Introduction
On 20 July 2026, the European Commission published the final Guidelines on the implementation of the transparency obligations under Article 50 of Regulation (EU) 2024/1689 (the “EU AI Act”).[1] Published less than two weeks before these obligations began to apply on 2 August 2026, the Guidelines provide practical direction for providers and deployers seeking to comply with the Act’s transparency requirements.
Complementing this guidance is the Commission’s Code of Practice on Transparency of AI-Generated Content (the “Code”), published on 10 June 2026.[2] Although neither document creates new legal obligations, non-compliance could create additional administrative burdens as entities that decide to comply through other means will have to demonstrate the adequacy of those measures to different market surveillance authorities. [1] Consequently, it is imperative for businesses, including UK and other non-EU organisations, to understand their obligations under the EU AI Act and the actionable steps required to ensure full compliance.
Article 50 Obligations
Article 50 imposes four distinct transparency obligations, engaging both providers and deployers of specific AI systems. Broadly, providers are responsible for designing AI systems so that transparency requirements are built into the technology itself, while deployers must ensure that individuals are appropriately informed when those systems are used in practice. The transparency rules target four distinct categories of AI use:
- Interactive AI systems (Article 50(1)): Providers of interactive AI tools intended to interact directly with natural persons, including chatbots, voice assistants, AI companions and agentic systems, must ensure that users are informed that they are interacting with an AI system no later than at first contact. The obligation does not apply where the artificial nature of the system is obvious from the circumstances and the context of use, although this exception has a very narrow interpretation.
- Synthetic content marking (Article 50(2)): Providers of generative AI systems must ensure that AI-generated audio, image, video or text is marked in a machine-readable format and can be identified as artificially generated or manipulated.
- Emotion recognition and biometric categorisation (Article 50(3)): Deployers of AI systems used for emotion recognition or biometric categorisation must inform natural persons that such systems are being used.
- Deepfakes and public-interest text (Article 50(4)): Deployers must clearly label deepfakes and AI-generated text published on matters of public interest, unless an exception applies. The disclosure obligation does not extend to AI-generated content that is used for the detection, prevention, or prosecution of criminal offences. In addition, for AI-generated or manipulated text, the disclosure obligation does not apply where the content has undergone significant human review or editorial control, and a natural person holds editorial responsibility for its publication.
What the Final Guidelines Clarify
While the legal obligations themselves remain unchanged, the Guidelines provide important clarification on several previously uncertain issues:
- Definition of deepfake: The Commission has retained a broad interpretation of what constitutes a deepfake. The concept extends to content that resembles an “existing” subject if the simulated person, object, place, or event which exists, can plausibly exist, or could plausibly have existed. The assessment of whether content “would falsely appear authentic” requires a holistic evaluation, taking into account audience composition, context, and the substantive message, with a lower threshold where that audience includes children or other vulnerable groups.
- Exceptions to marking: The Guidelines further clarify the distinction between content that requires marking and content that falls within an exception. AI-generated translations are now treated similarly to grammar corrections and minor stylistic edits, meaning that they may benefit from the editing exception. By contrast, AI-generated summaries and substantive rewrites generally remain subject to the marking requirement. The Commission also confirms that certain very short outputs, such as individual words, image captions and alt-text, fall outside the scope of Article 50 altogether.
- AI agents: For the first time, the Guidelines specifically address AI agents. Systems capable of interacting with natural persons in the execution of tasks such as making bookings, managing correspondence, or negotiating contracts, must be designed to disclose both their artificial nature and the identity of the person on whose behalf they act.
- No retroactive obligation: The Guidelines also clarify how the transparency obligations apply to content created before 2 August 2026. For deepfake image, audio and video, the relevant cut-off is the date of generation. As a result, content generated before that date does not need to be retrospectively labelled, although the Commission encourages organisations to do so where possible. Alternatively, for text published on matters of public interest, the relevant date is the date of publication, meaning that text generated before 2 August 2026 but published afterwards must still be labelled unless it falls within the editorial control exception.
Phased Implementation and the Digital Omnibus
On 24 July 2026, the Digital Omnibus was published, entering into force on 27 July 2026,[3] which imposed the final deadlines for providers and deployers of AI systems.[2] Generative AI systems which were already on the EU market before 2 August 2026 will benefit from a four-month transitional period for the marking obligation (Article 50(2)) until 2 December 2026. However, all other Article 50 obligations have applied from 2 August 2026 without transitional relief.
Enforcement
Enforcement falls to national market surveillance authorities, which manage compliance within individual EU member states, and the AI Office, which directly supervises general-purpose AI models and cross-border systemic risks. For EU institutions, agencies, and bodies acting as providers or deployers, enforcement falls to the European Data Protection Supervisor.
Penalties for non-compliance operate on a tiered system under Article 99 of the EU AI Act. Breaches of standard and transparency obligations under Article 50 may lead to penalties reaching up to €15 million or 3% of total worldwide annual turnover, whichever is higher. EU institutions, bodies, and agencies acting as providers or deployers face fines of up to €750,000.[4]
Furthermore, supplying incorrect, incomplete, or misleading information to authorities or notified bodies can trigger fines of up to €7.5 million or 1% of total worldwide annual turnover.
For small and medium-sized enterprises (SMEs) and startups, the regulation dictates that the lower of the percentage or fixed amount applies, whereas larger corporations are automatically subject to whichever number is higher.
Broader Regulatory Context and Extraterritoriality
Article 50 sits within the wider EU AI Act framework but is notable for its broad reach. Unlike the high-risk system provisions, it applies across sectors and business models to any organisation that uses AI for chatbots, content generation, or biometric analysis. Importantly, the obligations apply extraterritorially. Providers and deployers located outside the EU fall within the scope of Article 50 wherever their AI system’s output is used or foreseeably disseminated in the EU.
The final Guidelines clarify that use in the EU happens where the deployer itself foresees dissemination and use of the AI outputs in the EU, such as by directing or authorising distribution within the bloc. However, the Guidelines also suggest this occurs when a deployer posts deepfakes on the ‘globally accessible internet’, without requiring the platform or content to specifically target the EU market. Providers and deployers are not, however, expected to be caught by incidental, unforeseeable, or unauthorised downstream use that is outside their control. This interpretation makes it challenging to shield online content from Article 50(4) deepfake labelling requirements unless strict geo-blocking is applied to the EU market. Given the potential for significant penalties, companies should take a conservative approach to compliance where AI-generated content may reach EU audiences.
This will be of particular relevance to UK businesses deploying AI-generated content that reaches EU audiences, including through globally accessible online platforms. For these UK organisations, the obligations under the EU AI Act will operate independently of any future UK AI regulatory framework, which remains significantly under-developed. This means that compliance strategies must simultaneously account for two diverging but related regimes. While the lack of overarching AI legislation in the UK currently makes domestic compliance easier, companies operating across both regions must still navigate UK-specific frameworks. The Information Commissioner’s Office (ICO), the UK’s primary AI regulator, has published extensive guidance on AI and data protection, while other regulators have issued guidance addressing specific industry and sector concerns. Ultimately, cross-border businesses must follow these sector-specific UK rules whilst implementing robust EU compliance to avoid severe non-compliance fines.
Actionable Steps: To ensure compliance from the August and ahead of the 2 December 2026 deadlines, companies that fall under the scope of Article 50 should:
- identify AI systems that fall within any of the four Article 50 categories;
- determine whether these AI systems act as a provider, deployer, or both;
- review customer-facing interfaces to ensure that AI interactions are disclosed appropriately;
- assess whether synthetic content outputs require machine-readable marking;
- review processes for publishing AI-generated content on matters of public interest;
- update contracts with AI vendors, developers, and creative agencies;
- train relevant legal, compliance, marketing, and product teams; and
- maintain evidence that demonstrates compliance decisions in the event of regulatory scrutiny.
Conclusion
The Commission’s Guidelines arrive at the eleventh hour, and practical uncertainties remain — particularly around watermarking technology, the holistic deepfake assessment, and the territorial reach of Article 50(4). The Code of Practice provides a voluntary yet practically significant route to demonstrating compliance. Businesses that have not yet mapped their AI use cases against the four Article 50 scenarios, assessed their disclosure obligations, and reviewed vendor and creative agency contracts should do so urgently.
Please contact Jose Saras if you have any questions or concerns regarding the above.
The material in this article is only for general review of the topics covered and does not constitute legal advice. No legal or business decision should be based on its content. This article is written in the English language. Preiskel & Co LLP is not responsible for any translation of all or part of its content into any language.
[1] European Commission, press release IP/26/1653, Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems, 20 July 2026 — ec.europa.eu/commission/presscorner/detail/en/ip_26_1653.
[2] European Commission, Code of Practice on Transparency of AI-Generated Content, 10 June 2026 — digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content.
[3] EU of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI), published in the Official Journal of the European Union on 24 July 2026 (OJ L, 2026/1744) and in force from 27 July 2026 — eur-lex.europa.eu/eli/reg/2026/1744/oj.
[4] European Commission, Quick Facts: Transparency rules for AI systems — digital-strategy.ec.europa.eu/en/factpages/quick-facts-transparency-rules-ai-systems.
[1] Code of Practice on Transparency of AI-Generated Content | Shaping Europe’s digital future
[2] AI Omnibus enters into force | Shaping Europe’s digital future