AI Act Article 50: what your compliant vendor does not cover
The transparency obligations in Article 50 of the EU AI Act have applied since 2 August 2026. The Commission adopted the final version of its guidelines on 20 July, less than two weeks before the obligations took effect, and confirmed the adequacy of the code of practice on transparency of AI-generated content, also endorsed by the AI Board. Fines reach β¬15 million or 3% of total worldwide annual turnover, with proportionality taken into account for SMEs and small mid-cap companies. Enforcement falls mainly to national market surveillance authorities.
The most common reflex in companies that do not build models is to treat this as largely the vendor's problem: the vendor has to mark its outputs, so buying from a compliant vendor settles the matter. The Commission's own FAQ closes that door explicitly, and in the opposite direction: deployers cannot simply rely on the machine-readable marking embedded in the content by the provider under Article 50(2) to fulfil their own disclosure obligation. The provider's marking addresses machines; your disclosure has to be perceivable by a person, without any specific technical tools or dedicated actions. These are two distinct obligations living on two different floors, and a faultless vendor covers exactly one of them.
The 15 July article on preparing for AI audits described the documentary machinery inspectors expect. What follows applies it to Article 50: who carries which obligation, where the exemptions sit and why the most sought-after one is narrower than it looks, and what matrix to maintain in order to be able to answer.

Provider, deployer, and the line between them
The regulation allocates obligations along a split that many organisations have not yet settled for themselves. A provider is whoever develops a system, or has it developed, and places it on the market or puts it into service under their own name or trademark, including from outside the Union as soon as the system's output is used in the Union. Providers carry the obligations in paragraphs 1, 2 and 5, to be met before placing on the market: informing people that they are interacting with an AI system, and marking the outputs of their generative systems in a machine-readable format that is effective, reliable, robust and interoperable.
A deployer is whoever uses the system under their own authority, excluding personal non-professional use. Deployers carry paragraphs 3 and 4: informing people exposed to emotion recognition or biometric categorisation systems, and clearly labelling deepfakes as well as AI-generated text published to inform the public on matters of public interest. Two clarifications from the Commission are worth noting, because they close escape routes one hears often. Employees acting on the instructions and under the control of a legal person are not separate deployers; the legal person is. And it remains the deployer when third parties, contractors or freelancers, operate the system on its behalf, under its responsibility and control.
An organisation can of course be both at once, and that is the common case as soon as an internal system is made available under the company's brand. The practical starting point is therefore not legal but documentary: for every system in production, someone has to have written down whether the company is a provider, a deployer, or both. The pattern that recurs in the field is that this classification exists nowhere, and gets decided under pressure the day an authority asks.
The exemptions, and the narrowest of them
Article 50 contains several legitimate exits, and it is better to know them precisely than to invoke them loosely.
The duty to disclose an AI interaction rests on four cumulative criteria: the system qualifies as an AI system, it is designed for a genuine two-way exchange rather than to collect data or return automated responses, the interaction is direct rather than mediated by a human, and it takes place with natural persons. Systems operating in the background or machine-to-machine fall outside. The exception for cases where it is obvious does exist, but the Commission asks that it be read restrictively, from the standpoint of an average person who is reasonably well-informed, circumspect and observant.
Marking of generative outputs has its own precise carve-outs: a short sequence of numbers, symbols or letters, source code, outputs intended exclusively for machine-to-machine communication with no human exposure, and outputs used in closed-loop industrial or product development environments, unless they are the final output. The obligation also does not apply where the system performs an assistive function for standard editing, a notion the guidelines illustrate with examples. A narrow exemption is further envisaged for business-to-business or industrial contexts, subject to conditions.
That leaves the exemption most management teams will want to use for their published content, human review or editorial control, and this is where the gap with existing practice is widest. The Commission defines human review as the deliberate examination of the substance of the content by one or more natural persons possessing relevant knowledge and professional judgement on the subject matter at hand. Editorial control requires a responsible editorial entity with the authority to approve, alter or reject the substance of the text on substantive grounds, including fact-checking and ensuring the trustworthiness of sources. Editorial responsibility further requires a person holding ultimate legal responsibility for the publication. And the text is explicit about what does not qualify: superficial, solely formal or procedural checks, spell-checking and grammatical correction in particular, are not human review. An approval workflow where somebody clicks approve is not editorial control, and yet that is what most AI-assisted publishing pipelines look like today.

The grace period is narrower than advertised
Some confusion is circulating about a general tolerance window. There isn't one. The Commission describes a limited grace period covering only systems placed on the market before 2 August 2026, and only for the marking and detectability obligation in Article 50(2). For those systems, and for that obligation alone, compliance is due from 2 December 2026. Everything else has applied since 2 August. Content generated before that date does not need retroactive labelling, though the Commission encourages it where possible.
Adhering to the code of practice on transparency of AI-generated content is the other decision variable. The code is voluntary and covers the marking and labelling obligations in paragraphs 2, 4 and 5. Signatories gain legal certainty and predictability regardless of where they are established or which supervisory authority is competent. Those who do not adhere must demonstrate compliance through alternative adequate means, and the Commission notes they may face more requests for information. That is not a penalty, it is a handling cost to anticipate, and the trade-off is better weighed now than at the first letter from an authority.
For the remaining obligations, notably paragraphs 1 and 3, each organisation determines its own compliance measures while taking the guidelines into account. That is the widest latitude in the whole scheme, and also the most exposed, since it rests entirely on the quality of what you will be able to show.
What to put in motion this week
List your exposed systems, chatbots, internal assistants, content generators, sentiment analysis tools, avatars, and for each write one line: provider, deployer, or both. Without that column, none of the obligations that follow can be assigned to anyone.
Build the system by obligation by evidence matrix. One row per system, one column per applicable paragraph of Article 50, and in each cell the artefact you retain: a capture of the disclosure screen at first contact, the technical specification of the marking, the visible notice on published content, the labelling procedure. Evidence is what is almost always missing, not compliance.
Check the human-facing disclosure layer specifically, separate from the vendor's marking. On published content that may fall under Article 50(4), the question is not whether the file carries a technical signature, but whether a reader sees a clear notice at first exposure.
Hold your editorial workflow up against the Commission's definition. Name the person carrying ultimate legal responsibility, describe the nature of the examination performed, and if it amounts to a check on form, either strengthen it or label the output.
Finally, settle the code of practice question with a written, dated decision. Signing or not signing is a defensible choice either way; not having decided is the only position that cannot be defended to an authority.
Conclusion
The trap in Article 50 is not its complexity; the text is short and the Commission has produced unusually clear documentation. It lies in a false intuition running through almost every organisation, that transparency comes bundled with the system. It is proven instead, system by system, in the terms of your own operations, and the two obligations that matter most to a deployer are covered by no vendor contract: making the disclosure perceivable to a person, and demonstrating that your human review actually is one.
Sources: As of July 2026
- [Primary] Transparency obligations under Article 50 of the AI Act (FAQ) β European Commission β updated 24 July 2026 β https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
- [Primary] Guidelines on transparency obligations for providers and deployers of certain AI systems β European Commission β 20 July 2026 β https://digital-strategy.ec.europa.eu/en/policies/guidelines-ai-transparency-obligations
- [Primary] Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems β European Commission β July 2026 β https://digital-strategy.ec.europa.eu/en/news/commission-publishes-guidelines-transparency-obligations-providers-and-deployers-certain-ai-systems
- [Primary] Article 50 β AI Act Service Desk, European Commission β 2026 β https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50
- [Primary] Code of Practice on Transparency of AI-generated content β European Commission β 2026 β https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
- [Secondary] European Commission adopts final Guidelines on AI Act Article 50 transparency obligations β Bird & Bird β July 2026 β https://www.twobirds.com/en/insights/2026/european-commission-adopts-final-guidelines-on-ai-act-article-50-transparency-obligations-first-impr
- [Secondary] EU AI Act β Commission Confirms Transparency Code of Practice as Adequate and Publishes Final Version of Its Guidelines on Transparency Obligations β Faegre Drinker Biddle & Reath β July 2026 β https://www.faegredrinker.com/en/insights/publications/2026/7/eu-ai-act-commission-confirms-transparency-code-of-practice-as-adequate-and-publishes-final-version-of-its-guidelines-on-transparency-obligations
- [Secondary] The AI Act's Transparency Obligations: Rules, Scope and Timeline β Stibbe β 2026 β https://www.stibbe.com/publications-and-insights/the-ai-acts-transparency-obligations-rules-scope-and-timeline
Comments ()