Executive briefing · week of 27 July 2026.
1. What happened
On 20 July 2026, the European Commission adopted the final Guidelines on the transparency obligations for certain AI systems under Article 50 of the AI Act — less than two weeks before those obligations begin to apply on 2 August 2026 (Bird & Bird; European Commission). The guidelines are the authoritative interpretation of a regime that has been contested for over a year: how providers and deployers of generative and interactive AI must be transparent about it.
They arrive in a crowded week. The Code of Practice on Transparency of AI-Generated Content, published in June, set the initial signatory deadline at 27 July, 18:00 CEST (European Commission). Google signed and committed to opening its SynthID watermarking to Apple, NVIDIA and OpenAI; OpenAI and Mistral also signed; Meta declined, arguing the Code reaches beyond the Act (Google; Reuters via AOL). And the Digital Omnibus — politically agreed on 7 May — sits in the background, having deferred the AI Act's high-risk obligations while leaving transparency almost entirely intact (Gibson Dunn).
The single most important line in the guidelines is a concession: the technical standards for measuring compliance with the machine-readable marking obligation are still being developed through the Code of Practice and EU standardisation work (TechTimes).
2. What it actually changes
Less than the headlines suggest, and more than the delay narrative admits.
The guidelines do not move the 2 August application date for Article 50's transparency obligations. They clarify scope across the four areas the Article governs: direct interaction (users must be told when they are dealing with an AI system), AI-generated content (providers must mark it machine-readably), emotion recognition and biometric categorisation (subjects must be informed), and deepfakes and AI-generated text on matters of public interest (deployers must disclose) (Sidley).
What the guidelines change is the level of certainty. Before 20 July, organisations were interpreting statutory text and a draft. Now there is a final reading to build against. But that reading contains a structural admission: the law requires marking to be effective, interoperable, robust and reliable, and no single deployed technique satisfies all four. C2PA content credentials — the primary mechanism named in the Code of Practice — carry rich provenance but can be stripped by a screenshot or a social re-upload. Imperceptible watermarks such as SynthID survive more processing but are not universally robust (ComplianceHub; TechTimes). The Code's response is explicit: a multilayered approach, combining marking techniques across the content value chain.
3. Who is affected
Three groups, in descending order of immediate exposure.
Deployers of interactive and generative AI in the EU. Any organisation running a customer-facing chatbot, generating synthetic media, or publishing AI-generated text on public-interest topics faces live disclosure duties from 2 August. This is the broadest population and the one most likely to have mistaken the Digital Omnibus for a general reprieve.
Providers of generative AI systems. They carry the marking obligation under Article 50(2). Crucially, systems placed on the market before 2 August receive a transitional period until 2 December 2026 before that marking obligation applies to them (Gibson Dunn). New systems do not get that runway.
Advisers and assurance providers. Law firms and the Big Four are being asked, this week, to translate the guidelines into board-ready action. The distinction between what is due now (disclosure) and what has a runway (marking) is the single most valuable thing they can hand a client — and the one most often blurred.
4. Implementation requirements
For deployers, the near-term work is unglamorous and unavoidable:
- Disclosure UX. Ensure users are informed when interacting with an AI system, in a clear and timely way; label deepfakes and, where applicable, AI-generated public-interest text. This is largely a product and copy task, and it is due on 2 August.
- Marking pipeline. For providers, embed machine-readable markers in generated outputs. The guidelines and Code point to C2PA signed metadata as the baseline, layered with a watermark for the cases where metadata is lost.
- Verification path. Because metadata is fragile in the wild, a marking pipeline that cannot be re-verified after the credential is stripped meets the letter of the obligation but fails its purpose. A durable, independent verification mechanism — an anchored registry queryable by any third party — closes that gap.
- Documentation. Keep evidence of the approach taken. With measurement standards unfinished, the defensible position is a documented, layered, upgrade-ready design rather than a single tool asserted as "compliant."
5. What to do this quarter
- Ship disclosure now. Treat the chatbot and deepfake labels as a 2 August deliverable, not a Q4 project. It is cheap relative to its legal weight.
- Design for layers, not point tools. Assume the marking standard will tighten. Build a pipeline where metadata, watermark and verification are separable and independently upgradeable, so a future standard is a configuration change, not a re-platforming.
- Test the failure mode. Take one signed asset, strip its metadata, and try to re-establish the provenance claim. If you cannot, you have found the gap the regulation will eventually close — address it before it is mandatory.
- Use the runway deliberately. For pre-existing systems, the 2 December marking transition is time to implement well, not time to ignore. Map which of your systems qualify.
- Brief advisers precisely. If you sit in legal or compliance, arm your stakeholders with the disclosure-vs-marking distinction so the organisation spends effort where the deadline actually is.
6. AIACT50's reading
The guidelines' candour is the story. A regulator that admits its measurement standard is unfinished is, in effect, describing a system rather than endorsing a product: metadata that carries provenance, a watermark that survives when metadata does not, and a durable verification layer that lets anyone re-check a claim after the file has travelled. That is not a marketing framing; it is the plain reading of a Code of Practice that mandates layering because no single technique passes all four statutory tests. The commercial temptation this week is to sell the €15 million fine. The more defensible — and more useful — position is to sell the architecture the regulation is visibly converging on, and to be honest that the hard part is not marking but verification: provenance you can prove after the credential is gone, not merely provenance you can claim at the moment of creation. AIACT50 is built to that shape, and this is the week the market is finally ready to hear why.
Sources: European Commission — Article 50 transparency guidelines · Bird & Bird · Sidley Data Matters · Gibson Dunn — Omnibus · ComplianceHub · TechTimes · Google — signing the Code · Reuters via AOL — Meta declines · Commission — signing FAQ.
If you want to see how layered marking, registry and public verification are combined into a single implementation:
Explore AI Act 50 →