Summary

  • Regulation (EU) 2024/1689 applies generally from 2 August 2026, bringing Article 50’s transparency duties into operation.
  • Providers of systems that interact directly with people must disclose the AI interaction unless it is obvious to a reasonably informed, observant and circumspect person, subject to stated exceptions.
  • Providers of systems generating synthetic audio, image, video or text must make outputs machine-readable and detectable as artificial or manipulated, within the rule’s feasibility and exception boundaries.
  • Deployers must inform people exposed to emotion-recognition or biometric-categorisation systems and disclose specified deepfakes and certain AI-generated public-interest text.
  • Required information must be clear and distinguishable no later than the first interaction or exposure.
  • The Commission-backed code is voluntary; an organisation that does not sign still has to demonstrate compliance through other adequate measures.

The date changes transparency from preparation to obligation

The operative event is the application date in the regulation, not the later publication time of an article describing it. From 2 August, organisations within Article 50’s scope move from implementation planning to a compliance surface that authorities can assess.

This is not a rule that every AI output must carry the same visible warning. Duties vary with the system, the operator’s role, the content and the context. A useful compliance map therefore begins with function and responsibility rather than a universal label.

Providers and deployers hold different controls

Providers design or place systems on the market; deployers use them in particular settings. Article 50 assigns technical marking of synthetic outputs to providers, while several human-facing disclosures sit with deployers. Direct-interaction notice is also a provider design duty.

The split matters in procurement. A deployer cannot assume that a vendor’s machine-readable marker satisfies its own deepfake or biometric notice. A provider cannot rely on a customer’s visible label to replace a required technical provenance control. Contracts need to state which evidence crosses that boundary.

Machine-readable provenance is not just a badge

For systems producing synthetic audio, images, video or text, the provider must make output detectable as artificially generated or manipulated in a machine-readable format. The regulation qualifies the duty by technical feasibility, content characteristics, implementation cost and the state of the art, and includes specified exceptions.

That creates an engineering requirement beyond adding a caption. Organisations need a marker that survives the intended delivery path, a way to test detectability and records showing which model or service inserted it. Downstream compression, screenshots and editing can weaken signals, so verification must follow the real distribution chain.

Human notice covers interaction and sensitive inference

People interacting directly with an AI system must generally be told, unless the fact is obvious under the regulation’s contextual test. Deployers of emotion-recognition and biometric-categorisation systems must also inform those exposed, subject to the legal exceptions.

The timing rule is practical: disclosure cannot be buried after the consequential moment. It must be clear and distinguishable by first interaction or exposure. That pushes product teams to design notices into the entry point rather than place them only in distant terms of service.

Deepfakes and public-interest text create a publishing duty

Deployers of systems generating or manipulating image, audio or video that constitutes a deepfake must disclose the artificial intervention. Artistic, creative, satirical and fictional works receive a tailored form of disclosure that should not obstruct enjoyment.

The provision also reaches AI-generated or manipulated text published to inform the public on matters of public interest. The regulation contains a qualification where human review or editorial control occurred and a person or legal entity holds editorial responsibility. The test is therefore not simply whether a model touched text; purpose, process and accountability matter.

The code is a compliance route, not the law itself

The Commission-supported code offers practices for marking and labelling. Signing is voluntary. Non-signatories do not breach Article 50 merely by declining the code, but they remain responsible for the underlying obligations and may need to explain how alternative measures are adequate.

That makes evidence design commercially important. A supplier should be able to show marker coverage, detection tests, notice placement, exception reasoning and governance records. A signature may standardise that proof; it does not replace implementation.

Transition language needs careful reading

The Commission says output generated and already made available before 2 August does not need retroactive labelling. It also describes a targeted proposed transition to 2 December for the Article 50(2) marking duty of some systems already on the market, contingent on adoption of the AI Omnibus measure.

Neither point is a general postponement. The first concerns old output already made available. The second is targeted, conditional and limited to a particular provider duty. Organisations should not use either to defer interaction notices, biometric disclosures or other obligations that already apply.

Sources