2 July 2026 · Updated: 10 August 2026
22 July and 2 August: who does Article 50 AI Act really apply to?
The deadline of 22 July 2026 at 18:00 CEST for organisations that wanted to appear on the initial list of signatories to the Code of Practice on Transparency of AI-Generated Content has passed. The code itself is voluntary. From 2 August 2026, Article 50 AI Act duties apply to systems within its scope. These are two different dates and two different events.
Signing is not a duty for every company using ChatGPT, Copilot or an image generator. First establish the organisation’s role and the use case. Only then can you tell whether the business is a provider covered by Article 50(1) or (2), a deployer in a situation covered by paragraph (3) or (4), or an ordinary user for whom that particular duty does not arise.
The shortest answer: 22 July was about appearing on the initial signatory list. Signing the code is voluntary, and not signing does not constitute non-compliance with the AI Act. From 2 August, an organisation within Article 50 that has not signed demonstrates compliance by other adequate means.
What happened on 22 July 2026?
The European Commission invited providers and deployers within Article 50(2) and (4) to sign the Code of Practice on Transparency of AI-Generated Content. Submitting the form by 22 July 2026, 18:00 CEST enabled an organisation to appear on the initial signatory list published before 2 August.
This was not a final deadline for joining the code. The Commission FAQ says providers and deployers can sign later. The 22 July date determined inclusion on the first list, not whether an organisation “can be compliant”.
The code describes practices involving machine-readable marking, metadata, watermarking and disclosures for deepfakes and other AI-generated or manipulated content. It may support a compliance case, but it does not remove the need to assess the organisation’s own system and duties.
What applies from 2 August 2026?
From 2 August 2026, the duties in Article 50(1)–(5) apply. They cover AI systems within the provision that are placed on the EU market or put into service in the EU. They do not depend on whether an organisation signed the code.
The practical distinction is:
- a signatory can use the code’s practices as part of its approach to demonstrating compliance;
- a non-signatory can still be compliant, but must demonstrate compliance through other means, whose adequacy will be assessed by the competent market-surveillance authority.
After 2 August, a “sign / do not sign” decision is still not enough. Evidence is needed: system inventory, role, scope of duty, marking or disclosure mechanism, owner, test and proof that the control operates.
Which paragraph applies to whom?
Article 50(1) — the system interacts directly with a person
The provider of a system intended to interact directly with people must ensure they are informed that they are interacting with AI, unless this is obvious to a reasonably well-informed, observant and circumspect person. In practice, this may cover a website chatbot, an in-app assistant or a voicebot.
Article 50(2) — the system generates synthetic content
The provider of a system that generates or manipulates image, audio, video or text must ensure that outputs are marked in a machine-readable format and detectable as AI-generated or manipulated. The provision includes exceptions, including for standard assistive functions that do not substantially alter input data or its semantics.
Article 50(3) — emotion recognition and biometric categorisation
The deployer informs the people exposed to such a system. Prohibited-practice rules must be checked separately: emotion recognition in the workplace and education is generally prohibited, subject to narrow medical or safety exceptions.
Article 50(4) — deepfakes and certain publicly disseminated text
A deployer using a system to generate or manipulate deepfakes must disclose that the content was artificially generated or manipulated. The duty also covers certain AI-generated or manipulated text published to inform the public on matters of public interest. Artistic, satirical, fictional and analogous works have a specific disclosure treatment, while text subjected to human review or editorial control may fall within an exception where a person or entity holds editorial responsibility.
Triage: does your company need to act?
Instead of asking “do we use generative AI?”, work through five questions:
- What does the system do? Does it interact, generate content, recognise emotion, create deepfakes or merely assist editing?
- What is the company’s role? Is it a provider developing or placing the system on the market, or a deployer using an off-the-shelf tool in its process?
- Where does the output go? To an employee, a customer, a public information service, a campaign or an internal draft?
- Does an exception apply? For example, human editorial review with responsibility, an obvious AI interaction or a standard assistive function.
- Which evidence remains? Interface capture, marking configuration, metadata, detectability test, editorial procedure, owner and change log.
Run this triage per system and per use case. A company can be a deployer in one process and a provider in another. One qualification should not be copied across the entire tool catalogue.
Operational checklist after 2 August
- Inventory AI–human touchpoints: chatbots, voicebots and text, image, audio or video generators.
- Assign a role and the relevant Article 50 paragraph to every use case.
- Check the user notice before interaction starts, not only in the terms.
- Verify machine-readable marking after export, conversion and publication, not only inside the source tool.
- Define the disclosure process and any editorial-control exceptions.
- Name an owner, threshold and test evidence. A policy alone does not show that a control works.
- Make an informed code decision: sign, join later or use your own set of adequate measures.
The fields, outcomes and decisions can be recorded in Semitora’s open Evidence Pack template. It is not automatic proof of compliance, but it forces the system version, owner, test and result to be named.
What about the Digital Omnibus?
Amending Regulation (EU) 2026/1744 (the Digital Omnibus) entered into force on 27 July 2026. For Article 50(2), it introduces a transitional rule for providers of generative systems placed on the market or put into service before 2 August 2026: compliance with machine-readable marking and detectability must be ensured from 2 December 2026.
That rule does not postpone the application date of Article 50 as a whole. From 2 August 2026, the provision’s other duties apply to systems within its scope, while outputs generated and already made available before that date do not need to be labelled retroactively.
Official source and disclaimer
The scope of duties, roles, exceptions and alternative adequate means is described in the Commission Guidelines on Article 50 of 28 July 2026. Signing status and procedural answers remain in the Commission FAQ on signing the Code, while the transitional rule is established by Regulation (EU) 2026/1744.
This article is informational. It does not replace legal advice or classification of a specific system. Duties depend on the organisation’s role, the use case, system function and the exceptions in the AI Act.
What next
If you need a system inventory, role qualification, marking test and evidence package, see the AI Act audit and AI Assurance & Governance. We can assess controls in a system built by another supplier without taking over the whole project.