Policy & Geopolitics
Three of Four EU AI Transparency Duties Had No Grace Period
EU AI transparency duties now apply to 75% of Article 50's main workstreams; only legacy machine marking gets until December 2.
Three of the EU AI Act’s four main Article 50 transparency workstreams applied on August 2, so 75% had no grace period. Only machine marking for systems already on the market receives the 122 days from August 2 to December 2; product teams treating the high-risk delay as a general AI Act delay are now late.
The delay did not delay visible AI
The European Commission’s Article 50 FAQ confirms the August 2, 2026 application date. The separate high-risk calendar moved to December 2, 2027 for specified standalone uses and August 2, 2028 for systems embedded in regulated products, according to the Commission’s AI Act timeline. Neither postponement suspends customer-facing transparency.
The legal text creates four role-specific jobs. First, providers of AI systems intended to interact directly with people must design them so users know they are interacting with AI unless that is obvious in context. The canonical Article 50 text requires notice by the first interaction, in a clear, distinguishable and accessible form. A human intermediary can alter scope; an agreeable avatar does not make the AI automatically “obvious.”
Second, providers of systems that generate synthetic text, audio, image or video must make outputs machine-readable and detectable as artificial or manipulated. The mechanism must be effective, interoperable, robust and reliable as far as technically feasible, considering state of the art and implementation cost. Standard editing, source code, short strings and some closed production contexts can fall outside the duty, but “B2B” is not a universal safe harbor.
Third, deployers of emotion-recognition or biometric-categorization systems must inform exposed people, including when analysis happens after the fact. A notice does not legalize a prohibited use: some workplace and education emotion recognition and biometric categorization involving protected characteristics remain forbidden under the Commission’s risk framework.
Fourth, deployers must visibly or audibly disclose realistic synthetic image, audio or video that could falsely appear authentic. Machine-readable provider metadata alone cannot satisfy a human-facing deepfake label. Public-interest text gets a narrower rule: disclosure applies when AI-generated or manipulated text is published to inform the public, unless substantive human review occurred and an identifiable person or entity holds editorial responsibility.
That division produces the derived headline. Article 50 has four operative obligation paragraphs, (1) through (4). The Commission grants transitional relief only to paragraph (2), and only for systems placed on the market before August 2. Therefore three of four workstreams—75%—were immediate. The count does not imply equal cost or risk; it is a triage map.
The Commission’s Code of Practice FAQ fixes the remaining deadline at December 2. There are 122 elapsed days between August 2 and December 2. That runway belongs to legacy-system machine marking, not chatbot disclosure, biometric and emotion notices, or deployer labels.
This is the operational sequel to the EU AI Office’s 38-person enforcement expansion, not a replay of deadline politics. It also matters to every provider selling capacity through SpaceX’s emerging AI cloud: infrastructure location does not erase the duties attached to systems and outputs used in the Union.
Ship notices now, preserve evidence for later
Start with a role-and-output inventory. For each system, record whether the company is provider, deployer or both; whether natural people interact directly; whether it generates text, image, audio or video; whether it performs biometric or emotion analysis; whether content qualifies as a deepfake or public-interest publication; and whether a named person exercises substantive editorial control. Assigning the wrong role is the fastest way to implement the right control in the wrong product.
Then ship low-cost visible controls immediately. Put an accessible AI notice at first interaction, not inside terms. Show deepfake disclosure by first exposure without requiring a metadata reader. Notify people exposed to covered biometric or emotion systems. For public-interest text, create a publishing gate that captures the reviewer, changes, factual checks and editorial responsibility rather than treating spell-checking as substantive review.
Provider machine marking demands a deeper engineering lane. Record when the system was first placed on the EU market, test marker survival across common transformations, collect upstream vendor attestations and decide whether to sign the voluntary Code or maintain equivalent evidence. The Code offers a more predictable evidentiary route; it does not replace legal obligations or guarantee that a fragile marker is effective.
There is no representative euro cost in the official sources. A chatbot notice may be a small UI release; durable provenance across several media types can require pipeline changes, QA, accessibility work and interoperability testing. Cost enters the technical-feasibility analysis for machine marking, but it is not a blanket affordability exemption.
The downside is material. Article 99 sets the ceiling for these failures at €15 million or 3% of worldwide annual turnover, whichever is higher for most operators and lower for SMEs and startups. The €15M figure is a maximum, not an expected ticket; authorities must consider gravity, duration, damage, cooperation and remediation. Still, it dwarfs the cost of adding an honest first-interaction notice.
The verdict can change as enforcement develops. Courts or regulators could narrow “output used in the Union,” “public interest,” “deepfake” or “obvious.” Harmonized standards could alter marking tests, and national authorities may converge on remediation before penalties. Those uncertainties justify logging decisions, not waiting with no control.
The operator rule is simple: ship the immediate three workstreams, use the remaining machine-marking runway only where eligibility is documented, and preserve screenshots, release dates, marker tests, vendor statements and review logs. Earlier analysis of the EU omnibus calendar showed that dates diverge by system class. Article 50 now proves the practical consequence: there was never one master “AI Act delay.”