Articles 2, 3 and 50 of Regulation (EU) 2024/1689 were read at the European Commission AI Act Service Desk on 25 September 2026. The pages for Article 2 and Article 50 each carried a notice stating that the provision has been amended by the Digital Omnibus on AI and that the displayed text had not yet been updated, and no amended text of either was read for this article. This article describes Union law only. It does not describe the law of any other jurisdiction, any national measure of a Member State, or any rule on jurisdiction or enforcement, none of which was read for it. It is not legal advice.

In short
  • The deferral introduced by Regulation (EU) 2026/1744 moved high-risk obligations to 2 December 2027 for stand alone Annex III systems and 2 August 2028 for Annex I systems. Article 50 is a transparency provision and was not moved. The European Commission states that it applies as from 2 August 2026.
  • Article 50 carries four duties and they are split between two roles. Interaction disclosure and machine-readable marking sit on the provider. Notice of emotion recognition or biometric categorisation, and disclosure of deep fake content and of AI-generated text published to inform the public on matters of public interest, sit on the deployer.
  • The only relief is narrow and it is closing. It applies to systems placed on the market before 2 August 2026, only to the Article 50(2) marking and detection duty, and it runs out on 2 December 2026.
  • Establishment in the Union is not the test for scope. Article 2(1)(a) reaches providers placing systems on the Union market irrespective of where they are established, and Article 2(1)(c) reaches providers and deployers located in a third country where the output produced by the system is used in the Union.
  • The operational asymmetry is the thing to design around. Marking is a property of the generation pipeline, which makes it a global build decision. Disclosure is a property of the interface, which makes it a per market decision. Teams that treat both as regional settings tend to ship unmarked output when a location inference goes wrong.

Section 1. The deferral everybody read about was about something else

The AI Act is often described as though it had one compliance date, and the reporting on the AI Omnibus reinforced that by giving it a new one. What moved were the obligations attaching to high-risk classification: stand alone Annex III systems to 2 December 2027, and Annex I systems embedded in regulated products to 2 August 2028. Those are the duties around risk management, technical documentation, conformity assessment, registration and post-market monitoring.

Article 50 does not depend on high-risk classification at all. It attaches to what a system does rather than to where it is used: interacting with a person, generating synthetic content, recognising emotion, producing a deep fake, publishing text about matters of public interest. A chatbot on a marketing site, an image generator inside a consumer application and a voice assistant are all capable of being within Article 50 while being nowhere near Annex III. The European Commission states that Article 50 applies as from 2 August 2026, and the broader framing is set out on the EU desk in the master brief on what the Omnibus changed.

For an operator outside the Union this matters more than the deferral did, because the deferral bought time on duties most non-EU operators were not carrying anyway, while Article 50 lands on exactly the products they do ship.

Section 2. Four duties, two roles

Article 50(1), the provider's interaction disclosure. Providers ensure that AI systems intended to interact directly with natural persons are designed and developed so that the persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. There is an exception for systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to safeguards and except where those systems are available for the public to report a criminal offence.

Article 50(2), the provider's marking duty. Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content ensure that the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The technical solutions have to be effective, interoperable, robust and reliable as far as technically feasible, taking into account the specificities and limitations of various types of content, implementation costs and the generally acknowledged state of the art. Exceptions cover systems performing an assistive function for standard editing or not substantially altering the input data or its semantics, and certain lawful criminal detection and prosecution uses.

Article 50(3), the deployer's notice. Deployers of an emotion recognition system or a biometric categorisation system inform the natural persons exposed to it of the operation of the system, and process personal data in accordance with the applicable data protection rules. An exception covers permitted law enforcement use, subject to safeguards.

Article 50(4), the deployer's disclosures. Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake disclose that the content has been artificially generated or manipulated, with an exception for law enforcement use and a modified requirement where the content forms part of an evidently artistic, creative, satirical or fictional work, in which case disclosure is made in an appropriate manner that does not hamper the display or enjoyment of the work. Deployers of a system that generates or manipulates text published with the purpose of informing the public on matters of public interest disclose that the text has been artificially generated or manipulated, unless the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. Deep fake is defined in Article 3(60) as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.

Article 50(5) applies to all of them: the information is provided to the persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure, and conforms with the applicable accessibility requirements. Article 50(6) preserves the other requirements of the Regulation and any other transparency obligations in Union or national law.

Section 3. The one relief, and when it closes

The European Commission states it in terms: a limited grace period is envisaged only for AI systems placed on the market before 2 August 2026 and only as regards the marking and detection obligation for AI-generated content in Article 50(2), and providers of such systems must comply with those obligations only as from 2 December 2026.

Three things follow. The relief is per system and not per company, which means a provider needs the date of placing on the market recorded for each product rather than a general belief about when it started selling into the Union. It covers one paragraph, so the interaction disclosure in Article 50(1) and the deployer duties in Article 50(3) and (4) have been live since August with no transition at all. And a system first placed on the Union market after 2 August 2026 never had the relief, which catches the common case of a product that expanded into the Union recently.

Section 4. Why an operator outside the Union is inside the scope

Article 2(1)(a) applies the Regulation to "providers placing on the market or putting into service AI systems or placing on the market general-purpose AI models in the Union, irrespective of whether those providers are established or located within the Union or in a third country". Article 2(1)(b) covers deployers that have their place of establishment or are located within the Union. Article 2(1)(c) extends it to providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union.

Point (c) is the one that surprises people, and it is the one worth reading slowly, because it is not about where the system runs or where the company is. It is about where the output is used. This desk has examined the wider scope question, including what that trigger does and does not reach, in the guide to the Act's reach over companies in the United States and the United Kingdom, and the new dates for non-EU operators in the Omnibus note. Two cautions belong here. The page serving Article 2 carried an amendment notice on 25 September 2026, so the text quoted above is the unamended one. And a scope conclusion for a specific product is a legal question about that product, not something a general article settles.

The practical position for most global operators is simpler than the scope analysis. If you serve customers in the Union, or your generated output is used there, plan on the basis that Article 50 reaches the product, and spend the effort on the implementation rather than on the argument.

Section 5. Marking is global, disclosure is local

This is the design point, and it is the one that separates teams who implement Article 50 cleanly from teams who implement it twice.

Marking under Article 50(2) is a property of the generation pipeline. Something is written into or alongside the artefact at the moment it is produced. Whatever is decided about it is decided once, in the part of the system furthest from any notion of a user's location, and it applies to every output that pipeline emits.

Disclosure under Article 50(1), (3) and (4) is a property of the interface. A line of text, a label, a notice at first exposure. Interfaces are already localised, already varied by market, and already owned by teams who change them weekly.

Treating both as regional settings is where the failure mode lives. Conditioning a marking behaviour on an inferred user location means the inference becomes load bearing: a user on a VPN, an API call from a customer's server, a batch export consumed somewhere nobody modelled, and the output goes out unmarked. Conditioning a disclosure string on the market being served is ordinary product work with an ordinary failure mode, which is that a string is missing on one surface.

This desk does not tell an operator to mark everything everywhere. That is a commercial judgement, and there are products where marking carries a real cost. The recommendation is narrower: decide it deliberately, write down which outputs are marked and which are not, and do not let the answer depend on a runtime guess about who is reading. The evidence standard that follows from that decision is set out at agentcertified.eu, on provenance as certification evidence.

Section 6. What the text does not say

Article 50(2) names no technology, no file format and no standard. It sets a functional test and points at the generally acknowledged state of the art, which is a moving reference rather than a list. Anyone telling a non-EU operator that a particular scheme is required by the Act is stating something the Act does not contain.

What exists alongside the text is voluntary. The European Commission describes a Code of Practice on Transparency of AI-generated content as a voluntary practical tool to help providers and deployers of generative AI systems demonstrate compliance with the marking and labelling obligations. This desk has not read that code and does not describe its contents, its status or its signatories. An operator deciding what to implement should read it directly rather than through a summary, including this one.

The Act also does not say how a recipient reads a mark, which is the interoperability half of the same sentence, and it does not set a survival threshold against ordinary transformations such as recompression or screenshotting. Those gaps are real, they are known, and the honest position for an operator is to record what its implementation does and does not survive rather than to claim a compliance it cannot demonstrate.

Section 7. What to hold on 2 December 2026

Five records, each of which takes hours rather than weeks, and none of which can be produced retrospectively with any credibility.

A per system date of first placing on the Union market, because the relief turns on it and a company level answer is not an answer.

A list of the output paths by which generated content leaves each system, with the marking status of each, reconciled against configuration rather than against memory.

A record of which exception is relied on for any path that is not marked, with the limb of the paragraph, the decision maker and the date.

A screenshot or reference implementation of each disclosure as a person encounters it, for the Article 50(1), (3) and (4) duties, including its accessibility treatment.

A statement of what was not tested or not covered, dated. The absence of that statement is what makes the other four hard to trust.

For an operator that also supplies into the Union through a reseller or a representative, those records are the ones the Union counterparty will eventually ask for, for its own reasons, alongside the product liability questions examined in the importer and representative chain.

Questions

Did the AI Omnibus delay the Article 50 transparency obligations?

No. The deferrals introduced by Regulation (EU) 2026/1744 moved the high-risk obligations, to 2 December 2027 for stand alone Annex III systems and 2 August 2028 for Annex I systems embedded in regulated products. Article 50 is a transparency provision rather than a high-risk one, and the European Commission states that it applies as from 2 August 2026.

Does the EU AI Act apply to a company with no establishment in the Union?

It can. Article 2(1)(a) covers providers placing on the market or putting into service AI systems in the Union irrespective of whether those providers are established or located within the Union or in a third country. Article 2(1)(c) extends the Regulation to providers and deployers located in a third country where the output produced by the AI system is used in the Union. Establishment is not the test.

What is the 2 December 2026 marking deadline?

It is the end of the only transitional relief in Article 50. The European Commission states that a limited grace period is envisaged only for AI systems placed on the market before 2 August 2026 and only as regards the marking and detection obligation in Article 50(2), and that providers of such systems must comply only as from 2 December 2026. Systems placed on the market on or after 2 August 2026 never had the relief.

Should a global product mark all of its output or only output reaching the Union?

That is a commercial and engineering judgement rather than a legal requirement, and this desk does not prescribe an answer. The structural point is that marking is a property of the generation pipeline while disclosure is a property of the interface. Conditioning a marking behaviour on the inferred location of a user adds a failure mode, because the inference can be wrong and the output then goes out unmarked.

Is there an approved technical standard for machine-readable marking?

The text of Article 50(2) names no technology and no standard. It sets a functional test and refers to the generally acknowledged state of the art. The European Commission describes a Code of Practice on Transparency of AI-generated content as a voluntary practical tool for demonstrating compliance with the marking and labelling obligations. This desk has not read that code and does not describe its contents.

Who carries the deep fake disclosure duty, the provider or the deployer?

The deployer. Article 50(4) places the disclosure of artificially generated or manipulated deep fake content on deployers of the system, with exceptions for law enforcement use and a modified form of disclosure for evidently artistic, creative, satirical or fictional work. The provider's corresponding duty is the machine-readable marking in Article 50(2), which is a different obligation discharged in a different place.

Section 9. Sources

Sources

  • Regulation (EU) 2024/1689 (EU AI Act), Article 50, paragraphs 1 to 7, read at the European Commission AI Act Service Desk, ai-act-service-desk.ec.europa.eu, on 25 September 2026. That page carried a notice stating that the provision has been amended by the Digital Omnibus on AI and that the displayed text had not yet been updated. No amended text of Article 50 was read for this article.
  • Regulation (EU) 2024/1689, Article 2(1), points (a) to (g), read at ai-act-service-desk.ec.europa.eu on 25 September 2026. The quotation in section 4 is verbatim from point (a) as served. That page carried the same amendment notice.
  • Regulation (EU) 2024/1689, Article 3(60) (definition of deep fake), read at ai-act-service-desk.ec.europa.eu on 25 September 2026.
  • The application date of 2 August 2026 for Article 50, the limited grace period for Article 50(2), the date of 2 December 2026, the formulation of the reasonably well-informed average person, and the description of the Code of Practice on Transparency of AI-generated content as a voluntary practical tool, all read at digital-strategy.ec.europa.eu on 25 September 2026. That page is the European Commission's own transparency FAQ. The code of practice itself was not read.
  • Regulation (EU) 2026/1744 (the AI Omnibus), under which Annex III high-risk obligations apply from 2 December 2027 and Annex I obligations from 2 August 2028, as published by the European Commission at digital-strategy.ec.europa.eu.
  • The asymmetry argument in section 5, the failure mode described there, and the five records in section 7 are this desk's own analysis. They are not requirements of the Regulation and are not attributed to any authority, standards body or company.
  • No national measure of any Member State, no law of any jurisdiction outside the Union, and no rule on jurisdiction or enforcement was read for this article, and none is described in it.