The EU Commission's Article 50 guidelines, adopted 20 July 2026, tell operators what to do from 2 August: an AI agent must say it is AI at first contact, and AI-generated content must carry a human-readable label.
The EU AI Act’s Article 50 guidelines, decoded: what your AI agent must disclose from 2 August
Published July 30, 2026 · Last reviewed July 30, 2026
The date part of the EU AI Act’s Article 50 is settled. From 2 August 2026 the transparency chapter applies, and we covered what lands that day and what slipped in a separate deadline explainer. What changed in July is the harder half: not when, but how.
On 20 July 2026, thirteen days before the rules bite, the European Commission adopted its final Guidelines on the Article 50 transparency obligations. They run to about fifty pages, and they are non-binding. That last word does a lot of work, so read it carefully: the Guidelines are not new law, but they are the clearest statement of how the Commission, and the national regulators who follow it, will read the Article. If you operate a customer-facing agent, they are the closest thing to an instruction sheet you will get before the deadline.
This piece decodes them for one reader: the person shipping an agent that talks to people or generates content. It walks through what “disclose” actually means, where the provider duty ends and the deployer duty begins, and the two dates and one number that decide the stakes. It is a map, not legal advice; scope for a specific product belongs with counsel.
What the 20 July guidelines actually change
The Guidelines do not move the deadline, and they do not touch the high-risk regime that the Digital Omnibus pushed into 2027 and 2028. Their job is narrower and more useful: they interpret the four transparency duties in Article 50 so that “be transparent” becomes a set of concrete actions.1
Article 50 covers providers and deployers of certain AI systems, and it splits into four buckets. Article 50(1) is direct interaction: a system that talks to a person has to disclose it is AI. Article 50(2) is synthetic content: a provider of a generative system has to mark its output as artificially generated in a machine-readable form. Article 50(3) covers emotion recognition and biometric categorisation, where the deployer informs the people exposed to it. Article 50(4) covers deepfakes and AI-generated text published to inform the public, where the deployer labels the content.2 Article 50(5) applies the same standard to all four duties: disclosures must be clear and distinguishable, delivered at first interaction or exposure, and accessible.2
For most working agents, two of those four carry the weight: the direct-interaction disclosure and the marking-and-labelling pair. The Guidelines also settle a recurring definitional fight, confirming that “AI system” is read broadly and that the duties attach to how a system is used, not to whether anyone has called it high-risk. So a chat widget, a site agent, a synthetic-voice caller, and a text generator can all be in scope on the same day. The rest of this piece stays on the two duties an agent operator has to build for.
Telling a person it is an AI: clear, distinguishable, and at first contact
The direct-interaction duty sounds trivial until you try to implement it, which is where the Guidelines earn their length. They define the two words the Article leans on. Information is “clear” where it is noticeable and easy to understand. It is “distinguishable” where it is easy to identify as separate from the surrounding content and the environment it sits in.3 A disclosure buried in a terms-of-service page, or folded behind two layers of menu, does not satisfy either test.
Timing is just as concrete. The notice has to reach the person at the latest at the moment of first interaction. For a chatbot or an agent, the Guidelines are explicit that this means before or at the very beginning of the conversation, and that a written line at the top of the chat is an acceptable form: an agent that opens by saying it runs on AI has met the duty. A disclosure that only appears if the user asks, or three messages in, has not.
There is one carve-out, and it is narrower than operators tend to hope. The disclosure is not required where it would be obvious to a reasonably well-informed person that they are dealing with an AI. The Guidelines treat this as a genuine exception, not a loophole: a tool clearly labelled as an AI assistant on a developer platform may qualify, but a site agent built to sound like a human sales rep does not get to claim the interaction was self-evident. When in doubt, disclose. The Guidelines also press on accessibility: the signal has to be perceivable by its actual audience, which for many products means it cannot be a purely visual cue.
Marking what the agent generates, and why a deployer cannot free-ride
The content duties are where most teams will get the split wrong, because there are two of them and they sit on different parties. The Guidelines keep them distinct on purpose.
The first is the provider duty in Article 50(2). Whoever builds a generative system, one that produces text, images, audio, or video, has to mark that output so it is detectable as artificially generated or manipulated, in a machine-readable format, using techniques that are state of the art and interoperable where feasible. This is provenance engineering: watermarks, embedded metadata, and content credentials that survive being copied downstream. The Code of Practice on marking and labelling is the companion document that works out the technical “how,” and the Guidelines point to it rather than restating it.4
The second is the deployer duty in Article 50(4): label deepfakes, and disclose AI-generated text that is published to inform the public on matters of public interest, with narrow exceptions where a human holds genuine editorial responsibility. Here is the clarification that catches people. The Guidelines say a deployer cannot simply rely on the machine-readable mark the provider embedded under Article 50(2) to discharge its own labelling duty. A watermark a detector can read is not the same as a label a person can see. The deployer disclosure has to be understandable and perceivable by a human, a visible or audible label, with no special tools or dedicated actions required to notice it. Marking is for machines; labelling is for people; doing one does not do the other.
The two dates and one number that set the stakes
Most of Article 50 applies in full from 2 August 2026, and the Guidelines do not soften that. The single carve-out is inside the marking duty. Generative systems already placed on the market before 2 August 2026 get a grace period on the Article 50(2) machine-readable marking requirement, until 2 December 2026.5 Two conditions ride on that grace, and both matter: it applies only to that one machine-readable marking duty, and only to systems on the market before the deadline. A system you ship on or after 2 August gets no grace, and the deployer labelling duties under Article 50(4) get none at all. So the human-perceivable label on a deepfake or on public-interest text is due on day one, even where the underlying watermark is not. The omnibus package cleared the European Parliament on 16 June 2026 and the Council on 29 June 2026, and takes effect once published in the Official Journal, so verify the final text before relying on the grace period.6
The number is the enforcement backstop. Breaching the Article 50 transparency obligations can attract fines of up to fifteen million euros, or 3% of worldwide annual turnover, whichever is higher.7 The Guidelines themselves are non-binding, but the Article they interpret, and the penalty attached to it, are not. Treating the guidance as optional because it is “only guidelines” reads the wrong noun: the duty is binding, and the Guidelines are the regulator telling you how it will be measured. For the broader timeline, including the high-risk obligations that moved to 2027 and 2028, the deadline explainer has the full map; this piece stays on what the guidance asks you to build.
A short operator checklist for 2 August
Translated into build items, the Guidelines come down to a handful of things an agent team can check off.
- Self-identification. The agent states that it is an AI at or before the first interaction, in clear and noticeable text, not hidden in a policy page or a menu.
- A human-perceivable label on synthetic output the agent shows or sends: a visible or audible marker a person notices without any tooling, separate from any machine-readable mark.
- Preserve the provider’s machine-readable marking rather than stripping metadata on the way through, and confirm your generative vendor actually supports Article 50(2) marking.
- Deepfakes and public-interest text: label them, and check that an editorial exception genuinely applies before you lean on it.
- Accessibility: make each disclosure perceivable to the real audience, which usually means pairing a visual cue with text a screen reader can announce, or an audible equivalent.
- Write down, per system, who is the provider and who is the deployer. The duties split on that line, and the checklist above changes depending on which side you are.
None of this is the conformity machinery of the high-risk regime. It is disclosure engineering, and it is the operator’s to build. A third-party network does not hand it to you, and this checklist is orientation rather than legal advice.
Disclosure is the floor. Identity and consent are the ceiling.
Article 50 answers one question and leaves a larger one open. It makes an agent announce “I am an AI,” and it makes the agent mark what it produces. It says nothing about who is accountable for that agent, and nothing about whether the person on the other end agreed to be contacted. A fully disclosed, fully marked agent can still be an unwanted message from a party you cannot read.
That gap is a different layer, and it is where Tobira sits, not inside compliance. Tobira is the trust layer for the agentic web: a readable @handle for the human or company an agent represents, a credibility signal built from real conversation history (a 0-5 scale shown as four plain levels), and mutual reveal, where contact details change hands only after both sides agree. As of a June 2026 founder update, roughly 648 agents were publicly discoverable on the network, including about 102 business agents.8
Set the two next to each other and they stay distinct. Article 50 makes the agent say it is an AI. A @handle makes it easy for a person to see, in plain terms, who stands behind that agent. Mutual reveal adds the piece the transparency rules never reach: the receiver’s consent. This is the same identity-is-not-consent line that runs through Know Your Agent verification and the consent layer: proving what an agent is, and deciding whether a human wants to hear from it, are two different jobs. To be exact about it, Tobira is not a compliance product. It does not perform your Article 50 disclosure and it does not mark your content. It complements those duties by making the disclosed agent readable and adding consent, and it should never be described as doing the compliance work itself.
What to remember
- The 20 July 2026 Guidelines are non-binding, but they are how the Commission and national regulators will read Article 50. Treat them as the instruction sheet, not as optional reading.
- Direct interaction: an agent must disclose it is AI in a clear and distinguishable way, at the latest at first contact. Buried or delayed notices do not count, and the “obvious” exception is narrow.
- Content duties split by party. Providers mark generative output in a machine-readable format (Article 50(2)); deployers add a human-perceivable label for deepfakes and public-interest text (Article 50(4)). A deployer cannot rely on the provider’s embedded mark.
- Dates: most of Article 50 applies from 2 August 2026. Only the Article 50(2) machine-readable marking has grace to 2 December 2026, and only for generative systems on the market before the deadline. Deployer labelling gets no grace.
- The penalty for a transparency breach reaches up to fifteen million euros or 3% of worldwide annual turnover.
- Disclosure is the legal floor and it belongs to the provider and deployer. Readable identity for the human behind an agent, plus mutual-reveal consent, is a separate, human-facing layer that sits above the Act’s duties, not inside them.
FAQ
What are the Article 50 guidelines, and are they binding? The European Commission adopted the final Guidelines on the Article 50 transparency obligations on 20 July 2026. They are non-binding interpretive guidance, not new law, but they signal how regulators will read the Article. They complement the Code of Practice on marking and labelling AI-generated content.
What does my AI agent have to disclose from 2 August 2026? Two things. If the agent interacts with a person, it must make clear it is an AI system, in a clear and distinguishable way, at the latest at the first interaction. And AI-generated or manipulated content the agent produces must be marked and, for a deployer, labelled so a person can perceive it.
Can I rely on my AI vendor’s watermark to comply? No. Providers of generative systems mark output in a machine-readable format under Article 50(2). A deployer has a separate duty under Article 50(4) to label deepfakes and certain public-interest text so a human can perceive it. The Guidelines state that a deployer cannot rely on the machine-readable mark embedded by the provider to discharge its own disclosure.
Is there a grace period? For most of Article 50, no; it applies from 2 August 2026. The one shift is the machine-readable marking duty in Article 50(2): generative systems already placed on the market before that date have until 2 December 2026 to comply. Deployer labelling duties under Article 50(4) get no grace.
What are the penalties for breaching Article 50? Breaches of the Article 50 transparency obligations can attract fines of up to fifteen million euros or 3% of worldwide annual turnover, whichever is higher.
Does a Tobira @handle make my agent Article 50 compliant?
No, and it should not be described that way. Disclosure and content marking are the responsibility of the provider and deployer of the system. Tobira is a human-facing identity and consent layer: a readable @handle, a credibility signal, and mutual-reveal consent. It complements the transparency duties by making the human behind an agent readable, but it does not perform or discharge compliance.
Sources
Footnotes
-
European Commission, Shaping Europe’s Digital Future, “Guidelines on transparency obligations for providers and deployers of certain AI systems” (final Guidelines adopted 20 July 2026, non-binding; paragraph 117 for the rule that a deployer cannot rely on the provider’s machine-readable mark alone). https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems ↩
-
EU Artificial Intelligence Act, “Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems” (the four transparency duties: direct interaction, synthetic content marking, emotion recognition and biometric categorisation, deepfakes and public-interest text). https://artificialintelligenceact.eu/article/50/ ↩ ↩2
-
EU Artificial Intelligence Act, “The EU AI Act’s Transparency Rules: A Practical Guide to Article 50” (the “clear and distinguishable” test and first-interaction timing for chatbots). The point that a deployer cannot rely on the provider’s embedded machine-readable mark is in the Commission Guidelines, paragraph 117 (see 1). https://artificialintelligenceact.eu/transparency-rules-article-50/ ↩
-
European Commission, Shaping Europe’s Digital Future, “Code of Practice on Transparency of AI-Generated Content” (companion to Article 50(2) and 50(4) marking and labelling). https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content ↩
-
The Article 50(2) machine-readable marking grace period to 2 December 2026, for generative systems placed on the market before 2 August 2026, comes from the AI Act simplification package (Digital Omnibus). Status current at time of writing; verify before relying. See our companion explainer, “The EU AI Act’s August 2026 deadline: what actually applies to AI agents,” for the full timeline and primary sourcing. ↩
-
Gibson Dunn, EU AI Act omnibus agreement. https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/ ↩
-
EU Artificial Intelligence Act, Article 99 penalty framework as applied to Article 50 breaches: up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. https://artificialintelligenceact.eu/article/99/ ↩
-
Tobira founder update, June 2026: approximately 648 public discoverable agents, including about 102 business agents. ↩