Illustrative composite scenario, 19 July 2026. A Vienna software company reads that the EU AI Act has been delayed. The legal update in the inbox is accurate: high-risk obligations moved to December 2027. The team closes the tab with relief, because nothing they run is high-risk. Their support chatbot answers 400 customer questions a week. Their marketing tool generates product descriptions and social copy. Neither is classified as high-risk. Both are in scope of an obligation that arrives on 2 August 2026, in fourteen days.

This composite reflects common production patterns; it is not a client case or claimed result. The failure here is not negligence. It is a reasonable executive reading a true headline about the wrong article.

The delay that was not

Two things happened in 2026 and they are frequently merged into one sentence. They should not be.

The first is the Digital Omnibus. A provisional political agreement reached on 6 May 2026, confirmed by the Council on 13 May 2026, moves the most operationally demanding parts of the AI Act. Stand-alone Annex III high-risk systems — recruitment scoring, credit decisions, education and similar uses — move from 2 August 2026 to 2 December 2027. AI embedded in regulated products under Annex I, such as medical devices and machinery, moves to 2 August 2028. This is a provisional agreement pending formal adoption and publication in the Official Journal; treat the dates as the intended landing point, not as settled law you can build a defence on.

The second is that Article 50 was left where it was. The transparency obligations apply from 2 August 2026. They were not part of the deferral. The single most broadly applicable duty in the entire Act is the one that did not move.

The reporting was not wrong. The inference was. "The AI Act was delayed" is true about high-risk and false about transparency, and the companies most likely to make that inference are precisely the ones Article 50 was written to reach.

Why Article 50 reaches further than high-risk ever did

High-risk classification is narrow by design. Most SMEs genuinely are outside Annex III, and their relief was justified as far as it went.

Article 50 does not work that way. It attaches to a behaviour, not a risk class. If an AI system talks to a person, or produces synthetic audio, image, video or text, the duty can apply regardless of how low-risk the use case is. A support chatbot on a plumbing supplier's website and a frontier model deployed by a bank sit on the same side of that line.

This inverts the usual compliance intuition. Under most of the AI Act, small and simple means out of scope. Under Article 50, small and simple is squarely in scope, and small and simple companies are the least likely to have read past the headline.

Enforcement follows. From 2 August 2026 national authorities and the AI Office can act on breaches of provider and deployer obligations, with exposure of up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. Whether any given breach attracts the maximum is a separate question — supervisory practice in Austria and Germany is still forming — but the ceiling is not theoretical.

Provider or deployer: the question that decides your duty

Article 50 does not impose one obligation on everyone. It splits duties between the party that puts a system on the market and the party that uses it. Getting your role wrong means preparing for the wrong obligation.

Roughly: if you build or rebrand an AI system and place it on the EU market, you carry provider duties under Article 50(1) and 50(2). If you operate someone else's system in your own business, you carry deployer duties under Article 50(3) and 50(4).

The trap is that a single company is usually both, and often both within one workflow. A firm running a vendor chatbot on its own site is a deployer of that chatbot. The same firm shipping an AI feature inside its own product is a provider of that feature. And a company that puts its own name on a white-labelled AI system may find it has become a provider of a system it did not build.

Role determination is case-specific and depends on contracts, branding and the degree of modification. This article gives you the method to ask the question properly. It does not answer it for your systems, and no article can.

MARK: four questions to answer before 2 August

Four questions, in order. The name deliberately echoes the marking duty in Article 50(2), because marking is the part teams discover last and need longest to build.

M — Map

Which of your systems interact directly with people, and which emit synthetic audio, image, video or text? This is narrower than "where do we use AI" and wider than "what did we procure." It includes features inside tools you bought for another purpose, and it includes AI that a department switched on without telling anyone.

A — Actor

For each mapped system, are you provider, deployer, or both? Record the reasoning and the contract clause it rests on, because this is the determination everything downstream inherits.

R — Reveal

What exactly is disclosed, on which surface, at which moment, in what form? A disclosure that exists in a document nobody opens is not a disclosure. This is the question most teams answer too cheaply.

K — Keep

What evidence shows the disclosure was live, in that form, on that date? Compliance you achieved but cannot demonstrate is indistinguishable from compliance you skipped, at exactly the moment it matters.

The four duties of Article 50 in operational terms

The text of the obligations is published by the Commission's AI Act Service Desk. What follows is the operational translation, not a substitute for the legal text.

Article 50 duties, roles and operational meaning
ProvisionWho owes itTriggerWhat compliance looks like in practice
50(1)ProviderAI system intended to interact directly with peopleThe person is informed they are dealing with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person
50(2)ProviderSystem generates synthetic audio, image, video or textOutput is marked in a machine-readable format and detectable as artificially generated or manipulated; the solution must be effective, interoperable, robust and reliable
50(3)DeployerEmotion recognition or biometric categorisation systemExposed persons are informed of the operation, and data protection law is complied with in parallel
50(4)DeployerDeepfakes; AI-generated text published to inform the public on matters of public interestThe artificial origin is disclosed; lighter, non-intrusive disclosure applies to evidently artistic, creative, satirical or fictional work; editorially reviewed text carries its own carve-out

Exceptions exist in each provision — law enforcement uses, assistive editing functions, systems that do not substantially alter input, editorial review. They are narrow, and reading yourself into one without documented reasoning is a decision you will have to defend later.

Product interface showing an AI disclosure notice placed at the point of interaction rather than buried in documentation
Disclosure has to live on the surface where the interaction happens; placement and timing carry the obligation, not the existence of a policy document.

What the Commission says is not enough

In parallel with the deadline, the Commission published draft guidelines on implementing the Article 50 obligations, with a targeted consultation that closed on 3 June 2026. These are a draft. They indicate the Commission's thinking; they are not the final word, and the final text may shift.

Two signals in that draft are worth acting on now, because both close off approaches teams reach for first.

A reference buried in terms and conditions or product documentation is treated as insufficient for the Article 50(1) duty. The obligation is to inform the person interacting with the system, and a link they never open does not inform them.

Technical marking alone — metadata or a watermark — is likewise treated as insufficient for that same duty. Machine-readable marking is its own obligation under 50(2); it does not discharge the duty to tell a human being they are talking to a machine. The draft points toward a combination: a clearly visible plain-language notice, a persistent visual indicator, and audio cues where the interaction is spoken.

Read together, these push the disclosure out of the legal layer and into the product layer. That is a design and engineering task with a fourteen-day runway, not a document review.

The 2 December 2026 window, and who actually gets it

There is one genuine extension inside Article 50, and it is routinely overstated.

Generative AI systems already placed on the market before 2 August 2026 get until 2 December 2026 to meet the machine-readable marking requirement under Article 50(2). That is four extra months, for one obligation, for systems that already exist.

It does not extend the 50(1) duty to disclose AI interaction. It does not extend the 50(4) deepfake duty. It does not apply to a system you launch in September. If your compliance plan rests on "we have until December," check that the sentence survives contact with those three limits, because in most cases it does not.

Who will actually be asking, in Austria and Germany

An EU regulation is enforced by national authorities, and in DACH those authorities are still assembling. That is a reason to prepare earlier, not later.

In Austria, the KI-Servicestelle established within RTR currently supports organisations in understanding their AI Act obligations and provides guidance. It is positioned to develop into the national authority responsible for market surveillance and related duties as the Act becomes fully applicable, at which point the enforcement powers and sanctions in the Act sit behind it. In Germany, the draft KI-Marktüberwachungs- und Innovationsförderungsgesetz would make the Bundesnetzagentur the central coordinator and market surveillance authority. That legislation is a draft, and its final shape is not settled.

The practical read is that the first months after 2 August 2026 are unlikely to look like aggressive enforcement, and equally unlikely to look like nothing. Guidance-first supervision still asks questions, and the answer "we assumed we were out of scope" is materially worse than "here is our scope determination, here is what we disclosed, here is the date." That is analysis of supervisory posture, not a prediction of any authority's conduct.

For companies operating across the DACH region, the same product often faces two supervisors with different timelines and vocabularies. Documenting the reasoning once, in a form both can read, is cheaper than reconstructing it twice.

Where disclosure actually lives: surface, timing, tone

Once disclosure is a product question, three decisions follow, and none of them are legal decisions.

Surface. The disclosure belongs where the interaction is, not where the documentation is: in the chat window, on the generated asset, in the voice flow. If a user can reach the AI without passing the disclosure, the surface is wrong.

Timing. Before or at the first interaction, and persistently enough that a user arriving mid-session is not misled. A notice that appears once and disappears fails users who scroll back or return the next day.

Tone. Plain language beats legal language, and this is where teams over-engineer. "You're chatting with an AI assistant. A human can take over any time." does more compliance work than a paragraph of defined terms, and it costs less trust.

There is a commercial argument here that has nothing to do with regulation. Clear AI disclosure is becoming a trust signal in DACH B2B, where buyers increasingly ask how a supplier uses AI before they ask what it costs. Companies treating this as a design opportunity will land somewhere better than companies treating it as a warning label. That is analysis, not a legal claim.

Evidence: proving a disclosure you already made

The pattern from every other compliance regime repeats here. The organisation did the right thing, cannot show it did the right thing on the relevant date, and argues from memory. Article 50 disclosures are especially easy to lose because they live in interfaces that ship continuously.

Minimum evidence record per disclosing system
RecordWhy it mattersOwner
System identity and role determinationFixes whether you owe provider or deployer duties, and on what reasoningAI system owner
Disclosure text, surface and screenshot, versionedShows what a user actually saw, not what a policy intendedProduct owner
Effective-from and changed-on datesAnswers the only question a supervisor asks: was it live then?Product owner
Marking method and detectability test resultSubstantiates the 50(2) claim rather than asserting itEngineering
Exception relied on, with reasoningTurns an implicit assumption into a defensible documented decisionLegal and system owner
Vendor attestation for procured systemsEstablishes what the provider claims, and what you still oweProcurement

This is the same discipline as an AI system inventory, applied to one narrow question. If that inventory already exists, the fourteen-day sprint below is realistic. If it does not, the inventory is the sprint.

Structured evidence record linking an AI disclosure notice to its version date owner and detectability test result
A disclosure without a dated, owned record is a compliance position that cannot be reconstructed once the interface has shipped three more times.

The fourteen-day sprint before 2 August

Fourteen days is not enough to build a governance programme. It is enough to close the gap between systems you did not know were in scope and disclosures that do not exist.

Days 1-4: map and classify

  1. List every system that talks to people or generates synthetic content, including features inside tools bought for other purposes.
  2. For each, record provider or deployer, and the reasoning behind it.
  3. Flag anything customer-facing or public-facing as first priority; internal-only systems can follow.
  4. Name one accountable owner per system. Unowned systems are where deadlines are missed.

Days 5-9: reveal

  1. Write the disclosure text in plain language, per system and per language you operate in.
  2. Place it on the interaction surface, not in documentation, and make it persistent.
  3. Ask vendors in writing what marking they apply under 50(2) and what they claim about detectability.
  4. Decide deliberately on deepfake and public-interest text disclosure under 50(4), even if the answer is that it does not apply.

Days 10-14: keep and verify

  1. Capture dated screenshots and version records for every live disclosure.
  2. Test that a user reaching the system by any route encounters the disclosure.
  3. Document every exception you rely on, with the reasoning, in writing.
  4. Assign the person who reviews this after 2 August, because interfaces keep shipping.

The 30/60/90 durable track

The sprint buys you the deadline. It does not leave you with a system that stays compliant while your product changes weekly.

Day 1-30

Fold Article 50 scope into the AI system inventory so new systems are classified at intake rather than audited later. Add a disclosure question to the procurement checklist. Define what evidence is captured automatically versus manually.

Day 31-60

Make disclosure a release-gate item: no AI-facing feature ships without a disclosure decision and a dated record. Validate vendor marking claims rather than accepting them. Track the finalisation of the transparency guidelines and the Code of Practice on marking and labelling of AI-generated content, and re-check your approach against the final text.

Day 61-90

Run an internal review as if you were a supervisor: pick three systems, ask what a user saw and when, and see whether the evidence answers. Extend to the AI literacy obligation, which has applied since February 2025 and is widely under-implemented across DACH. Decide what changes when the deferred high-risk obligations arrive in December 2027, while there is still time to design rather than react.

What the official sources support

The Commission's AI Act Service Desk page for Article 50 carries the authoritative text of the four transparency provisions and their exceptions. The draft guidelines on implementing the Article 50 transparency obligations set out the Commission's current thinking, including on insufficient disclosure methods; they remain a draft following the consultation that closed on 3 June 2026. The Code of Practice on marking and labelling of AI-generated content is being finalised in parallel and will shape what "effective, interoperable, robust and reliable" marking means in practice.

The Digital Omnibus deferral of high-risk obligations is a provisional political agreement pending formal adoption. Classification of any specific system, and the role you hold in relation to it, is case-specific. Nothing above is legal advice.

FAQ

Was the EU AI Act delayed?

Partly. High-risk obligations moved under a provisional political agreement — Annex III systems to 2 December 2027 and Annex I embedded systems to 2 August 2028. The Article 50 transparency obligations were not deferred and apply from 2 August 2026.

Does Article 50 apply to my company if I have no high-risk AI system?

It can. Article 50 attaches to behaviour rather than risk class: systems that interact directly with people, or that generate synthetic audio, image, video or text. A low-risk support chatbot can be in scope while nothing you run is high-risk.

Is a note in our terms and conditions sufficient disclosure?

The Commission's draft guidelines treat a reference in terms and conditions or product documentation as insufficient for the Article 50(1) duty, and treat metadata or watermarking alone as insufficient for it as well. The direction is a visible plain-language notice on the interaction surface.

What is the 2 December 2026 deadline?

A limited grace period. Generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking requirement under Article 50(2). It does not extend the other Article 50 duties or cover systems launched after 2 August 2026.

What are the penalties for breaching Article 50?

Exposure for breaches of provider and deployer obligations runs up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. How supervisory authorities in Austria and Germany will apply this in practice is still developing.

Next step

Bring the systems that talk to your customers, the tools that generate your content, your vendor contracts, and whatever inventory you already have. As an AI Systems Architect, Ali Najafzadeh maps Article 50 scope, decides provider and deployer roles with you, designs the disclosure surfaces, and leaves you with a dated evidence record rather than an opinion. Book an AI Systems Review.