Free tool
Where do you stand under the EU AI Act?
Article 50 transparency duties, Commission enforcement of GPAI model providers, and the fines that back them have applied since 2 August 2026, and the Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) did not defer them. Answer a short questionnaire and get a deterministic risk-tier classification — prohibited, high-risk, transparency, or minimal — with the exact obligations for your role, each with its deadline and article citation. Nothing you enter leaves your browser unless you ask for the emailed report.
By the Shieldra Compliance Team · Last updated July 2026
Key takeaways
- The check classifies across every tier — prohibited, high-risk (Annex I and III), transparency, and minimal — and scopes obligations to your role: provider duties are not deployer duties.
- Article 50 applies to AI systems placed on the EU market or used by EU users — it is not limited to high-risk systems.
- There are four duties: disclose AI interaction, mark AI-generated content machine-readably, disclose deep fakes, and notify people subject to emotion recognition or biometric categorisation.
- Penalties reach the greater of €15 million or 3% of total worldwide annual turnover.
- Watermarking applies from 2 August 2026 for new systems, and from 2 December 2026 for systems already on the market.
- The high-risk conformity regime is separate and was deferred by the Digital Omnibus (Regulation (EU) 2026/1744) to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
- The Omnibus also added two prohibitions — non-consensual intimate imagery and child sexual abuse material — that apply from 2 December 2026, and rewrote the Article 4 AI-literacy duty as an obligation of effort.
The four Article 50 transparency duties
Tell people they are interacting with AI
Providers must ensure people are informed they are interacting with an AI system, at or before the first interaction, unless that is obvious to a reasonably well-informed user. In practice this covers chatbots, assistants, copilots, and voice agents.
Mark AI-generated content machine-readably
Synthetic audio, image, video, and text must carry machine-readable markers so it is detectable as artificially generated. A visible label alone does not satisfy this — the marking has to be machine-readable.
Disclose deep fakes
Where output resembles real people, objects, places, or events and could falsely appear authentic, deployers must disclose that it has been artificially generated or manipulated.
Notify people subject to emotion recognition or biometric categorisation
People exposed to these systems must be informed that the system is operating, and the personal data involved must be processed in line with the GDPR.
What changed with the Digital Omnibus
The Digital Omnibus — adopted by Parliament on 16 June 2026 and Council on 29 June 2026, published as Regulation (EU) 2026/1744 on 24 July 2026, and in force since 27 July 2026 — deferred the high-risk regime: Annex III standalone high-risk systems moved to 2 December 2027, and Annex I embedded systems to 2 August 2028. The dates are fixed; the Commission's proposed standards-readiness trigger was dropped in negotiation.
It also added two prohibited practices to Article 5 — AI systems that generate non-consensual intimate imagery, and systems that generate child sexual abuse material — applying from 2 December 2026 at the €35 million / 7% penalty tier, and rewrote the Article 4 AI-literacy duty from ensuring a sufficient level to taking measures that support it.
It did not defer Article 50. Transparency obligations, Commission enforcement of GPAI model providers, and the fines for Article 50 breaches all took effect on 2 August 2026 as originally scheduled; the general Article 99 penalty regime has applied since 2 August 2025. The only Article 50 relief is a grace period to 2 December 2026 for machine-readable marking by systems already on the market (Article 111(4)). Describing this as "the EU delayed the AI Act" is imprecise, and it has left a lot of published guidance wrong.
Who this applies to
The Act reaches AI systems placed on the EU market or whose output is used in the EU, so a company with no EU entity can still be in scope through its EU users. Most teams discover this the same way: an enterprise customer sends a security questionnaire with AI governance questions attached, and the deal stalls until they can be answered.
Article 50 is also broader than the high-risk regime that gets most of the attention. It attaches to ordinary products — a support chatbot, an AI writing feature, a voice agent — not just systems in the Annex III list.
Frequently asked questions
Does Article 50 only apply to high-risk AI systems?
No. Article 50 transparency duties attach to AI systems that interact with people or generate synthetic content, regardless of risk classification. The high-risk regime in Chapter III is separate and was deferred to 2 December 2027 for Annex III standalone systems and 2 August 2028 for Annex I embedded systems.
When did Article 50 take effect?
2 August 2026, alongside Commission enforcement of GPAI model providers and the fines for Article 50 breaches. Watermarking of synthetic content applies from that date for systems placed on the market on or after it, and from 2 December 2026 for systems already on the market.
What are the penalties for an Article 50 breach?
Up to the greater of €15 million or 3% of total worldwide annual turnover.
Does the EU AI Act apply if my company is not in the EU?
It can. The Act applies to AI systems placed on the EU market or whose output is used in the EU, so a non-EU company with EU users can be in scope.
Is a visible "AI generated" label enough?
Not for the marking duty. Article 50(2) requires machine-readable markers embedded in the output so it is detectable as artificially generated. A visible label may help satisfy the separate deep-fake disclosure duty, but it does not replace machine-readable marking.
Did the Digital Omnibus delay the whole AI Act?
No, and that framing is a common mistake. It deferred the high-risk conformity obligations by sixteen months for Annex III systems and twelve months for Annex I systems. Article 50 transparency, GPAI enforcement powers, and the fine tiers were not deferred and have applied since 2 August 2026, and the Omnibus added two new prohibitions that apply from 2 December 2026.