EU AI Act updates
Article 50, the EU AI Act's transparency chapter, has applied since 2 August 2026. The ground around it keeps moving: Commission guidelines, a code of practice and an amendment law. National enforcement machinery is still being assembled. This page is a running record of what has actually changed for operators bound by the transparency duties. Every entry is dated and sourced to a primary document. We track Article 50 because we scan for it.
Where the law stands, August 2026
- Since 2 Aug 2026
- The Article 50 transparency duties apply: chatbot disclosure (50(1)), machine-readable marking of synthetic media (50(2)), notice of emotion recognition and biometric categorisation (50(3)), and visible labels for deepfakes and AI-generated public-interest text (50(4)).Penalties are available from the same day. Full guide →
- Until 2 Dec 2026
- One narrow grace period: machine-readable marking only, and only for generative systems already on the market before 2 Aug 2026.What this date does and doesn't cover →
- Fines
- Up to €15M or 3% of worldwide annual turnover, whichever is higher — for SMEs and start-ups, whichever is lower.Art. 99(4)(g), 99(6).
- From 2 Dec 2027
- High-risk duties for Annex III systems.Moved from Aug 2026 by the Digital Omnibus, Regulation (EU) 2026/1744.
- From 2 Aug 2028
- High-risk duties for AI embedded in Annex I regulated products.
- UK / US sites
- In scope whenever the system's output is used in the EU.There is no general small-business exemption.
Next dates
- 2 Dec 2026 — the 50(2) marking grace period for pre-August-2026 generative systems expires; the new prohibitions on nudification and CSAM generators also take effect.
- 1 Jan 2027 — US state AI-disclosure laws apply: Colorado SB 26-189 (automated decision-making transparency), Oregon SB 1546 and Washington HB 2225 (companion-chatbot disclosure — overview).
- 2 Dec 2027 — the Annex III high-risk regime applies.
- 2 Aug 2028 — the Annex I high-risk regime applies.
The record, newest first
State of play
Who can actually fine: the authority map is still incomplete
Enforcement of Article 50 belongs to national market-surveillance authorities. The map is incomplete: as of March 2026 only 8 of 27 member states had notified their single points of contact (EPRS), and roughly nine have clearly designated a lead authority — among them Italy (ACN), Malta (MDIA), Finland (Traficom), Denmark, Cyprus, Hungary, Ireland, Lithuania and Slovenia. Germany's draft KI-MIG act hands the role to the Bundesnetzagentur; Spain built AESIA. Austria, Belgium, Bulgaria, Croatia, Estonia and Greece have designated nobody. No Article 50 enforcement action had been recorded anywhere when this entry was written. The duties apply regardless.
Sources: National implementation tracker (FLI)
Application date
Article 50 applies, and so do the penalties
The four transparency duties became applicable across the EU: chatbot disclosure (Article 50(1)), machine-readable marking of synthetic media (50(2)), notice of emotion recognition and biometric categorisation (50(3)), and visible labels for deepfakes and AI-generated public-interest text (50(4)). Breaches fall under Article 99(4)(g): fines up to €15 million or 3% of worldwide annual turnover, whichever is higher — for SMEs and start-ups, whichever is lower. The Commission's power to fine general-purpose AI model providers under Article 101 switched on the same day.
For website owners: if your site runs an AI chat widget or publishes AI-generated content, these duties are live now. There is no general grace period.
Sources: Article 113 (application dates) · Article 99 (penalties)
Official Journal
The Digital Omnibus is law, and it did not move Article 50
Regulation (EU) 2026/1744 — the Digital Omnibus on AI — was published in the Official Journal on 24 July and entered into force on 27 July. It moved the high-risk regime (Annex III systems to 2 December 2027, Annex I products to 2 August 2028) and added prohibitions on nudification and CSAM generators with a transitional period to 2 December 2026. It did not move Article 50. The one transparency concession it confirmed: machine-readable marking under 50(2) is deferred to 2 December 2026, and only for generative systems already on the market before 2 August 2026. Chatbot disclosure and the labelling duties received no grace.
Sources: EUR-Lex — Regulation (EU) 2026/1744
Commission
The Commission's final Article 50 guidelines land
The European Commission adopted its final Guidelines on the Article 50 transparency obligations: 51 pages, non-binding, and the reference document national authorities are expected to work from when they assess a system. The final text followed a March draft and a public consultation, and arrived thirteen days before the duties applied. When an authority asks whether a disclosure was clear and distinguishable at first interaction, this is the document its reading will come from.
Sources: Commission guidelines (library page)
Adequacy decision
The transparency Code of Practice is confirmed adequate
The Commission (8 July) and the AI Board (9 July) concluded that the Code of Practice on Transparency of AI-generated Content is an adequate voluntary tool for implementing Articles 50(2), (4) and (5). Around 190 companies and organisations had signed by late July; the initial signatory list closed on 27 July, ahead of the application date. Signing remains voluntary — non-signatories must show they meet the duties by other means, assessed case by case by the market-surveillance authorities.
For website owners: adherence is a commitment on paper. What a visitor is actually shown on your pages is what an authority can check — and what a scan records.
Sources: Commission opinion on the Code · Signatories announcement
AI Office
The Code of Practice publishes, with the official EU icons
The AI Office published the final Code of Practice on Transparency of AI-generated Content: provenance and marking commitments for providers of generative systems, visible-labelling practice for deployers, and an official set of EU icons and text labels for AI content and deepfakes. The icon set gives deployers a recognisable, Commission-backed way to meet the visible-disclosure duties. It is not the only lawful way to disclose. The icons, explained →
Sources: Code of Practice (Commission page)
Common questions
Is the EU AI Act in force?
Yes, in stages. The transparency duties in Article 50 — chatbot disclosure, machine-readable marking of synthetic media, and visible labels for deepfakes and AI-written public-interest text — have applied since 2 August 2026, with penalties available from the same day. The high-risk regime follows later: 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products, after the Digital Omnibus moved those dates.
Is there a grace period for the transparency rules?
Only one, and it is narrow: machine-readable marking under Article 50(2) is deferred to 2 December 2026 for generative AI systems that were already on the market before 2 August 2026. Chatbot disclosure and the visible labelling duties have no grace period — they apply now, to everyone in scope.
Does the EU AI Act apply to UK and US companies?
Often, yes. The Act covers providers and deployers outside the EU whenever the system's output is used in the Union, so a UK or US site serving EU visitors is in scope. There is also no general small-business exemption: SMEs get a lower fine cap, not a pass on the duties.
Has anyone been fined under Article 50 yet?
No enforcement action had been recorded as of August 2026. The ceilings are real — up to €15 million or 3% of worldwide annual turnover, whichever is higher, and for SMEs whichever is lower — but fines come from national market-surveillance authorities, and many member states are still standing that machinery up. A late enforcer does not suspend the duty.
How often is this page updated?
At least monthly, and faster when something moves. Every entry is dated and linked to a primary source, and the review date in the page header changes only when the page has actually been re-checked.