Article 50 applies on 2 August 2026, and your model vendor cannot carry it for you

Ulf Aslak Lai photo Ulf Aslak Lai Published 30 July 2026 Updated 27 August 2026 AI drafted 13 min read
Article 50 applies on 2 August 2026, and your model vendor cannot carry it for you

I spent an evening reading all 51 pages of the Commission's new Article 50 guidelines, which is not how I planned to spend it 1. They were adopted on 20 July, thirteen days before the rules they explain started to apply 2. One paragraph in the middle settles an argument I have had with three different founders this year, and it does not settle it the way any of us wanted.

Here is the short version. If your product has an AI feature, the law treats you as the one who has to tell users about it, even though the model belongs to OpenAI or Anthropic or Mistral. You are allowed to use whatever those vendors build to help you comply. You are not allowed to point at them when a regulator asks whether you did.

What applies since 2 August 2026?

Five rules, all of them in Article 50 itself 6. The first two sit on providers, the companies that ship an AI system. The next two sit on deployers, the companies that use one. A SaaS company running its own AI feature wears both hats, and most are caught by two or three of the five.

  • Tell users when they are talking to an AI. Chat, a support assistant, a voice agent, anything conversational. Article 50(1), a provider duty.
  • Mark generated content so a machine can detect it. Synthetic text, images, audio, video. Article 50(2), also on the provider. This is the only one that needs engineering rather than copy.
  • Tell people when you are reading emotions or sorting them by biometric traits. Article 50(3), a deployer duty. Rare in B2B SaaS, but if you score sentiment from faces or voices, it is you.
  • Label AI-written text you publish on matters of public interest, and label deepfakes. Article 50(4), also a deployer duty.
  • Deliver all of it clearly, at the first interaction. Not in a policy page someone opens three clicks later. Article 50(5).

There is an escape hatch in Article 50(1), and someone on your team will find it: the duty falls away when it is obvious to a reasonably well-informed person that they are dealing with an AI. The guidelines say that test "should be interpreted restrictively" 1. Six experiments with 4,600 participants by Jakesch, Hancock and Naaman found that people cannot reliably spot AI-generated text, and that the cues they trust misfire badly enough for machine text to read as more human than human. Do not build on it.

You may have read in June that the EU delayed the AI Act. That was real 4, and it was a different part of the law: the rules for high-risk uses such as hiring and credit scoring moved to December 2027. Article 50 was never a high-risk rule, so there was nothing in it to delay.

One narrow piece of timing relief exists, in Regulation (EU) 2026/1744. If your AI feature was already live before 2 August 2026, you have until 2 December 2026 for the content-marking rule, and only that one 3, 7. Anything that went live after 2 August gets no grace period. Old output is not dragged back in either, though labelling attaches at publication rather than generation, so text written in July and published in August still needs a label 1.

Does your legal documentation match what you ship?

Lawcel watches your product changes and flags the moment your terms or privacy policy fall out of sync, so your legal pages always match what you actually ship.

Try for free

If we call someone else's model, whose marking is it?

Yours. I will show the work, because the opposite answer is so widely believed.

The reasoning I keep hearing goes: we call an API, the model is theirs, the generation runs on their hardware, so the marking is theirs. The definition does not work that way. Article 3(3) says a provider is whoever develops an AI system and puts it on the market "under its own name or trademark" 6. Your product ships under your name, which makes you the provider of your AI feature. Your vendor is the provider of the model underneath it. Different things, different duties. Nor does it matter where you sit: the guidelines catch a provider offering an AI feature on the Union market "regardless of whether the provider is established or located in the Union or in a third country" 1.

I want to be careful here, because the guidelines are thinner on this point than most write-ups pretend. Their worked example of becoming a provider by modifying someone else's system is retraining it on new data, and they never squarely address a product that wraps a vendor's API without touching the model 1. It is the Act itself that closes the gap. Article 3(68) defines a downstream provider as a company whose AI system integrates an AI model, and says it makes no difference whether that model is your own or supplied by another entity under contract 6. An API agreement is that contract. The guidelines use the same frame when they discuss general-purpose models, and speak of compliance "by downstream AI system providers with their obligations under Article 50(1) and (2) AI Act" 1. The duty sits with the company that built the feature, not the company that trained the model.

Then paragraph 74, which is the sentence this whole post is about. You may rely on marking your model vendor has implemented, "to the extent that the marking solution is compliant with Article 50(2)". The next sentence: "Such reliance is without prejudice to the responsibility of the provider of the AI system to demonstrate compliance with Article 50(2) AI Act." 1

So when a regulator asks how you comply, "our model vendor handles it" is not an answer, because proving it was never their job. You have to show that marking survives your product, end to end. A test that generates an image, runs it through your resizer and your PDF export, and checks the marker is still there is worth more than any assurance in a vendor's documentation. The assurance has a known ceiling anyway: Zhang and colleagues' "Watermarks in the Sand", presented at ICML 2024, proved that a watermark an attacker cannot strip without wrecking output quality is impossible under natural assumptions, and demonstrated it on three existing schemes.

Does a smaller team get a smaller obligation?

No, and the guidelines close that door explicitly. Paragraph 81: technical feasibility "is an objective notion that is not dependent on the specific resources and capabilities of individual providers." 1

You do not get a lighter duty for the same content type because you are eight people and your competitor is eight hundred. Harsh, and also the only version that works, because the alternative is a rule whose strength depends on the balance sheet of whoever generated the image. The one concession is that nobody can require you to use a technique that does not exist yet.

If you have no in-house view on watermarking, the Code of Practice on Transparency of AI-generated Content, published 10 June 2026, is the shortcut. The Commission has confirmed it as an adequate voluntary tool for demonstrating compliance 5, so signatories argue from a recognised baseline instead of from first principles. It is not a shield: recital 41 of Regulation (EU) 2026/1744 says these codes grant no presumption of conformity 7. For the questions the guidelines leave open, the Commission's AI Act Service Desk takes them directly, answered by a team working with the AI Office.

Is there a way out for an internal or B2B tool?

There is, and it is narrower than it sounds. Paragraph 87 exempts some industrial and business-to-business tools from marking 1, but all three of these have to be true at once:

  1. The output is strictly technical: engineering designs, production workflows, technical instructions, predictive maintenance output, internal documentation before it is finalised.
  2. Only a limited, pre-defined group of people read it, acting professionally, inside your company and your customer's.
  3. It is not meant to leave the company at all, and you have controls that stop it.

If your tool drafts something an account manager later pastes into a customer email, condition three is gone and so is the exemption. The guidelines do call this a carve-out for "business to business applications" 1, so a B2B product whose output genuinely stays inside those walls can qualify. In practice condition three decides it, and for most SaaS products the whole point of the output is that it travels.

What does an AI agent have to disclose?

Two things: its artificial nature, and the person on whose behalf it is acting. The second half is missing from most implementations I have looked at. An agent that books, negotiates, buys or manages correspondence has to say whose authority it is carrying.

Paragraph 31 handles the case that makes this hard to build. You often cannot know in advance whether an agent will meet a human, so the disclosure belongs in the architecture rather than at each call site, and it fires whenever a human interaction is reasonably likely 1. Agents should also identify themselves to the people instructing them, at authorisation, validation and reporting. Not once at onboarding.

What happens if you get it wrong?

Transparency breaches sit in the middle penalty tier: up to EUR 15 000 000 or 3% of worldwide annual turnover, whichever is higher, under Article 99(4). The write-ups I have read stop there. Article 99(6) then inverts the test for SMEs and startups, who face whichever of the two is lower 6. The simplification package touched Article 99 around the edges but left both the transparency tier and the SME rule standing 7. If you are a twenty-person company, the headline number is not your number. Either way it is a statutory ceiling, not a forecast of what an authority would do to a company that made a serious attempt.

What do you actually have to do now?

The deadline has passed, so if anything on this list is still open it is not preparation any more, it is catch-up. The work itself is the same, and it depends on the shape of your product.

You ship a chat or assistant surface. Put the disclosure in the surface itself, at the first interaction, before the user types anything. Then check it actually renders in every place that surface appears: the widget, the mobile view, the version embedded in a customer's app, the email your bot replies from. That last one is where I keep finding it missing.

Your product generates content a user can export. The one with real work in it. Take a generated file, run it through every transform you own, and check the marker survives: resize, re-encode, thumbnail, PDF export, CDN. The guidelines define robustness as accuracy "under varying conditions, covering both common alterations and adversarial attacks" 1. They never name a screenshot, and I would treat one as a common alteration anyway. Then make it a test that runs in CI, because a passing test is what you can hand a regulator.

You publish AI-drafted text on your own site. The labelling duty in Article 50(4) is narrower than most checklists admit: it covers text published to inform the public on matters of public interest, which the guidelines read as topics that concern society at large, such as public health, consumer safety or public administration 1. A changelog, a release note or a status page update will rarely meet that bar. Where a piece of text does cross it, a security advisory that a lot of people depend on might, you have two options and you have to pick one per content type: a named person who reads it and takes editorial responsibility, or a label saying it was AI-written. An approval nobody owns is the version that fails.

You ship an agent that acts for a user. Two disclosures rather than one, both at every new interaction: that it is artificial, and whose authority it carries.

If your AI is internal tooling and nothing else, work through paragraph 87's three conditions before you decide you are out. And if you only have room for one of these, do the export one. It is the only one that needs code rather than copy.

What are we changing at Lawcel?

Lawcel is a compliance platform that watches a company's product changes and flags the ones that contradict its published legal documents. That makes us a SaaS company with AI features, so all of the above lands on us. Here is our list.

Our drafting produces text that customers publish. Lawcel writes legal documents from a company's legal profile, the set of factual claims about the company that those documents are generated from, and the documents get published on the customer's own site and embedded in their product. Synthetic text from a system we provide, so the marking duty is ours, and it has to hold through our export and embed paths rather than only at generation. The internal-tooling exemption is no help, because the point of the output is that it goes public.

Our case analyses are machine-written. When Lawcel opens a case it writes a summary of what changed and which documents it affects. Strictly, Article 50 may not force a label here: the analysis is read by a small professional group inside our customer's organisation, which is close to the shape of paragraph 87's carve-out 1. We will label it anyway. A compliance product that is coy about its own AI provenance would be a strange thing to sell.

The second item is the one Lawcel exists for. Our legal documents describe our product, and our product changes every week, so every pull request in our repo gets analysed against those documents. When a change contradicts something we have published, it opens a case naming the document to fix. That is the loop I would want for Article 50 anyway, and it is what we run for other people's documents too.

In fact (and this counts as disclosure) this post was drafted by a model and reviewed by me. Whether a blog post about EU law even clears Article 50(4)'s public-interest bar is debatable, but the editorial route it describes is the right shape regardless: a named person who reads the text and is accountable for it. My name is on it because I went through it line by line.

What still matters after 2 August?

You probably read this article because you were concerned about the deadline, but the deadline is in fact the least interesting thing about this.

Article 50 turns a set of claims about your product into claims you have to keep true while the product keeps changing. The disclosure in your chat UI, the sentence in your privacy policy about how AI features work, the allocation in your vendor contract, and the marking in your pipeline all describe the same system. They were written at different times by different people, and nothing in your stack tells you when they stop agreeing. It is the same drift that leaves a privacy policy on version one while the product deploys on every merge.

So the failure I expect is not a team that ignored this. It is a team that does the list above properly before the deadline, then swaps model vendors in the spring, adds an endpoint that writes customer-facing copy, moves the assistant somewhere and forgets to render the disclosure. None of this would have been a compliance event in the past, but it is now.

FAQ

No. The package moved Annex III high-risk obligations to 2 December 2027 and product-embedded high-risk obligations to 2 August 2028. Article 50's application date was not moved, and it applies from 2 August 2026. The package did amend Article 50, but not its timing: Regulation (EU) 2026/1744 redrafted Article 50(7) so that codes of practice are assessed as adequate rather than approved by implementing act, while keeping the Commission's power to impose common rules by implementing act if a code falls short. It also inserted a new Article 111(4) giving a transitional period to 2 December 2026 for the Article 50(2) marking and detection duty, and only for systems already placed on the market before 2 August 2026.
Not by default. Article 50(2) binds the provider of the AI system that generates the content. Under Article 3(3) an AI system shipped under your own name or trademark is yours, and Article 3(68) counts a system that integrates another company's model under contract as exactly that, an AI system with you as its provider. The Commission's guidelines say you may rely on a marking solution implemented by an upstream model provider, but that this reliance is "without prejudice to the responsibility of the provider of the AI system to demonstrate compliance". The burden of proof stays with you.
No. The guidelines state that technical feasibility "is an objective notion that is not dependent on the specific resources and capabilities of individual providers". You are not required to use a solution that does not exist yet, but you do not get a lighter duty for the same content type because you have fewer engineers than your competitor.
There is a narrow one, and all three conditions must hold together: the output is strictly technical in nature, it is only intended to be perceived and processed by a limited pre-defined set of people acting professionally inside the provider's and deployer's organisations, and it is not intended to be shared outside the company, with safeguards against foreseeable misuse. Anything public or consumer-facing falls outside it.
Not if it stays inside standard editing, which the guidelines describe as preparing existing content for publication: grammar, readability, formatting, accessibility. Editing goes beyond that "if the content is changed in a material way ... that affect its meaning, style or intent". A grammar pass is out of scope. A rewrite that changes what the sentence says is not, and neither is a tone change, since style is named directly.
Both its artificial nature and the person on whose behalf it is acting. Where you cannot determine in advance whether the agent will meet a human, the guidelines say to design the disclosure in at the architecture level and fire it whenever interaction is reasonably likely. Agents should also disclose themselves to the people instructing them at key steps such as authorisation and validation, and at every new interaction.
Article 99(4) puts transparency infringements in the middle tier, up to EUR 15 000 000 or 3% of total worldwide annual turnover, whichever is higher. Article 99(6) then flips the test for SMEs and startups, who face whichever of the two is lower. That is the statutory ceiling, not a prediction of what any authority would actually impose.
Article 50(2) is about generating or manipulating synthetic audio, image, video or text. A system that ranks, filters or recommends existing content is not producing new synthetic content, so the marking duty is not the hook for it. Other parts of the AI Act and other EU law may still apply.

References

  1. Commission Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act, C(2026) 5054 final - accessed 30 Jul 2026
  2. European Commission - Guidelines on transparency obligations for providers and deployers of AI systems - accessed 30 Jul 2026
  3. European Commission - Transparency obligations under Article 50 of the AI Act (FAQ) - accessed 30 Jul 2026
  4. European Commission - AI Act regulatory framework and application timeline - accessed 30 Jul 2026
  5. European Commission - Code of Practice on Transparency of AI-generated Content - accessed 30 Jul 2026
  6. Regulation (EU) 2024/1689 (AI Act) - as originally published, including Articles 3, 50 and 99 - accessed 30 Jul 2026
  7. Regulation (EU) 2026/1744 amending the AI Act (the simplification package), including the new Article 111(4) transitional period and the redrafted Article 50(7) - accessed 30 Jul 2026

About the author

Ulf Aslak Lai

Ulf Aslak Lai

Co-founder, Chief Technology Officer

Ulf is Co-founder and CTO at Lawcel. He leads engineering architecture for connectors, analysis pipelines, and the safeguards needed when automation touches regulated customer content.

  • Platform architecture
  • Data governance
  • ML/AI systems
AI Act

Most SaaS AI features are not high-risk under the AI Act. Hiring and credit tools need a check.

Most SaaS features are not high-risk under the EU AI Act. Two things make a system high-risk: it is, or is built into, a product covered by EU product-safety law, or it sits in one of the eight areas in Annex III, such as hiring, education or credit scoring. If yours is, Article 6(3) can still take it out, but you then owe a written assessment and an EU database entry.

GDPR

GDPR gives you one month to answer a deletion request, even if the data is already deleted

On 21 July 2026 the CNIL fined the IT consultancy EXTIA 300,000 euros over deletion requests, mostly because 166 people were never told what had happened to theirs. If you hold data on job applicants, leads or your own users, GDPR Article 12(3) gives you one month to answer, and deleting the data without telling the person does not count as answering.

GDPR

Scraping the whole internet is the easy case. Your small, targeted scrape is not.

The EDPB's draft Guidelines 03/2026 cover web scraping for generative AI, and they reach the team that re-uses someone else's scraped dataset, including for fine-tuning. The Article 14(5)(b) escape from telling people individually turns on whether you could contact them, so a small, recent, directly identifiable dataset is in a worse position than a web-scale crawl. Consultation runs until 30 October 2026.

GDPR

Adding AI to your app? Add these three disclosures to your privacy policy.

Calling an LLM API adds three things to what GDPR Article 13 makes you disclose: the model vendor becomes a recipient of personal data, wherever it runs the prompt is probably a transfer out of the EEA, and if the output decides something about a person you may owe the automated-decision disclosure too. AI Act Article 50 then adds two duties to the product itself.