EU AI Act Article 50 is already in force. It took effect on August 2, 2026, and the widely reported delay to the Act’s high-risk obligations did not touch it. Many organizations read the headlines about the EU’s Digital Omnibus pushing back the Act’s most demanding requirements, filed the entire regulation under next year’s problem, and moved on. That assumption is now a compliance gap, not a scheduling one, because Article 50’s transparency obligations apply today, regardless of whether an organization’s AI systems are classified as high-risk under the Act’s separate Annex III framework.
This article explains what changed, what Article 50 actually requires, why it reaches organizations that do not think of themselves as AI companies, and how to fold compliance into governance infrastructure many regulated organizations are already building.
Article 50 Is Already in Force, and the Omnibus Did Not Change That
The confusion here is understandable, because the EU AI Act’s implementation timeline genuinely did change in 2026, just not in the way most coverage suggested.
What the Digital Omnibus Actually Delayed
The EU’s Digital Omnibus on AI, formally Regulation (EU) 2026/1744, entered into force on July 27, 2026, after final adoption on June 29, 2026. It pushed the compliance deadline for high-risk AI systems under Annex III from August 2, 2026 to December 2, 2027, and delayed the Annex I product-safety obligations to August 2, 2028. Those are real, substantial delays, and they are the reason so much of the public discussion around the EU AI Act in mid-2026 described the regulation as having been pushed back by more than a year.
What that coverage largely missed is that the Omnibus explicitly left Article 50 untouched. The transparency obligations in Article 50 became generally applicable and enforceable by national authorities across the EU on August 2, 2026, on schedule, and they apply regardless of whether the underlying AI system is classified as high-risk. An organization that correctly tracked the Annex III delay and incorrectly assumed the same delay covered Article 50 is not behind schedule. It is currently out of compliance with a regulation that has already taken legal effect.
The One Narrow Exception
The Omnibus did make one specific, limited change relevant to Article 50. Providers of AI systems that generate synthetic audio, image, video, or text content, and that placed those systems on the market before August 2, 2026, received a four-month grace period on the machine-readable marking requirement under Article 50(2), extending that specific deadline to December 2, 2026. This exception is narrow in three ways: it applies only to the marking obligation, only to systems already on the market before the original deadline, and not at all to the other three transparency obligations Article 50 establishes, all of which remain in force from August 2, 2026 with no grace period.
What Non-Compliance Actually Costs
Article 99 of the EU AI Act sets the enforcement framework, and it assigns Article 50 breaches to the middle of the Act’s three penalty tiers. Non-compliance with Article 50’s transparency obligations can result in administrative fines of up to fifteen million euros or three percent of an organization’s total worldwide annual turnover for the preceding financial year, whichever figure is higher. This sits below the top tier reserved for the Act’s prohibited practices under Article 5, which reaches thirty-five million euros or seven percent of turnover, but it is a real, material exposure rather than a symbolic one. The Regulation caps the fine at the lower of the two figures for small and medium enterprises, and enforcement sits with each member state’s national market surveillance authority, which took on that enforcement power on the same August 2, 2026 date the obligations themselves became applicable. Reviewing the full EU AI Act compliance timeline puts this specific enforcement date in context alongside the other deadlines the Digital Omnibus did and did not move.
The Four Transparency Obligations Under Article 50
Article 50 covers four distinct situations, each triggering a specific disclosure duty. Understanding which apply to a given organization requires looking at actual AI use cases, not at industry classification.
AI Systems That Interact Directly With People
Providers of AI systems intended to interact directly with natural persons must ensure those individuals are informed they are interacting with an AI system, unless it is obvious from the circumstances to a reasonably well-informed person. This obligation covers chatbots, virtual assistants, and any conversational AI interface a person might otherwise reasonably mistake for a human. The disclosure requirement is not satisfied by a policy buried in terms of service. It requires the interaction itself to make the AI nature of the system reasonably clear to the person engaging with it.
Marking AI-Generated Content
Providers of AI systems that generate synthetic audio, image, video, or text content must mark that output in a machine-readable format detectable as artificially generated or manipulated. This obligation is covered in depth in Elevate’s guide to labeling AI-generated content under the EU AI Act, including the specific format requirements and the narrow grace period for legacy systems described above.
Emotion Recognition and Biometric Categorization Disclosure
Deployers of an emotion recognition system or a biometric categorization system must inform the individuals exposed to that system of its operation, and must process any personal data involved in line with EU data protection law. An exception applies to systems used to detect, prevent, or investigate criminal offenses, subject to safeguards under other applicable law. This obligation attaches to the deployer, the organization using the system, not only to the technology’s original provider, which means an organization that purchases and operates a third-party emotion-recognition or biometric-categorization tool carries this disclosure duty directly.
Deepfake Disclosure
Deployers of AI systems that generate or manipulate image, audio, or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated. This obligation sits alongside the provider-side marking requirement under Article 50(2) but applies specifically to the deployer’s disclosure to the audience encountering the content, which is a distinct duty from the technical marking embedded by the system itself.
Why This Reaches Organizations That Are Not AI Companies
The pattern across all four obligations is the same: Article 50 attaches to specific functionalities and use cases, not to an organization’s primary industry or self-description. A defense contractor, a financial services firm, or a healthcare provider is not exempt from Article 50 because AI is not its core business. It is subject to Article 50 the moment it deploys any of the four covered functionalities and its activity touches an EU person, whether through an EU subsidiary, EU-based employees, EU government or NATO-adjacent contracts, or an EU-facing product or service.
Customer-Facing AI Assistants and Support Tools
Organizations across regulated industries have rapidly added AI-powered customer support chatbots, internal help-desk assistants, and AI-driven compliance or sales tools that interact directly with people, often without treating that addition as a regulatory event. Any such tool that reaches an EU-based customer, partner, or employee triggers the interaction-disclosure obligation, and the fact that the organization’s primary business is compliance consulting, cybersecurity, or defense contracting is irrelevant to whether the obligation applies. The disclosure does not need to be intrusive. A brief, clear statement at the start of an interaction, or a persistent visual indicator that the interface is AI-driven, is generally sufficient, provided it is not buried where a reasonable person would be unlikely to see it before engaging with the system.
A specific edge case worth flagging directly: an organization that licenses a third-party chatbot platform and embeds it in its own website or product does not transfer away its disclosure obligation simply because it did not build the underlying AI system. The deploying organization is still responsible for ensuring the end user sees the disclosure, which means procurement conversations with chatbot and virtual-assistant vendors should now include a direct question about how the vendor’s product satisfies this requirement out of the box, rather than assuming it does.
Generative AI in Marketing and Technical Content
Marketing, proposal, and technical documentation teams increasingly use generative AI to draft content that reaches an external audience. If that content includes synthetic audio, image, video, or text distributed to an EU audience, the marking obligation under Article 50(2) attaches to whichever entity provides the generative system, and organizations relying on third-party tools should confirm those tools meet the marking requirement rather than assuming the obligation is someone else’s problem entirely.
Biometric and Emotion-Recognition Technology in Physical Security Programs
This is the obligation most likely to reach a defense contractor or regulated-industry organization directly, and the one most often overlooked, because it does not sound like an AI product decision. Physical security and insider-threat programs, the kind that sit alongside personnel security and facility access controls in a CMMC or NIST 800-171 environment, increasingly incorporate biometric access control, behavioral analytics, or emotion-recognition technology at facility entry points or within monitoring systems. An organization deploying this kind of technology, even as a purchased security product rather than a custom-built AI system, is the deployer under Article 50 and carries the disclosure obligation to the individuals exposed to it. An organization with EU-based personnel, an EU facility, or an EU government or defense-adjacent customer relationship should treat this as a direct compliance question, not a theoretical one, the next time a physical security vendor proposes this kind of technology.
The practical difficulty is that physical security procurement decisions are rarely routed through the same team evaluating AI governance risk. A facilities or security operations lead selecting an access-control vendor is unlikely to independently flag an Article 50 obligation unless the organization has built a review step that catches AI-enabled functionality regardless of which department is doing the purchasing. Understanding the practical next steps after the EU AI Act entered into force includes exactly this kind of cross-functional intake question, and it is worth revisiting specifically for any security technology procurement already in progress.
Connecting Article 50 to an Existing AIMS
Organizations already building or operating an ISO 42001 AI management system have most of the governance infrastructure Article 50 compliance actually requires. The AIMS’s existing inventory of AI systems, its risk assessment process, and its documented policies are the natural home for Article 50 obligations, which are best treated as a specific set of controls to add to that structure rather than a parallel compliance program built from scratch. Comparing how NIST, the EU AI Act, and ISO 42001 map to a given use case is a useful starting point for organizations trying to understand where Article 50’s specific obligations fit inside a broader governance program they may already be building for other reasons. The EU AI Code of Practice’s relationship to ISO 42001 is a related piece of this same puzzle, since the Code of Practice and Article 50’s disclosure obligations both draw on the same underlying AI system inventory an AIMS maintains.
An organization without an AIMS yet, evaluating its exposure for the first time, should start with an honest inventory: every AI system that interacts directly with people, generates content for external audiences, or performs emotion recognition or biometric categorization, whether built internally or purchased as a third-party product. That inventory is the same starting point ISO 42001 implementation requires, which means the work done to assess Article 50 exposure is not wasted effort even for an organization not yet pursuing certification.
Elevate helps regulated organizations, including defense contractors navigating physical security and insider-threat programs, identify where the EU AI Act’s transparency obligations actually apply and build the disclosure and governance controls Article 50 requires, as part of a broader EU AI Act compliance readiness engagement. To assess your organization’s exposure under Article 50, book a readiness call with an Elevate advisor.
Conclusion
Article 50 of the EU AI Act is not a future deadline. It has been enforceable since August 2, 2026, and the Digital Omnibus’s widely publicized delay to the Act’s high-risk provisions did not extend to it, apart from one narrow marking exception for legacy generative systems. Organizations that conflated the two are not ahead of a coming requirement. They are behind a current one.
The obligation reaches further than most regulated organizations initially assume, particularly through emotion-recognition and biometric technology deployed in physical security programs that were never evaluated as an AI governance question in the first place. Treating Article 50 compliance as an extension of an existing or planned AIMS, rather than a separate scramble, is the difference between a manageable set of additional controls and a compliance gap discovered during a customer or regulator inquiry. Book a readiness call to find out where your organization stands.
Key Takeaways
- Article 50 has been enforceable since August 2, 2026, and the Digital Omnibus did not delay it. Only the machine-readable marking obligation for legacy generative systems received a narrow four-month extension to December 2, 2026.
- Article 50 covers four distinct obligations: AI interaction disclosure, content marking, emotion recognition and biometric categorization disclosure, and deepfake disclosure. Each attaches to a specific functionality and use case, not to an organization’s industry.
- Regulated organizations are frequently in scope through use cases they do not think of as AI products. Customer-facing chatbots, generative content tools, and biometric or emotion-recognition security technology all trigger obligations regardless of the organization’s primary business.
- Biometric and emotion-recognition technology in physical security programs is the most overlooked trigger for defense and regulated-industry organizations. A purchased security product, not just custom-built AI, makes the deploying organization responsible for the disclosure obligation.
- Article 50 compliance fits naturally inside an existing or planned ISO 42001 AIMS. The same AI system inventory and risk assessment process an AIMS requires is the right foundation for identifying and closing Article 50 gaps.
FAQs
What are the penalties for non-compliance with EU AI Act Article 50? Under Article 99 of the EU AI Act, non-compliance with Article 50’s transparency obligations can result in administrative fines of up to fifteen million euros or three percent of an organization’s total worldwide annual turnover for the preceding financial year, whichever is higher. This falls below the top penalty tier reserved for the Act’s prohibited practices, which reaches thirty-five million euros or seven percent of turnover, but it remains a material financial exposure. Small and medium enterprises benefit from a cap set at the lower of the two figures, and enforcement is carried out by each EU member state’s national market surveillance authority.
Is EU AI Act Article 50 currently in force? Yes. Article 50’s transparency obligations became generally applicable and enforceable across the EU on August 2, 2026. The Digital Omnibus, which delayed the Act’s high-risk obligations under Annex III to December 2, 2027, explicitly did not amend Article 50, apart from a narrow four-month grace period on the content-marking obligation for generative AI systems already on the market before August 2, 2026.
Does Article 50 only apply to companies that build AI products? No. Article 50 attaches to specific functionalities, an AI system interacting directly with people, generating synthetic content, performing emotion recognition or biometric categorization, or producing deepfakes, regardless of an organization’s primary industry. An organization that purchases and deploys a third-party tool with one of these functionalities carries the relevant disclosure obligation directly, even if it does not consider itself an AI company.
What does Article 50 require for emotion recognition and biometric categorization systems? Deployers of emotion recognition or biometric categorization systems must inform the individuals exposed to the system of its operation and process any personal data involved in accordance with EU data protection law. An exception applies to systems used specifically to detect, prevent, or investigate criminal offenses, subject to safeguards under other applicable law. This obligation applies to the organization deploying the system, not only to its original developer.
How should an organization start assessing its Article 50 exposure? Start with an inventory of every AI system in use, whether built internally or purchased from a third party, that interacts directly with people, generates content for an external audience, or performs emotion recognition or biometric categorization. For each system, determine whether its use touches an EU-based individual through an EU subsidiary, EU employees, or an EU-facing product or customer relationship. This inventory is the same foundation an ISO 42001 AI management system requires, so the work applies even for organizations not yet pursuing certification.