Most of the coverage this year was about the delay. The Digital Omnibus moved the EU AI Act’s high-risk obligations out to 2027 and 2028, and a lot of teams read that as breathing room across the board. Article 50 was never part of that delay. Its transparency duties applied from 2 August 2026, they are now enforceable, and they reach systems that most people would not think of as regulated at all, starting with an ordinary chatbot.
If you run anything that talks to your customers, generates content, reads emotion or produces synthetic media, this is the part of the Act that already affects you. We covered the wider reshuffle in what the Digital Omnibus actually changed; this piece is about the obligation it deliberately left in place.
What Article 50 actually requires
Article 50 sets out four transparency duties. They are about disclosure, not about how the system is built, and they split between providers and deployers.
AI that interacts with people (Article 50(1)). If you provide an AI system intended to interact directly with people, you must make sure those people are told they are dealing with an AI, unless it is already obvious to a reasonably informed person. This is the one that catches everyone, because it covers the everyday chatbot, the voice assistant and the AI agent handling a support queue. None of those need to be high-risk to be in scope.
AI-generated synthetic content (Article 50(2)). If you provide an AI system that generates synthetic audio, image, video or text, the outputs have to be marked in a machine-readable format and detectable as artificially generated or manipulated. This is the watermarking and provenance duty, and it falls on the provider of the generating system, including general-purpose systems. There is a narrow exception where the AI performs an assistive or standard editing function and does not substantially alter the input. We go deeper on the model-level duties in what GPAI providers have to do.
Emotion recognition and biometric categorisation (Article 50(3)). If you deploy a system that infers emotion or sorts people into categories from their biometric data, you must inform the people exposed to it. This duty sits with the deployer, and it runs alongside your data protection obligations rather than replacing them.
Deep fakes and public-interest text (Article 50(4)). If you deploy AI that generates or manipulates image, audio or video to create a deep fake, you must disclose that the content is artificially generated or manipulated. Where AI generates or manipulates text that is published to inform the public on matters of public interest, that too must be disclosed, unless the content went through human editorial review with a person or organisation holding editorial responsibility. There are carve-outs for clearly artistic, creative or satirical work, where the disclosure must not spoil the piece.
The trap: the delay does not cover this
The reason Article 50 keeps catching people is that the headline was about high-risk. The Omnibus pushed the standalone high-risk deadline to 2 December 2027 and the regulated-product deadline to 2 August 2028, and it is easy to assume the whole Act moved with it. It did not. The high-risk timeline and the transparency timeline are two separate clocks, and only one of them was reset. Our EU AI Act deadlines guide keeps the two apart.
Article 50 also does not care about your risk tier. A support chatbot is almost never high-risk, but the moment it talks to a customer it is inside Article 50(1). So an organisation can be entirely correct that its high-risk obligations are years away, and still be non-compliant today because nobody told users the chatbot was an AI.
One deadline that has not passed yet
There is a single date still ahead. The Article 50(2) marking duty applied immediately to generative systems placed on the market from 2 August 2026, but systems that were already on the market before that date have a transition to 2 December 2026 to put machine-readable marking in place. If you launched a generative feature earlier in the year, that clock is still running. It is the one part of Article 50 where you may still have time to prepare rather than remediate.
Working out where you stand
The obligations are triggered by roles, so the first job is to be honest about whether you are the provider or the deployer of each system. The two roles carry different Article 50 duties, and it is common to be both across a portfolio: a provider of the chatbot you built, a deployer of the deep-fake tool you bought in. We wrote a full guide to telling provider from deployer, and it is the distinction that decides which parts of Article 50 land on you. If you are mostly on the buying side, the deployer’s view of the Act sets out what that means in practice.
Once the roles are clear, the work is straightforward to describe:
- Inventory the systems in scope. Chatbots and assistants, anything that generates media or text, anything doing emotion recognition or biometric categorisation, and any deep-fake tooling. This is exactly what an AI system register is for, and if you already keep one, Article 50 scoping is a filter over it rather than a fresh exercise.
- Add the disclosures. A clear notice at first interaction that a user is dealing with AI, exposure notices for emotion and biometric systems, and deep fake and public-interest labelling. The information has to be given at the latest at the first interaction and be accessible.
- Implement machine-readable marking for generative outputs, and treat 2 December 2026 as the backstop for anything already live.
- Keep the evidence. Note who is the provider and who is the deployer for each system, what disclosure was applied, and how the marking works. If a regulator or a customer asks, the answer should already exist.
The European Commission has published guidelines on the Article 50 obligations, and a code of practice on marking and detecting AI-generated content is being developed, so the practical detail is firmer than it was a year ago.
Why this rewards having a system
Article 50 is not hard to understand. What makes it awkward is that the duties are scattered across whichever teams happen to own a chatbot, a content generator or an analytics tool, and no single person usually has the full list. That is a governance problem more than a legal one. Organisations that already run an AI inventory and a simple process for classifying systems find Article 50 is a short piece of scoping work. Organisations without one tend to discover their obligations the hard way, one system at a time.
This is the quiet argument for treating AI governance as a standing capability rather than a project. The transparency rules are now live, the marking deadline is weeks rather than months away for some, and the high-risk obligations are coming back around in 2027. A team that can answer where its AI is and what it does will meet each of those in turn without a scramble.
The short version
The delay was real, but it was about high-risk. Article 50 transparency has applied since 2 August 2026 and is enforceable now, with fines up to 15 million euros or 3 percent of worldwide turnover. It covers ordinary chatbots, AI-generated content, emotion recognition and deep fakes, regardless of risk tier, and it splits between providers and deployers. The only date still ahead is 2 December 2026, for marking generative systems that were already on the market. Work out your role for each system, add the disclosures, mark your synthetic outputs, and keep the evidence.
That is the kind of scoping we do with clients under our EU AI Act work: finding the systems in scope, sorting provider from deployer, and getting the disclosures and evidence in place. If you want a quick read on where Article 50 lands for your systems, get in touch.
Frequently asked questions
Did the Digital Omnibus delay the Article 50 transparency rules?
No. The Digital Omnibus deferred the EU AI Act's high-risk obligations, moving the standalone high-risk deadline to 2 December 2027 and the regulated-product deadline to 2 August 2028. It left Article 50 untouched. The transparency duties have applied since 2 August 2026 and are now enforceable, so a team that assumed the delay covered everything may already be non-compliant.
Who has to comply with Article 50, providers or deployers?
Both, and the split matters. Providers carry the duties for AI systems that interact with people (Article 50(1)) and for marking AI-generated synthetic content (Article 50(2)). Deployers carry the duties for emotion recognition and biometric categorisation (Article 50(3)) and for disclosing deep fakes and certain AI-generated public-interest text (Article 50(4)). Many organisations are both, on different systems, so you need to work it out system by system.
Does Article 50 apply if our AI system is not high-risk?
Yes. Article 50 is a horizontal transparency obligation that applies to certain kinds of AI regardless of their risk classification. An ordinary customer-service chatbot is not high-risk, but if it interacts directly with people it still falls under Article 50(1). This is why the high-risk delay does not help here: the trigger is what the system does, not which risk tier it sits in.
What is the 2 December 2026 deadline?
It is the transition for one specific duty. Providers of generative AI systems that were already on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) obligation to mark their synthetic outputs in a machine-readable, detectable format. Systems placed on the market from 2 August 2026 onwards had to comply from that date. So if you shipped a generative feature before August, the marking clock is still running.
What are the penalties for breaching Article 50?
Non-compliance with the Article 50 transparency obligations can attract fines of up to 15 million euros or 3 percent of total worldwide annual turnover, whichever is higher. That is a lower tier than the ban on prohibited practices, but it is still significant, and it applies to obligations that are already live rather than ones still on the horizon.
Building something you need to govern?
Start with a fixed-scope AI Opportunity & Risk Audit.
Meet an Expert