Saltar al contenido
APFerrer

Article 50 of the EU AI Act: what the Digital Omnibus has not postponed and what your company should review

APFerrerOctober 02, 202618 min
Lead

The Digital Omnibus pushes the high-risk rules of the EU AI Act back to 2027, but since 2 August 2026 Article 50 has required companies to disclose their chatbots and mark AI-generated content.

Article 50 of the EU AI Act: what the Digital Omnibus has not postponed and what your company should review

What has moved is high risk. The chatbot on your website is exactly where it was.

On 24 July 2026, Regulation (EU) 2026/1744, the Digital Omnibus on AI, was published in the Official Journal of the EU. It entered into force on 27 July (Adequa). Since then, the line I keep hearing from SME managers is always the same: "They've postponed the AI Act, so we'll leave it until 2027".

What has been postponed are the high-risk obligations. Article 50 of the EU AI Act, the one that requires you to tell customers they are talking to an AI and to identify generated or manipulated content, has applied since 2 August 2026 (TrustAI). If your company has a chatbot on its website, an assistant answering on WhatsApp or campaign images that came out of a generator, that is the part of the regulation that concerns you. And that part has not moved.

There is a second date almost nobody has in their diary: on 2 December 2026 the grace period for marking synthetic content ends for generators that were already on the market before 2 August (CumpleConIA).

It applies now.

What changed with the Digital Omnibus (Regulation (EU) 2026/1744) and what did not

The Digital Omnibus amends the EU AI Act. It does not repeal it. The Council of the EU approved it in June 2026 (Cuatrecasas) and it then followed the usual route: publication in the Official Journal and entry into force a few days later.

The headline doing the rounds on social media and in newsletters says "the AI Act is delayed". It is convenient, because it saves the reader work. It is also inaccurate.

What does move. The obligations for high-risk systems. Those in Annex III move to 2 December 2027. Those in Annex I, which cover products already regulated by other EU legislation (machinery, medical devices, toys and the like), move to 2 August 2028 (Adequa). The reason is practical: high risk needs technical standards, conformity assessments and bodies to carry them out, and all of that has taken longer than planned.

What does not move. AI literacy under Article 4 and the prohibited practices have been in force since February 2025 (CumpleConIA). The transparency obligations in Article 50 apply from 2 August 2026. The bulk of Article 50 comes out of the Omnibus as it went in.

In plain terms: if nobody in your company uses AI to decide who gets hired, who gets credit or how a student is assessed, the postponement changes nothing for you. Your calendar is the same as before.

Annex III is the list of high-risk uses: recruitment, creditworthiness assessment, education, access to essential services, biometrics and a handful of public-sector areas. An online shop, a dental clinic or an accountancy practice rarely appears there. What almost all of them do have is a chatbot or a folder of generated images.

That is what Article 50 regulates.

The real EU AI Act calendar for 2026 and 2027, date by date

This is the table I would stick next to the screen of whoever runs marketing and customer service:

Date What happens Does it affect a typical SME?
February 2025 AI literacy (Art. 4) and prohibited practices Yes. Still in force, the Omnibus does not touch it
June 2026 The Council of the EU approves the Digital Omnibus on AI Context
24 July 2026 Regulation (EU) 2026/1744 published in the Official Journal of the EU Context
27 July 2026 The Omnibus enters into force Context
2 August 2026 Article 50 transparency obligations Yes, if you use chatbots, synthetic voice, or generated images or video
2 December 2026 End of the marking grace period for generators already on the market before 2 August, and ban on systems intended to generate non-consensual intimate images and child sexual abuse material Yes, as far as your generative tools are concerned
2 August 2027 National regulatory sandboxes must be operational (TrustAI) Only if you develop a product with AI
2 December 2027 Annex III high-risk obligations Only if you use AI in recruitment, credit, education and the other listed uses
2 August 2028 Annex I high-risk obligations (regulated products) Only if you manufacture regulated products that integrate AI

Look at the right-hand column. The "Yes" entries are all in 2025 and 2026.

Rule: if you read "postponement" in a headline, check which annex it refers to before you close the folder.

What Article 50 of the EU AI Act requires, without jargon

Article 50 of Regulation (EU) 2024/1689 groups several obligations, and each one falls on a different party. The text distinguishes between the provider (whoever develops the system or places it on the market under their own name) and the deployer (whoever uses it in their professional activity). An SME is almost always the second. Sometimes, without realising it, it is the first.

1. Disclose that people are talking to an AI

Systems intended to interact directly with people must be designed so that those people know they are talking to an AI. The exception: when this is obvious to a reasonably well-informed, observant and circumspect person, given the context.

That exception is the one most people use as a reason to do nothing. It is also the weakest. An assistant that answers on your website with a first name, an avatar photo and natural phrasing is not obvious to anyone. It is designed precisely so that it isn't.

The obligation is written for the provider. If you buy a chatbot from a software company and install it with two lines of code, the provider is whoever built it. If you build your own assistant on top of a language model's API and publish it under your brand, you are most likely the provider of that particular system. Either way, it is your company the customer holds to account.

2. Mark synthetic content

Providers of systems that generate synthetic audio, images, video or text must mark the output in a machine-readable format, so that it can be detected as artificial. The makers of the generators do this. You don't.

Your role here has two parts. First, know whether the tools you use mark what they generate. Second, don't destroy that mark in your own workflow. The mark often sits in the file's metadata, and your website's image optimiser, the compression plugin or the export from your editor will strip it without warning.

Context: the Omnibus gives generators that were already on the market before 2 August 2026 a grace period until 2 December 2026 to comply with this technical marking (CumpleConIA). That margin is for the manufacturer. Your notices to customers get no such margin.

3. Inform people about emotion recognition and biometric categorisation

If you use a system that detects emotions or classifies people by biometric traits, you must inform the people exposed to it. In an SME this turns up where you least expect it: phone system software that analyses a caller's tone of voice to measure how annoyed they are, or sales video call analytics that score the other person's interest.

Critical note: the GDPR has its say here too, and Article 50 itself points this out. The notice does not replace the legal basis for processing that data.

4. Identify deepfakes and certain published text

Anyone who uses a system to generate or manipulate images, audio or video that resemble real people, objects, places or events, and that could pass as authentic, must disclose that the content is artificial. That is the regulation's definition of a deepfake, and it is broader than the word suggests. You don't need to impersonate a politician. A generated photo shoot on a street that looks like Madrid, in a scene anyone would take as real, is already very close.

If the content is evidently artistic, creative, satirical or fictional, the obligation is limited to disclosing it in a way that does not spoil the work.

For text, the obligation applies when it is published to inform the public on matters of public interest. If a person has reviewed it and your company takes editorial responsibility, it no longer applies. A product description written with AI and reviewed by someone on your team falls outside this.

What the notice has to look like

The regulation requires the information to be given in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure, and in line with accessibility requirements. In practice:

  • At the start. The notice goes before the bot's first reply. The footer of the conversation is too late.
  • Where people can see it. In the chat window itself, in the welcome message or on the image label. The privacy policy does not count.
  • Readable. Enough contrast, normal text size and compatible with screen readers.
Obligation Who holds it What an SME does in practice
AI interaction notice System provider Check that the notice appears and, if the assistant is yours, add it
Synthetic content marking Generator provider Know which tools mark content and don't strip the mark
Emotion recognition or biometrics Whoever uses it Inform exposed customers or employees
Deepfakes Whoever uses it Label realistic generated images, audio or video
Text on matters of public interest Whoever publishes it Human review with editorial responsibility, or a notice

Does it affect you? Typical SME cases with chatbots, WhatsApp, product pages and campaign images

Online furniture shop in Valencia, 14 employees. It has a chatbot from a SaaS provider on its website that handles questions about delivery and sizes. It is called "Laura", shows a photo of a smiling woman and answers with phrases like "let me check that for you". The provider offers an AI notice in the settings, but it is switched off by default. There is work to do here: switch the notice on, replace the avatar with one that doesn't look like a photo of a real person and rewrite the welcome message.

Dental clinic in Zaragoza, 9 people. It uses a WhatsApp Business assistant that confirms appointments and answers frequent questions, and a phone system with a synthetic voice that takes calls out of hours. Both channels talk directly to patients. Both need a notice. On the phone, the notice goes in the first sentence of the recorded message, before the options menu.

Employment advisory firm in Seville, 22 people. It drafts replies to clients with an AI assistant, and a specialist reviews them before they go out. The client is dealing with a person who uses a tool. Article 50 does not require a notice here. What the firm should review is which client data gets pasted into that tool, and that is already the territory of AI literacy and the GDPR.

Online fashion shop in Bilbao, 6 people. It generates product photos with models who don't exist, in outdoor settings that look real. This is the deepfake without bad intentions: a scene that passes as authentic and isn't. The sensible approach is to treat it as one and put a visible label on those images. On the product page too, not only on Instagram.

Home renovation company in Málaga, 18 people. It has signed up for a phone system that "measures customer satisfaction from their voice". That is emotion recognition. It has to inform callers and, before that, confirm with whoever handles its data protection that it is allowed to process that information.

If you recognise yourself in any of these, the next section is your afternoon's work.

Article 50 EU AI Act checklist by channel, in one afternoon

Before reviewing channels you need to know which AI tools are really in use in the company, including the ones nobody has approved. If you don't have that inventory, start with the shadow AI audit. Without an inventory, this checklist falls short.

With the list in hand, open each channel as if you were a customer. What counts is what the other person sees. The settings panel can say one thing and the customer's screen another.

Website and chatbot

  • Visible notice before the first reply. In the chat header or in the welcome message.
  • Honest name and avatar. If the assistant has a person's name, the notice has to be even clearer. Better an avatar that doesn't look like a photo.
  • Handover to a person. Article 50 doesn't require it, but a visible "talk to a person" option reduces complaints and makes clear which part is automated.
  • Provider settings. Check whether the notice comes as standard, whether it can be switched off and who last changed it.
  • Mobile version. If the widget crops the header on small screens, the notice disappears.

A notice that works, ready to copy and paste:

"Hi, I'm the virtual assistant for [company]. I'm an artificial intelligence system and I can make mistakes. If you'd rather talk to a person, type PERSON."

WhatsApp and messaging

  • Notice in the first automated message. The business profile description won't do, almost nobody opens it.
  • Handover from bot to human flagged. When someone from the team steps in, they should say so. That way the customer knows which replies come from whom.
  • Templates reviewed. Quick replies generated by AI and sent by the system without anyone reading them count as interaction with AI.

Email

  • AI-generated replies without human review. If the system replies on its own, the sensible thing is for the email to say it was written by an automated system.
  • Drafts reviewed by a person. They don't need a notice under Article 50. They do need whoever sends them to actually read them before pressing send.

Phone and voice

  • Recorded messages with a synthetic voice. Notice in the first sentence: "You are speaking to an automated assistant".
  • Cloned voice of a real person, for example the manager's voice for the recorded messages. It is audio that resembles an existing person and can pass as authentic. You have to say so.
  • Emotion analysis on calls. If the phone system does it, inform callers at the start of the call and check the legal basis with whoever handles data protection.

Social media

  • Realistic generated images and videos. A label on the piece itself or in the post text, plus the platform's AI content label if it offers one.
  • Synthetic avatars and presenters in video. Notice at the start of the video. Nobody sees the end credits.
  • Clearly creative or humorous content. A light notice that doesn't spoil the piece. But a notice.

Product and catalogue images

  • Photos with generated models, settings or situations. A visible label on the website, in the PDF catalogue and on the marketplaces where you sell.
  • Metadata. Check that your image optimiser, your CMS or your CDN doesn't strip the content credentials the generator adds.
  • Minor retouching. Removing a reflection or cleaning up a background doesn't turn a real photo into a deepfake. Replacing the whole setting or the person does.

Blog and text

  • Documented human review. One line in your editorial procedure stating who reviews and approves texts before publication.
  • Texts on matters of public interest without review. Here you do need a notice.

Providers

  • Ask in writing. What the generator marks, whether the chatbot comes with a notice as standard and what happens if you switch it off. The clauses worth negotiating with an AI provider are in the article on contracts with AI providers.

A template email to send this week:

"Hello. We are reviewing our obligations under Article 50 of the AI Act. Please confirm in writing: 1) whether your system shows a notice that the user is interacting with an AI and whether it is switched on by default; 2) whether the content your tool generates carries machine-readable marking and in what format; 3) whether that marking survives standard export and compression. Thank you."

Wrap up the afternoon with a one-page document. Columns: channel, tool, obligation, status and owner.

That's it.

Common mistakes

Mistake 1: The hidden notice. Symptom: the notice that the chat is an AI sits in the privacy policy, the legal notice or a "more information" link nobody clicks. Fix: move it into the chat window and place it before the first reply. It is the same failure as badly built cookie banners, and it is fixed with the logic I explain in the article on GDPR consent on a small website.

Mistake 2: "It's obviously a bot". Symptom: the team decides no notice is needed because "everyone knows those things are automated". Fix: test the chat with someone from outside the company and ask them afterwards whether they were talking to a person. If they hesitate, it wasn't obvious. The regulation's exception requires it to be obvious to a reasonably well-informed, observant and circumspect person. Your technical team is not the yardstick.

Mistake 3: Marking only on social media. Symptom: the generated images carry the AI label on Instagram because the platform adds it automatically, but on the website, in the catalogue and on the marketplace they appear with nothing. Fix: the obligation travels with the image wherever it is published. Label it everywhere.

Mistake 4: Stripping the mark by accident. Symptom: the generator embeds the mark in the metadata and the publishing workflow removes it when compressing or resizing. Fix: upload a test image, download it from the live website and check its metadata with any viewer. If the mark has gone, adjust the optimiser settings.

Mistake 5: Assuming the provider has it covered. Symptom: "the chatbot comes from a big company, they'll take care of compliance". Fix: the provider has its part, but you control the settings. A notice switched off by default complies with nothing. Ask in writing what the provider does and what falls to you.

What to prepare before 2 December 2026

On 2 December 2026 the grace period for technical marking ends for generators that were already on the market before 2 August. From that date, any generator you use should mark what it produces, and you should be able to show that you don't strip that mark. The same day brings the ban on AI systems intended to generate non-consensual intimate images and child sexual abuse material (CumpleConIA).

The ban seems remote, unless you offer your customers a tool that generates images or your team uses generators from personal accounts. For most SMEs, an acceptable use policy that prohibits it in writing and a register of authorised tools is enough.

List for the coming weeks:

  1. Inventory of generators. Which image, video, audio and text tools are used, with which account and for what.
  2. Answer from each provider. Whether it marks content, how, and where that can be checked.
  3. Publishing test. One generated image, published through your normal workflow and checked afterwards to see whether it keeps the mark.
  4. Visible labels agreed. A standard text for realistic generated images and the exact place it goes on each channel.
  5. Acceptable use policy updated. With the new prohibitions written in plain language.
  6. Training for the team that publishes. Marketing, customer service and whoever manages the website. The groundwork is in the guide to AI literacy under the EU AI Act, which I won't repeat here.

If you also use AI in any Annex III process, such as screening CVs, your next date is 2 December 2027. Use these months to document which tool it is, what it decides and who supervises it. And if you develop a product with AI, national regulatory sandboxes must be operational by 2 August 2027. That is the route to test it under supervision before launch.

It's not complicated. It's discipline.

Frequently asked questions

Has the EU AI Act been postponed by the Digital Omnibus?

Only in part. The Digital Omnibus postpones the high-risk obligations: Annex III to 2 December 2027 and Annex I to 2 August 2028. AI literacy and the prohibited practices have been in force since February 2025, and Article 50 of the EU AI Act on transparency has applied since 2 August 2026.

Since when has it been mandatory in the EU to disclose that a chatbot is an AI?

Since 2 August 2026. The notice must be given clearly, at the latest at the first interaction, unless it is obvious to a reasonably well-informed person that they are talking to a machine. An assistant with a person's name and natural language hardly fits that exception.

Do I have to label AI-generated images and text on my website?

Realistic images, audio and video showing people, places or objects that look authentic, yes. Text, only when it informs the public on matters of public interest and has not gone through human review with editorial responsibility. A product description drafted with AI and reviewed by your team doesn't need a label.

Which EU AI Act obligations are delayed to 2027 and which are not?

The Annex III high-risk obligations, which include uses such as recruitment or creditworthiness assessment, are delayed to 2 December 2027. Those in Annex I, linked to regulated products, move to 2 August 2028. AI literacy, the prohibited practices and Article 50 transparency are not delayed.

What is Regulation (EU) 2026/1744?

It is the Digital Omnibus on AI, the regulation that amends the EU AI Act. It was published in the Official Journal of the EU on 24 July 2026 and entered into force on 27 July 2026, after the Council of the EU approved it in June. It mainly changes the high-risk calendar and leaves transparency almost untouched.

What happens on 2 December 2026 under the EU AI Act?

The grace period ends for generators that were already on the market before 2 August 2026 to mark their content in a machine-detectable way. The same day, the ban on AI systems intended to generate non-consensual intimate images and child sexual abuse material comes in. For an SME, the task is to check that its tools mark content and that its publishing workflow doesn't strip that mark.

What I would do this week

Open the website on your phone, go into the chat like any customer and read the first message. If it doesn't say it is an AI, you already have your first task. Then do the same with WhatsApp, the phone system and the product pages that carry generated images. One afternoon is enough to know where you stand.

The Digital Omnibus has given breathing room to those working with high risk. To the online shop with a chatbot, the clinic with a WhatsApp assistant and the brand that generates its catalogue photos, it has given nothing. Their date was 2 August and it has already passed.

If the bottleneck is that the team that publishes and serves customers doesn't know which tools it uses, what they mark and where a notice is needed, take a look at the AI courses for companies and start there.


Sources:

AF
APFerrer
APFerrer · Consultora en datos y procesos
Author's note

Does it apply to your company? Tell me in 30 minutes and we'll see what fits.

Book 30 min