The headline about the AI Act being delayed concerns high-risk systems. The transparency obligations in Article 50 arrived on schedule, on 2 August 2026, and they, not the distant 2027 dates, are the work sitting in your product right now.
dfzoo AI Institute implements the Article 50 transparency obligations of Regulation (EU) 2024/1689 in digital products and content publishing workflows. Those obligations have applied since 2 August 2026 and were not covered by the postponement that Regulation (EU) 2026/1744 introduced for Annex III high-risk systems and for AI in regulated products. We translate three duties into engineering work: telling a user they are interacting with an AI system, machine-readable marking of generated content, and visible labelling of manipulated material and deepfakes. Marking is verified at the end of the publishing path rather than inside the authoring tool, and we leave behind a test that repeats that check on every deployment. The legal reading is signed by counsel.
Regulation (EU) 2026/1744, the digital omnibus, has applied since 27 July 2026 and postponed compliance deadlines for high-risk systems. It did not postpone the transparency obligations in Article 50.
| Obligation | Original deadline | Status after the change |
|---|---|---|
| AI literacy (Article 4) | 2 February 2025 | Unchanged, in force |
| Transparency obligations (Article 50) | 2 August 2026 | Unchanged, in force |
| Annex III high-risk systems | 2 August 2026 | Moved to 2 December 2027 |
| AI in regulated products (Annex I) | 2 August 2027 | Moved to 2 August 2028 |
Article 50 describes an outcome, not an implementation. Below is what follows from it for a product, split into where it shows up, how it is done, and how it is verified.
| Obligation | Where it shows up in the product | How to implement it | How to verify it |
|---|---|---|---|
| Disclosing that the counterpart is an AI system | First message in the conversation and a persistent label in the header, on every entry point: widget, voice channel, email, partner integration | A message in the interface layer, not in the terms of service; wording clear to someone who has never seen your product | Walk every entry point and capture a screenshot from each |
| Machine-readable marking of generated content | The file leaving your system, and the same file fetched from the production URL | Content Credentials under the C2PA standard or metadata in XMP and IPTC fields, plus an entry in the generated-asset register | Fetch the published asset and read the marking with a reader, rather than checking the file in the tool |
| Visible labelling of manipulated material and deepfakes | The place of publication: page, video, post, ad creative | A human-readable label in the material itself or directly next to it, independent of metadata | Review published material channel by channel, with a list and a date |
This question comes up on every engagement and has no single answer, because some channels do not let you replace a published asset without losing its address. The order of work that holds: inventory first, then priorities, then a decision recorded somewhere it can be found again.
Content Credentials and XMP metadata survive the export from the authoring tool, and are then removed by the first step of the publishing path that re-encodes the file: a CDN converting images to WebP, compression inside the CMS, or an upload to a social platform. The team sees a correctly marked file in the repository and treats the matter as closed, while the asset in production carries nothing.
We verify the marking at the end of the path, on the asset fetched from its production URL, not on the file in the tool. We leave a test that repeats this on every deployment and reports the gap. Where a channel strips metadata and that cannot be changed, we add a human-readable label and record the decision in the asset register.
The statement that a user is talking to an assistant ends up in the privacy policy or in a tooltip, because the team does not want to spoil the first impression. The duty is about information given clearly and intelligibly at the point of interaction, so where the statement lives is the substance of it, not a detail. On top of that it is usually missing from the entry point nobody remembers: the partner integration, the voice channel, the automated email reply.
We put the disclosure in the first message and as a persistent label in the conversation header, then walk every entry point into the system, partner surfaces included. Each entry point gets a status and a screenshot. The list of entry points stays with you, so when a new channel is added it is clear what has to be checked.
The team adds a line of text in the corner of an image and treats it as satisfying the machine-readable requirement. The caption is cropped by the first video frame or by a thumbnail in a social feed, and no machine will read it anyway. It fails in the other direction too: metadata in a file is not a human-readable label, so on its own it does not satisfy the places where a visible label is required.
We separate the two requirements and implement both, each with the technique that fits it: a label readable by a person, and marking readable by a machine. For every content type, image, video, audio and text, we write down exactly what appears and where. The result is checked with a C2PA reader and by visual review, separately.
The model vendor's documentation mentions watermarking or Content Credentials, so the item leaves the list. In practice the marking can depend on the model version, on the call mode and on which endpoint you use, and your integration may predate the feature or bypass it. The claim lives in the vendor's documentation, not in your artifact.
We sample your actual integration, per model and per call mode, and check what really comes out. Differences from the documentation are recorded with a date and a model version and escalated to the vendor. Whatever the vendor does not add, we mark on your side rather than waiting for their release.
The headline about the AI Act being postponed concerns high-risk systems, but it lands in the plan as a single sentence: we have until 2027. The transparency duties arrived on time and apply to products that are live now. The plan is built from the headline rather than from the table of deadlines, and the difference only becomes visible when somebody outside asks about a specific feature.
We hand over a deadline table with the legal basis for each row and map it onto your systems, stating for each one what applies now and what applies later. The summary fits on one page, so it can go to the board without translating a regulation. We update it whenever the legal position changes.
We walk every entry point into a conversation with the system and every channel that publishes generated content. The output is a list with statuses, not an opinion.
We agree what appears in the interface and how each content type is marked, then implement the changes together with your team.
We check the marking on assets fetched from production URLs, channel by channel, and leave a test that repeats the check on every deployment.
We hand over the specification, the register and the test. We come back when a model or vendor is swapped, because that is when marking most often disappears quietly.
Article 4 has applied since 2 February 2025 and was not postponed. Role-to-competence mapping, a programme per role, and the records that let you evidence the obligation on demand.
Poland's AI act (Journal of Laws 2026 item 1003) entered into force on 11 August 2026; the inspection and penalty provisions on 28 October 2026. How to build a register that holds up.
AI system inventory, risk classification and the technical documentation the Act requires.
Independent evaluation of how well the AI you already deployed actually does its job.
Pre-release certification: observability, runbooks, rollback paths, on-call signals.
We are an engineering team, not a law firm. This page covers how to perform the obligation in a product and how to verify that it works, not how the article should be read for your case. Scope boundaries, in particular around published text and the exceptions in Article 50, are settled by counsel: yours, or our legal partner. Dates and instrument numbers are published together with their sources.
Tell us where you are with the Article 50 transparency obligations. We respond within one business day.