AI-generated content. This article was researched and written by an automated AI editorial system and published without prior human review. Every factual claim is checked against cited primary sources before publication, but no journalist read this page before you did — treat it accordingly, and report anything that looks wrong. How this works ›

Some links on this page are affiliate links. We may earn a commission at no extra cost to you.
Updated: Sep 2, 2026
·
regulationeupolicytransparencycompliance

The EU AI Act's transparency rules are live — what actually changes if you use AI tools

TL;DR: Article 50 of the EU AI Act (Regulation (EU) 2024/1689) became applicable on 2 August 2026. Two things changed. Providers of generative systems must mark synthetic audio, image, video and text in machine-readable form so it can be detected downstream — with a transition to 2 December 2026 for systems already on the market before today. Deployers who publish AI-generated text to inform the public on matters of public interest must disclose it. The Commission published binding-in-practice guidelines (last updated 29 July) and a voluntary Code of Practice (10 June, ~190 signatories). The load-bearing detail nobody is emphasising: the disclosure exemption requires human review and a person holding editorial responsibility — cumulatively. A great many publishers who believe they are exempt are not. If you buy AI tools, the vendor-side marking is mostly free to you; if you publish AI-written text, the obligation is yours and it is live today. Related (August 16, 2026): a separate strand of EU law — the GDPR, not Article 50 — is now biting AI business models too, as OpenAI brings ads to ChatGPT’s free tier in Europe and runs straight into the bloc’s contested “consent-or-pay” rules.

Update — 29 August 2026: the AI Office starts asking

Four weeks after the general-purpose AI obligations became enforceable on 2 August, the Commission used the powers. On 29 August 2026, Executive Vice-President Henna Virkkunen confirmed the first formal enforcement step: the AI Office has sent requests for information to a number of providers of general-purpose AI models based in different regions of the world. Reported recipients include OpenAI, Anthropic and Google.

The requests cover three things — model security, independent external evaluations, and post-market monitoring of models once they are on the market. Providers are legally required to respond, and the answers become part of a permanent supervisory record. The available penalties under this chapter run to EUR 15 million or 3% of annual turnover, whichever is higher, alongside powers to inspect models and restrict market access.

Two notes for buyers. First, this is a Chapter V obligation on model providers, distinct from the Article 50 transparency duties this article covers — the RFIs are about how frontier models are secured and evaluated, not about whether output is labelled. Nothing in them changes what you must do when you publish AI-written text. Second, the practical effect on your tool choice today is close to zero: an RFI is an information request, not a finding. What it establishes is that the enforcement machinery is real and moving on a four-week timescale rather than a multi-year one, which is worth knowing before you assume a compliance deadline will slip.

It is worth noting what the regime is not pointed at. The AI security incident that actually cost users money in August was commodity malware stealing Claude login sessions off personal computers — an account-security failure with no model-level component and no compliance regime aimed at it. Model-risk regulation and the exposure sitting in your own stack are largely disjoint problems.

What actually became applicable today

The AI Act has been phasing in since it entered into force in August 2024. Prohibited practices and the AI-literacy duty landed in February 2025. Obligations for general-purpose model providers landed in August 2025. 2 August 2026 is the big one — the bulk of the regulation, including Article 50, the transparency chapter.

Article 50 is not the high-risk chapter. It does not ask for conformity assessments, technical documentation, or notified bodies. It asks for one thing across four scenarios: tell people when they are dealing with a machine.

Most of the commentary landing today is written by law firms for compliance officers at large companies. That audience is well served. The audience that is not well served is the much larger one: people who use these tools, and the smaller publishers who now have an obligation they may not know exists.

If you buy AI tools, most of this is somebody else’s problem

The marking duty in 50(2) is on the provider — OpenAI, Google, Anthropic, Black Forest Labs, Midjourney. Not on you for using their output.

That is genuinely good news, and it is the part of Article 50 that will do the most work over time. When Midjourney or Runway embeds a machine-readable marker in generated media, everything downstream — platforms, newsrooms, courts, your own team — gets a detection signal that does not depend on anyone’s honesty. The industry standard here is IPTC’s trainedAlgorithmicMedia digital source type, which C2PA content credentials also carry.

Update (11 August 2026): the marking obligation stopped being theoretical for text. Anthropic said Claude now embeds an invisible, machine-readable watermark in its generated text — a statistical mark applied during token sampling, plus C2PA for files — and is applying it worldwide, not only in the EU. It is the first major provider to ship text watermarking under this code, and it is a clean illustration of the point above: this is the vendor’s duty landing invisibly in the product, and it does nothing for the separate deployer duty below. It also shows the load-bearing limit — the mark survives copy-paste but a paraphrase erases it, which is exactly why 50(2) marking and 50(4) disclosure are two obligations, not one.

Two caveats worth holding.

The transition period is real. Systems placed on the market before today get until 2 December 2026 to comply with the marking obligation. So if you check your image tool this week and find no embedded provenance data, that is not necessarily non-compliance — it may simply be a vendor using the four months it is entitled to. Check again in December.

Voluntary means voluntary. The Code of Practice on Transparency of AI-generated Content was published on 10 June 2026 and had roughly 190 signatories by late July. Signing is optional. The Commission’s position is that non-signatories must instead demonstrate compliance “through alternative equivalently adequate means” — which is a meaningful stick, but it is not the same as a hard technical standard. Expect implementation quality to vary a lot between vendors through the rest of 2026.

If you publish AI-written text, the obligation is yours

This is the part that will catch people.

Article 50(4)‘s second subparagraph puts the duty on the deployer — the person or business using the AI system, not the lab that built it. If you use ChatGPT or Claude to draft articles, newsletters, or market commentary that informs the public on matters of public interest, and you publish that text, you are the one who must disclose.

The exemption is where this gets interesting. The obligation does not apply where the content “has undergone a process of human review or editorial control” and “a natural or legal person holds editorial responsibility for the publication.”

Read that twice. It is two conditions, both required. And the Commission’s guidelines describe the covered case as text published “without human review or editorial control” — the review is the operative element, not the responsibility.

Almost every publisher using AI has the second condition covered. Someone always holds editorial responsibility; that is what a masthead is. The first condition is the one that actually discriminates, and the honest question is uncomfortable: does a human read the piece before it goes live?

Those last two are increasingly common, and they are precisely the workflows most likely to describe themselves as “human-in-the-loop.” Setting standards is not review. Auditing afterwards is not review. The word in the regulation is undergone — past tense, before publication.

The disclosure this site had to make

Worth stating plainly, because it is the same analysis applied to us and it is on the public record.

Pick Right’s articles are written by an automated system and published without a human reading them first. Applying the test above, this publication does not qualify for the Article 50(4) exemption. Until this week it claimed otherwise — the About page stated that every article was reviewed under human editorial judgment before going live, which was false.

That has been corrected. Every page now carries a disclosure above the article body, the site publishes a full AI disclosure, and the compliance analysis — role determination, risk classification, findings — is public in the repository. The full record of what was wrong is in the corrections log.

The reason for mentioning it here is not confession. It is that the easy failure mode of Article 50(4) is not deliberate concealment — it is a publisher describing its workflow in flattering language and sliding into the exemption without ever running the test. “Editorially overseen” and “human-reviewed before publication” feel like synonyms when you are writing your own About page. They are not synonyms in the regulation.

Why this matters more than a compliance checkbox

It creates the first legal definition of “AI-generated” that anyone has to live by. Platform policies and search-engine guidance have gestured at this for two years without ever drawing a line. Article 50 draws one: review before publication, or disclose.

It targets the right layer. Marking at the provider level survives copy-paste, re-hosting, and screenshotting in a way that a visible label does not. That is a better design than most national proposals, which fixate on visible watermarks that are trivially cropped.

The enforcement asymmetry is the thing to watch. Article 50 is enforced by national market surveillance authorities, the AI Office, and the EDPS — and there is no case law. Nobody expects a regulator to open 2026 by fining a solo newsletter. But a false claim of human editorial review is also a misleading commercial practice under EU consumer law, which is enforced by a completely different set of authorities with a long track record and much lower appetite for novelty. The AI Act creates the standard; consumer law is where the early consequences are more likely to appear.

It is a floor, not a ceiling. The US is moving in the opposite direction, toward voluntary frontier-model arrangements and export controls on open weights rather than disclosure duties. Update (3 August): the contrast sharpened within 24 hours — the White House said its own frontier framework was complete but declined to publish it. Same week, two governments: one published the rules and let anyone comply, the other briefed four companies privately. As with Apple’s DMA-driven Siri delay in the EU, expect vendors to build to the strictest regime and ship it everywhere, because maintaining two content-marking pipelines is more expensive than marking everything.

Honest caveats

Guidelines are not law. The Commission’s guidelines and FAQ clarify Article 50; they do not replace it, and a court could read the text differently. The Code of Practice is explicitly voluntary.

“Matters of public interest” is undefined at the edges. Political and economic reporting is clearly inside. Product reviews and industry coverage — this article’s own category — are less clear. The pragmatic answer for most publishers is that disclosure is cheap and the boundary is not worth testing.

Nobody knows what enforcement looks like yet. Every confident prediction about penalties published today, including the ones citing headline percentages of turnover, is extrapolation from statute rather than observation.

This is not legal advice. It is a reading of the regulation and the Commission’s own published guidance, with the sources linked so you can check them. If your exposure is material, the €500 you spend asking a lawyer is better spent than the time you spend reading commentary — including this.

What to actually do this week

If you only use AI tools: nothing urgent. Check in December whether your image and video tools embed provenance data, since that is when the transition ends.

If you publish AI-assisted text: run the one test that matters — does a human read it before it goes live? If yes, document that; you are exempt and you should be able to show why. If no, add a disclosure. It takes an afternoon, and doing it before someone asks is a materially better position than doing it after.

If you are not sure which of those you are: that uncertainty is itself the answer. Workflows nobody can describe precisely are usually the ones where review quietly stopped happening.


Update, 31 August 2026 — a second European regime now sits on the same products. On 31 August the Commission designated ChatGPT a Very Large Online Search Engine under the Digital Services Act, the first generative AI assistant brought under that regime. Nothing in it changes any Article 50 obligation described above — the DSA governs systemic risk in large services, the AI Act governs transparency about synthetic output, and they are enforced separately. The practical point for anyone building a compliance file is that the two are now easy to confuse and a vendor answering one has not answered the other. Ask for AI Act marking and disclosure by name, and ask for DSA risk assessments and audit reports by name.

Related: July 2026 in AI — what changed for buyers · The 2026 AI Safety Index: Anthropic tops it, nobody passes · How the government-gated AI regime became permanent

Update, 2 September 2026: platform policy is now moving faster than the statute on the same subject, and drawing a narrower line. On 31 August Instagram renamed its AI badge to “AI-generated profile” and attached a reach penalty, scoping the duty to accounts that feature an AI-generated person and explicitly exempting creators who merely use AI tools. Article 50 remains the legal floor and applies wherever you publish; the platform rule is the one with a same-week commercial consequence attached.

Frequently asked questions

Does the EU AI Act apply to me if I'm not in the EU?

Often yes. The Act reaches providers placing AI systems on the EU market regardless of where they are established, and deployers established in the Union. If you are a US publisher using AI to write articles that EU readers see, the safest reading is that you are in scope. The practical answer for most small publishers is that disclosure costs almost nothing, so the jurisdictional question is rarely worth litigating.

If I edit an AI draft before publishing, do I still have to disclose it?

Probably not, if the review is genuine. Article 50(4) exempts content that has undergone human review or editorial control where a person holds editorial responsibility. Both conditions must hold. A human editor reading and revising a draft before it goes live is squarely inside the exemption. Spot-checking a sample after publication is not.

Is the Code of Practice on Transparency of AI-generated Content mandatory?

No. It is voluntary, published 10 June 2026, with roughly 190 signatories by late July. But the underlying Article 50 obligations are law. The Commission's guidelines state that anyone not adopting the code must demonstrate compliance with the marking and labelling obligations through alternative equivalently adequate means — so declining the code shifts the burden of proof onto you rather than removing it.

What is the 2 December 2026 grace period?

A limited transition for the marking and detection obligation on AI systems already placed on the market before 2 August 2026. Those providers have until 2 December 2026 to comply with machine-readable marking. It does not extend the deployer disclosure duty under Article 50(4), which applies now.

What happens if a publisher just ignores this?

Enforcement sits with national market surveillance authorities, the AI Office and the European Data Protection Supervisor. There is no case law yet, and no realistic expectation that regulators start with small publishers. The more immediate risk for most sites is not a fine — it is that a false claim of human editorial review is also a misleading commercial practice under consumer law, which has a much better-established enforcement track record.

Sources

Related tool reviews

Questions or corrections? Email Pick Right. Want the full list? See all news.