Initializing portfolio

000

Aravind.
All articles
AI6 min read

The EU AI Act Rule That Reaches You Even If You Never Built a Model

The high-risk obligations moved to December 2027. Article 50 did not — and it splits its transparency duties between providers and deployers, which puts live obligations on companies that never built a model.

AravindChief Technology Officer & Advisor · AI, Cloud & Cybersecurity
The EU AI Act Rule That Reaches You Even If You Never Built a Model

On 2 August 2026, the part of the EU AI Act that actually took effect was Article 50 — the transparency chapter. The high-risk obligations everyone had been preparing for did not arrive; they moved to 2 December 2027, which I wrote about when the Parliament approved the delay.

The delay got the coverage. Article 50 got much less of it, and it is the one that reaches ordinary enterprises today.

Article 50 does not put all its duties on the company that built the model. It splits them by role, and that is the part that gets missed.

Who owes what

Article 50 has four operative paragraphs, and they bind two different parties.

Providers — the ones who develop the system and place it on the market:

  • 50(1): an AI system that interacts directly with people has to tell them they are dealing with AI, unless that is obvious to a reasonably well-informed person.
  • 50(2): a system that generates synthetic audio, image, video or text has to mark its output in a machine-readable format, detectable as artificially generated. There is an exemption where the AI performs an assistive function for standard editing and does not substantially alter the input.

Deployers — the ones who use the system in the course of their business:

  • 50(3): if you run emotion recognition or biometric categorisation, you have to inform the people exposed to it.
  • 50(4): if you generate or manipulate deepfake content, you have to disclose it. For AI-generated text published to inform the public on matters of public interest, the disclosure requirement falls away where the content underwent human review with someone holding editorial responsibility.

An Indian company selling into Europe is, in most cases, a deployer. It licenses a model, wires it into a workflow, and ships something to a customer. On that reading, 50(3) and 50(4) are live obligations today, and 50(1) and 50(2) sit with the vendor.

Where the line stops being clean

The follow-up question is whether a deployer can become a provider. Put your own brand on a licensed system, modify it substantially, and the roles might swap.

The AI Act does have a rule for this. Article 25 says a distributor, importer or deployer becomes a provider when it puts its name or trademark on a system, makes a substantial modification, or changes the intended purpose so the system becomes high-risk.

But Article 25 is written for high-risk systems. Whether it re-labels you a provider for the purposes of Article 50's transparency duties is not something the current guidance settles, and I have not seen a source that resolves it cleanly.

That is not an academic question. If you white-label a third-party chatbot under your own brand for EU customers, you are in a genuinely grey zone on who owes the 50(1) disclosure. The safe operating assumption is that you own it, because the cost of being wrong is asymmetric: implementing a disclosure you did not strictly owe costs a line of UI copy, while missing one you did owe costs up to €15 million or 3% of worldwide annual turnover, whichever is higher.

Two dates that still bite

The high-risk delay does not slow either of these:

  • 2 December 2026. Providers of generative AI systems already on the market have until then to comply with the marking and detection requirements. That is the nearest real deadline in the AI Act, and it is four months away at the time of writing.
  • Content published before 2 August 2026 does not need retroactive labelling. If you have been publishing AI-assisted material into EU markets, you do not have to go back through the archive.

What I would do about it

This section is my assessment, not reporting.

Most enterprise AI compliance work I see is organised around the high-risk register — classify the systems, assess the risk tier, prepare the conformity paperwork. That work is now due in December 2027, and the extra sixteen months are real.

Article 50 does not fit that shape. It is not a register exercise, it is a product question: does this interface tell the user it is AI, and does this output carry a mark. It lands on the people who ship the front end, who are usually not the people in the compliance programme.

Three things worth checking this quarter, if you have EU-facing AI:

  1. Inventory by role, not by system. For each AI-touching product, write down whether you are the provider or the deployer, and who signed off on that answer.
  2. Find every interface where a customer talks to a model, and confirm the disclosure exists.
  3. Ask your model vendor, in writing, whether their output carries machine-readable marking and what the detection mechanism is. If you are a deployer, that answer is theirs to give — but you are the one whose customers are exposed if it is missing.

The high-risk deadline moved by sixteen months. Article 50's did not move at all.

Cover image: European Commission headquarters, Brussels, by Stephane Mignon, CC BY 2.0, via Wikimedia Commons.

Sources

#AI Governance#AI Regulation#EU AI Act#Compliance#Article 50

Comments

Checking you're human…

Keep reading

Get the next essay first

Checking you're human…

By subscribing you agree to our Privacy Policy. Unsubscribe anytime.