Updated: August 2, 2026 — Added: Article 4 AI competency obligations now active; Aug 2028 sector-specific deadline clarified; FAQ added.
Published: August 1, 2026, 18:10 IST
EU AI Act Article 50 is enforceable from August 2, 2026. Every AI chatbot, voice assistant, and synthetic-content tool serving EU users must disclose its AI nature — or face fines up to €15 million or 3% of global annual turnover. The delay that dominated headlines applied only to high-risk Annex III systems; transparency rules never moved.
What Article 50 Requires From Today
Article 50 requires interactive AI systems to tell users they are talking to an AI “at the latest at the time of the first interaction,” in plain, accessible terms. According to the Cloud Security Alliance AI Safety Initiative, the duty falls on providers and deployers of chatbots, synthetic-media generators, emotion-recognition systems, and deepfake tools — regardless of whether the system qualifies as high-risk under Annex III. Three further obligations apply from today:
- Synthetic-content watermarking: image, audio, video, and text generators must embed machine-readable markers. Systems already on the market before August 2 get a grace period until December 2, 2026 to add watermarking.
- Deepfake disclosure: deployers of deepfakes and AI-generated public-interest text must disclose AI generation, with an exemption for clearly artistic or satirical content.
- Emotion-recognition notification: deployers of emotion-recognition or biometric-categorization systems must inform the people exposed to them.
The burden of proving timely disclosure rests on the organization, not the regulator. National market surveillance authorities in each EU member state enforce the penalties independently.
Article 4 AI Competency: The Obligation Most Teams Overlooked
Article 4 of the EU AI Act entered force in February 2025 and carries renewed significance from August 2, 2026 — yet most compliance teams overlooked it entirely while focused on Article 50’s chatbot labeling rules. Article 4 requires every individual who operates an AI system on behalf of a provider or deployer to demonstrate a “sufficient level of AI competence” proportionate to their role. According to Bayootec’s June 2026 compliance guide, this extends beyond technical teams to employees in marketing, HR, or sales who routinely use tools such as ChatGPT, Microsoft Copilot, or Salesforce Einstein. Companies must establish documented training programs — participation records must be producible to regulators on request. An organization that has rolled out AI broadly across commercial functions without a competency framework is now non-compliant on two fronts simultaneously: Article 50 disclosure and Article 4 literacy. Penalties apply to both.
Why the “EU AI Act Delayed” Message Was a Trap
The Digital Omnibus package, approved by the EU Council on June 29, 2026, delayed only specific high-risk categories. Autonomous high-risk systems under Annex III (covering hiring, credit scoring, and education) are deferred to December 2, 2027. AI embedded in regulated products under Annex I (medical devices, machinery, automotive safety components) faces a further deferral to August 2, 2028, because EU harmonized technical standards remain unfinished. Article 50 was never part of either deferral — it attaches by function, not risk tier. According to Holland & Knight’s April 2026 compliance bulletin, the Cloud Security Alliance names OpenAI’s ChatGPT and Anthropic’s Claude as falling “squarely within scope” as conversational AI providers, which puts mainstream enterprise deployments — not just niche deepfake tools — under Article 50 today. Small Mid-Caps, defined as companies with up to 750 employees and €150 million in revenue, receive a simplified compliance framework under the June 2026 amendments.
Which Business AI Tools Are Affected
Four categories of enterprise AI tools now carry Article 50 disclosure duties for EU-facing deployments:
- CRM and support chatbots — Salesforce Agentforce, HubSpot Customer Agent, Zoho SalesIQ, and Intercom Fin must state at first interaction that the user is talking to an AI.
- AI image generators — Canva AI, Adobe Firefly, and Midjourney need machine-readable watermarks on every output file by December 2, 2026.
- AI writing tools producing public-facing text — Jasper and Copy.ai must embed metadata markers on EU-audience content.
- HR sentiment-analysis tools — any tool that applies AI emotion recognition to EU employee interactions must notify the individuals exposed.
Businesses deploying autonomous AI agents for tasks like customer service and sales should verify each agent’s EU disclosure behavior before deployment. The fine accrues per violation, not per product, so a single enterprise chatbot handling 10,000 EU sessions without a disclosure could face liability on each session.
For Context
WithO2 has covered the enterprise AI systems now in Article 50’s scope: Salesforce Agentforce’s customer service chatbot went GA with per-resolution pricing, and Unstop launched 7 AI agents to automate enterprise hiring — the hiring category the EU treats as high-risk from December 2, 2027.
Frequently Asked Questions
Does EU AI Act Article 50 apply to US companies?
Yes. Article 50 applies to any provider or deployer that places an AI system on the EU market or that makes an AI system accessible to EU users — regardless of where the company is headquartered. A US SaaS product with EU customers is in scope today.
What is the penalty for not disclosing an AI chatbot under the EU AI Act?
Fines for Article 50 violations are set at up to €15 million or 3% of global annual worldwide turnover, whichever is higher. National market surveillance authorities in each EU member state can initiate enforcement independently.
Was the EU AI Act delayed to 2027?
Partially. The Digital Omnibus (approved June 29, 2026) delayed high-risk AI obligations under Annex III to December 2, 2027 and Annex I obligations to August 2, 2028. The Article 50 transparency requirements — chatbot disclosure, deepfake labeling, synthetic-content watermarking — took effect on schedule on August 2, 2026.
What does Article 4 AI competency require from employees?
Article 4 requires that everyone who operates an AI system for a business must have a “sufficient level of AI competence” suited to their role. This means marketers, HR staff, and salespeople who use ChatGPT, Copilot, or similar tools in their work need documented AI literacy training. Companies must be able to show regulators that training was completed.
Does the EU AI Act apply to AI-generated images and videos?
Yes. Under Article 50, providers of AI systems that generate synthetic images, audio, video, and text must embed machine-readable markers in the output. Systems already on the market before August 2, 2026 have until December 2, 2026 to add watermarking. Deepfakes used in public-interest contexts must carry an explicit AI-generated disclosure visible to end users.