, a provider is the organization that has developed an AI system and “places it on the [European Economic Area (EEA)] market” or “puts it into service” under its own name or trademark.
By contrast, a deployer is an organization using a provider’s AI system without substantial modification or white-labelling, and other than for a personal, nonprofessional activity.
What Went into Effect on 2 August?
For Providers
Providers of AI systems that
- are intended to interact directly with individuals must ensure that individuals are appropriately informed that they are interacting with such a system, unless this would already be obvious to individuals
- generate synthetic text, images, audio, or video must also ensure that relevant outputs are appropriately marked in a machine-readable format and can be detected as artificially generated or manipulated.
The transition period described below applies to certain AI systems already on the EEA market.
For Deployers
Deployers of AI systems involving
- emotion-recognition or biometric-categorisation systems must appropriately inform the individuals exposed to those systems
- certain AI-generated or manipulated content (including deepfakes and certain text published to inform the public about “matters of public interest”) must make appropriate human-facing disclosures
These deployer duties are separate from the provider’s technical marking obligation.
What Was Deferred to 2 December 2026?
For Providers
The four-month transition period applies only to the provider-side machine-readable marking and detection obligation.
Providers of in-scope systems, including general-purpose AI systems, that generate synthetic audio, images, video, or text and were “placed on the [EEA] market” before 2 August 2026 have until 2 December 2026 to comply. Systems “placed on the [EEA] market” on or after 2 August must comply from the outset.
For Deployers
The 2 December transition period does not postpone the deployer duties. The requirements concerning emotion recognition, biometric categorisation, deepfakes, and relevant public-interest text have applied since 2 August 2026.
What Should Businesses Do Now Considering the Timing of Article 50?
The first key steps should be identifying whether the organisation is a provider or deployer relative to the AI system and determining the appropriate “risk” level for the AI system in question considering its use case (and whether Article 50 is even applicable). Our EU AI Act Compliance Checklist sets out these steps in more detail.
We set out below a summary of certain key steps for providers and deployers of AI systems, which have been assessed as being subject to Article 50.
The European Commission’s Guidelines on Transparency for Providers and Deployers of AI Systems and Code of Practice on Transparency of AI-generated Content provide an important framework, but each system and use case still requires its own assessment.
For Providers
Providers should confirm that appropriate notices are provided when individuals interact directly with AI systems and that any required marking and detection measures are in place.
Where an AI system was placed on the EEA market before 2 August 2026, the provider should determine whether it is relying on the transition period to 2 December and document the basis for doing so.
For Deployers
Deployers should ensure that appropriate notices are given to individuals exposed to emotion-recognition or biometric-categorisation systems. They should also review processes for publishing deepfakes and AI-generated or manipulated public-interest text, including when a disclosure is required, who is responsible, and how it will be presented.
Where third-party AI systems are used, deployers should obtain information about the provider’s marking arrangements and any reliance on the 2 December transition period.
Looking Ahead
The immediate priority is to confirm that the Article 50 duties applying from 2 August have been addressed, while providers relying on the limited transition period complete the necessary work before 2 December.
Article 50 tests whether businesses can translate AI regulation into day-to-day governance. Organisations that build transparency into product design, procurement, contracting, and content approval will be better placed than those treating it as a one-off labelling exercise. The stronger position is one in which the organization can explain what information is provided, by whom, when, and why.
