
Blog Post
Article 50 Is Live: What You Have to Be Able to Produce
August 29, 2026
Coverage of the EU AI Act has largely moved on to 2027, because the high-risk obligations moved there. The transparency obligations did not move. Article 50 became enforceable on 2 August 2026, and the question worth asking now is not what it says but what an organization would have to produce if somebody asked today.
The Commission closed the interpretive questions before the deadline, publishing a Code of Practice on transparency of AI-generated content in June and finalized guidelines in July. What remains is operational, and most of it concerns records rather than technology.
Establish Which Role You Hold Per System
Article 50 attaches different duties to providers and deployers, and most organizations are both depending on the system. The obligations also attach to AI systems rather than to models, so building an application on a third-party model makes you a provider of that system.
Three obligations sit underneath, and they carry different deadlines. Disclosure that a person is interacting with an AI system falls on providers of interactive systems. Machine-readable marking of synthetic output falls on providers of generative systems. Labeling of published deepfakes and of AI-generated text on matters of public interest falls on deployers.
Only One of the Three Got a Deferral
The extension to 2 December 2026 applies to machine-readable marking for generative systems that were already on the market before August. It does not cover the deployer labeling duty, which has been live since 2 August with no grace period, and it does not cover anything placed on the market after that date. Organizations reading a December deadline into the whole article have misread the carve-out.
The Interaction Disclosure Has a Judgment Inside It
An interactive system has to inform people they are dealing with AI unless that is obvious from the circumstances. The exemption is reasonable and it transfers a decision onto the organization, because somebody has to determine that obviousness applies and be able to explain why later.

A chat window on a support page labeled as an assistant is one thing. The same model answering a phone line, or drafting replies a human sends under their own name, is considerably less certain. Recording the reasoning per surface, with the interface as it appeared and the date, converts a judgment into a defensible position. Nobody will accept a screenshot taken during the investigation.
Voice Is Where This Gets Uncomfortable
Synthetic voice on an inbound call has none of the visual cues that make a chat widget obvious, and the disclosure has to reach the person before the interaction proceeds rather than in terms nobody hears. Organizations running voice deployments should treat this as the first surface to document, and recording each deployment separately is what makes per-surface evidence possible.
Marking Is Achievable at Generation and Fragile Afterward
The marking obligation asks for output to be detectable as artificially generated, in a format described as effective, interoperable, robust and reliable. The Code of Practice points at content credentials and provenance metadata as satisfying that, alongside imperceptible watermarking.
The part that matters operationally is what happens after generation. Compression, re-encoding, resizing, cropping and platform upload all degrade watermarks, and screen capture removes provenance metadata entirely. A mark that survives the generator and not the publishing pipeline satisfies nothing at the point anybody looks.
Test the Mark Through the Real Path
The useful exercise is not implementing marking but verifying it end to end. Generate an asset, push it through the same resizing, format conversion and platform upload the real content takes, then attempt detection at the far end. Where the mark does not survive, that is a finding about the pipeline rather than the generator, and it is fixable.
Stripping a Mark Is Now Prohibited
The Code addresses deliberate removal explicitly, so a workflow that flattens metadata for file size or brand reasons has become a compliance question rather than a production preference. Worth checking with whoever owns the asset pipeline before somebody discovers it in an audit, since an examination samples rather than reads.
The Editorial Exemption Is an Evidence Obligation
AI-generated text published to inform the public on matters of public interest requires labeling, unless it underwent human review or editorial control. The exemption is the one most organizations will rely on, and relying on it means the review becomes the compliance artifact.

An unattributed claim that content was reviewed proves very little. A record naming the reviewer, the date and the version they saw proves the exemption applies. Where review is recorded as an attestation, the attestation data deserves examining on its own, since rates near one hundred percent across high volume describe either a disciplined team or a checkbox, and telling one from the other is a measurement rather than an assumption.
The Publication Date Creates a Live Backlog
The rules are not retroactive, so content generated and published before August needs no retrospective labeling. Public-interest text generated earlier and published on or after 2 August is a different matter, and may require a label unless the editorial exemption covers it. Any organization holding a scheduled content queue assembled before the deadline has an obligation attaching to material already written.
What You Would Have to Produce
Four artifacts answer the questions an authority or a customer would ask.
- A System List With Roles: Every AI system touching EU users, marked as provider or deployer, and which of the three obligations applies to each.
- Disclosure Evidence Per Surface: How the disclosure appeared, from when, and where the obviousness exemption was relied on instead with the reasoning recorded.
- Marking Verification Results: Detection tested through the real publication path, dated, rather than a vendor assurance that marking is enabled.
Review records for anything published under the editorial exemption complete the set, naming the reviewer and the version. All four share one property worth noticing, which is that each needs a date attached. The question is whether the control operated at the time of the interaction, and a current screenshot answers a different question. An audit trail that stores only the present state cannot support the claim.
The Penalty Figure Is Usually Quoted Wrong
Article 50 breaches carry administrative fines up to fifteen million euro or three percent of total worldwide annual turnover, whichever is higher. The figure appears in most coverage and it is not the applicable ceiling for every organization.
For small and medium enterprises the Act inverts the test, capping the fine at the lower of the two amounts. A company with two million in turnover therefore faces a materially smaller maximum than the headline suggests. Maximum penalties also are not automatic, with severity, duration, intent and cooperation all bearing on the outcome. Quoting fifteen million to an SME board overstates the exposure and tends to be discovered.
Where This Sits Against 2027
Treating the Act as a 2027 problem is understandable and incomplete. The high-risk obligations for Annex III systems now apply from December 2027, and the transparency obligations apply now, so an organization can be simultaneously early on one chapter and late on another.
The work also compounds usefully. A system list with roles recorded is the same list the high-risk classification will need, and disclosure records are the same kind of dated operational evidence a conformity assessment asks for. Building it for Article 50 today is cheaper than building it twice, and the revised timeline sets out what falls where.
Interoperable Detection Arrives in February
One further date is worth holding. Providers who signed the voluntary Code and use watermarking have until 2 February 2027 to implement an interoperability solution for watermark detection. The obligation follows from signing the Code rather than from the Act itself, which is a distinction worth establishing internally before anyone commits to it.
The Records Are the Deliverable
Article 50 has been enforceable for weeks, and almost none of what it requires is technology an organization does not have. Disclosure exists or it does not. Marking is enabled or it is not. What tends to be missing is the dated evidence that either was true at the time, the recorded reasoning where an exemption was relied on, and verification that a mark survives the pipeline it travels through. Kovrr's automated EU AI Act assessment tracks obligations article by article, which is the granularity this particular article requires.
To see which of your AI systems fall under Article 50 and what evidence exists for each, book a demo mapped to your own estate.
Article 50 Transparency FAQs
Speak to an ExpertIs EU AI Act Article 50 already in force?
Yes. The transparency obligations became enforceable on 2 August 2026, and they did not move when the high-risk provisions moved to 2027. The Commission also closed the interpretive questions beforehand, publishing a Code of Practice on transparency of AI-generated content in June 2026 and finalized guidelines in July. Only one part of the article received a deferral, being machine-readable marking for generative systems already on the market before August, which extends to 2 December 2026.
Which parts of Article 50 have no grace period?
The deployer labeling duty, covering published deepfakes and AI-generated text on matters of public interest, has been live since 2 August with no extension. The interaction disclosure obligation for providers of interactive systems is also live. The December 2026 deferral applies only to machine-readable marking for generative systems already on the market before August, and it does not cover anything placed on the market after that date. Reading a December deadline into the whole article misreads the carve-out.
What does the obviousness exemption require?
An interactive system must inform people they are dealing with AI unless that is obvious from the circumstances, which transfers a judgment onto the organization. Somebody has to determine that obviousness applies and be able to explain the reasoning later. A chat window labeled as an assistant is straightforward, while the same model answering a phone line or drafting replies a person sends under their own name is considerably less so. Recording the reasoning per surface, with the interface as it appeared and the date, is what makes the position defensible.
Does machine-readable marking survive publishing?
Frequently not, and that is the operational problem rather than implementing marking at all. Compression, re-encoding, resizing, cropping and platform upload all degrade watermarks, while screen capture removes provenance metadata entirely. The useful exercise is verification end to end, generating an asset, pushing it through the same conversions and uploads real content takes, then attempting detection at the far end. The Code also addresses deliberate removal explicitly, so workflows that flatten metadata for file size reasons have become a compliance question.
How does the editorial exemption for public-interest text work?
AI-generated text published to inform the public on matters of public interest requires labeling unless it underwent human review or editorial control. Relying on that exemption makes the review itself the compliance artifact, so an unattributed claim that content was reviewed proves little while a record naming the reviewer, the date and the version they saw proves the exemption applies. Where review is captured as an attestation, the attestation data deserves examining, since rates near one hundred percent across high volume are ambiguous.
What are the penalties for an Article 50 breach?
Administrative fines up to fifteen million euro or three percent of total worldwide annual turnover, whichever is higher. That figure is widely quoted and is not the applicable ceiling for everyone, because the Act inverts the test for small and medium enterprises and caps the fine at the lower of the two amounts. A company with two million in turnover therefore faces a materially smaller maximum. Maximum penalties are also not automatic, with severity, duration, intent and cooperation all bearing on the outcome.



