TechLaw
26/8/26

Article 50(2) of the AI Act: the 2 December 2026 marking deadline

7 min read

Guillermo Passas Varo

Since the Digital Omnibus was published in July, one sentence has been doing a great deal of unearned work in compliance meetings: the AI Act has been delayed. Regulation (EU) 2026/1744 did defer the high-risk regime, by sixteen months for Annex III systems and by two years for the Annex I product route. It left Chapter IV where it was, with a single exception that runs for four months and reaches exactly one paragraph. Organisations that read the deferral as covering Article 50 as a whole have been in breach since 2 August 2026, with no event to tell them so.

The exception is Article 50(2), the machine-readable marking of synthetic output, and it reaches only providers whose generative systems were placed on the Union market before 2 August 2026. Those providers have until 2 December 2026. Every other obligation in the article took effect on 2 August with no transition of any kind.

What Article 50(2) requires, and of whom

Article 50(2) addresses providers of AI systems, general-purpose AI systems included, that generate synthetic audio, image, video or text. It asks for two things. Outputs have to be marked in a machine-readable format and detectable as artificially generated or manipulated. The technical solution used to achieve that has to be effective, interoperable, robust and reliable so far as is technically feasible, judged against the specificities and limitations of the content type, the cost of implementation and the acknowledged state of the art.

The paragraph carves out systems performing an assistive function for standard editing, systems that do not substantially alter the deployer's input data or its semantics, and systems authorised by law to detect, prevent, investigate or prosecute criminal offences. The Commission's guidelines of 20 July 2026 read those carve-outs narrowly and supply worked examples. Grammar and spell-checking, format conversion and minor cropping sit outside. So do short outputs such as single words, captions and data labels, source code, machine-to-machine communication and interim outputs in closed industrial loops.

Two scope points matter more than they appear to. Article 50 attaches to AI systems rather than to models, which brings application-layer companies building on someone else's foundation model squarely within the provider obligation for their own system. And Article 2(1)(c) extends the Regulation to providers and deployers located in a third country where the output produced by the system is used in the Union, which is why a company with no EU entity can be the addressee of Article 50(2).

The four-month extension covers one paragraph, one class of system and one type of operator

The transitional rule sits in a new paragraph 4 of Article 111, inserted by the Digital Omnibus and in force since 27 July 2026. It gives providers of AI systems (general-purpose AI systems included) generating synthetic audio, image, video or text content, placed on the market before 2 August 2026, until 2 December 2026 to comply with Article 50(2). Read against the rest of the article, the boundaries are sharp.

Article 50(1), the provider duty to design directly interactive systems so that people are informed they are dealing with an AI system, has applied since 2 August 2026. Article 50(3), the deployer duty to inform people exposed to emotion recognition and biometric categorisation systems, has applied since 2 August 2026. Article 50(4), the deployer duty to disclose deepfakes and AI-generated text published to inform the public on matters of public interest, has applied since 2 August 2026. So has Article 50(5), which requires the information under paragraphs 1 to 4 to be clear, distinguishable and given no later than first interaction or exposure. Generative systems placed on the market on or after 2 August 2026 owe compliance with Article 50(2) from that moment, with no runway for new products. What the Omnibus moved, and what it left alone, is set out in our reading of the final text.

Whether the system was placed on the market before 2 August 2026 decides everything else

The Regulation defines placing on the market as the first making available of a system on the Union market, and making available as supply for distribution or use on that market in the course of a commercial activity, whether in return for payment or free of charge. For a boxed product the test is trivial. For a continuously deployed service it is anything but, and this is where most assessments now being run go astray.

Three situations recur. A product generally available in the Union since 2024 that has since received model upgrades falls on the transitional side, and the date of first supply weighs more than the version history. A product in closed beta before August that became generally available afterwards is likely on the other side, since a restricted trial is not obviously supply for use in the course of a commercial activity. A long-standing product to which a generative feature was added in September is the hard case, and the more defensible reading is that the generative capability now on offer was made available after 2 August and attracts no transition at all.

Whichever answer applies, it needs a documentary basis fixed now rather than reconstructed under a request for information: release notes, commercial terms, pricing pages and internal launch records establishing the date of first supply in the Union, together with a record of what has changed since. The date is a question of fact, and market surveillance authorities will treat it as one.

The obligation that was deferred and the obligation that was not sit with different operators

Article 50(2) binds the provider. Article 50(4) binds the deployer. A company frequently occupies both roles at once, as provider of the system it makes available under its own name and as deployer when it uses that system or another to publish content. The grace period and the exposure can therefore coexist inside one organisation, and they will not surface on the same compliance dashboard unless someone has separated the roles deliberately.

The guidelines make three points that bear directly on this. The provider's machine-readable marking does not discharge the deployer's duty to label. The deepfake test is objective, so an intention to deceive is not required and photorealism is not decisive; it suffices that the subject is plausibly real, which captures digital replicas and de-aged performers while leaving out content no audience would take as genuine. And the editorial exception for AI-generated public-interest text carries a high threshold: review by a person with relevant competence, documented, with cursory sign-off insufficient and any substantive AI editing after the review removing the exception altogether.

A marketing team that has published a synthetic image of a plausibly real person on an EU-facing channel since 2 August has an Article 50(4) exposure that the December date does nothing to address.

Content produced before August does not have to be marked retrospectively

The guidelines confirm that content generated before 2 August 2026 requires no retroactive labelling, and neither the guidelines nor the Code impose any duty to work back through an archive. One asymmetry deserves attention. For the deployer duty in Article 50(4), the operative moment is publication rather than generation, so text drafted with AI in July and published in September is caught unless the editorial exception applies on its own terms.

What the guidelines and the Code of Practice give, and what they withhold

The Commission published the final Article 50 guidelines on 20 July 2026, alongside the Code of Practice on Transparency of AI-Generated Content, which has been assessed as adequate. Under Article 50(7), a code approved through that route serves to demonstrate compliance with the transparency obligations, and around 190 organisations had signed by the end of July.

Signing buys a documented, EU-wide route to demonstrating adequacy and a more predictable relationship with market surveillance authorities. It stops short of a safe harbour, since adherence has not been declared conclusive evidence of compliance, and non-signatories remain free to justify their own measures at the cost of closer scrutiny and more information requests. It also moves the December date by precisely nothing.

In several respects the Code asks for more than the Article does. For most content types it expects at least two machine-readable techniques, typically digitally signed tamper-evident metadata combined with an imperceptible watermark, reserving single-layer approaches for free-form text and for generative systems embedded in closed physical products. It requires a detection mechanism that is in principle free of charge, with unrestricted access for regulators, researchers, media and fact-checkers. It exempts text below roughly 200 tokens from the watermarking expectation. Any provider weighing signature should treat those commitments as the operative specification, because the Article itself offers no comparable detail.

February 2027 constrains the technical decision being taken now

Code signatories have until 2 February 2027 to put an interoperability solution in place for their watermark detection mechanisms, so that content can be verified without running it through every provider's detector in turn. The Code contemplates a query-routing method built on a public industry standard, a readable signpost embedded in the content, or a shared provider-agnostic solution.

That deadline is a commitment under the Code rather than a free-standing statutory date, and the distinction is worth holding onto. Interoperability is nonetheless one of the four quality criteria written into Article 50(2) itself, which leaves a marking scheme with no interoperability path exposed on the statutory test as well as on the Code. For a provider planning a December implementation, a proprietary approach buys eight weeks and then requires a second build.

The exposure, the authority, and a date that means two different things

Non-compliance with Article 50 falls under Article 99(4)(g): administrative fines of up to 15,000,000 euros or, where the offender is an undertaking, up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs and start-ups, Article 99(6) applies the lower of the two figures. Enforcement sits with national market surveillance authorities, save where the new Article 75(1) confers exclusive competence on the AI Office, which covers systems built on a general-purpose AI model by the same provider or undertaking, and systems integrated into very large online platforms or search engines.

One source of confusion is worth removing. 2 December 2026 is also the date on which the two prohibited practices inserted into Article 5 by the Digital Omnibus take effect, together with the new Article 5(1a) delimiting their personal scope. That regime addresses different operators, concerns non-consensual intimate imagery and child sexual abuse material rather than marking, and carries the higher band of up to 35,000,000 euros or 7% of worldwide turnover. Article 5(1a) is a new paragraph with no relationship to Article 5(1), point (a), on subliminal techniques, which has been in force since February 2025. We have addressed the provider-scope question under Article 5(1a) separately.

The weeks that remain

The work that fits in the time available is a short list. Inventory every system that generates synthetic content and record, for each one, whether the company is provider, deployer or both. Fix the date of first making available in the Union and place the evidence somewhere retrievable. Run the Article 50(1), (3) and (4) assessment as a separate and already overdue workstream, since nothing in the Omnibus touched it. Choose a marking architecture with an interoperability route in preference to the fastest thing that ships. Document every exception relied on, whether obviousness, standard editing or editorial responsibility, at the moment of reliance rather than afterwards.

The four months were granted for a technical retrofit that is genuinely difficult. The assessment identifying who owes what was never on that timetable, and it is what most organisations still owe. Where that assessment has to be signed by someone carrying professional liability for it, our AI Act work for providers is built around exactly that deliverable.

If your situation fits, you can book a Virtual Consultation here (90 euros, VAT included, deductible from the first invoice if we go on to accept the engagement).

Questions we are being asked

Our generative feature runs on a third-party model. Are we the provider for Article 50(2) purposes?

Article 50 attaches to systems rather than to models. Under Article 3(3), an entity that develops a system, or has one developed, and places it on the market or puts it into service under its own name or trade mark is that system's provider. The marking duty for its outputs is yours, whatever the upstream model provider does under Chapter V. Contractual assurances that the model marks its outputs do not transfer the obligation, though they may form part of how you discharge it. Verify what the marking actually consists of and whether it survives your own processing pipeline.

We signed the Code of Practice. Does that give us until February 2027 for marking?

No. The 2 February 2027 commitment concerns interoperability of detection mechanisms. The marking duty itself fell due on 2 August 2026, or on 2 December 2026 for a system placed on the market before August. Signature changes how compliance is demonstrated, and leaves the dates untouched.

We are established outside the EU with no European entity. Does Article 50 reach us?

Article 2(1)(c) applies the Regulation to providers and deployers located in a third country where the output produced by the AI system is used in the Union. A US or UK company serving EU users through a generative product is within scope for the paragraphs matching its role. The connecting factor is the use of the output in the Union, and it operates irrespective of where the company sits.

VIRTUAL CONSULTATION · 60 MIN

If You Think You Need Us, Tell Us.

90
60
100
%