How to track EU AI Act transparency obligations
AI Act Article 50 applied on 2 August 2026, with fines up to 15m euro. How to monitor the guidance pages that decide compliance, and catch every change.
The short answer
Article 50 of the EU AI Act applied on 2 August 2026, and breaches carry fines up to 15 million euro or 3% of worldwide annual turnover. The statute is short and stable; the guidance that decides what compliance means is not. Track it by monitoring the AI Office pages, harmonised standards and your national authority's enforcement pages, with a rule on each that fires on substantive edits and stores a dated snapshot of every version.
What Article 50 actually requires
Article 50 is a transparency rule, not a risk rule. It does not ask whether your system is dangerous. It asks whether a person could mistake a machine for a human, or synthetic content for real content, and it obliges you to remove that mistake.
The obligations split by who you are. A provider builds or places the system on the market. A deployer uses it under their own authority. Both are caught, in different places, and the same organisation is frequently both.
| Situation | Who is obliged | What is required |
|---|---|---|
| AI systems people interact with directly | Provider | Design the system so people are told they are dealing with AI, unless it is obvious to a reasonably observant person |
| Synthetic audio, image, video or text | Provider | Mark outputs in a machine-readable format that is detectable as artificially generated or manipulated |
| Deepfakes | Deployer | Disclose that the content has been artificially generated or manipulated |
| AI-generated text published to inform the public on matters of public interest | Deployer | Disclose that the text was artificially generated or manipulated |
The disclosure has to reach the person at the right moment. For a chatbot that means at or before the first interaction, not buried in a policy page nobody opens. For synthetic media it means clear and distinguishable, at the latest when the content is first shown.
The grace period most summaries leave out
Article 50 applied on 2 August 2026, and that date is correct. What gets dropped from most write-ups is that the machine-readable marking duty in Article 50(2) carries a four-month transition to 2 December 2026 for systems that were already on the market.
This matters because it splits your estate in two. A generative feature you shipped last year has until December to carry a detectable marker. The same feature launched after August had no runway at all. If you are triaging work, that distinction is the first cut to make.
It does not extend the other three duties. Chatbot disclosure, deepfake disclosure and public-interest text labelling were live on 2 August with no transition.
What the Omnibus postponed, and what it did not
The most expensive misreading circulating right now is that the Omnibus agreement delayed the AI Act. It delayed part of it. Transparency was not the part.
| Obligation | Original date | Now applies |
|---|---|---|
| Article 50 transparency | 2 August 2026 | 2 August 2026, unchanged |
| Article 50(2) marking, systems already on the market | 2 August 2026 | 2 December 2026 |
| High-risk systems, Annex III stand-alone | 2 August 2026 | 2 December 2027 |
| High-risk systems, Annex I embedded | 2 August 2027 | 2 August 2028 |
| AI regulatory sandboxes | 2 August 2026 | 2 August 2027 |
If your compliance plan assumed a single slipped date, it is now wrong in both directions: too relaxed about the chatbot on your support page, too urgent about an Annex III classification that has another year on it.
What non-compliance costs
Article 99 sets the penalty tiers. Breaching Article 50 sits in the middle tier: up to 15 million euro, or up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.
The reversal is worth knowing. Article 99(6) flips the test for SMEs and startups, so the lower of the two figures applies rather than the higher. A small company reading a headline of 15 million euro is reading a number that does not apply to it, and a large one reading 3% may be understating.
Enforcement runs through national market surveillance authorities rather than a single central regulator, so the practical question is which member state's authority reaches you first, and what that authority has said it will prioritise.
The compliance risk is the guidance, not the article
Article 50 runs to a few hundred words, and you can read it once and be done. Almost everything that will decide whether a regulator agrees you complied is being published elsewhere, on pages that are edited in place without an announcement.
That is the actual exposure. The statute is stable and the interpretation is not, so the failure mode is not misreading the article. It is that the marking specification moved in March and you built against the January version, and nobody in the business found out until an authority asked.
A quarterly manual check does not cover this. A page you look at in January can change in February and read as normal in April, because you are comparing it against your memory of it rather than against what it actually said.
- The Commission's AI Office pages, including the code of practice on marking and labelling synthetic content.
- Harmonised standards and technical specifications for machine-readable marking, which decide what counts as compliant watermarking in practice.
- Your national market surveillance authority's guidance and enforcement pages, which differ by member state.
- Delegated and implementing acts, which fill in detail the article deliberately leaves open.
- The terms and model cards of any foundation model you build on, because a provider's own disclosures shape what you can claim downstream.
Set up the tracking
The configuration is the same for each source and the whole set takes about fifteen minutes. The aim is a watch list that stays quiet for weeks and then speaks up on the one edit that changes what you have to ship.
- Add each page above as its own tracked page rather than one monitor covering a section of a site. Keeping them separate means the alert names the source before you open it, and one page going stale does not hide the others.
- Write the rule in plain English on each. Something like "alert me when the marking or labelling requirements change" on the AI Office guidance, or "alert me when a new enforcement decision or penalty is published" on your national authority. That narrows the watch to substance and stops navigation edits, cookie notices and page furniture from firing.
- Watch policy and guidance pages in full rather than picking one element. On a legal text a single reworded clause is exactly the signal, so nothing should be filtered out. Reserve element-level watches for index and listing pages, where you want the new-entry row and not the rest.
- Check daily. Guidance does not move hourly, and a daily cadence gives you a clean dated version history rather than a stream you learn to ignore.
- Route each alert to the person who owns the obligation, not a shared compliance inbox. Add a team channel as a second destination so a change gets picked up the same morning rather than waiting for someone to come back from leave.
- Keep the snapshots. Every check stores a copy of the page, so you build a dated record of what each version said from the day you start.
The snapshot history is the half that matters later. When an authority asks why you implemented marking the way you did, the answer is the guidance as it stood on the day you decided, shown next to the current version. That is a different conversation from asserting you remember it saying something.
A short compliance pass on your own systems
Monitoring covers the sources. This covers your side of the line.
- Inventory every place a user could meet AI output: support chat, on-site assistants, generated product copy, synthetic imagery, voice, and anything embedded from a vendor.
- For each, decide whether you are the provider, the deployer, or both, because that determines which of the four duties attaches.
- Split the list by market date. Anything already on the market before 2 August 2026 has until 2 December for machine-readable marking; anything newer does not.
- Fix the interaction disclosures first. They are the cheapest to ship and the easiest for a regulator or a journalist to spot from outside.
- Watch your own published AI notices too, so a disclosure that gets edited out in a redesign surfaces as an alert rather than as a finding.
What monitoring does not do
It does not interpret the AI Act, classify your system, or tell you whether a given disclosure satisfies Article 50. Those are judgement calls for your counsel, and a tool that claimed otherwise would be selling you a compliance failure.
What it does is narrower and genuinely uncovered: it tells you the day a source you rely on changed, shows you the old wording beside the new, and keeps a dated record of both. That shortens the gap between a rule moving and your business knowing, which on a 15 million euro exposure is the gap worth closing.