← Blog
Field note

EU AI Act Article 50: Developer Checklist (Oct 2026)

Thien Nguyen · Oct 6, 2026

Yes, EU AI Act Article 50 is live. Its transparency rules for chatbots, AI agents, deepfakes and AI-generated content have applied since 2 August 2026, and the Digital Omnibus (Regulation (EU) 2026/1744) did not postpone them. The one exception is a short grace period: generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to add machine-readable marking. What the Omnibus did delay is the high-risk regime: Annex III systems now start on 2 December 2027 and Annex I products on 2 August 2028. Breaking Article 50 can cost up to €15 million or 3% of worldwide annual turnover, whichever is higher. For SMEs and start-ups, the cap is whichever is lower.

This is a developer's guide, not legal advice. It explains what Article 50 requires, what changed in July 2026, and how to implement disclosure and marking in a real product. It draws on the Act's text on EUR-Lex, the Commission's Article 50 guidelines of 20 July 2026, and the Code of Practice on transparency of AI-generated content published on 10 June 2026. Check your specific case with counsel.

What does EU AI Act Article 50 require?

Article 50 sets four transparency duties. Two fall on providers (whoever builds the AI system and puts it on the market under their name), and two on deployers (whoever uses it in a professional capacity). They apply whatever the system's risk class:

ParagraphWhoApplies toWhat you must do
50(1)ProviderAI systems that interact directly with people: chatbots, voice assistants, AI agents, avatarsDesign the system so people are told they are interacting with AI, unless that is obvious to a reasonably well-informed person
50(2)ProviderSystems (including general-purpose AI) that generate synthetic audio, image, video or textMark outputs in a machine-readable format so they are detectable as AI-generated or manipulated
50(3)DeployerEmotion recognition and biometric categorisationInform the people exposed, and process their data under GDPR
50(4)DeployerDeepfakes, and AI-generated text published to inform the public on matters of public interestDisclose that the content is AI-generated or manipulated. For text, this does not apply if a human reviewed it and someone holds editorial responsibility
50(5)BothAll of the aboveGive the information clearly and distinguishably, at the latest at the first interaction or exposure, and meet accessibility requirements

There are narrow carve-outs, mainly for systems authorised by law for criminal investigations and, under 50(2), for AI that only assists with standard editing or does not substantially alter the input.

EU AI Act Article 50 obligations by paragraph: 50(1) and 50(2) for providers, 50(3) and 50(4) for deployers, 50(5) for both; applies since 2 Aug 2026, fines up to €15M or 3% of turnover
Figure 1: EU AI Act Article 50 obligations by paragraph: 50(1) and 50(2) for providers, 50(3) and 50(4) for deployers, 50(5) for both; applies since 2 Aug 2026, fines up to €15M or 3% of turnover

What did the Digital Omnibus delay, and what still applies now?

The Omnibus moved the high-risk deadlines, not the transparency ones. Regulation (EU) 2026/1744 was adopted on 8 July 2026, published in the Official Journal on 24 July 2026, and entered into force on 27 July 2026. Here is the timeline as it stands in October 2026:

DateWhat appliesStatus (Oct 2026)
1 Aug 2024AI Act enters into forceDone
2 Feb 2025Prohibited practices (Article 5) and AI literacy (Article 4)Applies
2 Aug 2025General-purpose AI model obligations, governance, penaltiesApplies
2 Aug 2026Article 50 transparency and general application of the ActApplies now
2 Dec 2026Article 50(2) marking for generative systems placed on the market before 2 Aug 2026. New Article 5 bans on non-consensual intimate deepfakes and AI-generated child sexual abuse materialUnder 2 months away
2 Feb 2027Code of Practice signatories: interoperable detection for watermarksVoluntary commitment
2 Dec 2027High-risk systems under Article 6(2) / Annex III (e.g. employment, credit scoring, education)Delayed from 2 Aug 2026
2 Aug 2028High-risk systems under Article 6(1) / Annex I (AI in regulated products)Delayed from 2 Aug 2027

The Omnibus also softened the AI literacy duty: Article 4 now requires providers and deployers to take measures to support staff AI literacy. It extended the SME-friendly fine cap to small mid-caps, and it removed the Commission's power to formally approve the marking Code by implementing act. Instead, the Commission assesses whether adhering to the Code is adequate.

EU AI Act timeline after the Digital Omnibus: Article 50 applies from 2 Aug 2026, marking grace period to 2 Dec 2026, high-risk Annex III delayed to 2 Dec 2027 and Annex I to 2 Aug 2028
Figure 2: EU AI Act timeline after the Digital Omnibus: Article 50 applies from 2 Aug 2026, marking grace period to 2 Dec 2026, high-risk Annex III delayed to 2 Dec 2027 and Annex I to 2 Aug 2028

Are you a provider or a deployer if you build on GPT, Claude or Gemini?

If you put a chatbot, agent or generator on the market under your own name, you are its provider, even if the model underneath comes from someone else. The Commission's guidelines give this exact example: a company offering a chatbot, image generator or AI agent under its own brand is the provider responsible for Article 50(1) and/or 50(2), paid or free, and whether or not it is established in the EU. A company that builds a chatbot in-house for its own use is also a provider.

Three points matter for startups:

  • Non-EU companies are in scope if their AI system's output is used in the EU. Incidental or unforeseeable use alone does not trigger it.
  • You may rely on your model vendor's marking for 50(2), for example a watermark applied by the upstream model, as long as it meets the requirements. The responsibility to show compliance stays with you.
  • You can be both. If you also publish AI-generated content yourself (marketing videos, auto-written news), you are a deployer for 50(4) too.
An AI assistant interface inside a professional app
An AI assistant interface inside a professional app

How must a chatbot or AI agent disclose that it is AI?

In the interaction itself, clearly, from the first turn. The 20 July 2026 guidelines spell out what works and what does not:

  • Works: a first-turn message ("I'm an AI assistant") plus a label near the input box. A spoken statement at the start of a voice call, with reminders in long calls. An "AI" label at the top of an email an agent sends. Persistent badges or icons alongside the text.
  • Not enough on its own: a line in the terms and conditions or documentation; metadata or watermarks the user cannot see; vague labels like "assistant"; a site-wide "services on this website use AI" notice; or "this system uses LLMs" without saying the user is talking to AI.
  • When to repeat it: one prominent notice before the first interaction usually suffices. Periodic reminders are likely needed for vulnerable users, emotionally sensitive or immersive use, and advice in finance, insurance, legal, health or complaints. The system must also answer truthfully whenever someone asks if it is AI.

AI agents get extra rules. An agent that books, negotiates, emails or buys on someone's behalf must disclose that it is AI and on whose behalf it acts. If you cannot predict whether it will meet a human, design it to disclose itself wherever that is reasonably likely. It should also disclose itself to the person instructing it at key steps (authorisation, reporting, validation) and at each new interaction. Machine-to-machine calls that never reach a person are out of scope.

The "obvious" exception is narrow. The guidelines limit it to cases with almost no doubt. Examples include a code-review bot used only by professional developers, an internal assistant for trained staff, or NPCs in a single-player game. A support chatbot on a consumer platform does not qualify. If children or other vulnerable users can reach the system, do not rely on the exception at all.

How do you mark AI-generated content in a machine-readable way?

Under the Code of Practice, with at least two layers for images, audio, video and text inside a file format: digitally signed metadata plus an imperceptible watermark. The Code is voluntary, but in July 2026 the Commission and the AI Board assessed it as adequate for Articles 50(2), (4) and (5), so following it is the most predictable route. Key points for builders:

  • Signed metadata. Record in the file's metadata that the content is AI-generated or manipulated, and sign it. Open provenance standards such as C2PA Content Credentials are the usual way to do this in practice.
  • Watermark. Embed a mark that survives common edits. Plain free-form text cannot carry metadata, so a watermark alone is enough there. Very short text is exempt from watermarking. Fingerprinting or logging is an optional extra layer, never the only one.
  • Detection. Providers must make detection available free of charge, with human-readable results. Signatories commit to interoperable watermark detection by 2 February 2027.
  • Exemptions. No marking is needed for standard editing (grammar fixes, translation, format conversion, minor crops). Strictly internal technical B2B output and ephemeral real-time content can also be exempt under narrow, cumulative conditions in the guidelines.
  • Agents. If an agent's action produces content a person will see (an email, an image, a document), mark that output. Its reasoning steps and web requests are not "synthetic content".

For most startups that wrap a foundation model, the practical job is to check what marking the model vendor already applies, keep it intact through your pipeline (do not strip metadata when you resize or re-encode), add signed metadata where your product creates files, and document it all.

What is the developer checklist for Article 50 compliance?

Fifteen checks to run on every AI feature that EU users can reach:

  1. Inventory every AI feature: chat, voice, agents, generators, emotion or biometric features. Note which ones EU users can reach.
  2. Decide your role per feature (provider, deployer or both) and write it down.
  3. Chat UI: a first-turn AI disclosure plus a persistent label near the input, in the user's language.
  4. Voice: a spoken disclosure at call start, with reminders in long sessions and after hand-offs.
  5. Agents: outbound messages carry an AI label and name the principal ("AI assistant acting for Acme Ltd").
  6. Agents: disclosure to the operator at authorisation, reporting and validation steps.
  7. Answer truthfully when asked "am I talking to a human?" Test it in your eval suite.
  8. Check accessibility: disclosures work with screen readers, and audio cues are never the only signal.
  9. Remove "AI disclosure only in the T&Cs" patterns and generic "assistant" wording.
  10. Generated media: keep the model vendor's marks, add signed provenance metadata, and never strip metadata in your processing pipeline.
  11. Generated text published as news or public-interest content: label it, or document human editorial review and who holds responsibility.
  12. Deepfakes in marketing or creative work: label them in a way that fits the work.
  13. Log disclosures and marking per output so you can show what was shown, when and to whom.
  14. Generative features launched before 2 August 2026: confirm marking is in place by 2 December 2026.
  15. Add AI-transparency checks to your release checklist and vendor due diligence, and re-review when the high-risk dates approach.

What are the fines for breaking Article 50?

Up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher (Article 99(4)(g)). For SMEs, including start-ups, the cap is whichever of the two is lower, and the Omnibus extended that treatment to small mid-caps. Member States set the penalty rules and must take the economic viability of smaller companies into account. Supplying incorrect or misleading information to authorities has its own cap of €7.5 million or 1%.

What does BeevR build for AI products that serve EU users?

We build the chatbots, agents and AI features that these rules apply to, with the controls designed in from the first sprint. Concretely, from what is published on beevr.ai:

  • Agents with a control layer. Our open-source framework Kite (MIT) treats the LLM as untrusted: the model proposes, a kernel validates every action, with a circuit breaker, kill switch and idempotency. That kernel is the natural place to enforce rules such as "every outbound message carries an AI label and names the principal". Our AI agent builds add immutable logs of every tool call and approval gates on actions that touch patient records or money.
  • Regulated-industry experience. We build HIPAA-aligned, BAA-backed AI agents with PHI masking, tamper-evident audit logging and human review, and payment systems architected to PCI DSS 4.0 (see the payment gateway case study). Our security page lists the controls and says plainly where we are aligned with a standard (SOC 2, ISO 27001) rather than certified.
  • Machine-readable interfaces we run ourselves. beevr.ai and our ESG product ecocheck.ai each run a public, read-only MCP server for AI assistants, documented in server cards on beevr.ai and ecocheck.ai.
  • Private AI when data must not leave. Nebula (Apache-2.0, 430+ tests) runs GraphRAG and an LLM entirely in the browser, so nothing leaves the device.
  • Fixed prices. A Pitch Demo at $4K (about 10 days), an Investor MVP at $18K (about 6 weeks) and a Flagship Sprint at $38K (about 10 weeks), listed on our MVP cost page. Agent builds are priced by phase from $10K. You own the code from day one.

Shipped work, including an AI platform for regulatory-grade bioequivalence assessment, is on our case studies page. For the governance side of agents, see AI agent governance and human-in-the-loop AI for regulated industries.

FAQ

Did the Digital Omnibus delay Article 50?

No. Article 50 has applied since 2 August 2026. The Omnibus only gave generative systems already on the market before that date until 2 December 2026 to add machine-readable marking, and it delayed the high-risk rules to 2 December 2027 and 2 August 2028.

Does Article 50 apply to a US or Asian startup?

Yes, if you place the AI system on the EU market or its output is used in the EU. Where you are established does not matter for providers. Purely incidental use in the EU does not trigger it.

Is a line in my terms of service enough to disclose a chatbot?

No. The Commission's guidelines say disclosures only in terms, URLs or documentation are insufficient. Tell the user in the interaction itself, at the latest at the first turn.

Do I have to watermark AI-generated text?

If you provide a system that generates text, outputs must be machine-readable marked. Under the Code, a watermark alone suffices for free-form text, very short text is exempt, and standard editing such as grammar fixes or translation needs no marking.

Is my AI feature high-risk?

Probably not if it is a support chatbot or content tool. High-risk covers Annex III uses such as hiring, credit scoring and education, plus AI in regulated products. Those obligations now start on 2 December 2027 or 2 August 2028. Article 50 applies to you either way.

BeevR is a senior, founder-led software and AI studio in Hanoi, Vietnam, building production AI for regulated industries at a fixed price per phase, with full code ownership from day one. If you are shipping a chatbot, agent or generator to EU users, tell us what you are building and we will map where disclosure, marking and logging belong in your architecture.