Free tool
Are you meeting EU AI Act Article 50?
Article 50 transparency duties, GPAI enforcement powers, and the penalty regime have applied since 2 August 2026. Answer twelve questions and see which obligations attach to your product and which you are currently missing. Nothing you enter leaves your browser.
By the Shieldra Compliance Team · Last updated July 2026
Key takeaways
- Article 50 applies to AI systems placed on the EU market or used by EU users — it is not limited to high-risk systems.
- There are four duties: disclose AI interaction, mark AI-generated content machine-readably, disclose deep fakes, and notify people subject to emotion recognition or biometric categorisation.
- Penalties reach the greater of €15 million or 3% of total worldwide annual turnover.
- Watermarking applies from 2 August 2026 for new systems, and from 2 December 2026 for systems already on the market.
- The high-risk conformity regime is separate and was deferred to 2 December 2027 (Annex III) and 2 August 2028 (Annex I).
The four Article 50 transparency duties
Tell people they are interacting with AI
Providers must ensure people are informed they are interacting with an AI system, at or before the first interaction, unless that is obvious to a reasonably well-informed user. In practice this covers chatbots, assistants, copilots, and voice agents.
Mark AI-generated content machine-readably
Synthetic audio, image, video, and text must carry machine-readable markers so it is detectable as artificially generated. A visible label alone does not satisfy this — the marking has to be machine-readable.
Disclose deep fakes
Where output resembles real people, objects, places, or events and could falsely appear authentic, deployers must disclose that it has been artificially generated or manipulated.
Notify people subject to emotion recognition or biometric categorisation
People exposed to these systems must be informed that the system is operating, and the personal data involved must be processed in line with the GDPR.
What changed with the Digital Omnibus
The Digital Omnibus, adopted by Parliament on 16 June 2026 and Council on 29 June 2026, deferred the high-risk regime: Annex III standalone high-risk systems moved to 2 December 2027, and Annex I embedded systems to 2 August 2028.
It did not defer Article 50. Transparency obligations, GPAI enforcement powers, and the penalty regime all took effect on 2 August 2026 as originally scheduled. Describing this as "the EU delayed the AI Act" is imprecise, and it has left a lot of published guidance wrong.
Who this applies to
The Act reaches AI systems placed on the EU market or whose output is used in the EU, so a company with no EU entity can still be in scope through its EU users. Most teams discover this the same way: an enterprise customer sends a security questionnaire with AI governance questions attached, and the deal stalls until they can be answered.
Article 50 is also broader than the high-risk regime that gets most of the attention. It attaches to ordinary products — a support chatbot, an AI writing feature, a voice agent — not just systems in the Annex III list.
Frequently asked questions
Does Article 50 only apply to high-risk AI systems?
No. Article 50 transparency duties attach to AI systems that interact with people or generate synthetic content, regardless of risk classification. The high-risk regime in Chapter III is separate and was deferred to 2 December 2027 for Annex III standalone systems and 2 August 2028 for Annex I embedded systems.
When did Article 50 take effect?
2 August 2026, alongside GPAI enforcement powers and the penalty regime. Watermarking of synthetic content applies from that date for systems placed on the market on or after it, and from 2 December 2026 for systems already on the market.
What are the penalties for an Article 50 breach?
Up to the greater of €15 million or 3% of total worldwide annual turnover.
Does the EU AI Act apply if my company is not in the EU?
It can. The Act applies to AI systems placed on the EU market or whose output is used in the EU, so a non-EU company with EU users can be in scope.
Is a visible "AI generated" label enough?
Not for the marking duty. Article 50(2) requires machine-readable markers embedded in the output so it is detectable as artificially generated. A visible label may help satisfy the separate deep-fake disclosure duty, but it does not replace machine-readable marking.
Did the Digital Omnibus delay the whole AI Act?
No, and that framing is a common mistake. It deferred the high-risk conformity obligations by roughly sixteen months. Article 50 transparency, GPAI enforcement powers, and the penalty regime were not deferred and applied from 2 August 2026.