A sense of relief has been circulating in the industry over the past few weeks: "The EU AI Act's transparency rules were pushed back to December, so there's no need to rush." This perception is wrong, and the misunderstanding is turning into a serious liability risk for every agency that delivers AI output into the EU market. The reality is this: the general transparency obligations of AI Act Article 50 have been in force since August 2, 2026, and have not been postponed.
In this article we set out, in technical detail, exactly what changed, which single exception actually exists, why it directly concerns an agency based outside the EU, and the concrete steps a business delivering AI to clients needs to take today. The goal is not to create panic; it is to close the real compliance gap opened up by the "relax, it's been delayed" narrative.
Setting the timeline straight: what is in force, and what is in a transition period
The source of the confusion is that two different things have been blended under a single headline. Let's draw the distinction clearly:
- The general Article 50 obligations—chatbot notification, content marking, emotion-recognition disclosure, deepfake labeling—are fully in force as of August 2, 2026. These were not postponed.
- The single exception concerns only the watermarking / machine-readable marking sub-obligation in Article 50(2), and it applies solely to generative AI systems placed on the market before August 2, 2026. For those systems, a transition period was granted—until December 2, 2026—to complete marking compliance.
Note carefully: this transition period was cut from six months to three months. So "there's a transition period" does not mean "sit back and wait"; on the contrary, the timeline has tightened. This change was formalized through the Digital Omnibus package: the European Parliament approved it on June 16, 2026, and the Council of the EU on June 29, 2026.
The critical point is this: for every generative AI system placed on the market after August 2, 2026, all obligations—including watermarking/marking—apply from day one. The transition period covers only legacy (grandfathered) systems. If you are rolling out a new chatbot, a new image-generation pipeline, or a new voice assistant today, no "grace period" protects you.
What exactly changed on August 2: four obligation areas
Article 50 introduces transparency obligations for four distinct scenarios. The products you deliver to clients likely fall into more than one of these areas.
1. AI systems that interact directly with people
AI that interacts directly with a person—chatbots, voice assistants, automated call/outreach systems—must inform that person that they are interacting with an artificial intelligence. The only exception is where this is obvious to a reasonably informed person given the context; in practice, relying on that exception is risky.
2. AI-generated or manipulated content
Synthetically generated or altered content—including text, images, audio, and video—must be marked in a machine-readable format and be detectable as AI-generated or manipulated. This is a technical obligation on the provider side.
3. Emotion recognition and biometric categorization
An organization using an emotion-recognition system or a biometric categorization system must inform the natural persons exposed to it about how the system operates. GDPR obligations continue to apply in parallel.
4. Deepfakes and AI-generated text published in the public interest
A deployer creating a deepfake must clearly disclose that the content has been artificially generated or manipulated. Likewise, AI-generated text published to inform the public on matters of public interest must be clearly labeled (subject to limited exceptions, such as content that has undergone human editorial control).
Chatbot and voice-assistant notification: where and how to place it, and why the T&Cs won't cut it
This is where the most common agency mistake begins. You roll out a chatbot, add a line to the terms and conditions (T&Cs) or privacy policy saying "some of our services may be provided using artificial intelligence," and assume you've achieved compliance. This is insufficient.
The spirit of Article 50 is that the notification must be perceivable within the interaction itself, at the moment it happens. Concrete criteria:
- A clause buried in a contract or the T&Cs is not enough. A disclosure hidden in a document nobody reads does not count as "informing the user."
- A vague "assistant" label is not enough. Merely showing "Support Assistant" in the chat window does not clearly tell the other party they're talking to an AI. The wording must plainly state that it is automated / AI-based.
- The notification must appear at the start of the interaction—before or at the same time as the user's first message; for voice assistants, it must be delivered audibly at the beginning of the call.
In practice, the right architecture is to place a persistent, visible notification layer in the chatbot interface: wording along the lines of "This chat is conducted by artificial intelligence," pinned in the chat header and repeated in the welcome message. This layer must be channel-independent; it needs to be applied separately to the web widget, WhatsApp, and the voice line.
For agencies running a Claude-based support flow over WhatsApp, this notification layer is a small but mandatory compliance component that needs to be added to the existing infrastructure. We cover the technical foundations of this architecture in our article on customer support with the WhatsApp Business Cloud API and Claude; adding the AI Act notification layer to that flow is a concrete example of delivering compliance invisibly.
Machine-readable marking of AI-generated content: why a watermark alone isn't enough
The second major misunderstanding is in content marking. Many teams place a visible "AI-generated" label in the corner of an image, or attach a metadata tag to the file, and consider the job done. What Article 50(2) actually requires goes deeper.
- A metadata watermark on its own is not sufficient. Simple metadata fields are easily lost during copying, screenshotting, re-encoding, or platform uploads. The obligation requires the marking to be reliable, interoperable, and effective.
- The benchmark for the obligation is technical feasibility and industry standards. That is why, in practice, the approach adopted is a C2PA / content provenance–based marking method—cryptographically signed, bound to the file, and verifiable.
- The marking must be embedded inside the production pipeline; it must not be left to manual labeling after delivery. Every pipeline that produces images, video, or audio must automatically attach provenance data the moment the output is generated.
The right solution is to embed a C2PA / machine-readable marking pipeline into your content-production flow: every synthetic output ships with a signed manifest recording the generating model, the time of creation, and the editing history. This both delivers AI Act compliance and makes content provenance provable, strengthening brand credibility.
Deepfakes: labeling required "even without intent"
The subtlety agencies overlook with the deepfake obligation is this: the labeling requirement does not depend on an intent to deceive. A realistic synthetic image or video you produce for a campaign—entirely legitimate, humorous, or creative in purpose—also falls under the deepfake definition if it resembles a real person, place, or event, and the fact that the content is artificial must be clearly disclosed.
This directly affects advertising and content agencies: AI-generated "photorealistic" ad visuals, synthetic presenters in product demos, voiceovers produced with voice cloning—all of it is in scope. The disclosure must be made at the first display of the content, and in a perceivable manner. One more point to emphasize: open-source models are not exempt, and the fact that a system is not high-risk does not remove it from Article 50's scope. Transparency obligations cover almost everyone producing synthetic content, independent of risk classification.
Why this concerns an agency outside the EU: extraterritorial scope
The most common—and most dangerous—assumption is: "We're based outside the EU, so an EU regulation doesn't bind us." This is false. The AI Act has extraterritorial effect. What matters is not where your company is established, but where the AI output is used.
- If you produce chatbots, AI content, or deepfakes for clients serving the EU market, you are in scope.
- Agencies based outside the EU that serve, in particular, the German (DE) market are a typical example: the client is in the EU, the end user is in the EU, and the output is used in the EU. Being headquartered in Istanbul provides no exemption.
- If the output—or the output of the system—is used by people inside the EU, producing it outside the EU does not eliminate the obligation.
In other words, "we're not in the EU" is not a defense; it's a risk indicator. An agency outside the EU that today delivers AI output into the EU market must carry the compliance responsibility—either alone or shared with its client.
Provider or deployer? The distinction must be settled in the contract
The AI Act distributes obligations across two roles, and in the agency–client relationship it is often unclear who those roles fall to. That ambiguity is the most expensive gap the moment an audit or complaint arrives.
- Provider: the party that develops or places the AI system on the market. Technical / production-side obligations—such as machine-readable content marking—sit predominantly here.
- Deployer: the party that uses the AI system under its own authority. Usage-side obligations—such as issuing the chatbot notification, disclosing a deepfake, and providing emotion-recognition disclosure—sit predominantly here.
If an agency develops a chatbot and delivers it to a client, in most scenarios the agency is the provider and the client is the deployer; but if the agency operates the system on its own behalf, the roles can shift. That is why every agency–client contract must state clearly who is responsible for which Article 50 obligation. When you decide what kind of solution to deliver, this allocation of roles shapes both the technical architecture and the boundaries of liability together—you can think of it along the lines of the decision framework we lay out in our comparison of custom software versus off-the-shelf software.
The penalty picture: the cost of non-compliance
The administrative fine set out for Article 50 transparency violations is significant:
- €15 million or 3% of global annual turnover—whichever is higher.
This penalty is a deterrent for a small agency and a large enterprise client alike; and the turnover-based calculation can easily exceed €15 million for large businesses. Compliance is not a "nice to have"—it's a commercial imperative.
An urgent compliance checklist: inventory + gap analysis
Concrete steps to start on today:
- Build an AI product inventory. List every AI system you deliver to clients and use internally: chatbots, voice assistants, image/video/audio generation pipelines, campaigns containing deepfakes, and emotion-recognition/biometric tools.
- Map each product to the four obligation areas. Which product interacts with people, which produces synthetic content, which contains deepfakes, which processes biometrics?
- Run the date test. Was the product placed on the market before August 2, 2026? Only legacy generative systems get a transition period until December 2, 2026 for the 50(2) marking; everything else applies today.
- Run a gap analysis. Is the chatbot notification visible within the interaction, or buried in the T&Cs? Is content marking C2PA-based and persistent, or metadata that disappears? Are deepfakes being disclosed?
- Update your contracts. Write the provider/deployer roles and the allocation of obligations into every client contract.
- Set up an audit trail. Who saw which notification, and when; which content was marked, and how—keep this in a GDPR-compliant audit trail.
Note: This article is for general information only and does not constitute legal advice. You should obtain an individual assessment from a legal advisor for your specific situation.
An architecture for delivering compliance invisibly
The core message here can be summed up in a single sentence: running AI is not enough; from August 2, 2026, you have to deliver it in a way that is legally compliant. And you have to do this while scaling your autonomous workflows. When you roll out an AI agent or an automation flow, making the transparency layer a natural part of the architecture is far healthier than patching it in afterward; you can think of this as an extension of the design discipline we discuss in our piece on what an AI agent is and autonomous workflows.
An architecture that delivers compliance invisibly includes these bridges:
- A chatbot notification layer—visible AI disclosure within the interaction itself, across web, WhatsApp, and voice channels.
- A C2PA / machine-readable content-marking pipeline—a signed, persistent provenance manifest on every synthetic output.
- A compliance layer for existing WhatsApp + Claude support—notification and logging added without breaking running flows.
- A GDPR audit trail—a verifiable record of notification and marking events.
Partnerfy: delivering compliant AI under your brand, on your behalf
Partnerfy is the invisible technology partner for agencies and large enterprises. We build the AI Act–compliant chatbot notification layer, the C2PA-based content-marking pipeline, the compliance upgrade to WhatsApp + Claude support flows, and the GDPR audit trail—all white-label; the product stays under your brand, inside your client relationship. You keep the client; we carry the compliance burden. Running AI is not enough; from August 2 you have to deliver it in a legally compliant way—and we do that on your behalf.
To review the AI Act compliance of the AI products you deliver, book a call. Let's build your inventory, run the gap analysis together, and add compliance to your brand invisibly.