EU AI Act Weekly Radar: Article 50 guidance lands as the 2 August transparency deadline approaches
This week’s EU AI Act radar is dominated by the Commission’s Article 50 transparency package, with new guidance, Q&A, and code-signing details arriving just before the 2 August 2026 go-live date.
The biggest EU AI Act development this week is not a new prohibition, a new high-risk classification rule, or a fresh enforcement action. It is something more operational: the European Commission has now published a concentrated package of guidance on Article 50 transparency obligations just ahead of the 2 August 2026 application date.
For providers, deployers, product counsel, compliance leads, and governance teams, this matters because Article 50 is where the AI Act becomes highly visible in day-to-day user experience. It is about when people must be told they are interacting with AI, when AI-generated or manipulated content must be marked, and how organisations should think about responsibility when systems are built, embedded, branded, or used across multiple actors.
This week’s package also gives a clearer signal about the Commission’s implementation style: practical guidance first, role-mapping second, and evidence of compliance close behind.
The core development: the Commission published Article 50 guidance
The headline update came from the European Commission’s announcement, “Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems.” According to the Commission, the guidance was issued ahead of the 2 August 2026 go-live date and is intended to clarify who must comply, when user-facing AI interactions must be disclosed, and when AI-generated or manipulated content requires machine-readable marking or visible labelling.
That announcement is backed by the longer Commission text, “Guidelines on transparency obligations for providers and deployers of AI systems.” The fuller guidance says it is meant to support consistent and proportionate enforcement and covers:
- the scope of Article 50 obligations,
- relevant legal definitions,
- exceptions,
- practical examples, and
- ways providers and deployers can evidence compliance, including through the transparency code of practice.
For lextrace readers, that last point is especially important. The Commission is not only explaining the rule; it is also signalling the types of documentation and implementation choices organisations may need if they want to show that their controls are real, repeatable, and reviewable.
What the transparency rules appear to cover in practice
The Commission’s overview page, “Guidelines on Transparency of AI-Generated Content,” offers the most practical summary of the new guidance package.
Based on that overview, the Commission distinguishes between obligations that sit primarily with providers and obligations that sit with deployers.
Provider-side themes
The Commission says providers must address transparency where users interact directly with AI. It also states that providers must add machine-readable marks for AI-generated or manipulated content.
That makes the provider workstream look less like pure legal interpretation and more like product implementation. Teams may need to examine:
- interface disclosures for chat and assistant experiences,
- technical marking for generated or manipulated media,
- system design choices that affect whether users can reasonably tell they are dealing with AI, and
- documentation showing how these measures were implemented.
Deployer-side themes
The same Commission overview states that deployers must disclose:
- deepfakes,
- certain public-interest AI text, and
- use of emotion recognition or biometric categorisation tools.
That is a significant operational point. In many organisations, the deployer is not the model developer. It may be the employer, platform operator, publisher, service provider, or enterprise customer using an AI system under its own authority. This means Article 50 compliance may sit with business functions that do not think of themselves as “AI builders” at all.
The Q&A may be the most useful document for role-mapping
If the main guidelines explain the framework, the Commission’s FAQ, “Transparency obligations under Article 50 of the AI Act,” appears to do the harder practical work: identifying who is what.
The FAQ addresses:
- who counts as a provider or deployer,
- when obligations can apply to non-EU providers whose outputs are used in the EU, and
- how employee use under a company’s authority is treated for deployer analysis.
These clarifications matter because a large share of AI Act implementation risk is really role confusion risk.
An organisation may:
- build a model internally,
- fine-tune a third-party model,
- embed AI outputs into a branded customer workflow,
- let employees use a general AI tool inside internal operations, or
- distribute generated content through a platform or media channel.
The Commission’s Q&A suggests that Article 50 analysis cannot stop at “who trained the model.” Teams will need to map who provides, who deploys, who controls the user context, and where the output is used.
That is especially relevant for cross-border businesses. The FAQ’s reference to non-EU providers whose outputs are used in the EU indicates that geography alone will not remove Article 50 exposure where the EU use context is present.
A code of practice is available, but it is not the only route
Another notable update this week is the Commission FAQ, “Signing the Code of Practice on Transparency of AI-generated Content.” The Commission says that providers and deployers subject to Articles 50(2) and 50(4) can sign the transparency code and that initial signatories had to submit forms by 27 July 2026, 18:00 CEST, to be listed before the 2 August 2026 application date.
The same Commission material also states that non-signatories must show compliance by other adequate means.
That is an important message for governance planning:
- signing the code may be a useful compliance path for some organisations;
- it is not presented as the only lawful route; and
- whether or not an organisation signs, it still needs an evidentiary story.
In practice, that means the strategic choice is not simply “sign or don’t sign.” It is closer to:
- sign and align internal controls to the code,
- or do not sign and prepare alternative evidence that your transparency controls are adequate.
Either way, the Commission appears to be pushing organisations toward a more mature compliance posture than one-off disclosures or ad hoc product notices.
The deadline is close, but there is a limited timing nuance
The Commission’s “Quick Facts: Transparency rules for AI systems” highlights the central date again: 2 August 2026.
But it also notes a narrower transitional point. According to that Commission explainer, there is a grace period until December 2026 for the Article 50(2) marking obligation for certain generative AI systems placed on the market before 2 August 2026 under the AI Omnibus changes.
This does not look like a general delay to Article 50. It looks more like a targeted timing adjustment for a specific marking obligation affecting certain already-marketed generative AI systems.
For product and compliance teams, that means the timing analysis may need to separate:
- obligations that apply from 2 August 2026,
- obligations that may have a limited grace period in specific circumstances, and
- the factual question of whether a given system falls within that narrower pre-2 August placement scenario.
That timing distinction may be especially important for organisations with older generative AI deployments that are now being adapted, reskinned, or rolled into broader enterprise products.
Why this week matters beyond transparency
Even though this week’s documents are focused on Article 50, they tell us something wider about AI Act implementation.
1. The Commission is moving from text to operational interpretation
The guidance package does not change the AI Act itself. But it materially affects how teams are likely to interpret and implement it. In other words, the regulatory conversation is moving from what the law says to what compliance actually looks like in products, workflows, and evidence files.
2. Provider/deployer distinctions are becoming central
The Commission’s documents repeatedly return to the provider/deployer split. That suggests one of the main implementation challenges will be assigning obligations correctly across vendors, customers, employers, publishers, and other downstream actors.
This is relevant not only for transparency duties, but for broader AI governance design. Organisations that have not yet mapped AI roles across procurement, branding, system configuration, and operational use may find that Article 50 forces them to do so quickly.
3. Enforcement readiness is likely to depend on documentation, not just labels
The full guidance explicitly mentions how providers and deployers can evidence compliance. That is a strong signal that implementation is not just about showing a notice to the end user. It is also about retaining the internal basis for why the notice was used, when it was triggered, and which actor was responsible.
The CNIL’s agentic AI note is not an AI Act update, but it is a governance warning sign
Alongside the Commission package, France’s CNIL and the Council for AI and Digital published an exploratory note titled “IA agentique et données personnelles : la CNIL et le Conseil de l’IA et du Numérique publient une note exploratoire.”
According to the summary provided, the note flags:
- complex data flows,
- persistent memory,
- hyper-personalised profiling,
- distributed responsibility, and
- expanded cybersecurity risk when AI agents act across multiple connected services.
This is not presented here as new AI Act guidance. But it is still relevant to lextrace readers because it highlights the kind of governance complexity that transparency rules alone will not solve.
If AI systems become more agentic, questions about who is the deployer, who controls the user context, what content is generated or manipulated, and how responsibility is distributed across services may become harder, not easier. The CNIL note therefore reinforces the broader compliance trend visible in the Commission materials: AI governance is becoming more cross-functional and more evidence-driven.
What teams should take away this week
This week’s developments point to a short list of practical priorities.
Reassess role allocation
The Commission’s Article 50 FAQ makes clear that provider and deployer status is an operational question, not just a contractual label. Organisations should review who is acting under whose authority, who controls the user-facing deployment context, and whether outputs are used in the EU.
Review user-facing disclosures now
The Commission’s guidance package suggests that direct AI interaction disclosures, deepfake disclosures, and other visible transparency measures need to be ready for the 2 August 2026 date unless a specific limited timing exception applies.
Check marking and labelling workflows
For AI-generated or manipulated content, the distinction between machine-readable marking and visible labelling matters. Teams should understand which obligation fits which content and where responsibility sits across providers and deployers.
Decide whether to use the code of practice
The Commission’s code-signing FAQ gives organisations a compliance-path decision: sign the transparency code or prepare another adequate method for demonstrating compliance.
Treat Article 50 as a governance test, not just a UX task
The week’s materials suggest that transparency under the AI Act is not merely a front-end messaging issue. It touches product design, internal authority structures, vendor relationships, content workflows, and recordkeeping.
Bottom line
This week’s EU AI Act radar is dominated by one clear message: Article 50 implementation has entered its practical phase.
The Commission has now published a coordinated set of materials covering the rule itself, its scope, key role definitions, operational examples, a supporting Q&A, and a code-signing path. With the 2 August 2026 date approaching, the immediate compliance question for many organisations is no longer whether transparency obligations are relevant in principle. It is which obligations apply to which actor, in which use case, and what evidence will support that conclusion.
For lextrace readers, that makes this week less about headline politics and more about execution. The legal text is only the starting point; the hard part now is building a defensible operating model around it.
Citations
- [2]
- [3]Transparency obligations under Article 50 of the AI ActEuropean Commission
- [4]Guidelines on Transparency of AI-Generated ContentEuropean Commission
- [5]Signing the Code of Practice on Transparency of AI-generated ContentEuropean Commission
- [6]Quick Facts: Transparency rules for AI systemsEuropean Commission