On 2 August 2026 the transparency obligations in Article 50 of the EU AI Act became applicable across the EU. Most of what has been written about it since is written for lawyers. Somebody still has to put the disclosure in the interface, decide what it says, and decide who checks it after the next release. That is usually a product manager.
Does Article 50 of the EU AI Act only apply to high-risk AI?
No. Article 50 applied from 2 August 2026 and covers four situations regardless of risk classification: systems that talk to people, systems that generate synthetic content, emotion recognition and biometric categorisation, and deepfakes or AI-written public-interest text. A company with no high-risk AI at all can still be in scope. Penalties reach €15 million or 3% of worldwide turnover.
So this is the product version.
When the Digital Omnibus deferred the high-risk obligations, Article 50 was left alone. It applied on the original date, and it is not scoped by risk classification at all. If your product has a support chatbot, you are in scope. If it generates text or images for users, you are in scope. If it categorises people by biometric data or reads their emotions, you are in scope. A company with no high-risk AI anywhere in its estate can still have live obligations today, which is the part most teams have not internalised.
Four situations, and they do not all land on the same person
The obligations split between the provider, who develops and places a system on the market, and the deployer, who uses it under their own authority. Getting this wrong is how work ends up on the wrong backlog.
Systems that interact directly with people. The provider designs the system so that a person is told they are dealing with AI, unless that is already obvious. The Commission’s guidelines frame obviousness from the perspective of a reasonably well-informed person, which is a lower bar than your team thinks it is. Your team knows it is a bot. A first-time user on a mobile browser at eleven at night does not.
Systems that generate synthetic audio, image, video or text. The provider marks the output in a machine-readable format so it can be detected as artificially generated. This is a build task, not a copy task, and it is the one with a real engineering dependency.
Emotion recognition and biometric categorisation. The deployer informs the people exposed to it, and handles the personal data under EU data protection law as well.
Deepfakes and public-interest text. The deployer discloses that image, audio or video content is artificially generated or manipulated, and in certain cases the same applies to AI-generated text published to inform the public on matters of public interest.
Read those last two again if you buy your AI rather than build it. Marking the output is the provider’s job, but disclosing a deepfake and disclosing public-interest text land on you, the company using the tool. Your vendor’s compliance does not discharge your obligation.
The most operationally sharp thing in the whole release is a date
Article 50(2), the machine-readable marking obligation, got a transitional period to 2 December 2026. That transition applies only to generative systems already placed on the EU market before 2 August 2026. Anything placed on the market on or after that date complies immediately, with no transition at all.
Sit with what that does to a roadmap. Two products, same architecture, same outputs, same provider. One shipped into Europe on 1 August and has until December to get watermarking working. The other shipped on 2 August and needed it working at launch.
If you are planning an EU launch this half, your ship date is now a compliance variable. I have not seen that on a single roadmap I have been shown this year, and it is the kind of thing that surfaces four days before a release when someone in legal finally reads the ticket.
Content generated before 2 August 2026 does not need to be labelled retroactively, which is the one piece of good news in the timing.
What “obvious” costs you in design
The interaction disclosure has an exemption where AI use is obvious from context, and every team I have watched reach this clause has immediately tried to live inside it. It is a bad place to build.
Obviousness is assessed from the user’s side, not yours. A widget labelled “Assistant” in the corner of a page is not obvious. A chat window that opens with a friendly human first name is actively working against you. The design question is not how little you can say, it is where the disclosure sits so that a person meets it before they act on the answer, which usually means at first interaction and again wherever the output gets consequential.
There is a related carve-out worth knowing for text: where AI-generated content undergoes human editorial review and somebody holds editorial responsibility for it, the publication obligation can fall away. That is a genuine exemption and it is also a genuine trap, because it only holds if the review is real. A person clicking approve on a queue of forty pieces an hour is not exercising editorial responsibility. This is the same problem I wrote about with human oversight, wearing different clothes.
What I would actually put on a backlog this month
Start with an inventory, because you cannot scope what you have not found. Every system that talks to a user, generates content, or touches biometric or emotional data. Include the ones bought on a team credit card, since those are the systems nobody has assessed. This is the same intake discipline as an AI use-case register, pointed at transparency rather than risk tier.
For each one, settle whether you are provider or deployer, and write it down. This determines which obligations are yours and it is the answer you will need first in any conversation with an authority.
Then the disclosure work itself. Copy, placement, and the state where it appears. Treat it as an interface change with a design review, because a disclosure nobody reads satisfies nobody.
Then the marking work, if you generate content, along with the market-placement date for anything launching into the EU this half.
Then the thing everyone skips: a check that survives the next release. Disclosures get refactored away. Put it in whatever your release checklist is, or accept that you will be compliant only until the next redesign.
The Commission’s guidelines on Article 50 were adopted on 20 July 2026 and are non-binding, but they are the clearest statement of how national market surveillance authorities are expected to read this, so they are worth an hour. There is also a voluntary Code of Practice on Transparency of AI-Generated Content, published on 10 June 2026, which offers a recognised route to demonstrating compliance on the marking obligations. Signing it is a commercial decision rather than a product one, but the product team usually ends up implementing it either way.
The trap nobody is talking about
The high-risk delay bought sixteen extra months, and the risk is that organisations read that as permission to demobilise. The architecture of the Act did not change. The risk-based approach, the governance structure, and the core obligations are all still there, sitting on a later date.
Meanwhile the obligation that reaches the most companies is the one that arrived on time, applies regardless of risk tier, and is enforceable now.
I’m an AI product manager working across fintech, SaaS, and regulated enterprise — currently leading AI and workflow product at T-Systems International. If you’re building AI governance into a product right now and want to compare notes, I’m at csincsakf@gmail.com or on LinkedIn.