Article 50 of the EU AI Act: What's Changing on August 2, 2026
Bria ai

On August 2, 2026, the transparency provisions of the EU AI Act take effect. Article 50 begins to apply, and with it the legal expectation that AI-generated content carries machine-readable provenance, that synthetic media is disclosed to the people who view it, and that organizations can prove, on demand, where their AI-generated assets came from.
Two things happened on 27 July 2026, and they are easy to mix up.
The high-risk rules got postponed. Obligations for high-risk AI systems, recruitment, credit scoring, and medical devices were due 2 August 2026. The Digital Omnibus pushed them to 2 December 2027 for Annex III use cases and 2 August 2028 for Annex I, embedded systems.
The transparency rules mostly held. Article 50 still applies from 2 August 2026, including the deployer labelling duty and the AI-interaction disclosure duty. One piece moved. Article 50(2), the provider marking obligation, now carries a four-month extension for systems already on the EU market before 2 August 2026, to 2 December 2026. New systems placed after 2 August 2026 get no extension. They comply on placement.
For most legal, compliance, and marketing teams, the obligations themselves are not new. The visibility is. Until now, AI provenance has been a procurement preference, a Trust & Safety conversation, an internal slide. After August 2, it is a regulatory floor. Non-compliance is fineable, deployment-specific, and applies whether your organization built the model or simply uses it.
This is a brief on what the regulation actually requires, how it changes enterprise vendor evaluation, and the operational adjustments your teams should be making in the runway.
What Article 50 obligates, in plain language
Article 50 of the AI Act creates three intertwined transparency obligations across the lifecycle of an AI system. They apply to two distinct roles: providers (organizations placing AI systems on the EU market, including via API) and deployers (organizations using AI systems in the course of business).
The obligations, in summary:
- Providers of generative AI systems must ensure that AI-generated or AI-manipulated outputs are marked in a machine-readable format and detectable as artificial. The marking must be technically robust, interoperable, and survive routine processing.
- Deployers of AI systems that produce deepfakes, meaning synthetic image, audio, or video content that resembles real people, objects, or events, must clearly disclose that the content is artificially generated or manipulated. A narrow carve-out exists for genuinely artistic, satirical, or fictional works, but the existence of synthetic content must still be acknowledged in an appropriate manner.
- Deployers of AI systems that generate or manipulate text published to inform the public on matters of public interest must disclose that the text is AI-generated, unless the content has been subject to human editorial review and a person or organization holds editorial responsibility.
The European Commission published the second draft of the Code of Practice on Marking and Labelling of AI-Generated Content on 3 May 2026. The Code is voluntary, but adherence is presumed to demonstrate compliance, and the technical baseline it sets is the working specification enterprise legal teams are designing against (Bird & Bird analysis; Herbert Smith Freehills Kramer analysis).
The penalty structure makes this a board-level conversation
Non-compliance with Article 50 falls under Article 99 of the AI Act and carries administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher.
That places transparency violations between the highest tier (€35M / 7% for prohibited-AI infringements) and the lowest tier (€7.5M / 1% for procedural infractions). For a company with a billion euros in global turnover, the upper bound is €30M per violation. National regulators determine application case by case, with explicit instructions to weigh intent, repetition, and remediation.
The implication: transparency is no longer procedural housekeeping. It is a category of regulatory exposure that boards and audit committees will track.
What “machine-readable marking” actually requires
The Code of Practice acknowledges what most technical teams already suspect: a single watermark is not enough. The draft mandates a multi-layered approach to marking, combining:
- Machine-readable provenance metadata embedded using open standards. The Coalition for Content Provenance and Authenticity (C2PA) is the most technically mature pathway and aligns directly with the Code's specification.
- An invisible, pixel-level watermark that survives common downstream processing - resizing, cropping, re-encoding, format conversion – and remains detectable by appropriate inspection tools.
- For enterprises, this raises a sharper question: which of your active AI vendors actually meets that specification today, and which of them will meet it on 2 August? (See SoftwareSeni's Article 50 compliance overview for a useful breakdown.)
How enterprise vendor evaluation has to evolve
Generative AI procurement has, until recently, been driven primarily by output quality, latency, and cost per asset. Article 50 introduces a different axis. Three questions now belong on every vendor evaluation:
- Where did the training data come from, and can the vendor evidence its rights position? Models trained on scraped or undisclosed datasets cannot offer the provenance audit trail Article 50 implicitly requires. They also expose the deployer to copyright as well as compliance risk.
- Does the system produce machine-readable provenance signals at the moment of generation, in a standard a downstream pipeline can preserve? Retrofitting metadata onto unmarked assets after the fact is brittle, and the Code of Practice is explicit that marking should be embedded by design.
- Can the vendor speak specifically to its own compliance timeline, rather than a blanket claim? Given the marking deadline now differs for systems already on the market (2 December 2026) versus new market entrants (2 August 2026), a vendor's answer here should be dated and specific.
Internally, the same shift requires that AI tools be onboarded the same way other regulated systems already are: a documented vendor-risk assessment, a data-protection impact assessment where personal data is implicated, contractual indemnification language tied to training-data rights, and a record-keeping standard for the assets themselves.
A practical due-diligence checklist for visual AI procurement
Every enterprise using or deploying generative visual AI in the EU should be able to answer the following, for every vendor, every model, and every output channel:
- Is the model trained on licensed, attributable data, or on scraped content? What evidence does the vendor provide?
- Does every generated asset carry C2PA-aligned provenance metadata at the moment of output?
- Is there an invisible, pixel-level watermark that survives downstream processing, and is detection tooling available?
- For deepfake-adjacent use cases (synthetic spokespeople, voice clones, faces of real people), is there a disclosure workflow built into the publishing pipeline?
- Does the vendor offer contractual indemnification for IP claims tied to training data?
- Is the vendor itself certified, SOC 2 Type II, ISO 27001, GDPR-aligned, C2PA-conformant, at the level your audit and security teams expect from any other regulated system?
- What deployment options exist for EU data-residency requirements: cloud, BYOC, on-premises, on-device?
These questions are not theoretical. They are the operational form Article 50 will take when it lands on a procurement desk.
How Bria’s Trust pillar maps to Article 50
Bria's posture on transparency was set well before the Article 50 deadline existed.
We've committed to it, and we've been ahead of it. The transparency rules apply from 2 August 2026. Bria shipped C2PA content credentials in January 2025, so our images have carried signed provenance for over a year. Our systems have been on the EU market since well before August 2, which means we fall inside the Digital Omnibus extension for the provider marking obligation: 2 December 2026 is the date that applies to us, not August 2.
The Trust pillar of Bria's platform is built on several architectural commitments that map directly to the obligations enterprises now need to evidence.
Licensed training data. Bria's foundation models are trained on 100% licensed content, sourced through partnerships with Getty Images, Alamy, Envato, Freepik, Depositphotos, and over 30 other rights-holders. There is no scraped data exposure, no LAION inheritance, no opaque dataset to defend in legal review. This is the precondition for every other piece of the trust stack.
Visual Birth Certificate. Every asset generated through Bria is associated with a provenance record that traces the output back to the licensed training data that influenced it. The Visual Birth Certificate is a periodic provenance report that documents what was generated under your token, which licensed sources contributed, and how creators were compensated. For audit, copyright registration, and regulator response, this is the per-asset evidence Article 50 implicitly requires.
C2PA Content Credentials by default. Bria has integrated C2PA content credentials across its image generation and editing endpoints. Outputs carry the cryptographic chain-of-custody assertion the EU Code of Practice describes as the most technically mature compliance pathway. C2PA is on by default, not a feature flag.
Signatory to the EU's Code of Practice on Transparency of AI-Generated Content. Bria signed on 1 July 2026, acknowledged by the AI Office on 27 July 2026, declared as both a provider of generative AI systems and a provider of generative AI models. This is the Commission's own code for exactly this obligation, and it puts us on the officially recognised pathway to demonstrate Article 50 compliance. Bria was also one of the only generative AI providers to sign the earlier EU AI Act voluntary pilot programme.
Attribution and creator compensation. Bria's attribution engine routes a share of revenue back to the rights-holders whose data informed each generation. This is operational architecture, not a marketing position, and it is the layer that makes the licensed-data story durable rather than declarative. As a European company, this sits inside the same jurisdiction we're complying with.
We're completing pixel-level watermarking and our own free detection tool ahead of the December deadline that applies to systems already on the market. These are not live yet; C2PA provenance is what's verifiable today.
Full indemnification and enterprise certifications. Bria provides full IP indemnification for outputs generated by its models, and is certified to SOC 2 Type II, ISO 27001, GDPR, and EU AI Act-aligned compliance standards.
Deployment flexibility for EU data residency. Bria runs on Bria Cloud, BYOC, on-premises, and on-device. EU customers managing data-residency or sovereignty requirements have an architectural option, not a workaround.
The Trust pillar was not built in response to Article 50. The regulation now codifies the standard the pillar has been operating against. That is the simplest summary of where Bria sits in the new compliance landscape.
What this means for your team
Three priorities for enterprise teams:
- Audit your active visual-AI vendors against the procurement questions above. Some cannot evidence training-data rights, machine-readable provenance, or C2PA support. Remediate or replace those.
- Document the disclosure workflow for any synthetic-content use case that touches the public. AI-generated spokespeople, voice clones, public-interest text, deepfake-adjacent creative. Disclosure is the deployer's obligation, not the vendor's.
- Bring procurement, legal, and creative teams into the same conversation. Article 50 sits across the boundary between operations and brand.
August 2 is a floor, not a finish line. Provenance, attribution, and disclosure are about to be commercial standards as much as legal ones, and the enterprises that treat them as architecture rather than compliance overhead will be the ones with the cleanest production pipelines on the other side.





