The EU AI Act transparency obligations under Article 50 apply from August 2, 2026 to every AI system on the EU market, regardless of when it was placed there. The European Commission confirmed enforcement by the AI Office and national authorities starts on the same date, with fines reaching EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. For small and medium companies, the lower of the two amounts applies.
The rules touch a wider circle of companies than the headlines suggest. If your product or internal tool includes a chatbot, an AI agent, or a feature generating text, images, audio or video, part of Article 50 applies to you, and your role, provider of the system or deployer using it, decides which duties land on you.
Most of the confusion comes from mixing two deadlines. The Digital Omnibus pushed high-risk obligations to 2027 and 2028, while the transparency obligations were not postponed by a single day, so some teams prepare documentation with no legal effect yet and leave the chatbot notice, in force since yesterday, for a future sprint.
The European Commission published its Guidelines on transparency obligations on July 20, 2026, non-binding but full of practical examples national authorities will work from. This post covers what applies from August 2, who must comply, where companies misjudge their role most often, and five compliance steps to work through without stopping development.
What applies from August 2, 2026, and what was postponed?
From August 2, 2026, the transparency obligations under Article 50 of Regulation (EU) 2024/1689 apply, together with the governance rules and the penalty framework. Regulation (EU) 2026/1744, known as the Digital Omnibus, postponed stand-alone high-risk systems under Annex III to December 2, 2027, and high-risk AI embedded in regulated products under Annex I to August 2, 2028.
The single transitional relief on transparency concerns machine-readable marking: generative systems placed on the market before August 2, 2026 have until December 2, 2026, while new systems comply from day one. Content published before August 2 needs no retroactive label, but older generated content you publish after this date must carry one.
Who must comply under Article 50?
Article 50 binds two groups of responsible actors, and the same company often holds both roles, for example when it develops its own generative system and produces content with it, so the obligations stack.
Providers
A provider is a natural or legal person developing an AI system, or having one developed, and placing it on the EU market or into service under its own name or trademark, for payment or free of charge. The place of establishment plays no part, the duties apply equally to companies based inside and outside the EU.
Deployers
A deployer is a natural or legal person using an AI system under its authority in a professional context. Employees acting under the employer's instructions and control don't count as a separate deployer, the duty stays with the company.
Who the obligations don't apply to
Out of scope are natural persons using AI purely for private, non-professional purposes, for example a student generating text for homework, and AI systems serving scientific research and development alone. The research exemption ends the moment the same system starts serving any purpose outside research.
What are the four transparency obligations under Article 50?
Two obligations fall on the provider, two on the deployer, and all four share the same horizontal rules on how and when the notice gets delivered.
Provider obligations
Interactive AI systems (Art. 50(1))
A chatbot, voice assistant or AI agent must tell the user they're talking to an AI system, at the latest during the first interaction. A notice hidden in the terms of use fails the test, and a label like "assistant" without naming AI isn't enough. The obviousness exception gets a narrow reading: a programming assistant available only to professional developers passes, a customer support chatbot on a public website does not.
Machine-readable marking of synthetic content (Art. 50(2))
Generated audio, images, video and text must be marked in a machine-readable format and detectable as artificially generated, through watermarks, metadata, cryptographic methods or fingerprints. Spelling fixes, color correction and similar standard editing sit outside the duty, while an AI summary or a paraphrase changing the structure and meaning of a text requires a mark.
Deployer obligations
Emotion recognition and biometric categorisation systems (Art. 50(3))
People exposed to such a system must receive a clear notice about its operation at the latest on first exposure, in writing, verbally or through a standardised icon, depending on the context.
Labeling deep fakes and certain text publications (Art. 50(4))
The obligation has two parts. A deep fake, meaning an image, video or audio clip resembling real people, places or events and appearing authentic, must carry a label visible or audible without technical tools, since a machine-readable mark alone isn't enough, and for evidently artistic and satirical works the label is allowed to be more discreet, for example in the closing credits.
The second part covers AI-generated or AI-modified text published to inform the public on politics, health, consumers or the economy. Such text must be disclosed, unless it passed genuine human review with editorial responsibility of a person or company whose identity and contact details are publicly available, where a superficial grammar check fails and any AI edit after approval revokes the exemption.
Horizontal requirements (Art. 50(5))
Every notice under paragraphs 1 to 4 must be noticeable, easy to understand and clearly separated from other content, delivered at the latest during the first interaction or on first exposure, with no hiding in the terms of use or menu layers. The accessibility requirements of Directives 2016/2102 and 2019/882 apply as well, and when children are part of the audience, the notice must be adapted to them.
When does an agency or its client become the provider?
Under Article 25 of the AI Act, a company placing its name or trademark on someone else's high-risk AI system, substantially modifying it, or changing its intended purpose so it becomes high-risk, takes over the full provider role, including technical documentation and conformity assessment. The original provider's documentation doesn't transfer with it.
The first trigger, rebranding, is transferable to the other side by written contract, the substantial modification and purpose change triggers are not. For companies ordering white-label solutions and agencies delivering them, this is the most expensive clause in the regulation, and it gets settled in the contract before development, because no code fixes it afterwards.
Why does Croatia's late implementation change nothing?
Croatia entered August 2026 without a designated market surveillance authority, even though the deadline expired on August 2, 2025, and its implementing law for Regulation (EU) 2024/1689 is still in preparation at the Ministry of Justice, Public Administration and Digital Transformation. Only the fundamental rights authorities under Article 77 are in place, among them the data protection agency AZOP and the Agency for Electronic Media.
The regulation applies directly in every member state, so a late national framework creates no grace period for companies, only uncertainty about which body knocks first and when. HUP's AI Coordination published a Croatian summary of the Guidelines in July, currently the most concrete domestic support for companies on this topic.
Per Eurostat, 20.0% of EU enterprises with at least 10 employees used AI in 2025, up from 13.5% a year earlier, with Croatia at 15.19%. Among medium enterprises the share is 30.4%, among large ones 55.0%, which means AI enters production at the fastest pace so far, right as the rules stop being an announcement. The first checks will target obvious gaps, a system with no notice and content with no metadata at all, and non-compliance shows up in client and investor due diligence questionnaires more and more often.
How do you comply with the EU AI Act transparency obligations in five steps?
For most companies, Article 50 compliance means a notice in the interface, a rule in the editorial process, metadata in the content generation pipeline, two clauses in the contracts and documented team training. The order below follows the ratio of risk to effort.
1. List your AI systems and assign roles
Build a list of every AI feature in production and on the roadmap, your own, purchased and API-embedded, and mark for each whether you're the provider, the deployer or both. The same list surfaces Article 25 exposure and shows whether anything falls under the high-risk cases of Annex III, such as AI in recruitment or credit scoring, where the 2027 and 2028 deadlines apply. For a team aware of what runs in production, this is an afternoon of work, and it decides every step after it.
2. Build the notice into the interface
A chatbot and an AI agent need a clear message during the first interaction, along the lines of the Guidelines example "You are interacting with an AI system", shaped by the horizontal requirements of paragraph 5. Voice agents deliver the notice as audio at the start of the call.
In a design system this is one component and one copy string. Any doubt about the obviousness exception is cheapest to settle by showing the notice, because the debate about what an average user finds obvious disappears with it.
3. Set up marking for generated content
The industry standard for machine-readable marking is C2PA Content Credentials, a specification developed by Adobe, Microsoft and the BBC and standardised as ISO/IEC 21694, combined with an invisible watermark such as Google's SynthID. The combination matters because a screenshot or a format conversion strips metadata, so the Code of Practice prescribes a multi-layer approach with logging, plus a provider duty to keep a detection tool available.
If you generate content through the APIs of the large providers, check whether they embed credentials already, since OpenAI, Google and Adobe do for part of their models, while for open source models like Stable Diffusion or FLUX you add the marks yourself through the c2pa SDK. Content created and consumed live, with no recording and no further distribution, is exempt from marking as long as users get a clear notice, which covers the typical voice agent on a call.
4. Define an editorial process for public-interest text
The paragraph 4 exemption asks for two cumulative conditions, genuine human review of the content and editorial responsibility with a publicly available identity and contact, so your process must prove both. In practice this means three rules in the editorial workflow: who checks the facts, who signs off on responsibility, and no AI tools touching the text after approval.
Product descriptions without health and safety claims stay out of scope, as does a summary a chatbot delivers only to the user who asked for it, while corporate reports aimed at investors are covered.
5. Fix the contracts, train the team and consider the Code of Practice
Write into every development contract with an AI component who the provider is, who holds the technical documentation and who reassesses the system if the intended purpose changes. The AI literacy duty under Article 4 has applied since February 2, 2025 and asks for proportionate, documented training for staff and external collaborators working with AI systems.
The Code of Practice on Transparency of AI-generated Content was published on June 10, 2026, and by the end of July around 190 organisations signed it, among them Google, Microsoft, OpenAI, Anthropic and Mistral, with roughly half being small companies. Signatories get legal certainty when proving compliance, while non-signatories prove it by other means and realistically receive more information requests from the authorities.
How we use this at Workspace
At Workspace we build internal tools and business systems where AI features increasingly sit next to work orders, documents and reports, so we treat transparency requirements as product requirements in the discovery and design phase, rather than a legal item before delivery. Role classification enters the project scope and the contract, the user notice is a component in the design system, and we pick models and APIs partly by whether they embed credentials in the output.
Serwizz, our CMMS product with AI features, went through the same procedure, with Workspace as both provider and deployer, exactly the dual case from the Guidelines where the obligations stack. For each AI feature we set the role, the interface notice and the treatment of generated content before it entered production, because retrofitting a live system costs more than one extra component in Figma.
For internal employee assistants, the Guidelines allow the obviousness exception when the team is trained and aware it's using AI, but we ship the notice anyway, since it costs one string and removes any debate with a future supervisory authority. For clients ordering solutions with an AI component we run a short assessment before the proposal: which features fall under Article 50, whether the project carries Article 25 risk, and whether the client needs an editorial process for published content. The assessment fits on one page and clears most surprises before the contract gets signed, and our post on AI-driven digital transformation describes the wider approach.
What comes next
The EU AI Act transparency obligations are a product requirement, cheapest to meet in design and most expensive to meet in production under supervision. The system list and the chatbot notice are realistically this week's work, the marking pipeline has a December 2, 2026 deadline, and the contract clauses go into the next amendment.
If you're building AI features into your tools or you're unsure which role you hold, a conversation about where to begin is a good first step. Reach out and walk your system list through with us on an intro call.



































