Last updated: 11 July 2026
Reading Time: 5 min read
With the 2 August 2026 enforcement date for the EU AI Act’s transparency obligations now immediately at hand, the European Commission has issued final non-binding guidelines to complement the previously released Code of Practice.
Designed to operationalise Article 50, these guidelines provide critical interpretive clarity on scope, AI agents, extraterritoriality, and watermarking exceptions.
Here is a practical breakdown of how the Commission’s updated guidance affects both providers and deployers preparing for compliance.
1. Summary of Article 50 Transparency Obligations
Article 50 divides compliance duties based on whether an organisation acts as an AI provider (developing or white-labelling a system) or an AI deployer (using a system within its business activities).
| Role | Key Requirement | Article |
|---|---|---|
| Provider | Ensure users are informed they are interacting with an AI system (unless obvious). | Art 50(1) |
| Provider | Embed machine-readable technical marks (watermarks) and detection mechanisms in AI-generated media. | Art 50(2) |
| Deployer | Inform natural persons when they are exposed to emotion recognition or biometric categorisation. | Art 50(3) |
| Deployer | Clearly label deepfakes and AI-generated public-interest text content. | Art 50(4) |
2. Key Clarifications in the Final Guidelines
The Commission’s guidelines resolve several ambiguities that previously challenged corporate legal and engineering teams:
Who Counts as a “Deployer”?
An organisation is only classified as a deployer if it uses an AI system under its own authority—meaning it retains control and decision-making over both the system’s deployment and operational outputs.
- Example: A company hiring a third-party marketing agency to produce an ad campaign—without dictating whether or how the agency uses generative AI—is not a deployer under Article 50. The agency retains deployer status.
Extraterritorial Limits & Unauthorized Use
Non-EU providers and deployers fall under the AI Act if their system outputs are used within the EU. However, the guidelines clarify that incidental, unforeseeable, or unauthorized downstream use of outputs within the EU does not automatically trigger liability.
Enterprise Tip: Licensing agreements and SaaS terms of use should explicitly define geographical usage boundaries to protect non-EU providers from accidental non-compliance.
AI Autonomous Agents Must Disclose Identity
The guidelines confirm that AI agents fall squarely within transparency rules. Conversational or autonomous agents must be designed to disclose:
- Their artificial nature (that the user is speaking with an AI).
- The identity of the legal or natural person on whose behalf the agent is acting.
Disclosures must occur at key decision-making steps, authorization checkpoints, and initial user touchpoints.
Cumulative Obligations
A single AI system can trigger multiple obligations across different roles. For instance, an enterprise chatbot that generates photorealistic avatar videos (deepfakes) and evaluates job candidate responses triggers Provider Interaction Disclosures (Art 50(1)), Provider Watermarking (Art 50(2)), Deployer Deepfake Labeling (Art 50(4)), and potentially High-Risk Governance Rules under Annex III.
Marking vs. Detection Rules
To fulfill Article 50(2), providers must not only apply technical watermarks or metadata tags to synthetic content—they must also ensure corresponding, human-readable detection tools exist to verify those marks.
Recognized Exemptions
- The “Obviousness” Threshold: Disclosures under Art 50(1) can be omitted if interaction with an AI is obvious to a “reasonably well-informed, observant, and circumspect” user. Regulators will construe this exception strictly.
- Excluded Content Types: Source code, simple machine-to-machine outputs, AI translations, spellcheckers, and basic standard photo editing tools (e.g., minor color adjustments) are exempt from watermarking duties.
3. Timeline & Next Steps for Compliance Teams
2 AUGUST 2026 2 DECEMBER 2026
│ │
▼ ▼
General Article 50 Rules Apply Grace Period Ends for Legacy
(Disclosures, Deepfakes, Biometrics) Model Machine-Readable Marking
- 2 August 2026: General transparency disclosures (Art 50(1), 50(3), and 50(4)) become active and enforceable.
- 2 December 2026: Extended grace period ends for pre-existing generative AI models to implement machine-readable technical watermarking (Art 50(2)).
Recommended Action Items
- Execute an Immediate Gap Analysis: Benchmark existing chatbots, AI tools, and synthetic content workflows against the Code of Practice and the final guidelines.
- Standardize User Interfaces: Replace vague notices (e.g., “This website uses AI”) with clear, contextual disclosures at the exact point of user interaction.
- Coordinate Vendor Integrations: Work with upstream foundation model providers to confirm that machine-readable marking and detection tools will be ready before the December grace period expires.