The EU AI Act Rule That Reaches You Even If You Never Built a Model
The high-risk obligations moved to December 2027. Article 50 did not — and it splits its transparency duties between providers and deployers, which puts live obligations on companies that never built a model.

On 2 August 2026, the part of the EU AI Act that actually took effect was Article 50 — the transparency chapter. The high-risk obligations everyone had been preparing for did not arrive; they moved to 2 December 2027, which I wrote about when the Parliament approved the delay.
The delay got the coverage. Article 50 got much less of it, and it is the one that reaches ordinary enterprises today.
Article 50 does not put all its duties on the company that built the model. It splits them by role, and that is the part that gets missed.
Who owes what
Article 50 has four operative paragraphs, and they bind two different parties.
Providers — the ones who develop the system and place it on the market:
- 50(1): an AI system that interacts directly with people has to tell them they are dealing with AI, unless that is obvious to a reasonably well-informed person.
- 50(2): a system that generates synthetic audio, image, video or text has to mark its output in a machine-readable format, detectable as artificially generated. There is an exemption where the AI performs an assistive function for standard editing and does not substantially alter the input.
Deployers — the ones who use the system in the course of their business:
- 50(3): if you run emotion recognition or biometric categorisation, you have to inform the people exposed to it.
- 50(4): if you generate or manipulate deepfake content, you have to disclose it. For AI-generated text published to inform the public on matters of public interest, the disclosure requirement falls away where the content underwent human review with someone holding editorial responsibility.
An Indian company selling into Europe is, in most cases, a deployer. It licenses a model, wires it into a workflow, and ships something to a customer. On that reading, 50(3) and 50(4) are live obligations today, and 50(1) and 50(2) sit with the vendor.
Where the line stops being clean
The follow-up question is whether a deployer can become a provider. Put your own brand on a licensed system, modify it substantially, and the roles might swap.
The AI Act does have a rule for this. Article 25 says a distributor, importer or deployer becomes a provider when it puts its name or trademark on a system, makes a substantial modification, or changes the intended purpose so the system becomes high-risk.
But Article 25 is written for high-risk systems. Whether it re-labels you a provider for the purposes of Article 50's transparency duties is not something the current guidance settles, and I have not seen a source that resolves it cleanly.
That is not an academic question. If you white-label a third-party chatbot under your own brand for EU customers, you are in a genuinely grey zone on who owes the 50(1) disclosure. The safe operating assumption is that you own it, because the cost of being wrong is asymmetric: implementing a disclosure you did not strictly owe costs a line of UI copy, while missing one you did owe costs up to €15 million or 3% of worldwide annual turnover, whichever is higher.
Two dates that still bite
The high-risk delay does not slow either of these:
- 2 December 2026. Providers of generative AI systems already on the market have until then to comply with the marking and detection requirements. That is the nearest real deadline in the AI Act, and it is four months away at the time of writing.
- Content published before 2 August 2026 does not need retroactive labelling. If you have been publishing AI-assisted material into EU markets, you do not have to go back through the archive.
What I would do about it
This section is my assessment, not reporting.
Most enterprise AI compliance work I see is organised around the high-risk register — classify the systems, assess the risk tier, prepare the conformity paperwork. That work is now due in December 2027, and the extra sixteen months are real.
Article 50 does not fit that shape. It is not a register exercise, it is a product question: does this interface tell the user it is AI, and does this output carry a mark. It lands on the people who ship the front end, who are usually not the people in the compliance programme.
Three things worth checking this quarter, if you have EU-facing AI:
- Inventory by role, not by system. For each AI-touching product, write down whether you are the provider or the deployer, and who signed off on that answer.
- Find every interface where a customer talks to a model, and confirm the disclosure exists.
- Ask your model vendor, in writing, whether their output carries machine-readable marking and what the detection mechanism is. If you are a deployer, that answer is theirs to give — but you are the one whose customers are exposed if it is missing.
The high-risk deadline moved by sixteen months. Article 50's did not move at all.
Cover image: European Commission headquarters, Brussels, by Stephane Mignon, CC BY 2.0, via Wikimedia Commons.
Sources
- AI Act | Shaping Europe's digital future — European Commission — the official implementation timeline, including the 2 December 2027 and 2 August 2028 high-risk dates and the 2 August 2026 enforcement milestone
- Commission starts enforcing AI Act rules and new transparency requirements on 2 August — European Commission — what the Commission itself says took effect
- Article 50: Transparency Obligations — EU Artificial Intelligence Act — the paragraph-by-paragraph split between providers and deployers, and the exemptions
- Article 25: Responsibilities Along the AI Value Chain — EU Artificial Intelligence Act — the conditions under which a deployer becomes a provider
- EU AI Act: Transparency Obligations Take Effect 2 August 2026 — Cooley — the 2 December 2026 transitional deadline, the no-retroactive-labelling point, and the penalty level
- What came into force with the EU's AI Act this week, and what didn't — Al Jazeera — the Digital Omnibus context for the high-risk postponement