The European Commission published its final 51-page Guidelines on Article 50 of the AI Act on July 20, giving providers and deployers exactly 13 days to reconfigure their products before transparency obligations begin applying on August 2. The compression isn’t accidental. Brussels has spent the year signaling that transparency, not high-risk classification, would be the first live front in AI Act enforcement, and the timing forces the market to treat DG CNECT’s interpretive text as operational rather than advisory.

Article 50’s scope is where the reach becomes clear. It’s not just high-risk systems. Chatbots, generative tools, deepfakes, emotion recognition, biometric categorization, and AI agents all fall inside four obligations: disclose to users when they’re interacting with AI, embed machine-readable marks on AI-generated outputs, and layer deployer-side disclosures on deepfakes and public-interest text.

The final draft softened the May version in ways providers had lobbied for. There’s no retroactive labeling; the trigger is date of generation for image, audio, and video, and date of publication for text. Legacy databases don’t have to be audited. Packaging doesn’t get reprinted. The AI Omnibus grandfathers marking obligations for systems already on the market before August 2.

Two caveats matter. Bird & Bird notes the Guidelines are non-binding and only the CJEU can authoritatively interpret the Act. And CDT Europe flags that disclosure duties extend to AI agents even when a provider can’t know in advance whether the agent will interact with third parties, an obligation that reads cleanly on paper and messily in deployment.

Enforcement splits across national market surveillance authorities, the AI Office, and the EDPS for EU institutions. Fines reach €15 million or 3% of worldwide annual turnover. Italy’s DPA, which fined character.ai this month over GDPR violations, has already shown what an activist regulator does with fresh authority.

Sources

Sources