Article 50 is in force. The grace period closes 2 December 2026.
Article 50(2) is the machine-readable marking duty, and it falls on the provider of a system that generates synthetic audio, image, video or text. If yours was on the EU market before 2 August 2026, it applies from 2 December 2026. The high-risk regime most vendors are selling against was deferred to December 2027 and August 2028. This page keeps the two apart, because conflating them in front of your own counsel costs you more credibility than saying nothing.
Dates verified 1 September 2026 against the Act implementation timeline and the European Commission. Orientation, not legal advice.
Wondering whether the machinery to comply actually exists yet? We keep a register of what does and does not: harmonised standards cited, notified bodies designated, Member State authorities in place. Each checked at source, with the date.
Where things stand today: Article 50 applies, the enforcement apparatus is operating, and the next dated obligation is 2 December 2026. Nothing in the high-risk regime is due before December 2027.
82days until 2 December 2026
2 Aug 2026122 day window2 December 2026
Counted on 2026-09-11, Europe/Brussels. Systems generating synthetic content, already on the EU market before 2 August 2026, have to carry machine-readable marking.
Does this apply to us?
Six questions, in the order a compliance lead should ask them. Answering yes to any of the first four brings a system into scope for review. Answering the last two tells you which date you are working to. None of this replaces advice from counsel; it tells you whether you need to go and get some.
- 01
Do you place an AI system on the EU market, or put its output in front of people in the EU?
Reach follows the market rather than your registered address. A US company with EU users is not automatically outside this. If you have no EU users, no EU customers and no EU-facing output, it does not reach you today, and that is an answer we give often.
- 02
Does a person interact with the system directly?
Customer support assistants, voice agents, intake bots, anything where a human is on the other end of the conversation and may not know what they are talking to.
- 03
Does it generate or manipulate image, audio, video or text that reaches an audience?
Synthetic and manipulated content is the second cluster Article 50 addresses. Marketing copy generation, synthetic voice, image editing at scale, generated summaries published under your name.
- 04
Does it infer emotions, or categorize people using biometric data?
This cluster carries its own disclosure expectations and it appears in more HR, insurance and retail stacks than the people running them realize.
- 05
Was the system already on the market before 2 August 2026?
Then, if it generates synthetic content and you are its provider, Article 50(2) applies to it from 2 December 2026 rather than immediately. Systems you place on the market now are in the first group; systems you were already running are in the second. If it does not generate synthetic content, 50(2) does not reach it on either date.
- 06
Is it a general-purpose AI model you placed on the market before 2 August 2025?
Then the compliance date for that model is 2 August 2027. Note separately that since 2 August 2026 the AI Office and member-state authorities hold enforcement powers over general-purpose AI models.
Where it does not apply: we say so. Telling a US-only firm with no EU exposure that this regulation does not reach them is more useful than manufacturing urgency, and it is usually what earns the engagement that does matter.
Five dates, in order, with what changed.
Two of these were moved. Reading a 2025 summary of this Act will give you the superseded timeline, which is how most of the wrong advice in circulation got there.
- In force
Article 50 transparency obligations apply
The transparency and disclosure regime became applicable. From the same date the AI Office and member-state authorities hold enforcement powers over general-purpose AI models: they can request technical documentation, evaluate models, require corrective measures and issue fines. The machinery is live, not pending.
- Next deadline
Article 50(2) marking, for synthetic-content systems already on the market
Article 50(2) requires the PROVIDER of a system that generates synthetic audio, image, video or text to mark that output so a machine can detect it as artificially generated. Where such a system was on the EU market before 2 August 2026, this is the date that duty runs to. It does not reach systems that only classify, rank or predict, and it carries an express carve-out for an assistive function for standard editing that does not substantially alter the input or its semantics.
- Pending
Older general-purpose AI models
General-purpose AI models placed on the market before 2 August 2025 must comply by this date. If you build on someone else's model, this obligation is theirs, and the date is a useful thing to raise in your next vendor review.
- Deferred
Annex III high-risk, use-based
Deferred from 2 August 2026 by Regulation (EU) 2026/1744, the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force since 27 July 2026. If a vendor tells you that use-based high-risk conformity obligations bite this year, check the date they are quoting against this one. A great deal of published guidance still predates the Omnibus and states the old schedule as current.
- Deferred
Annex I high-risk, product-regulated
Deferred from 2 August 2027. This is the cluster covering AI inside products already governed by EU product law, including radio equipment, lifts and medical devices.
The high-risk deferrals came through the Digital Omnibus amendments. Dates verified 1 September 2026; we re-verify this page on a 60-day cycle and it has already been amended once.
What exactly must we do?
Article 50 is a transparency and disclosure regime. It is not the full high-risk conformity regime, and treating it as one will cost you a quarter of engineering time you did not need to spend. In practice the work resolves to four streams, in this order.
- 01
Inventory
You cannot disclose what nobody has listed. Every AI system, its purpose, who it faces, whether it generates or manipulates content, which model sits underneath it, and a named owner. Most firms find at least one system that nobody owns and one that nobody knew was running.
- 02
Classification
For each system, decide which transparency expectations are engaged, and write down why. The reasoning is the artifact. A decision with no recorded basis is an opinion; the same decision with a dated basis and a named author is evidence.
- 03
Disclosure
Where a person interacts with an AI system, or meets content it generated or manipulated, that fact has to be made clear to them. In practice this means actual user-facing wording, in the interface, at the moment it is relevant. A paragraph buried in a policy PDF is not a disclosure.
- 04
Evidence
A dated log of what you decided, when, on what basis, what shipped, and what changed since. This is the artifact an authority asks for, and it is also, under a different name, the artifact your enterprise buyer asks for in diligence. Build it once.
This describes obligations and the artifacts that evidence them. It is not legal advice, and the classification of a specific system should be confirmed with counsel qualified in the relevant jurisdiction.
What happens if we do not?
Three consequences, arriving in roughly the reverse of the order people expect. The commercial one lands first, and for most mid-market firms it lands hardest.
- Regulatory
Enforcement powers exist as of 2 August 2026
Since that date the AI Office and member-state authorities can request technical documentation, evaluate general-purpose AI models, require corrective measures and issue fines. This is no longer a timetable with a distant start; the supervisory apparatus is operating now.
- Commercial
The deal stalls long before a regulator writes to you
Enterprise buyers now make six things gating conditions of purchase: kill switches, evidentiary audit trails, human-in-the-loop boundaries, model change control, outcome-based SLAs, and an ISO/IEC 42001 or SOC 2 attestation. A quarter of planned enterprise AI spend for 2026 is being deferred into 2027 because CFOs want ROI evidence and security teams flag governance gaps.
- Organizational
There is now a named person whose job is to ask
Forrester expects 60% of the Fortune 100 to appoint a head of AI governance during 2026. The questions above used to arrive scattered across procurement, legal and security. Increasingly they arrive from one person, in one document, with a deadline attached.
We do not publish fine figures on this page. Penalty exposure depends on the provision engaged and the member state enforcing it, and a number quoted out of that context is the kind of thing your counsel will correct in front of your board.
The seven questions we are actually asked.
Written for a compliance lead at a firm of 50 to 500 people who has a board question due on Friday and no in-house AI counsel.
- Does the EU AI Act apply to a US company with no EU office?
Reach follows the market, not your registered address. If you place an AI system on the EU market, or people in the EU are shown its output, treat it as in scope until counsel qualified in the relevant jurisdiction tells you otherwise.
If you have no EU users, no EU customers and no EU-facing output, it does not reach you today. We will tell you that on the first call rather than sell you an assessment you do not need.
- Article 50 is already in force. Have we missed it?
Not necessarily, and the December date is narrower than most coverage suggests. Article 50 transparency obligations have applied since 2 August 2026. What runs to 2 December 2026 is Article 50(2) specifically, the machine-readable marking duty, and it reaches providers of systems that generate synthetic audio, image, video or text and were already on the market before August.
So there are two populations. Anything you launch now sits in the first. Anything you were already running in July sits in the second, and that is the population the December date was written for.
- Do we have to complete the full high-risk conformity process this year?
No, and this is the single most common error in vendor marketing. Annex III high-risk obligations were deferred from 2 August 2026 to 2 December 2027, and Annex I product-regulated high-risk from 2 August 2027 to 2 August 2028, through the Digital Omnibus amendments.
The live near-term pressure is transparency and disclosure. Anyone selling you a high-risk conformity program on a 2026 deadline is quoting a superseded timeline, and your counsel will notice.
- We use a third-party model. Is this the vendor's problem?
Partly, and the split is exactly the thing to get in writing. Obligations attach differently to the provider of a general-purpose AI model and to you as the organization deploying it, and since 2 August 2026 the AI Office can request technical documentation, evaluate those models, require corrective measures and issue fines at the model level.
What does not move is the interface. The disclosure your users see, the classification decision, and the evidence log behind it are yours regardless of whose model is underneath. Ask your vendor in writing, keep the reply, and note that models placed on the market before 2 August 2025 have until 2 August 2027.
- What does evidence actually mean here?
Five artifacts: the inventory of systems, the classification decision for each one, the written reasoning behind that decision, the disclosure wording you shipped and where it appears, and the dated log of changes since.
None of it is exotic. The reason most firms cannot produce it is not difficulty, it is that nobody was ever assigned to write it down. Enterprise buyers ask for the same five artifacts under different names during diligence, so the work is not spent once.
- Can MetaMinds certify us as compliant?
No. The EU AI Act is a regulation, and obligations sit with the organizations placing systems on the market and deploying them, not with a consultant's certificate.
ISO/IEC 42001 is a certifiable standard, but that certificate is issued by an accredited certification body after an external audit, and we are not one. We do gap assessment, readiness, control design and evidence preparation for the auditor who does issue it. We also do not hold SOC 2 Type II. If a firm offers to certify you against ISO/IEC 42001 itself, that tells you what you need to know about the firm.
- What do we get for $4,900?
The EU AI Act readiness assessment (T2-01). One week, $900 deposit to reserve the slot, balance invoiced against delivery.
It produces the inventory of AI systems in scope, a written classification per system with the reasoning recorded, the transparency gaps ranked by exposure against 2 December 2026, the disclosure wording you are missing, and an evidence structure your counsel and your enterprise buyers can both work from. Where a system needs nothing, the report says so explicitly, in its own section.
EU AI Act readiness assessment
One week. We inventory the AI systems in scope, classify each one in writing with the reasoning recorded, rank the transparency gaps against 2 December 2026, and hand back the disclosure wording and the evidence structure. Where a system needs nothing, the report says so.
Not legal advice. We describe obligations and the evidence that closes them; anything with legal effect should be reviewed by qualified counsel.
$4,900
$900 deposit reserves the week. Balance invoiced against delivery.
- Inventory of AI systems in scope
- Written classification, with the reasoning recorded
- Transparency gaps ranked by exposure
- Disclosure wording you are missing
- Evidence structure counsel and buyers can both use
Deeper problem than transparency? The security, grounding and agent governance assessments run $5,900 to $8,900.