Current as of 18 August 2026
On 2 August 2026, the EU AI Act crossed a line that matters more than any of its earlier milestones: the European Commission's AI Office and national authorities began actively enforcing the Act, and the Article 50 transparency obligations became applicable. For organisations whose AI system outputs are used in the Union — the statutory test, and one that captures many businesses headquartered in the UK, US and elsewhere — transparency is no longer a roadmap item. It is a live operational requirement with investigation powers behind it.
The commentary this summer has been dominated by one word: delayed. That framing is dangerously incomplete. Six days before the deadline, the EU did change the timeline — but it left the transparency regime fully intact, and it changed more than dates. This article sets out what is actually enforceable today, what the July amendments really did, and what to do in the next 30 days. Key legal claims are verified against primary EU sources, listed at the end.
The timeline — including what the Omnibus actually changed
The AI Act entered into force on 1 August 2024 and applies in phases. As of today, the accurate picture is:
- 2 February 2025 — the prohibitions on unacceptable-risk AI practices (Article 5) and the AI literacy duty (Article 4) began to apply.
- 2 August 2025 — obligations for providers of general-purpose AI (GPAI) models began to apply, alongside the governance and penalties framework.
- 27 July 2026 — the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force three days after publication in the Official Journal, amending the AI Act.
- 2 August 2026 — the Commission's AI Office and national authorities began enforcing the Act, and the Article 50 transparency obligations became applicable.
- 2 December 2026 — the machine-readable marking obligation (Article 50(2)) extends to generative AI systems already on the market before 2 August 2026, and new Article 5 prohibitions — covering AI-generated non-consensual intimate imagery and child sexual abuse material — begin to apply.
- 2 December 2027 — high-risk obligations for standalone Annex III systems (recruitment, credit scoring, biometrics and similar) apply.
- 2 August 2028 — high-risk obligations for AI embedded in regulated products (Annex I) apply.
The AI Act wasn't simply "delayed." The July Omnibus moved the high-risk deadlines out, created a four-month transition for existing generative AI systems under Article 50(2), rewrote the AI literacy obligation, added new prohibited practices and adjusted parts of the enforcement framework. Article 50 itself nevertheless became applicable, in full, on 2 August 2026.
The Article 4 change deserves a sentence of its own, because it is widely misreported as "unchanged." The Omnibus replaced Article 4 in its entirety: providers and deployers must now take measures to support the development of AI literacy among their staff, and the amended text expressly states that no specific level of literacy must be guaranteed for any individual. It is an obligation of effort, not of result — but it is still an obligation, and the regulator's question becomes the simpler and harder one: what measures did you actually take? For an organisation that has taken none, the softening changes nothing.
The practical consequence of the timeline overall: the Omnibus bought time for the heaviest compliance regime, but it bought no time at all for transparency. Anyone treating "the AI Act was delayed" as a general statement is exposed today.
Article 50: four obligations now live
Article 50 imposes transparency duties in four scenarios, split between providers (who develop and place AI systems on the market) and deployers (who use them under their own authority). Third-country providers are in scope where the output of their AI system is used in the Union — a deliberately broad test.
- Interactive AI systems (Article 50(1)). Providers must design systems that interact directly with people — chatbots, AI agents, voice assistants, avatars — so that individuals are informed they are dealing with AI, unless this is obvious to a reasonably well-informed, observant person. The Commission's guidance sets four cumulative criteria: it must be an AI system, designed for genuine two-way exchange, interacting directly (not through a human intermediary), and with natural persons. The disclosure must come no later than the start of the first interaction, in a clear and distinguishable manner, and in accordance with accessibility requirements. The "obviousness" exception is to be interpreted restrictively.
- Machine-readable marking of synthetic content (Article 50(2)). Providers of generative AI systems — including general-purpose AI systems — must ensure that synthetic audio, image, video and text outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, using solutions that are effective, reliable, robust and interoperable as far as technically feasible. Note the transition: systems already on the market before 2 August 2026 have until 2 December 2026 to comply with this specific obligation. New systems must comply immediately.
- Deepfake labelling and public-interest text (Article 50(4)). Deployers who generate or manipulate image, audio or video content constituting a deepfake must disclose this — and, as covered below, the disclosure must be one a human can actually perceive. AI-generated or manipulated text published to inform the public on matters of public interest must also be labelled, unless it has undergone genuine human review or editorial control with a person holding editorial responsibility. Content generated before 2 August 2026 does not require retroactive labelling, though the Commission encourages it.
- Emotion recognition and biometric categorisation (Article 50(3)). Deployers must inform natural persons exposed to these systems — whether the system operates in real time or ex-post — relevant to recruitment, customer analytics, security operations and access control, among others.
Non-compliance carries fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher, with proportionality available for SMEs and small mid-caps. Prohibited practices sit in a higher band (up to €35 million or 7%). The fine is not the only exposure: an organisation that cannot answer a regulator's information request quickly reveals weak ownership and weak records — which invites deeper scrutiny.
The overlooked details: exclusions, B2B contexts and human review
Most coverage stops at the four headline duties. The Commission's Guidelines, adopted on 20 July 2026, and the accompanying FAQ contain the detail that determines whether a given enterprise workflow is in scope at all. Four points matter most for enterprise environments:
Some outputs are out of scope entirely. The marking obligation does not cover short sequences of numbers, symbols or letters; source code; outputs communicated exclusively machine-to-machine and processed automatically without human exposure; or outputs used only within closed-loop industrial and product development environments (film production pipelines, for example) — unless they are the final output. Interactive-system disclosure likewise does not apply to systems operating solely in the background.
There is a narrow B2B/industrial exemption. The guidelines envisage a limited exemption from the marking obligation for AI systems generating outputs used in business-to-business or industrial contexts, subject to conditions set out in the guidelines. For enterprises embedding generative AI deep in internal toolchains, this is worth a careful scoping exercise — narrow does not mean negligible.
Standard editing is not generation. Where the AI performs an assistive function for standard editing — grammar correction, formatting — or does not substantially alter the input or its meaning, the marking obligation does not apply. The guidelines give worked examples of where assistance ends and generation begins.
Human review has a real threshold. The exemption for public-interest text requires deliberate examination of the substance by people with relevant knowledge and judgement, or control by a responsible editorial entity with authority to approve, alter or reject the content — with a person holding ultimate legal responsibility for publication. Spell-checking and procedural sign-off do not qualify. "Public interest" itself is broad: politics, public administration, justice, fundamental rights, public security, public health, environmental protection, consumer safety, and economic, financial, scientific or cultural developments relevant to public debate.
The operating implication: neither blanket assumption survives contact with the guidelines. "All AI-assisted content is exempt" is wrong; so is "everything needs a label." Build a repeatable classification test — what did the system generate or change, did it affect substance or meaning, was there genuine editorial control, is the context genuinely closed-loop or B2B — and log the decisions so you can prove them later.
Who is actually enforcing this
For Article 50, enforcement sits mainly with national market surveillance authorities in each Member State. The AI Office has a deliberately limited role: it is competent only where an AI system is built on a GPAI model provided by the same entity, or where the system is integrated into a very large online platform or search engine designated under the DSA. The European Data Protection Supervisor covers EU institutions.
This matters for multinationals. Article 50 exposure is not a single conversation with Brussels — it is potential contact with up to 27 national authorities, each with its own enforcement posture. Your evidence needs to work in any of those conversations.
The Code of Practice: the easiest evidential route — not a presumption of conformity
The AI Office's voluntary Code of Practice on Transparency of AI-Generated Content had been signed by around 190 organisations by the end of July. The Commission and the AI Board have assessed the Code as an adequate tool to demonstrate compliance with the marking and labelling obligations under Article 50(2), (4) and (5), giving signatories legal certainty and predictability regardless of where they are established or which authority supervises them.
Be precise about what that is and isn't. The Code does not confer a formal presumption of conformity. What it confers is an approved, EU-wide evidential route. Organisations that choose not to adhere must demonstrate compliance through alternative adequate means — and the Commission notes they may face more information requests, precisely because there is less visibility into how they comply. For most businesses, adopting the Code as a baseline and documenting any deviations is materially cheaper than defending an undocumented alternative in front of a national authority.
Watermarking and provenance are now architecture concerns
The two weeks since enforcement began have shown what Article 50 compliance looks like at the model level — and where its limits sit.
In mid-August, Anthropic confirmed — via a support page update on 11 August and a detailed technical explainer on 14 August — that Claude models launched on or after 2 August 2026 embed an invisible watermark in generated text, with signed C2PA provenance metadata attached to supported files. The approach is based on Google DeepMind's SynthID-Text technique: it biases low-stakes word choices during generation to leave a statistical pattern detectable with Anthropic's key. The markings apply worldwide, not only in the EU; older models are being brought into scope during the transition period, and a detection API is planned. Anthropic is explicit about the limits: light editing may leave the watermark intact, a substantial rewrite will likely remove it, a mark shows Claude was involved — not that Claude authored the content — and its absence proves nothing.
On 14 August, Google announced that users can now remove the visible watermark from Gemini-generated images, video and music — while the invisible SynthID watermark and C2PA metadata remain embedded, and the toggle is withheld in jurisdictions that mandate visible marks.
The two-layer transparency model
Read together, these developments and the Commission's guidance define a structure worth naming explicitly, because conflating the layers is where compliance programmes will fail:
The machine layer — watermarks, provenance metadata, detectability. This is the provider's Article 50(2) territory, and it is an engineering property of the content: it must survive export pipelines, CMS ingestion, compression, format conversion and API transformation as far as technically feasible.
The human layer — visible or audible disclosure where Article 50 requires it. This is largely the deployer's territory, and the Commission is explicit that it cannot be delegated to the machine layer: for deepfakes, deployers cannot simply rely on the machine-readable marking embedded by the provider to satisfy their disclosure obligation. The disclosure must be perceivable by a person — visible or audible — at first exposure at the latest, without special tools or dedicated actions.
The visible label is becoming a product-experience choice; the machine-readable layer is becoming the load-bearing detectability control. But neither layer substitutes for the other. An organisation can have perfect provenance metadata and still breach Article 50(4) because no human-facing label existed — or a prominent label and still breach Article 50(2) because the mark was stripped in its publishing pipeline. Both layers need owners, and both need testing.
A 30-day operating plan
The gap between a policy statement and operational evidence is where enforcement risk lives. Starting now: discover → classify → implement → prove.
Days 1–7 — discover the AI estate. Record every AI system that interacts with EU-based users, generates or manipulates content, performs emotion recognition or biometric categorisation, or relies on a third-party generative model. Capture provider, model, business owner, user population, content types and EU exposure.
Days 8–14 — classify roles and scope. For each system, determine whether you are provider, deployer, or both — and apply the scope tests: direct interaction with natural persons or background-only; generation or standard editing; closed-loop/B2B context or public exposure; human editorial control or automated publication. Then test every user-facing experience: does the chatbot identify itself from the first interaction, accessibly; are deepfakes carrying a perceivable label; are biometric and emotion-recognition notices visible?
Days 15–21 — implement and test transparency controls, including vendors. Require each generative AI vendor to state whether it has signed the Code of Practice, whether it is relying on the 2 December 2026 transition period, and to provide marking specifications, C2PA or equivalent metadata detail, detection capability and robustness evidence. Then test in your own channels: do marks survive your CMS, compression, document conversion, social publishing and API transformations?
Days 22–30 — prove it. Stand up an Article 50 control register, an escalation path for transparency incidents, evidence-retention rules, a decision log for scope classifications, and a quarterly report to the board or audit committee. Report exceptions in decision-grade language: affected systems, EU exposure, control weakness, owner, deadline, residual risk. Fold the amended Article 4 duty in here too: document the literacy measures you have taken — the obligation is effort-based, and undocumented effort is indistinguishable from none.
None of this requires waiting for the high-risk regime in 2027. It requires ownership, evidence and testing — now.
How Hexalink can help: Article 50 Readiness Review
Legal counsel answers what does the law require? The harder operational question — the one a market surveillance authority's information request actually tests — is can your organisation demonstrate that those requirements are operating?
That is where Hexalink works. Our EU AI Act Article 50 Readiness Review, delivered through our Compass AI governance advisory, moves an organisation through the sequence above: AI estate discovery, provider/deployer and scope classification, transparency control review, vendor and provenance testing, a gap register of factual observations with contextual benchmarks, and an executive readout in board-grade language. Compass assessments are grounded in the EU AI Act, NIST AI RMF and ISO/IEC 42001 — and in how the obligations actually operate, not how vendors summarise them. Where Article 50 raises wider resilience or assurance questions across your technology estate, our advisory services cover programme leadership and technical assurance in complex environments.
Hexalink provides AI governance, technology assurance and implementation advisory services. We do not provide legal advice, and we work alongside clients' legal and compliance teams where legal interpretation is required.
Disclaimer: This article provides general information based on sources available on 18 August 2026. It is not legal advice and does not determine whether any organisation, system or workflow is within scope of the EU AI Act. Obtain qualified legal advice for your circumstances and verify the applicable national requirements and enforcement position.
Sources
Primary EU sources
- Regulation (EU) 2026/1744 — Digital Omnibus on AI, Official Journal, 24 July 2026
- AI Act consolidated text as amended, 27 July 2026
- European Commission — Commission starts enforcing AI Act rules and new transparency requirements on 2 August (31 July 2026)
- European Commission — Guidelines on transparency obligations for providers and deployers of AI systems (adopted 20 July 2026)
- European Commission — FAQ: Transparency obligations under Article 50 of the AI Act
- European Commission — Quick Facts: Transparency rules for AI systems
- European Commission — Code of Practice on Transparency of AI-Generated Content
Industry and secondary sources
- Anthropic — How Claude's text watermarking works (14 August 2026)
- TechCrunch — Anthropic says it will watermark text generated by its AI models (11 August 2026)
- TechCrunch — Google will now allow users to remove visible watermark from its AI generations (14 August 2026)
- White & Case — EU AI Omnibus enters into force, amending the AI Act
- Cooley — EU AI Act: Transparency Obligations Take Effect 2 August 2026

