On 2 August 2026 the transparency obligations in Article 50 of the EU AI Act became applicable and enforceable by national authorities across the EU. Five days ago. Most of what has been written about it since is written for lawyers, and it’s good, but it stops at the point where the work starts. Somebody has to put the disclosure in the interface, decide what it says, decide when it appears, and decide who checks it still works after the next release. That somebody is usually a product manager.
Does Article 50 only apply to high-risk AI systems?
Article 50 of the EU AI Act applied from 2 August 2026. It covers four situations: systems that talk to people, systems that generate synthetic content, emotion recognition and biometric categorisation, and deepfakes or AI-written public-interest text. It applies whatever your risk classification. Penalties reach €15 million or 3% of worldwide turnover.
So this is the product version.
The first thing to understand is that it reaches you even if nothing you own is high-risk
The high-risk regime is what everyone spent two years preparing for, and it didn’t arrive on 2 August. The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July and came into force on 27 July, six days before the deadline it moved. Stand-alone high-risk systems under Annex III now apply from 2 December 2027, and AI embedded in regulated products under Annex I from 2 August 2028.
Article 50 was left alone. It applied on the original date, and it isn’t scoped by risk classification at all. If your product has a support chatbot, you’re in scope. If it generates text or images for users, you’re in scope. If it categorises people by biometric data or reads their emotions, you are in scope. A company with no high-risk AI anywhere in its estate can still have live obligations today, which is the part most teams haven’t internalised.
Four situations, and they don’t all land on the same person
The obligations split between the provider, who develops and places a system on the market, and the deployer, who uses it under their own authority. Getting this wrong is how work ends up on the wrong backlog.
Systems that interact directly with people. The provider designs the system so that a person is told they’re dealing with AI, unless that’s already obvious. The Commission’s guidelines frame obviousness from the perspective of a reasonably well-informed person, which is a lower bar than your team thinks it’s. Your team knows it’s a bot. A first-time user on a mobile browser at eleven at night doesn’t.
Systems that generate synthetic audio, image, video or text. The provider marks the output in a machine-readable format so it can be detected as artificially generated. This is a build task rather than a copy task, and it’s the one with a real engineering dependency.
Emotion recognition and biometric categorisation. The deployer informs the people exposed to it, and handles the personal data under EU data protection law as well.
Deepfakes and public-interest text. The deployer discloses that image, audio or video content is artificially generated or manipulated, and in certain cases the same applies to AI-generated text published to inform the public on matters of public interest.
Read those last two again if you buy your AI rather than build it. Marking the output is the provider’s job, but disclosing a deepfake and disclosing public-interest text land on you, the company using the tool. Your vendor’s compliance does not discharge your obligation.
The most operationally sharp thing in the whole release is a date
Article 50(2), the machine-readable marking obligation, got a transitional period to 2 December 2026. That transition applies only to generative systems already placed on the EU market before 2 August 2026. Anything placed on the market on or after that date complies immediately, with no transition at all.
If you’re planning an EU launch this half, your ship date is now a compliance variable. I’ve not seen that on a single roadmap I’ve been shown this year, and it’s the kind of thing that surfaces four days before a release when someone in legal finally reads the ticket.
Content generated before 2 August 2026 doesn’t need to be labelled retroactively, which is the one piece of good news in the timing.
What "obvious" costs you in design
The interaction disclosure has an exemption where AI use is obvious from context, and every team I’ve watched reach this clause has immediately tried to live inside it. It’s a bad place to build.
Obviousness is assessed from the user’s side rather than yours. A widget labelled "Assistant" in the corner of a page isn’t obvious. A chat window that opens with a friendly human first name is actively working against you. The design question isn’t how little you can say, it’s where the disclosure sits so that a person meets it before they act on the answer, which usually means at first interaction and again wherever the output gets consequential.
There’s a related carve-out worth knowing for text: where AI-generated content undergoes human editorial review and somebody holds editorial responsibility for it, the publication obligation can fall away. That is a genuine exemption and it is also a genuine trap, because it only holds if the review is real. A person clicking approve on a queue of forty pieces an hour isn’t exercising editorial responsibility. This is the same problem I wrote about in meaningful human oversight, wearing different clothes.
What I’d actually put on a backlog this month
Start with an inventory, because you can’t scope what you’ve not found. Every system that talks to a user, generates content, or touches biometric or emotional data. Include the ones bought on a team credit card, since those are the systems nobody has assessed. If you already keep an AI use-case register, this is what it’s for.
For each one, settle whether you’re provider or deployer, and write it down. This determines which obligations are yours and it’s the answer you’ll need first in any conversation with an authority.
Then the disclosure work itself. Copy, placement, and the state where it appears. Treat it as an interface change with a design review, because a disclosure nobody reads satisfies nobody.
Then the marking work, if you generate content, along with the market-placement date for anything launching into the EU this half.
Then the thing everyone skips: a check that survives the next release. Disclosures get refactored away. Put it in whatever your release checklist is, or accept that you’ll be compliant only until the next redesign.
The Commission’s guidelines on Article 50 were adopted on 20 July 2026 and are non-binding, but they’re the clearest statement of how national market surveillance authorities are expected to read this, so they’re worth an hour. There’s also a voluntary Code of Practice on Transparency of AI-Generated Content, published on 10 June 2026, which offers a recognised route to demonstrating compliance on the marking obligations. Signing it’s a commercial decision rather than a product one, though the product team usually ends up implementing it either way.
The trap nobody is talking about
The high-risk delay bought sixteen extra months, and the risk is that organisations read that as permission to demobilise. The architecture of the Act didn’t change. The risk-based approach, the governance structure, and the core obligations are all still there, sitting on a later date.
Meanwhile the obligation that reaches the most companies is the one that arrived on time, applies regardless of risk tier, and is enforceable now.
Common questions
Does Article 50 only apply to high-risk AI systems?
No. Article 50 applies to any AI system used in one of the four situations it covers, whatever its risk classification. A company with no high-risk AI at all can still be in scope simply by running a chatbot or publishing AI-generated content.
Who is responsible, the vendor or the company using the tool?
Both, for different things. The provider who develops and places the system on the market handles interaction disclosure and machine-readable marking of synthetic output. The deployer who uses the system handles disclosure of deepfakes, disclosure of AI-generated public-interest text, and notification for emotion recognition or biometric categorisation. Buying a tool does not transfer the deployer obligations to the vendor.
Is there a grace period for Article 50?
Only one, and it is narrow. The machine-readable marking obligation under Article 50(2) runs to 2 December 2026, and only for generative systems already placed on the EU market before 2 August 2026. Anything placed on the market on or after 2 August 2026 complies immediately. Content generated before 2 August 2026 does not need retroactive labelling.
What happened to the high-risk obligations due on 2 August 2026?
They moved. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and deferred stand-alone Annex III high-risk systems to 2 December 2027, and AI embedded in regulated products under Annex I to 2 August 2028. Article 50 was not amended.
What are the penalties for breaching Article 50?
Non-compliance can attract fines of up to 15 million euro or 3% of worldwide annual turnover, whichever is higher.
When is AI use obvious enough to skip the disclosure?
The Commission's guidelines assess obviousness from the perspective of a reasonably well-informed person encountering the system, rather than from the perspective of the team that built it. A product label, or an internal assumption that everyone knows it is a bot, does not meet that test on its own.
I’m an AI product manager working across fintech, SaaS, and regulated enterprise — currently leading AI and workflow product at T-Systems International. If you’re building AI governance into a product right now and want to compare notes, I’m at csincsakf@gmail.com or on LinkedIn.