The countdown is real. On August 2, 2026 — less than 60 days from now — the European Union’s AI Act begins enforcing its Article 50 transparency obligations. If your business uses any generative AI tool to produce content (text, images, audio, video), you are in scope. This is not a regulation for Big Tech. It applies to marketing teams, agencies, SaaS products, e-commerce brands, and any organization that touches AI-generated content in the EU market.
The good news: compliance is achievable. The bad news: most companies haven’t started. Here’s what you actually need to know and do.
What Happens on August 2, 2026
Article 50 of Regulation (EU) 2024/1689 — the EU AI Act — establishes mandatory transparency obligations for AI systems. This is the third wave of the regulation’s rollout. The first wave (February 2025) banned outright harmful AI practices such as social scoring and real-time biometric surveillance. The second wave (August 2025) introduced rules for general-purpose AI models. Now comes the one that affects the broadest set of businesses.
What makes Article 50 unusual — and often misunderstood — is its scope. It does not target only high-risk AI systems. It applies to any AI system that interacts with people or generates synthetic content, regardless of risk level. If you run a customer-facing chatbot, publish AI-generated blog images, use an AI voice for customer support, or create video content with generative tools, Article 50 applies to you.
The 4 Core Obligations of Article 50
The regulation defines four specific situations that trigger transparency requirements:
- AI interaction disclosure. Any system designed to interact directly with people — chatbots, virtual assistants, AI support agents — must inform users that they are talking to an AI. This obligation is unambiguous and starts on August 2, no exceptions and no grace period.
- Machine-readable marking of AI-generated content. Providers of generative AI systems must ensure outputs (images, video, audio, and text) are marked in a machine-readable format that identifies the content as AI-generated. This is the watermarking obligation under Article 50(2).
- Deepfake detection and disclosure. Anyone deploying AI systems that generate or manipulate images, video, or audio of real people in a way that could mislead must clearly label that content as artificially generated or altered.
- AI-generated content on public interest topics. When AI is used to produce text intended for publication on matters of public interest — news, political analysis, journalism — it must be disclosed as AI-generated.
How the Watermarking Requirement Actually Works
This is the part where the regulation gets technical — and where the Draft Code of Practice (developed by independent experts and expected to be finalized shortly) provides critical guidance.
The Code adopts a multilayered approach to watermarking, meaning a single technique is not sufficient. The layers work together to ensure marks cannot be easily removed or degraded:
- Metadata watermarking. Machine-readable provenance data — who generated the content, when, and with which AI system — is embedded directly into the file. Standards like C2PA (Coalition for Content Provenance and Authenticity) are referenced as a baseline approach.
- Interwoven (imperceptible) watermarking. Hidden marks are embedded at the pixel or signal level, designed to survive common transformations such as compression, cropping, or format conversion. This is the hardening layer — it ensures the mark persists even if the metadata is stripped.
- Fingerprinting as a fallback. Where active marking fails or content has been manipulated to remove marks, providers are expected to implement logging or fingerprinting systems that allow content to be identified and verified after the fact.
For text content specifically, the Draft Code acknowledges a technical reality: embedding imperceptible watermarks directly into text tends to degrade quality or produce unnatural output. The pragmatic alternative endorsed by the Code is the Provenance Certificate — a digitally signed manifest formally linking the text to its AI origin, without altering the content itself.
Importantly, the regulation does not mandate a specific technical standard. Companies may develop internal solutions, use third-party services, or build on open standards. What matters is that the solution is robust, machine-readable, and not trivially removable.
The Omnibus Twist: Don’t Misread the Grace Period
In May 2026, the EU reached a provisional agreement on an AI Omnibus — a package of amendments to the original Act. One provision has been widely reported as “a delay” for watermarking. The reality is more nuanced.
AI systems already on the market before August 2, 2026 benefit from a four-month grace period — until December 2, 2026 — before the machine-readable watermarking requirement under Article 50(2) applies to them specifically. This only covers existing, unchanged systems.
What the grace period does not cover: the obligation to disclose AI interaction to users starts August 2 regardless. If your chatbot goes live today and doesn’t tell users it’s an AI, you are already non-compliant from day one. The same applies to deepfake labeling and public interest content disclosures.
The grace period is a technical runway, not a free pass. Use it to implement watermarking properly — not as a reason to postpone.
Who Will Enforce This — and Where
For companies operating in Spain, enforcement does not come from Brussels. It comes from AESIA — the Agencia Española de Supervisión de la Inteligencia Artificial, headquartered in A Coruña. AESIA is already operational and has preliminary investigations open. It is the first national AI supervisory authority in the EU to become active.
Like the GDPR before it, the AI Act has extraterritorial reach: it applies to any business whose AI systems are used by people in the EU, regardless of where the company is based. A US startup, a Latin American SaaS, a UK agency with EU clients — all are in scope if their AI-generated content reaches EU users.
The Sanctions: What Non-Compliance Actually Costs
Violations of Article 50 obligations carry administrative fines of up to €15 million or 3% of global annual turnover, whichever is greater. More serious violations — prohibited practices, high-risk system failures — escalate to €35 million or 7% of global turnover.
Beyond fines, the regulation gives supervisory authorities the power to prohibit the deployment of non-compliant AI systems in the EU market. For businesses that depend on AI-powered products, that is a far more consequential risk than the financial penalty alone.
Your Minimum Compliance Checklist for August 2026
With less than 60 days left, here is the minimum viable action plan for a business that uses — but does not build — AI systems:
- Audit your AI touchpoints. Map every tool your team uses that generates content or interacts with users. ChatGPT, Midjourney, Adobe Firefly, ElevenLabs, Synthesia, AI chat widgets — all qualify. Document the modality (text, image, audio, video) and the use case.
- Add AI disclosure to all user-facing interactions. Any chatbot, AI assistant, or automated voice system must clearly inform the user they are interacting with AI. Update scripts, onboarding flows, and chat interfaces before August 2.
- Implement labeling for AI-generated visual and audio content. At minimum, add visible labels to published AI-generated images, video, and audio (“Created with AI” or equivalent). Machine-readable metadata should follow as you implement the technical layer.
- Check whether your AI tools are already C2PA-compliant. Major platforms — Adobe, Microsoft, Google, OpenAI — have already started embedding C2PA provenance data. Verify whether the tools you use output compliant metadata by default, and whether your publishing workflow preserves it.
- Establish a provenance logging process for text. If you publish AI-generated editorial content, start documenting creation records: which tool, which date, which version. A simple internal log satisfies the spirit of the Provenance Certificate approach while formal standards are finalized.
- Assign ownership. Designate someone — legal, compliance, or a senior digital lead — responsible for AI Act compliance. This does not require a dedicated hire, but it does require an accountable person before the deadline.
The Bottom Line
The EU AI Act is not a future concern. Article 50 enforcement begins in weeks, and the obligation to declare AI interactions to users is already overdue for many businesses. The watermarking and provenance requirements are technically achievable — and largely being built into the major platforms already. What most companies lack is not technology, but process: clear ownership, documented workflows, and visible labeling.
The companies that treat this as a compliance checkbox will scramble. The ones that treat it as a trust-building opportunity — transparent about how they use AI, consistent in how they label it — will be ahead of the curve when enforcement begins in earnest.
The clock is ticking. August 2 is not a soft deadline.


