Article 50 of the EU AI Act became applicable on August 2, and the Commission’s AI Office and national market surveillance authorities started enforcing it the same day. There is no grace period on the disclosure duties. Exposure runs to €15 million or 3% of worldwide annual turnover, and for most companies it is whichever of the two is higher.
If you operate a support chatbot, a voice agent, or anything generating text, images, audio, or video that reaches people in the EU, you have been inside this rule since Sunday. Plenty of teams will be surprised, because the story most people read this year was that Europe blinked.
The delay everyone read about did not cover this rule
Regulation (EU) 2026/1744, the AI Omnibus, was published in the Official Journal on July 24 and entered into force three days later on urgency grounds, since the deadline it amended fell on August 2. It moved the Annex III high-risk obligations (biometrics, employment screening, education, critical infrastructure) out to December 2, 2027, and high-risk AI embedded in regulated products to August 2, 2028. We covered that deferral when negotiators agreed it in May.
Article 50 was left exactly where it was. The omnibus did soften Article 4, rewriting the AI literacy duty from an obligation to ensure a sufficient level among staff into one to support its development, with an explicit statement that no particular level has to be guaranteed for any individual. That change applied from July 27, also without deferral.
So the reprieve went to systems that need conformity assessments, technical documentation, and notified bodies — not to the rule that says a person should know when they are talking to a machine. Most compliance roadmaps assumed the reverse.
The Act reaches outside the EU
Article 2(1)(c) extends the Act to providers and deployers established in a third country where the output produced by the AI system is used in the Union. The test is where the output lands, not where the company is registered or where inference runs.
Travers Smith reads the Commission guidelines as applying where EU use is foreseeable rather than merely incidental. A US SaaS company with European customers is foreseeable; a stray European visitor to a service that only ships domestically is a different question, and one worth putting to counsel rather than guessing at.
What the chatbot disclosure has to look like
Article 50(1) puts the duty on providers of AI systems intended to interact directly with people. The Commission’s final guidelines, adopted July 20, set four cumulative conditions: it is an AI system under Article 3(1) rather than rule-based automation, it is intended to interact, the interaction is direct and near-real-time, and the counterpart is a person rather than a machine.
Disclosure has to be perceivable inside the interaction itself, at or before the first exchange. A plain-language line at the top of the session qualifies, as does a persistent badge next to the input box. For a voice agent it has to be spoken at the start of the call, since a banner is no use to a caller who cannot see it.
Several common approaches do not count: a sentence in the terms of service, a machine-readable mark with no visible notice, a tooltip, or a vague label like “Assistant” that leaves the artificial nature to inference. There is no prescribed wording, and “You’re chatting with our AI assistant” is enough.
”Unless obvious” is much narrower than it reads
The statutory exception applies where the AI nature is obvious “from the point of view of a natural person who is reasonably well-informed, observant and circumspect.” The Commission construes that restrictively, confining it to cases where almost no doubt remains, judged against the intended audience rather than the general population.
The worked examples show how little room that leaves. A code-review assistant used by professional developers qualifies as obvious, as does an internal tool operated by trained staff or a non-playable character in a single-player game. A helpdesk chatbot a customer might read as a person does not, and neither does a realistic avatar or a companion product designed to feel lifelike.
If your product sits anywhere near that second group, disclose and stop thinking about it. A sentence at the top of a chat window costs almost nothing, and defending an obviousness argument to a market surveillance authority costs a great deal.
Marking synthetic output, and who owes it
Article 50(2) requires providers of generative systems to mark outputs in a machine-readable format and make them detectable as artificially generated. This is the only obligation with a transitional period: systems already on the market before August 2 have until December 2, 2026. Everything else applied immediately.
For a business building on somebody else’s model, the guidelines allow a downstream provider to rely on marking implemented at the model level upstream, but require it to demonstrate that the solution actually works in its own deployment. That is a testing obligation rather than a paperwork one. If you generate video for EU audiences on a hosted model, and that generation now produces synchronized audio in a single pass, you have to know whether the provenance signal survives your re-encode, the CDN transform, and thumbnail extraction.
Several categories sit outside the marking duty: source code and machine-readable configuration, very short strings such as captions and alt text, assistive editing that does not substantially alter the input (translation included), and outputs that never leave a closed machine-to-machine loop.
The Code of Practice on Transparency of AI-generated Content, assessed as adequate by the Commission and the AI Board in early July, recommends two layers for media: cryptographically signed metadata plus an imperceptible watermark, on the sound assumption that metadata does not survive contact with the internet. Around 190 organisations had signed by the end of July, with Anthropic, Google, Meta, Microsoft, Mistral and OpenAI among the providers and Getty Images and Lufthansa among the deployers. Signing buys a presumption of good faith rather than immunity, and it is a cheaper way to show a compliance pathway than building one from scratch.
The duties your vendor cannot discharge for you
Article 50(3) and 50(4) sit on deployers, and no supplier contract moves them.
If you run emotion recognition or biometric categorisation, you have to inform the people exposed to it, with the GDPR analysis running alongside. If you publish a deepfake, meaning AI-generated or manipulated media that appreciably resembles a real person, place or event and would falsely appear authentic, you have to disclose it in a form a person can perceive without special tools. A machine-readable mark on the file does not satisfy this; the label has to be visible or audible. The carve-out for evidently artistic, satirical or fictional work moves the label to the credits rather than an overlay, but does not remove it.
The text obligation is narrower than the coverage suggests. It applies to AI-generated text published to inform the public on matters of public interest: politics, public administration, health, consumer safety, and scientific or financial developments open to public debate. Ordinary marketing copy and product descriptions are not in scope.
Where a person with relevant expertise substantively reviewed the text and an identifiable person or organisation takes public editorial responsibility, no label is required. Spell-checking does not count as review, and the responsible party needs a name and contact details a reader can actually find.
The penalty math runs the other way if you are small
The €15 million or 3% figure comes from Article 99(4). Article 99(6) inverts it for SMEs and start-ups: their cap is whichever of the two is lower. On a business with €4 million of turnover, 3% is €120,000, and that is the ceiling instead of €15 million.
That is a real difference in exposure and a poor reason to relax, because fines are the visible end of enforcement rather than the likely first contact. What arrives first is an information request, a buyer’s procurement questionnaire, or a complaint through a national contact point.
Enforcement capacity is also uneven in a way worth planning around. Member states were supposed to designate market surveillance and notifying authorities by August 2, 2025; the tracker at artificialintelligenceact.eu currently shows nine with both clearly designated, twelve partial, and six with neither. A rule that is live across the bloc and staffed in a third of it produces patchy early enforcement, and the first cases in that situation tend to be the loud ones.
Where to start, and in what order
Start with an inventory: every AI feature you ship or operate, mapped to the paragraph of Article 50 that touches it and to whether it went live before or after August 2, since that date decides whether the December marking deadline applies to you. Most teams find more surface than they expected once agents, embedded assistants, and generated marketing assets land on one list. If you have no inventory at all, that gap is the first task, and it is the same work as any baseline AI governance for a small business.
The disclosures come next, and they are a UI job rather than a legal one; an afternoon of frontend work covers most of it. Marking takes longer, because it has to be tested end to end instead of accepted from a vendor datasheet. Keep evidence as you go: screenshots of each live disclosure, written reasoning if you lean on the obviousness exception, the marking method and its known limits, editorial review records for public-interest text. The burden of showing you disclosed sits with you.
Two questions deserve a lawyer rather than a blog post. Whether a deployment makes you a provider or a deployer is fact-dependent for white-labelled and heavily configured systems, and it decides which paragraphs bind you at all. The other is whether your EU exposure is foreseeable or incidental. Everything else here is ordinary product work, and a competent team can close it out well before December. But the rule went live on August 2, which makes this remediation rather than preparation, and the December marking deadline is the only slack left in it.
Sources
- EU AI Act: Transparency Obligations Take Effect 2 August 2026 — Cooley
- Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems — EU Artificial Intelligence Act (artificialintelligenceact.eu)
- Transparency obligations under Article 50 of the AI Act — European Commission
- Commission starts enforcing AI Act rules and new transparency requirements on 2 August — European Commission
- European Commission adopts final Guidelines on AI Act Article 50 transparency obligations: first impressions — Bird & Bird
- Is it a bot? EU AI Act transparency rules take effect 2 August 2026 — Travers Smith
- Strong backing for the Code of Practice on Transparency of AI-generated Content — European Commission
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) — EUR-Lex
- Article 99: Penalties — EU Artificial Intelligence Act (artificialintelligenceact.eu)
- Overview of all AI Act National Implementation Plans — EU Artificial Intelligence Act (artificialintelligenceact.eu)
