Skip to content
Cirran

By Michał Puchała · 2026-07-27 · 8 min read

The AI Act's 2 August Deadline: What Companies Need to Check Now

From 2 August 2026, the EU AI Act requires clearer notices for chatbots, machine-readable marking of synthetic content and labels for specified AI uses. A practical guide to identifying your role, checking systems and documenting the controls your company relies on.

On 2 August 2026, a new set of EU AI Act transparency duties begins to apply. The rules reach beyond companies building large AI models. They can also affect an organisation that offers a chatbot, uses emotion recognition, publishes certain AI-generated text or releases synthetic audio, images or video.

The European Commission published its final Article 50 guidance on 20 July, leaving little time between clarification and application. A useful response starts with a short system inventory, a clear decision about your role and evidence that the required notices, marks and review steps work in practice.

The deadline is narrower than the headlines suggest

The AI Act applies in stages. Rules on prohibited practices and AI literacy started earlier, while several requirements for high-risk systems arrive later. The AI Act Service Desk timeline identifies 2 August 2026 as the start date for Article 50 transparency requirements, rather than a single deadline for every obligation in the Act.

Article 50 covers four situations. Providers of systems that interact directly with people must tell them they are dealing with AI, unless that fact is already obvious. Providers of systems that generate synthetic content must make that output detectable through a machine-readable mark.

Deployers have a different set of duties. They must inform people exposed to emotion recognition or biometric categorisation, and they must clearly disclose specified deepfakes and AI-generated public-interest text. The Commission's quick guide presents these as four distinct cases because the responsible party and required control differ in each one.

This distinction matters for management. Buying access to an AI model does not settle your responsibilities, and running the model in a European data centre does not provide the required disclosure. The questions are what the system does, how your organisation makes it available and what people see when they interact with its output.

First decide whether you are a provider or a deployer

Under the Commission's Article 50 questions and answers, a provider develops an AI system, or has one developed, and places it on the EU market or puts it into service under its own name or trademark. A deployer uses an AI system under its authority for a professional activity. The same organisation can occupy different roles for different systems.

A company using a third-party assistant internally will usually begin its assessment as a deployer. If it commissions a customer-facing system and releases that system under its own name, the provider definition may also become relevant. Branding, contractual wording, technical control and the way the system reaches users all belong in the role assessment.

The legal entity remains the deployer when employees, contractors or freelancers operate a system under its authority. Individual staff members do not each become separate deployers in that situation, according to the Commission's guidance. That allows one accountable owner to coordinate the controls across product, communications, legal and IT teams.

Start the inventory with systems people already recognise as AI, such as support chatbots, document assistants and image generators. Then look for AI features inside recruitment, call-centre, security, marketing and analytics products. Many teams will find that procurement records describe the software but do not record the model, the output type or the person who decides how that output is used.

Match each system to the right transparency control

For a chatbot, agent or avatar designed for a genuine two-way exchange, the person must know from the first interaction that they are dealing with AI. The Commission says background processing, machine-to-machine communication and systems without direct contact with people fall outside this particular duty. It also advises interpreting the "obvious" exception narrowly, so a clearly worded notice is usually easier to defend than an assumption about what a user will infer.

Synthetic content creates a separate provider-side requirement. Systems generating audio, images, video or text must apply a machine-readable mark that makes the output detectable as AI-generated or manipulated. The official Article 50 text says the method should be effective, interoperable, robust and reliable as far as technically feasible.

There are limits. Standard editing that does not substantially alter the input or its meaning is excluded, and the Commission's guidance also identifies examples such as source code, short strings and machine-to-machine output. A narrow exception may apply to certain business-to-business or industrial contexts, but a team should document why the conditions apply rather than treating all internal output as exempt.

For emotion recognition and biometric categorisation, the deployer must inform the people exposed to the system. The duty applies whether the analysis happens in real time or afterwards. A procurement team assessing workplace, customer-service or security software should therefore ask whether such a feature exists even when it is not the main purpose of the product.

Deepfakes require a clear and perceivable disclosure when people first encounter them. An embedded machine-readable mark from the provider does not satisfy the deployer's visible disclosure duty by itself. The Commission defines a deepfake by resemblance to an existing or plausibly existing person, object, place, entity or event, combined with a false appearance of authenticity.

Human review must be more than a final click

Article 50 also covers AI-generated or manipulated text published to inform the public on matters of public interest. The Commission gives a broad set of examples, including public health, environmental protection, consumer safety and economic, financial, political, scientific or cultural developments that may be part of public debate. This can reach a regulated company's public reports, notices or explanatory content, depending on their subject and purpose.

Text does not need the Article 50 label when it has undergone human review or editorial control and a person or legal entity holds editorial responsibility. The Commission's detailed explanation describes meaningful review as an examination of the substance by someone with relevant knowledge and professional judgement. A spelling or grammar check does not meet that standard.

That makes the control operational rather than ceremonial. The reviewer needs authority to challenge facts, check sources, change the substance or reject publication. The organisation should also be able to show who held final responsibility, what they reviewed and when approval occurred.

Existing publishing workflows can often carry this evidence. A named reviewer, a recorded approval and retained source material make the process visible and repeatable. Where teams publish directly from an AI tool into a website, customer portal or social channel, they need an explicit review gate before release.

Build one practical register and assign the gaps

A useful register can remain compact. For each AI system, record:

  • the business owner, supplier, model and user group;
  • whether the organisation is acting as provider, deployer or both;
  • whether the system interacts directly with people or generates text, audio, images or video;
  • whether emotion recognition, biometric categorisation, deepfakes or public-interest publishing are involved;
  • the notice, machine-readable mark, visible label or human-review control that applies;
  • the vendor evidence, test result and internal owner supporting that control.

Add hosting location, data retention, administrative access, subprocessors and exit options if the organisation is already reviewing cloud or data sovereignty. Those fields go beyond Article 50, but collecting them at the same time produces a more useful dependency map. It also prevents compliance work from becoming detached from the infrastructure and contracts on which the AI system depends.

Test the controls through the same path a real user follows. A chatbot notice hidden in terms and conditions may not appear at the first interaction. A machine-readable mark may disappear when a file is resized, exported or passed through another platform, while a public-interest article may bypass its reviewer when a publishing integration changes.

Where the role or exception remains uncertain, record the facts before seeking legal advice. A narrow question supported by the system's purpose, audience, output and release process is easier to answer than a general request to assess "our AI". The resulting decision should return to the register with an owner and review date.

Use the grace period carefully

The Commission's current Article 50 FAQ states that the rules apply from 2 August 2026, with a limited grace period for the machine-readable marking duty. Providers of systems placed on the market before that date have until 2 December 2026 to meet that specific requirement. The extension does not postpone the other Article 50 duties, and content generated before 2 August does not need to be labelled retrospectively.

The EU has also published a voluntary Code of Practice for marking and labelling AI-generated content. Providers and deployers can sign it and use its measures to demonstrate compliance. Organisations that do not sign remain free to use other adequate methods, but they should be ready to explain and document those methods.

For most mid-sized companies, the immediate result should be modest and concrete: a reliable inventory, visible notices where required, a working review process and written confirmation of what suppliers provide. That creates an answer a board, auditor or customer can understand, while giving the technical team a clear list of gaps to close.

Thinking about migration? Book a free consultation to discuss your situation.

See the European equivalent for your stack. Compare AWS, Azure, and GCP services side by side with OVHcloud, Scaleway, STACKIT, IONOS, and Hetzner.

Open the service mapping

Thinking about migration?

Book a free consultation to discuss your situation.

The AI Act's 2 August Deadline: What Companies Need to Check Now | Cirran