By Greg Nowak. Last updated 2026-09-29.
The EU AI Act’s 2 August 2026 transparency deadline has passed. If your business uses a customer bot, publishes AI-generated material or commissions synthetic media, the useful question now is simple: what does a person actually see or hear, and does the right disclosure reach them in time?
Article 50 assigns different duties to providers, who make AI systems available under their own name or trademark, and deployers, who use them under their authority. An agency or business may need to assess more than one role across its projects. Buying a tool does not tell you whether the website, publication or media workflow using it is covered.
The deadline has passed, with one narrow transition
Article 50 has applied since 2 August 2026. The Commission’s current Article 50 FAQ describes a transition until 2 December 2026 for providers of systems placed on the market before 2 August, and only for the machine-readable marking and detection duty in Article 50(2). It is not a general extension for bot notices or deployer disclosures. The Commission also says content generated before 2 August does not have to be labelled retroactively.
For an operations lead, that means checking live experiences now, while separately confirming whether a provider you rely on qualifies for the marking transition. Record the reason for any exception or transition decision rather than treating a vendor’s general compliance statement as the answer.
Which control belongs where?
The duties are easy to mix up because they concern similar content. A machine-readable mark helps identify an output as AI-generated or manipulated; it is not the same thing as a notice a person can understand. Equally, labelling a published image does not settle whether the system that produced it has the required technical marking capability.
| Touchpoint | Question to settle | Practical control |
|---|---|---|
| Customer chat or AI agent | Does AI communicate directly with a person? | Clear, accessible notice from the first interaction, unless AI involvement is genuinely obvious in context |
| Generated text, image, audio or video | Who provides the system, and does an exception or transition apply? | Check machine-readable marking and whether it survives the output workflow |
| Image, audio or video presented as authentic | Does it meet the Act’s definition of a deepfake? | Human-perceivable disclosure when the audience first encounters it |
| Public-interest text | Was AI used to generate or manipulate published text, and was there substantive human review or editorial control? | Disclosure or a recorded assessment of the editorial exception |
| Emotion recognition or biometric categorisation | Who is exposed to the system? | Accessible notice about its operation and a separate privacy review |
Map the experience, not just the software licence
One AI service can sit behind a website chat widget, an internal drafting tool and an agency content pipeline. List those as separate touchpoints. For each, record the audience, where the interaction or output appears, who controls the interface, who approves publication and which vendor supplies the underlying system. Give each touchpoint a business owner and a technical owner.
Then walk through a real example. On mobile, does a visitor see that the support conversation is with AI before exchanging messages? If an editor generates an image, does its mark remain detectable after cropping, compression and export through the CMS? If a campaign uses a realistic synthetic voice or scene, will the disclosure travel with the clip when a client or social platform republishes it? These checks reveal gaps that a vendor questionnaire alone will miss.
Make publishing decisions repeatable
Not every AI-assisted edit needs the same treatment. The Commission’s final guidelines distinguish standard editing from more substantial generation or manipulation. A deepfake is also narrower than “any AI image”: it concerns image, audio or video that resembles an existing person, object, place, entity or event and could falsely appear authentic or truthful. Have the relevant adviser assess borderline cases before a team builds a blanket labelling rule.
For text published to inform the public on matters of public interest, the editorial exception requires meaningful human review or editorial control and an identifiable person or organisation with editorial responsibility. Spell-checking alone is not substantive review. A useful CMS process records who checked the claims and sources, who could change or reject the piece, and who accepted responsibility for publication. Where disclosure is required, make it a required publishing field rather than a reminder in a spreadsheet.
Notices should be clear, distinguishable and accessible at the first interaction or exposure. Test them in the formats people actually use: an embedded bot, a mobile page, a silent video preview and a shared social post. The Commission’s voluntary Code of Practice on Transparency of AI-generated Content offers measures for marking and labelling. Its scope does not remove the separate work on direct AI interaction, emotion recognition or biometric categorisation.
Turn the inventory into a delivery plan
Start with public bots, realistic synthetic media and automated publishing because people encounter those outputs directly. For each touchpoint, record the provisional provider or deployer role, the applicable duty, the current control, the evidence you tested and the person who can approve a fix. Route uncertain classifications and exceptions to legal counsel; route personal-data questions to the privacy team.
Then place fixes in the systems that produce the experience: chat components, CMS templates, media export steps, vendor requirements and release checks. Re-test the published result after changes. If several teams and suppliers are involved, Greg can help coordinate the inventory and delivery work so decisions become controls people can actually use.
Related on GrN.dk
- AI Images Need a Chain of Custody, Not Just a Disclosure Label
- AI automations need a spend dashboard before the first runaway bill
- AI disclosure rules belong in your CMS, not a spreadsheet
Need help with this kind of work?
Discuss your AI transparency project with Greg Get in touch with Greg.