Category: AI Regulation | Reading time: 9 minutes

The half-truth that's circulating
In May 2026, the EU institutions reached provisional political agreement on the Digital Omnibus on AI, the first set of amendments to the AI Act since adoption. The headline that travelled was simple: the EU has delayed the AI Act.
That is true of one part and false of another, and the distinction matters enormously depending on what your organisation actually does with AI.
What moved: the high-risk obligations. Requirements for stand-alone Annex III systems, covering employment decisions, creditworthiness, education and essential services, were deferred from 2 August 2026 to 2 December 2027. High-risk AI embedded in regulated products under Annex I moved to 2 August 2028.
What did not move: Article 50. The transparency obligations apply from 2 August 2026, exactly as originally scheduled.
If you rebuilt your compliance calendar around "the AI Act is delayed until 2027," part of that calendar is wrong. And Article 50 catches a far wider population of organisations than the high-risk rules ever did, because it applies regardless of whether your system is classified high-risk.
An organisation with no high-risk AI whatsoever can still have substantial Article 50 obligations, because it runs a customer-facing chatbot, generates marketing imagery, or publishes AI-assisted content.
The timing has just sharpened. On 20 July 2026, thirteen days before the obligations apply, the European Commission published its final guidelines on Article 50.1 Anything you read about the "draft guidelines" from 8 May is now superseded.
What Article 50 actually requires
Article 50 of Regulation (EU) 2024/1689 imposes four distinct duties.2 They fall on different parties, and that allocation is where most of the practical difficulty sits.
1. Interactive AI systems must identify themselves (Article 50(1))
Falls on: the provider.
Any AI system designed to interact directly with people must be built so those people are explicitly informed they are dealing with an AI system.3 In practice, a clear notice at the start of the conversation ("You're chatting with an AI assistant") satisfies this.
There is an exception where the AI nature is obvious from context. It is narrower than it sounds: the test is calibrated to a reasonably well-informed, observant and circumspect member of the target audience. Treat it as a fallback you can argue, not a strategy you rely on.
2. Generative outputs must carry machine-readable marks (Article 50(2))
Falls on: the provider.
Providers of systems generating synthetic audio, image, video or text must add machine-readable marks enabling detection of AI-generated or manipulated content.3 The technical solutions must be effective, interoperable, robust and reliable as far as technically feasible, taking into account the state of the art and implementation costs.4
This is a provenance obligation, not a visible-label obligation. Compliance typically involves metadata tagging, watermarking, cryptographic provenance mechanisms or machine-readable audit logs.
This is also the one duty with breathing room. Systems already on the market before 2 August 2026 have until 2 December 2026 to meet the marking requirement. Note that the Omnibus compressed this grace period. The original proposal offered six months; the final agreement gave three.
Content already in circulation before 2 August 2026 does not need retrospective marking.
3. Emotion recognition and biometric categorisation require notice (Article 50(3))
Falls on: the deployer.
If you operate a system inferring emotions or categorising people biometrically, you must inform those subjected to it.3 Limited exemptions apply for law-enforcement uses authorised by law.
This catches more organisations than expected. Sentiment analysis on customer calls, attention monitoring, and some recruitment screening tools all potentially engage it.
4. Deepfakes and public-interest text must be labelled (Article 50(4))
Falls on: the deployer.
Where you publish image, audio or video content constituting a deepfake, you must disclose that it was artificially generated or manipulated. The Code of Practice defines a deepfake as content resembling existing persons, objects, places, entities or events which would falsely appear authentic or truthful.4
The definition is broader than most assume. The Commission's guidance treats content as capable of being a deepfake where it resembles something that could have existed, so a photorealistic image of a person who does not exist still qualifies. Clearly unrealistic content, such as fantasy scenes or things defying physics or biology, generally falls outside.
The obligation applies regardless of deceptive intent.
Article 50(4) also covers AI-generated or manipulated text published to inform the public on matters of public interest, unless the publication has undergone human review and is subject to editorial responsibility.4 That exception is doing significant work for anyone publishing AI-assisted content, and it is worth documenting your editorial process in order to rely on it.
The exceptions are narrower than the headlines suggest
Two carve-outs get cited constantly and misunderstood almost as often.
The artistic and satirical carve-out is not an exemption. For evidently artistic, creative, satirical or fictional works, the obligation is attenuated rather than eliminated. You still disclose, but in a manner that does not hamper display or enjoyment of the work. A notice at the start or end of a video, rather than a persistent watermark, would typically suffice.
Critically, this allowance excludes content primarily serving an informative or commercial purpose. An AI-generated deepfake of a celebrity in an advertisement cannot shelter under "it's creative."
The "obvious from context" exception uses two different tests. Under Article 50(1), obviousness is judged against a reasonably well-informed average member of the target audience. Under Article 50(4), the assessment must account for the actual composition of the exposed audience, including foreseeable exposure to children, older people, or audiences with lower digital and AI literacy. The second test is materially harder to satisfy.
Yes, this reaches UK organisations
The AI Act is extraterritorial, and the architecture will feel familiar to anyone who worked through GDPR. Geography of incorporation does not determine scope. Where your outputs land does.2
A UK organisation is caught where it places an AI system on the EU market, or where its AI system's output is used in the EU. Concretely:
A UK firm running a customer-service chatbot serving EU customers engages Article 50(1).
A UK marketing function generating synthetic content for EU campaigns engages Article 50(2), and where real people are depicted, the labelling duty in 50(4).
A UK professional services firm producing AI-generated client-facing documents for EU clients needs the same analysis.
Penalties for Article 50 breaches reach up to €15 million or 3% of global annual turnover, the tier below the €35 million and 7% band reserved for prohibited practices.
Who enforces it: national market surveillance authorities, the AI Office for systems under its supervision, and the European Data Protection Supervisor where EU institutions are the provider or deployer.3
The part most coverage misses: this is a contracts problem
Here is where the real work sits, and it is not where most organisations are looking.
The technology of labelling is largely solved. Watermarking tools exist. Disclosure banners are trivial. The genuinely hard question is who holds each duty at each link in your supply chain, because provider duties and deployer duties fall on different parties.
The Commission's guidelines clarify the notion of providers and deployers, setting expectations about which obligations apply to each stakeholder along the value chain.3 That is the section to read first.
Consider a common arrangement. You license a generative AI tool from a vendor. Your marketing agency uses it to produce campaign imagery. That imagery runs on your website, reaching EU customers.
Who is the provider? Who is the deployer? Who marks the output machine-readably, and who applies the visible label? If your contracts with vendor and agency are silent, you have an unallocated regulatory duty, and unallocated duties land on whoever the regulator can most easily identify.
Contracts signed before 2 August 2026 need to say which party holds each duty. That is a legal and procurement workstream, not an engineering one, and it takes longer than adding a banner to a chatbot.
There is a second reason this matters for regulated firms. The systems in scope rarely sit with your technical team. Customer-facing chatbots belong to operations. Synthetic marketing imagery belongs to marketing. AI-assisted client documents belong to fee earners. If your AI governance conversation happens exclusively in IT, the people holding these duties are not in the room.
The Code of Practice: a genuine shortcut
The Commission published the final Code of Practice on Transparency of AI-Generated Content on 10 June 2026, and the Commission and AI Board have confirmed it is an adequate voluntary tool for demonstrating compliance.5
The structure is straightforward. Section 1 covers provider obligations for marking and detection. Section 2 covers deployer obligations for labelling deepfakes and AI-generated text.5
The practical calculation is this. Adherence is voluntary, but the underlying Article 50 obligations are legal requirements either way.5 Providers and deployers who sign can rely on the code's measures to demonstrate compliance, reducing administrative burden and giving predictability across all Member States. Those who comply through other means must demonstrate those measures are adequate, assessed individually by different market surveillance authorities.5
For a UK firm without an EU compliance function, that difference is substantial. Signing gives you one recognised standard. Not signing means defending your approach separately to potentially several national regulators.
The EU has also published a set of icons deployers may use to label AI-generated content,6 which removes the design question entirely. The signatory form and instructions are published.7
One caution: signing is a commitment, not simply an administrative shortcut. Signatories collaborate in Signatory Taskforces and take on the code's specific measures. Worth a legal review before committing.
The UK overlay: no new law, same expectations
The UK has taken a deliberately different path. There is no single horizontal AI statute, but sector regulators apply existing duties to AI conduct. For regulated firms, that produces a stacked compliance picture rather than a simpler one.
Under SM&CR, accountability for AI-influenced outcomes sits with a named senior manager.8 Individual Conduct Rule 2 requires acting with due skill, care and diligence.9 "The model produced it" has never been a defence.
Under Consumer Duty, where AI makes or influences decisions affecting pricing, eligibility, service or complaint handling, the firm must demonstrate outcomes meet the Duty's standards.10 Consumer understanding is one of the four outcome areas, and whether a customer knows they are dealing with a machine is squarely a consumer understanding question, EU obligations or not.
Under UK GDPR, transparency duties operate independently of Article 50. Satisfying one does not discharge the other.11 A UK business serving EU users must clear both bars.
Even if you conclude you are outside the EU AI Act's scope entirely, the underlying conduct of telling people when they are dealing with AI, and keeping evidence of who approved what, maps onto expectations your existing regulator already holds.
What to do before 2 August
1. Inventory, scoped to disclosure. List every AI system that (a) interacts directly with people, (b) generates content you publish externally, or (c) infers emotion or biometric categories. Not all AI, only systems touching people or producing published output.
2. Determine EU exposure per system. Ask whether the outputs reach people in the EU. Not whether the vendor is European. Not where you are incorporated. Where the output lands.
3. Allocate roles in writing. For each system in scope, record whether you are provider, deployer, or both. Check what the contract says. Where it says nothing, close that gap before the deadline.
4. Fix the quick wins. Chatbot disclosure notices are a same-day change. Visible labelling on AI-generated imagery is a workflow change, not a technology project.
5. Decide on the Code of Practice. If you are a provider or deployer of generative AI systems with EU exposure, work through whether signing is the lower-burden route.7
6. Plan the slower work. Machine-readable marking requires technical integration, designed and validated rather than bolted on. Providers of generative systems already on the market have until 2 December 2026.
7. Keep the evidence. Who approved the system. What users are told. How it is monitored. Under SM&CR this is not optional, and it is the part organisations most often skip because it produces nothing visible.
What Article 50 does not do
It does not reclassify your system as high-risk. Transparency-only systems require disclosure, not conformity assessment, technical documentation or CE marking.
It does not create a general labelling rule for every internal AI-assisted document. The duties attach to systems interacting with people and content published externally.
It does not replace GDPR transparency obligations. It sits alongside them.
The bottom line
The delay everyone reported was real, but it applied to a different set of rules than the ones now arriving. Article 50 catches more organisations than the high-risk regime, reaches UK firms serving EU users, and turns on a question that lives in your contracts rather than your codebase: who holds which duty.
The organisations that will struggle are not the ones without watermarking technology. They are the ones that cannot say, for any given AI system, which named person is accountable for telling users it is AI.
References
Further reading
European Commission, Questions & Answers, Transparency obligations under Article 50 of the AI Act: https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
European Commission, Quick Facts: Transparency rules for AI systems: https://digital-strategy.ec.europa.eu/en/factpages/quick-facts-transparency-rules-ai-systems
European Commission, Market surveillance authorities under the AI Act: https://digital-strategy.ec.europa.eu/en/policies/market-surveillance-authorities-under-ai-act
Digital Omnibus on AI, Commission proposal COM(2025) 836: https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=celex:52025PC0836
This article is general guidance, not legal advice. Where the provider and deployer allocation is genuinely unclear for a specific system, that is a question for your legal counsel. You should be able to hand them a completed inventory and a clear question rather than a blank page.
Where does your organisation actually stand?
The SAFE™ AI Readiness Assessment scores you across ten governance domains, including accountability and human oversight, the two that Article 50 exposes most sharply. Under ten minutes, personalised maturity report.
Footnotes
European Commission, Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems, press release IP/26/1653, 20 July 2026: https://ec.europa.eu/commission/presscorner/detail/en/ip_26_1653 ↩
Regulation (EU) 2024/1689 (Artificial Intelligence Act), full text: https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng | Article 50 direct: https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50 ↩ ↩2
European Commission, Guidelines on Transparency of AI-Generated Content (policy page, last updated 20 July 2026): https://digital-strategy.ec.europa.eu/en/policies/guidelines-transparency-ai-generated-content | Full guidelines download: https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems ↩ ↩2 ↩3 ↩4 ↩5
European Commission, Code of Practice on Transparency of AI-Generated Content (policy page): https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content | Commission and AI Board adequacy opinion: https://digital-strategy.ec.europa.eu/en/library/commission-opinion-assessment-code-practice-transparency-ai-generated-content ↩ ↩2 ↩3 ↩4
European Commission, EU icons for labelling AI-generated content: https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content ↩
European Commission, How to sign the Code of Practice on transparency of AI-generated content: https://digital-strategy.ec.europa.eu/en/library/how-sign-code-practice-transparency-ai-generated-content | Q&A on signing: https://digital-strategy.ec.europa.eu/en/faqs/signing-code-practice-transparency-ai-generated-content ↩ ↩2
FCA, Senior Managers and Certification Regime: https://www.fca.org.uk/firms/senior-managers-certification-regime ↩
FCA Handbook, COCON 2.1.2R, Individual Conduct Rule 2 (due skill, care and diligence): https://www.handbook.fca.org.uk/handbook/COCON/2/1.html ↩
FCA Policy Statement PS22/9, A new Consumer Duty (PRIN 2A): https://www.fca.org.uk/publication/policy/ps22-9.pdf ↩
ICO, Guidance on AI and data protection: https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/ ↩