The EU’s AI transparency rules are now in force.
Article 50 of the AI Act applies from 2 August 2026, while the high-risk requirements moved to 2027 and 2028. The work due now is an inventory of where AI meets people, and a decision on who carries the disclosure in each case.
Insights bi îngilîzî tên weşandin.
On 2 August 2026 the Artificial Intelligence Act, Regulation (EU) 2024/1689, reached its general date of application. For most companies, the obligation that arrived was not the one they had prepared for: six days earlier, the high-risk requirements had been moved to 2027 and 2028. What became applicable on schedule was Article 50 — a short set of rules about telling people when they are dealing with a machine. What binds today is therefore inventory, wording and documentation rather than engineering.
What arrived on 2 August is a disclosure duty, not a risk-classification project
Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and amended Article 113 of the AI Act. The Chapter III requirements for high-risk systems — risk management, data governance, conformity assessment — now apply from 2 December 2027 to the Annex III use cases, recruitment and credit scoring among them, and from 2 August 2028 to high-risk AI embedded in regulated products.
Article 50 was left standing; its four obligations are unchanged.
- Providers of systems that interact directly with people must design them so that the person is told they are dealing with an AI system, unless that is obvious (Article 50(1)).
- Providers of systems generating synthetic audio, image, video or text must mark the outputs in a machine-readable format, detectable as artificially generated or manipulated (Article 50(2)).
- Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them (Article 50(3)).
- Deployers must disclose deepfakes, and public-interest text published without human review or editorial control (Article 50(4)).
Article 50(5) fixes the timing: the information must reach the person clearly at first interaction or exposure, and must meet accessibility requirements.
Which obligation applies depends on a role defined by name, not by size
A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark (Article 3(3)); a deployer uses one under its authority, except where the use is a personal, non-professional activity (Article 3(4)). The first two obligations bind providers, the last two bind deployers.
A firm that licenses a chatbot from a vendor is normally a deployer, and the design duty in Article 50(1) sits with the vendor; a firm that supplies a system under its own name or trademark takes on the provider’s obligations. Neither role depends on establishment in the Union: Article 2(1)(c) reaches third-country providers and deployers where the output produced by the system is used in the Union.
Eurostat’s survey gives the scale: just under 20% of EU enterprises with ten or more employees used AI technologies in 2025, with 9.6% using technologies that generate images, video or audio and 8.8% natural language generation or speech synthesis.
The guidelines narrow the duty in places and close an easy exit in others
The Commission published guidelines on Article 50 on 20 July 2026, with questions and answers; they cut in both directions.
The duty to announce an AI system applies only where four criteria are met cumulatively: the system qualifies as an AI system; it is built for a genuine two-way exchange rather than for collecting data or returning automated responses; the interaction is direct; and it is with natural persons. Whether an interaction is obvious is judged from the standpoint of a reasonably well-informed, observant and circumspect person, and the Commission reads the exception restrictively because it deprives people of transparency. The marking obligation excludes source code, machine-to-machine outputs never exposed to people, and closed-loop industrial and product-development environments, with a narrow business-to-business exemption.
Labelling is bounded too. Content counts as a deepfake only where it resembles a subject that exists or could plausibly have existed and could appear falsely authentic. Text must be labelled only where it is published, informative to the public and on a matter of public interest, and the duty falls away where it has undergone human review or editorial control for which a person holds responsibility; spell-checking does not qualify.
One assumption is closed off explicitly: a deployer cannot rely on the provider’s machine-readable marking to discharge its own duty. What is owed to a person must be perceivable without technical tools.
The remaining transitional date is 2 December 2026, and the penalties are fixed
The Digital Omnibus added a transitional provision: providers of systems generating synthetic content that were placed on the market before 2 August 2026 must comply with Article 50(2) by 2 December 2026, a grace period of four months. It covers only that obligation and only systems already on the market, and content generated before 2 August 2026 need not be labelled retroactively.
The Code of Practice on Transparency of AI-generated Content, drawn up by independent experts facilitated by the AI Office, has been confirmed by the Commission and the AI Board as an adequate voluntary tool for the marking and labelling obligations. About 190 organisations had signed by the end of July 2026 — 82 to the provider section and 152 to the deployer section. Those that do not adhere must demonstrate compliance through alternative measures of equivalent adequacy.
Enforcement rests mainly with the national market surveillance authorities that member states were required to designate by 2 August 2025. Infringement of Article 50 carries fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher; for SMEs and start-ups, Article 99(6) caps the fine at whichever is lower, and the Commission states that proportionality can be taken into account for SMEs and small mid-caps.
For a Swiss company the duty arrives through the customer, not through Swiss law
Switzerland has no equivalent statute, and none is imminent. On 12 February 2025 the Federal Council decided to incorporate the Council of Europe’s AI Convention into Swiss law and to keep legislative change sector-specific, instructing the Federal Department of Justice and Police to prepare a consultation bill by the end of 2026 — covering, in particular, transparency, data protection, non-discrimination and supervision.
Swiss law is not silent in the meantime. Article 21 of the Data Protection Act requires a controller to inform the data subject of any decision based exclusively on automated processing that has a legal consequence or a considerable adverse effect, and to allow that person, on request, to have it reviewed by a natural person. Article 3 extends the Act to circumstances that have an effect in Switzerland even if initiated abroad.
The larger exposure runs the other way. Because the AI Act reaches third-country providers and deployers whose output is used in the Union, the test for a Swiss exporter is not where the company sits but where the output lands. With 51% of Swiss exports going to the EU, it is met routinely — by a chat assistant answering a German buyer, by product imagery generated for an Italian distributor.
What a management team can settle before December
Four decisions cover most of the exposure, and none requires new technology.
- Map where AI meets people, and assign the role. For each point of contact — chat, voice, e-mail drafting, product imagery, marketing copy — record whether the company is provider or deployer. That follows from whose name the system carries, not from who pays the licence.
- Verify the disclosure that actually appears. Where a vendor holds the Article 50(1) duty, the customer relationship is still yours: open the chat window and confirm the notice appears at first contact and stays legible on a phone.
- Make the deployer-side labels visible. The Commission’s EU icon set is optional; the label itself is not.
- Decide on the code of practice, and record the decision. Sign the relevant section, or write down which alternative measures the company relies on.
Three dates belong in the calendar: 2 December 2026, for the marking transition and the new prohibition on AI systems generating non-consensual sexually explicit or intimate content and child sexual abuse material; the end of 2026, for the Swiss consultation draft; and 2 December 2027 and 2 August 2028, for the high-risk requirements.
The obligation that arrived on 2 August is modest in itself. Its significance is that disclosure has moved from communication policy to a property of the product — specified, documented and enforceable — and now reaches companies that never set out to build an AI system.
