Explore Enzai’s full suite of AI governance products designed to help organizations manage, monitor, and scale AI with confidence. From structured intake and centralized AI inventories to automated assessments and real-time oversight, Enzai provides the building blocks to embed governance directly into everyday AI workflows—without slowing innovation.

Enzai

AI Regulations

EU AI Act Article 50: Final Guidance Is Here

AI Regulations

EU AI Act Article 50: Final Guidance Is Here

AI Regulations

EU AI Act Article 50: Final Guidance Is Here

The Commission published final EU AI Act Article 50 transparency guidance ahead of the 2 August 2026 deadline. Here is what changed and what to do now.

Belfast

Belfast

7 min read time

Topics

What changed

On 20 July 2026, the European Commission published its final Guidelines on the transparency obligations in Article 50 of the EU AI Act (Regulation (EU) 2024/1689). The 51-page document lands 13 days before those obligations become directly enforceable across all 27 member states, on 2 August 2026 (European Commission, Guidelines on transparency obligations).

This is not the Commission's first word on Article 50. A draft version went out for public consultation on 8 May 2026, and the final text differs from that draft in places that matter operationally, most notably on how far an AI system provider can rely on marking done upstream by a foundation model provider, versus having to implement and verify its own solution (Bird & Bird, first impressions).

The four things Article 50 actually requires

Article 50 is not one rule. It is four separate disclosure duties, and enterprise teams often treat it as a single "add a chatbot disclaimer" task when the scope is wider than that.

  • Article 50(1): providers of interactive AI systems (chatbots, voice assistants, anything a person talks to) must make the AI nature of the interaction clear, unless it is already obvious to a reasonably well-informed, observant and circumspect person. A narrow exemption applies to systems authorised by law for detecting, preventing, investigating or prosecuting crime, subject to safeguards.

  • Article 50(2): providers of systems that generate synthetic audio, image, video or text must mark that output as AI-generated or manipulated, in a machine-readable format. The Guidelines confirm this obligation sits with the AI system provider, who may rely on marking built in by an upstream model provider or a third-party tool, but must be able to show the solution is effective, interoperable, robust and reliable.

  • Article 50(3): deployers of emotion recognition or biometric categorisation systems must tell the people exposed to them.

  • Article 50(4): deployers publishing deepfakes, or AI-generated text on matters of public interest, must disclose the artificial origin of that content. Exemptions exist for evidently artistic, creative, satirical or fictional work, subject to appropriate safeguards, and for text that has gone through human review under editorial responsibility.

Penalties for non-compliance reach up to EUR 15 million or 3% of global annual turnover, whichever is higher, enforced by national market surveillance authorities (European Commission FAQ on Article 50).

The Code of Practice, and a deadline this week

Alongside the Guidelines sits a separate instrument: the Code of Practice on Transparency of AI-Generated Content, published in final form in June 2026 and assessed as adequate by the Commission on 9 July 2026. This is a distinct code from the General-Purpose AI Code of Practice that model providers signed in August 2025. It is aimed specifically at the marking and labelling duties in Article 50(2) and 50(4) (European Commission FAQ on signing the Code).

Signing gives an organisation a presumption of conformity with Article 50(2) and 50(4), which shifts the burden onto regulators, rather than the company, to show non-compliance. Organisations that submit a signature form by 27 July 2026, 18:00 CEST will appear on the initial published list of signatories, ahead of the Act's 2 August entry into application. Sign-up stays open after that on a rolling basis, but later signatories miss the initial list and, more importantly, go without the presumption of conformity until they are added.

What did not change

Two things keep getting conflated with this news, and both are worth correcting before they end up in a board deck.

The high-risk AI deadlines are still delayed, separately

Under the Digital Omnibus on AI, provisionally agreed by the Council and Parliament on 7 May 2026, the compliance deadline for high-risk AI systems (Articles 9-15: hiring, credit, education and similar use cases) moved from 2 August 2026 to 2 December 2027 for stand-alone systems, and to 2 August 2028 for AI embedded in regulated products (Council of the EU press release). That delay does not touch Article 50. Transparency obligations for chatbots, deepfakes and synthetic content stay on the original 2 August 2026 date. If your organisation's high-risk workstream was deprioritised because of the Omnibus delay, your transparency workstream should not have been.

The Guidelines are not binding law

The Commission is explicit that the Guidelines are non-binding. Only the Court of Justice of the EU can give an authoritative interpretation of the AI Act itself. In practice, national market surveillance authorities and the AI Office (where it holds exclusive competence) are expected to follow the Guidelines closely, so treat them as the de facto enforcement standard even though they carry no formal legal force of their own.

Marking text reliably is still an unsolved problem

The Guidelines do not resolve a real technical gap: robust, tamper-resistant machine-readable marking for AI-generated text remains limited, compared with image, audio and video watermarking. Do not assume a vendor claiming "Article 50(2) compliant" text marking has solved something the market has not yet solved. Ask them to show their method.

Five things to do this week

1. Build an Article 50 view of your inventory, separate from your risk-tier view

Your AI inventory almost certainly already tracks risk classification under the Act. Add an Article 50 flag to every entry: does this system talk to people (50(1)), generate synthetic content (50(2)), read emotion or biometric signals (50(3)), or produce deepfakes or public-interest text (50(4))? A well-maintained inventory turns this into a filtering exercise instead of a discovery project.

2. Decide on the Code of Practice before the window closes

Legal and product should jointly decide, this week, whether to sign. Signing buys a presumption of conformity on the marking and labelling obligations. Not signing is a legitimate choice, but it means carrying the full burden of proving your own approach is at least as effective, under closer scrutiny from national regulators from day one.

3. Test your chatbot disclosures against the "obvious" standard, not your own judgement

Article 50(1)'s exemption only applies where the AI nature of an interaction is obvious to a reasonably well-informed, observant and circumspect person, not where it is obvious to the team that built it. Have someone outside the project run through your customer-facing chatbots and voice interfaces and flag anywhere that is genuinely ambiguous.

4. Ask every GenAI vendor how they mark output, specifically

For any tool in your stack that generates images, audio, video or text, ask the vendor whether marking happens at the model level or the application level, whether it is machine-readable, and whether they can evidence it is robust and interoperable. The Guidelines put the verification burden on the AI system provider even where marking is inherited from upstream, so "our vendor handles that" is not a complete answer for your own compliance file.

5. Brief legal and comms on the deepfake definition now, not after an incident

Article 50(4)'s deepfake disclosure duty is broader than most non-lawyers assume. It is not limited to malicious fakes. AI-retouched staff photography, synthetic marketing imagery of real people, and AI-voiced ads can all fall inside the definition depending on how they are generated and used. Get legal and marketing aligned on what needs a disclosure label before the next piece of AI-touched creative goes out after 2 August.

Where Enzai helps

None of the five actions above need to be manual spreadsheet work. An inventory that tags systems by regulatory obligation, not just risk tier, turns step one into a report instead of a project. Enzai's AI Inventory gives every system a single record that carries its EU AI Act status, including Article 50 exposure, alongside its ISO 42001 and NIST AI RMF mappings, so the same data answers all three questions at once.

For teams tracking several frameworks in parallel, EU AI Act, ISO 42001, NIST AI RMF and a growing list of US state laws, Enzai's Compliance Frameworks map controls once and reuse them across every framework a system is in scope for, rather than re-running the same assessment per regulator. Our EU AI Act solution page has more detail on how that maps to the Act specifically.

For organisations already looking past chatbots to autonomous agents, the same Article 50 logic (does this system interact with people, generate content, or make decisions that need disclosure) is starting to extend into agentic systems, where transparency expectations are still being written. Enzai's agentic AI governance product applies the same inventory-and-control model to agents that take action, not just systems that generate content.

If you need working definitions for any of the above, our AI governance glossary has entries on Article 50, deepfake, presumption of conformity and compliance framework.

Join our Newsletter

By signing up, you agree to the Enzai Privacy Policy

Join our Newsletter

By signing up, you agree to the Enzai Privacy Policy

Join our Newsletter

By signing up, you agree to the Enzai Privacy Policy

Join our Newsletter

By signing up, you agree to the Enzai Privacy Policy

Compliance by Design

Compliance by Design

ISO 27001

Enzai is ISO 27001 certified, and has been since 2023. We commit to annual audits which are performed by NQA, and work closely with our security consultant partners Instil to continually update and enhance our security posture.

GDPR

ISO 27001

Enzai is ISO 27001 certified, and has been since 2023. We commit to annual audits which are performed by NQA, and work closely with our security consultant partners Instil to continually update and enhance our security posture.

GDPR

AI Governance

AI Governance

Infrastructure

Infrastructure

engineered for Trust.

engineered for Trust.

Empower your organization to adopt, govern, and monitor AI with enterprise-grade confidence. Built for regulated organizations operating at scale.

Seamlessly connect your existing systems, policies, and AI workflows — all in one unified platform.

Seamlessly connect your existing systems, policies, and AI workflows — all in one unified platform.