Solutions

Article 50 transparency obligations became applicable on 2 August 2026

AI Governance & Documentation

The governance artifacts your customers and regulators ask for.

Risk-management frameworks, human-oversight policies, Article 50 transparency notices, technical documentation and GPAI model docs — the governance artifacts the AI Act names, built for your product.

“We have an AI policy” stopped being enough on 2 August 2026

For two years, AI governance was something companies could describe. Now it’s something they have to show. On 2 August 2026, Article 50 of the EU AI Act became applicable: from that date, people must be told when they’re interacting with an AI system, AI-generated content must be marked in machine-readable form, deepfakes and AI-generated text on matters of public interest must be labelled, and deployers of emotion-recognition and biometric-categorisation systems must inform the people exposed to them. These duties are horizontal — they apply regardless of whether your system is high-risk — and the Digital Omnibus, which moved the high-risk deadlines, deliberately did not move these.

And that’s only the newest layer. The prohibited-practices rules and the AI-literacy duty (Article 4) have applied since February 2025. The general-purpose AI model obligations have applied since August 2025, with legacy models due in full compliance by August 2027. The high-risk conformity machinery arrives for Annex III systems in December 2027. Each wave demands the same thing in a different shape: documents that exist, say true things about your product, and can be handed over when asked.

There’s a second force pushing in the same direction, and for most young companies it bites first: enterprise procurement. Buyers now send AI-governance questionnaires before they send contracts. “Do you have a risk-management framework? Who provides human oversight? Show us your model documentation.” A missing answer doesn’t get you fined — it gets you dropped from the vendor shortlist. Good governance has quietly become a sales prerequisite, not just a compliance one.

This service builds the artifacts themselves. Not a memo about what you need — the actual frameworks, policies, notices and documentation, written for your product, in the shape the Act names.

The artifact inventory: what the Act actually asks you to have

The AI Act is unusually concrete about paperwork. For each governance artifact, there is an article that names it and a reader who will one day ask for it — a market-surveillance authority, a notified body, or an enterprise customer’s security team. This is the inventory we build from:

Art. 9

Risk-management system

A documented, continuously maintained process for identifying, estimating and mitigating the risks your system poses across its lifecycle — including reasonably foreseeable misuse. Not a one-off assessment: the Act requires it to be iterated and updated.

Art. 10

Data-governance documentation

For systems trained on data: how training, validation and testing datasets were chosen, their relevance and representativeness, and the measures taken to detect and mitigate bias.

Art. 11 · Annex IV

Technical documentation

The core dossier: system description, intended purpose, architecture, capabilities and limitations, performance metrics, and the records demonstrating conformity — drawn up before market placement and kept current.

Art. 12

Logging and record-keeping

Automatic event logging across the system’s lifetime, designed in, so that operation can be reconstructed after the fact.

Art. 13

Instructions for use

The transparency package for your deployers: what the system does, what it must not be used for, its accuracy limits and its human-oversight measures — so the people operating it can actually comply.

Art. 14

Human-oversight design

Documented measures that let humans understand, monitor, intervene in and override the system — who reviews what, when, and with what authority. Written to the standard high-risk systems require.

Art. 15

Accuracy, robustness and cybersecurity

The declared performance levels and the measures maintaining them, including resilience against attempts to manipulate the system.

Art. 17

Quality-management system

The umbrella: the documented processes that hold all of the above together, from design controls to post-market monitoring and serious-incident reporting.

LIVE NOWArt. 50

Article 50 transparency notices

The user-facing layer that just became mandatory: interaction disclosures (“you are talking to an AI”), machine-readable marking of AI-generated content, deepfake and public-interest-text labels, and the deployer notices for emotion recognition and biometric categorisation. The Commission’s Guidelines on Article 50 and the Code of Practice on Transparency of AI-Generated Content — confirmed adequate by the Commission and the AI Board — define what good looks like; we draft to that standard.

LIVE NOWArt. 53

GPAI model documentation

For teams building or fine-tuning models: the model documentation for the AI Office and downstream providers, the copyright policy, and the public training-content summary using the Commission’s template — with the GPAI Code of Practice as the recognised compliance route.

Arts. 26–27

Deployer-side governance

If you deploy high-risk AI rather than build it: use per instructions, assigned and trained human oversight, log retention, worker notification — and, for public-sector and certain private deployers, the fundamental-rights impact assessment.

LIVE NOWArt. 4

AI-literacy measures

Already in force, and almost universally forgotten: documented measures ensuring your staff have the AI literacy their roles require.

Deploying agents? See Compliance for AI Agents for the agent-specific control set.

Not every company needs every artifact — the set depends on your role (provider, deployer, GPAI provider, or several at once) and your system’s risk class. The first thing we do is establish which of these documents your product actually owes, and to whom.

Two codes of practice, one confusion worth clearing up

Since mid-2026 there are two EU codes of practice with similar names and different jobs, and buyers mix them up constantly.

GPAI Code of Practice

2025 · for general-purpose model providers

Covers general-purpose model providers — documentation to the AI Office and downstream providers, copyright, and safety for systemic-risk models. The recognised compliance route for Article 53 duties.

Code of Practice on Transparency of AI-Generated Content

June 2026 · adequacy confirmed · providers and deployers

Covers Article 50 — the marking and labelling of AI outputs, for providers and deployers alike.

Signing the transparency code is voluntary; the underlying Article 50 obligations are not — but the Commission has indicated that for signatories, enforcement will focus on adherence to the code, which is a materially more predictable posture. Whether signing makes sense for you is one of the questions this engagement answers.

What’s already law, and what’s coming — the honest timeline

2 Feb 2025
LIVE

Prohibited practices; AI-literacy duty (Article 4).

2 Aug 2025
LIVE

GPAI model obligations (legacy models: full compliance by 2 August 2027).

2 Aug 2026
LIVE

Article 50 transparency — interaction disclosure, content marking, deepfake and public-interest-text labelling, emotion-recognition and biometric-categorisation notices. One grace period: systems already on the market before 2 August 2026 have until 2 December 2026 for the machine-readable marking duty. No retroactive labelling of earlier content.

2 Dec 2027
AHEAD

High-risk obligations for Annex III systems (the full Articles 9–17 machinery, conformity assessment, registration).

2 Aug 2028
AHEAD

High-risk obligations for AI embedded in Annex I regulated products.

The pattern to notice: everything horizontal — prohibitions, literacy, GPAI, transparency — is already live. Only the high-risk conformity machinery is still ahead, and the documents it requires take months to build well. Companies that wait for the deadline discover the work was sequential.

Beyond the Act: the questionnaire layer

Enterprise customers rarely quote articles. They quote frameworks: ISO/IEC 42001 (the AI management-system standard) and the NIST AI Risk Management Framework. The artifacts above map onto both — a risk-management system under Article 9 is the spine of an ISO 42001 management system; human-oversight and documentation duties answer most of a NIST-aligned questionnaire. We build the documents once, structured so the same set answers the regulator, the auditor and the procurement questionnaire without triplicating the work.

EU AI ActISO/IEC 42001NIST AI RMFCustomer questionnaires

Our approach

1

Role and scope mapping

Which entity in your group is the provider, which the deployer, whether you’re a GPAI provider — and therefore which artifacts you owe, under which articles, by when.

2

Risk-management framework

The Article 9 system, built as a working process your team runs — identification, assessment, mitigation, review cadence — not a shelf document.

3

Human-oversight policy

Who reviews what, when, with what training and what authority to override — documented to the standard high-risk systems require, and usable today as the answer to every “human in the loop?” question a customer asks.

4

Transparency and disclosure notices

The Article 50 package written to the Commission’s Guidelines and the adequacy-confirmed Code of Practice: interaction disclosures, marking approach, deepfake and public-interest labels, deployer notices — fitted to your actual product surfaces.

5

Technical documentation scaffolding

Annex IV-shaped documentation, logging and record-keeping templates your engineers can maintain without a lawyer on call.

6

Model and GPAI documentation

For teams building or fine-tuning: model cards, training-data governance, the public training-content summary on the Commission’s template, and the downstream-provider information pack.

7

The living layer

Governance rots without maintenance. We wire the framework to Horizon, our regulatory-change monitoring, so when the guidelines, standards or deadlines move, you hear about it as a dated task — not as a surprise.

Who it’s for

AI product companies past the readiness stage

That need the actual artifacts, not another gap analysis.

Teams losing enterprise deals

Because they can’t answer a customer’s AI-governance questionnaire.

Providers of generative systems

Who just inherited Article 50 duties on 2 August 2026 and need the notices and marking approach settled — especially in-market systems facing the 2 December 2026 marking deadline.

Model builders and fine-tuners

With GPAI documentation obligations to the AI Office and downstream providers.

Deployers of high-risk AI

Banks, insurers, HR platforms, public-sector suppliers who carry Articles 26–27 duties and get asked about them in every audit.

FAQ

What’s the difference between this and a readiness assessment?

The readiness assessment tells you what you need. This builds it — the frameworks, policies, notices and documentation themselves, written for your product.

Do the new transparency rules really apply to us already?

If you provide or deploy an AI system that interacts with people or generates content for the EU market — very likely yes, since 2 August 2026. The obligations are horizontal: they don’t depend on being high-risk. One narrow grace period exists (machine-readable marking for systems already on the market, until 2 December 2026), and there’s no duty to label content generated before August 2026.

Should we sign the Transparency Code of Practice?

It’s voluntary, but the Commission and AI Board have confirmed it as an adequate compliance route, and enforcement for signatories is expected to focus on adherence to the code — a more predictable posture. Whether it fits depends on your product and marking capabilities; it’s one of the questions we answer in the engagement.

Our high-risk deadline moved to December 2027. Can this wait?

The high-risk machinery moved; nothing else did. Prohibitions, AI literacy, GPAI duties and Article 50 are live now. And the high-risk documents are sequential — inventory before classification, classification before technical files — so late starts compress badly. Building the horizontal layer now is also most of the head start on the high-risk layer.

Do early-stage startups need this?

Increasingly yes — and usually because of customers before regulators. Enterprise buyers won’t sign without governance answers. The set we build doubles as your questionnaire answer bank.

Can you document models we fine-tune rather than build from scratch?

Yes. Fine-tuning and integrating third-party models carries its own documentation and provider obligations — and in some configurations makes you a provider — which the kit covers.

Does this map to ISO 42001 or NIST AI RMF?

Deliberately. The artifacts are structured so the same documents serve the AI Act, an ISO/IEC 42001 management system and a NIST-aligned customer questionnaire — built once, answered three ways.

Build governance that holds up

The transparency layer is already law. The high-risk layer is on the clock. Book a 30-minute consultation and we’ll tell you exactly which artifacts your product owes — and build them.

Book a Consultation

Related solutions: Data Protection & GDPR for AI · Compliance for AI Agents

General information about the EU AI Act and related frameworks. It is not legal advice, and building these artifacts is not a guarantee of compliance.