On 2 August 2026, the EU AI Act's Article 50 transparency obligations became applicable. The high-risk obligations scheduled to land beside them did not, because the Digital Omnibus on AI deferred them, a package the Council gave final approval on 29 June 2026. The result is a split many teams have already misread: the high-risk deadline moved, the disclosure deadline did not.
The EU AI Act's high-risk obligations were deferred to 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for Annex I product-embedded systems, but the Article 50 transparency obligations became applicable on 2 August 2026 and were not deferred. The part that was not deferred is the part most mid-market companies touch daily. The Digital Omnibus deferral applies to high-risk classification and the conformity machinery around it: risk management files, technical documentation, post-market monitoring. Some mid-market firms do operate an Annex III system, since HR screening and candidate evaluation tooling sits in that annex, and for those the clock now runs to December 2027. Nearly all operate a chatbot, a content pipeline, or a voice agent, and those fall under Article 50, which is live now.
The EU AI Act's high-risk deadlines were deferred to December 2027 and August 2028, but the Article 50 transparency and disclosure obligations became applicable on 2 August 2026 and were not deferred. If you run a customer-facing AI agent or publish AI-generated content that reaches the EU, the obligation is current, not future.
Yes, if the output of your AI system is used in the EU, which is a lower bar than having an EU entity. A US company with EU customers, an EU subsidiary, or a website serving EU visitors can be in scope as a provider, a deployer, or both. This is an operational readiness article and not legal advice, so scope questions belong with counsel. The inventory work does not need a lawyer, and it is most of the job.
There is a second reason to do this even if EU exposure is thin. Disclosure and provenance are converging into one template across US state AI statutes, procurement questionnaires, and customer security reviews. "Do you label AI-generated content and disclose AI interaction" now appears in diligence packets regardless of geography, and building the control once is cheaper than retrofitting it per jurisdiction. Teams already running a formal AI agent governance checklist will find this maps onto controls they partially built.
Article 50 of the EU AI Act imposes six practical duties, split between providers and deployers:
One timing detail matters for planning. Systems generating or manipulating synthetic content already placed on the market before 2 August 2026 received a four-month transition, with marking requirements applying from 2 December 2026. Anything placed on the market after 2 August 2026 complies on placement. A content tool you shipped in 2025 has until December; one you turn on next month does not.
Disclosure obligations land in four places, and most teams find all four. The first is customer-facing chat and voice. An AI receptionist that answers the main line and books appointments without ever saying it is an AI is the most common exposure we see, because operations bought it, not IT, and nobody treated it as a regulated interface.
The second is the marketing and content pipeline: generated hero images, product photography variants, voiceover, short video, AI-drafted copy. The third is any agent drafting outbound text published at scale, usually sales sequences running through AI CRM and sales tooling plus whatever your workflow automation platform posts publicly on a schedule. The fourth is HR and CX tooling doing emotion or biometric inference: interview analysis, call sentiment scoring, contact center voice analytics. Treat the workplace side of that category differently, because Article 5(1)(f) prohibits using AI to infer emotions of a natural person in the workplace and in education institutions, except where intended for medical or safety reasons, and that prohibition has applied since 2 February 2025. Emotion inference on employees or candidates is a stop-and-verify item rather than a labelling item, while emotion recognition outside those contexts remains an Article 50 disclosure. That fourth category is the one companies most often do not know they bought, because it arrived as a feature inside a platform they already owned.
Because a visible label is not machine-readable marking, and the marking has to survive your pipeline. The common approach is C2PA style content credentials, which attach signed provenance metadata to the asset itself. The engineering problem is that the asset rarely reaches the public in the form it was generated: it is uploaded to a CMS, resized, recompressed, converted to WebP or AVIF, pushed to a CDN, and rewritten by an optimization layer. Every one of those steps can strip metadata, and most default configurations do.
Treat this as a testable property, not a policy statement. Generate an asset, publish it through the real production path, fetch it from the public URL, and inspect it. If the provenance data is gone you have a pipeline defect, usually in one transform you can configure. Re-run the test after any CMS, CDN, or theme change, because this control silently regresses. That verification is standard AI security and governance work, and it belongs in the release checklist, not a compliance binder.
Most mid-market companies are deployers of somebody else's model and assume the vendor handled marking, which is where the gap opens. Provider obligations attach to whoever puts the system on the market, so if you consume a commercial model or off-the-shelf agent, the marking duty largely sits upstream. Deployer duties, meaning deepfake disclosure, published text disclosure, and the emotion recognition notice, sit with you.
The practical control is one written question to every AI vendor: do you mark generated outputs machine-readably, in which formats, and can you demonstrate it on a sample we choose. Get the answer in the contract or security exhibit, not a sales email. If you build your own custom AI agents or fine-tune anything customer-facing, you may be a provider yourself, and marking becomes your engineering backlog item.
A named person accountable for the published text, not a checkbox saying someone looked at it. The carve-out depends on human review plus a person or organization holding editorial responsibility, and a coordinator clicking approve on forty drafts in an hour will not look like editorial responsibility later. Make it concrete: every published piece records a named reviewer, the review date, and a change log showing the review had effect, stored with the content in the CMS. If your process cannot produce that record automatically, it is not real yet.
Start with one row per AI touchpoint and force yourself to fill every column, because the empty cells are the findings. For each touchpoint, record:
Six numbers, all cheap to produce once the inventory exists: inventory coverage, disclosure coverage, marking survival, vendor attestations, editorial accountability, and time to inventory.
A workable plan finds every AI touchpoint in the first month, proves marking survives the publishing pipeline in the second, and makes the control durable in the third.
Four failure modes recur almost verbatim across companies. Disclosure buried in a privacy policy instead of presented at first interaction, which fails the clear and distinguishable requirement however accurate the policy text is. Marking stripped by the pipeline, found only when a customer or auditor checks the live asset. An agent added after the audit, because AI procurement happens in departments and the inventory has no intake path. And treating the deferral as permission to stop, since the work moved to 2027 and 2028 was never the work due this week.
The AI Act's high-risk obligations moved. Its transparency obligations did not, and they became applicable on 2 August 2026, with a transition to 2 December 2026 for synthetic content systems already on the market. Legal exposure depends on your EU footprint; the operational work does not. An inventory, a disclosure at first interaction, machine-readable marking that survives your pipeline, a written question to every AI vendor, and a named human accountable for published text. Those five controls cover the operational surface Article 50 touches and answer the AI questions now appearing in procurement reviews, though whether they satisfy your obligations is a call for counsel who knows your EU footprint. Build once, use everywhere. A short AI consulting engagement usually covers the inventory and the first pipeline test, after which the ongoing effort is small. We run this work from Dallas–Fort Worth and deliver it remotely for clients across the country.
Infonaligy builds AI disclosure inventories and provenance controls from our Dallas–Fort Worth home base, and delivers them to teams across the country, remotely nationwide.
Book an assessment and we will inventory every AI touchpoint in your stack, record provider and deployer roles, and test whether machine-readable marking survives your real publishing pipeline. You get a prioritized gap list, the vendor questions to send, and a 30/60/90 plan your team can run.