Vol. 1 · Edition 033Free · No paywall

Everyone Needs a Samwise

AI news · Synthesized · Opinionated · 🌿

7
days left
EU AI Act Article 50 · August 2, 2026
Regulation
By Sam Taylor with Samwise

On what Article 50 actually requires, why the Omnibus headline created a false impression, and what chatbot builders and synthetic media operators need to do before next Saturday.

The EU AI Act deadline that didn't get delayed. Seven days.

Source lean on this story
▲ avg

Anti-AI

00

Skeptic

01

Neutral

00

Pro (practical)

03

Pro (hyped)

00

← Anti-AI · Pro-AI →

Five days ago, the EU's Digital Omnibus amendment moved the Annex III high-risk AI system deadline from August 2 to December 2, 2027. That was genuinely good news for the builders building in healthcare, education, HR, and critical infrastructure — the sectors most affected by Annex III's compliance obligations.

The coverage of that news had one problem. It implied, without quite saying it, that the whole August 2 deadline was gone. It wasn't. Article 50 of the EU AI Act — the transparency obligations — was not in the Omnibus amendment. August 2 is still the effective date. That is in seven days.

If you run a chatbot that talks to EU users, generate AI images or video, deploy emotion recognition software, or build deepfake-adjacent tools, this section of the regulation applies to you, and you have a week.

Source spread

What Article 50 actually says

EU AI Act rollout schedule (Regulation 2024/1689)
  1. Aug 2, 2024

    Entry into force

    Regulation published. No obligations active yet.

  2. Feb 2, 2025

    Prohibited practices and literacy provisions

    Bans on social scoring, real-time biometric surveillance in public, subliminal manipulation. GPAI provider literacy obligations.

  3. Aug 2, 2025

    GPAI rules go live

    Foundation model providers — training data transparency, incident reporting, safety evaluations. Governance structure.

  4. Aug 2, 2026

    Article 50 transparency — STILL ACTIVE

    Chatbot disclosure, synthetic content marking, emotion recognition disclosure, deepfake labeling.

  5. Dec 2, 2027

    Annex III high-risk AI (delayed from Aug 2026)

    Healthcare AI, education AI, HR AI, critical infrastructure AI. Moved by the Omnibus amendment.

Article 50 has four operative paragraphs. Here is what each one requires, stripped of legal language.

Para 1 — Chatbot disclosure. If you deploy an AI system designed to interact directly with natural persons, you must ensure the person knows they're talking to an AI. The exception: when it's already obvious from context. "Obviously an AI" sounds like a wide door, but the burden is on the operator to document why it's obvious, not to assume it.

Para 2 — Emotion recognition and biometric categorization. If you operate a system that detects emotional states or categorizes people by biometrics (face, voice, gait), you must inform the people being analyzed. This one catches a lot of HR tech products and retail analytics tools that most builders don't think of as regulated AI.

Para 3 — Machine-readable content marking. Providers of AI systems that generate synthetic audio, image, video, or text must mark the outputs as AI-generated in a machine-readable format — technically feasible where technically feasible. C2PA content credentials are the current industry standard here. If you're an API provider whose customers generate images with your model, this obligation lands on you. If you're an operator using those images downstream, you need to check that your vendor is compliant.

Para 4 — Deepfake disclosure. Operators deploying AI systems that generate or manipulate realistic depictions of real people must disclose that the content is AI-generated. The exception is satire, parody, and art — but even those require "appropriate disclosure," not just "it's clearly a joke."

What's real

  • The Annex III delay was real and meaningful. High-risk AI compliance is genuinely expensive, and the 16-month extension gives builders in regulated sectors time to get it right rather than rush.
  • Article 50 was left out of the Omnibus deliberately. The transparency requirements are considered foundational and low-cost to implement. The EU didn't think these needed more time.
  • Extraterritorial scope applies. If your product serves EU users, Article 50 applies, regardless of where your company is incorporated. This is not new; it mirrors GDPR's territorial scope. But it surprises US builders every time a new EU regulation goes into effect.
  • C2PA is actually pretty well-tooled at this point. The technical implementation burden for para 3 machine-readable marking is not enormous. Adobe, Google, Microsoft, and most major AI image providers have been shipping C2PA credentials for a year. If you're generating images with a major API, ask your vendor about their current C2PA support.

What deserves a side-eye

  • Enforcement on day one is unlikely to be aggressive. The EU's pattern with GDPR and DSA was: rules in place, enforcement builds up over 12-24 months, big fines go to high-profile cases. Article 50 will probably follow the same arc. That's not a reason to skip compliance — it's a reason to deprioritize perfect compliance over obvious compliance.
  • The "obvious from context" exception in para 1 is genuinely ambiguous. There's no EU guidance yet on what "obviously an AI" means in practice. A cartoon robot avatar probably qualifies. A photoreal AI avatar probably doesn't. Everything in between will get litigated. For now, err toward disclosure.

Samwise's take

What builders need to know

  • Audit your chatbot UI for para 1 disclosure. Does it say, somewhere visible, that the user is talking to an AI? If not, that's a straightforward fix. Do it before August 2.
  • Check your AI image/video/audio vendor for C2PA compliance. If you're deploying AI-generated media to EU users and your vendor doesn't support C2PA content credentials, you either need to add machine-readable marking yourself or escalate to your vendor this week.
  • Document your emotion recognition and biometric categorization flows. If you run sentiment analysis on calls, face detection in retail, or gait analysis in security, you need disclosure mechanisms. Map the flows and determine what disclosure looks like before next Saturday.
  • Don't rely on the "obvious from context" exception without documentation. Write down why you believe your use case is obviously AI. If a regulator asks, "we assumed users knew" is not a defense. A documented rationale is.
  • Annex III is delayed; Article 50 is not. Brief your team and any legal counsel working on your EU compliance roadmap. The headline created a false impression, and you want to catch any internal assumption that "everything is pushed."

Further reading

🌿

Liked this? Get the weekly digest.

Free. Monday mornings. The week's stories, synthesized. Unsubscribe anytime.

Your take

How'd I do on this one?

What did I miss?

Tell Samwise (and Sam).

Disagree with the take? Spotted a fact I got wrong? Have context I should have included? Drop it here. Anonymous unless you leave an email.