The Wire · Article 50 Transparency Notice Kit · 2026-07-26

This month's Template Drop: a fill-in-ready Article 50 transparency and synthetic-content disclosure notice, built for the 2 August 2026 EU AI Act deadline that held while the high-risk regime deferred.

Why This Template Now

The month closing 26 July 2026 delivered a split screen. One clock moved; another held firm. Operators need to read both correctly.

The Digital Omnibus on AI was signed 8 July 2026, per secureprivacy.ai reporting on the Council's 29 June 2026 final approval. Parliament had endorsed the package 423-57 on 16 June 2026. The Omnibus deferred the standalone Annex III high-risk regime — hiring, credit scoring, biometrics — to 2 December 2027. Annex I embedded product AI moved to 2 August 2028. That is an easing on one track.

The transparency track did not move. Per technology.org reporting dated 17 July 2026, the Omnibus left Article 50 obligations on their existing schedule. From 2 August 2026, providers and deployers must disclose chatbot interactions, mark synthetic content, and label deepfakes. Penalties reach up to EUR 15M or 3% of global turnover. This is the enacted obligation with the nearest binding date across the entire month's digest.

The gap between those two tracks is worth reading slowly. The 423-57 Parliament vote and the Council's 29 June 2026 approval carried a package that touched the high-risk regime and the transparency regime in the same instrument, yet did not treat them the same way. The Annex III deferral to 2 December 2027 and the Annex I deferral to 2 August 2028 are the visible headlines; the untouched Article 50 schedule is the quiet clause that most operators will overlook precisely because the surrounding text is about postponement. When a single omnibus both defers some duties and leaves others in place, the defaults invert: silence on Article 50 is not neglect, it is preservation. The obligation that did not move is the one that binds soonest.

Two adjacent EU clocks reinforce the urgency. Per jonesday.com, GPAI enforcement begins 2 August 2026 for models placed on the EU market after 2 August 2025. Per usercentrics.com, the Article 50(2) machine-readable marking requirement for synthetic content applies from 2 December 2026, with a narrow four-month grace window for the marking format on systems already on the market. New Article 5 prohibitions on nudifier and CSAM-generating AI also apply from 2 December 2026.

Read together, these dates describe a staged sequence rather than a single cliff. The 2 August 2026 disclosure duties come first and require no new technology — a chatbot notice, a deepfake label, a public-interest text disclosure are interface and editorial decisions. The 2 December 2026 marking-format requirement comes second and is the technically harder lift, because it depends on machine-readable provenance that must be effective and interoperable. The four-month grace window is scoped narrowly to the format on systems already on the market, not to the underlying disclosure duties, which means an operator cannot use the grace as cover for missing the August obligations. GPAI enforcement landing on the same 2 August 2026 date compounds the pressure for any organization that both operates a general-purpose model and interacts with EU users through it.

The deferral creates a specific risk. Deployers who read "high-risk deferred to 2027" may stand down their entire AI Act program. That would be an error. The transparency duties bind in days, not years. This template exists to close that gap: a single document that operationalizes the 2 August 2026 disclosure duties and stages the 2 December 2026 marking-format work behind them.

The error is not merely a scheduling mistake; it is a category error. Standing down "the AI Act program" treats the Act as one undifferentiated obligation with one date, when the enacted structure is a set of independently timed duties. A deployer whose systems fall outside Annex III entirely still faces Article 50 in full. A deployer whose systems fall inside Annex III faces both the deferred high-risk regime and the undeferred transparency regime — the deferral relieves the former and leaves the latter untouched. In neither case does 2027 describe the operative deadline for transparency work. The template stages the two live EU dates in order so that the near duty is not buried under preparation for the far one.

The template below is drawn strictly from the enacted AI Act as amended by the Omnibus. It is a starting document, not a compliance guarantee.

The Template: Article 50 Transparency & Synthetic-Content Disclosure Notice Kit

This kit contains four components: (A) a chatbot interaction disclosure, (B) a synthetic-content marking record, (C) a deepfake labeling statement, and (D) an internal control register. Bracketed fields are fill-ins. Footnote citations trace each clause to its instrument.

Component A — Chatbot / AI Interaction Disclosure

[ORGANIZATION LEGAL NAME] — AI Interaction Disclosure, effective [DATE, on or before 2 August 2026].1

A.1. This disclosure applies to [SYSTEM / PRODUCT NAME], an AI system intended to interact directly with natural persons.1

A.2. Users are informed at first interaction: "You are interacting with an artificial intelligence system, not a human." This notice appears [PLACEMENT: e.g., pre-chat interstitial / persistent header].1

A.3. This disclosure is omitted only where the interaction is obvious to a reasonably well-informed natural person from the circumstances and context of use. [STATE WHETHER THE OBVIOUSNESS EXEMPTION IS RELIED ON — YES / NO. If YES, document the basis.]1

A.4. Obligation owner. The disclosure duty in A.1–A.3 falls on the provider of the system. Where [ORGANIZATION] deploys a third-party system, the deployer confirms the provider-supplied disclosure is active and unaltered.1

A.5. Accessibility. This information is provided in clear and distinguishable form, accounting for [ACCESSIBILITY MEASURES].1

Component B — Synthetic-Content Marking Record

B.1. Scope. This record governs [SYSTEM NAME], which generates synthetic audio, image, video, or text content.2

B.2. Marking duty (provider). Outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. This obligation falls on the provider of the generative system.2

B.3. Marking-format compliance date. The machine-readable marking requirement under Article 50(2) applies from 2 December 2026.2 Systems already on the market before transparency rules took effect have a four-month grace window for the marking format only. [STATE WHETHER THIS SYSTEM WAS ON THE MARKET BEFORE 2 AUGUST 2026 — YES / NO.]2

B.4. Format selected. [NAME THE MACHINE-READABLE MARKING STANDARD ADOPTED, e.g., C2PA-based provenance metadata / cryptographic watermark]. Where no standardized format is yet available, document the interim measure and the review date. [INTERIM MEASURE / REVIEW DATE].2

B.5. Technical feasibility. Marking solutions are effective, interoperable, robust, and reliable as far as technically feasible, accounting for [CONTENT TYPE-SPECIFIC CONSTRAINTS].2

Component C — Deepfake & Public-Interest Text Labeling

C.1. Deepfake disclosure (deployer). Where [SYSTEM NAME] generates or manipulates image, audio, or video content constituting a deepfake, [ORGANIZATION] discloses that the content has been artificially generated or manipulated. Effective on or before 2 August 2026.3

C.2. Editorial-control exemption. Where content forms part of an evidently artistic, creative, satirical, or fictional work, disclosure is limited to a manner that does not hamper display or enjoyment. [STATE WHETHER RELIED ON — YES / NO.]3

C.3. Public-interest text. Where AI-generated text is published to inform the public on matters of public interest, [ORGANIZATION] discloses the artificial generation, unless the content underwent human review or editorial control with assigned editorial responsibility. [STATE THE EDITORIAL-RESPONSIBILITY ARRANGEMENT.]3

Component D — Internal Article 50 Control Register

D.1. System inventory. Each in-scope AI system is logged: [SYSTEM ID | PROVIDER/DEPLOYER ROLE | INTERACTION TYPE | SYNTHETIC OUTPUT Y/N | DEEPFAKE CAPABILITY Y/N].1,2,3

D.2. Role determination. For each system, the register records whether [ORGANIZATION] acts as provider (develops/places on market under own name) or deployer (uses under its authority). Misassignment shifts the wrong duties to the wrong party.1

D.3. Evidence of compliance. For each duty, the register links the artifact demonstrating it: interface screenshot, marking-format specification, label design, exemption justification memo.

D.4. Penalty exposure note. Non-compliance with Article 50 transparency obligations carries penalties up to EUR 15M or 3% of global annual turnover, whichever is higher.4

D.5. Review cadence. This register is reviewed [FREQUENCY] and re-reviewed on the 2 December 2026 marking-format date and again if the Official Journal publication of the Omnibus alters entry-into-force timing.2,5

Footnotes. 1 Article 50 chatbot/interaction disclosure, per technology.org (17 July 2026). 2 Article 50(2) machine-readable marking, applies 2 December 2026 with four-month format grace, per usercentrics.com. 3 Article 50 deepfake and public-interest text labeling, per technology.org. 4 Penalties up to EUR 15M or 3% global turnover, per technology.org. 5 Digital Omnibus on AI signed 8 July 2026; entry into force three days after Official Journal publication, per secureprivacy.ai.

Usage Notes

This kit is a starting document. It operationalizes enacted duties under the AI Act as amended; it does not guarantee compliance and does not substitute for counsel on material exposure.

Who signs it. Component D — the internal control register — should carry the sign-off of the person accountable for AI governance: a designated compliance owner, product counsel, or the officer holding data-protection responsibility. Components A through C are customer-facing artifacts; they do not require a signature, but the register that proves they are live does. Assign one named owner per in-scope system. Diffuse ownership is how a 2 August 2026 disclosure fails to ship. The failure mode is predictable: three teams each assume another holds the duty, the interstitial in A.2 never gets prioritized, and the deadline passes with the interface unchanged. A single named owner per system converts a shared assumption into an assigned task, which is the difference between a control that exists on paper and one that is live in the product.

Where it lives. The register belongs in the same evidence store used for GDPR records of processing — versioned, timestamped, retrievable. The customer-facing disclosures live in the product itself: the chatbot interstitial (A.2), the content-provenance metadata (B.4), the deepfake label (C.1). Keep the design artifact and a dated screenshot in the register so the interface state is provable at a point in time. Co-locating the register with the GDPR records of processing is not a filing convenience; it puts the Article 50 evidence in the same retrieval path an authority already knows how to inspect, and it links the transparency artifact to the accountability practices the organization has presumably already built for data protection. A dated screenshot matters because compliance is a state at a moment: an interstitial that shipped in September proves nothing about whether the notice was live on 2 August 2026 unless the interface state on that date is independently recorded.

What records it generates. Three: the role-determination memo (D.2), the exemption justification memos where A.3, C.2, or C.3 are relied upon, and the marking-format specification (B.4). The exemption memos matter most. The obviousness exemption, the editorial-control exemption, and the human-review carve-out for public-interest text are each defensible only if documented before reliance, not reconstructed after an inquiry. A memo written before reliance records a genuine contemporaneous judgment; one assembled after an inquiry opens reads as advocacy for a position already taken. The three exemptions share this structure — each is a conditional relief that the operator, not the regulator, elects to invoke, and the burden of showing the condition was met sits with the party claiming it.

The role question is the whole game. Article 50 splits its duties. The interaction-disclosure and synthetic-marking duties in A and B fall primarily on the provider — the party that develops the system and places it on the market under its own name. The deepfake and public-interest labeling duties in C fall on the deployer — the party using the system under its authority. An organization that builds and uses its own model holds both roles for that system. An organization that licenses a third-party model is usually a deployer, and its duty narrows to confirming provider-supplied marking is active (A.4, B.2) and to applying its own deepfake labels (C.1). Fill D.2 first. Everything downstream depends on it. The reason the register front-loads role determination is that every subsequent duty is conditional on it: a deployer who wrongly self-classifies as a provider may waste effort building marking infrastructure it does not owe, while a provider who wrongly classifies as a deployer may leave the A and B duties unowned entirely. The dual-role case — build and use your own model — is the one that most often gets under-scoped, because the organization tends to think of itself as one thing when Article 50 treats it as two.

Jurisdictional reach. Article 50 binds providers and deployers placing systems on the EU market or whose output is used in the EU, regardless of establishment. A US-headquartered deployer serving EU users is in scope. The kit covers the EU transparency obligations only. It does not cover the GPAI obligations enforceable from 2 August 2026, per jonesday.com, nor the Article 5 prohibitions on nudifier and CSAM-generating AI effective 2 December 2026, per usercentrics.com. Those require separate treatment. The output-based trigger is the part US operators most often misread: establishment outside the EU is not a shield when the output is used inside it, so a model hosted and run entirely on US infrastructure can still pull its operator into scope the moment EU users consume its results. That reach is why the kit's role and market-timing questions cannot be waved off as a European concern for European entities alone.

Where it needs counsel review for variants. Three points warrant it. First, the obviousness exemption at A.3 — its scope is contextual and untested by enforcement. Second, the editorial-responsibility carve-out at C.3 — the guidance on Article 50(4) is still developing per usercentrics.com. Third, the market-timing determination at B.3, which decides whether the four-month format grace applies to a given system. Each is a judgment call with penalty exposure behind it. All three share a common feature: they turn on a boundary that the enacted text states but does not fully define, and where the definition is thin the safer reading is the narrower one. Treating the obviousness exemption expansively, stretching the editorial carve-out, or resolving an ambiguous market-timing date in the operator's favor each converts a documentation question into a wager against an untested enforcement posture.

What this kit is not. It is not a high-risk conformity package. The Annex III high-risk regime deferred to 2 December 2027, per secureprivacy.ai; systems in hiring, credit scoring, and biometrics carry additional duties this kit does not address. Deployers of those systems should not read the deferral as a reason to stand down transparency work that binds on 2 August 2026. The point bears repeating precisely because it is counterintuitive: a hiring or biometrics system can simultaneously enjoy the high-risk deferral and owe the full Article 50 transparency duties, and the same system can therefore be behind schedule on August while comfortably ahead on 2027. The deferral changes what those systems must document for conformity; it changes nothing about what they must disclose to the people interacting with them.

The Month on the Clock

JurisdictionInstrumentCompliance dateStatus
EUAI Act Article 50 transparency (chatbot, synthetic content, deepfake) — per technology.org2 August 2026Holds — this kit's deadline. Not deferred by the Omnibus.
EUGPAI obligations + fines, models placed after 2 Aug 2025 — per jonesday.com2 August 2026Live; soft-touch first year ends
EUArticle 50(2) machine-readable marking format — per usercentrics.com2 December 2026Standing; four-month format grace for pre-existing systems
EUArticle 5 prohibitions (nudifier, CSAM-generating AI) — per usercentrics.com2 December 2026New prohibition added by Omnibus
EUAI Act Annex III standalone high-risk — per secureprivacy.ai2 December 2027 (deferred)Moved this month; deferred from prior schedule
EUAI Act Annex I embedded product AI — per secureprivacy.ai2 August 2028 (deferred)Moved this month
EUGPAI models on market on/before 2 Aug 2025 — per jonesday.com2 August 2027Standing grace
Colorado, USSB 26-189 ADMT duties (replaced SB 24-205) — per verifywise.ai1 January 2027Enacted; AG rulemaking after 13 July 2026 comment close
Illinois, USAI Safety Measures Act (SB 315), signed 6 July 2026 — per skadden.com1 January 2027 (audits from 1 January 2028)Enacted this month
ChinaImplementation Opinions on AI Agents — per machinebrief.comEnforceable 15 July 2026Enacted this month; live

The month's arc: two EU high-risk clocks moved back, one EU transparency clock and one GPAI clock held firm on 2 August 2026, and three jurisdictions — Illinois, China, and Colorado's rulemaking track — advanced enacted obligations. The nearest binding date this template addresses is 2 August 2026.

Reading down the board, the cross-region pattern is that the deadlines cluster rather than scatter. Four EU dates and two US dates fall within roughly seventeen months of each other, and the two dates that are already live — the EU's 2 August 2026 transparency and GPAI obligations, and China's 15 July 2026 AI Agents opinions — bracket the close of this very month. The Illinois and Colorado dates land together on 1 January 2027, with Illinois audits following a further year out on 1 January 2028 and Colorado's duties still awaiting the AG rulemaking that follows the 13 July 2026 comment close. That staging tells an operator with exposure across regions where to point effort now: the EU transparency clock and the live Chinese obligation demand attention this month, while the US state duties, though enacted, leave a full quarter or more of runway. The template addresses only the nearest of these, but the board makes clear it sits at the front of a queue, not alone.

Independent regulatory intelligence — not legal advice. Matters with material exposure warrant counsel.