Where things stand — 4 August 2026: Article 50 transparency and watermarking obligations are now legally in force across the EU, having applied from 2 August 2026 (with a grace period to 2 December 2026 for AI systems already on the market before that date). The Commission's guidelines, published 29 July 2026, are non-binding interpretive guidance — they clarify how the Commission expects Article 50 to be applied, but the legal obligation itself comes from the Regulation, not the guidance document.

What the Guidelines Cover

Article 50 is the EU AI Act's transparency article — it does not classify systems by risk tier the way Annex III does. Instead, it imposes disclosure duties on specific AI use cases regardless of risk classification: AI systems that interact with people directly, systems that generate or manipulate synthetic content, and systems used for emotion recognition or biometric categorisation. The Commission's guidelines, issued by the Directorate-General for Communications Networks, Content and Technology, are aimed at giving providers and deployers legal certainty about how to meet these duties in practice.

Role Obligation Applies to
Provider Design the system so people are explicitly informed they are interacting with an AI system Chatbots, voice assistants, conversational AI — unless obvious from context to a reasonably informed person
Provider Embed machine-readable marks enabling detection of AI-generated or manipulated content Synthetic audio, image, video, and text generation and manipulation systems
Deployer Inform exposed individuals about the system's operation Emotion recognition and biometric categorisation systems
Deployer Disclose that content has been artificially generated or manipulated Deepfakes — image, audio, or video resembling real people, places, or events
Deployer Disclose that text was AI-generated Text on matters of public interest published without human review or editorial responsibility

In every case, the guidelines stress that disclosure must be "clear, distinguishable, and accessible" — a small watermark buried in metadata that an ordinary user would never see is unlikely to satisfy the obligation.

How Providers Can Demonstrate Compliance

For the content-marking obligation specifically, the guidelines point to two routes. Providers can adhere to the Code of Practice on Transparency of AI-generated Content — a voluntary framework similar in structure to the GPAI Code of Practice — or demonstrate compliance through "alternative equivalently adequate means," such as proprietary watermarking, metadata tagging, or cryptographic content-provenance systems. Neither route is legally mandatory on its own; what matters is that the chosen method reliably enables detection of AI-generated content.

Who Enforces It

Authority Scope
National market surveillance authorities General enforcement across all providers and deployers established or operating in that member state
EU AI Office Supervisory role for general-purpose AI models and systemic-risk GPAI
European Data Protection Supervisor AI systems provided or deployed by EU institutions, bodies, offices, and agencies

The Penalty for Getting It Wrong

Article 50 non-compliance sits in the EU AI Act's second-highest penalty tier under Article 99: fines of up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. That is below the €35M / 7% tier reserved for prohibited AI practices under Article 5, but above the €7.5M / 1% tier for supplying incorrect information to authorities.

SME-relevant detail the headlines usually miss: for SMEs, including start-ups, Article 99 caps the fine at whichever of the amount or percentage is lower — not higher, as is the case for larger undertakings. This meaningfully reduces exposure for smaller companies relative to the flat maximums usually quoted, though the disclosure obligations themselves apply equally regardless of company size.

Why This Is Different From the High-Risk Deadline

It is easy to conflate Article 50 with the Annex III high-risk obligations, but they are separate tracks with separate timelines. The high-risk deadline was provisionally deferred from 2 August 2026 to 2 December 2027 under the Digital Omnibus — see our Digital Omnibus explainer for the full status. Article 50 was not part of that deferral. It applied on schedule on 2 August 2026 and is now the law in force, regardless of where a system sits on the risk-tier spectrum. A minimal-risk chatbot with no high-risk obligations whatsoever can still trigger Article 50 disclosure duties simply by talking to a human.

Common mistake: assuming that because your AI system is not classified as high-risk, no EU AI Act obligations apply to it. Article 50 applies independently of risk tier. A customer-support chatbot, an AI image generator, or an internal tool that drafts public-facing text can all trigger transparency duties even when no Annex III high-risk category applies.

What to Do Now

  1. Inventory every system that talks to people or generates content — chatbots, voice agents, image/video/text generators, and any tool producing public-facing text without human review.
  2. Check your disclosure is actually visible — "clear, distinguishable, and accessible" is the guidelines' standard; a disclosure a user has to hunt for likely does not meet it.
  3. Confirm your content-marking method is real, not cosmetic — whichever route you choose (Code of Practice or an alternative technical method), it needs to reliably enable detection, not just exist on paper.
  4. Don't stop at the deadline — the 2 December 2026 grace period only covers systems already on the market before 2 August 2026. Anything you deploy after that date needs to be compliant from day one.

Aurora Trust maps Article 50 transparency requirements alongside Annex III risk classification — so a system that is both low-risk on Annex III and subject to Article 50 disclosure duties is documented once, correctly, rather than falling through the gap between "not high-risk" and "still regulated." Starting at €49/month.