I keep a written engineering standard for everything I build. It runs to about a hundred and ten rules covering security, data retention, accessibility, sales tax, email compliance, the whole unglamorous list. Last week I went to confirm that my own apps were on the right side of the EU AI Act, which in that document got exactly one rule. I had written it myself some months earlier and I was reasonably confident about it.
It was wrong in two directions at once. It described one of the four things Article 50 actually requires, and the column where I had recorded which of my apps complied said "every AI-facing surface" when the honest answer was one app, unfinished. Nobody had lied. I had written the rule from a summary of the law rather than the law, and then I had written down the coverage I intended rather than the coverage I had.
I mention this because I suspect it is a common position, and because the correction turned out to be much smaller than the fear that preceded it. What follows is what I learned fixing it. It is an explainer and not legal advice, and I will be clear about which parts are settled and which are not.
Two Countries, One Day, One Idea
On 2 August 2026 the EU's Article 50 transparency duties became applicable. The same day, after its own delay from January, California's SB 942 took effect. Two legal systems that agree on very little landed on the same narrow proposition within hours of each other: people are entitled to know when they are dealing with a machine.
Almost everything written about the AI Act this year has been about the other tiers, the ones with conformity assessments and registration databases and seven-figure penalties. Those tiers are real. They also apply to a category of system most businesses will never build. The duty most operators will actually owe is the transparency one, and it is the cheapest thing in the entire regulation to satisfy, which may be exactly why so little has been written about it.
What Article 50 Actually Asks For
Article 50 of Regulation (EU) 2024/1689 has four limbs. In plain language:
- 50(1): A chatbot must tell people it's a machine, unless that's already obvious.
- 50(2): Synthetic audio, image, video, and text must be marked in a machine-readable way.
- 50(3): If you run emotion recognition or biometric categorisation, you disclose it to the people exposed to it.
- 50(4): Deepfakes get a visible label. AI text published to inform the public on matters of public interest must be disclosed — but this one is exempt where a human reviewed it and a person or entity holds editorial responsibility.
My rule had covered the third of those and only barely. The one I had missed entirely was the first, which is also the one most likely to apply to an ordinary business, because an ordinary business is far more likely to put a chat widget on a page than to run biometric categorisation.
The Commission's guidance names two ways of getting this wrong, and both are worth knowing because both are tempting. Burying the disclosure in your terms and conditions or your product documentation does not satisfy it. Neither does a watermark or a metadata tag on its own, on the reasoning that users do not see either one at the moment they are actually being addressed by a machine. The disclosure has to be where the person is looking.
There is one more date on this side of the ledger. On 2 December 2026 the grace period ends for the 50(2) marking duty on systems that were already on the market, and the same day a new Article 5 prohibition applies to AI systems that generate non-consensual intimate imagery or child sexual abuse material. That second one is not a transparency question and does not belong in the same mental category as the rest of this. It sits in the tier with the largest penalties for a reason.
The Deadlines Moved, Which Tells You Something
While everyone was writing that the AI Act would land in August, Europe spent June moving its hardest deadlines back.
The Digital Omnibus on AI cleared its final Parliament vote on 16 June 2026 and received Council approval on 29 June. Stand-alone Annex III high-risk obligations, which had been due on 2 August 2026, moved to 2 December 2027. High-risk AI embedded in regulated products moved from 2 August 2027 to 2 August 2028. The Article 4 AI literacy duty was softened from guaranteeing a level of literacy among staff to supporting its development.
The stated reason was that national competent authorities had not been designated and the harmonised standards and compliance tooling were not ready. I find that more informative than the delay itself. The transparency duties arrived on schedule because they are cheap to comply with and cheap to check. The heavy obligations got sixteen extra months because the apparatus to administer them did not exist yet. If you are trying to plan around any deadline in this area, the useful question is not what the calendar says but whether anyone has built the machinery to enforce it.
Whether It Reaches You At All
Coverage of this tends to either terrify American readers or wave them off, and the honest answer sits between the two and depends on facts about your business.
The test is not where you are incorporated. Article 2(1)(c) applies the Act to providers and deployers outside the EU where the output of the system is used in the Union. Being a New Jersey company, which I am, buys nothing on its own.
In practice the gradient looks roughly like this:
- A restaurant with a booking form and no AI anywhere on the site. The output of a system is not being used in the Union in any sense that matters here, and this is not your problem.
- A software product with a generative feature and paying subscribers in the EU. The output plainly lands in the Union, Article 50 applies, and the work is labelling the assistant and sorting out how your generated media is marked.
- You publish a company blog with AI-assisted drafts, read by anyone. This is the genuinely unsettled one, and it applies to this article. Does a business blog count as text published to inform the public on matters of public interest under 50(4)? Most likely not, since the provision is aimed at material that reads as news or reporting. But the exemption is the part worth knowing: it applies where the content went through human review and a person or entity holds editorial responsibility for it. If someone is actually reading and standing behind what goes out, you are inside it.
That last case is not settled, and I would rather say so than pretend otherwise. What will settle it is enforcement practice and further guidance, neither of which exists yet. In the meantime, having a named human who is accountable for what gets published is cheap and answers the question before anyone asks it.
Washington Is Not Going To Simplify This For You
The comforting American version of this story is that the federal government is putting a stop to state AI regulation. It is trying, and so far it has not managed it.
Executive Order 14365, signed 11 December 2025, built out the machinery. A Justice Department AI Litigation Task Force became operative on 10 January 2026 to challenge state AI laws in federal court. Commerce was directed to identify burdensome state laws, the FTC to issue a policy statement on how the FTC Act applies to AI, and forty-two billion dollars in already-allocated broadband funding was conditioned on states repealing rules deemed onerous. In March 2026 the White House went further and asked Congress to broadly preempt state AI laws that impose undue burdens.
The detail that matters more than any of that: no federal preemption statute has been enacted. Preemption ordinarily flows from an act of Congress rather than an executive order, which means EO 14365 probably cannot displace state AI law on its own. It shapes federal agency conduct and litigation posture. Whether it accomplishes more than that will be decided by a court or by Congress, and neither has spoken yet.
The states, meanwhile, did not wait to find out. Texas TRAIGA took effect on 1 January 2026, alongside California's frontier AI transparency law, with SB 942 arriving on 2 August. Colorado's original AI Act was delayed, then repealed and replaced outright by a new statute signed in May, with obligations beginning 1 January 2027.
So the EU gives you one rulebook whose dates keep moving, and the US gives you fifty jurisdictions plus a federal government trying to unwind them without the votes to do it cleanly. If you were hoping the American approach would be the simpler one to plan around, it is not.
What I Would Actually Do
Four things, and most of them are an afternoon.
- Label your chatbot. If a machine is talking to your customers, it should say so, somewhere they can see it rather than in the terms of service.
- Find out whether your generated images and video carry provenance data. Most tools do not embed anything by default, and knowing which side of that you are on takes ten minutes. The marking is a separate duty from the visible label, and neither one substitutes for the other.
- Write down who holds editorial responsibility for what you publish. A name, not a department. That is the 50(4) exemption, it costs nothing, and it is the answer to the hardest question anyone is likely to ask you.
- Do not add applicant ranking, credit scoring, or anything that sorts people, without reading Annex III first. Employment and candidate screening, credit, education, essential services, law enforcement and migration are the high-risk categories, and moving into them converts a modest product into a project with a conformity assessment and an EU registration behind it. That is a budget decision, not a feature decision.
What is not on that list is as important as what is. No compliance program. No vendor. No panic.
The Bottom Line
The penalties are genuinely large. Up to thirty-five million euro or seven percent of worldwide turnover for the prohibited practices, and up to fifteen million or three percent for most of the rest, Article 50 included. Those numbers are doing an enormous amount of work in the marketing that has been aimed at you this year. They scale with what you build, though, not with the fact that you exist and have a website.
My own correction took an afternoon once I stopped reading summaries and read the provision. The rule in my standard now covers all four limbs, and the coverage column says what is actually true rather than what I intended, which is less flattering and considerably more useful. If you are going to fix one thing after reading this, make it that second part.
Need help putting this into practice?
SynthBridge helps businesses turn ideas like these into working systems. Free consultation, no sales pitch.
Schedule a Free Consultation