Article 50, checked
The EU AI Act's transparency rules apply as of August 2, 2026 — what they require, what they don't, who they bind, and what ignoring them costs.
As of August 2, 2026, Article 50 of the EU AI Act — the transparency provisions — applies. Most of what you’ll read about it today will be either panic or dismissal. Both are wrong, and both are checkable, so let’s check — against the regulation text and the European Commission’s own guidance, all linked below.
What it actually requires
Article 50 sets four obligations, and it matters who each one lands on.
1. If you provide an AI system people interact with — a chatbot, a voice agent — the people interacting must be informed they’re dealing with AI. The regulation requires such systems be “designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system,” unless that is already obvious to a reasonably well-informed person. This is the provider’s duty, not the user’s. (Art. 50(1))
2. If you provide an AI system that generates synthetic content — text, audio, images, video — the output must be “marked in a machine-readable format and detectable as artificially generated or manipulated.” This is the marking/provenance provision, and it binds the provider of the system. (Art. 50(2))
3. If you deploy emotion-recognition or biometric-categorization systems, you must “inform the natural persons exposed thereto of the operation of the system” — and handle the data under the EU’s data-protection rules. This one lands on the deployer: the business using the system, not the vendor who built it. (Art. 50(3))
4. If you deploy deepfakes, or publish AI-generated text to inform the public on matters of public interest, you must “disclose that the content has been artificially generated or manipulated.” Also a deployer duty. (Art. 50(4))
Timing is specified too: the information must be provided “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure,” and in a way that meets accessibility requirements. (Art. 50(5))
What it doesn’t require
This is where the panic loses the thread. Article 50 is not a licensing regime, an audit requirement, or a ban. The regulation carves out: AI performing an assistive function for standard editing, or that doesn’t substantially alter the input (think grammar suggestions); certain law-enforcement uses authorized by law; artistic, satirical, and fictional works (where disclosure only has to acknowledge existence without hampering the work); and AI-drafted text that has undergone human review where a person or entity holds editorial responsibility for its publication. That last one matters for every business using AI to draft content a human actually edits and owns: edited, human-accountable text is treated differently from raw machine output pushed to the public.
What the EU has published to help — and what it costs to ignore
This isn’t arriving unaccompanied. On June 10, 2026, the European Commission published a voluntary Code of Practice on marking and labelling AI-generated content, including common EU icons for labeling, and on July 20, 2026 it adopted guidelines on the Article 50 transparency obligations intended, in the Commission’s words, to ensure compliance “in a consistent, effective, proportionate and uniform manner.” Henna Virkkunen, the Commission’s Executive Vice-President for Technological Sovereignty, put the intent plainly: “These guidelines help providers and developers to comply with their obligations under the European AI Regulation.”
Non-compliance carries defined penalties: under Article 99(4)(g), violations of the Article 50 transparency obligations can draw administrative fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher — with a lower-of rule for SMEs and startups under Article 99(6).
Does it reach a US business?
It can. The AI Act follows the GDPR long-arm pattern: offering AI systems in the EU market, or having their outputs used there, can put you in scope regardless of where you’re incorporated. Whether it reaches your business is a legal question — one for counsel, not for a blog post, and not for a readiness vendor either.
The useful question underneath
Here’s the part that’s true whether or not Brussels ever knows your name. Every one of Article 50’s duties presumes something most small businesses can’t currently do: produce an accurate inventory of where AI touches their operation. Which customer interactions involve an AI system? Which published content is AI-generated, and did a human take editorial responsibility for it? Which vendor tools quietly added AI features this year?
That’s not a legal question — it’s a governance question, and it’s measurable today against NIST AI RMF 1.0, the US framework built for exactly this. Your enterprise customers, your insurer, and US regulators are converging on the same demand the EU just wrote down: show us you know what your AI does.
If you can’t answer the inventory question, start there. We built a free read that does it in about five minutes: initialeyes.com/ai-governance. Readiness, not legal advice — and if what you actually need is a lawyer, it will tell you that plainly.
Sources
Article 50, Regulation (EU) 2024/1689 — full text via the AI Act Explorer
Corroborating analyses consulted: Sidley Data Matters (24 June 2026) · Cloud Security Alliance research note (29 July 2026) · AI Act Explorer practical guide to Article 50
ScrutinEyes discloses per its own standard: portions of this piece were drafted with AI assistance and carry human editorial review and responsibility — the same editorial-control principle Article 50(4) recognizes, practiced here.


