Table of contents
On 2 August 2026 a wave of articles rolled through the industry announcing that “the AI Act now applies in full” and that companies running high-risk systems are in trouble. The date is real, the conclusion is not. High-risk obligations did not start that day: the EU Digital Omnibus pushed them to December 2027 and August 2028.
What did start is something that affects far more companies than high-risk ever will. The whole of Article 50 - the transparency obligations. A chatbot has to say it is a chatbot. Generative output has to be marked. Deepfakes need a visible label. And - the part that matters most to us - all of it has to happen in the interface, “in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure”.
That last sentence is why we are writing this. Hundreds of legal analyses of Article 50 already exist. Almost none of them answer the question our clients have been asking us this week: how do you actually design this so that it is compliant and does not wreck the product?
What actually started on 2 August
Let’s fix the calendar first, because half of the confusion comes from articles written before November 2025 and never updated.
The Digital Omnibus - Regulation (EU) 2026/1744 - was published in the Official Journal on 24 July 2026 and entered into force on 27 July, a week before the AI Act’s general date of application. This is not a proposal or an announcement, but binding law that amended Article 113 of the Regulation.
| Obligation | Applies from | Who it covers |
|---|---|---|
| Prohibited AI practices (Art. 5) | 2.02.2025 | everyone |
| AI literacy (Art. 4) | 2.02.2025 | providers and deployers |
| General-purpose AI models (GPAI), governance | 2.08.2025 | GPAI model providers |
| Transparency - all of Article 50 | 2.08.2026 | providers (paras 1–2) and deployers (paras 3–4) |
| Market surveillance (Ch. IX), Commission fines for GPAI (Art. 101) | 2.08.2026 | all operators |
| High-risk - Annex III (recruitment, HR, scoring) | 2.12.2027 (postponed) | providers and deployers |
| High-risk - Annex I (AI in regulated products) | 2.08.2028 (postponed) | manufacturers and providers |
The Omnibus did not touch the general date of application, Article 50, or Chapter IX. In other words: what everyone was writing about got postponed, and what actually lands in the interface stayed.
Breaching Article 50 carries a fine of up to EUR 15 million or 3% of worldwide annual turnover - whichever is higher. For SMEs and start-ups, the mitigating rule in Article 99(6) applies: the lower of the two figures is used.
Four situations, two different addressees
Article 50 describes four scenarios and - this is the part most often missed - splits them between two different roles. Buying a tool “compliant with the AI Act” closes at most half the topic.
- A provider develops an AI system and places it on the market under its own name or trademark. In practice: a software house or SaaS company building its own AI product. Note: if you build an assistant on someone else’s model and sell it under your own brand, you are the provider of that system. The fact that the model comes from OpenAI or Anthropic changes nothing.
- A deployer is a company using an AI system in the course of its professional activity. In practice: almost every company publishing content or serving customers with AI.
The four Article 50 scenarios split by role - and what each of them has to surface in the interface
Two of those four things the user will see. One is entirely invisible. And it is exactly at the seam between those layers that the most expensive mistake in Article 50 happens - we come back to it under paragraph 4.
Paragraph 1 - the chatbot has to introduce itself
A provider of a system that interacts directly with a person must design it so that the user knows they are dealing with AI. Note the wording: the obligation concerns the design of the system, not the terms of service. A sentence in a privacy policy does not discharge it.
The Commission’s guidelines of 20 July 2026 spell out four cumulative criteria. The obligation applies where:
- the system qualifies as an AI system,
- it is designed for a genuine two-way exchange with people - not merely collecting data or returning automated responses,
- the interaction is direct, meaning the AI itself communicates with the person rather than through a human intermediary,
- the other party is a natural person - a consumer, a professional, anyone.
Systems operating solely in the background, through machine-to-machine communication or without direct human contact, fall outside the scope. A recommender quietly ordering a listing does not need to introduce itself. An assistant in a chat window does.
The “obvious” exception is narrower than you think
Article 50(1) waives the obligation where the interaction with AI is obvious “from the point of view of a natural person who is reasonably well-informed, observant and circumspect”. The Commission is explicit: this exception must be interpreted restrictively, because it deprives people of transparency.
So you cannot defend yourself with “everyone knows it’s a bot”. The test is an average reasonably well-informed person, not your product team. And if you deliberately build the illusion of a human - an avatar with a human name, a photo, a simulated “typing…”, a tone of voice imitating a consultant - you are closing off that exception yourself. The better you imitate a human, the more clearly you have to disclose.
When and where
Article 50(5) adds three conditions that are, in substance, design requirements:
- “at the latest at the time of the first interaction” - not after the third message, not behind an accordion, not in the footer. The disclosure has to be in place before the user starts the conversation,
- “in a clear and distinguishable manner” - distinguishable from the rest of the interface, not a grey micro-annotation under the input field,
- in conformity with the applicable accessibility requirements - this is not decoration. A disclosure hidden in a
titleattribute or encoded in colour alone does not exist for some users, and therefore does not discharge the obligation.
That last point matters twice over in Poland, where digital accessibility already has its own regime - we wrote about it in our piece on the Polish Accessibility Act. These two obligations are not alternatives. The AI disclosure has to be accessible.
Paragraph 2 - the marking the user will never see
Providers of systems generating synthetic audio, images, video or text must mark the outputs in a machine-readable format and make them detectable. The solutions must be effective, interoperable, robust and reliable - as far as technically feasible.
This is the invisible layer: watermarks, metadata, signatures in the file. From an interface designer’s point of view, nothing happens here. From a product team’s point of view, two things do.
First thing - the date of placing on the market decides the deadline. The Digital Omnibus added a transitional provision: generative systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with the marking obligation. A system placed on the market from 2 August marks from day one. That is four months of breathing room for what already exists - not a general postponement.
Second thing - this belongs in a contract, not in a backlog. The marking obligation sits with the provider of the tool. If you are buying a generative tool, state explicitly in the contract who is responsible for the outputs’ compliance with Article 50(2). Since 10 June 2026 there is a reference point: the Code of Practice on Transparency of AI-generated Content, assessed by the Commission and the AI Board as an adequate tool for demonstrating compliance. By the end of July 2026 around 190 organisations had signed it. A clause saying “marking in line with the Code” means considerably more today than a generic “AI Act compliance”.
Paragraph 4 - the label the user must see
Here we return to the most expensive mistake in the whole of Article 50.
A deployer must disclose that content is artificially generated or manipulated where it constitutes a deepfake, and must label AI-generated text published to inform the public on matters of public interest. Now note the sentence the Commission wrote into its FAQ:
Deployers cannot simply rely on the machine-readable marking embedded in the content by the provider under Article 50(2) to fulfil their disclosure obligation.
Buying a “tool compliant with the AI Act” does not close the topic. The disclosure has to be understandable and perceivable by natural persons - with visible or audible labels - without the need for any specific technical tools or dedicated actions. Metadata is not a label. An icon buried under “show details” is not a label.
A deepfake is defined in Article 3(60) by three cumulative criteria: a high level of resemblance to the simulated subject, the existence (or plausible existence) of that subject in reality, and the capacity to mislead as to authenticity. If the intended audience in a given context does not expect the content to be authentic, the third criterion may not be met - which is why generated backgrounds, special effects and standard film post-production usually do not create a deepfake.
For text, the obligation is narrower than it sounds. Three conditions must be met at once: the text is published, it informs the public, and it concerns matters of public interest - politics, public administration, the administration of justice, fundamental rights, public security, public health, environmental protection, consumer safety, and significant economic, financial, scientific and cultural developments. A product description in a shop and a newsletter about a new feature do not qualify.
The exemption also applies where the text has undergone genuine editorial review: the deliberate examination of substance by people with the relevant knowledge, or editorial control with a person assuming responsibility for publication. The Commission adds that superficial, purely formal or procedural checks - spell-checking, grammatical correction - do not count as editorial review.
The EU icon set and one research finding you should care about
The Commission has released a set of icons for labelling AI-generated content. Three meanings - a basic icon, “fully AI-generated” and “partially AI-modified” - each in four colour variants (black, white, and both at 50% transparency), downloadable as SVG and PNG. Using the icons is voluntary; the labelling obligation is not. And the icon alone does not establish compliance.
Now the thing that gets lost in legal briefings and is pure usability research: the icons were user-tested, and performance improved across all measures when the basic icon was accompanied by a text label.
This is exactly the finding we know from every navigation audit: an icon without a caption is a guessing game. The Commission has just confirmed it on its own set. So if you are designing an AI content marker - icon plus word, not icon alone. “Generated with AI” next to the mark, rather than a cryptic symbol the user has to puzzle over.
There is one more exception worth knowing when working on entertainment products: where a deepfake is part of an evidently artistic, creative, satirical or fictional work, the obligation is limited to disclosure in a manner that does not hamper the enjoyment of the work. A full-frame label on a feature film is not what the law asks for.
Paragraph 3 - emotion recognition and biometric categorisation
The shortest of the four scenarios and the most often skipped, because it sounds exotic. A deployer of an emotion recognition or biometric categorisation system must inform the people exposed to it. The obligation applies whether the system runs in real time or analyses material after the fact.
The scope of information here is narrower than in the other cases: it is about informing people that the system is operating, not explaining its purpose. If your product contains sentiment analysis from a camera, engagement measurement from faces, or categorisation of people based on biometric traits - this is your provision.
What Article 50 does NOT require
Over-compliance costs as much here as neglect - except that you pay in usability rather than fines. Outside the scope are, among others:
- short sequences of numbers, symbols or letters, and source code,
- outputs intended exclusively for machine-to-machine communication, processed automatically without human exposure,
- outputs used only in closed-loop industrial and product development environments - unless they are the final output,
- assistive functions for standard editing - the Commission’s guidelines give a set of examples of what still counts as standard editing and what goes beyond it,
- content generated before 2 August 2026 - it does not need retroactive labelling, though the Commission encourages it.
A narrow marking exemption is also envisaged for systems whose outputs are used in business-to-business and industrial contexts, subject to the conditions set out in the guidelines.
The practical conclusion: do not label everything. An “AI” badge stuck onto every element of the interface stops carrying information after the third occurrence - which is precisely the opposite of what the provision is meant to achieve.
How to design disclosure so it doesn’t kill the product
Article 50 says what has to appear in the interface. It does not say how. What follows is our design recommendation, not the text of the law.
Treat disclosure as trust-building, not as a disclaimer. Teams instinctively design these messages the way legal clauses are designed: small type, grey, as far from the primary action as possible. That is optimising for “so nobody notices”, which is exactly the scenario in which an authority concludes the message was not “clear and distinguishable”. A user who knows they are talking to AI calibrates their expectations and walks away disappointed less often - that is not a conversion cost but an investment in conversion quality.
Separate the first and second layer. The requirement concerns the first interaction, not volume. A short, unambiguous sentence on entry (“You’re chatting with an AI assistant”) plus an accessible expansion with the details - which model it runs on, what it does with data, how to reach a human - discharges the obligation without turning the chat window into terms of service. The Code of Practice explicitly allows an interactive second layer for content labelling.
Do not design deceptive patterns here. A disclosure that disappears after 800 ms, a message below the fold, contrast on the edge of legibility, a label obscured by a control - each of these technically “exists” and functionally does not. “Clear and distinguishable” is a perceptual criterion and will be judged by what the user actually had a chance to notice.
Icon plus word. Back to the Commission’s testing result, because it is the best-documented recommendation in this entire piece. The symbol alone is not enough.
Close it into one pattern in the design system. This is the moment to do the boring, profitable thing: one AI disclosure component, one content label component, with variants and usage rules - instead of a dozen implementations scattered across the product, half of them inaccessible and the other half inconsistent. With a scattered implementation, every change in guidance is a migration across the whole product; with one component it is a single change. We wrote about this mechanic at length in the piece on a design system built for AI.
The underlying problem is not new either. “The machine calculated something, and the user has to understand it and decide on that basis” is a task we were solving in quote calculators and B2B panels long before Article 50 - the difference being that back then nobody required it of us:
In both cases the work came down to showing the components of the result and letting people change the assumptions. AI disclosure is the same job, only with more uncertainty on the system’s side - and now with a date in the calendar.
The provision will not tell you how to design it. Disclosure is one of four places that decide whether anyone uses an AI feature at all - alongside showing where the answer came from, control over it, and the states other than “it worked”. We break those down separately, with the full list of states and the metrics, in the piece on designing AI interfaces.
Disclosure is not a waiver of responsibility. The line “content generated by AI, may contain errors” is often used as an umbrella over answer quality. Article 50 does not work like consent under the GDPR - telling someone that something is AI does not legalise what that AI does. If an assistant advises on financial or health matters, information about its nature is the beginning of your obligations, not the end.
Poland - KRiBSI and the window that is opening now
The AI Act is a regulation, so it applies directly. A national law is needed to designate the authority and the procedures - and that law has just come into force.
The Act of 3 July 2026 on artificial intelligence systems (Journal of Laws 2026, item 1003) was promulgated on 27 July 2026 and enters into force on 11 August 2026. It establishes the Commission for the Development and Security of Artificial Intelligence (KRiBSI) - a collegial market surveillance body and, at the same time, a single point of contact for businesses. The Act also provides the legal basis for regulatory sandboxes.
The authority’s rollout calendar is more forgiving than the calendar of obligations. The deadline for launching KRiBSI and appointing its Chair is 11 October 2026, and its inspection powers, proceedings and fines start on 28 October 2026.
Read that as follows: the obligation applies from 2 August, enforcement in Poland starts in late October. This is not a grace period - it is a window to get the product in order before anyone starts asking. Complaints filed with KRiBSI after it launches will also concern what happened earlier.
Where to start - five steps
- Establish your role separately for each system. Provider or deployer? Within a single product you may be both at once - the provider of your own assistant and the deployer of someone else’s image generator.
- Inventory every point where AI meets a human. Every chat window, every assistant, every content generator, every image or voice analysis. Mark background-only systems as out of scope - deliberately, with a justification.
- Check where and when the message appears. Before the first interaction? Is it distinguishable? Will a screen reader announce it? Does it survive high-contrast mode?
- Separate marking from labelling. Enforce machine-readable marking with your tool vendor and write it into the contract. Design the visible label yourself - with an icon and a word.
- Close the patterns into the design system before they spread across the product in a dozen variants.
If at this point you do not know how many such touchpoints your product has - that is the first finding of this audit, and the one we see most often.
FAQ
Do I have to label every text written with AI? No. The obligation in Article 50(4) covers text meeting three conditions at once: published, informing the public, and concerning matters of public interest. A product description, a newsletter or a company blog post about a new feature usually do not qualify. In addition, text that has undergone genuine editorial review with a person assuming responsibility for publication is exempt - and spell-checking does not count as editorial review.
I bought a tool that is “AI Act compliant”. Does that cover me? Only half the topic. Machine-readable marking (para 2) is the tool provider’s obligation. Visible disclosure of deepfakes and of text on matters of public interest (para 4) sits with the deployer - you. The Commission states explicitly that you cannot rely solely on the marking embedded by the provider.
Our chatbot has a name and an avatar. Is that a problem? Not in itself, but it closes off the “obvious” exception in paragraph 1. The more the interface suggests a human, the clearer the disclosure has to be. The safe answer is an unambiguous message at the first interaction, regardless of what the assistant is called.
Is a clause in the terms of service or privacy policy enough? No. Article 50(1) requires the system to be designed so that the person is informed, and paragraph 5 requires the information at the latest at the first interaction, in a clear and distinguishable manner. A document you have to navigate to separately does not do that.
Do we have to label content published before 2 August 2026? There is no such obligation - content generated before that date does not require retroactive labelling. The Commission does encourage it where possible.
We have had a generative system on the market since last year. When do we have to mark? By 2 December 2026. The Digital Omnibus transitional provision applies only to systems placed on the market before 2 August 2026 and only to the marking obligation in paragraph 2. A system placed on the market from 2 August marks from day one.
Who will enforce this in Poland? The Commission for the Development and Security of Artificial Intelligence (KRiBSI), established by the Act of 3 July 2026, which entered into force on 11 August 2026. KRiBSI gains inspection powers and the ability to impose fines on 28 October 2026, with appeals to the Regional Court in Warsaw.
This text describes the legal position as at 8 August 2026 and is educational material written from a design perspective - it does not constitute legal advice. The classification of a specific system and the scope of its obligations should be confirmed with a lawyer.
Sources: European Commission guidelines on transparency obligations (Article 50 AI Act) · Commission FAQ on Article 50 · Code of Practice on Transparency of AI-generated Content · EU icon set · Act of 3 July 2026 on artificial intelligence systems