← Provenote blog
compliance standards

Article 50, in plain English: what’s already in force — and what December actually covers

The EU AI Act’s transparency duties have applied since 2 August 2026 — not December. Here’s what has to be marked, what has to be visibly disclosed, where a hidden watermark isn’t enough, and what the December 2026 date really is.

Deepak R Chandran, Ph.D.
Deepak R Chandran, Ph.D.
Founder, Provenote · · 6 min read

Article 50 of the EU AI Act — its transparency chapter — has applied since 2 August 2026. It is not a future deadline; it is current law. Here is what it actually requires, in plain terms, and where a hidden watermark is not enough.

The date most compliance plans get wrong

Plans tend to carry a single date for Article 50, and it is usually the wrong one. The transparency duties themselves have applied since 2 August 2026. What runs to December 2026 is much narrower: a grace period for the machine-readable marking duty under Article 50(2), and only for generative AI systems that were already on the market before 2 August 2026. Anything placed on the market since then has had to mark from day one.

We had this backwards ourselves. An earlier draft of this post said the duties had been “pushed” from August to December; our pre-publication fact-check caught it and held the post. We are printing that here rather than quietly fixing it, because a verification company that hides its own corrections is not worth much.

The four duties, plainly

The distinction that trips people up

For deepfakes, a hidden machine-readable mark does not satisfy the duty on its own. Deployers must add a disclosure a person can understand without any detection tool — visible or audible, at first exposure. Machine-readable marking (the provider’s job) and human-visible disclosure (the deployer’s job) are two different obligations, and you often need both.

“Marked” and “disclosed” are not the same word. One is for machines to read; the other is for a person to see. Article 50 asks for both, in different places.

Where Provenote fits

We are the layer that reads the machine-readable marks the Act already expects — provider watermarks (SynthID, Claude) and C2PA content credentials — and turns them into an auditable verdict an organisation can keep as evidence. We are compliance-supporting infrastructure and decision-support, not legal advice; the obligations above are the Act’s, and you should confirm your own position with counsel.

Note

Next up: Content Credentials for text — what C2PA actually covers, and the one thing it cannot follow. How we approach EU AI Act compliance →

Sources

  1. EU AI Act — Article 50 (transparency obligations)
  2. European Commission — Quick facts: transparency rules for AI systems
  3. Provenote — Security & compliance
Deepak R Chandran, Ph.D.
Deepak R Chandran, Ph.D.
Founder, Provenote

Deepak R Chandran, Ph.D., is the founder of Provenote. He writes about content provenance, AI watermarking, and building verification that is honest about what it can and cannot prove.

Get provenance you can prove

Provenote is in private beta. Request early access →

More reading: Absence of a watermark is not proof of a human →