The EU AI Act's Transparency Rules Are Live, and Most Small Teams Are Not Ready

The high-risk regime slipped to 2027, but Article 50 took effect on 2 August, and it touches every chatbot and image generator shipped into Europe.

2 min read ·

On 2 August the transparency obligations in Article 50 of the EU AI Act became enforceable by national authorities across the bloc. That date was supposed to be the big one, when the high-risk rules also landed. They did not: the AI Omnibus, which entered into force on 27 July as Regulation (EU) 2026/1744, pushed standalone high-risk obligations to 2 December 2027 and those for AI built into regulated products such as medical devices and toys to 2 August 2028. A lot of teams read "AI Act delayed" and stopped there. That was a mistake.

What actually applies now

Article 50 is short, and it reaches far more products than the high-risk annex ever did. In plain terms:

  • Chatbots and interactive systems must make it clear to people that they are dealing with AI, unless that is obvious from context.
  • Generative systems that output audio, images, video or text must mark that output in a machine-readable, detectable way. Providers whose generators were already on the market before 2 August have until 2 December 2026 to comply.
  • Deployers who publish deepfakes of real people, places or events must disclose them.
  • Emotion recognition and biometric categorisation deployers must tell the people being analysed, on top of existing data protection duties.

Fines for breaching these duties run up to €15m or 3 per cent of worldwide turnover, whichever is higher. The prohibitions already in force stay in force, general-purpose model obligations keep their original timetable, and new bans on nudification and CSAM generation apply from 2 December.

The builder's reading

From where I sit in Kuala Lumpur, shipping products that end up in European hands through app stores and SaaS sign-ups, the disclosure requirement is the easy part. A line in the interface and a sensible default cover most chat products. The marking requirement is harder. If your app wraps a third-party image or video model, you need to know whether your upstream provider embeds a machine-readable mark, whether your own post-processing strips it, and who counts as the "provider" once you have fine-tuned or chained models together. Resizing, re-encoding and cropping are exactly the operations that tend to destroy metadata, and most of us do all three in a typical media pipeline.

The four-month grace period for existing generators is useful, but only if you spend it auditing. Concretely, that means tracing one generated asset from model call to the file your user downloads and checking what survives. If nothing survives, you have a compliance gap and probably a product decision to make about which vendors you use.

What is still unclear

National enforcement is the open question. Article 50 is enforced by member-state authorities, and their appetite and capacity will vary. Nobody yet knows how aggressively a regulator will treat a small non-EU developer whose chatbot has a few thousand European users. The safe assumption is that enforcement will start with big, visible deployments and spread slowly. The unsafe assumption is that "not EU-based" means "not in scope". It does not.

My advice to other small teams: put the disclosure in this week, audit your media pipeline for marking before December, and stop treating the omnibus delay as a reason to ignore the Act altogether.


Sources

Responses (2)

Sign in to leave a response.

  • The metadata point is real. Half the image CDNs I have profiled strip everything on transform by default, so the mark dies long before the user sees the file.

  • Fair warning on scope, though I suspect early enforcement targets the platforms rather than the long tail. The deepfake disclosure rule is where I expect the first real cases.

More from Fakhrul

Recommended from Horizon