Yes, EU AI Act Article 50 is live. Its transparency rules for chatbots, AI agents, deepfakes and AI-generated content have applied since 2 August 2026, and the Digital Omnibus (Regulation (EU) 2026/1744) did not postpone them. The one exception is a short grace period: generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to add machine-readable marking. What the Omnibus did delay is the high-risk regime: Annex III systems now start on 2 December 2027 and Annex I products on 2 August 2028. Breaking Article 50 can cost up to €15 million or 3% of worldwide annual turnover, whichever is higher. For SMEs and start-ups, the cap is whichever is lower.
This is a developer's guide, not legal advice. It explains what Article 50 requires, what changed in July 2026, and how to implement disclosure and marking in a real product. It draws on the Act's text on EUR-Lex, the Commission's Article 50 guidelines of 20 July 2026, and the Code of Practice on transparency of AI-generated content published on 10 June 2026. Check your specific case with counsel.
Article 50 sets four transparency duties. Two fall on providers (whoever builds the AI system and puts it on the market under their name), and two on deployers (whoever uses it in a professional capacity). They apply whatever the system's risk class:
| Paragraph | Who | Applies to | What you must do |
|---|---|---|---|
| 50(1) | Provider | AI systems that interact directly with people: chatbots, voice assistants, AI agents, avatars | Design the system so people are told they are interacting with AI, unless that is obvious to a reasonably well-informed person |
| 50(2) | Provider | Systems (including general-purpose AI) that generate synthetic audio, image, video or text | Mark outputs in a machine-readable format so they are detectable as AI-generated or manipulated |
| 50(3) | Deployer | Emotion recognition and biometric categorisation | Inform the people exposed, and process their data under GDPR |
| 50(4) | Deployer | Deepfakes, and AI-generated text published to inform the public on matters of public interest | Disclose that the content is AI-generated or manipulated. For text, this does not apply if a human reviewed it and someone holds editorial responsibility |
| 50(5) | Both | All of the above | Give the information clearly and distinguishably, at the latest at the first interaction or exposure, and meet accessibility requirements |
There are narrow carve-outs, mainly for systems authorised by law for criminal investigations and, under 50(2), for AI that only assists with standard editing or does not substantially alter the input.

The Omnibus moved the high-risk deadlines, not the transparency ones. Regulation (EU) 2026/1744 was adopted on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026. Here is the timeline as it stands in October 2026:
| Date | What applies | Status (Oct 2026) |
|---|---|---|
| 1 Aug 2024 | AI Act enters into force | Done |
| 2 Feb 2025 | Prohibited practices (Article 5) and AI literacy (Article 4) | Applies |
| 2 Aug 2025 | General-purpose AI model obligations, governance, penalties | Applies |
| 2 Aug 2026 | Article 50 transparency and general application of the Act | Applies now |
| 2 Dec 2026 | Article 50(2) marking for generative systems placed on the market before 2 Aug 2026. New Article 5 bans on non-consensual intimate deepfakes and AI-generated child sexual abuse material | Under 2 months away |
| 2 Feb 2027 | Code of Practice signatories: interoperable detection for watermarks | Voluntary commitment |
| 2 Dec 2027 | High-risk systems under Article 6(2) / Annex III (e.g. employment, credit scoring, education) | Delayed from 2 Aug 2026 |
| 2 Aug 2028 | High-risk systems under Article 6(1) / Annex I (AI in regulated products) | Delayed from 2 Aug 2027 |
The Omnibus also softened the AI literacy duty: Article 4 now requires providers and deployers to take measures to support staff AI literacy. It extended the SME-friendly fine cap to small mid-caps, and it removed the Commission's power to formally approve the marking Code by implementing act. Instead, the Commission assesses whether adhering to the Code is adequate.

If you put a chatbot, agent or generator on the market under your own name, you are its provider, even if the model underneath comes from someone else. The Commission's guidelines give this exact example: a company offering a chatbot, image generator or AI agent under its own brand is the provider responsible for Article 50(1) and/or 50(2), paid or free, and whether or not it is established in the EU. A company that builds a chatbot in-house for its own use is also a provider.
Three points matter for startups:

In the interaction itself, clearly, from the first turn. The 20 July 2026 guidelines spell out what works and what does not:
AI agents get extra rules. An agent that books, negotiates, emails or buys on someone's behalf must disclose that it is AI and on whose behalf it acts. If you cannot predict whether it will meet a human, design it to disclose itself wherever that is reasonably likely. It should also disclose itself to the person instructing it at key steps (authorisation, reporting, validation) and at each new interaction. Machine-to-machine calls that never reach a person are out of scope.
The "obvious" exception is narrow. The guidelines limit it to cases with almost no doubt. Examples include a code-review bot used only by professional developers, an internal assistant for trained staff, or NPCs in a single-player game. A support chatbot on a consumer platform does not qualify. If children or other vulnerable users can reach the system, do not rely on the exception at all.
Under the Code of Practice, with at least two layers for images, audio, video and text inside a file format: digitally signed metadata plus an imperceptible watermark. The Code is voluntary, but in July 2026 the Commission and the AI Board assessed it as adequate for Articles 50(2), (4) and (5), so following it is the most predictable route. Key points for builders:
For most startups that wrap a foundation model, the practical job is to check what marking the model vendor already applies, keep it intact through your pipeline (do not strip metadata when you resize or re-encode), add signed metadata where your product creates files, and document it all.
Fifteen checks to run on every AI feature that EU users can reach:
Up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher (Article 99(4)(g)). For SMEs, including start-ups, the cap is whichever of the two is lower, and the Omnibus extended that treatment to small mid-caps. Member States set the penalty rules and must take the economic viability of smaller companies into account. Supplying incorrect or misleading information to authorities has its own cap of €7.5 million or 1%.
We build the chatbots, agents and AI features that these rules apply to, with the controls designed in from the first sprint. Concretely, from what is published on beevr.ai:
Shipped work, including an AI platform for regulatory-grade bioequivalence assessment, is on our case studies page. For the governance side of agents, see AI agent governance and human-in-the-loop AI for regulated industries.
No. Article 50 has applied since 2 August 2026. The Omnibus only gave generative systems already on the market before that date until 2 December 2026 to add machine-readable marking, and it delayed the high-risk rules to 2 December 2027 and 2 August 2028.
Yes, if you place the AI system on the EU market or its output is used in the EU. Where you are established does not matter for providers. Purely incidental use in the EU does not trigger it.
No. The Commission's guidelines say disclosures only in terms, URLs or documentation are insufficient. Tell the user in the interaction itself, at the latest at the first turn.
If you provide a system that generates text, outputs must be machine-readable marked. Under the Code, a watermark alone suffices for free-form text, very short text is exempt, and standard editing such as grammar fixes or translation needs no marking.
Probably not if it is a support chatbot or content tool. High-risk covers Annex III uses such as hiring, credit scoring and education, plus AI in regulated products. Those obligations now start on 2 December 2027 or 2 August 2028. Article 50 applies to you either way.
BeevR is a senior, founder-led software and AI studio in Hanoi, Vietnam, building production AI for regulated industries at a fixed price per phase, with full code ownership from day one. If you are shipping a chatbot, agent or generator to EU users, tell us what you are building and we will map where disclosure, marking and logging belong in your architecture.