DEV Community

Jules Robineau
Jules Robineau

Posted on Originally published at jrobineau.com

AI Act: Your Assistant Must Say It Is an AI. Since August 2, Not December 2

On 2 December 2026, an AI Act deadline falls. Many teams remember that date and assume they have until then. For the essential part, that is wrong. The duty to tell a human they are talking to an AI has applied since 2 August. December 2 only covers one technical point, and only for systems already in service.

I am not a lawyer. I run LLM agents in production, and one of them writes to strangers in my name. So I read Article 50 with a single question: what do I change in the code?

TL;DR: Article 50 of the AI Act has applied since 2 August 2026. A chatbot, an assistant, an agent that writes to people must say it is an AI. At the latest at the first exchange, unless it is obvious. Generated content must carry a machine-readable mark, with a delay until 2 December 2026 for systems already on the market. If you build on a third-party model API, you are the provider of your system: the obligation sits with you. Possible fine: up to 15 million euros or 3% of worldwide turnover. Here is the code-side runbook, in the format of the CRA one.

This article is for developers and small teams with an AI assistant facing users, or an agent that sends messages. Dates and scope come from the primary sources listed at the bottom.

What Article 50 asks, in four lines

The AI Act is the EU regulation on artificial intelligence. Most of its heavy obligations target high-risk systems, and those were pushed back to late 2027, even 2028. Article 50 targets everyone, and it is in force.

It holds four obligations. One: a system designed to interact with people must inform them they are talking to an AI. Two: a system that generates text, images, audio or video must mark its outputs in a machine-readable format. Three: emotion recognition and biometric categorisation must be announced. Four: whoever spreads a deepfake, or publishes generated text to inform the public on a matter of public interest, must say so.

The first two concern you the moment an LLM faces a human. That is the subject of this article.

The dates, without confusion

Article 50 applies since 2 August 2026. Full stop. The duty to inform users has no grace period.

December 2, 2026 comes from the Digital Omnibus, a text that entered into force in late July 2026 and reshuffled the AI Act calendar. It grants a delay for one thing only: machine-readable marking, and only for systems placed on the market before 2 August. A system launched after 2 August must mark from day one.

2 August 2026     inform users (art. 50.1), announce emotion recognition
                  (50.3), label deepfakes and public-interest text (50.4).
                  Everyone, no delay.
2 August 2026     machine-readable marking (50.2) for any system launched
                  after that date.
2 December 2026   machine-readable marking (50.2) for systems already on
                  the market before 2 August.
Penalty           up to EUR 15M or 3% of worldwide turnover (art. 99.4).
Enter fullscreen mode Exit fullscreen mode

Read the first line again. If your assistant does not introduce itself as an AI today, you are not early. You are late.

Provider or deployer? If you code the chatbot, it is you

The AI Act separates two roles. The provider develops a system and places it on the market under their name. The deployer uses it under their responsibility. The duty to inform users falls on the provider. So does marking.

The classic trap: "we use the OpenAI or Mistral API, so it is their problem". No. They are providers of their model. You develop a system from that model and put it under your name in front of your users. You are the provider of that system. The banner, the message, the marking: that is your code.

You are also a deployer of the upstream model, but that takes nothing away. The two hats add up.

Obligation 1: say it is an AI, at the first exchange

The text requires the person to be informed "at the latest at the time of the first interaction", in a clear and distinguishable manner. Unless it is obvious to a reasonably well-informed and observant person, given the context.

The Commission's guidelines give examples. Obvious: a coding assistant for professional developers, a non-player character in a video game. Not obvious: a help chatbot embedded in a website, an avatar, a companion. The exception is read narrowly. When in doubt, you inform.

In code, that means four things. A message at the first exchange, per user, not once per deployment. In every language you serve. Accessible: readable by a screen reader, not a light grey line at the bottom. And a trace: the date this user saw the message. The day you are asked to prove it, a log beats a screenshot.

// First-interaction disclosure: per user, per language, logged.
func (s *Chat) Open(ctx context.Context, u User) (*Session, error) {
    sess := s.newSession(u)
    if u.AIDisclosureSeenAt.IsZero() {
        sess.Prepend(Message{Role: RoleSystem, Text: t(u.Lang, "ai_disclosure")})
        s.audit.Log(ctx, "ai_disclosure_shown", u.ID, time.Now())
        s.users.MarkDisclosureSeen(ctx, u.ID)
    }
    return sess, nil
}
Enter fullscreen mode Exit fullscreen mode

The button's name matters too. In an app I built, the assistant is called "AI Assistant" in the menu, and the terms of use say so. That is already a good part of the job. An assistant called "Lea" with a photo, no.

The case that made me reread the text: my email agent

My email agent reads my inbox, qualifies assignments and drafts the replies. In hybrid mode, it sends simple questions on its own, to recruiters who write to me. Signed with my name. Without a line saying a machine wrote it.

The guidelines cover agentic systems. A system designed to interact with people is in scope, including when it acts on someone's behalf and addresses other people. And when the provider cannot know whether a human is on the other end, it informs at every interaction. A recruiter receiving my reply is a human. They cannot guess the agent wrote it. It is not obvious, so it has to be said.

My reading, with a non-lawyer's caution. In review mode, I reread and send myself. The email is mine, the agent is a drafting tool. In hybrid mode, the agent sends without me. It is the one interacting. The line goes there, in code, not in the prompt:

// Disclosure only when the agent sends by itself.
// A draft I review and send myself is my own message.
if decision.AutoSend {
    body += "\n\n" + AIDisclosure(lang)
    // EN: "Reply drafted and sent by my automated assistant.
    //      I read the whole thread and take over from the next step."
}
Enter fullscreen mode Exit fullscreen mode

Does it change the tone? A little. But a recruiter would rather know. And a system that has to hide to work has a bigger problem than the AI Act.

Obligation 2: mark generated content, "as far as technically feasible"

The text requires machine-readable, detectable marking, "effective, interoperable, robust and reliable as far as technically feasible". For images, audio and video, techniques exist: signed metadata such as C2PA, invisible watermarks. For text, it is weaker, and the Commission admits it: no single technique is enough, they must be stacked.

Two important clarifications from the guidelines. Feasibility is assessed objectively: a small team's lack of resources is no excuse. And some outputs are out of scope, such as technical outputs between professionals. The text of a consumer chatbot is squarely in.

The code of practice published in June 2026 is the marked path. It is voluntary, but if you do not sign it, you must demonstrate equivalent compliance by other means. In other words, you follow it anyway, without the trust bonus.

What I do for text, for lack of better. Metadata wherever the format accepts it: an attribute on the rendered HTML block, a header on API responses, a field in exports. A log of generated outputs, with a hash of each text. So you can answer "yes, this text came from us" if someone shows it to you. And if the upstream model offers a text watermark, you turn it on, you do not strip it.

// Machine-readable marking on generated text, wherever the format allows.
// No standard header exists yet: document yours in the compliance file.
w.Header().Set("X-AI-Generated", "true")
w.Header().Set("X-AI-Generated-By", "assistant/1.4; model="+model)
fmt.Fprintf(w, `<div class="answer" data-ai-generated="true">%s</div>`, rendered)

sum := sha256.Sum256([]byte(text))
audit.Log(ctx, "generated_text", hex.EncodeToString(sum[:]), model, time.Now())
Enter fullscreen mode Exit fullscreen mode

It is not perfect. A copy-paste wipes everything. But it is feasible, documented, and dated. That is exactly what the text asks for.

The runbook I install

BEFORE (this week)
- inventory: every place where an LLM talks to a human or produces text
- for each one: provider or deployer? (if it is your code, provider)
- "you are talking to an AI" message at first exchange, per user, per language
- explicit assistant name in the UI, terms of use aligned
- agents that send on their own: disclosure line in the message, in code
- marking: metadata where the format allows it, output log with hashes
- market date of each system, written down: before or after 2 August?

FILE (before 2 December for existing systems)
- one page describing your marking measures, and why they are feasible
- exportable disclosure logs
- the code of practice read: signed, or the gap documented

THEN
- drill: a user asks "was that an AI?", you prove it in ten minutes
Enter fullscreen mode Exit fullscreen mode

Nothing exotic. A message, a log, a description page. The difficulty is not technical, it is doing it before someone asks.

Who enforces, in France

Fines are national. In France, the scheme announced in September 2025 gives coordination and the single point of contact to the DGCCRF. The CNIL, the data protection authority, keeps biometrics and personal data. Arcom, the media regulator, takes deepfakes and online content. The ACPR, finance. On 2 August, the law designating these authorities had not yet been definitively adopted. The obligations apply anyway: the regulation is directly applicable.

Do not count on that limbo. A complaint from a user or a competitor can arrive before the decree.

The checklist

A machine does not pass itself off as a person. And it leaves a trace of what it produces.

  • [ ] For each system, you know whether you are provider or deployer, and you wrote it down
  • [ ] Your assistant says it is an AI at the first exchange, per user, in every language
  • [ ] The message is accessible and distinguishable, not grey text in a footer
  • [ ] Your agent that sends messages on its own flags them as such, in code
  • [ ] The assistant's name and description do not make it pass for a human
  • [ ] Every display of the disclosure leaves a timestamped trace
  • [ ] Generated text carries a machine-readable mark wherever the format allows
  • [ ] A log keeps a hash of every generated output, with the model and the date
  • [ ] The market date is written down: before 2 August, you have until 2 December for marking
  • [ ] The code of practice is read: signed, or the gap documented

What to remember

Article 50 does not ask for technical magic. It asks you to stop passing a machine off as a person, and to keep a trace of what it produces.

Most measures take a day to code. The date, though, has already passed.

Got an LLM assistant or agent in production, and want it clean before someone asks? Let's talk.


Sources: Regulation (EU) 2024/1689, Articles 50 and 99 (EUR-Lex) · Article 50 on artificialintelligenceact.eu · European Commission, guidelines on transparency obligations (Article 50) · Code of practice on marking and labelling AI-generated content (final version, 10 June 2026) · Lewis Silkin, the Digital Omnibus enters into force (27 July 2026) · Covington, ten takeaways from the guidelines (May 2026) · economie.gouv.fr, DGCCRF to coordinate market surveillance authorities · MIAI, France without designated authorities on 2 August 2026

Top comments (0)