AI Act Transparency Requirements Apply From 2 August 2026. The Bigger Exposure Has Been Live Since February 2025.

Last updated: 14 July 2026

The AI Act transparency requirements in Article 50 apply from 2 August 2026. That is the date in every compliance calendar, and it is not the date most companies should be worried about. Article 4 and Article 5 of Regulation (EU) 2024/1689 have applied since 2 February 2025, they reach every AI system a company builds or uses rather than a labelled subset, and Article 5 carries the heaviest penalty tier in the regulation at 35 million euro or 7% of worldwide turnover. Article 50 gives you until 2 August 2026. Articles 4 and 5 stopped giving you time on 2 February 2025.

Article 50 is the deadline that survived the Omnibus intact. Where it sits against the dates that moved is in the AI Act compliance timeline.

The Transparency Duties Split Between Provider and Deployer, and the Split Decides Who Pays

Article 50 sets four disclosure duties. Two belong to the provider who builds or places the system on the market, and two belong to the deployer who puts it in front of people.

An AI policy that says only that the company will label its AI outputs has covered two of the four duties.

On the provider side, Article 50(1) requires that systems intended to interact directly with natural persons are designed so the person knows they are dealing with an AI system, unless that is obvious to someone “reasonably well-informed, observant and circumspect”. Article 50(2) requires that outputs of systems generating synthetic audio, image, video or text are marked in a machine-readable format and detectable as artificially generated. That duty is not confined to general-purpose models. A voice cloner, an image generator and a translation tool with a generative back end all sit inside it, with a carve-out for assistive editing that does not substantially alter the content or its semantics.

On the deployer side, Article 50(3) requires anyone operating an emotion recognition or biometric categorisation system to inform the people exposed to it. Article 50(4) requires deployers who generate or manipulate deepfake image, audio or video content to disclose it, with a lighter regime for evidently artistic, creative, satirical or fictional work, and an exception for AI-generated text published in the public interest where a human has reviewed it and someone holds editorial responsibility. Article 50(5) fixes the timing for all of it. Disclosure has to be clear, distinguishable, and made no later than the first interaction or exposure.

If you licence a model and deploy it, the marking and chatbot duties travel with your supplier. The emotion recognition and deepfake duties stay with you, and no procurement clause moves them.

Systems on the Market Before 2 August 2026 Get Until 2 December 2026. New Ones Mark From Day One.

The Digital Omnibus on AI pushes the machine-readable marking duty in Article 50(2) to 2 December 2026, but only for generative systems already placed on the market before 2 August 2026. Systems launched on or after 2 August 2026 get no transition at all.

If the Omnibus is published, ship in July and you buy four months. Ship in September and you mark from the first output. The extension is shorter than the six months the Commission originally proposed, and it is narrower than most summaries suggest, because it touches Article 50(2) alone. The chatbot duty in 50(1), the emotion recognition duty in 50(3) and the deepfake duty in 50(4) all apply from 2 August 2026 with no grandfathering.

The relief runs to whoever was already selling. A provider with a generative product on the market in July 2026 gets four months to build machine-readable marking into it. A competitor launching the same product in September builds it in before the first customer sees an output.

Which raises the question nobody has answered. A model released in 2025 and materially retrained in 2026 is either the same system placed on the market before the cutoff, or a new one that marks from day one, and the difference is four months of engineering. Ask your supplier which position they are taking and get it in writing, because it is their classification that lands on your outputs.

The transitional rule sits in a new Article 111(4) with recital 20 as its basis, not in Article 113, which is where several published analyses have put it. That distinction matters when you are citing your own compliance memo back to a supervisory authority.

The Omnibus Was Signed on 8 July 2026 and Was Not in the Official Journal on 14 July 2026

Every postponed date in this article becomes binding only when the Digital Omnibus on AI is published in the Official Journal. On 14 July 2026 it had not been. Until it is, the original AI Act deadlines are the legal reference and the extensions are drafting, not law.

The file is otherwise finished. The Commission proposed it on 19 November 2025, political agreement came on 6 and 7 May 2026, Parliament approved it on 16 June 2026 by 423 votes to 57 with 174 abstentions, and the Council gave final approval on 29 June 2026. The final act was signed on 8 July 2026 as LEX 00030/2026, and the Parliament’s procedure file still read “procedure completed, awaiting publication in Official Journal” a week later. It enters into force on the third day after publication, which means it has to appear by 30 July 2026 to be in force on 2 August.

The Union is racing to publish a regulation by 30 July 2026 whose purpose is to move 2 August 2026, and if it misses, 2 August 2026 stands. We keep the dates that survive each redraft in the EU compliance deadline tracker.

The same conditionality covers everything else the Omnibus does. Standalone Annex III high-risk obligations move to 2 December 2027 and embedded Annex I systems to 2 August 2028. A new prohibition on AI systems generating non-consensual intimate imagery and child sexual abuse material applies from 2 December 2026, and its sub-paragraph number in Article 5 is not worth citing until the published text is on EUR-Lex, because legal-linguistic revision re-letters things. None of it binds until publication.

Article 4 and Article 5 Have Applied Since 2 February 2025 and Sit in the 35 Million Euro Tier

Article 4 (AI literacy) and Article 5 (prohibited practices) have applied since 2 February 2025, per Article 113. Breaches of Article 5 attract fines of up to 35,000,000 euro or 7% of total worldwide annual turnover for the preceding financial year, whichever is higher, per Article 99(3). Penalty powers under Chapter XII have been available to national authorities since 2 August 2025.

This is where a 200-person company is most exposed, and it has nothing to do with labelling chatbots. Article 4 applies to providers and deployers alike, covers staff and “other persons dealing with the operation and use of AI systems on their behalf”, which pulls in contractors, and attaches to every AI system rather than to high-risk ones. The Commission’s AI literacy FAQ is the working reference. The Omnibus softens the wording to supporting and facilitating literacy rather than guaranteeing a level, which helps, once it is published.

The reason to care is not the fine. A company that never bought business licences has staff pasting draft contracts and customer records into free consumer accounts, and the resulting exposure is a GDPR problem that an Article 4 training record would have prevented. The AI Act asks whether you trained your people. Your data protection authority asks where the personal data went, and those two questions have the same root cause.

Article 5 lists eight prohibitions. Most of them describe practices an ordinary employer will not encounter. Untargeted facial scraping, predictive policing by profiling alone, social scoring, real-time remote biometric identification for law enforcement. Two reach into ordinary corporate systems. Article 5(1)(f) bans emotion recognition in the workplace and in education, and Article 5(1)(g) bans biometric categorisation used to infer race, political opinion, religious belief or sexual orientation.

A sentiment analysis feature bolted onto an HR platform has been prohibited since 2 February 2025, and it sits in the same fine bracket as social scoring.

Article 50 Breaches Sit in the 15 Million Euro Tier, and SMEs Are Capped at the Lower Figure

Transparency failures fall under Article 99(4), which sets fines of up to 15,000,000 euro or 3% of total worldwide annual turnover, whichever is higher. Supplying false, incomplete or misleading information to authorities falls under Article 99(5), at 7,500,000 euro or 1%.

Two numbers in wide circulation are wrong. Several published summaries print 1.5% for the information tier and 6% for the prohibited practices tier. The regulation says 1% and 7%. If your risk register was built from a secondary source, those are the two cells to check.

Article 99(6) then inverts the structure for small and medium enterprises, including start-ups, for whom each fine is capped at whichever of the amount or the percentage is lower. A start-up with 2 million euro of turnover faces a theoretical maximum of 140,000 euro under Article 99(3), not 35 million. In our assessment that is the provision that decides whether the number in your board pack survives contact with anyone who has read the Act.

The Commission’s Draft Article 50 Guidelines Run to Around 40 Pages and Bind Nobody

The Commission published draft guidelines on Article 50 through the AI Office on 8 May 2026, running to roughly 40 pages, with a consultation that closed on 3 June 2026. They are interpretive. They do not bind a court, and only the Court of Justice gives an authoritative reading of the Act.

That matters for how you use them. Guidelines are the best available signal of how the AI Office thinks the marking and disclosure duties should work in practice, and they are also the document a supervisory authority will have read. Our read is that following them is a defensible position and departing from them is one you should be able to explain in writing. Neither is a safe harbour. A separate Code of Practice on marking AI-generated content is where the technical detail behind Article 50(2) is being settled, on the same non-binding footing.

Article 50 Applies Whatever Your Risk Classification

Article 50 attaches to what a system does, not to where it sits in the risk pyramid. A minimal-risk customer chatbot and a high-risk recruitment tool both fall under it if they interact with people or generate synthetic content.

The inverse is true and worth stating before anyone starts writing policy. If you neither provide nor deploy a system that interacts directly with natural persons, generates synthetic audio, image, video or text, recognises emotion, categorises people biometrically or produces deepfakes, Article 50 does not reach you. Article 4 still does, because it applies to any use of any AI system.

One classification duty survived the Omnibus intact. Under Article 6(4), a provider who concludes that an Annex III system is not high-risk must document that assessment before placing the system on the market, and under Article 49(2) must register itself and the system in the public EU database anyway. The Commission proposed deleting this. Council and Parliament refused, and it stands with only the submitted information trimmed. Deciding you are not high-risk is still paperwork, filed publicly, and our read is that the drafters wanted exactly that friction. The AI Act Risk Classifier runs the Annex I and Annex III tests that put a system on one side of that line or the other.

The Work That Does Not Depend on the Official Journal

Nothing in the transparency regime rewards waiting for a published Omnibus text. The duties already in force, and the inventory work underneath them, can be closed before any postponed date lands.

Start with the population. List every AI system you build, deploy or procure, and flag the ones that interact directly with people or generate synthetic audio, image, video or text. That flagged set is your Article 50 exposure, and the risk classifier sorts the remainder against Annex I and Annex III.

The Article 5 sweep is narrower and more urgent than a full inventory. HR, recruitment, workplace monitoring, training platforms. Emotion recognition in those settings has been prohibited since 2 February 2025 and carries the 7% tier.

The Article 4 record is the third piece, and it has to cover the period from 2 February 2025 to be worth anything when an authority asks for it. The shadow AI audit belongs in the same exercise, because unlicensed consumer accounts are where the untrained staff and the leaked contracts meet.

Launch dates decide the marking question. Anything generative placed on the market on or after 2 August 2026 marks its output from day one. Anything already on the market has until 2 December 2026, conditional on publication in the Official Journal.

Contracts close the loop. Articles 50(1) and 50(2) sit with the provider. Articles 50(3) and 50(4) sit with the deployer, and that is you.

RegDossier

Making EU compliance almost enjoyable. Almost.

EU regulatory updates in your inbox every two weeks. Free.

Get the next briefing

Similar Posts