Article 50, in plain English: what’s already in force — and what December actually covers
The EU AI Act’s transparency duties have applied since 2 August 2026 — not December. Here’s what has to be marked, what has to be visibly disclosed, where a hidden watermark isn’t enough, and what the December 2026 date really is.
Article 50 of the EU AI Act — its transparency chapter — has applied since 2 August 2026. It is not a future deadline; it is current law. Here is what it actually requires, in plain terms, and where a hidden watermark is not enough.
The date most compliance plans get wrong
Plans tend to carry a single date for Article 50, and it is usually the wrong one. The transparency duties themselves have applied since 2 August 2026. What runs to December 2026 is much narrower: a grace period for the machine-readable marking duty under Article 50(2), and only for generative AI systems that were already on the market before 2 August 2026. Anything placed on the market since then has had to mark from day one.
We had this backwards ourselves. An earlier draft of this post said the duties had been “pushed” from August to December; our pre-publication fact-check caught it and held the post. We are printing that here rather than quietly fixing it, because a verification company that hides its own corrections is not worth much.
The four duties, plainly
- Interactive systems. A chatbot or AI agent must make clear to people that they are dealing with an AI.
- AI-generated content. Providers must mark audio, image, video, and text output with a mark that is effective, interoperable, robust, and reliable and machine-readable — so the output can be detected as AI-generated or manipulated.
- Emotion recognition & biometric categorisation. People exposed to these systems must be told.
- Deepfakes and certain public-interest text. Their artificial origin must be disclosed.
The distinction that trips people up
For deepfakes, a hidden machine-readable mark does not satisfy the duty on its own. Deployers must add a disclosure a person can understand without any detection tool — visible or audible, at first exposure. Machine-readable marking (the provider’s job) and human-visible disclosure (the deployer’s job) are two different obligations, and you often need both.
“Marked” and “disclosed” are not the same word. One is for machines to read; the other is for a person to see. Article 50 asks for both, in different places.
Where Provenote fits
We are the layer that reads the machine-readable marks the Act already expects — provider watermarks (SynthID, Claude) and C2PA content credentials — and turns them into an auditable verdict an organisation can keep as evidence. We are compliance-supporting infrastructure and decision-support, not legal advice; the obligations above are the Act’s, and you should confirm your own position with counsel.
Next up: Content Credentials for text — what C2PA actually covers, and the one thing it cannot follow. How we approach EU AI Act compliance →
Sources
Deepak R Chandran, Ph.D., is the founder of Provenote. He writes about content provenance, AI watermarking, and building verification that is honest about what it can and cannot prove.
Provenote is in private beta. Request early access →