Article 50 of the EU AI Act took effect on 2 August 2026, according to the European Commission's FAQ on Article 50 transparency obligations. It's not a data-privacy rule like GDPR. Teams already running GDPR compliance by default for EU-jurisdiction engineering teams don't get a pass here: Article 50 is a separate, additional layer of disclosure and content-marking duties, not a subset of GDPR. Two dates matter, and conflating them is the most common mistake teams make with this law. 2 August 2026 has already passed, and every obligation under Article 50 became legally binding that day, except one. 2 December 2026 applies to that one exception only, a narrow marking duty that covers systems already on the market before August. If you finish this article thinking you have until December to build everything, you've misread it.
What Article 50 actually requires
Article 50 groups four separate obligations under one article number, and they don't all apply to the same actor. The Commission's quick-facts page on AI transparency rules lays out the same four categories as the FAQ. Providers of systems designed for direct interaction with a person, chatbots and voice assistants, have to disclose that the user is talking to an AI, unless that's obvious from context. Providers of systems that generate synthetic audio, image, video, or text have to mark those outputs as machine-generated. Deployers running emotion-recognition or biometric-categorisation systems have to tell the people exposed to them that the system is operating. And deployers publishing deepfakes, or AI-generated text on matters of public interest that skipped human editorial review, have to disclose that the content is artificial.
Four duties, two different actors, and Article 50 doesn't collapse them into one checklist. Which one applies to you depends on what your team builds and how it's used, not on which department adopted AI first.
Are you a provider or a deployer?
The Commission defines both terms plainly. A provider is a "natural or legal persons, public authorities, agencies or other bodies that develop AI systems, or have them developed, and place them on the EU market." A deployer is any entity "using AI systems under their authority, excluding use for personal, non-professional activities."
Most engineering teams read those definitions and assume they're one or the other. Nothing in the definitions stops a company holding both roles at once, for different products, and carrying both sets of duties at the same time. A company that builds a support chatbot is a provider of that chatbot, subject to the interaction-disclosure duty. If that same company also runs a third-party transcription tool internally that scores customer sentiment, it's a deployer of that tool, subject to a separate, unrelated emotion-recognition disclosure duty. Two roles, two duties, and neither one exempts the other. This article describes what each role requires under the regulation. Which roles your company actually holds, and for which systems, is a determination your own legal or compliance function has to make.
How to build for Article 50 compliance
1. Inventory every AI-generated or AI-mediated output
Start with a full list of what your systems actually produce or do, not just the AI features product marketing talks about: synthetic audio, image, video, and text outputs; any system running emotion recognition or biometric categorisation; and any interactive system a user could plausibly mistake for a human. This is close to the same kind of audit checklist CI agent security now requires, and it fits the habit engineering teams already setting default policies for what their AI agents are allowed to do should already have in place. Most teams can list the AI features on their roadmap. Fewer can list every AI-mediated output actually running in production, including the internal tool nobody thinks of as "the AI feature."
2. Separate what needs marking from what's exempt
Not everything on that list needs marking. The Commission's FAQ page lists explicit exemptions from the marking and detection duty: short sequences, source code, machine-to-machine outputs, closed-loop industrial use, and assistive editing functions. Source code is on that list by name. If your product generates or ships AI-written code, that output isn't subject to the marking duty. That's worth flagging because it cuts against the obvious assumption: a reasonable engineer might guess AI-written code needs a label the way a synthetic image does. It doesn't.
3. Implement machine-readable marking for provider-side outputs
Article 50(2) requires providers to apply marks that are machine-readable and that enable the outputs to be detected as artificially generated or manipulated. The Commission's FAQ text doesn't specify a single technical format. It points instead to the Code of Practice on Transparency of AI-generated Content as the voluntary tool for demonstrating compliance, and it published guidelines on transparency obligations for providers and deployers of AI systems on 20 July 2026 for teams that need more detail than the FAQ gives. Build to the requirement in the regulation text, machine-detectable, not merely human-readable, and treat the specific method, watermarking, metadata, cryptographic signing, whatever your stack supports, as an implementation choice your team makes rather than one the Commission hands you.
4. Build the deepfake disclosure flow for deployers
Article 50(4) requires deployers publishing deepfakes to disclose that the content is artificially generated or manipulated, upon first exposure at the latest, in a clear and distinguishable manner. The Commission's three-part test for what counts as a deepfake: the content resembles an existing person, object, place, or event; that person, object, place, or event is real; and the result would falsely appear authentic to someone viewing it. Build the disclosure into the first render, not a follow-up banner a user can dismiss without reading, and word it so a reasonable viewer would actually notice it, not just technically satisfy an audit.
5. Build the public-interest AI-text labeling flow
Article 50(4) also covers AI-generated or AI-manipulated text published to inform the public on matters of public interest: politics and democratic processes, public administration and services, the administration of justice and law enforcement, fundamental rights, public security, public health, environmental protection, and consumer safety and any economic, financial, political, scientific, or cultural developments. If that text went through human review first, the duty doesn't apply. The Commission defines editorial control as "authority to approve, alter or reject the substance of the text based on substantive grounds," and that's the exemption most content and marketing teams are going to lean on. Build the review gate before you build the label, because a nominal review that never actually changes anything is a weak basis for claiming the exemption if anyone asks.
6. Track the two deadlines separately
This is the fact the rest of the piece has been building toward, and it's worth isolating on its own. Every Article 50 obligation became legally binding on 2 August 2026, except one. The marking and detection duty under Article 50(2), the machine-readable-marks requirement from step 3, gets a grace period until 2 December 2026, and only for AI systems that were already placed on the market before 2 August 2026. The Commission's FAQ page scopes the grace period to that exact duty, and its quick-facts page summarizes it the same way: a grace period for the marking obligation, for generative AI systems already on the market, ending in December. Every other duty covered in this article, interaction disclosure, deepfake labeling, public-interest text labeling, emotion-recognition disclosure, has been live since 2 August. A new system you're building today doesn't inherit the grace period at all. It only ever applied to systems that predate the law's application date.
What happens if you don't comply
Penalties scale with the violation and the violator. The Commission's FAQ puts the general ceiling at up to EUR 15 million or 3% of a company's total worldwide annual turnover for the preceding financial year, whichever calculation applies, with proportionality built in for SMEs. EU institutions, bodies, and agencies face a separate, lower ceiling: up to 750,000 euros for EU institutions, bodies, and agencies, per the Commission's quick-facts page.
Enforcement doesn't run through a single body. National market surveillance authorities handle most of it. The AI Office has a limited role, specific to general-purpose AI systems. The European Data Protection Supervisor covers EU institutions themselves. For engineering teams already working inside the unified EU regulatory framework nearshore teams already operate inside, Article 50 enforcement runs through bodies many will already recognize from other EU compliance work, not through a single new regulator with sole jurisdiction.
FAQ
Does the December 2026 deadline delay all of Article 50?
No. It only extends the deadline for the marking and detection duty under Article 50(2), and only for AI systems that were already placed on the market before 2 August 2026. Every other duty under Article 50, interaction disclosure, emotion-recognition disclosure, deepfake labeling, and public-interest text labeling, has applied since 2 August 2026.
Does Article 50 apply to AI-written source code?
No. The Commission's FAQ page lists source code among the explicit exemptions from the marking and detection duty, alongside short sequences, machine-to-machine outputs, closed-loop industrial use, and assistive editing functions.
Do I need to label AI-generated content published before 2 August 2026?
No. The Commission's FAQ states that content generated before 2 August 2026 doesn't need to be labeled retroactively, though it notes that doing so voluntarily is encouraged.
Who enforces Article 50, and where do complaints go?
National market surveillance authorities are the primary enforcers. The AI Office has a limited role, covering general-purpose AI systems specifically. The European Data Protection Supervisor handles EU institutions, bodies, and agencies. </content>
