EU AI Act 2026: the 5 transparency features to ship before 2 August
Summary. Article 50 of the EU AI Act enters into force on 2 August 2026, which is 13 days from this article's publication date of 20 July 2026. Breaching it sits in the second penalty band of Article 99: administrative fines up to EUR 15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. Two things are widely misreported. First, the Digital Omnibus agreed on 7 May 2026 pushed the high-risk obligations back to 2 December 2027 and 2 August 2028, but it left Article 50 alone, so the teams telling their boards "the AI Act got delayed" are looking at a different chapter. Second, the same agreement shortened the grace period for implementing transparency solutions for artificially generated content from 6 months to 3, setting that date at 2 December 2026. It moved earlier, not later. If you run a chatbot, generate images or copy with AI, or do emotion recognition anywhere in the European Union, five concrete features are now on your critical path.
What Article 50 actually says
Article 50 is short, and reading the text beats reading the commentary. It creates four duties, split between providers who build AI systems and deployers who use them.
Paragraph 1, on providers. AI systems intended to interact directly with natural persons must be designed so the person "are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect." That "unless obvious" carve-out is doing real work, and it is also where most disputes will land. A widget labelled "AI assistant" is probably obvious. A support agent with a human first name and a headshot is not.
Paragraph 2, on providers of generative systems. Outputs of AI systems generating synthetic audio, image, video or text "shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated." The obligation is qualified by technical feasibility and cost, and there is a carve-out where the system "perform[s] an assistive function for standard editing or do[es] not substantially alter the input data provided by the deployer or the semantics thereof."
Paragraph 3, on deployers. Anyone running an emotion recognition or biometric categorisation system must inform the people exposed to it, and must process the personal data under the GDPR and its sister instruments.
Paragraph 4, on deployers of deepfakes and public-interest text. Deployers generating deepfakes must disclose that the content is artificially generated. There is a lighter regime for evidently artistic, creative, satirical or fictional work, limited to disclosure "in an appropriate manner that does not hamper the display or enjoyment of the work."
The second half of paragraph 4 is the one marketing teams should read twice. Deployers publishing AI-generated or AI-manipulated text "with the purpose of informing the public on matters of public interest" must disclose it, but the obligation does not apply "where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content." An editorial process with a named responsible person is an exemption, not a nicety.
Paragraph 5 sets the timing: the information must be given "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure", and must meet applicable accessibility requirements.
The deadline map, corrected
Most of the confusion in July 2026 comes from conflating three separate dates that the Digital Omnibus moved in different directions.
| Obligation | Original date | Date now | Direction |
|---|---|---|---|
| Article 50 transparency duties | 2 August 2026 | 2 August 2026 | Unchanged |
| Transparency solutions grace period for generated content | 6 months | 3 months, to 2 December 2026 | Shortened |
| Stand-alone high-risk AI systems (Annex III) | 2 August 2026 | 2 December 2027 | Delayed |
| High-risk AI embedded in products | 2 August 2026 | 2 August 2028 | Delayed |
| National AI regulatory sandboxes | 2 August 2026 | 2 August 2027 | Delayed |
| Article 99 penalty regime | 2 August 2025 | 2 August 2025 | Already in force |
The Council of the EU's own press release on the 7 May 2026 provisional agreement is explicit that the deal "reduces the grace period for providers to implement transparency solutions for artificially generated content from 6 months to 3 months, with the new deadline set on 2 December 2026." Marilena Raouna, Deputy Minister for European affairs of the Republic of Cyprus, framed the package as one that "significantly supports our companies by reducing recurring administrative costs" while "stepping up the protection of children targeting risks linked to the AI systems." The same agreement adds a prohibition on AI systems generating non-consensual sexual or intimate content and child sexual abuse material.
So the honest summary for a board is: the expensive engineering work on high-risk classification bought you 16 months, and the cheap engineering work on transparency did not.
One more date is worth keeping in view. The penalty regime in Article 99 has been in force since 2 August 2025 under Article 113(b), so the enforcement machinery is not being stood up on 2 August 2026. Only the substantive duty is new. Member states were required to notify the Commission of their national penalty rules by the date of entry into application, and Article 99(11) obliges them to report annually on the fines they have issued. That reporting duty is the reason to expect visible enforcement statistics rather than a quiet first year, and it is a better planning assumption than hoping regulators start with warning letters.
The five features to ship
None of these is hard. All of them are the kind of work that slips because nobody owns it.
1. An AI disclosure at first interaction. Anywhere a user talks to a model, the interface must say so before or at the first exchange. Put it in the opening message and in a persistent label, not only in a terms page. Log the disclosure event, because paragraph 5 requires it "at the latest at the time of the first interaction" and you will want to prove when it fired.
2. Machine-readable marking on every generated asset. Paragraph 2 asks for outputs "marked in a machine-readable format and detectable as artificially generated or manipulated." In practice that means C2PA-style content credentials or a watermark that survives your pipeline, plus provenance metadata that your CDN and image processor do not strip. Test the strip case specifically: resizing, re-encoding and social upload all routinely destroy metadata, and a marking that does not survive your own pipeline is not a marking. Our guide to AI content marking under Article 50 goes into the implementation detail, and the watermarking approaches now shipping on consumer platforms are covered in our note on SynthID watermarks and content authenticity.
3. A visible deepfake disclosure path. If any product surface generates or manipulates images, audio or video of people, you need a disclosure that a human sees, separate from the machine-readable mark. The artistic and satirical carve-out is narrower than it sounds: it limits the manner of disclosure, it does not remove it.
4. Notice on emotion recognition and biometric categorisation. If you run either, paragraph 3 requires you to inform the people exposed. This is an easy one to miss in a call-centre analytics feature or a retail camera product that a different team bought.
5. An editorial-responsibility record for published AI text. If you publish AI-assisted content on matters of public interest, decide now which route you are taking: disclose, or document human review with a named person holding editorial responsibility. The exemption is only available if that process genuinely exists and you can evidence it.
What non-compliance costs, and the SME nuance almost everyone gets wrong
Article 99(4) puts breaches of "transparency obligations for providers and deployers pursuant to Article 50" in the same band as failures by providers, importers and distributors of high-risk systems: up to EUR 15,000,000 or up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.
Now the nuance. Article 99(6) states that for SMEs, including start-ups, "each fine referred to in this Article shall be up to the percentages or amount referred to in paragraphs 3, 4 and 5, whichever thereof is lower." The general rule takes the higher of the euro cap and the percentage. For SMEs, it takes the lower. A great deal of the "EUR 15 million fine" commentary aimed at start-ups has this backwards.
| Infringement | Cap for a large undertaking | Statutory basis |
|---|---|---|
| Prohibited practices (Article 5) | EUR 35,000,000 or 7% of worldwide turnover, whichever is higher | Article 99(3) |
| Article 50 transparency breach | EUR 15,000,000 or 3% of worldwide turnover, whichever is higher | Article 99(4)(g) |
| Incorrect or misleading information to authorities | EUR 7,500,000 or 1% of worldwide turnover, whichever is higher | Article 99(5) |
| Any of the above, for an SME or start-up | The lower of the euro figure and the percentage | Article 99(6) |
Article 99(7) also lists what regulators weigh when setting an amount, and two entries are worth engineering for: "the degree of responsibility of the operator taking into account the technical and organisational measures implemented by it", and whether the operator notified the infringement itself. Documented controls and self-reporting are mitigating factors written into the text.
Who this catches that does not think it is caught
The Act's reach is not limited to European companies. Any team offering an AI-touched product to users in the European Union is in scope, which sweeps in a large share of Indian SaaS and services businesses selling into Europe.
Three patterns come up repeatedly in our work:
A D2C brand running an AI support chatbot for European customers is a deployer with a paragraph 1 problem and, if the bot drafts public-facing copy, a paragraph 4 problem.
A marketing team generating product imagery with a commercial image model is a deployer of a system whose provider owes the paragraph 2 marking duty, but the brand still owns the disclosure question and the practical burden of not stripping the marking on the way to the CDN.
A B2B SaaS product with a sentiment or emotion feature buried in an analytics dashboard has a paragraph 3 notice duty that nobody in the company has read.
If you already went through this exercise for the European Accessibility Act and WCAG 2.2, the shape is familiar: an EU obligation that lands on product surfaces rather than on a legal document, and that has to be evidenced rather than asserted.
India-specific considerations
Indian teams have to hold two regimes at once, and they do not decompose neatly. The Digital Personal Data Protection Act 2023 governs personal data of people in India, with obligations on data fiduciaries to give itemised notice of what is collected and why, and to maintain reasonable security safeguards. The EU AI Act governs how AI systems behave towards people in the European Union, whoever built them.
The overlap is sharpest on emotion recognition and biometric categorisation, where Article 50(3) requires notice and DPDP requires a lawful basis and notice of its own. Building one consent and disclosure layer that satisfies both is cheaper than retrofitting a second one later, and it is the sort of decision that is nearly free at design time and expensive at month nine. Our DPDP engineering playbook for Indian startups covers the Indian half.
A practical note for Indian founders selling into Europe: the Article 99(6) SME rule is genuinely favourable, but it depends on qualifying, and it caps the fine rather than removing the obligation. Plan for the obligation.
An engagement model that fits a 13-day runway
Nobody builds a governance programme in 13 days, and pretending otherwise produces theatre. What is achievable before 2 August 2026 is a scoped inventory and the user-facing disclosures, with the marking pipeline landing against the 2 December 2026 date.
The sequence we use with clients on this deadline runs in three phases.
Phase one is an AI surface inventory, usually one to two weeks: every place a model touches a user, mapped to a paragraph of Article 50, with an owner. Most teams are surprised by the count. Features bought as vendor add-ons are the usual blind spot.
Phase two is the disclosure layer, typically two to three weeks depending on the number of surfaces: first-interaction notices, deepfake disclosure, emotion recognition notice, and the editorial-responsibility record for published text. This is the part that maps to 2 August.
Phase three is the marking pipeline against 2 December 2026: content credentials or watermarking at generation, provenance metadata preserved through processing and delivery, and an automated check that the marking survives the whole path to the user. That last check is the piece teams skip, and it is the piece that decides whether any of this actually works.
Running evaluations and logging over the AI surfaces makes the Article 99(7) "technical and organisational measures" argument evidenceable rather than rhetorical, which is why we usually fold it into phase three rather than treating it as a separate programme. Our work on AI evaluations and observability covers that layer, and the wider control structure is set out in our note on governance layers for enterprise AI agents.
We design applications aligned with EU AI Act and DPDP requirements. We do not certify compliance, and any consultancy that offers to is selling something the regulation does not recognise.
FAQ
Does the EU AI Act transparency deadline still apply on 2 August 2026?
Yes. Article 50 enters into force on 2 August 2026 under Article 113. The Digital Omnibus agreed on 7 May 2026 delayed the high-risk obligations to 2 December 2027 and 2 August 2028, and pushed national regulatory sandboxes to 2 August 2027, but it did not amend Article 50 itself.
What is the fine for breaching Article 50?
Article 99(4) sets administrative fines of up to EUR 15,000,000 or up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. Article 50 breaches are listed explicitly at point (g) of that paragraph, alongside provider, importer, distributor and deployer obligations for high-risk systems.
Do smaller companies face the same fines?
No. Article 99(6) states that for SMEs, including start-ups, each fine is capped at the percentage or the euro amount, whichever is lower, rather than higher. The obligation itself is unchanged, and Article 99(1) separately requires member states to take SME economic viability into account when setting penalties.
What changed on 2 December 2026?
The 7 May 2026 provisional agreement reduced the grace period for providers to implement transparency solutions for artificially generated content from six months to three, setting the deadline at 2 December 2026. That date moved earlier than originally planned, so it should be treated as a second engineering deadline rather than relief.
Does AI-generated marketing copy need a disclosure?
Article 50(4) covers text published to inform the public on matters of public interest. The obligation does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. Document that process if you intend to rely on the exemption.
Does a chatbot always need to announce itself?
Article 50(1) requires it unless the fact is obvious to a reasonably well-informed, observant and circumspect person given the context. There is a separate exception for systems authorised by law to detect, prevent, investigate or prosecute criminal offences, unless the public can use them to report an offence.
Does the Act apply to Indian companies?
It applies to AI systems offered to people in the European Union regardless of where the provider or deployer is established, so Indian SaaS and services businesses selling into Europe are in scope. Indian companies must also meet Digital Personal Data Protection Act 2023 obligations for personal data of people in India.
What is exempt from the machine-readable marking duty?
Article 50(2) does not apply where AI systems perform an assistive function for standard editing, or do not substantially alter the input data provided by the deployer or its semantics, or where use is authorised by law to detect, prevent, investigate or prosecute criminal offences. Ordinary generative output is not exempt.
How eCorpIT can help
eCorpIT is a Gurugram technology consultancy, founded in 2021 and assessed at CMMI Level 5, that builds and ships the product changes this deadline requires rather than writing a report about them. Our senior engineering teams run the AI surface inventory, build the disclosure layer against 2 August 2026, and land the content-marking pipeline against 2 December 2026, including the checks that prove a marking survives your CDN and image processing. We work as a multi-disciplinary organisation across product, engineering and data, and we design applications aligned with EU AI Act and DPDP requirements. If you are 13 days out and unsure what is in scope, talk to us about an AI surface review.
References
- Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems, EU Artificial Intelligence Act, Regulation (EU) 2024/1689.
- Article 99: Penalties, EU Artificial Intelligence Act, Regulation (EU) 2024/1689.
- Artificial Intelligence: Council and Parliament agree to simplify and streamline rules, Council of the EU press release, 7 May 2026.
- Article 113: Entry into Force and Application, EU Artificial Intelligence Act.
- Chapter IV: Transparency Obligations for Providers and Deployers of Certain AI Systems, EU Artificial Intelligence Act.
- Guide to Article 50 transparency rules, EU Artificial Intelligence Act.
- AI Act implementation timeline, EU Artificial Intelligence Act.
- Digital Omnibus on AI Regulation Proposal, European Commission, Shaping Europe's digital future.
- Code of Practice on marking and labelling of AI-generated content, European Commission.
- AI Act regulatory framework, European Commission.
- Digital Omnibus on AI, Legislative Train Schedule, European Parliament.
- Council agrees position to streamline rules on Artificial Intelligence, Council of the EU, 13 March 2026.
- Digital Personal Data Protection Act, 2023, Ministry of Electronics and Information Technology, Government of India.
Last updated: 20 July 2026.
Top comments (0)