Since 2 August 2026, the EU AI Act transparency obligations in Article 50 of Regulation (EU) 2024/1689 apply across the Union. Unlike the much-discussed high-risk regime, these rules were not postponed. They are in force now, and they reach far beyond AI developers: any business that runs a customer-facing chatbot, publishes AI-generated marketing copy, or uses synthetic voice or video is potentially in scope.
This post sets out who is caught, what exactly must be disclosed, the one deadline still ahead of you, and how to structure a defensible compliance position.
What changed on 2 August 2026 — and what did not
The AI Act entered into force on 1 August 2024 with a staggered application timetable. For two years, 2 August 2026 was marked in compliance calendars as the date the framework would become substantially applicable.
That is no longer quite true. The Digital Omnibus on AI (Regulation (EU) 2026/1744), in force since 27 July 2026, deferred the core high-risk regime:
- Stand-alone high-risk systems (Annex III) — recruitment and HR tools, credit scoring, education, critical infrastructure, law enforcement — now apply from 2 December 2027.
- High-risk AI embedded in regulated products (Annex I) — medical devices, machinery, toys — apply from 2 August 2028.
Article 50 was deliberately left on the original timetable. The only carve-out is a short transitional period for one technical obligation, discussed below. If your compliance plan assumed the Omnibus bought you time across the board, that assumption is wrong.
Who the EU AI Act transparency obligations apply to
Article 50 imposes distinct duties on providers (those who develop an AI system and place it on the EU market under their own name) and deployers (those who use an AI system under their own authority in a professional capacity).
Most businesses are deployers. That is not a lesser status: several of the disclosure duties fall squarely and exclusively on deployers, and they cannot be contracted away to the vendor.
The territorial reach is broad. The AI Act applies to providers placing AI systems on the EU market irrespective of establishment, and to providers and deployers in third countries where the output of the system is used in the Union. A Bulgarian company using a US-developed model to generate content for the Bulgarian market is in scope. So is a German group deploying the same tooling across its EU subsidiaries.
The four transparency scenarios under Article 50
1. Chatbot disclosure requirement: direct interaction with people
Obligation on the provider. AI systems intended to interact directly with natural persons — chatbots, voice assistants, AI agents, automated call handling — must be designed so that the person is informed they are dealing with an AI system, unless this is obvious to a reasonably well-informed and observant user in the circumstances.
Practical point: “obviousness” is a narrow escape route. A chatbot named “AI Assistant” sitting in a clearly labelled widget may qualify; a synthetic voice on an inbound sales line almost certainly does not.
2. AI-generated content labelling and the watermarking obligation
Obligation on the provider. Providers of systems that generate synthetic audio, image, video or text must ensure the output is marked in a machine-readable format and detectable as artificially generated or manipulated. This is a provenance obligation — watermarking, metadata, cryptographic signatures — and the solutions must be effective, interoperable, robust and reliable as far as technically feasible.
It does not apply where the system performs a purely assistive function for standard editing, or does not substantially alter the deployer’s input data or its semantics. Spell-check and contrast adjustment are out; generating a photorealistic image from a text prompt is in.
3. Deepfake disclosure obligation
Obligation on the deployer. A deployer who generates or manipulates image, audio or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated.
Where the content is part of an evidently artistic, creative, satirical or fictional work, the disclosure duty is limited: it must be made in an appropriate manner that does not hamper the display or enjoyment of the work. Film credits and an on-screen notice at the start have been the working precedent.
4. AI-generated text on matters of public interest
Obligation on the deployer. Where AI-generated or manipulated text is published to inform the public on matters of public interest, the deployer must disclose that it was artificially generated — unless the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for it.
For publishers, PR agencies, trade associations and companies running a corporate news function, this is the provision to read twice. The safe harbour is real but conditional: it requires an identifiable human accountable for the output, not a rubber stamp.
And separately: emotion recognition and biometric categorisation
Deployers of emotion recognition systems or biometric categorisation systems must inform the persons exposed to them and process personal data in compliance with the GDPR. This obligation sits alongside — not instead of — the data protection analysis.
The one deadline still ahead: 2 December 2026
The Digital Omnibus granted a short transitional period for the machine-readable marking obligation under Article 50(2), and only for generative AI systems already placed on the market before 2 August 2026. Those providers have until 2 December 2026 to comply.
Two things follow:
- The transitional period covers the marking obligation only. Every other Article 50 duty — chatbot disclosure, deepfake labelling, text disclosure, emotion recognition notification — applies now, to all in-scope systems, regardless of when they were placed on the market.
- Content generated and published before 2 August 2026 does not have to be retroactively labelled. Going forward, it does.
How the information must be given
Article 50(5) is easy to overlook and frequently determines whether a disclosure passes muster. The information must be provided at the latest at the time of the first interaction or exposure, in a clear and distinguishable manner, and must comply with the applicable accessibility requirements.
A disclosure buried in terms of use, or surfaced only after the user has already exchanged several messages with a bot, does not satisfy this standard.
The Commission’s guidelines and the Code of Practice
Two soft-law instruments now shape the compliance picture:
- The Commission Guidelines on Article 50, adopted 20 July 2026, clarify scope, exceptions and use cases. They are not binding, but they are the reference point supervisory authorities will use, and departing from them requires a reasoned position on file.
- The Code of Practice on Transparency of AI-generated Content, facilitated by the AI Office, offers providers a recognised route to demonstrate compliance with the marking and detection duties, including a standardised set of labelling icons. Adherence is voluntary; several major providers have signed. Signatories gain a degree of presumed conformity and a more favourable enforcement posture.
For deployers, the practical consequence is procurement-side: ask your vendors whether they have signed, and whether their outputs carry compliant machine-readable marks. If they cannot answer, you have a supply-chain gap and should paper it.
AI Act penalties and enforcement exposure
Infringement of Article 50 attracts administrative fines of up to EUR 15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs and start-ups, the lower of the two figures applies.
Note also that the Omnibus added a new prohibition, applicable from December 2026, on AI systems used to generate non-consensual intimate imagery and child sexual abuse material — including so-called “nudifiers”. Prohibited practices sit in a different penalty bracket entirely.
Regulatory fines are not the only exposure. Undisclosed AI interaction and unlabelled synthetic content also raise questions under unfair commercial practices law, consumer protection rules, sector-specific advertising regimes and — where personal data is involved — the GDPR. In our experience, the commercial risk of a competitor complaint or a customer dispute materialises faster than a regulator’s file.
AI compliance in Bulgaria and cross-border groups
The AI Act is a Regulation. It applies directly in Bulgaria and in every other Member State; no national implementing act is needed for Article 50 to bite.
What national law determines is who enforces it and under what procedure. Member States were required to designate market surveillance and notifying authorities by 2 August 2025, and national implementation has been uneven across the Union. Businesses should not read a delay in designating an authority as a grace period. The substantive obligation exists regardless, and private-law and consumer-law routes to liability are unaffected by it.
For groups operating across Bulgaria and Germany — a configuration we advise on regularly — the practical issue is consistency. Group-wide AI tooling deployed from a German parent into Bulgarian operations creates provider/deployer roles that differ by entity and by system. Getting that allocation wrong at the contractual level is the most common structural error we see.
AI Act compliance 2026: a practical checklist
- Build the inventory. List every AI system your organisation develops, buys or embeds. You cannot classify what you have not found — and shadow AI adoption in marketing and customer service is the usual blind spot.
- Allocate roles. For each system, determine whether the entity is a provider, a deployer, or both. Do it per legal entity, not per group.
- Map to the four scenarios. Interaction, synthetic content, deepfake, public-interest text. Record the reasoning, including where you conclude an exception applies.
- Fix the disclosure layer. First-interaction notices for chatbots, labelling for synthetic media, accessible formats. Review the wording — vague “powered by AI” badges may not meet the clear-and-distinguishable standard.
- Establish editorial control. If you rely on the human-review exception for published text, document who holds editorial responsibility and how review is evidenced.
- Address the supply chain. Vendor warranties on machine-readable marking, Code of Practice adherence, and indemnities. Update your standard IT and SaaS terms.
- Document the governance. A short, dated compliance memo with your classification decisions is the cheapest evidence you will ever produce — and the first thing an authority will ask for.
Frequently asked questions
Does Article 50 apply to my company if we only use AI, not develop it? Yes. Deployers have their own obligations, in particular for deepfakes, AI-generated text published on matters of public interest, and emotion recognition or biometric categorisation systems. These duties cannot be transferred to your vendor by contract.
We are established outside the EU. Are we in scope? Potentially. The AI Act applies where an AI system is placed on the EU market, and to providers and deployers in third countries where the system’s output is used in the Union.
Do we have to label content we published before August 2026? No. Retroactive labelling of previously generated and published content is not mandatory, though it is encouraged. New output must comply.
Were the transparency rules delayed by the Digital Omnibus? Only in one narrow respect. Generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking obligation under Article 50(2). Everything else has applied since 2 August 2026.
What are the penalties? Up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher; the lower figure applies to SMEs and start-ups.
How we can help
Slavchev & Vasilev advises Bulgarian and German companies on AI Act readiness: system inventories and role allocation, Article 50 gap assessments, disclosure and labelling wording, vendor contract review, and group-wide governance documentation across Bulgarian, German and EU law.
Contact us to discuss an Article 50 assessment for your organisation.

Attorney Vasilev has been part of the law firm’s team since its establishment when he was a law student at Sofia University “St. Kliment Ohridski.” From the very beginning, he demonstrated exceptional commitment and ability to successfully handle even the most complex legal cases.



