Not all EU AI Act obligations were deferred.

From 2 August 2026, the transparency obligations in Article 50 of the AI Act apply to providers and deployers of specified AI systems.

For organisations that develop, place on the market or deploy AI systems, the practical question is therefore no longer simply when the AI Act will begin to apply.

For Article 50, that date has arrived.

One limited transition remains. Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content that were placed on the market before 2 August 2026 have until 2 December 2026 to comply with the marking and detection requirements in Article 50(2).

Depending on the system and the organisation’s role, compliance may require:

  • informing individuals that they are interacting with an AI system;
  • marking certain AI-generated or manipulated content in a machine-readable format;
  • informing individuals when emotion-recognition or biometric-categorisation systems are used;
  • disclosing deepfake content; and
  • identifying certain AI-generated or manipulated text published for the purpose of informing the public on matters of public interest.

At the same time, organisations outside the European Union may face a different AI Act obligation.

Certain providers of General-Purpose AI models established outside the Union must appoint an EU Authorised Representative under Article 54 before placing the model on the Union market.

These are separate requirements.

Article 50 concerns transparency around specified AI systems and content.

Article 54 concerns regulatory representation for certain third-country GPAI model providers.

An organisation therefore needs to determine which obligations apply to its actual role, model and system architecture.

Article 50 transparency obligations now apply

Article 50 applies from 2 August 2026, subject to the limited Article 50(2) transition described above.

The provision assigns obligations according to the system, the organisation’s role and the interaction or content involved. Providers and deployers should map those factors before designing transparency controls.

Users may need to be told when they are interacting with AI

Article 50(1) addresses AI systems designed to interact directly with natural persons.

Providers must design and develop relevant systems so that individuals are informed that they are interacting with an AI system, unless this is already obvious from the circumstances in accordance with the conditions in the Regulation.

The obligation therefore affects the design of the system itself.

For relevant interactive AI services, providers should consider:

  • when the disclosure appears;
  • whether it is sufficiently clear;
  • whether users encounter it before or during the interaction;
  • whether the presentation works across different interfaces and devices; and
  • whether the nature of the interaction makes the use of AI sufficiently obvious.

This is therefore both a legal and product-design requirement.

Certain AI-generated content must be technically identifiable

Article 50(2) places a separate obligation on providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text content.

Relevant outputs must be marked in a machine-readable format and be detectable as artificially generated or manipulated, subject to the scope, technical limitations and exceptions provided by the Regulation.

This requirement differs from a visible disclosure shown directly to a human user.

The objective is to make the artificial origin of relevant content capable of being identified through technical means.

Implementation therefore requires organisations to consider:

  • content provenance;
  • machine-readable marking;
  • technical robustness;
  • interoperability;
  • persistence of the marking;
  • and whether downstream processing can remove or degrade the signal.

The final Code of Practice on Transparency of AI-generated Content was published in June 2026 and has since been assessed by the Commission and the AI Board as an adequate voluntary tool for demonstrating compliance with the relevant marking and labelling obligations under Article 50. Adherence remains voluntary and does not constitute conclusive evidence of compliance.

Deployers also have disclosure obligations

Article 50 does not apply only to providers.

Deployers can also have transparency duties.

Where a deployer uses an AI system to generate or manipulate image, audio or video content constituting a deepfake, the artificial nature of that content must be disclosed in accordance with Article 50 and its applicable exceptions.

Article 50 also addresses AI-generated or manipulated text published for the purpose of informing the public on matters of public interest.

The obligation depends on the conditions set out in the Regulation, including the role of human review and editorial responsibility.

For organisations publishing content externally, the practical questions include:

  • whether the content falls within Article 50;
  • whether the organisation is provider or deployer;
  • whether a visible disclosure is required;
  • whether technical marking is already provided upstream;
  • and who internally is responsible for checking compliance before publication.

Certain biometric and emotion-recognition uses require notice

Article 50(3) requires deployers of emotion-recognition and biometric-categorisation systems falling within the provision to inform natural persons exposed to those systems.

This is a separate transparency obligation.

Organisations using such systems should therefore identify:

  • where the systems are deployed;
  • who may be exposed;
  • when the required notice is provided;
  • whether other data-protection obligations also apply; and
  • whether the particular use is permitted under the wider AI Act framework.

Article 50 transparency does not itself determine whether the underlying use is lawful under every other applicable provision.

Provider and deployer obligations should not be conflated

An organisation may be a provider for one AI system and a deployer for another. Provider duties concerning interaction notices and technical marking must be distinguished from deployer duties concerning biometric exposure, deepfakes and public-interest text.

Article 50 also regulates how transparency information is provided. Under Article 50(5), the relevant information must be given in a clear and distinguishable manner at the latest at the time of the first interaction or exposure and must comply with applicable accessibility requirements.

The Commission’s 2026 Guidelines should be built into implementation

The Commission’s July 2026 Guidelines clarify the scope and implementation of Article 50, including interactive systems, technical marking, deepfakes, public-interest text and provider/deployer responsibilities. Together with the voluntary transparency Code of Practice, they inform practical implementation without replacing the Regulation’s binding requirements.

Article 50 Commission Guidelines →


A SEPARATE QUESTION FOR THIRD-COUNTRY GPAI PROVIDERS

Article 54 creates a separate EU representation requirement

Article 54 concerns providers of General-Purpose AI models established in third countries. Before placing a model on the Union market, a provider falling within its scope must appoint an EU-established authorised representative by written mandate.

This requirement is not triggered simply by using generative AI. The assessment concerns model classification, provider status, Union market placement and any statutory exemption.

Who needs an EU Authorised Representative under Article 54?

The requirement applies to providers of General-Purpose AI models established outside the European Union before they place those models on the Union market.

The Commission’s GPAI Guidelines explain that placing a model on the market can occur through mechanisms such as:

  • APIs;
  • model downloads;
  • cloud services;
  • integration into downstream products or services;
  • or other forms of making the model available in the Union.

The AI Act provides specified exemptions, including for certain models released under free and open-source licences where the statutory conditions are met.

Those exemptions do not apply in the same way to GPAI models with systemic risk.

Third-country providers should therefore assess Article 54 on a model-by-model basis rather than assume that an open-source label or non-EU establishment automatically determines the outcome.

The Article 54 representative has defined statutory functions

The mandate must empower the representative to verify that the technical documentation specified in Annex XI has been drawn up and that the obligations under Article 53 and, where applicable, Article 55 have been fulfilled; keep the required technical documentation available for the AI Office and national competent authorities for the statutory period; provide the AI Office, upon a reasoned request, with the information and documentation necessary to demonstrate compliance; cooperate with the AI Office and competent authorities; and act as the provider’s regulatory contact within the Union.

The representative must keep a copy of the technical documentation specified in Annex XI at the disposal of the AI Office and national competent authorities for ten years after the model has been placed on the market.

The role also carries an escalation obligation. Where the authorised representative considers or has reason to consider that the provider is acting contrary to its obligations under the AI Act, Article 54 requires the representative to terminate the mandate and immediately inform the AI Office, including the reasons for termination.

This is a substantive regulatory function, not merely an EU address.

Need an EU Authorised Representative for a General-Purpose AI model?

Explore OSTRAI’s AI Act GPAI Authorised Representative service →

Article 50 and GPAI obligations follow different timelines

GPAI provider obligations entered into application on 2 August 2025. Providers placing new models on the Union market from that date must address the applicable obligations, including Article 54 representation where required.

From 2 August 2026, the Commission’s enforcement powers in relation to the GPAI provider obligations enter into application.

Providers of models placed on the market before 2 August 2025 have a separate compliance deadline of 2 August 2027. Role, model type and market-placement date therefore determine the relevant timetable.

Commission GPAI Guidelines / FAQ →

An organisation may need to address both transparency and representation

A third-country GPAI provider may also supply an interactive or synthetic-content-generating AI system. It may therefore need both Article 54 representation for the model and Article 50 controls for the system. Model and system classification, operator roles and market placement should be assessed together, while keeping the resulting obligations distinct.

What organisations should check now

01 · ROLE

Are we a provider, deployer, GPAI model provider or more than one of these?

02 · SYSTEM / MODEL

Are we dealing with an AI system, a General-Purpose AI model or both?

03 · ARTICLE 50 SCOPE

Does the system interact directly with individuals, generate synthetic content, use emotion recognition or biometric categorisation, or create content requiring disclosure?

04 · MARKING AND DISCLOSURE

Are machine-readable marking and human-facing disclosure controls implemented where required?

05 · CONTENT GOVERNANCE

Who decides whether deepfake or public-interest disclosure obligations apply before content is released?

06 · GPAI MARKET PLACEMENT

Is a General-Purpose AI model being placed on the Union market by a provider established outside the EU?

07 · ARTICLE 54 REPRESENTATION

Is an EU Authorised Representative required, or does a statutory exemption apply?

08 · MANDATE AND DOCUMENTATION

Does the representative have the written mandate, documentation and authority necessary to perform the Article 54 functions?

09 · ONGOING GOVERNANCE

Are regulatory changes, model modifications, new use cases and compliance responsibilities monitored after launch?

Transparency and representation are now operational obligations

The original Privacy Minders post highlighted that not every AI Act deadline had moved into the future. Implementation now requires notices, marking and disclosures to work in actual products and publishing workflows, subject to the limited transition for pre-existing systems under Article 50(2).

Where Article 54 applies, the provider also needs a functioning mandate supporting documentation, regulatory cooperation and escalation. The operational test is specific: which obligation applies to this model, system and role, and is the required mechanism operating?

Originally published by Privacy Minders, now OSTRAI, on LinkedIn on 10 August 2026. This Regulatory Update expands the original analysis. Original LinkedIn post →