From the journal

EU AI Act Article 50 Transparency: 2026 Implementation and Compliance Guide

Article 50 of the EU AI Act assigns disclosure duties to providers and deployers of certain AI systems. The question is which duties apply on August 2, 2026, what the official guidance and Code add, and what remains unsettled. This analysis assumes nonpersonal use with an EU territorial connection. It excludes exclusively military, defence, or national-security uses. It assumes no authorized law-enforcement exception. It states the law as of July 31, 2026.

27 min read

Summary

Article 50 generally applies from August 2, 2026. Article 111(4) gives one Article-50-specific extension. Providers of covered synthetic-content systems placed on the market before that date have until December 2, 2026, for Article 50(2). Regulation (EU) 2024/1689, arts. 50, 113; Regulation (EU) 2026/1744, art. 1(39)(b).

Separate grandfathering language creates two narrow qualifications. Without prejudice to Article 5, Article 111(1) gives Annex X large-scale IT system components placed on the market or put into service before August 2, 2027, until December 31, 2030, to comply. Article 111(2) literally refers to “this Regulation” for qualifying legacy high-risk systems. Commission guidance limits Article 111(2) to high-risk duties. Regulation (EU) 2024/1689, art. 111(1); Regulation (EU) 2026/1744, art. 1(39)(a); C(2026) 5054 final, Annex, footnote 50.

Outside those special classes, no Article-50-specific extension covers interaction, emotion, biometric, deepfake, or public-interest text disclosures. Systems placed on the market from August 2 must meet Article 50(2) immediately. Regulation (EU) 2026/1744, art. 1(39)(b).

Providers bear the interaction and synthetic-output duties. Deployers bear the emotion, biometric, deepfake, and public-interest text duties. One entity can hold both roles. Regulation (EU) 2024/1689, arts. 3(3), 3(4), 50(1)–(4).

Provider marking does not replace a deployer’s human-perceivable deepfake or public-interest text label. The two duties can attach to the same output. Regulation (EU) 2024/1689, art. 50(2), (4), (5); C(2026) 5054 final, Annex, paras. 8, 117.

The Commission approved and published the English guidance content on July 20, 2026. Its approval communication says formal adoption awaits all language versions. No later adoption act was located by July 31. The guidance remains nonbinding in every event. Commission, C(2026) 5054 final, at 2 and Annex, para. 5.

The voluntary Code addresses Articles 50(2), 50(4), and 50(5). It does not address interaction or emotion and biometric notices. The Commission and AI Board found it adequate, but adherence gives no conclusive proof of compliance. Commission Opinion C(2026) 4839 final, paras. 8, 52; AI Board Conclusion (July 9, 2026), at 7.

Notice does not make a prohibited emotion or biometric use lawful. A controller still needs a lawful basis and all required safeguards. Regulation (EU) 2016/679, arts. 5, 6, 9; Regulation (EU) 2024/1689, arts. 2(7), 5(1)(f), 5(1)(g), 50(3); C(2026) 5054 final, Annex, para. 110.

For operators under Article 99, an Article 50 fine can reach EUR 15 million. An undertaking’s ceiling is the higher of that amount and 3% of prior-year worldwide turnover. Qualifying SMEs and small mid-cap companies use lower ceilings. Union institutions face an Article 100 ceiling of EUR 750,000. Regulation (EU) 2024/1689, arts. 99(4), (6), (6a), (7), 100(3); Regulation (EU) 2026/1744, art. 1(38).

Implementation date and transition

Article 50 becomes applicable on August 2, 2026. The Digital Omnibus did not postpone that general date. Regulation (EU) 2024/1689, art. 113; Regulation (EU) 2026/1744, arts. 1(40), 4.

The Omnibus created one targeted transition. A provider gets until December 2, 2026, when three conditions exist. The system generates synthetic audio, image, video, or text. The provider placed it on the market before August 2. The outstanding duty falls under Article 50(2). Regulation (EU) 2026/1744, art. 1(39)(b).

The enacted rule says “placed on the market,” not “put into service.” The Act defines those events separately. Placement means first making a system available on the Union market. Putting into service covers supply for first use directly to a deployer or for own Union use. The use must follow the system’s intended purpose. Regulation (EU) 2024/1689, arts. 3(9), 3(11). An own-use system may therefore lack the transition if nobody placed it on the market.

Guidance paragraph 153 describes a broader transition for systems placed on the market “or put into service.” That wording conflicts with the enacted amendment. The enacted text controls. A provider should not rely on the broader phrase without official clarification. C(2026) 5054 final, Annex, para. 153.

Two broader legacy provisions require caution. Without prejudice to Article 5, Article 111(1) covers AI systems that are components of Annex X large-scale IT systems. They must have been placed on the market or put into service before August 2, 2027. They must comply by December 31, 2030. Regulation (EU) 2024/1689, art. 111(1).

Subject to the same Article 5 carveback, amended Article 111(2) addresses other high-risk systems. They must have been placed on the market or put into service before their applicable Chapter III date. It says “this Regulation” applies only if those systems undergo significant design changes from that date. In any event, providers and deployers of high-risk systems intended for public-authority use must comply by August 2, 2030. Regulation (EU) 2026/1744, art. 1(39)(a).

Guidance footnote 50 limits Article 111(2) to high-risk requirements. It says Article 50 still applies on August 2. That purposive reading fits new Article 111(4), but the operative wording is broader. No court has resolved the conflict. C(2026) 5054 final, Annex, para. 153 and footnote 50.

Outside Article 111(1) and the disputed Article 111(2) wording, no transition covers Articles 50(1), 50(3), or 50(4). The Commission’s nonbinding guidance rejects broader Article 111(2) reliance. Affected legacy operators should not rely on Article 111(2) without tailored advice. C(2026) 5054 final, Annex, footnote 50.

Article 111(4) also omits Article 50(5). Paragraph 5 governs information referenced in Article 50(2). The text does not say whether that related presentation duty starts in August or follows the December deadline. A legacy provider should treat this timing point as open. Regulation (EU) 2024/1689, art. 50(5); Regulation (EU) 2026/1744, art. 1(39)(b).

The guidance takes a nonretroactive view of existing content. It says outputs created before August 2 need no later mark or label. It treats public-interest text differently when first published on or after that date. That text needs disclosure even if generated earlier. C(2026) 5054 final, Annex, para. 154. The regulation does not state this content rule expressly. Treat it as persuasive enforcement guidance, not a statutory safe harbor.

Status of the guidance and Code

The statute controls every duty, exception, and penalty. The Commission guidance can aid interpretation, but it cannot amend Article 50. Its own paragraph 5 calls it nonbinding. Only the Court of Justice can give the final authoritative interpretation. C(2026) 5054 final, Annex, para. 5.

The public record contains a status mismatch. The Commission’s July 29 webpage says it adopted the guidelines. European Commission, “Guidelines on transparency obligations for providers and deployers of AI systems” (updated July 29, 2026). The posted instrument approved the content of a draft communication. It says formal adoption and applicability will follow when all language versions become available. C(2026) 5054 final, at 2. No later formal-adoption instrument was located through July 31. The prudent description is “Commission-approved and published English content, pending documented formal adoption.”

This mismatch affects the guidance’s procedural status, not Article 50’s start date. It also does not change the guidance’s nonbinding character. Businesses can use its interpretations as an enforcement-risk indicator. They should distinguish its textual readings from added policy detail.

The Code of Practice has a different function. It gives voluntary technical and labeling measures for Articles 50(2), 50(4), and 50(5). It does not cover Articles 50(1) or 50(3). Code of Practice on Transparency of AI-Generated Content, at 5–36.

The Commission and AI Board assessed both Code sections as adequate. A signatory may rely on the Code across the Union as an organized compliance method. Adherence does not create a presumption or conclusively prove compliance. Regulation (EU) 2026/1744, recital 41; Commission Opinion C(2026) 4839 final, paras. 51–52; AI Board Conclusion (July 9, 2026), at 7.

The Opinion and Board assessment preceded the Omnibus’s July 27 entry into force. Opinion paragraph 5 says the parallel assessments remain valid under the amended process. That is the Commission’s position, not a judicial ruling. Commission Opinion C(2026) 4839 final, para. 5.

The nonbinding guidance permits other adequate methods for non-signatories. It suggests explaining compliance through a gap analysis against the Code. The Code is not a binding equivalence benchmark. C(2026) 5054 final, Annex, paras. 147–148.

The amended Code procedure contains a drafting tension. New Article 50(7) retains a fallback implementing-act power and cross-refers Article 56(6). Amended Article 56(6) discusses assessments for Articles 53 and 55, not Article 50. Recital 41 also describes removing implementing-act approval for codes. Guidance paragraph 150 adds Article 50(5) to potential common rules, but Article 50(7) names only paragraphs 2 and 4. The operative Article 50(7) controls. This tension affects future procedure, not the present duties or dates. Regulation (EU) 2026/1744, recital 41 and arts. 1(20), 1(21); C(2026) 5054 final, Annex, para. 150.

Actor and duty map

Article 50 divides responsibility by legal role and system use. Contract labels do not displace the Act’s definitions. One company may act as provider for one feature and deployer for another. Regulation (EU) 2024/1689, arts. 3(3), 3(4), 50(1)–(4).

A provider of an AI system intended for direct human interaction must design and develop it to inform each person that the person interacts with AI. No notice is required when that fact is obvious to the specified reasonable person.

A provider of a system generating synthetic audio, image, video, or text must make its outputs machine-readably marked and detectable as artificial or manipulated. Technical-feasibility factors and three express exceptions limit this duty.

A deployer of emotion recognition or biometric categorisation must inform exposed natural persons of the system’s operation. A narrow authorized law-enforcement exception applies.

A deployer generating or manipulating a deepfake must disclose the artificial generation or manipulation. Evident creative works receive a special presentation rule. A law-enforcement exception also applies.

A deployer generating or manipulating public-interest text must disclose the artificial generation or manipulation. The review exception says “AI-generated content.” The guidance also applies that exception to manipulated text.

The provider is the actor that develops a system, or has it developed, under its name or trademark. It must also place the system on the market or put it into service. A deployer uses a system under its authority, except during purely personal nonprofessional activity. Regulation (EU) 2024/1689, arts. 3(3), 3(4).

An upstream model supplier is not automatically the Article 50 provider. The duties attach at AI-system level. A general-purpose AI system can still fall within Article 50(2). Regulation (EU) 2024/1689, arts. 3(3), 3(66), 50(2), recital 133.

Direct AI interaction notices

A provider must build notice into a system intended to interact directly with natural persons. The person must learn that the interaction is with AI. Regulation (EU) 2024/1689, art. 50(1).

The draft guidance reads “interaction” as a genuine, contextual, two-way exchange. It generally excludes passive data collection, background processing, recommendations, and human-mediated communications. It includes conversational agents, avatars, and robots when the AI itself communicates. C(2026) 5054 final, Annex, paras. 29–31.

An AI agent can trigger the duty when it communicates with a third party for a principal. The guidance asks the notice to identify the artificial nature and the represented person. C(2026) 5054 final, Annex, para. 31. The first point follows Article 50’s text. Identifying the principal is added guidance and should be followed where feasible.

The notice must be clear and distinguishable by the first interaction. Applicable accessibility rules also govern it. Regulation (EU) 2024/1689, art. 50(5). A prominent opening message will usually work. Terms alone, a hidden machine mark, or an ambiguous label like “assistant” will not meet the guidance’s view. C(2026) 5054 final, Annex, paras. 32–40.

The obviousness exception is narrow and contextual. The test asks whether AI interaction is obvious to a reasonably well-informed, observant, and circumspect person. The provider must consider the circumstances and use context. Regulation (EU) 2024/1689, art. 50(1). Audience age, vulnerability, language, and digital literacy can defeat obviousness. C(2026) 5054 final, Annex, paras. 41–46. Providers should record that analysis before using the exception.

Authorized crime-detection, prevention, investigation, or prosecution systems receive a limited exception. Safeguards and third-party rights still apply. Public-facing systems through which people report crimes remain covered. Regulation (EU) 2024/1689, art. 50(1).

Machine-readable marking and detection

Article 50(2) imposes a provider-side technical duty. It covers systems generating synthetic audio, images, video, or text. It expressly includes general-purpose AI systems. Regulation (EU) 2024/1689, art. 50(2).

The output must be machine-readably marked and detectable as artificial or manipulated. The guidance treats marking and detectability as distinct, linked elements. A mark without an available detection method is insufficient under that view. C(2026) 5054 final, Annex, paras. 69–78.

Article 50(5) also refers to information under paragraph 2. The statute does not explain how an invisible mark can be clear to a person. The guidance treats a human-readable detection result as the relevant information. It expects that result when a person chooses to verify content. C(2026) 5054 final, Annex, paras. 75–78, 141–143. This nonbinding gloss does not resolve the legacy timing issue.

The solution must be effective, interoperable, robust, and reliable where technically feasible. The provider must consider each content type’s limits, implementation cost, and the acknowledged state of the art. Regulation (EU) 2024/1689, art. 50(2). These factors shape the method. They do not create a general cost defense.

Three statutory exceptions narrow the duty. It does not apply when the system only assists standard editing. It also does not apply when the system does not substantially alter deployer input or its meaning. An authorized law-enforcement use can qualify under the third exception. Regulation (EU) 2024/1689, art. 50(2).

The guidance places reproduction, ranking, raw recording, and simple data processing outside “synthetic” generation. It also excludes source code, short symbol sequences, machine-only outputs, and nonfinal closed-loop workflow outputs. C(2026) 5054 final, Annex, paras. 64–68. Those categories do not appear verbatim in Article 50. A provider should test each output against the statute before adopting them.

The guidance proposes two further narrow readings. Certain closed industrial or business-only outputs may need no mark. Ephemeral real-time content may also qualify when marking is infeasible and viewers receive an in-experience notice. C(2026) 5054 final, Annex, paras. 86–88. Article 50 states no express industrial or business-only exemption. Reliance carries more risk until courts, standards, or an implementing act confirm the view.

The Code translates Article 50(2) into operational measures. It generally uses signed metadata plus an imperceptible watermark. Free-form text uses one watermark layer and treats text under 200 tokens as too short. Code of Practice, Section 1, Measure 1.1.

One layer also suffices in a narrow physical-product setting. The environment must be technically controlled, closed, and mainly instructive. Effective measures must prevent capture, export, or external dissemination. Code of Practice, Section 1, Measure 1.1.

The Code calls for mark preservation, an accessible detector, clear results, documentation, and testing. Code of Practice, Section 1, Measures 1.2, 2.1, 2.3, 4.1–4.2. By February 2, 2027, signatories must implement a minimum watermark-detection interoperability solution. They must keep working toward fuller interoperability. Code of Practice, Section 1, Measure 3.4. That milestone does not postpone the statutory duty.

The AI Board reserved both measures for review. It singled out the short-text treatment and minimum interoperability method as standards and evidence develop. AI Board Conclusion (July 9, 2026), at 6–7. Neither measure creates a statutory exemption.

Emotion recognition and biometric categorisation notices

A deployer must inform every natural person exposed to an emotion-recognition or biometric-categorisation system. The notice concerns the system’s operation. Regulation (EU) 2024/1689, art. 50(3).

An emotion-recognition system identifies or infers emotions or intentions from biometric data. A biometric-categorisation system assigns people to categories using biometric data. An ancillary categorisation feature can fall outside the latter definition. It must be ancillary to another commercial service and strictly necessary for objective technical reasons. Regulation (EU) 2024/1689, arts. 3(39), 3(40).

Physical states, including pain or fatigue, fall outside the emotion definition. Mere detection of an apparent expression also falls outside unless used to infer emotion or intention. Regulation (EU) 2024/1689, recital 18.

The guidance applies the notice duty to real-time and later analysis. It asks the deployer to reach all exposed people, including children, no later than first exposure. C(2026) 5054 final, Annex, paras. 99–108. The notice need not state the purpose under Article 50 alone. Other laws may require the purpose, controller identity, legal basis, retention period, and rights.

Article 50 does not authorize the underlying use. Since February 2, 2025, emotion inference in workplaces and education institutions is generally prohibited. Medical or safety uses can qualify for the exception. Regulation (EU) 2024/1689, arts. 5(1)(f), 113.

Article 5(1)(g) also prohibits biometric categorisation used to deduce or infer listed traits. They include race, political opinions, trade-union membership, religious or philosophical beliefs, sex life, and sexual orientation. The prohibition does not cover labelling or filtering lawfully acquired biometric datasets based on biometric data. It also does not cover categorising biometric data in law enforcement. Regulation (EU) 2024/1689, art. 5(1)(g). A notice cannot cure either prohibition.

Article 50(3) is broader than those prohibitions and Annex III. It can require notice for permitted categories that are not high-risk. The system must still fit Article 3(39) or 3(40). Regulation (EU) 2024/1689, arts. 3(39), 3(40), 50(3); C(2026) 5054 final, Annex, paras. 102–104.

Personal-data law applies independently and by data role. A controller must select a lawful basis and give the required data notice. A processor must follow lawful instructions and its own processor duties. An Article 50 notice is not consent, a lawful basis, or a substitute for that data notice. Regulation (EU) 2016/679, arts. 5, 6, 12–14, 28.

Biometric inputs do not automatically trigger GDPR Article 9. They do so as biometric data when used to identify a person uniquely. Other inferred protected data can trigger Article 9 on their own terms. A controller shall conduct a DPIA when processing is likely to result in a high risk to natural persons’ rights and freedoms. Regulation (EU) 2016/679, arts. 9, 35.

Competent authorities processing for criminal-law purposes may instead face Directive (EU) 2016/680, arts. 1(1), 2, 3(7), 4, 8, 10–13, 27. Union institutions face Regulation (EU) 2018/1725, arts. 4, 5, 10, 14–16, 24, 27, 39. The GDPR territorial test under Article 3 needs its own analysis.

The timing differs for related high-risk duties. Annex III lists emotion recognition. It also lists biometric categorisation by sensitive or protected attributes or characteristics based on inference. Article 6(3) can remove a listed system from high-risk status when its conditions are met. The applicable Chapter III duties generally start on December 2, 2027. Article 50(3) still starts on August 2, 2026, subject to the Article 111 issue above. Regulation (EU) 2024/1689, art. 6(3), Annex III, points 1(b), 1(c), art. 113; Regulation (EU) 2026/1744, art. 1(40)(b).

When high-risk duties apply, a deployer must keep automatically generated logs under its control. The period must be appropriate and at least six months, unless applicable law provides otherwise. An employer must notify worker representatives and affected workers before workplace use. Article 26(11) covers people subject to an Annex III system’s decisions or decision assistance. Regulation (EU) 2024/1689, arts. 26(6), 26(7), 26(11), 113; Regulation (EU) 2026/1744, arts. 1(39)(a), 1(40)(b).

The Article 50(3) law-enforcement exception is narrower than a general public-sector exemption. The system must be permitted by law for crime detection, prevention, or investigation. Safeguards and Union law still apply. Regulation (EU) 2024/1689, art. 50(3).

Deepfake disclosure

A professional deployer must disclose covered deepfakes at or before first exposure. A provider’s hidden technical mark does not satisfy this person-facing duty. Regulation (EU) 2024/1689, art. 50(2), (4), (5); C(2026) 5054 final, Annex, para. 117.

A deepfake is AI-generated or manipulated image, audio, or video content. It must resemble existing persons, objects, places, entities, or events. It must also falsely appear authentic or truthful to a person. Regulation (EU) 2024/1689, art. 3(60). Text alone is not a deepfake under this definition.

The guidance says the definition does not require intent to deceive. It treats context and audience expectations as relevant to false appearance. A visible fantasy scene may fail that element. A realistic fabricated recording of a public official will usually satisfy it. C(2026) 5054 final, Annex, paras. 113–116.

The guidance reads “existing” to include a subject that could plausibly exist or could have existed. C(2026) 5054 final, Annex, para. 113. That reading extends beyond the ordinary statutory phrase. Deployers may follow it for enforcement caution, but should identify it as nonbinding.

The disclosure must be perceivable without a special tool. A visible label, audible statement, or comparable cue can work. The Code offers an EU “AI” icon or an equivalent label, with medium-specific placement rules. Code of Practice, Section 2, Measures 1.1–1.2.

Evidently artistic, creative, satirical, fictional, or analogous works still need disclosure. The deployer may use an appropriate method that does not hinder display or enjoyment. Regulation (EU) 2024/1689, art. 50(4). The exception changes presentation, not the existence of the duty.

An authorized law-enforcement use can receive an exception. Regulation (EU) 2024/1689, art. 50(4).

New Article 5 prohibitions apply from December 2, 2026. Point (ba) covers realistic images, videos, audio, or similar material of an identifiable person’s intimate parts or sexually explicit activities. It requires the absence of that person’s freely given, specific, informed, unambiguous, and explicit consent. Point (bb) covers material or performance defined in Directive 2011/93/EU, Article 2(c) and (e). A national-law “without right” defence can apply. For placement or putting into service, the ban applies when generation or manipulation is the intended purpose. It also applies when the outcome is reasonably foreseeable and reproducible without significant technical modification, and the system lacks reasonable and adequate preventive and corrective safeguards. For use, the deployer must act for that purpose. A change that neither increases exposure of intimate parts nor alters the nature of depicted sexually explicit activities is not manipulation under point (ba). A label cannot legalize prohibited content. Directive 2011/93/EU, arts. 2(c), 2(e), 5(1); Regulation (EU) 2026/1744, arts. 1(7), 1(40)(a).

Public-interest generated text

Article 50(4) reaches a narrower text class than Article 50(2). It covers generated or manipulated text when published to inform the public. The publication must concern a matter of public interest. The original generation purpose need not be publication. Regulation (EU) 2024/1689, art. 50(4), second subparagraph.

The guidance treats “published” as communication to a fairly large, indeterminate audience. It excludes private messages and ordinary internal circulation. It reads public-interest matters broadly across public affairs, safety, health, rights, science, culture, and material economic developments. C(2026) 5054 final, Annex, paras. 130–132.

The deployer must disclose that AI generated or manipulated the text. The label must be clear, distinguishable, and present by first exposure. Regulation (EU) 2024/1689, art. 50(4), (5). Article 50 contains no obviousness exception for this text.

One exception has two cumulative parts. The text must undergo human review or editorial control. A natural or legal person must also hold editorial responsibility for publication. Regulation (EU) 2024/1689, art. 50(4), second subparagraph.

The exception literally says “AI-generated content,” though the main duty also covers manipulated text. The guidance applies the exception to both classes. C(2026) 5054 final, Annex, paras. 133–138. That extension is nonbinding. A deployer of manipulated-only text should treat the point as unresolved.

The guidance expects substantive, knowledgeable review. Fact-checking and source evaluation can qualify. Grammar correction, automated review, or cursory approval cannot. Later material AI revision can defeat the earlier review. C(2026) 5054 final, Annex, paras. 133–138.

The exception removes only the deployer’s public-interest text label. It does not remove the provider’s Article 50(2) marking duty. C(2026) 5054 final, Annex, para. 8. It also does not excuse data, intellectual-property, personality, advertising, or criminal law. C(2026) 5054 final, Annex, paras. 124, 127–129.

The law-enforcement exception remains available only for use authorized by law. Regulation (EU) 2024/1689, art. 50(4).

Presentation, accessibility, and evidence

Every person-facing Article 50 disclosure must be clear and distinguishable. It must arrive no later than the person’s first interaction or exposure. It must conform to applicable accessibility requirements. Regulation (EU) 2024/1689, art. 50(5).

“First exposure” applies person by person within targeted and foreseeable distribution. A label may fail after controlled reposting or clipping. Persistent or repeated labels can reduce that risk. Unforeseeable third-party dissemination does not alone make the original actor responsible. C(2026) 5054 final, Annex, paras. 12–13, 115, 143. The Code requires signatories to use specified start, interval, and top-of-text placement. Code of Practice, Section 2, Measure 1.2.

Article 50 adds no separate accessibility code. Existing rules determine the applicable standard. Public-sector websites may face Directive (EU) 2016/2102, arts. 1, 3–5. Covered products and services may face Directive (EU) 2019/882, arts. 2, 4, 14. C(2026) 5054 final, Annex, para. 144.

An implementation record should map each system, role, modality, audience, territory, and exception. It should preserve notice versions, technical tests, detection access, review approvals, and exception analyses. These are prudent recommendations, not a statutory retention schedule.

The Code separately requires signatory compliance processes and supporting documentation. It also requires testing and monitoring under its narrower terms. Code of Practice, Section 1, Measures 4.1–4.2; Section 2, Measure 2.1. Those records can answer authority requests and support a defense.

Territorial scope and cumulative duties

Article 50 can reach actors outside the Union. The Act covers providers placing systems on the Union market or putting them into service there. It covers deployers located in the Union. It also reaches certain third-country actors when their system’s output is used in the Union. Regulation (EU) 2024/1689, art. 2(1).

The guidance links the output rule to authorized or reasonably foreseeable Union use. C(2026) 5054 final, Annex, paras. 10, 13. The statute does not state that limitation in those words. Third-country actors should document why any Union use is incidental, unforeseeable, or unauthorized before relying on that interpretation.

Several exclusions can remove an actor or activity. Article 2(3) excludes systems only where and insofar as used exclusively for military, defence, or national-security purposes. Article 2(6) excludes defined sole-purpose scientific research and development.

Article 2(8) excludes premarket research, testing, and development. It expressly keeps real-world testing within the Act. A natural person acting only in a personal, nonprofessional capacity is not a deployer. Regulation (EU) 2024/1689, art. 2(3), (6), (8), (10).

Article 2(4) also excludes certain third-country public authorities and international organizations. They must use the system within international cooperation or agreements for law-enforcement and judicial cooperation with the Union or Member States. The third country or international organization must provide adequate safeguards for individuals’ fundamental rights and freedoms. Regulation (EU) 2024/1689, art. 2(4).

The free and open-source exemption does not shield an Article 50 system. Regulation (EU) 2024/1689, art. 2(12). A professional social-media creator can also be a deployer despite using a public consumer tool. Regulation (EU) 2024/1689, arts. 2(10), 3(4).

One amended product rule creates a separate exclusion. Article 50 does not apply to Article 6(1) systems tied to products in Annex I, Section B. Article 2(2) applies only its listed provisions to that product class. Regulation (EU) 2026/1744, art. 1(2)(a). Those systems need a product-specific scope review.

Article 50 duties can accumulate. An interactive generator may trigger both provider duties. Its output may later trigger a deployer label. High-risk system duties can also apply when their separate dates and criteria are met. Regulation (EU) 2024/1689, art. 50(1)–(5); C(2026) 5054 final, Annex, para. 8.

The Omnibus delayed many Annex III high-risk duties until December 2, 2027. It delayed covered Annex I duties until August 2, 2028. Those Chapter III dates do not themselves delay Article 50. The separate Article 111 language remains relevant. Regulation (EU) 2024/1689, arts. 111, 113; Regulation (EU) 2026/1744, arts. 1(39)(a), 1(40)(b). Compliance with Article 50 also does not resolve duties under data, platform, consumer, intellectual-property, civil, or media law. Regulation (EU) 2024/1689, art. 2(7); C(2026) 5054 final, Annex, paras. 124–129, 140.

Enforcement and near-term actions

Member States had to designate their AI authorities by August 2, 2025. National market-surveillance authorities will enforce most Article 50 duties. The relevant Chapter IX powers generally apply from August 2, 2026. Regulation (EU) 2024/1689, arts. 70, 74, 113.

The AI Office has exclusive supervision in two main categories. The first requires the same provider or undertaking to develop both the model and system. Exceptions cover Annex I products, Annex III point 2, certain Article 74(6) systems, and Annex III point 8 justice systems. The second category covers systems constituting or integrated into a designated very large platform or search engine.

Deployer supervision shifts to the AI Office only when the deployer is the provider or belongs to that undertaking. The EDPS acts for Union institutions, bodies, offices, and agencies. Regulation (EU) 2024/1689, arts. 74, 75, as amended by Regulation (EU) 2026/1744, art. 1(31).

Any natural or legal person may complain to the relevant market-surveillance authority. That complaint is supervisory and does not itself award compensation. The Act creates no bespoke Article 50 damages action. Article 110 added the AI Act to Annex I of Directive (EU) 2020/1828. From July 27, 2026, qualified entities may seek representative injunctive or redress measures. The Directive’s scope and national procedures must be satisfied. Regulation (EU) 2024/1689, arts. 85, 110; Directive (EU) 2020/1828, arts. 2, 4, 7–9 and Annex I, point 68; Regulation (EU) 2026/1744, arts. 1(40)(c), 4.

Authorities can seek information, inspect, and order corrective action within their powers. Data-protection and other fundamental-rights authorities retain parallel mandates and cooperation rights. Regulation (EU) 2024/1689, arts. 74, 75a–75d, 77, 79; Regulation (EU) 2026/1744, arts. 1(32), 1(34).

For operators under Article 99, an Article 50 fine can reach EUR 15 million. An undertaking’s ceiling is the higher of that amount and 3% of prior-year worldwide turnover. Qualifying SMEs and small mid-cap companies receive lower statutory ceilings. Regulation (EU) 2024/1689, art. 99(4), (6), (6a); Regulation (EU) 2026/1744, art. 1(38).

Those amounts are ceilings. Authorities must assess gravity, duration, fault, cooperation, prior fines, and steps taken to limit harm. Prior fines under other laws for the same conduct also matter. Member State rules may include warnings and nonmonetary measures. Regulation (EU) 2024/1689, art. 99(1), (7); Regulation (EU) 2026/1744, art. 1(38)(a).

Supplying incorrect, incomplete, or misleading information to a notified body or national competent authority in reply to a request has a separate ceiling. It is EUR 7.5 million. An undertaking’s ceiling is the higher of that amount and 1% of prior-year worldwide turnover. Qualifying SMEs and small mid-cap companies use lower ceilings. Member States set the extent of fines for their public authorities and bodies. Due process and judicial remedies apply. Regulation (EU) 2024/1689, art. 99(5), (6), (6a), (8)–(10); Regulation (EU) 2026/1744, art. 1(38)(c).

Union institutions, bodies, offices, and agencies face up to EUR 750,000 for Article 50 violations. They face up to EUR 1.5 million for Article 5 violations. Regulation (EU) 2024/1689, art. 100(2), (3). For operators governed by Article 99, an Article 5 breach carries a ceiling of EUR 35 million or, for an undertaking, 7% of prior-year worldwide turnover, whichever is higher. For a qualifying SME, Article 99(6) uses whichever ceiling is lower. Regulation (EU) 2024/1689, art. 99(3), (6). Giving notice cannot move a prohibited use into the lower tier.

Article 50 sets no dedicated evidence format or retention period. High-risk logging rules do not fill that gap before their own application dates. Regulation (EU) 2024/1689, arts. 12, 19, 26(6), 113; Regulation (EU) 2026/1744, art. 1(40)(b). Voluntary records remain prudent because an authority can demand information and corrective action.

The immediate work is role-specific. Providers need live interaction notices and tested synthetic-output marking paths. Deployers need first-exposure notices for emotion and biometric systems. They also need labels suited to targeted and foreseeable distribution of deepfakes and covered public-interest text.

The Article 111(4) transition should not slow new-system work. It protects only qualifying legacy providers and only for Article 50(2). Any reliance should record the placement date and first Union-market availability. The separate Article 111 issues above remain.

More from the journal

See all
Illia Prokopiev

Dubai VASP Licensing: Fresh Authorizations Signal Continued Regulatory Momentum

Dubai’s Virtual Assets Regulatory Authority records permissions for specified virtual-asset activities in Dubai outside the Dubai International Financial Centre. The question is whether “Dubai VASP licensing continues to show fresh authorization activity” is supported as at 31 July 2026, and what those records legally permit. This analysis treats VARA’s English register and entity pages as the current factual record. It distinguishes active full licences from non-operational in-principle approvals.

Illia Prokopiev

UK Crypto Authorisation: From Future Watching to Application Preparation

The United Kingdom has made legislation and principal FCA rules for a new authorisation regime covering specified cryptoasset activities. The question is whether firms should now prioritise application work, given the published dates and FCA pre-application warning. This analysis tests that proposition as at 31 July 2026. It assumes no firm-specific facts and addresses commercial cryptoasset services provided in or to the United Kingdom.

Illia Prokopiev

Regulation (EU) 2026/1744, the Digital Omnibus on AI, changes selected duties under the EU Artificial Intelligence Act

Regulation (EU) 2026/1744, the Digital Omnibus on AI, changes selected duties under the EU Artificial Intelligence Act. The question is whether the stated entry date, revised high-risk dates, small mid-cap support, and sandbox expansion are legally accurate.