September 4, 2026

EU AI Act Article 50 Is Live: The Engineering Checklist

A
Abhijit
Aug 11, 20269 min read
EU AI Act Article 50 Is Live: The Engineering Checklist

Transparency obligations took effect on 2 August 2026. Here is what actually has to change in your product, and what the AI Omnibus moved out of the way.

Verified as of 12 August 2026. Regulatory timelines in this article changed twice in 2026. Re-check against the primary sources linked at the end before acting on any date.

This is technical analysis, not legal advice. Obligations depend on your role under the Act (provider, deployer, importer, distributor) and on your specific system.

What changed on 2 August 2026

Article 50 of the EU AI Act - Regulation (EU) 2024/1689 - became applicable on 2 August 2026. It is the transparency chapter, and it is the part of the Act most likely to require changes to code you have already shipped.

The European Commission adopted guidelines on these obligations on 20 July 2026, roughly two weeks before the deadline. If you built your compliance plan before then, it is worth re-reading.

Penalties for infringement of Article 50 fall under Article 99(4): up to €15 million or 3% of total worldwide annual turnover, whichever is higher.

The obligations that touch product code

Article 50 is narrower than "the AI Act applies to you now." Four obligations have direct engineering consequences.

1. Disclose that the user is talking to a machine

If your system interacts directly with people, those people must be informed they are interacting with an AI system - unless it is obvious to a reasonably well-informed person in the circumstances.

In practice this is a UI and copy problem, not an architecture problem. The failure mode we expect to see most often is a disclosure that exists on a marketing page but not in the interface where the conversation actually happens.

2. Mark synthetic content in machine-readable form

This is the obligation with real engineering weight. Providers of systems that generate synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated.

Two things follow:

  • Machine-readable is the operative phrase. A visible watermark or a caption is not sufficient on its own. The marking has to survive as metadata or as an embedded signal that a machine can read.
  • It applies at the point of generation. If you are a deployer consuming someone else's model through an API, you need to know whether the provider marks output, and what happens to that marking when your pipeline re-encodes, resizes or transcodes the asset. Re-encoding is where marking quietly dies.

If you generate media, audit your pipeline end to end and confirm the marking survives every transformation between the model and the user.

3. Label deepfakes and certain AI-generated text

Deployers of systems producing deep fake content must disclose that the content is artificially generated or manipulated. Similar disclosure applies to AI-generated or manipulated text published to inform the public on matters of public interest.

4. Notify people subject to emotion recognition or biometric categorisation

Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. This is a notice obligation layered on top of whatever data protection basis you already need.

The extension almost nobody has flagged

There is a grace period, and it is narrow.

Generative AI systems already placed on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement under Article 50(2). Systems placed on the market on or after 2 August 2026 are expected to comply from day one.

That distinction matters operationally. A feature you shipped in July has a runway. The same feature shipped in September does not.

What the AI Omnibus moved - and what it did not

This is the single most misread part of the current timeline.

The AI Omnibus was approved by the European Parliament on 16 June 2026 and received final Council approval on 29 June 2026. It pushed most high-risk system obligations back:

| Obligation set | Original date | Revised date | | :--- | :--- | :--- | | Article 50 transparency | 2 August 2026 | Unchanged - now live | | High-risk, standalone (Annex III) | 2 August 2026 | 2 December 2027 | | High-risk, embedded in regulated products (Annex I) | 2 August 2026 | 2 August 2028 |

Transparency arrived. High-risk slipped. Coverage that says "the AI Act was delayed" is describing the second row and ignoring the first. If you ship a generative feature into the EU, the row that applies to you today is the one that did not move.

For context on the phases already behind us: prohibited practices and AI literacy obligations became applicable in February 2025, and the rules covering general-purpose AI models began applying in August 2025.

A practical checklist

Work through this against each AI-touching surface in your product:

  • [ ] Classify your role. Provider, deployer, importer or distributor. The obligations differ and the Act is explicit about which attach to whom.
  • [ ] Inventory every generative output path. Text, image, audio, video. Include paths you inherited from a vendor SDK.
  • [ ] Test whether marking survives your pipeline. Generate, then run the asset through every transformation you apply, then check the marking is still readable.
  • [ ] Confirm what your model provider does. If you consume a third-party API, get a written answer on output marking rather than an assumption.
  • [ ] Audit disclosure placement. In the interface, at the point of interaction - not in a policy document.
  • [ ] Separate your pre- and post-2 August inventory. The 2 December 2026 extension only helps the former.
  • [ ] Check your emotion recognition and biometric surfaces. These carry notice obligations that are easy to miss because they often sit inside analytics rather than a user-facing feature.
  • [ ] Log your reasoning. Where you concluded an obligation does not apply, record why. That record is the artefact a regulator will ask for.

What is still genuinely unclear

Two areas where we would not assert confidence:

Technical standards for marking. Article 50(2) requires machine-readable marking and says it should be effective, interoperable, robust and reliable as far as technically feasible. The "as far as technically feasible" qualifier is doing significant work, and harmonised standards are still settling. Teams are making reasonable engineering choices that may need revisiting.

Interaction with regional model availability. Frontier model access is increasingly shaped by export controls - in June 2026 the US government applied controls to two of Anthropic's newest models, requiring access restrictions for foreign nationals. If your compliance posture depends on a specific provider's marking implementation, and your access to that provider changes, your compliance posture changes with it. We have not seen this addressed well anywhere.

Bottom line

Article 50 is live, it is enforceable, and its most demanding requirement - machine-readable marking that survives your own pipeline - is an engineering task rather than a policy one. The high-risk provisions that dominated 2025 planning have moved to late 2027 and 2028. Plan accordingly, and do not let the delay headlines convince you nothing applies today.


Primary sources

Share:
A

Abhijit

Founder & Editor-in-Chief

Founder & Editor-in-Chief at TechPari. Covering AI, cybersecurity, programming, and the tech that shapes tomorrow.

No Comments

Add Your Comment

Leave a Reply

Instagram

Visual Feed
Visual Feed
Visual Feed
Visual Feed
Visual Feed
Visual Feed