EU AI Act Transparency Rules Are Live From August 2026: Here Is How We Comply
The EU AI Act's Article 50 transparency obligations are live from 2 August 2026. Here is what they require and how we already comply.
Transparency is not a box to tick before the regulator calls. It is the foundation on which customers decide to trust an AI-powered business, and we chose to build that foundation before the deadline, not after it.The Agency
Find the gaps leaking the most revenue
Show me my revenue leak Your annual leak in pounds, in 30 seconds. Free.The EU AI Act's Article 50 transparency obligations became applicable on 2 August 2026, and any business running AI systems in front of customers now has four live legal duties, fines of up to EUR 15 million or 3 per cent of worldwide annual turnover for non-compliance, and very little room to argue ignorance. For businesses using AI agents to generate leads, qualify prospects or handle customer conversations, this is not a future consideration. It is a present one. The good news is that compliance is straightforward if it is built in from the start, and that is exactly what we did at The Agency, shipping our AI disclosure labels to production on 27 July 2026, ahead of the deadline.
What the Law Actually Is
The EU AI Act is Regulation (EU) 2024/1689. It is the European Union's comprehensive framework for regulating artificial intelligence across a wide range of risk categories, from minimal-risk applications all the way through to prohibited systems. The Act has staggered application dates, meaning different obligations have come into force at different points. Article 50, the transparency chapter, became applicable on 2 August 2026. This is the provision that governs how businesses must communicate with people when AI is involved in the interaction. It does not replace GDPR. It does not impose specific cyber-security controls. It is, straightforwardly, a transparency regime: a set of rules about disclosure, labelling and honest communication. Businesses that already operate with genuine transparency in their AI deployments will find the requirements sensible. Businesses that have been vague or silent about AI involvement in their customer-facing processes will find the adjustment more significant.
The Four Obligations Under Article 50
Article 50 sets out four distinct transparency obligations, and it is worth understanding each one clearly because they land on different parties in different ways.
The first obligation is that AI systems which interact directly with a person must make clear that the person is dealing with a machine, unless that is obvious from context. This is the chatbot disclosure rule. If you are running an AI agent to handle inbound enquiries, qualify leads or book calls, the person on the other end must know they are talking to an AI before the conversation substantively begins. Under Article 50(1) this duty sits with the provider, meaning whoever places that system on the market, though in practice the business running the conversation is the one who has to make sure the customer actually sees the disclosure.
The second obligation is that AI-generated content must be marked. Article 50(2) additionally requires machine-readable marking, commonly called watermarking, of synthetic audio, image, video and text for systems placed on the market from 2 August 2026. This is the provision with the one meaningful extension: the AI Omnibus provisional agreement of May 2026 gives generative AI systems already on the market before that date until 2 December 2026 to meet the machine-readable marking requirement. New systems have no such grace period.
The third obligation applies where an AI system is used to recognise emotions or categorise people biometrically. In that case, the deployer must inform the people who are exposed to it. For most businesses in the AI marketing and lead generation space, this obligation will not be the most pressing, but it matters for anyone using sentiment analysis in customer-facing contexts in ways that feed into categorisation.
The fourth obligation covers deepfakes and AI-generated text published on matters of public interest, which must be disclosed as artificially generated. This is aimed at media and public communications contexts, but any business publishing AI-generated content on public affairs topics needs to be across it.
Who the Obligations Land On
Article 50 splits its duties between two parties, and knowing which one you are matters. Article 50(1), telling people they are dealing with a machine, and Article 50(2), marking AI-generated output in a machine-readable way, both fall on providers, meaning whoever places the system on the market. Article 50(3), informing people exposed to emotion recognition or biometric categorisation, and Article 50(4), disclosing deepfakes and AI-generated text on matters of public interest, fall on deployers, meaning the businesses that put those systems to work.
That split is not a way out. Most businesses are deployers of someone else's model and providers of their own product built on top of it, so both sets of duties tend to land in the same place. If you are using a third-party AI platform to run your customer conversations, the obligation to disclose does not disappear because someone else built the underlying model: whoever puts that experience in front of a customer has to make sure the disclosure happens at the point of interaction. For any business using AI lead generation and customer engagement tools to grow revenue, this means building disclosure into your product flows, not leaving it to a footer or a buried terms page. What a customer actually experiences is the thing being regulated, so that is where the effort belongs.
What Penalties Look Like
Non-compliance with Article 50 can attract fines of up to EUR 15 million or 3 per cent of worldwide annual turnover, whichever is the higher figure. These are not token amounts. The turnover limb means the ceiling rises with the size of the business.
We are not going to guess at how hard this will be enforced in its first months, because nobody credibly can on the day it becomes applicable. What is knowable is the standard itself, and that documenting your compliance steps matters as much as taking them, because a disclosure you cannot evidence is one you may as well not have made.
How We Built Compliance at The Agency
We want to be direct about this: we are not describing a compliance framework we are planning to build. We are describing one that is already live. Our AI disclosure labels went to production on 27 July 2026, ahead of the 2 August 2026 deadline. They carry a clear, plain-language disclosure at the point of engagement.
Our AI action log stores structured fields and a hash only, never the text of a customer message. This is a deliberate design choice that serves both compliance and privacy: we maintain the audit trail that regulators may request without creating a repository of sensitive conversation content. Our retention periods are fixed in code rather than left to policy documents that can drift. Conversations are retained for 12 months, AI action logs for 24 months, event logs for 12 months, error logs for 90 days, and compliance records for the life of the customer relationship plus 6 years.
We run data export, erasure and suppression endpoints, meaning customers can exercise their rights without requiring manual intervention from our team. We hold a signed data processing agreement with every one of our seven processors. None of this happened because a regulator asked for it. It was built in because building AI tools for businesses means building them in a way that those businesses can confidently deploy without creating legal exposure for themselves.
What Compliance Looks Like in Practice
For a business deploying an AI agent for lead generation or customer engagement, Article 50 compliance in practice comes down to three things. First, a clear disclosure at the moment the AI interaction begins: not after the person has already engaged, not in the privacy policy, but at the point of first contact. Second, a record that the disclosure was made, in a form that can be retrieved if a regulator or a customer asks for it. Third, if you are generating and publishing AI content, appropriate labelling and, for new systems, machine-readable marking.
None of this requires extraordinary technical investment. It does require intentionality. The businesses that will struggle are those running AI in customer-facing contexts without any documentation, any disclosure UI, or any audit trail. The businesses that will find this straightforward are those that built AI into their products honestly from the beginning.
It is also worth being clear about what Article 50 does not require. It is about disclosure rather than about how your AI is built. It is a transparency law. It asks you to be honest with people about when AI is involved. That is a reasonable ask, and it is one that businesses generating leads and revenue from AI-powered tools should be able to meet without compromising their competitive position.
The Practical Takeaway for AI-Powered Businesses
If your business runs AI in any customer-facing context, you now need two things as a baseline: a disclosure and a record. The disclosure tells the customer they are interacting with AI. The record proves you told them. Everything else in Article 50 builds from those two foundations.
At The Agency, we build both in by default. That is not a marketing claim. It is reflected in how our systems are architected, what our retention schedules say, and the fact that our disclosure labels were live before the legal deadline arrived. The EU AI Act's transparency obligations are not a burden on businesses that are already operating honestly. They are a minimum standard that the rest of the market now has to meet. The businesses that grow fastest in AI marketing and lead generation over the coming years will be the ones that customers trust, and trust starts with being clear about what you are.
Find the gaps leaking the most revenue
Show me my revenue leak Your annual leak in pounds, in 30 seconds. Free.Frequently asked questions
When did the EU AI Act transparency rules come into force?
Article 50 of the EU AI Act, Regulation (EU) 2024/1689, became applicable on 2 August 2026. This is the transparency chapter of the Act and it applies to any business deploying AI systems that interact with people, generate content, or perform biometric categorisation. It does not cover every provision of the Act, which has staggered application dates.
What are the fines for not complying with Article 50?
Non-compliance with the Article 50 transparency obligations can attract fines of up to EUR 15 million or 3 per cent of worldwide annual turnover, whichever is higher. These are not trivial sums for any business operating at volume, and regulators across EU member states are the primary enforcement bodies. Businesses outside the EU that deploy AI to EU residents are also in scope.
Does the EU AI Act apply to businesses outside the EU?
Yes. If your AI system interacts with people located in the EU, the Act applies to you regardless of where your business is incorporated. The Agency is a Gibraltar company, and Gibraltar has applied EU GDPR since 15 July 2026 with the Gibraltar Regulatory Authority as its data protection regulator, which is why we build to EU-aligned standards by default.
What is the AI Omnibus extension for machine-readable watermarking?
The AI Omnibus provisional agreement of May 2026 gives generative AI systems that were already on the market before that date until 2 December 2026 to meet the Article 50(2) machine-readable marking requirement. This is a narrow extension covering only watermarking of synthetic audio, image, video and text on legacy systems. New systems placed on the market from 2 August 2026 onwards must comply immediately.
Is the EU AI Act a data security or privacy law?
No. Article 50 is a transparency regime, not a cyber-security or data protection regime. It does not require you to encrypt customer data in any specific way, nor does it replace GDPR. What it does require is honest disclosure: telling people when they are talking to a machine, labelling AI-generated content, and marking synthetic media. Security and privacy obligations come from separate legislation.
What does an AI disclosure label need to say?
The law does not prescribe exact wording, but the obligation under Article 50(1) is that the person must be made clearly aware they are interacting with an AI system and not a human, unless that is obvious from context. In practice this means a clear, plain-language label at the point of interaction, placed before the conversation begins rather than buried in a footer or terms page.