Regulatory Analysis
The AI Act rule that just went live (and hits your chatbots)
Article 50 transparency duties are now enforceable across the EU. What they require, who fines you, and why agents are first in line.
Published on


The EU AI Act's Transparency Rules Are Now Live: What Article 50 Means for AI Agents
On 2 August 2026 the transparency obligations under Article 50 became applicable, and national authorities began enforcing them. Here is what changed, who it binds, and why it lands on conversational AI and agents first.
On 2 August 2026, the part of the EU AI Act that many enterprises had treated as secondary became the part they have to answer for. The transparency obligations in Article 50 became applicable across the EU, and from the same date the AI Office and national authorities began enforcing the Act. The Commission put it plainly: it has started enforcing the rules.
Most of this year's attention went the other way, to the high-risk obligations that were pushed back. Under the Digital Omnibus that entered into force on 27 July 2026, the standalone high-risk rules moved to 2 December 2027. Transparency did not move. That makes Article 50 the major obligation to take effect on the date the market had circled for the high-risk regime, and it lands squarely on chatbots, AI agents, and generated content.
For a security or risk leader, the shift is not really about adding a label. Enforcement sits with market surveillance authorities that can request documentation and levy fines of up to 15 million euros or 3% of worldwide turnover. Transparency has become a demonstrability problem: you have to be able to show, on request, that your AI systems disclosed what they were, and that you can account for how they behaved.
What changed on 2 August 2026
On 2 August 2026, the transparency obligations in Article 50 of the EU AI Act (Regulation (EU) 2024/1689) became applicable, and the AI Office together with national authorities began enforcing the Act. The Commission described the move directly: new transparency rules take effect, and enforcement starts on the same date.
The AI Act entered into force on 1 August 2024 and applies in stages. Prohibited practices and AI literacy duties applied from 2 February 2025, and the governance rules and general-purpose AI obligations from 2 August 2025. Article 50 sits in the Act's transparency-risk category, which covers disclosure duties for systems such as chatbots and generative AI rather than the stricter high-risk regime.
The four transparency obligations under Article 50
Article 50 sets four transparency obligations. Two bind providers, covering disclosure of AI interaction and the marking of generated output. Two bind deployers, covering emotion recognition or biometric categorisation, and the labelling of deepfakes and public-interest text. All four apply from 2 August 2026, with one narrow grace period.
Provision | Binds | What it requires | Applies from |
|---|---|---|---|
Article 50(1) | Providers | Design AI systems that interact directly with people so users are informed they are interacting with an AI system, unless it is obvious. | 2 August 2026 |
Article 50(2) | Providers (including GPAI systems) | Mark generated audio, image, video or text output in a machine-readable format so it can be detected as AI-generated or manipulated. | 2 August 2026 (2 December 2026 for systems placed on the market before 2 August 2026) |
Article 50(3) | Deployers | Inform people exposed to emotion recognition or biometric categorisation systems that those systems are in operation. | 2 August 2026 |
Article 50(4) | Deployers | Clearly label deepfakes, and AI-generated or manipulated text published to inform the public on matters of public interest without human review or editorial control. | 2 August 2026 |
Two points shape how these obligations bite. The disclosure duty in Article 50(1) carries an exception where it is obvious that a person is dealing with an AI, but the Commission's guidelines say that exception should be read restrictively, judged from the perspective of a reasonably well-informed, observant person. The marking duty in Article 50(2) must produce marks that are machine-readable and detectable, and it applies to providers of generative systems, including general-purpose AI systems.
Who enforces Article 50, and what the penalties are
Article 50 is enforced mainly by national market surveillance authorities. The AI Office has a limited role, and the European Data Protection Supervisor covers AI systems used by EU institutions, bodies and agencies. Fines can reach up to 15 million euros or 3% of total worldwide turnover for the preceding financial year.
Per the Commission's guidance, the AI Office is competent only for specific cases: AI systems built on general-purpose AI models where the same entity provides both the model and the system, or systems integrated into a very large online platform or search engine designated under the Digital Services Act. For EU institutions the ceiling is 750,000 euros, and proportionality is taken into account for small and medium-sized enterprises and small mid-cap companies. The practical message is that a breach of a disclosure or labelling duty now carries a supervisory authority and a fine attached to it.
Why transparency lands hardest on conversational AI and agents
The obligation with the widest reach for enterprises running agents is Article 50(1). Any AI system that interacts directly with people, including chatbots, AI agents and avatars, must be built so users are informed they are dealing with an AI, unless that is obvious. That places most customer-facing agents squarely in scope.
The Commission's guidelines set four cumulative criteria for the duty to apply: the system is an AI system, it is designed for a genuine two-way exchange, the interaction is direct, and it is with natural persons. Notice must be given from the start of the first interaction, in a clear and distinguishable way, and in line with accessibility requirements. Systems working purely machine-to-machine fall outside the duty.
This is the obligation most enterprises can and must act on now. The marking duty in Article 50(2) is largely a task for whoever builds the generative model or system, but the interaction-disclosure duty in Article 50(1) attaches to the way an organisation deploys agents in its own products and support flows.
What the delayed high-risk rules do and do not change
The Digital Omnibus did not touch the transparency obligations. It deferred the high-risk regime: standalone Annex III systems now apply from 2 December 2027, and AI embedded in regulated products under Annex I from 2 August 2028. The Omnibus was adopted as a proposal on 19 November 2025, agreed politically on 7 May 2026, and entered into force on 27 July 2026.
So the extra runway is for high-risk work, not for transparency. One narrow grace period applies inside Article 50 itself: systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty under Article 50(2), and content generated before 2 August 2026 does not need to be labelled retroactively. The same package also added a prohibition on AI systems that generate non-consensual intimate imagery or child sexual abuse material, and reinforced the AI Office's oversight of systems built on general-purpose AI models. The sensible reading is to treat the deferral as time to prepare for high-risk, not as a reason to pause transparency work.
From labelling to demonstrability: the governance question
Article 50 turns transparency into something an organisation has to be able to evidence. Because enforcement sits with authorities that can request documentation, the practical task is twofold: make the required disclosures, and keep a record of how your AI systems and agents behaved that you can produce on demand. The first half is disclosure; the second half is accountability.
This is where AI agent governance tooling fits, and where its limits matter. A governance platform does not mark or watermark content, so the Article 50(2) marking duty stays with the provider or model builder. What such tooling can do is govern the agent and produce evidence of that governance, which addresses the accountability half of the problem.
OpenBox, an AI agent governance platform, evaluates each agent operation and returns one of four governance decisions: ALLOW, REQUIRE_APPROVAL, BLOCK, or HALT, with precedence HALT > BLOCK > REQUIRE_APPROVAL > ALLOW. REQUIRE_APPROVAL pauses an operation for human review, which is one way to keep a person in the loop on higher-risk agent actions, and each decision is recorded for audit.
For evidence, the OpenBox documentation describes a per-session attestation pipeline: each governance event is hashed with SHA-256, the hashes are combined into a Merkle tree, and the session root is signed, producing a Proof Certificate for the session. By default the signing uses ECDSA NIST P-256 through AWS KMS. The docs describe this as tamper-evident, meaning an auditor can confirm the recorded governance events were not altered after the fact. None of this satisfies the disclosure or marking duties on its own; it addresses the second half of the demonstrability problem, giving a compliance or security team signed evidence of how an agent was governed when a regulator or an internal reviewer asks.
For teams building out that accountability layer, the AI agent governance guide for enterprise teams sets out how assessment, authorisation, monitoring and audit fit together. Article 50 is a good reason to make sure the record is there before someone asks to see it.
Frequently asked questions
When did the EU AI Act's transparency obligations start to apply?
The transparency obligations under Article 50 of the EU AI Act apply from 2 August 2026. From that date, providers and deployers must comply. A limited grace period runs to 2 December 2026, but only for the marking duty under Article 50(2) and only for systems placed on the market before 2 August 2026.
Does the Digital Omnibus delay the transparency rules?
No. The Digital Omnibus, which entered into force on 27 July 2026, deferred the high-risk obligations, with Annex III systems moving to 2 December 2027 and Annex I systems to 2 August 2028. It did not defer Article 50, so the transparency obligations still applied from 2 August 2026.
Who enforces Article 50 and what are the fines?
Article 50 is enforced mainly by national market surveillance authorities, with a limited role for the AI Office and the European Data Protection Supervisor covering EU institutions. Fines can reach up to 15 million euros or 3% of total worldwide turnover, with proportionality for SMEs and small mid-cap companies.
Do AI chatbots have to tell users they are AI?
Yes. Under Article 50(1), providers must design AI systems that interact directly with people, such as chatbots, AI agents and avatars, so users are informed they are interacting with an AI system, unless that is obvious. Notice must be given clearly from the start of the first interaction.
What must deployers label under Article 50?
Deployers must inform people exposed to emotion recognition or biometric categorisation systems, and clearly label deepfakes and AI-generated or manipulated text published to inform the public on matters of public interest without human review or editorial control. These duties apply from 2 August 2026.
Sources |
European Commission, "Safer and more transparent AI," accessed 3 August 2026. European Commission, "Commission starts enforcing AI Act rules and new transparency requirements on 2 August" (IP/26/1714), accessed 3 August 2026. European Commission, "Transparency obligations under Article 50 of the AI Act" (FAQs), accessed 3 August 2026. European Commission, "AI Act" (regulatory framework), accessed 3 August 2026. OpenBox (docs.openbox.ai), "Governance Decisions," , accessed 3 August 2026. OpenBox (docs.openbox.ai), "Attestation & Cryptographic Proof," , accessed 3 August 2026. |

