As of today, 2 August 2026, Article 50 of the EU AI Act applies. A chatbot serving anyone in the EU has to make clear it is a machine. A deepfake has to be disclosed. AI-generated text published to inform the public on matters of public interest has to say so, unless a human reviewed it and someone took editorial responsibility for it. Non-compliance sits in the €15 million or 3% of worldwide turnover tier, whichever is higher.

The part that did not arrive today is the one engineering teams have been building for. Machine-readable marking of synthetic output, Article 50(2), does not bind generative systems that were already on the market before today. Under the provisional agreement the Council and Parliament reached on 7 May, that obligation slides to 2 December 2026.

RelatedWeb Bot Auth: The IETF Standard to Verify AI Agents

What each paragraph actually requires

Article 50 splits along a line that matters more than the paragraph numbers: some duties fall on providers, meaning whoever builds and places the system on the market, and some fall on deployers, meaning whoever uses it. Getting this wrong in either direction is expensive, because a provider cannot discharge a deployer's duty by adding a disclosure to its docs, and a deployer cannot point at the model vendor.

  • 50(1), providers. Systems that interact directly with people must be built so users know they are dealing with AI, disclosed at the latest at the first interaction. The exception is where it would be obvious to a reasonably well-informed person, which is narrower than most product teams are assuming.
  • 50(2), providers. Synthetic audio, image, video and text must be marked in a machine-readable format and detectable as artificially generated. Assistive editing that does not substantially alter the input, grammar correction being the canonical example, is carved out.
  • 50(3), deployers. Anyone exposed to emotion recognition or biometric categorisation has to be told, in a clear and distinguishable manner. This is separate from the outright bans in Article 5 covering workplaces and schools.
  • 50(4), deployers. Deepfakes must be disclosed. AI-generated text published to inform the public on matters of public interest must be disclosed too, unless it went through substantive human review with assigned editorial responsibility.
Which Article 50 duties bind today and which slip to December A split diagram. On the left, obligations live from 2 August 2026: paragraph 50(1) requiring providers to make chatbots identify themselves, paragraph 50(3) requiring deployers to notify people subject to emotion recognition or biometric categorisation, and paragraph 50(4) requiring deployers to disclose deepfakes and AI-generated public-interest text. On the right, deferred to 2 December 2026: paragraph 50(2) machine-readable marking of synthetic content, but only for generative systems already placed on the market before 2 August 2026. A footer notes that new systems placed on the market from today are bound by 50(2) immediately, and that penalties reach fifteen million euro or three percent of worldwide turnover. EU AI ACT ARTICLE 50 · WHAT BINDS WHEN LIVE · 2 AUG 2026 DEFERRED · 2 DEC 2026 50(1) · providers chatbots must identify as machines at the latest on first interaction 50(3) · deployers notify on emotion recognition and biometric categorisation 50(4) · deployers disclose deepfakes and public-interest AI text 50(2) · providers machine-readable marking of synthetic audio, image, video, text deferred only for systems already on the market before 2 Aug 2026 new systems: bound today Penalty tier €15M or 3% turnover whichever is higher, Article 99 genztech.blog
Fig 1 The December deferral is narrow. It covers 50(2) only, and only for systems already on the market.

Why does the December carve-out matter so much?

Because it is the only obligation in Article 50 that requires real engineering rather than copy. Making a chatbot say it is a chatbot is a string. Watermarking every image, audio file, video and text output your model produces, in a format that survives re-encoding and that third parties can actually detect, is infrastructure. That is the work, and the systems most affected are the ones that shipped before anybody knew what the standard would look like.

Read the deferral precisely, though, because it is narrower than the relief people are hoping for. It applies to generative systems placed on the market before 2 August 2026. A model you launch tomorrow is bound by 50(2) immediately. A model you launched last year gets until 2 December. Every other paragraph of Article 50 binds today regardless of when the system shipped, and 50(4)'s deepfake disclosure duty is a deployer obligation that does not care about your model's release date at all.

  1. Aug 2024Regulation (EU) 2024/1689 enters into force phased application begins
  2. Feb 2025Prohibited practices apply Article 5, the €35M / 7% tier
  3. Aug 2025General-purpose AI model rules apply provider duties for GPAI
  4. May 7 2026Council and Parliament provisional agreement Digital Omnibus defers 50(2) for legacy systems
  5. Aug 2 2026Article 50 applies 50(1), 50(3) and 50(4) bind today
  6. Dec 2 202650(2) marking for legacy systems the deferral expires

What counts as adequate disclosure?

The guidance is unusually direct about what does not work. Burying the disclosure in terms and conditions is insufficient. A faint label is insufficient. A one-time approval click that the user scrolls past is insufficient. Disclosure has to arrive before or during first exposure, in a clear and distinguishable manner, and it has to meet applicable accessibility requirements, which rules out disclosure that exists only as an unlabelled visual element.

For artistic and satirical work there is a softer standard: disclose that the content exists as AI-generated, in a way that does not hamper the enjoyment of the work. That is the clause that lets a film use a synthetic performance without stamping a banner across every frame, and it is going to be argued over for years.

RelatedThe Anti-AI Browser Backlash Is Fueling DuckDuckGo's Surge

The editorial-review exemption in 50(4) is the one publishers should read twice. AI-generated text about matters of public interest is exempt from disclosure only where it "underwent substantive human review" and someone holds editorial responsibility for it. Both conditions, not either. A newsroom that runs drafts past an editor who signs off has a defensible position. A pipeline that publishes on a schedule with a spot check does not.

Our take

The chatbot rule will be complied with almost instantly and will change almost nothing, because most assistants already announce themselves and the ones that do not are mostly doing it deliberately. The marking rule is the one with teeth, and deferring it for legacy systems while binding new ones creates an odd incentive: for four months, the compliance cost of shipping a new generative model in Europe is strictly higher than the cost of continuing to run an old one. That is not what anybody intended and it is probably too small a window to distort much, but it is a real asymmetry.

The provision worth watching is 50(4)'s public-interest text clause, because it is the first regulation anywhere that puts a specific, auditable condition on AI-written journalism. Not a ban, not a labelling mandate in the abstract, but a named exemption you either qualify for or you do not. Publishers running generation pipelines now have a bright line to sit on one side of, and regulators have something concrete to ask about. Whether it gets enforced against anyone in the next year is a separate question, and the honest answer is that market-surveillance authorities across 27 member states are not obviously staffed for it yet.

What to watch · to December
  • The standardised EU label. A common mark across languages, "AI", "KI", "IA", is under development. Until it lands, machine-readable marking means whatever each provider decides it means.
  • First enforcement action. Which member state moves first, and against a chatbot disclosure or a marking failure, sets the tone for everything after.
  • Whether the December date holds. The Digital Omnibus already moved it once. A second slip is not unthinkable.
  • Detection interoperability. Marking is only useful if platforms can read each other's marks. Watch for cross-vendor detection commitments rather than vendor-specific schemes.
Primary sources

Original analysis by GenZTech. This is a summary of published regulatory text and official guidance, not legal advice.