Executive briefing · week of 3 August 2026. All regulatory and technical claims verified against public sources, cited inline.
1. What happened
Three events, closely spaced, closed the drafting phase of Article 50 and opened the enforcement phase.
First, on 10 June 2026 the European AI Office released the Code of Practice on Transparency of AI-generated Content — a voluntary framework through which signatories can demonstrate compliance with the marking and disclosure duties in Article 50(2), (4) and (5). On 8 July the Commission, and on 9 July the AI Board, concluded that the Code is adequate to facilitate the practical implementation of those provisions (Reed Smith; digital-strategy.ec.europa.eu).
Second, on 20 July 2026 the Commission adopted the final version of its Guidelines on the implementation of the transparency obligations under Article 50 — less than two weeks before the obligations began to apply. The final Guidelines keep the nine-section structure of the draft (interactive systems, synthetic-content marking, emotion recognition, biometric categorisation, deepfakes, horizontal information requirements, enforcement and so on) and add interpretive detail and worked examples (Bird & Bird).
Third, on 2 August 2026 the transparency obligations of Article 50 entered into application (Commission enforcement note). Running in parallel, the Digital Omnibus simplification package — given final adoption by the Council on 29 June, following Parliament's endorsement on 16 June — deferred the machine-readable marking sub-obligation in Article 50(2) to 2 December 2026 for synthetic-content systems placed on the market before 2 August, and moved most stand-alone high-risk Annex III deadlines to 2 December 2027 (Consilium; Gibson Dunn).
2. What it actually changes
The most important change is not a new rule; it is the removal of ambiguity about the shape of a compliant answer.
The Code of Practice, and the Guidelines that complement it, make explicit that no single marking technique currently satisfies all four legal requirements of Article 50(2) — effectiveness, interoperability, robustness and reliability. Providers are therefore directed toward a layered solution combining digitally-signed metadata and imperceptible watermarking, with an optional third mechanism of fingerprinting or logging that, as the guidance puts it, "requires a registry database" for recovery (TechPolicy.Press). This is a material shift in the compliance conversation: the question is no longer "which marking technique" but "which combination", and any product positioned as a single-technique answer now sits awkwardly against the regulator's own framing.
The second change is temporal and widely misread. The Digital Omnibus deferral is narrow. It touches only the marking sub-obligation in 50(2), and only for synthetic-content systems already on the market before 2 August. The disclosure duties — informing users they are interacting with an AI, labelling deepfakes and synthetic media, disclosing emotion-recognition and biometric-categorisation — apply from 2 August with no grace period, for systems old and new. "Delayed to December" is true only of a sub-clause; it is false as a description of Article 50 as a whole.
The third change is institutional. By the end of July roughly 190 organisations had signed the Code of Practice, including the major model providers — Anthropic, Google, Meta, Microsoft, Mistral, OpenAI, Cohere, Aleph Alpha, Black Forest Labs and Synthesia — and a first wave of enterprise deployers such as Getty Images, Iberdrola, Lenovo, Lufthansa, Bulgari and Fastweb (digital-strategy.ec.europa.eu; TechPolicy.Press). Signing is voluntary, but it establishes an EU-recognised route to demonstrating compliance, and it signals where the centre of the market is settling.
3. Who is affected
The scope is broader than the high-risk debate suggests. Article 50 offers no general SME exemption, and an organisation with no high-risk AI at all can still be in scope simply by operating a customer-facing chatbot, publishing AI-generated or AI-edited media, or producing AI-drafted text on matters of public interest. In practice this reaches nearly every consumer-facing enterprise in the EU, plus non-EU providers whose systems are used in the Union. Penalties for breach of the disclosure obligations run up to €15 million or 3% of worldwide annual turnover, whichever is higher.
Deployers carry the disclosure duties that are live now. Providers of synthetic-content systems carry the marking duty — now for systems placed on the market on or after 2 August, and from 2 December for the pre-existing estate. Assurance and advisory firms — the Big Four and mid-market law firms building AI-assurance practices — are affected as intermediaries: their clients now need demonstrable, technical answers rather than policy memos.
4. Implementation requirements
The Guidelines and Code, read together, imply a concrete checklist. Disclosure copy must be present and unavoidable at the first point of interaction for chatbots, and clearly attached to synthetic media. Marking, where it applies, should be layered: signed C2PA-style metadata for interoperability, an imperceptible watermark robust to routine editing and re-encoding, and — as the guidance's optional but recommended third mechanism — a registry or logging layer that allows a credential to be recovered after metadata is stripped. C2PA remains the reference metadata standard; version 2.1 was ratified in 2025 and is now an ISO standard (ISO/IEC 22144), and Durable Content Credentials already combine manifest, watermark and fingerprint recovery in the same layered pattern (contentauthenticity.org). Organisations choosing the Code-of-Practice route should also review the signatory process and the horizontal information requirements the Guidelines set out.
5. What to do this quarter
Audit live systems first: every EU-facing chatbot, every published synthetic image or video, every AI-drafted public-interest text should carry compliant disclosure today. Build the two-column view — obligations live now versus obligations due 2 December — so that the marking project for the legacy estate is scoped without letting the live disclosure gap sit open. For synthetic-content providers, begin the 50(2) marking design against the three mechanisms rather than selecting a single tool, and decide whether to demonstrate compliance via the Code of Practice. For advisory firms, pair the assurance offering with a technical marking-and-registry layer, because clients will now ask to see the mechanism, not just the policy.
6. AIACT50's reading
For a year the market argued about which single signal — watermark or metadata — would carry Article 50. The EU's own adequacy-assessed guidance has now answered that none of them does alone, and has described the layered architecture instead: signed metadata, robust watermarking, and a registry for recovery. That is precisely the architecture AIACT50 was built around, which means our task this week is not to claim vindication but to explain the layers as neutrally and precisely as the guidance does — including the third, registry layer that the market has largely ignored and that becomes decisive the moment content leaves a controlled pipeline. The discipline for the quarter is to sell the architecture the regulator has converged on, not the fear of the fine attached to it.
Sources: Commission enforcement note (2 Aug 2026) · Code of Practice · Commission Guidelines · Bird & Bird · Reed Smith · TechPolicy.Press · Consilium (29 Jun 2026) · Gibson Dunn · Content Authenticity Initiative.
If you want to see how signed metadata, robust watermarking and a recovery registry are combined into a single implementation:
Explore AI Act 50 →