You Talkin' To Me? Operationalising The EU AI Act's Transparency Obligations

Viewpoints
August 3, 2026
7 minutes

Compliance conversations around the European Union’s AI Act have been dominated by its high-risk regime, which was set to take effect from 2 August 2026. But those conversations began to change three months ago, when the European Parliament and Council of the European Union agreed to push most of the Act’s high-risk timetable to December 2027 — and, for AI embedded in regulated products such as lifts and robot-assisted surgical devices, to August 2028.

However, there is another obligation that applies from 2 August 2026 that is largely untouched by the Digital Omnibus: the transparency obligations under Article 50 of the AI Act, which cover interactive AI, synthetic content, emotion recognition and biometric categorisation, and deepfakes. Businesses that have treated the Omnibus as a general extension to the Act will find that most of the Article 50 requirements remain firmly in place.

One Article; Four Obligations

Article 50 reads as a single provision but operates as four separate obligations — and it is possible for an AI system to trigger more than one obligation at a time. The European Commission’s guidelines on AI transparency, that were published in final form on 20 July 2026, provide helpful colour on how each obligation is intended to operate.

Article 50(1)

Applies to providers of AI systems that are built for direct interaction with people, such as chatbots, voice assistants and other agents, and the type of bots that have become a familiar feature of social media comment sections. Article 50(1) requires that whoever is on the other end of that interaction know that they are dealing with AI, unless it would be obvious to a reasonably well-informed user. 

The Commission’s guidelines take a narrow view of what counts as “obvious”, linking the assessment to an average member of the system’s actual intended audience. In practice, that tends to mean more disclosure wherever children, older users or other vulnerable groups are likely to be involved. The guidelines also make clear that if a provider cannot be confident an autonomous agent will avoid contact with a real person, it must disclose its artificial nature in every situation where that contact is reasonably foreseeable, not only where it is intended.

Article 50(2)

Applies to providers of systems — including general-purpose AI systems — that generate or manipulate synthetic audio, image, video or text, and requires providers to embed machine-readable markings in their output and ensure it is technically detectable as AI-generated. This is the one obligation that is affected by the Omnibus, but only for systems that are already on the market.

Article 50(3)

Applies to deployers of emotion recognition or biometric categorisation systems, who must tell people that they are being exposed to such a system — whether that exposure happens in real time or is reviewed afterwards.

Article 50(4)

Applies to deployers who must label deepfakes and AI-generated text published to inform the public on matters such as politics, public administration, the justice system or public health. The deepfake definition is broad and covers any AI-generated or manipulated image, audio or video that closely resembles a real (or plausibly real) person, place or event, and that would give someone a false impression of its authenticity. 

The principal way out for public interest text is genuine human review. Someone with relevant expertise has to have gone through the content and that person needs to be identifiable and empowered to approve, change, or reject it. A skim read before publication will not meet that bar.

Exemptions

Article 50 contains three carve-outs:

  1. Tools that pass content along without generating or altering it are exempt. This means that recommender engines, playlists, plain data logging and similar functions fall outside Article 50(2) because they are, in the Commission’s terms, not actually producing anything; instead, they are shuffling and surfacing content that already exists. However, a recommendation feature that also summarises, rewrites or otherwise transforms the underlying content becomes a “generator”, and the labelling obligation therefore applies.
  2. Source code is largely exempt on the basis that code is a technical instruction set rather than the kind of audio, image, video or text output that Article 50(2) intends to capture. Conversely, the exemption does not apply to plain-language documentation, README files and commit messages merely because they travel with exempt code, and providers generating such documentation with AI should treat it as requiring its own analysis.
  3. A narrow business-to-business exception applies to strictly technical outputs that are used only within a defined professional group and not released more widely. An output that starts life as an internal technical artefact but makes its way into a client deliverable, a marketing deck or a public repository is not covered by the exception, whatever its original purpose.

The Commission’s guidelines describe each exclusion in considerably more detail than the Act itself, such that a carve-out that looks applicable when reading Article 50 may be narrowed after consulting the guidelines. A link to the guidelines is available here.

What the Omnibus changed and what it didn't

The Council of the European Union formally adopted the Digital Omnibus on 29 June 2026, following the European Parliament’s approval on 16 June 2026. Although the Omnibus has been seen as a blanket delay to the AI Act, in reality it does three specific things: it postpones the high-risk regime described above, bans “nudifier” apps from December 2026 and carves out machinery already regulated under the EU Machinery Regulation.

In respect of Article 50, the Omnibus grants one extension: generative AI systems that were already on the market, or were already in service, before 2 August 2026 now have until 2 December 2026 to comply with the marking and detection obligation under Article 50(2). 

  • Articles 50(1), 50(3) and 50(4) are untouched by the Omnibus and remain on their original timeline.
  • Article 50(2) applies from 2 August 2026 to any system placed on the market from that date onwards, so the extension reaches only pre-existing systems.
  • Content generated before 2 August 2026 need not be labelled retrospectively, although the Commission has made clear that it would prefer organisations to do so voluntarily.

Enforcement and exposure

Article 50 will not be regulated by a single agency. Rather, national market surveillance authorities in each member state carry primary responsibility for enforcement, and the EU AI Office steps in only in narrower circumstances — namely, where the same entity provides both a general-purpose AI model and the system built on it, or where the system sits inside a very large online platform or search engine designated under the Digital Services Act. Penalties can reach fines of up to €15 million or 3% of global annual turnover, whichever is higher, with some scope for proportionality where SMEs and small mid-caps are concerned.

Given that multiple national authorities will be interpreting the Article 50 obligations, their readings may not always align. One reference point helps to address that uncertainty: the Code of Practice on Transparency of AI-Generated Content, which was finalised by the Commission on 10 June 2026 and assessed as adequate by both the Commission and the AI Board. Signatories can rely on it to demonstrate compliance with the Article 50(2), (4), and (5) marking and labelling obligations, regardless of where they are established or which authority supervises them. Providers and deployers that choose not to sign up can still demonstrate compliance by other means, but should expect more questions and closer scrutiny as a result.

Guidance for legal and compliance counsel

Businesses working through what Article 50 means for their own systems should bear the following in mind:

  • Audit each Article 50 limb separately rather than as a single compliance exercise. One chatbot or generative tool can trigger multiple obligations, and treating Article 50 as undifferentiated risks overlooking duties that fall on deployers rather than providers, or vice versa. That audit should extend to agentic systems, which the Commission’s guidelines bring into scope, even though the Act itself does not name them.
  • Implement user-facing disclosures as soon as possible. General terms and conditions or vague labels (e.g., “agent”) will not satisfy Article 50(1). Disclosure must sit in the interface, at the point of first contact and pitched to whoever is actually likely to encounter it.
  • Understand and apply the two-tier Article 50(2) deadline. Systems that are already on the market before 2 August 2026 have until 2 December 2026 to comply with the marking and detection obligation, whereas systems placed on the market on or after 2 August 2026 do not have a grace period. Organisations running a mix of legacy and newly deployed tools should map each system against the correct date rather than assuming that a single deadline applies across the board.
  • Check editorial workflows against the Article 50(4) exemption. Businesses that publish AI-assisted content on public-interest topics that intend to rely on the human-review exemption should confirm that someone with genuine expertise and authority is reviewing the content, rather than rubbing stamping it.
  • Consider signing the Code of Practice on Transparency of AI-Generated Content. For organisations that do or will generate or manipulate synthetic content at scale, the Code offers predictability over trusting that a tailored approach will survive scrutiny from whichever national authority ends up reviewing it.
  • Track what the Commission’s guidelines leave unresolved. The line between exempt source code and non-exempt natural-language output remains unclear, as does how the “obvious AI interaction” test will apply outside of the examples that the Commission has offered. This is not a reason to delay preparation, but highlights the need to build flexibility into whatever compliance programme is put in place now.

We are following developments in this area closely and are happy to help clients work through what Article 50 means for their own systems and deployment plans.

Subscribe to Ropes & Gray Viewpoints by topic here.