The Commission's Final Article 50 Guidelines: What Actually Changes Before 2 August 2026
TL;DR
- On 20 July 2026 the European Commission adopted its final guidelines on the Article 50 transparency obligations, roughly two weeks before those obligations apply on 2 August 2026.
- The guidelines do not create new obligations. They are the Commission's authoritative reading of what Article 50 already requires, aimed at national authorities, providers and deployers alike.
- The headline duties are unchanged: tell people when they are interacting with an AI, and make AI-generated or manipulated content detectable in a machine-readable way.
- The most useful clarification for ordinary businesses: standard editing operations, such as spelling correction, do not trigger the obligations, because they do not alter the informational substance of the content.
- On marking technology, the guidelines are deliberately technology-neutral. There is no single mandated standard. C2PA, watermarking and metadata are all routes, and the choice must suit the content type and distribution path.
- The provider versus deployer split is preserved, and it decides which duty is yours. Misreading your role is the most common and most expensive mistake here.
- There is no grace period. Transparency breaches sit in the EUR 15 million or 3% of global turnover tier (Article 99(4)).
- Practical work for most companies is small: a visible chatbot notice, a labelling habit for AI-generated content, and a written record of both.
What was actually published
On 20 July 2026 the Commission adopted the final version of its Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act. It runs to 51 pages, and it landed less than two weeks before the obligations start to bite.
The stated purpose is practical: to give competent authorities, providers and deployers a consistent basis for applying Article 50 in a "consistent, effective, proportionate and uniform" way across the Union. The underlying policy aim is simpler still. People should be able to tell when they are dealing with a machine, and when what they are looking at was made or altered by one.
Guidelines are not new law
This matters, and it is where a lot of commentary goes wrong. Commission guidelines are not binding legislation. They do not add obligations, and they cannot remove any. What they do is tell you how the Commission reads the text, which in practice is how national authorities will approach enforcement. Treat them as the most authoritative available interpretation, not as a new rulebook.
So if you already did the Article 50 work on the basis of the regulation itself, the guidelines are unlikely to overturn your analysis. They will, however, resolve several of the judgement calls you probably had to make on your own.
Is your AI system high-risk?
Find out in 2 minutes, free, no signup required.
Take the free assessmentWhat the guidelines clarify
1. Disclosure when people interact with AI (Article 50(1))
Systems intended to interact directly with people must be designed and used so those people are informed they are dealing with an AI. Chatbots sit squarely inside this. The duty is framed as a design duty on the provider, but if you run the website, you are the deployer and the notice has to actually be visible to your visitors. "The vendor should have handled it" is not a defence for a notice nobody saw.
The exception for cases where it is obvious from the circumstances survives, and it remains narrow. A fluent, human-sounding support bot does not qualify. If a reasonable visitor could plausibly think they might be talking to a person, tell them they are not. We cover the boundaries of this in detail in do I need to disclose my AI chatbot?.
2. Machine-readable marking of generated content (Article 50(2))
Providers of systems that generate synthetic audio, image, video or text must mark the output as artificially generated, in a machine-readable format, so it can be detected as such.
The important clarification is what the guidelines decline to do: they do not mandate one technology. They describe acceptable approaches without elevating any single one into a legal requirement. In practice that means:
- C2PA / Content Credentials is the natural reference point for images, video and audio, largely because of industry adoption rather than any legal designation.
- Watermarking is a useful second layer, because metadata is routinely stripped by ordinary distribution (screenshots, re-encoding, social uploads).
- Metadata and provenance fields are the practical path for text, where there is no signal to embed a watermark in.
The obligation is about the outcome (detectable, machine-readable, robust enough to be meaningful), not about buying a particular product. See content marking for how these layers fit together.
3. Deepfakes and AI-generated text on public-interest matters (Article 50(4))
Deployers who publish deepfakes, or AI-generated text on matters of public interest without meaningful human review, must disclose that the material is artificially generated. The editorial-responsibility carve-out for genuine human review remains, and "genuine" is doing real work in that sentence. A rubber-stamp review does not qualify.
4. Emotion recognition and biometric categorisation (Article 50(3))
Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. This is narrower in scope than the chatbot duty, but it is absolute where it applies.
5. The carve-out worth knowing: standard editing operations
This is the most quietly useful clarification in the document. Standard editing operations do not trigger the marking obligations, because they do not change the informational substance of the content. Spelling correction is the Commission's own example.
The practical read: running a human-written article through a grammar checker does not turn it into AI-generated content requiring a label. Generating the article with a language model does. The line sits at whether the AI shaped the substance, not whether an AI touched the file at all.
Do not stretch this. "I only used AI to tidy it up" stops being credible somewhere well before "the model wrote the draft."
6. Provider or deployer: still the question that decides everything
The guidelines keep the AI Act's role architecture intact. Providers place systems on the market; deployers use them professionally. The duties differ, and your obligations follow your role, not your intuition about how involved you feel. If you use a third-party chatbot on your own site, you are a deployer with a live duty. Our provider vs deployer guide works through the boundary cases.
7. Case-by-case assessment, not an exemption list
The guidelines do not offer an exhaustive catalogue of exemptions, and they lean on proportionate, case-by-case assessment. That is honest, but it means you cannot look up your situation and find a definitive answer. Where the position is genuinely ambiguous, the cheap move is almost always to disclose. A short notice costs nothing; a wrong call on an exception costs a transparency breach.
How the Code of Practice fits
Alongside the guidelines sits the Code of Practice on marking and labelling AI-generated content, published in final form on 10 June 2026. It is voluntary, it is technology-neutral, and signing it does not change your legal obligations. What it offers is a defined set of measures you can point to as evidence that you acted in good faith, instead of constructing your own justification in front of a regulator.
It is not immunity, and the competent authorities remain the final judge. We break down what it contains and who should sign in the Code of Practice on marking AI-generated content.
What you should actually change before 2 August
This is the part most coverage skips. For the large majority of organisations, the required work is modest and concrete.
Step 6 is the one people skip and later regret. Transparency compliance is easy to achieve and surprisingly hard to prove six months later. A dated note recording what you disclosed, where, and in which languages is the difference between "we think we handled it" and "here is the record."
If you run a WordPress site, steps 2 and 3 are largely a configuration task. See the WordPress checklist and the free EU AI Act plugin, which handles the disclosure locally with no account.
Penalties and timing
There is no transition period tucked inside the guidelines. The obligations apply from 2 August 2026.
National authorities apply proportionality for SMEs, and the realistic near-term risk for a small company is reputational rather than a headline fine. That is not a reason to skip a notice that takes ten minutes to add. Full detail in penalties and fines explained.
Frequently asked questions
Do the guidelines change my obligations?
No. They interpret Article 50; they do not extend or reduce it. If your analysis was sound before 20 July, it is very likely still sound.
Do I have to use C2PA?
No. Neither Article 50 nor the guidelines mandate a specific technology. C2PA is the widely adopted reference point for images and media, but the obligation is that marking is machine-readable and detectable, not that it comes from one vendor or standard.
Does running my blog post through an AI grammar checker mean I have to label it?
No. Standard editing operations such as spelling correction do not alter the informational substance and do not trigger the marking obligations. Generating the text with a model is a different matter.
Is there a grace period after 2 August 2026?
No. The obligations apply from that date.
My chatbot is a third-party product. Is the vendor responsible?
You are the deployer, and the notice has to be visible on your site. If the vendor's built-in notice is clear and shown at first contact, confirm it and you are fine. If not, add your own.
Does signing the Code of Practice make me compliant?
No. It is voluntary and it is evidence of good faith, not a legal presumption of compliance in the sense of a harmonised standard. The obligations apply either way.
Next steps
- Confirm your obligations: free EU AI Act assessment, no account needed
- Understand the rule: Article 50 transparency obligations
- Implement marking: content marking guidance
- Track the dates: EU AI Act deadline tracker
This article is general information, not legal advice. For your specific situation, consult a qualified professional.



