Somebody on your team read that Brussels postponed the AI Act and filed it under next year. Half right. The high risk rules did slip, some of them into 2028, but Article 50 landed on schedule on 2 August 2026 and it is the one that touches ordinary products: if you run a chatbot, generate images or audio, publish AI-written text on matters of public interest, or ship a generative model other people build on, you now owe somebody a disclosure. We spent the afternoon in the text rather than the summaries, because the summaries kept merging two different deadlines into one. They are not the same deadline. One of them was already in force when you woke up this morning.
The short answer
The EU AI Act transparency rules are in force. Providers must disclose that a user is talking to an AI and machine-mark generative output. Deployers must visibly label deepfakes and AI-written text published on matters of public interest. The delay you read about in the spring moved the high risk obligations, not these. If a human edits your published text and owns it, the text duty does not reach you.
The delay was real. It just wasn’t this one.
The Digital Omnibus is where the confusion starts. Council and Parliament reached provisional political agreement on 7 May 2026 and rewrote the high risk calendar, pushing Annex III obligations from 2 August 2026 out to 2 December 2027 and Annex I products to 2 August 2028. Formal adoption still hasn’t happened. That’s a genuine reprieve, and it earned the coverage it got.
It didn’t touch Article 50.
So the transparency duties applied on Sunday, on the original schedule, to systems that were never classed high risk to begin with. Your support chatbot isn’t high risk. It’s still in scope here. That gap between what got delayed and what people think got delayed is the whole story this week.
Four duties, and only two are yours
Article 50 splits along a line worth getting right, because guessing wrong puts the obligation on the wrong company. Paragraphs 1 and 2 bind providers. Paragraphs 3 and 4 bind deployers. Building on someone else’s model does not make you the provider of it.
Providers owe two things. People have to know they’re dealing with an AI system, told from the start of the first interaction in a clear and distinguishable manner, unless it’s obvious to a reasonably well-informed person. And generative output has to be marked in a machine-readable format and detectable as artificially generated or manipulated.
Deployers owe the visible half. Deepfakes get disclosed in a way a human can perceive, which means a visible or audible label and not a line buried in EXIF. AI-generated text published to inform the public on matters of public interest gets labelled too, politics and public health being the examples the Commission reaches for. The third deployer duty covers emotion recognition and biometric categorisation. If you run one of those, you already know.
One nuance that catches people who ship image or video generation: the marking duty is on the provider of the system, so if you’re wrapping a hosted model, the mark is meant to come from upstream. Worth checking whether it actually does. When Flux 3 shipped video and audio with weights promised later, questions like this were exactly what nobody had answered yet.
The exemption most publishers live under
The public interest text duty has a hole in it, and it’s a wide one. Text that went through substantive human review, where a natural or legal person holds editorial responsibility for the publication, isn’t caught. That describes most editorial workflows that were already working properly. Draft with a model, have an editor read it and own it, and paragraph 4 doesn’t reach you.
We know how that reads coming from a site that publishes daily. So, plainly: this piece was checked against the Commission’s own FAQ and the legal text before it went up, and a person owns it. That’s the standard the Act describes. It isn’t a high bar. It’s just one you have to clear rather than assert.
Two other carve-outs matter. AI performing an assistive function for standard editing, grammar correction being the stock example, doesn’t trigger the marking duty. And evidently artistic or satirical work needs only disclosure that doesn’t hamper the display or enjoyment of the work.
None of this is escaped by being outside the EU. The obligations reach non-EU companies where the output lands with users in Europe.
Live obligation, missing yardstick
Now the awkward part. The duty is in force and there’s no test for passing it.
The text asks for marking that’s effective, reliable, robust and interoperable. Four adjectives, no technology. No named watermark scheme, no metadata format, nothing you can point an auditor at. The harmonised standards meant to fill that gap are late, and not quietly: the Commission recorded significant delays in implementing decision C(2025)3871 back in June 2025, and they weren’t ready for August.
What exists instead is a voluntary Code of Practice, final version published on 10 June 2026. Read it and you find an unusually honest admission for a compliance document, that no single marking technique meets the Act’s requirements. So it asks signatories to run at least two complementary machine-readable layers and to offer a detection mechanism users and researchers can check against. Voluntary, though. Signing is evidence of good faith rather than a safe harbour. The Commission also promised guidelines clarifying the scope of Article 50 alongside the Code, and we haven’t found them published.
Enforcement runs through national market surveillance authorities. The ceiling in Article 99(4) is 15 million euros or 3 percent of total worldwide annual turnover, whichever is higher, with SMEs capped at whichever is lower. Nobody has been fined, and no authority has said what a clear and distinguishable label looks like to them. I’d expect the first real answer to arrive as an enforcement action rather than guidance, which is a rotten way to find out.
Industry pushback isn’t the usual noise either. Karen Massin at Google warned that a flood of overlapping labels makes it “harder for people to get the clear context they need”, and there’s something to that, because a label that appears on everything stops carrying information. Ashley Casovan gave the flatter response, that we hear this with every compliance requirement, “and yet, the world turns”.
The pattern rhymes with what happened when Google took its €890M DMA fine: the rule arrives stated as an outcome, the specifics get worked out later against whoever tests them first.
If you ship anything generative into Europe, the boring next hour is the right one. Work out whether you’re the provider or the deployer on each surface, then look at what a user actually sees before they type. The chatbot disclosure is the cheapest of the four to get right and the easiest to have skipped.
Sources
The obligations, the deepfake definition in Article 3(60), the exemptions and the 2 December 2026 marking grace are taken from the European Commission FAQ, Transparency obligations under Article 50 of the AI Act, with the article-by-article breakdown cross-checked against the Article 50 guide and the fine ceilings against Article 99. That Article 50 was not postponed by the Digital Omnibus, and the 7 May 2026 provisional agreement moving the high risk dates, is reported by aiactblog.nl and Gibson Dunn. The Code of Practice publication date, its voluntary status and the two-layer marking commitment come from Jones Day, and the harmonised standards delay recorded in C(2025)3871 from Plesner. The Massin and Casovan quotes are as reported by Euronews on 2 August 2026. One caveat on the grace period: most sources put it at four months to 2 December 2026, while Plesner’s reading of an earlier Omnibus draft cited six months to 2 February 2027. The Commission FAQ says 2 December 2026, and that is the date used above.
Frequently asked questions
Did the Digital Omnibus delay the AI Act transparency rules?
No. The provisional political agreement of 7 May 2026 moved the high risk obligations, Annex III out to 2 December 2027 and Annex I products to 2 August 2028, and formal adoption is still pending. It left Article 50 where it was. The transparency duties applied from 2 August 2026 on the original schedule. The only Article 50 concession is a four month grace on the machine-readable marking duty in paragraph 2, and only for generative systems already placed on the market before that date.
Do I have to label AI-assisted articles on my own site?
Probably not, if a human edits them. The Article 50(4) duty covers text published to inform the public on matters of public interest, and it carves out text that underwent substantive human review or editorial control where a natural or legal person holds editorial responsibility for the publication. A normal editorial workflow clears that. Fully automated publishing on politics or public health does not, and that is the case the provision was written for.
What counts as a deepfake under the AI Act?
Article 3(60) sets three cumulative criteria: the content resembles existing persons, objects, places or events, it appears authentic or truthful, and that appearance is false. All three have to hold. Deployers must disclose deepfakes in a clear and distinguishable manner that a person can actually perceive, so a visible or audible label rather than metadata alone. Evidently artistic, creative, satirical or fictional work only needs disclosure that does not hamper the display or enjoyment of the work.
Which watermarking technology does the AI Act require?
None. The text asks for marking that is effective, reliable, robust and interoperable, and names no scheme at all. The harmonised standards meant to fill that gap are late, formally recorded as significantly delayed in Commission implementing decision C(2025)3871 of 23 June 2025. The voluntary Code of Practice published on 10 June 2026 concedes that no single marking technique meets the requirements, and asks signatories to run at least two complementary machine-readable layers plus a detection mechanism. Signing it is evidence of good faith, not a safe harbour.
Does Article 50 apply to companies outside the EU?
Yes, where the output is used in the EU. A US or UK company serving European users is in scope, the same extraterritorial reach the GDPR established. Enforcement runs through national market surveillance authorities, and the ceiling in Article 99(4) is 15 million euros or 3 percent of total worldwide annual turnover, whichever is higher. For SMEs and startups the fine is capped at whichever of the two is lower.