Insight · 2 August 2026

Guidance on EU AI Act Article 50. The duties the delay did not move.

Straight to the checklist

Sixteen questions a regulator or auditor would ask. Three pages, built to print, no email required.

The memo starts here, for anyone who wants the reasoning behind the questions.

Since the Omnibus landed, almost every piece I have read about the EU AI Act has been about postponement. That is why this one is not.

Regulation (EU) 2026/1744 pushed the high-risk obligations out to December 2027 and August 2028. Article 50 was never part of it.

Its transparency duties apply from 2 August 2026, on the original timetable, and the penalties with them.

What Article 50 catches turns on what a service does, not on the risk tier it sits in and not on where the company sits. An AI system that talks to people, generates content, reads emotion, sorts people biometrically or produces material published to the public is caught.

Article 2 reaches providers placing AI on the EU market wherever they are established, and providers and deployers outside the EU where the system’s output is used in the Union. If people in the EU use your AI feature and receive its output, a chatbot reply, a generated file, a recommendation, that output is used in the Union and you are in scope.

What I hear most often at this point is that this is EU law, not UK law. Or more simply: I thought that didn’t apply here.

I have been having a version of this conversation since GDPR, usually with companies outside the EU working out whether a European regulation reaches them. US firms spent years insisting that one did not. It did. The wrong first question is which jurisdiction am I in. The question that settles it is where the effect lands.

With GDPR that turned on whether you set out to offer services to people in the EU or to monitor them. Article 50 does not ask what you set out to do. It asks whether the output your system produces is used in the Union, which is a lower bar than the targeting test in Article 3(2) of the GDPR.

A UK firm with EU customers is in scope. So is a US one.

The timing argument has form too. A lot of firms did nothing about GDPR until it was actually law, and some waited longer than that, until they watched other people get fined. Waiting for 2027 is the same bet: the obligations that were deferred are not the ones that apply now.

The duties are narrow. People interacting with an AI system have to be told so, before or as the interaction starts, unless it is already obvious. AI-generated audio, image, video and text carry machine-readable marking. Anyone exposed to emotion recognition or biometric categorisation is informed. Deepfakes and AI-generated text published on matters of public interest carry visible disclosure.

Article 99(4)(g) provides for fines up to EUR 15 million or 3 per cent of worldwide turnover, whichever is higher. SMEs and start-ups are capped at whichever is lower, and Regulation (EU) 2026/1744 adds a further capped tier for small mid-caps.

One honest limit. The marking duty carries the Act’s only transition: generative systems already on the market before 2 August 2026 have until 2 December 2026, and that window covers machine-readable marking alone. Nothing else in Article 50 has one.

Marking and disclosure are separate obligations, and which one falls on you depends on whether you are acting as provider or deployer. Machine-readable marking under 50(2) is the provider’s. Visible disclosure, the "this content is generated by AI" line under 50(4), is the deployer’s. A firm that checks its vendor embeds provenance and concludes it is covered may not be.

I saw this pattern constantly as a CISO, in security assurance rather than AI: organisations leaning on their suppliers to hold assurance instead of holding it themselves. Article 50 does not allow it. One duty does not discharge the other, and most organisations are both provider and deployer at once, for different systems.

Article 50 is also additional. Meeting it discharges none of the Chapter III obligations arriving in 2027 and 2028, though the evidence answers to much the same questions, so a file built now is not a file built twice.

The checklist below sets out sixteen questions a market surveillance authority, an auditor or an acquirer’s due diligence team might ask, with what the Act requires and what good looks like against each. Sixteen, for four duties, because each one has to be evidenced separately rather than asserted.

Work through it honestly and you may conclude your position is sound and that further support isn’t needed. For most firms that pass, that is the right answer. The value of the exercise is knowing, on evidence, which kind of firm you are, before somebody outside asks.

The checklist as a PDF

Stephen Randles

Founder & Principal · Alvermere

This memo is general information and does not constitute legal or regulatory advice.

All Insight