TL;DR: The EU began enforcing Article 50 of the AI Act on 2 August 2026, requiring AI systems that interact with people to disclose they are AI, synthetic content to be machine-readable, and certain deployers to disclose emotion recognition, biometric categorisation, and deepfakes, according to Cakewalk. This turns transparency into an operational control problem, not a policy statement, because role assignment and first-contact disclosure now determine whether an AI deployment is compliant.
NHIMG editorial — based on content published by Cakewalk: The EU Started Enforcing the AI Act's Transparency Rules on August 2
By the numbers:
- Article 99 caps the fine at 15 million euros or 3% of worldwide annual turnover, whichever is higher.
- The European Commission and national authorities began enforcing Article 50 on 2 August 2026.
Questions worth separating out
Q: How should organisations govern AI systems that can make consequential decisions?
A: Organisations should govern consequential AI systems with the same discipline used for high-risk identities: defined ownership, least privilege, logging, approval boundaries, and human override.
Q: When do AI transparency rules become an IAM concern?
A: They become an IAM concern when AI systems are tied to employee access, customer identity journeys, biometric categorisation, or any workflow where the system directly interacts with natural persons.
Q: What do privacy teams get wrong about AI disclosures in privacy law?
A: They often treat AI disclosures as notice language alone, when the real requirement is operational evidence.
Practitioner guidance
- Map provider and deployer ownership Create a register that records which teams act as providers and which act as deployers for each AI system, including human-facing use cases and internal-only deployments.
- Embed first-contact disclosure Require every human-facing AI system to present a clear disclosure at the first interaction or exposure, including chat interfaces, service portals, and support workflows.
- Preserve machine-readable provenance Ensure synthetic audio, image, video, and text are tagged in a machine-readable format so labelling survives publication, transfer, and downstream detection.
What's in the full article
Cakewalk's full article covers the operational detail this post intentionally leaves for the source:
- The exact wording of Article 50's transparency duties and how the EU distinguishes providers from deployers.
- The enforcement timeline, including the December 2026 grace period for some generative AI systems placed on the market before 2 August 2026.
- The fine structure under Article 99 and how enforcement responsibility is split across EU authorities.
- The specific categories of synthetic content, emotion recognition, and biometric categorisation that trigger different notice obligations.
👉 Read Cakewalk's analysis of the EU AI Act's transparency rules and enforcement →
EU AI Act transparency rules: what do providers and deployers need to do?
Explore further
Role assignment is now a control, not a legal footnote. Article 50 makes provider versus deployer classification a governance decision that directly changes what must be disclosed, labelled, and audited. Organisations that cannot map those roles consistently will struggle to prove compliance across chatbots, synthetic media systems, and biometric use cases. The practical outcome is that AI inventory must be tied to ownership and exposure, not just model names.
A question worth separating out:
Q: Who is accountable when AI-generated content or biometric use fails to meet transparency rules?
A: Accountability depends on the role and use case. Providers usually own system design and labelling obligations, while deployers can own disclosure to exposed individuals and published content responsibilities. Organisations should document that split before deployment so evidence exists if regulators ask who controlled the workflow.
👉 Read our full editorial: AI Act transparency rules shift disclosure and labelling risk