ENDASV · soonNO · soon

JOURNAL

EU AI Act: what your company must do now the transparency rules apply

The Omnibus delayed the high-risk requirements. Article 50 was not delayed, and it hits your chatbot, your images and your text.

3 August 2026·18 min read·eu ai act · article 50 · transparency · ai compliance · gdpr · ai consultant denmark · smb

The EU has delayed the AI rules. You probably read that last week, and it is true. Just not about the part that started applying to you on Sunday.

On 27 July 2026 the Digital Omnibus on AI entered into force, and it pushed the high-risk requirements back by nearly a year and a half. That was the story that got shared.

Six days later, on 2 August, Article 50 of the AI Act started to apply. It was not delayed. It covers transparency, and it hits something quite different from the big high-risk systems. It hits the chatbot on your front page. It hits the image your marketing team generated. It hits the text you published without anyone actually reading it.

That difference is what this article is about. Because I think a good number of Nordic companies read the first headline, relaxed, and missed the second.

TL;DR: The Omnibus moved the high-risk requirements from August 2026 to December 2027 and August 2028. It did not move Article 50. The transparency rules have applied since 2 August 2026. They apply to you even if you only use AI rather than build it. Fines run up to EUR 15 million or 3 percent of global turnover. One piece of relief is worth knowing: systems already placed on the market before 2 August have until 2 December 2026 for the machine-readable marking.

The European Commission page on the regulatory framework for AI

What moved, and what stayed

Let us get the dates straight, because this is where the confusion sits.

The Omnibus is formally Regulation (EU) 2026/1744. It was adopted on 8 July 2026 and entered into force on 27 July 2026. It amends the 2024 AI Act on a number of points.

What it moved:

  • High-risk systems in Annex III (the list of stand-alone systems covering areas such as employment, education, credit scoring and law enforcement) moved from 2 August 2026 to 2 December 2027.
  • High-risk systems in Annex I (AI embedded in products that are already regulated, for example machinery and medical devices) moved from 2 August 2027 to 2 August 2028.
  • The deadline for member states to have their regulatory sandboxes running moved to 2 August 2027.
  • The relief for small and medium-sized businesses was widened to cover small mid-caps too, meaning under 750 staff and EUR 150 million in turnover.

What it did not move:

  • Article 50. The transparency rules. They apply from 2 August 2026, exactly as planned.

And what it added:

  • Two new prohibitions from 2 December 2026, against AI tools that generate sexual material of people without their consent and against AI-generated child sexual abuse material. Those two carry the heaviest fines in the whole regulation, up to EUR 35 million or 7 percent.

So the picture is not that the EU pulled the handbrake. The picture is that the EU moved the part that needs a compliance project, and left standing the part that needs you to know what you are running.

Table setting the original AI Act dates against the dates after the Omnibus. High-risk systems in Annex III and Annex I move to December 2027 and August 2028, while Article 50 stays unchanged at 2 August 2026.
The Omnibus moved the high-risk requirements. Article 50 stayed.

What Article 50 actually asks of you

Article 50 has four parts. Two fall on the provider, meaning whoever built the system. Two fall on the deployer, meaning you, using it in your business. That distinction is worth holding on to, because many people assume the whole thing is the vendor's problem. It is not.

Article 50(1). Say that it is an AI. If an AI system talks directly to a person, that person has to be told. The duty falls on the provider, and the information has to be given at the latest at the first interaction, clearly and distinctly from everything else. Not in a footnote. Not in the terms of service. There is an exception where it is obvious to a reasonably well-informed person, but it is a narrow exception, and it should not be your plan.

Article 50(2). Mark what gets generated. Systems that generate synthetic content, meaning audio, image, video or text created by AI, must mark it in a machine-readable format. Machine-readable marking means the mark sits in the file itself or in its metadata, so a detection tool can read it, as opposed to a visible label a human can see. The duty falls on the provider. Ordinary editing assistance, for example spellchecking or light language cleanup, is exempt.

This is where the one piece of relief sits: systems already placed on the market before 2 August 2026 have until 2 December 2026 on this point. Anything reaching the market from 2 August onward has to mark from day one.

Article 50(3). Say so if you read emotions or categorise biometrically. If you use emotion recognition or biometric categorisation systems, you must inform the people exposed to them, and you must comply with data protection law as well. The duty falls on you as the deployer.

Article 50(4). Label deepfakes and AI text that informs the public. If you publish image, audio or video that has been generated or manipulated to resemble real people or events, you have to disclose it. If you publish AI-generated text with the purpose of informing the public on matters of public interest, you have to disclose that too. The duty falls on you as the deployer.

The exception in the last part is the most important sentence in the whole article for most companies: you avoid the disclosure if the text went through human review and editorial responsibility. Someone has to have read it and to stand behind it.

Here is how that duty is worded.

Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated.
Article 50(4), AI Act, Regulation (EU) 2024/1689
Decision tree showing whether Article 50 applies to a company. The tree splits into provider and deployer, with two questions under each and the matching duty in paragraphs 1 to 4.
Two questions if you built the system, two if you use someone else's.

Five objections I hear, and what I answer

I have had this conversation enough times to know the order it comes in.

"We do not build AI. We just use it."

That is exactly why. Paragraphs 3 and 4 fall on the deployer, not the provider. You can buy your entire AI toolkit from other people and still carry two of the four duties. The contract with your vendor does not move them.

"But the EU delayed the rules."

They delayed the high-risk part. That part covers systems that assess applicants, grant credit or run critical infrastructure. If that is not you, the delay was not your news. Your news was Article 50, which arrived on schedule.

"We are too small for this to apply."

There is no size exemption in Article 50. The relief in the Omnibus is about the documentation burden in the high-risk rules, not about transparency. A company with 25 staff and a chatbot carries the same duty as one with 2,500.

"Our vendor has this covered."

Maybe their part of it. Ask them specifically what they have done about paragraphs 1 and 2, and get it in writing. But paragraphs 3 and 4 stay with you whatever they answer.

"We are a Danish company selling to Danes. This is for the big internationals."

It is a regulation. It applies directly, without Denmark having to implement it first. The Danish Agency for Digital Government coordinates supervision here, and supervision is sector-based, so it is your usual sector authority you deal with. The regulation also reaches beyond the EU: it applies to providers outside the EU whose output is used here.

And then the question nobody asks out loud: what if we simply do not bother. The fine ceiling for Article 50 is up to EUR 15 million or 3 percent of total worldwide annual turnover, whichever is higher. That is a ceiling, not an expected fine, and member states set the specific penalties within it. But the ceiling tells you something about how seriously the legislator means it.

Graphic with the figure of 15 million euros in large type as the fine ceiling for Article 50, with a table below showing the three ceilings in the regulation at 35, 15 and 7.5 million euros.
The Article 50 fine ceiling, set against the other ceilings in the regulation.

Here is my opinion: they moved the wrong piece

I am moving from fact to judgement now, and I am marking it clearly.

The Omnibus also changed Article 4, the AI literacy duty. That duty has applied to all providers and deployers since 2 February 2025. The old wording said you had to take measures to ensure, to your best extent, a sufficient level of AI literacy among your staff. The new wording says you have to take measures to support the development of AI literacy, and it adds explicitly that no specific level is required.

That change took effect with the Omnibus on 27 July.

It was the wrong order.

Not because relief is wrong in itself. But because Article 50 switched on six days later, and Article 50 is a rule employees break by accident, not by decision. Marketing publishes an AI-written piece on a matter of public interest without anyone actually taking editorial responsibility. A developer puts an agent on the website and forgets the disclosure at first interaction. An employee shares a generated image that resembles a real person. None of those three get caught by a compliance department. They get caught by people who know the rule exists.

So the Commission removed the measurable part of the training duty in the same month it switched on a duty that only works if people are trained. That is my objection. It is about timing, not politics.

There is one more consequence I have not seen anyone discuss. Large companies train their people anyway. They have learning budgets, and they are not going to stop because a wording got softer. The companies that will quietly drop AI training now are the smaller ones. Not because they do not care, but because the measurable bar is gone and nobody is asking. The net effect is that the capability gap between large and small companies gets wider, not narrower. That can hardly have been the point of a simplification.

And let me say it plainly: I sell workshops and advisory work in AI literacy, so I have an interest in companies training their people. Read my opinion with that in mind. I am not lowering the bar with my own clients, whatever the wording now says.

A label is not the same as compliance

Still my judgement, not a paragraph of the regulation. I see two reactions coming, and I think both are dead ends.

Reaction one will be to put "written with AI" at the bottom of everything. Reaction two will be to let an employee click approve on a text and call that editorial responsibility.

Neither works.

Blanket labelling does not work, because it makes the label meaningless. If everything is labelled, the label says nothing, and you still have not done what the article actually asks for: machine-readable marking on the generated content, and a clear disclosure at the right moment in the right channel. A statement in your footer is not machine-readable.

The quick approve click does not work, because the exception in paragraph 4 requires real human review and editorial responsibility. A superficial approval is not editorial responsibility. The Commission's own guidelines from 20 July 2026 are fairly clear on that point. If you want to use the exception, you need to be able to point to a person who read the text and stands behind the content.

There is a shortcut that genuinely helps. On 10 June 2026 the Commission published a Code of Practice on Transparency of AI-generated Content, and roughly 190 companies and organisations had signed it by the end of July. It is voluntary. But it comes with a common EU icon set for labelling, and if you follow it you have a documented route to showing that you meet the requirement. If you do not follow it, you have to be able to demonstrate that your own method is equally adequate.

I would rather have a client who got three things right than twelve things half right.

Anatomy diagram of a chat window with four numbered callouts showing what a valid AI disclosure requires: it sits in the interface, it lands at the first interaction, it is accessible, and generated content carries marking in the file.
Four things that separate a valid disclosure from a label in the footer.

The table at the bottom of my articles

If you have read anything here before, you have seen a table at the bottom. It shows what I did and what AI did on that particular article. I have been asked a couple of times why it is there.

That is why. The rule was coming.

I am not a news publisher, and a professional article from a consultant is not automatically text on a matter of public interest in the sense of the regulation. So I could probably have skipped it. I did it anyway, because I would rather have the habit in place before the date than have to work it out afterwards. And because I want to be able to tell a client what it looks like in practice without guessing.

It is the same exercise I ask clients to do: find the three places where AI meets a person or leaves the building, and do the right thing there. Not twelve places. Three.

What this means for you

Owners and leaders in SMBs

Your reflex on a headline like this is to pull the handbrake. Do not. You do not have a high-risk system, and that is not the end to start from.

Here is the yardstick instead. Can you answer three questions in ten minutes: where does a customer meet an AI at our company, where does AI-generated content leave the building, and who here stands behind the text we publish. If you can answer, you are in a better place than most. If you cannot, that is where you start, and it is a morning's work, not a project.

Operations and transformation leads

You are going to own this, whoever decides it. The operational consequence is an overview you do not have today: every AI system in operation, who owns it, whether you are the provider or the deployer of it, and which of the four duties applies.

The cheap fix is one sheet. One row per system. One approved disclosure text reused everywhere a person meets an agent, so it does not get renegotiated every time. And a note on each system saying whether it was on the market before 2 August 2026, because that decides whether the machine-readable marking deadline is now or 2 December.

Sales and RevOps leads

You have two sides to this, and they often get mixed up.

Inward: agents in your CRM, scoring, call summaries, sequence drafts. Here the transparency requirement is rarely the binding constraint. The binding constraint is permissions and data. What can the agent see, and what happens to customer data along the way.

Outward: an agent talking to a real person on the website or in chat. Paragraph 1 applies there without argument. The disclosure has to land at the first interaction, not when the conversation gets awkward. And if you use tools that read mood or sentiment on real people, you are into paragraph 3, where the disclosure duty and data protection apply at the same time.

If you use AI to write outbound text to named contacts, that is not the same as text informing the public. There, consent rules and marketing law weigh heaviest, not Article 50.

Product and engineering leads

If you built what you sell, you are the provider and not just the deployer. That means paragraphs 1 and 2 land on your desk, and that is the heavier end of Article 50.

The afternoon's work looks like this. Move the notice that the user is talking to an AI out of the system prompt and into the interface itself, because an instruction to the model is not a guarantee. Check whether what you generate carries machine-readable marking, and if you build on a vendor's model, ask them what they provide there. Look up when your system was placed on the market, because that decides whether you have until 2 December on the marking. And write down who holds editorial responsibility for what you publish.

Ten questions that decide whether you are there

Five for your vendor:

  1. How does your system meet the disclosure duty at first interaction, and can I see it in the interface?
  2. Do you mark generated content machine-readably, and in what format?
  3. Have you signed the Commission's Code of Practice on Transparency of AI-generated Content?
  4. Was the system placed on the market before 2 August 2026?
  5. Where does the processing run, and what does the data processing agreement say about it?

Five for yourselves:

  1. How many places does a customer or an applicant meet an AI system at our company?
  2. Who is named as editorially responsible for what we publish with AI help?
  3. Do we use anything that reads emotions or categorises people biometrically, including indirectly?
  4. Could a new employee find our AI labelling rule in under two minutes?
  5. When did we last spend an hour teaching the team the rules rather than the tools?

Two lists, ten questions. If you can answer all of them, you are done with Article 50 for now.

Data protection and where it runs

Article 50(3) points directly at data protection law. That is not an accident. Emotion recognition and biometric categorisation hit two rule sets at once, and the disclosure duty in the AI Act does not release you from GDPR.

For most Nordic companies the practical question is still the same as before: where does the data sit, and who can reach it. It is possible to run Claude with processing inside the EU, both through AWS Bedrock and through Google Vertex AI. But it does not happen by itself. In both places you have to actively select the European endpoint, meaning the address your system calls. If you do not, the call runs globally by default, and you are having a different conversation with your lawyer than the one you thought.

It is not a requirement in the AI Act. It is a requirement in a lot of procurement processes, which in practice is just as binding.

What I am doing myself

I am going through my own setup this week. The chatbot, the disclosure text, the table at the bottom, and a note on every system saying when it went live. Not because I expect an inspection. Because I cannot sell a review I have not done myself.

If you want someone keeping an eye on this sort of thing continuously, so you do not have to read regulations on a Sunday, that is exactly what an external AI lead on retainer is for. We go through the setup every month, and you get told when a date like this one moves.

Sources

Primary sources:

Third-party sources:

This work was produced in collaboration with AI. Overall: AI roughly 76 percent, Kim roughly 24 percent. Looking at production alone, it is AI roughly 92 percent and Kim roughly 8 percent. That is a qualified estimate, not a measured log.

Table of how the work on this article was divided between AI and Kim, phase by phase, with a total of AI 76 percent and Kim 24 percent.
How the work on this article was divided. A qualified estimate, not a measured log.

FAQ

Frequently asked questions

Yes. Article 50 has no exemption for small companies. The relief in the July 2026 Omnibus covers documentation requirements in the high-risk rules, not transparency. If you have a chatbot or publish AI-generated content, you are covered.

The provider developed the system or places it on the market under its own name. The deployer uses the system in its business. Disclosure at first interaction and machine-readable marking fall on the provider. Labelling deepfakes and informing people about emotion recognition fall on the deployer.

No. The requirement in Article 50(4) covers deepfakes and AI-generated text published to inform the public on matters of public interest. If the text went through real human review with editorial responsibility, the disclosure duty does not apply. A blanket label on everything is neither required nor sufficient.

Fines run up to EUR 15 million or 3 percent of total worldwide annual turnover, whichever is higher. Giving incorrect information to the authorities carries a ceiling of EUR 7.5 million or 1 percent. These are ceilings, not expected fines.

The Danish Agency for Digital Government coordinates supervision nationally, and supervision itself is sector-based, so your usual sector authority supervises its own area. Questions can be sent to [email protected].

That the mark sits in the file or its metadata, so a detection tool can read that the content was generated by AI. It is not the same as visible text at the bottom of a page. A visible label may be necessary for other reasons, but it does not meet the requirement in paragraph 2 on its own.

Only part of them. Regulation (EU) 2026/1744 moved the high-risk requirements to 2 December 2027 and 2 August 2028. The transparency rules in Article 50 were not moved and have applied since 2 August 2026.

Yes. Both AWS Bedrock and Google Vertex AI offer European endpoints where processing stays inside the EU. It requires you to actively select the European endpoint, otherwise the call runs globally by default. It is not a requirement in the AI Act, but it usually makes the conversation with lawyers and procurement teams shorter.

Get new essays by email.

Roughly twice a month. Same voice. No list rental, no retargeting.

Sign up for the Brinvik journal. Unsubscribe anytime. See our privacy policy.

Protected by Cloudflare Turnstile. No challenge, no CAPTCHA. Brinvik never shares your address.