Operational notes Regulation

AI transparency: the EU guidelines say who is on the hook from 2 August

7 min read

Seven pale paper tags hanging from thin strings against a black background, all of them blank
Seven tags hanging, none of them filled in. From 2 August the law asks who fills them — and how you prove it.

In four days, on 2 August 2026, Article 50 of Regulation (EU) 2024/1689 enters into application: the AI transparency obligations. On 20 July the European Commission adopted the document explaining how it works — communication C(2026) 5054 final and its annex, fifty pages market surveillance authorities will work from. With one caveat almost nobody reports: what was approved on 20 July is the content of the draft; formal adoption follows once all language versions are ready, and “it is only from that moment that these Guidelines will be applicable”. The obligation is not waiting for translations.

The sentence that removes the alibi

Paragraph 153. Article 50 applies from 2 August, and this requires all in-scope AI systems placed on the market or put into service in the Union to be compliant on that date, “regardless of their date of placement on the market or putting into service”. Anyone who bought a system two years ago is not sheltered: there are no acquired rights.

The only derogation is surgical: the AI Omnibus provides a targeted grandfathering rule “only with regard to the marking and detection obligations under Article 50(2) AI Act” for generative systems already on the market, with until 2 December 2026 to comply — we wrote about that asymmetry on 26 July. The guidelines add the line that was missing: “Systems that are partly interactive and partly generative may benefit from this transitional period only with regard to the marking obligation under Article 50(2) AI Act, while compliance with the disclosure obligation for AI systems directly interacting with natural persons must be ensured as of 2 August 2026.” An assistant that talks and generates images carries two dates inside one product. And text generated before 2 August but “published on or after that date” must still be labelled (§154).

Who answers for what

The provider must inform people that they are interacting with an AI (para. 1) and mark outputs in a machine-readable format (para. 2). The deployer — the company or public body using that system on people — must inform about the use of emotion recognition or biometric categorisation (para. 3) and disclose deep fakes and text on matters of public interest (para. 4).

Using a system “under one’s authority”, §12 explains, means assuming responsibility for the decision to deploy it and for the manner of its actual use: it “does not necessarily require technical control over the operation of the AI system”. And a legal person “remains a deployer even if it involves third parties (e.g. contractors, freelancers)” (§14).

The threshold that will surprise anyone who publishes

This is not a newsroom-only matter: among the examples the guidelines list “AI-manipulated corporate reports published on a listed company’s website containing investor information”.

The exemption exists, on two cumulative conditions (§133): human review or editorial control, and someone holding editorial responsibility. Paragraph 134 raises the bar: human review is “the deliberate examination of the substance of the content by one or more natural persons possessing relevant knowledge and professional judgement pertaining to the subject matter under scrutiny”, and “fact-checking the accuracy of the content is a minimum requirement that should be part of that review”. Editorial control is that exercised by “a responsible editorial entity (e.g. an editor-in-chief)” holding “the authority to approve, alter or reject the substance of the text”.

Paragraph 135 says what does not count: “superficial, solely formal or procedural checks (e.g. spell-checking or grammatical correction), the mere existence of an editorial policy, automated review processes or cursory editorial approval without substantive engagement” cannot fulfil the condition. And if AI intervenes after editorial sign-off, the exception becomes void (§136).

Who, in your organisation, actually read that text, with what competence, and how do you prove it?

The code is not the only route

One question is going round: our vendor did not sign the code, are we exposed? No. Paragraph 146: adhering to a code assessed as adequate under Article 50(7) is one route, and that code “does not replace the AI Act or these Guidelines”. Paragraph 147: providers and deployers “may also demonstrate compliance with those obligations through adequate alternative means”, while adherence remains “a straightforward, predictable, and legally certain way”.

The price of the other route sits in §148: non-signatories “should carry out a gap analysis” against the measures set out by the code, and will likely face “a larger number of requests for information and requests for access”. So the right question to a vendor is not “did you sign?” but: which alternative means do you use, and how do you document them. Incidentally: on the morning of 29 July the Commission’s page on the code is still marked as last updated 20 July and publishes no list of signatories.

The exclusions, read properly

Two recurring illusions. First: “it is open source, so we are out”. Paragraph 23 says the opposite. Free and open-source licences keep a system outside the AI Act provided it does not fall under the Article 5 prohibitions, is not high-risk and does not fall under the Article 50 transparency obligations: “providers and deployers of open-source AI systems within the scope of Article 50 AI Act still need to ensure compliance with their respective transparency obligations”. What stays out are free components that do not themselves constitute an AI system (§24) — not the system you are running.

Second: “it is still an experiment”. Article 2(6) covers systems put into service “for the sole purpose of scientific research and development” (§21): if they serve anything else, the obligations come back. And “testing in real world conditions (inside or outside of AI regulatory sandboxes) is not covered by that exclusion” (§22).

Four adjectives that amount to a specification

Technical solutions must be “effective, interoperable, robust and reliable”. Paragraph 79 unpacks them: effectiveness is detecting your own marks and letting people distinguish artificial content; reliability is identifying it accurately “in nominal conditions”; robustness is doing so “under varying conditions, covering both common alterations and adversarial attacks”; interoperability is operating “across multiple systems, actors, contexts and technical implementations”. Four procurement questions, four verifiable answers — not “we joined a code”.

Paragraph 87 deserves a read: in industrial or business-to-business applications marking and detection may not be required, but only if the output is strictly technical, stays within a pre-defined group of professionals and never leaves the company, “with appropriate safeguards in place to avoid reasonably foreseeable misuse (e.g. cloud isolation, role-based controls)”. The exemption is earned through architecture.

Four days

Penalties reach EUR 15 million or 3% of total worldwide annual turnover, whichever is higher (§152). But the practical point is elsewhere: transparency is not demonstrated by a statement, it is demonstrated by a log. Who generated that content, with which system, who reviewed it, when, with what outcome. That log exists only if the system runs where you can read it, retain it and produce it.

That is why we work in two modes only: on-premise, in the client’s own environment, or CSIDIA dedicated cloud — an environment reserved to the single client, access over a dedicated VPN, data centre located in Italy, premises staffed directly by us. Either way the logs stay yours. It is the method we describe here, and it is the reason an internal AI policy has to be written before, not after.

If you want to know which of your systems fall under Article 50, and what you must be able to prove, write to us.

Sources