Technology · Digital regulation
EU AI Act transparency rules now apply, with limited grace period for some providers
Article 50 obligations took effect on 2 August, requiring disclosure of AI interactions, deepfakes and biometric systems. Only machine-readable marking duties get a transition period to December.
As of 2 August 2026, organisations operating in the European Economic Area must tell people when they are interacting with an artificial intelligence system, when their emotions or biometric traits are being categorised by one, and when content has been generated or manipulated by AI. These are the transparency obligations set out in Article 50 of the EU AI Act, and they are now law.
The EU Digital Omnibus, which amended the AI Act before these provisions took effect, deferred only a narrow subset of the Article 50 duties. The vast majority of transparency requirements are already enforceable. That distinction between what is deferred and what is not is the detail that matters most for any company still calibrating its compliance plans.
What Article 50 actually demands
Article 50 imposes three broad categories of transparency duty. First, organisations must disclose to individuals when they are interacting directly with an AI system rather than a human. Second, when emotion-recognition or biometric-categorisation systems are being applied to a person, that person must be informed. Third, when content constitutes a deepfake or AI-generated or AI-manipulated text that is relevant to the public interest, the fact that it was produced or altered by AI must be disclosed.
These are not abstract principles. They are specific legal obligations, enforceable from 2 August, and they apply to both the providers that develop and place AI systems on the EEA market and the deployers that actually use them. The responsibilities, however, are distributed differently depending on which side of that divide an organisation falls.
Providers and deployers face different duties
Under the AI Act, a provider is the organisation that has developed an AI system and places it on the EEA market or puts it into service under its own name or trademark. A deployer is the organisation that uses such a system in its operations. The distinction is not always straightforward, particularly where companies both build and operate their own AI tools, but the classification matters because each role carries different transparency requirements.
Providers bear the technical obligation to ensure that machine-readable markings and detection measures are built into their systems, so that AI-generated synthetic audio, images, video or text can be identified as such. Deployers, meanwhile, must ensure that individuals exposed to emotion-recognition or biometric-categorisation systems receive appropriate notice. Deployers are also responsible for disclosing when they publish deepfakes or AI-generated public-interest text.
The provider's marking duty and the deployer's notification duty run in parallel. They are separate obligations, and satisfying one does not discharge the other.
The narrow transition period
The only grace period in Article 50 applies to the provider-side machine-readable marking and detection obligation, and only for AI systems that were already on the EEA market before 2 August 2026. Providers relying on this transition have until 2 December 2026 to bring their systems into compliance. Systems placed on the market on or after 2 August must comply from day one.
Crucially, the four-month transition does not postpone any deployer duties. The requirements covering emotion recognition, biometric categorisation, deepfakes and public-interest text have applied since 2 August, regardless of when the underlying AI system was first placed on the market. Any organisation that assumed a blanket transition period would apply to all Article 50 obligations has misread the regulation.
What the Commission's guidelines say
The European Commission has published two documents to help organisations interpret Article 50: the Guidelines on Transparency for Providers and Deployers of AI Systems and the Code of Practice on Transparency of AI-generated Content. Both provide a framework, but neither is a substitute for case-by-case assessment. The guidelines describe what transparency should look like in principle; the Code of Practice offers more practical direction on labelling AI-generated content. Neither carries the force of law on its own, though they will inform how national regulators interpret compliance.
The gap between what the guidelines describe and what an individual system requires is where the compliance burden actually falls. A social media company deploying emotion-recognition tools on user-generated video faces different practical questions from a bank using biometric categorisation in identity verification. Each system and use case demands its own assessment.
The practical steps organisations should take now
The immediate priority, according to legal analysis from Morgan Lewis, is confirming that the Article 50 duties applying from 2 August have been addressed. For providers, that means ensuring appropriate notices are given when individuals interact directly with AI systems and that required marking and detection measures are in place. Where a provider's system was on the EEA market before 2 August and is relying on the transition period, the provider should document the basis for that reliance clearly.
For deployers, the work is more varied. They must ensure individuals exposed to emotion-recognition or biometric-categorisation systems receive proper notice. They must also review how they publish deepfakes and AI-generated or manipulated public-interest text: when disclosure is required, who is responsible for making it, and how it will be presented to the audience.
Deployers using third-party AI systems have an additional task. They should obtain information from the provider about the provider's marking arrangements and whether the provider is relying on the 2 December transition period. Without that information, a deployer cannot be confident that the system it is using meets the provider-side obligations that run alongside its own.
Where responsibility can fall between the cracks
The split between provider and deployer obligations creates a coordination problem that the regulation does not fully resolve. A provider may build machine-readable watermarks into its AI-generated images, satisfying its own duty, but if the deployer fails to disclose that the content is AI-generated to the end user, the transparency purpose of Article 50 is undermined. Conversely, a deployer might assume the provider has handled technical marking, only to find the provider invoked the transition period and has not yet complied.
This is not a theoretical concern. Many organisations will be both providers and deployers of different AI systems, and internal compliance functions may not have mapped which systems fall under which set of duties. The stronger position, as the Morgan Lewis analysis notes, is one in which the organisation can explain what information is provided, by whom, when, and why. That level of clarity requires more than a compliance checklist. It requires governance.
The wider enforcement picture
Article 50 is not the only part of the AI Act coming into force this year. Prohibited AI practices, including social scoring and certain types of biometric identification, have been banned since February 2026. Rules on high-risk AI systems, which carry the heaviest compliance burden under the Act, will apply from August 2027. General-purpose AI model obligations, including transparency and copyright requirements, take effect in August 2025.
The staggered timetable means that enforcement activity in the coming months will focus on transparency and prohibited practices. National market surveillance authorities in each member state are responsible for enforcement, and the European Commission has said it will monitor how consistently those authorities apply the rules. Early enforcement patterns will shape how companies approach the much larger compliance exercise that high-risk AI rules will require next year.
There is also a question of resources. Several member states have yet to designate their national authorities or allocate budgets for AI Act enforcement. Where enforcement capacity is thin, compliance may become a matter of corporate policy rather than regulatory pressure, at least initially. But that calculus could shift quickly once the first enforcement actions are taken.
Sources
Organisations
European Commission · Morgan Lewis