Skip to content
Frontier Tech

Article 50 [What It Changes]

Sep 2, 2026

TL;DR

  • Article 50 is the EU AI Act rule that, as of 2 August 2026, requires chatbots and other systems that talk to people to say they are AI, and requires certain AI-generated content to be marked or labelled.

  • The Digital Omnibus delayed high-risk paperwork; it did not delay Article 50. A narrow grace period to 2 December 2026 covers only machine-readable marking for generative systems already on the market before 2 August.

  • Fines for Article 50 sit in the Act's middle band: up to €15 million or 3% of worldwide annual turnover, whichever is higher, with a lower-of-the-two cap for SMEs.

  • A US-only shop is not automatically in scope, but a provider or deployer whose system is on the EU market or whose outputs are used in the EU is.

What Article 50 is

Article 50 is the transparency chapter of the EU Artificial Intelligence Act: if a system talks to a person, generates synthetic media, reads emotion or biometrics, or publishes AI-made public-interest text, someone in the chain must say so in a clear way.

That is not an enterprise-only story. A two-truck HVAC shop with a website chat that books emergency calls, a ten-person marketing agency that ships client social videos, and a solo clinic with an after-hours intake bot all sit closer to Article 50 than to Annex III high-risk classification. The job is operational: tell the caller they are talking to software, mark generated files before they leave the folder, and keep a human on anything that looks like a public statement.

As of 2 August 2026, those duties apply. The rest of this hub is the mechanism, the dates, the honest limits, and a single arithmetic check on how much time the remaining marking grace actually buys.

Why a small shop should care this week

If the HVAC dispatcher uses a voice agent to take after-hours calls from EU customers, the person on the line needs to know they are not talking to a technician. If the agency posts a product video that was generated or heavily altered, the deployer may need a visible label. If the clinic publishes an AI-drafted explainer on a health topic of public interest without a named editor, the text may need a disclosure.

None of those examples wait for a high-risk conformity assessment. They sit in Chapter IV. Teams that already route intake forms, call transcripts, and client files through US Tech Automations workflows can treat disclosure as a step on the same path: capture the interaction, stamp the label, park the exception for a person.

This is current as of 2 August 2026, the application date named by the European Commission.

What happened on 2 August 2026

According to the European Commission, 2 August 2026 is when the AI Office and national authorities began enforcing the Act and when new transparency rules started to apply. The same notice says chatbots and other interactive systems must tell users they are dealing with AI, deepfakes must be labelled, and AI-generated or altered content must carry machine-readable marks.

According to Cooley, €15 million or 3% of worldwide annual turnover, whichever is higher, is the fine band for noncompliance, and the Act reaches providers, deployers, importers, and distributors that place AI on the EU market or whose outputs are used in the Union. According to the same Cooley alert, providers of generative systems already on the market have until 2 December 2026 to finish marking and detection.

According to Goodwin, 2 December 2027 is the new date for standalone Annex III high-risk duties after Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. That delay is a different instrument; it is not a pause on Article 50.

The legal text of the original Act is Regulation (EU) 2024/1689, with the HTML Official Journal copy at OJ L 2024/1689. The delay instrument is Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026.

The four duties, in plain language

The AI Act Service Desk Article 50 page and Cooley's four-scenario map line up. Providers (the people who develop and place a system on the market) own two of the four. Deployers (the people who use a system under their own authority) own the other two.

DutyWho owns itStartNarrow exception
Tell a person they are talking to AIProvider2 Aug 2026Obvious from context; some law-enforcement systems
Machine-readable mark on synthetic audio, image, video, or textProvider2 Aug 2026Standard editing; systems already on market get until 2 Dec 2026
Inform people of emotion recognition or biometric categorisationDeployer2 Aug 2026Certain crime-prevention uses under other EU law
Disclose deepfakes and AI public-interest textDeployer2 Aug 2026Artistic works (limited); human editorial review with a named person

Sources: Article 50; Cooley; Goodwin.

The Commission's guidelines on transparency of AI-generated content were adopted to help providers, deployers, and competent authorities apply those duties. The guidelines landing page states they complement the Code of Practice and were developed with Member States, the AI Board, and a public consultation.

Article 50(5), as summarised on the Service Desk, requires the information to be clear, distinguishable, and accessible at the latest at the first interaction or exposure.

Fines and who enforces them

The Article 99 Service Desk page lists €15 million or 3% as the upper band that explicitly includes Article 50 transparency obligations at paragraph 4(g). The same article puts prohibited practices at €35 million or 7%, and misleading information to authorities at €7.5 million or 1%. For SMEs, including start-ups, each fine is the lower of the percentage or the amount.

Infringement bandAmount capTurnover capArticle 50 in this band?
Prohibited practices (Art. 5)€35,000,0007%No
Operator duties including Art. 50€15,000,0003%Yes
Incorrect information to authorities€7,500,0001%No
SME ruleLower of amount or %Lower of amount or %Yes, if the operator is an SME

Sources: Article 99; Cooley.

The guidelines page names national market surveillance authorities, the AI Office for systems under its supervision, and the European Data Protection Supervisor when EU institutions are providers or deployers. The Commission's 31 July notice also points to an AI Act complaints tool and a whistleblower tool.

The Code of Practice is voluntary. Article 50 is not.

The Code of Practice on Transparency of AI-generated Content is a voluntary path to show compliance with marking and labelling. It has two sections: providers (marking and detection) and deployers (deepfakes and public-interest text). The Commission and the AI Board have assessed it as adequate.

The Commission's 31 July 2026 signatory notice lists about 190 organisations signed by the end of July 2026. The same page lists 82 Section 1 signatories and 152 Section 2 signatories, and says about half of the signatories are small and recent companies. Named Section 1 examples include Anthropic, Google, Meta, Microsoft, Mistral, and OpenAI.

Signing reduces the burden of proving adequacy to each market surveillance authority. Not signing does not remove the legal duty. The Commission published a positive assessment of the code, hosts sign-up instructions, and posts the code PDF. The code also points to a set of EU icons for labelling AI-generated content.

Machine-readable marking is a technical problem as well as a legal one. The Coalition for Content Provenance and Authenticity publishes Content Credentials, an open standard for origin and edits of digital content. That standard is one industry path for marks; it is not a substitute for Article 50, and signing C2PA is not the same as signing the Code of Practice.

Timeline: what moved, what did not

The AI Act implementation timeline now includes Digital Omnibus amendments.

MilestoneDateWhat starts
AI Act entry into force1 Aug 2024Staggered clock begins
Prohibitions and literacy2 Feb 2025Article 5 bans; Article 4 literacy
GPAI rules and national authorities2 Aug 2025GPAI duties; Member State designations
Article 50 and general enforcement2 Aug 2026Transparency; national and EU enforcement of applicable rules
Art. 50(2) transition for legacy generative systems2 Dec 2026Marking for systems already on the market before 2 Aug 2026
New Article 5 bans on certain intimate and CSAM generation2 Dec 2026Separate prohibition track
National sandbox per country2 Aug 2027At least one sandbox operational
Annex III high-risk2 Dec 2027Standalone high-risk duties
Annex I product-embedded high-risk2 Aug 2028Product-safety-embedded AI

Sources: AI Act timeline; Commission Omnibus notice; lawandtechnology.eu.

According to Forkast, 16 months is the Annex III deferral from 2 August 2026 to 2 December 2027, and 9 of 27 EU Member States had fully designated national competent authorities as of June 2026. Forkast also cites a September 2024 Deloitte Legal Germany survey of 500 AI decision-makers in which 53.8% had taken zero compliance measures, and a February 2026 CSA finding that over 50% of organisations still lacked a systematic AI inventory. Those survey figures are Forkast's secondary report, not a Commission dataset.

lawandtechnology.eu records that Regulation (EU) 2026/1744 is dated 8 July 2026, published 24 July, and entered into force on 27 July, and that the marking grace was cut from six months to three months, landing on 2 December 2026.

USTA analysis

USTA analysis. Inputs, all cited above: Article 50 applies on 2 August 2026; the remaining marking grace for generative systems already on the market ends on 2 December 2026; Annex III high-risk duties now start on 2 December 2027.

Calendar arithmetic from those three dates:

  • 2 August 2026 → 2 December 2026 = 122 days of remaining marking grace for legacy generative systems.

  • 2 August 2026 → 2 December 2027 = 487 days until Annex III high-risk duties.

  • 487 − 122 = 365 extra days of high-risk paperwork delay after the marking grace is already gone.

A shop that treats "the Omnibus delayed AI rules" as a single pause is reading two clocks as one. Chatbot disclosure is already live. Machine-readable marks for systems that were already shipping have 122 days from 2 August. High-risk files have roughly a year more than that. The analysis does not invent a fine, a conversion rate, or a probability of enforcement; it only subtracts published dates.

What to do in the workflow, not in a memo

Map every system that talks to a person or emits a file. For a marketing agency, that is the client chatbot, the image generator, the video editor, and the public blog. For a clinic, that is the after-hours bot and any patient-facing summary that was not reviewed by a named clinician. For a trades shop, that is the booking bot and any AI-written estimate that goes to the customer.

Then split provider versus deployer. If you bought a hosted chatbot, the vendor is usually the provider for the "this is AI" notice, and you are the deployer for anything you publish. If you fine-tuned or wrapped a model and put it on your site, you may be the provider.

Put the disclosure on the first interaction, not in a footer after the quote. Keep the original customer message next to the labelled output so a reviewer can see both. Teams already routing documents through US Tech Automations can add a label field and a human-review queue on the same extraction path used for form-to-CRM automation, rather than standing up a second stack.

If the work looks like executive-assistant automation — inbox, calendar, draft replies — treat outbound drafts as deployer content until a person accepts editorial responsibility. The state of small-business automation is the same operational question: which step is software, and which step still needs a name on it.

Law practices comparing practice systems should read the same split into their intake bots; the comparison posts on Clio alternatives, Smokeball versus Clio, and MyCase versus Clio are about case workflow, not a substitute for Article 50.

Do not send a labelled deepfake or a public-interest AI text without a named reviewer if you intend to rely on the editorial-responsibility exception. The exception is not "someone glanced at it."

Honest limits

This hub does not claim the Act applies to every US-only shop. Scope follows the Act: placing on the EU market, putting into service, or producing output used in the Union.

Article 50 is not a ranking, a watermark brand, or a guarantee that a mark will survive every downstream crop. The Code of Practice is voluntary. The Commission's first list of Code signatories and the later "about 190" figure are snapshots, not a closed club.

High-risk duties, GPAI model duties, and the new 2 December 2026 prohibitions on certain intimate and CSAM-generating systems are neighbouring clocks. Mixing them into one "AI Act delay" sentence is the most common error in vendor emails this summer.

Signal vs Speculation

Signal (sourced). Article 50 applied on 2 August 2026. The Digital Omnibus delayed Annex III high-risk duties to 2 December 2027 and Annex I product-embedded high-risk duties to 2 August 2028. Marking for generative systems already on the market before 2 August has a 2 December 2026 deadline. Article 99 lists Article 50 in the €15 million / 3% band. About 190 organisations had signed the Code of Practice by the end of July 2026. Forkast reported 9 of 27 Member States fully designated competent authorities as of June 2026.

Speculation (our read). If those designation numbers hold, small deployers will meet national authorities that are still staffing, which usually means uneven first-year enforcement rather than a uniform fine wave. Our read: shops that put a one-line AI notice on the chatbot and a label on generated client files will be in a stronger position than shops that waited for high-risk templates. Our read is not a prediction of any fine amount against any named firm.

Over 12–36 months, expect more vendors to ship default "this is AI" banners and C2PA-style marks because the Code of Practice and the remaining 122-day marking window reward packaging, not because every small US site will be inspected. Treat vendor "AI Act compliant" badges as marketing until you can see which Article 50 paragraph they mean.

According to AICPA, 62% of firms reported cloud-workflow adoption.

According to Journal of Accountancy, the mid-market close still runs 8-10 business days.

According to Thomson Reuters, tax-prep utilization hits 85-95% in March and April.

According to NFIB, 44% of small businesses cite time-management. According to SBA Office of Advocacy, 33M+ small businesses sit in the 2025 profile. According to Goldman Sachs, 62% of SMBs reported workflow-tool ROI inside 12 months.

Key Takeaways

  • Article 50 is live as of 2 August 2026; the Omnibus did not move it.

  • Four duties, two roles: providers disclose interaction and mark generative output; deployers disclose emotion/biometric systems, deepfakes, and some public-interest text.

  • The remaining marking grace is 2 December 2026, and only for generative systems already on the market before 2 August.

  • Fine math for Article 50 is the €15 million / 3% band, with SMEs taking the lower of amount or percentage.

  • Put the label in the workflow that already handles the file or the chat, then keep a named person on anything public.

FAQ

Does Article 50 apply to a US company with no EU office?

Direct-answer first sentence: it can, if the system is on the EU market or the output is used in the Union. Cooley states the Act applies globally to providers, deployers, importers, and distributors in those conditions. A purely domestic US shop with no EU users is outside that fact pattern; do not assume either extreme without mapping where the chatbot or file actually goes.

Did the Digital Omnibus delay chatbot disclosure?

Direct-answer first sentence: no. Goodwin and the Commission both state that Article 50 stayed on 2 August 2026 while Annex III high-risk duties moved to 2 December 2027.

What is the 2 December 2026 date for?

Direct-answer first sentence: it is the end of the marking-and-detection transition for generative systems already on the market before 2 August 2026, and separately the start date for new Article 5 bans on certain intimate and CSAM-generating systems. It is not a new start date for chatbot disclosure.

Is the Code of Practice mandatory?

Direct-answer first sentence: no; Article 50 is mandatory and the code is a voluntary way to demonstrate marking and labelling. About 190 organisations had signed by the end of July 2026, See the Commission.

What if we only use AI to tidy grammar in a human-written email?

Direct-answer first sentence: standard editing that does not substantially alter the input can fall outside the generative marking duty. Article 50(2) as summarised on the Service Desk excludes assistive standard editing and non-substantial alterations. If the system writes the email from a prompt, treat it as generative until counsel says otherwise.

Who is the "deployer" when an agency runs a client's chatbot?

Direct-answer first sentence: the party using the system under its own authority is the deployer, and Cooley flags agency and contractor arrangements as a mapping problem. Write the contract so one named organisation owns the notice, the labels, and the editorial sign-off.

What to do next

Inventory the four Article 50 scenarios against every bot and every generated file that can reach an EU user. Put the disclosure on the first turn. Keep a named reviewer on public text. If you want that label-and-review step on the same path as intake and document routing, use the agentic workflow builder on the US Tech Automations homepage stack rather than a one-off compliance microsite.

About the Author

Garrett Mullins
Garrett Mullins
Workflow Specialist

Helping businesses leverage automation for operational efficiency.

See how AI agents fit your team

US Tech Automations builds and runs the AI agents that handle this work end to end, so your team doesn't have to.

View pricing & plans