What changed on 2 August 2026 and who is covered

On 2 August 2026, the EU began applying the transparency chapter of Article 50 of the AI Act and, in parallel, the Commission (through the AI Office) obtained full powers to enforce the obligations of general‑purpose AI (GPAI) models. For providers and deployers operating in the EU—whether or not they are established there—this translates into concrete technical and interface requirements, with potential penalties if non‑compliant from that date onward.

There is a narrowly scoped grace period: the obligations on machine‑readable marking and facilitating detection of synthetic content under Article 50(2) are deferred until 2 December 2026 only for generative systems that were already on the market before 2 August 2026. All other Article 50 obligations have applied without exception since 2 August 2026.

Dates, scope and who enforces

The AI Act sets a staged timeline: governance and GPAI obligations started applying on 2 August 2025; as of 2 August 2026 the Commission can investigate and sanction GPAI non‑compliance, while Article 50 applies to providers and deployers of systems that interact with people or generate synthetic content. In practice, the framework is mixed: national market surveillance authorities, the AI Office and the European Data Protection Supervisor (EDPS) have distinct competences.

As to fines and measures, authorities can demand documentation, assess systems and, where appropriate, impose administrative penalties proportionate to the gravity and duration of the infringement. For Article 50, the Commission’s guidance indicates penalties can reach up to EUR 15 million or 3% of the worldwide turnover from the preceding financial year, with mitigation for SMEs.

GPAI: obligations active since 2025 and enforceable since 2026

GPAI providers must, among other measures, publish a sufficiently detailed summary of the training content using the official template; establish a copyright policy that respects reservations of rights and use state‑of‑the‑art technologies to identify them; and make available to integrators the technical information necessary for them to meet their own duties. In addition, they must notify the AI Office without delay if their model meets systemic risk criteria, and report serious incidents and corrective actions.

To support implementation, the Commission has issued Guidelines for GPAI providers and a voluntary Code of Practice that operationalises transparency, copyright and safety. While the code is not mandatory, adherence offers a practical, verifiable pathway to compliance; those who do not adhere must demonstrate by other means how they satisfy Articles 53 and 55.

Transparency (Art. 50): marking, detection and visible notices

Article 50 requires providers to ensure that generative systems’ outputs are marked in a machine‑readable format and are detectable as generated or manipulated by AI. Techniques may include persistent metadata, watermarks or cryptographic provenance methods, provided they are effective, reliable, robust and interoperable to the extent technically feasible. This requirement coexists with the obligation to inform when a system interacts directly with people (chatbots, agents, avatars) unless it is obvious.

For deployers, the rule requires perceptible labels (visual/audible) on deepfakes and on generated or manipulated text published to inform the public on matters of general interest, unless there has been substantive human review and editorial responsibility. They must also disclose the use of emotion recognition or biometric categorisation to exposed individuals. The guidance clarifies exclusions such as standard editing and, in certain cases, source code or M2M outputs with no human exposure.

Grace periods and precise limits until 2 December 2026

The only active deferral covers marking and detection under Article 50(2) for systems already on the market before 2 August 2026, expiring on 2 December 2026. There is no obligation for retroactive labelling of content generated before 2 August 2026, although the Commission recommends it where feasible.

Across the broader framework, GPAI obligations have applied since 2025, with the Commission’s enforcement powers in force since 2026. Milestones for high‑risk systems progress in 2027–2028, but they do not alter what is already required of generative systems and GPAI in 2026.

Official guidance and codes: how requirements land in practice

The Commission has published Transparency Guidelines for Article 50 with operational definitions (e.g., when there is ‘direct interaction’, what a ‘deepfake’ is, what amounts to ‘human review’), interface examples and exception scenarios. In parallel, the Code of Practice on content transparency sets out a multi‑layer approach (marking + publicly accessible detection tools or via API), useful for aligning providers and platforms.

For GPAI, the Guidelines and Code of Practice include model documentation forms, safety guidance and an official template for the public training summary. In addition, the AI Office has enabled EU SEND as the channel to submit documentation (e.g., systemic risk reports, serious incidents) and to sign codes of practice.

Practical impact for generative apps: immediate adjustments

For products generating text, image, audio or video in the EU, priorities are clear: 1) implement machine‑readable marking consistently across all output channels; 2) add visible indicators in the interface where required (deepfakes; public‑interest informational texts without human editorial oversight); 3) publish a transparency policy and technical documentation describing limitations, capabilities and the marking/detection scheme; 4) enable admin controls for B2B customers to configure notices, export metadata and provenance logs.

Legal teams should map roles (provider vs deployer), confirm whether the underlying model is GPAI and whether it could qualify as systemic risk, and prepare workflows for information requests from authorities. On the engineering side, it is prudent to test the robustness of marking against compressions, crops and reposting, and to document exceptions (e.g., standard editing) with reproducible criteria.