ScrutinEyes · 2026-08-01
Article 50, checked
The EU AI Act's transparency rules apply as of August 2, 2026 — what they require, what they don't, who they bind, and what ignoring them costs.
What it actually requires
Article 50 sets four obligations, and it matters who each one lands on.
1. If you provide an AI system people interact with — a chatbot, a voice agent — the people interacting must be informed they're dealing with AI. The regulation requires such systems be “designed and developed in such a way that the natural persons concerned are informed” of the AI interaction, unless already obvious to a reasonably informed person. This duty falls on the provider, not the user. (Art. 50(1))
2. If you provide an AI system that generates synthetic content — text, audio, images, video — the output must be “marked in a machine-readable format and detectable as artificially generated or manipulated.” This marking obligation binds the provider of the system. (Art. 50(2))
3. If you deploy emotion-recognition or biometric-categorization systems, you must “inform the natural persons exposed thereto of the operation of the system” — and handle data under EU data-protection rules. This lands on the deployer: the business using the system, not its vendor. (Art. 50(3))
4. If you deploy deepfakes, or publish AI-generated text on matters of public interest, you must “disclose that the content has been artificially generated or manipulated.” Also a deployer duty. (Art. 50(4))
Timing is specified: information must be provided “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure,” meeting accessibility requirements. (Art. 50(5))
What it doesn't require
Article 50 is not a licensing regime, audit requirement, or ban. The regulation exempts: AI performing assistive editing functions without substantial input alteration (grammar suggestions); certain authorized law-enforcement uses; artistic, satirical, and fictional works (disclosure only acknowledges existence without hampering the work); and AI-drafted text that undergoes human review where a person or entity holds editorial responsibility for publication. That final exemption matters for businesses using AI to draft content a human actually edits and owns: edited, human-accountable text receives different treatment from raw machine output.
What the EU has published to help — and what it costs to ignore
This implementation arrives with support. On June 10, 2026, the European Commission published a voluntary Code of Practice on marking and labelling AI-generated content, including common EU icons for labeling. On July 20, 2026 it adopted guidelines on the Article 50 transparency obligations meant to ensure compliance “in a consistent, effective, proportionate and uniform manner.” Henna Virkkunen, the Commission's Executive Vice-President for Technological Sovereignty, stated: “[Guidelines help] providers and developers to comply with their obligations.”
Non-compliance carries defined penalties: under Article 99(4)(g), violations of Article 50 transparency obligations can draw administrative fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher — with reduced penalties for SMEs and startups under Article 99(6).
Does it reach a US business?
It can. The AI Act follows the GDPR long-arm pattern: offering AI systems in the EU market, or having their outputs used there, can put you in scope regardless of incorporation location. Whether it reaches your business is a legal question for counsel, not for blog posts or readiness vendors.
The useful question underneath
Here's what's true regardless of Brussels's awareness: every one of Article 50's duties presumes something most small businesses currently cannot do: produce an accurate inventory of where AI touches their operation. Which customer interactions involve an AI system? Which published content is AI-generated, and did a human take editorial responsibility for it? Which vendor tools quietly added AI features this year?
That's not a legal question — it's a governance question, and it's measurable today against NIST AI RMF 1.0, the US framework built for exactly this. Your enterprise customers, your insurer, and US regulators are converging on the same demand the EU just wrote down: demonstrate you know what your AI does.
If you can't answer the inventory question, start there. We built a free resource that addresses it in about five minutes: initialeyes.com/ai-governance. Readiness guidance, not legal advice — and if what you actually need is a lawyer, it will tell you that plainly.
Sources
- Article 50, Regulation (EU) 2024/1689 — full text via the AI Act Explorer
- Article 99 (penalties) — AI Act Explorer
- European Commission: Guidelines on transparency obligations (adopted 20 July 2026)
- European Commission: Code of Practice on marking and labelling AI-generated content (10 June 2026)
- Eunews, 20 July 2026 — source of the Virkkunen quote
- Corroborating analyses consulted: Sidley Data Matters · Cloud Security Alliance research note · AI Act Explorer practical guide
ScrutinEyes discloses per its own standard: portions of this piece were drafted with AI assistance and carry human editorial review and responsibility — the same editorial-control principle Article 50(4) recognizes, practiced here.
Reading this because someone's asking about your security? See exactly which rules apply to you and where you stand — check your readiness free. Five minutes, in your browser, nothing stored unless you ask. Readiness, not legal advice.