EU AI Act transparency requirements in force now
Providers and deployers carry different halves of it: the AI systems people interact with, and the content those systems generate.
The EU AI Act's transparency obligations have been in force since 2 August 2026 (Article 50).
If your organisation is within the Act's scope, this duty is live now, and it sits apart from the Annex III and Annex I high-risk obligations deferred to December 2027 and August 2028 under Regulation (EU) 2026/1744.
The European Commission guidelines on Article 50 split the duties between providers and deployers, so the first thing to settle is which role you hold for each system. The EU AI Act overview covers that alongside the Article 2 scope test.
Does Article 50 reach you? Four quick checks
You carry at least one Article 50 duty if any of these is true of an AI system you provide or use:
- People talk to it directly, through a chatbot, a voice agent or an assistant on your site or in your product.
- It generates audio, images, video or text that leaves the organisation.
- It produces or edits content that could pass for a real person, place or event, which the Act defines as a deepfake (Article 3(60)).
- It reads faces, voices or bodies to infer emotion or to sort people into categories.
If one of them fits, the EU AI Act check asks the same questions in order and tells you which duty attaches to which system, and whether you carry it as provider or deployer.
Is there a grace period for systems already on the market?
The substance is unchanged, with one transitional rule the omnibus added. Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text and were placed on the market before 2 August 2026 have until 2 December 2026 to take the necessary steps to comply with the machine-readable marking duty in Article 50(2) (Regulation (EU) 2026/1744, Article 111(4)). Article 50's main application date of 2 August 2026 is untouched, so this window only affects systems already on the market by then.
Which Article 50 duties apply to providers and deployers?
Providers must design their systems so people are explicitly informed when they interact directly with an AI system, and must add machine-readable marks that enable detection of AI-generated or manipulated content (European Commission guidelines on Article 50).
Deployers must inform people exposed to emotion recognition and biometric categorisation systems, label deepfakes, and disclose AI-generated text published to inform the public on matters of public interest where it has not had human review or editorial control (European Commission guidelines on Article 50).
Screen the use case against Article 5 before you design any of that. Emotion inference in the workplace or education is a prohibited practice, subject to narrow medical or safety exceptions, and biometric categorisation used to infer sensitive attributes is also among the prohibited practices described in Regulation (EU) 2024/1689 (Article 5). A transparency notice doesn't turn a prohibited practice into a permitted one.
What counts as public-interest text?
The European Commission guidelines on Article 50 describe the covered case as AI-generated text published to inform the public on matters of public interest where it has not had human review or editorial control. That last condition is part of the duty, so check a specific publication against the wording in the guidelines before you decide it's covered.
Which exceptions change the disclosure?
The European Commission guidelines on Article 50 state that exceptions exist and give standard editing as an example. Deepfake disclosure carries conditions and exceptions of its own, so read those before you treat labelling as automatic in every case.
What does the voluntary Code of Practice do?
The Article 50 transparency requirements are legal obligations. The Code of Practice on Transparency of AI-generated Content is voluntary, covers Article 50(2), (4) and (5), and has been confirmed by the Commission and the AI Board as an adequate voluntary tool for demonstrating compliance with those obligations.
It has a provider section on marking and detection and a deployer section on labelling deepfakes and AI-generated or manipulated text, and signatories can rely on its measures to demonstrate compliance. An organisation that complies by other means has to show its own measures are adequate, and market surveillance authorities assess those individually. Signing the Code does not establish compliance by itself.
How can the optional EU icons be used?
The EU has published a set of icons that deployers may use to label AI-generated content. Using them is optional and an icon does not establish compliance on its own, so a deployer still has to meet the Article 50 duty that applies to the content and read the European Commission guidelines on Article 50 alongside it.
What should a UK company do first?
Start with scope. The EU AI Act overview explains the Article 2 routes and the roles the Act recognises, and the UK scope guide applies that test to a UK organisation. If you're in scope, list the interactions and content flows that matter, then assign the provider or deployer role for each system.
Where you're the provider, record how you tell people they're dealing with an AI system and how you apply machine-readable marking. Where you're the deployer, record who might be exposed to emotion recognition or biometric categorisation and how covered publications get labelled, and check the conditions and exceptions in the European Commission guidelines on Article 50 before you label a deepfake or a piece of public-interest text.
The EU AI Act timeline has the dates for everything else the Act asks of you, and you can download it as a one-page PDF. The AI literacy guide covers the other organisation-wide duty already in force.