From 2 August 2026, EU AI Act Article 50 transparency obligations apply — users must be told when they are interacting with an AI system or looking at AI-generated media. The digital omnibus deferred the high-risk regime; it did not defer this. If your chatbot stays silent, you are the one exposed.
Who this is for
- Anyone running a customer-facing chatbot, voice assistant or support agent in the EU market.
- Product and engineering leads who ship AI features and assumed the omnibus bought them time.
- Compliance and risk owners who need a defensible answer on what applies on 2 August.
- Marketing and content teams publishing AI-generated or AI-edited images, audio or video.
What’s happening
Article 50 of the EU AI Act sets the transparency duties: a system that interacts with people must make clear they are dealing with an AI unless it is obvious; synthetic audio, image and video content must be marked as artificially generated or manipulated; and deployers of emotion-recognition or biometric-categorisation systems must inform the people exposed to them. Those obligations become applicable on 2 August 2026.
The confusion comes from the digital omnibus. It pushed the high-risk obligations back — Annex III high-risk to 2 December 2027, Annex I embedded high-risk to 2 August 2028. Article 50 was not part of that reset. It sits on the original date and it is now binding law. Read the omnibus as a deferral of the heavy conformity work, not a general amnesty.
Free · 4 minutes
Do you know where AI is already being used in your business — and what it can see?
Fourteen questions on shadow AI, data exposure, oversight, and governance debt — the gap between how fast AI is arriving and how much control you have over it. Banded finding on screen, full sheet by email.
Why it bites
Transparency looks like the easy tier, and that is exactly why it gets missed. The duty falls on the deployer — the organisation putting the system in front of users — not only on whoever built the model. A generic “powered by AI” footer is not the same as telling a user, at the point of interaction, that the thing answering them is a machine. And AI-media labelling is a duty most content teams have never been briefed on, so the exposure is spread across functions that do not think of themselves as running an AI system at all.
The one thing to do before 2 August
Inventory every point where a user meets your AI and confirm each one carries a clear disclosure. Walk the actual journeys — the web chat, the in-app assistant, the phone line, the auto-generated images on your campaigns — and write down, for each, the exact words shown and when they appear. If any surface has no disclosure, or hides it behind a settings menu, fix that one first. I set out what a disclosure that holds up actually looks like in this piece on building Article 50 disclosure.
If you want a second pair of eyes on that inventory before the date, a technology control review covers exactly this: mapping the interaction points, checking the disclosures against the obligation, and leaving you with evidence you can show a regulator.
Engagements are fixed-scope and priced up front, so you know the cost before you commit.
Transparency is the part of the AI Act you can get right with a checklist rather than a programme — but only if you start before 2 August 2026. That is the date. It did not move.
Free interactive tool
Website compliance checklist
What your site has to do, based on what it actually does
Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.
Everything that applies
Ordered by what to do first: legal requirements you can close quickly, then larger pieces of work, then what is expected rather than required. Not exhaustive, and not a legal audit.
Dated PDF, yours to keep or circulate.
Free interactive tool
Interactive deadline calculator
Check which regulations apply to you and when
Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.
Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.
Most technology problems are not technology problems. They are control problems.
The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.
Full Governance by Sixteen Pillars
Govern your business. Prove your compliance.
A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.
See what's coming