Javascript is required
logo-dastralogo-dastra

AI Act Transparency Rules: What Changes August 2, 2026

AI Act Transparency Rules: What Changes August 2, 2026
Leïla Sayssa
Leïla Sayssa
July 17, 2026·6 minutes read time

The AI Act's transparency rules are going live. Here's what actually changes.

Context

The EU AI Act entered into force in August 2024, and its obligations have been phasing in since then: prohibited practices and AI literacy requirements from February 2025, governance rules and obligations for general-purpose AI models from August 2025. The next milestone is August 2, 2026, when Article 50 becomes applicable, which sets out transparency obligations for certain AI systems.

Article 50 is not tied to the Act's risk-based classification. It applies regardless of whether a system qualifies as high-risk, prohibited, or minimal-risk. Its purpose is narrower and more specific: giving people the information they need to recognize when they are dealing with AI, and when content has been artificially generated or manipulated.

What Article 50 requires

Two categories of obligations are worth distinguishing.

The first concerns systems that interact with people. Providers of AI systems intended to interact directly with natural persons must design them so that users are informed they are dealing with AI. This disclosure must be clear and made upfront, not buried in terms of service. An exception applies where it is obvious from the circumstances that AI is involved.

For example: customer service chatbots, virtual assistants, or automated phone systems.

The second concerns generated or manipulated content.
Providers of systems that generate synthetic audio, image, video, or text must ensure the output is marked in a machine-readable format that allows it to be identified as artificially generated or manipulated.
Deployers of AI systems that produce deepfakes, meaning image, audio, or video content resembling real people, places, or events, must disclose that the content has been artificially generated or manipulated.

For example: a company using an AI-generated video of its CEO for a product announcement. The tool provider must embed a machine-readable marker in the output; the company publishing it, as deployer, must separately disclose to viewers that the footage was AI-generated, since it depicts a real person in a way that could otherwise pass as authentic.

Deployers who publish AI-generated or AI-manipulated text on matters of public interest must also disclose this, unless the content has undergone human review and a natural or legal person holds editorial responsibility for its publication.

The European Commission published a Code of Practice on Transparency of AI-Generated Content in June 2026, covering the technical marking obligations under Article 50(2) and the deployer labelling obligations under Article 50(4).

Organizations that follow the Code can rely on it as a way to demonstrate compliance, though it remains voluntary.

What the Omnibus actually delays

Since the AI Act's adoption, the Commission has proposed and, as of the Council's final approval on June 29, 2026, adopted a Digital Omnibus package intended to simplify parts of the framework. This has led to some confusion about what is and is not postponed ahead of August 2.

The most significant change concerns high-risk AI systems under Annex III. Obligations tied to that classification, including conformity assessments and related documentation, have been pushed from August 2026 to December 2, 2027. Same goes for the obligations pertaining to high-risk AI systems under Annex I who have been pushed to August 2028.

Article 50's general transparency obligations are a separate set of rules and are not covered by that deferral, with one exception described below. The disclosure obligations for AI systems interacting with people, and for deployers labelling deepfakes or public-interest text, apply as scheduled from August 2, 2026.

The one exception set by Omnibus on AI, is a grace period for the technical watermarking measures under Article 50(2), which runs until 2 December 2026, and applies only to generative AI systems already on the market before August 2026. This grace period does not extend to systems placed on the market on or after August 2, 2026, and it does not affect the deployer-facing obligations under Article 50(4), such as deepfake labelling or disclosure of AI-generated public-interest text.

Organizations should treat this as a limited transitional accommodation rather than a general postponement of Article 50.

What organizations should be doing now

Legal, compliance, and product teams have a few weeks left to close any gaps.

A practical starting point is an inventory of AI systems that interact with users or generate content on the organization's behalf: chatbots, virtual assistants, voice systems, image or video generation tools, and any generative AI used for text published externally.

For each system, the relevant question is which Article 50 obligation applies and who is responsible for meeting it, provider or deployer, since the two roles carry different duties.

  • For user-facing systems, this typically means adding a clear, upfront disclosure at the point of interaction.
  • For generated content, it means confirming whether machine-readable marking is technically in place, and if not, whether the system qualifies for the transitional grace period or needs to comply by August 2.
  • For any AI-generated text published on matters of public interest, organizations should establish and document a human review and editorial responsibility process if they intend to rely on that exemption, since the burden will be on the organization to show the review took place.

Vendor and contractual review is also worth prioritizing. Many organizations deploy AI systems built by third-party providers, and deployer obligations under Article 50 sit with the organization using the system, not necessarily the one that built it. Contracts and technical documentation should confirm what marking or disclosure capabilities the provider has built in, and what remains the deployer's responsibility to implement.

Finally, given the penalties involved, up to €15 million or 3% of total worldwide annual turnover, whichever is higher, this is a reasonable moment for governance and compliance functions to confirm ownership of Article 50 compliance internally and to brief leadership on what has changed, what has not, and what remains to be done before August 2.


See Dastra in action

In just a few minutes, schedule a personalized demo and discover how Dastra can adapt to your organization.

Ask for a demo
Subscribe to our newsletter

We'll send you occasional emails to keep you informed about our latest news and updates to our solution

* You can unsubscribe at any time using the link provided in each newsletter.