Article 50 of the EU AI Act applies from 2 August 2026, making it the first day that AI systems across the European Union must tell people they are AI and mark their synthetic outputs as machine-detectable. The far larger high-risk rulebook covering hiring, credit, education and law enforcement did not arrive with it - the July 2026 Digital Omnibus pushed those obligations to December 2027 and August 2028.
Key facts
- The European Commission states plainly that "these transparency rules apply from 2 August 2026."
- Article 50 breaches sit in the up to 15 million euro or 3% of worldwide annual turnover penalty band, not the higher 35 million euro or 7% tier reserved for prohibited practices.
- Roughly 190 organisations had signed the Commission's voluntary transparency Code of Practice by the end of July.
- Primary sources: the Commission's transparency fact page and the AI Act text on EUR-Lex.
The shorthand doing the rounds - "the EU AI Act takes effect today" - is wrong in both directions. Parts of the Act have been binding since February 2025, when the prohibited-practices chapter and the AI-literacy duty started. Other parts will not bind for another two years. Today is the Act's general application date, which is a real milestone, but what actually changes for ordinary users is narrower and more specific than the headlines suggest.
The European Commission's own framing is the clearest available: Article 50 exists "to help EU citizens recognise when they are interacting with an AI system or are exposed to AI-generated content." That splits into two layers that are constantly conflated.
The first layer binds providers - the companies that build and place systems on the market. A system intended to interact directly with people must be designed to tell them they are dealing with AI, unless that is already obvious. And a system generating synthetic audio, image, video or text must mark its outputs so they are machine-readable and detectable as artificial, to the extent technically feasible.
The second layer binds deployers - the organisations using those systems. A deployer publishing a deepfake must disclose the manipulation. A deployer publishing AI-generated text intended to inform the public on matters of public interest must disclose it, unless the text underwent human review or editorial control with someone holding editorial responsibility. Deployers using emotion recognition or biometric categorisation must tell the people exposed to it.
The distinction people keep missing is the one between marking and labelling. Think of a printed banknote: the visible design is one thing, the embedded thread and watermark that a machine reads are another. Article 50(2) is mostly about the thread, not the design. It requires provenance data that software can detect, and it explicitly does not prescribe a visible on-screen badge or a single standard. Standard editing assistance and changes that do not substantially alter the input are exempt. There is no obligation to stamp "AI" across every AI-assisted advert or artwork.
The legacy grace period is worth knowing. Generative systems already on the EU market before today have until 2 December 2026 to satisfy the marking requirement. That reprieve applies only to provider-side marking. Chatbot disclosure, biometric and emotion notices, deepfake disclosure and the first-interaction timing rule all apply now. The Commission has also said deepfakes generated before today need not be relabelled retroactively, though it encourages it.
Open-weight releases get less shelter than the open-model community often assumes. The Act's free and open-source carve-out in Article 2(12) expressly does not exclude systems falling under Article 50. A bare model has narrower documentation exemptions under the separate general-purpose rules; a directly usable generative system released or operated into the EU can still be in scope. Whether a given repository counts as a model, a system, or a market placement is fact-specific, which is exactly the ambiguity maintainers will spend the autumn arguing about.
The strongest technical objection comes from industry rather than activists. In its consultation response, the Association for Financial Markets in Europe argued that no single provenance method survives every path content takes - through multi-agent pipelines, PDFs, email, copy-paste, screenshots, compression and republication - and urged a layered approach combining metadata, cryptographic provenance, watermarking, logging and testing. That is a real engineering problem. It is not, however, an argument that the statute demands universal visible labels, because it does not. Separately, EuroCommerce warned that an over-broad reading of "deepfake" could sweep in ordinary synthetic product photography and produce indiscriminate labelling.
Enforcement lands mainly with national market-surveillance authorities, with the AI Office holding narrower system-specific authority and the European Data Protection Supervisor covering EU institutions. The Commission's Code of Practice on AI-generated content is voluntary; Article 50 itself is not, and non-signatories must show adequate alternative measures.
The honest caveat: the Commission's own AI Act Service Desk warns that its displayed Article 50 text has not yet been updated for the Digital Omnibus amendments, so anyone checking dates should read the Official Journal version rather than the convenience page. On a day defined by a compliance deadline, the official summary of the rule is itself out of date.
Originally published on Ground Truth, where every claim is checked against the primary source.
Top comments (0)