This informal CPD article, ‘The Deadline That Moved and the Duty That Did Not: AI Act Transparency Obligations After the Digital Omnibus’, was provided by Nikolas Demetriades, CFA, who holds the CySEC Advanced and AML certifications. He is the founder of CPDs.Academy, a CPD training platform delivering compliance education for professionals in EU-regulated financial services.
The Artificial Intelligence Act arrives in stages, and 2 August 2026 was the date on which most of it became applicable (1). Six days earlier, the timetable changed. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal on 24 July 2026 and in force three days later (2). Describing that change simply as a delay to the AI Act is too broad. The omnibus deferred specified requirements for high-risk AI systems and amended a number of other provisions besides. The general application date survived, and with it the transparency obligations in Article 50, which became applicable on 2 August 2026 (1), (2).
What the omnibus actually moved
Article 113 governs when each part of the Regulation applies. As adopted it applied from 2 August 2026, with earlier dates for the prohibited practices and the general-purpose AI provisions (1). The omnibus rewrote that Article's third paragraph. The Chapter III, Sections 1, 2 and 3 requirements for high-risk systems classified under Article 6(2) and Annex III now apply from 2 December 2027, and for systems classified as high-risk under Article 6(1) and Annex I to which those requirements apply, the date is 2 August 2028 (2). Article 6(1) covers AI intended as a safety component of a product governed by the Union harmonisation legislation in Annex I, or AI that is itself such a product, where the relevant third-party conformity assessment is required (1).
A further qualification attaches to products governed by Section B of Annex I legislation. As amended by the omnibus, Article 2(2) limits which provisions of the AI Act apply directly to high-risk systems related to those products (1), (2). The 2 August 2028 date should not be read as a single blanket Chapter III compliance date for every product category in Annex I.
The reasons stated in the legislation were principally practical and concerned implementation readiness. Harmonised standards, common specifications and guidance were not available in time, and preparations by national competent authorities had lagged (2).
Chapter IV, which houses the transparency obligations, received no new date. Article 50 had never carried one of its own, so it fell under the general application date, which the amendment left in place (1), (2). A compliance calendar built around 2 December 2027 alone omits duties live since August 2026.
What Article 50 requires
Article 50 allocates duties by legal role (1). A provider is not only a business that supplies an AI system to someone else. Article 3(3) also catches an organisation that develops, or has developed, a system and puts it into service under its own name or trademark. A deployer, by contrast, is a person using an AI system under its authority, and one organisation can be both (1), (3). Two duties fall on providers. One concerns systems intended to interact directly with natural persons, which must be designed so that those persons are informed they are interacting with an AI system, unless that would be obvious to a reasonably well-informed, observant and circumspect person in the circumstances and context of use, account being taken of people in vulnerable groups, including because of age or disability (1). Another applies to systems, general-purpose AI systems included, generating synthetic audio, image, video or text content, whose outputs must be marked in machine-readable format and detectable as artificially generated or manipulated (1).
A deployer of an emotion recognition or biometric categorisation system must inform the natural persons exposed to it that the system is operating and must process personal data in accordance with the applicable Union data protection instruments (1), (4). A deployer using an AI system to generate or manipulate image, audio or video content constituting a deep fake must disclose that it has been artificially generated or manipulated (1). Article 3(60) defines that term more widely than a likeness of a real individual, covering AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic or truthful (1).
A separate limb addresses text. Where a deployer uses an AI system to generate or manipulate text published to inform the public on matters of public interest, the artificial generation or manipulation must be disclosed (1). The exception is narrower than it looks, applying where the content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication (1). Editorial responsibility here means ultimate responsibility for publishing rather than authorship. The Commission's guidance is explicit that superficial or purely procedural checks, spell-checking and grammatical correction among them, do not count as human review or editorial control (3).
Article 50(5) sets a common presentational standard for the information required under paragraphs 1 to 4. The information must reach the natural persons concerned in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure, and must conform to the applicable accessibility requirements (1).
Several duties are qualified. Marking does not apply where a system performs an assistive function for standard editing, or leaves the deployer's input data and its semantics substantially unaltered (1). Where deep-fake content forms part of an evidently artistic, creative, satirical, fictional or analogous work, disclosure narrows to revealing that generated content exists without hampering enjoyment of the work (1). Each duty is also disapplied for specified law enforcement purposes (1).
The one concession, and how narrow it is
On transparency the omnibus granted one measure of relief. A new paragraph added to Article 111 gives providers of AI systems generating synthetic audio, image, video or text content, where those systems were already on the market before 2 August 2026, until 2 December 2026 to comply with the marking obligation in Article 50(2) (2). The stated purpose was a four-month transitional period for existing providers (2). The relief attaches to the Article 50(2) marking duty alone, leaving the other paragraphs unaffected. For a firm acting only as deployer, it does not postpone any transparency obligation imposed on the deployer itself (2).
Some detail has since been settled. Article 50(7), as amended, requires the Commission to encourage and facilitate Union-level codes of practice on the detection, marking and labelling of artificially generated or manipulated content. Taking utmost account of the AI Board's opinion, the Commission assesses whether adherence to such a code is adequate to ensure compliance with the relevant obligations in Article 50(2) and (4) (2). The final Code of Practice on Transparency of AI-generated Content was published on 10 June 2026, and the Commission and the AI Board have confirmed it as an adequate voluntary tool for demonstrating compliance with the obligations it covers, those in Article 50(2), (4) and (5) (5). Adherence to the Code is voluntary. The obligations in Article 50 are not. The Commission adopted its Guidelines on 20 July 2026 (3).
Why the penalties are not theoretical
Non-compliance with Article 50 attracts a fine of up to EUR 15,000,000 or, if the offender is an undertaking, up to 3% of its total worldwide annual turnover for the preceding financial year, whichever is higher (1). For the prohibited practices the figures are EUR 35,000,000 or, again where the offender is an undertaking, 7% (1). For small and medium-sized enterprises, including start-ups, the ceiling is the lower of the fixed amount and the percentage rather than the higher (1).
Enforcement is shared. Much of it falls to the market surveillance authorities designated by the Member States, but the AI Office has a role for systems within its competence, and the European Data Protection Supervisor enforces the rules for AI systems used by Union institutions, bodies and agencies (3). Preparations at national level had been slow (2), and enforcement intensity may vary as the regime develops. That bears on the likelihood of early scrutiny rather than on whether a duty exists, since an obligation applies whatever the authority's readiness.
What it means for firms
Article 50 is not a general rule about customer-facing AI. It is triggered in defined situations, and which applies turns on the system and its use. For providers, the obligations concern systems intended to interact directly with natural persons and systems generating synthetic content subject to the marking duty, and they can catch an organisation that puts such a system into service under its own name without supplying it to anyone (1). The others fall on the deployer, arising on deployment of an emotion recognition or biometric categorisation system, and where a firm is acting as deployer of an AI system used to generate or manipulate image, audio or video content constituting a deepfake, or acting as deployer of an AI system used to generate or manipulate text published to inform the public on matters of public interest (1). A use of AI meeting none of these does not engage Article 50, though it may engage other parts of the Regulation.
Those triggers turn on authority over the AI system rather than proximity to the content (1). A firm that receives, hosts, broadcasts or redistributes AI-generated material produced by somebody else's system does not thereby become its deployer, so dissemination alone does not create Article 50 status. The position differs where a third party operates a system on the firm's behalf and under its responsibility and control, in which case the firm remains the deployer (3).
Article 50(1) places its obligation on the provider (1). A firm does not assume that provider duty merely by deploying a third-party chatbot. Its concern is whether the provider's disclosure actually appears in the customer journey as configured, and by the first interaction (1).
Synthetic voice does not, of itself, fall within Article 50(1). The Commission's guidance treats the direct-interaction duty as requiring a genuine two-way exchange, so an interactive voice agent conversing with a caller differs from a one-way recorded announcement (3). Separately, synthetic audio generated by an AI system may fall within the provider-side marking obligation in Article 50(2), subject to that provision's exceptions and the qualifications set out in the Commission's guidance (1), (3).
Ordinary AI-generated marketing copy does not attract the deployer disclosure duty in Article 50(4) merely because a model produced it. It reaches text published to inform the public on a matter of public interest, and then only where the exception for human review or editorial control with editorial responsibility is unavailable (1). Whether a person has been named is not the legal test. Where a firm itself acts as deployer of the AI system used to generate or manipulate a promotional video, Article 50(4) disclosure is required if the resulting material constitutes a deepfake under Article 3(60) (1). A company that commissions an advertising agency, without deciding or controlling whether or how the agency uses AI, is not on that basis the deployer of the agency's system (3).
The Regulation is horizontal legislation, applying by how a system is used rather than by sector, so it is relevant well beyond the technology sector (1). The same Article 50 framework can apply across sectors, although the duties depend on the system, the use case and the organisation's role. The Regulation also recognises a connection between artificially generated content and the systemic risk responsibilities of very large online platforms and search engines under the Digital Services Act (1), (6). That is an acknowledged interaction between two regimes, not a mechanism by which one firm's disclosure creates a fresh obligation for an intermediary.
Vendor assurance does not settle the question. Marking under Article 50(2) is a provider obligation, and deployer disclosure duties arise only where Article 50(3) or Article 50(4) is engaged (1).
Closing thoughts
In specified circumstances people must be informed that they are interacting with an AI system, or exposed to particular categories of AI-generated or manipulated content, while providers separately carry marking obligations for qualifying synthetic outputs (1). Not every AI-generated item attracts a human-facing disclosure. These obligations became applicable on 2 August 2026. Firms that treated the high-risk extension as a general postponement of the AI Act risk overlooking duties that already apply.
We hope this article was helpful. For more information from CPDs.Academy, please visit their CPD Member Directory page. Alternatively, you can go to the CPD Industry Hubs for more articles, courses and events relevant to your Continuing Professional Development requirements.
References
(1) Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), including Article 2(2) on systems related to Section B of Annex I products, Article 3(3) defining a provider, Article 3(4) defining a deployer, Article 3(60) defining a deep fake, Article 6 on the classification of high-risk AI systems, Article 50 on transparency obligations for providers and deployers of certain AI systems, Article 99 on penalties, Article 111 on systems already placed on the market, Article 113 on entry into force and application, and recital 132 on taking account of persons belonging to vulnerable groups.
(2) Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI), published in the Official Journal of 24 July 2026 and in force from 27 July 2026. It amends the third paragraph of Article 113 of Regulation (EU) 2024/1689, adds a new paragraph 4 to Article 111 and replaces Article 50(7).
(3) European Commission, Guidelines on transparency obligations for providers and deployers of certain AI systems under Article 50 of Regulation (EU) 2024/1689, adopted 20 July 2026, together with the Commission's accompanying guidance on those obligations.
(4) Regulation (EU) 2016/679 (General Data Protection Regulation), Regulation (EU) 2018/1725 and Directive (EU) 2016/680, to which Article 50(3) of Regulation (EU) 2024/1689 refers, as applicable.
(5) Code of Practice on Transparency of AI-generated Content, final version published 10 June 2026, which the European Commission and the AI Board have confirmed to be an adequate voluntary tool for demonstrating compliance with the obligations in Article 50(2), (4) and (5) of Regulation (EU) 2024/1689.
(6) Regulation (EU) 2022/2065 of the European Parliament and of the Council of 19 October 2022 on a Single Market For Digital Services (Digital Services Act), in particular the systemic risk obligations of providers of very large online platforms and very large online search engines.