Creuto is now an OpenAI Select Partner Read More
EU AI Act Article 50 has applied since 2 August 2026. Only systems already on the market get until 2 December. What to mark, and what it costs.

EU AI Act Article 50 has applied since 2 August 2026. If your product generates text, images, audio or video for users in the EU, the machine-readable marking duty is live today. The 2 December 2026 date in most coverage is not a general labelling deadline — it is a transition window for systems that were already on the market.
That distinction decides what you do this quarter. Teams reading "label AI content by 2 December" are planning a December sprint for an obligation that already binds them. Teams who shipped a generative feature before August have a narrower, more specific job: get Article 50(2) marking into an existing system within 62 days.
The official AI Act implementation timeline separates them cleanly.
| Date | Legal basis | What happens |
|---|---|---|
| 2 August 2026 | Article 113 | The remainder of the AI Act starts to apply unless specified otherwise. Article 50 transparency obligations bite for systems placed on the market from this date. |
| 2 December 2026 | Article 111(4) | Providers of AI systems, including GPAI systems, generating synthetic audio, image, video or text content that were placed on the market before 2 August 2026 must have taken the necessary steps to comply with Article 50(2) by this date. |
| 2 December 2026 | Article 113(a) | A separate obligation: the Article 5 prohibitions on AI systems that generate non-consensual intimate imagery and child sexual abuse material become applicable. |
Two things follow. First, the December date is scoped to Article 50(2) — machine-readable marking of synthetic output — and not to the rest of Article 50. The chatbot disclosure in Article 50(1), the deepfake disclosure in Article 50(4) and the timing rule in Article 50(5) have no grandfathering clause of their own. Second, the December date is scoped to systems already on sale. Ship something new in October and you inherit no grace period at all.
Article 50 is four obligations wearing one number. The text on the Commission's AI Act Service Desk splits them by who carries them.
Article 50(1) binds providers of systems that interact directly with people: users must be informed they are interacting with an AI system "unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect".
Article 50(2) is the one with the December date. Providers of systems "generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated", with technical solutions that are "effective, interoperable, robust and reliable as far as this is technically feasible".
Article 50(3) binds deployers of emotion recognition and biometric categorisation systems to tell exposed people the system is running. Article 50(4) binds deployers to disclose deepfakes, and to disclose AI-generated text "published with the purpose of informing the public on matters of public interest".
Note the split: 50(1) and 50(2) are design duties on whoever builds and ships the system. 50(3) and 50(4) are disclosure duties on whoever uses it. Most product teams are on both sides of that line at once.
This is where most compliance plans go wrong. Teams integrating a third-party model assume the model vendor carries Article 50(2) and they carry nothing. The Commission's guidelines of 20 July 2026 (C(2026) 5054 final) say otherwise.
A company provides a generative or interactive AI application (e.g. a chatbot, image generator, AI agent) on the Union market under its own name or trademark... The company is a provider responsible for compliance with the transparency obligations in Article 50(1) and/or (2) AI Act, regardless of whether the AI system is provided for free or for payment and regardless of whether the provider is established or located in the Union or in a third country.
Two consequences worth stating plainly. Building a chatbot in-house and putting it into service for your own staff under your own name makes you a provider. And taking someone else's generative system, modifying it — new training data, for instance — and putting it into service under your own trademark makes you the provider of the new system, without discharging the original provider.
Non-EU establishment is not a defence. The guidelines say the obligation holds regardless of where the provider sits, which is the usual extraterritorial reach when outputs land with people in the Union. If you are an Indian or UAE studio shipping a generative feature to European users, you are inside the scope. We treat that as a default assumption on every generative AI build that has European users, rather than something to establish case by case.
The guidelines set out four cumulative conditions for Article 50(2): the system qualifies as an AI system; it is capable of generating or manipulating synthetic content; the content is audio, image, video or text; and it falls into none of the exceptions.
Scope is wider than "an image generator". The guidance says Article 50(2) applies to narrow single-purpose generative systems, to multi-purpose and general-purpose systems, and expressly to "agentic AI systems, so long as they generate synthetic audio, image, video or text content". An agent that drafts customer emails generates synthetic text. So does a support bot that writes its own replies.
Open source is not a carve-out either. The guidelines state that providers and deployers of open-source AI systems within the scope of Article 50 "still need to ensure compliance with their respective transparency obligations". The free and open-source exemption elsewhere in the Act reaches components, not systems in Article 50 scope.
The Act names no technology. Recital 133, quoted in the Commission guidelines, gives examples: "watermarks, metadata identifications, cryptographic methods for proving provenance and authenticity of content, logging methods, fingerprints or other techniques, and a combination of such techniques". Providers may use one technique or several, so long as the overall solution is machine-readable and meets the effectiveness, interoperability, robustness and reliability test.
Three engineering points come out of the guidance that are easy to miss:
There is a proportionality valve. The guidance allows "less robust metadata markings" in narrowly defined cases where output is produced in a closed, technically controlled environment and is mainly instructive — its example is an AI system embedded in a vehicle navigation system, where the output cannot leave the product environment. That is a narrow door, not a general excuse.
The Code of Practice on Transparency of AI-generated Content was published on 10 June 2026 and the Commission and the AI Board confirmed it as an adequate voluntary tool for demonstrating compliance. Signing it is not required. Reading it is the cheapest way to see what the regulator considers state of the art.
Article 50(2) does not apply "to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof". Spell-check and auto-levels are out of scope. A feature that rewrites a paragraph in a different voice changes the semantics and is not.
Article 50(4) carries the exemption most people have heard of: where deepfake content "forms part of an evidently artistic, creative, satirical, fictional or analogous work", the duty is limited to disclosing its existence "in an appropriate manner that does not hamper the display or enjoyment of the work". For AI-generated text on matters of public interest there is a second exemption — where the content "has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication".
Both are deployer exemptions. Neither relieves the provider of the marking duty in 50(2). An artistic exemption at publication time does not mean your image generator may ship unmarked output.
Article 50 sits in the middle penalty tier. Article 99(4) covers infringements of Articles 16, 22, 23, 24, 25(2) and (4), 26, 31, 33, 34 and 50, and sets fines "up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of its total worldwide annual turnover for the preceding financial year, whichever is higher". The 7% tier above it is reserved for the Article 5 prohibitions.
Member States were required to lay down their penalty rules and notify them to the Commission by 2 August 2025, so the enforcement machinery predates the obligation. This is a live regime, not a consultation.
Stripped of the legal framing, this is a short engineering list. In the systems we build, it comes down to five changes.
None of this is large work. On a platform like the AI-powered sales training platform we built for Škoda Auto, with four AI-powered features across three platforms, the expensive part is not the marking itself — it is finding every path that produces generated content after the fact. Doing it at design time costs a day. Doing it as an audit costs a sprint.
On the same date, under Article 113(a), the Article 5 prohibitions on AI systems that generate non-consensual intimate imagery and child sexual abuse material become applicable. That is a prohibition, not a transparency duty, and it sits in the 7% penalty tier. It is not a labelling deadline and conflating the two produces exactly the muddle this post exists to clear up.
The useful frame here is the one we drew in our post on regulation that is law versus regulation that is still a proposal: Article 50 is in force, with dated application and a published penalty tier, which puts it in a different category from the frameworks still being drafted. Compliance posts about the AI Act age badly because people quote the proposals. Quote the timeline instead. Teams who worked through the DPDP consent manager rules will recognise the pattern: the engineering is small, the scoping is the work, and the date in the headline is usually not the date that binds you.
If you shipped a generative feature before August, the question to answer this week is not whether Article 50 applies. It is which of your features were on the market on 1 August 2026, because that list is the only one with 62 days left on it. Everything else was due two months ago. We build this kind of scoping into custom software delivery rather than bolting it on, and confirm the legal read with your own adviser before you rely on an exemption.
The remainder of the EU AI Act, including the Article 50 transparency obligations, started to apply on 2 August 2026 under Article 113. Any generative or interactive AI system you place on the EU market from that date carries those duties immediately, with no transition period of its own.
If you provide a system that generates synthetic audio, image, video or text, Article 50(2) requires the outputs to be marked in a machine-readable format and detectable as artificially generated. If you publish deepfakes or AI text on matters of public interest, Article 50(4) adds a visible disclosure duty.
Article 111(4) gives providers of systems generating synthetic content that were placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2). It covers machine-readable marking only, and only for systems already on sale before August.
The AI Act names no single technique. Recital 133 gives watermarks, metadata identifications, cryptographic provenance methods, logging methods and fingerprints as examples. Commission guidance of July 2026 lets providers combine several techniques, provided the overall solution is machine-readable, effective, interoperable, robust and reliable as far as is technically feasible.
Usually yes. Commission guidance says a company offering a chatbot, image generator or AI agent on the EU market under its own name or trademark is the provider responsible for Article 50(1) and 50(2), regardless of payment, and regardless of whether it is established outside the Union.
Article 99(4) places Article 50 infringements in the middle tier: administrative fines up to EUR 15,000,000 or, for an undertaking, up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. The 7% tier applies to prohibited practices under Article 5.
No. Commission guidance states that providers and deployers of open-source AI systems within the scope of Article 50 must still ensure compliance with their transparency obligations. The free and open-source carve-out covers components that are not themselves AI systems in scope.
Ready to take the first step towards unlocking opportunities, realizing goals, and embracing innovation? We're here and eager to connect.
11th Floor, O-Hub, Chandaka Industrial Estate, Infocity, Bhubaneswar, Odisha 751024
Level 4, 11 York Street Sydney Startup Hub Sydney, NSW – 2000
30 N. Đinh Nghệ, Phước Mỹ Sơn Trà, Đà Nẵng / Da Nang City – 550000
Level 25, AIDP Business Tower, Dubai Marina, United Arab Emirates
50 Beauchamp Street, Wellington, WGN 5028, New Zealand