Listen to this article
On July 20, the European Commission published the guidance companies have been waiting for on Article 50 of the EU AI Act: who must disclose an AI interaction, which synthetic outputs need machine-readable marks, when deepfakes need visible labels, and what counts as human review of AI-generated public-interest text. The rules apply on August 2. There is no general grace period.
The most important line is easy to miss. A superficial, formal, or procedural check - including spelling and grammar correction - is not human review. The Commission says the exemption requires deliberate examination of the substance by a person with relevant knowledge and professional judgment, or real editorial control with authority to approve, alter, or reject the content.
Transparency is now an operating requirement
Article 50 separates responsibility between providers and deployers. Providers must build direct AI interactions so people are informed from the start, unless the AI involvement is obvious. They must also make synthetic text, images, audio, and video detectable with effective, interoperable, machine-readable marks. Deployers carry the duties closest to the audience: disclose emotion recognition and biometric categorization, clearly label deepfakes at first exposure, and label AI-generated public-interest text that did not receive qualifying human review.
Those are not four versions of a footer disclaimer. They are controls at different points in the content lifecycle. A hidden provenance mark can help a platform detect synthetic media, but the Commission explicitly says a deployer cannot rely on that hidden mark alone to disclose a deepfake to a person. The visible disclosure is a separate gate with a separate accountable party.
| Responsible party | Trigger | Required control |
|---|---|---|
| Provider | Direct interaction with a person | Clear notice from the first interaction |
| Provider | Synthetic or manipulated output | Robust, detectable machine-readable marking |
| Deployer | Emotion recognition or biometric categorization | Inform every person exposed to the system |
| Deployer | Deepfake or unreviewed public-interest text | Clear, perceivable label for the audience |
The guidance also narrows the edges. Source code, short strings of numbers or symbols, closed-loop industrial outputs, and machine-to-machine content that is never exposed to people can fall outside the marking duty. Standard editing that does not substantially alter the input or its meaning can qualify for an exception. But these are scoped exceptions, not a broad enterprise carve-out. The limited transition to December applies only to the machine-readable marking obligation for certain generative systems already on the market before August 2. It does not postpone the interaction, biometric, deepfake, or public-interest disclosure duties. Existing inventory therefore matters: teams need to classify each system, role, output, audience, and release path before deciding which control applies.
The human-review exemption is a validation chain
The public-interest text rule has a practical exemption. AI-generated text does not need the Article 50 label when it has undergone human review or editorial control and a person or legal entity holds editorial responsibility. But the new guidance closes the checkbox loophole. A reviewer needs subject knowledge and must examine the substance. An editor needs actual authority over the substance. Someone must ultimately own the publication.
If the reviewer cannot reject the output, the review is theater. Article 50 now makes that distinction operational.
That changes the evidence an enterprise should retain. Who reviewed the output? Which version did they see? What source material and policy did they compare it against? What changed after review? Who approved release, and can the organization reproduce that decision later? A content label is the visible result. The governance system is the traceable decision behind it.
The AuthorityGate take
The Commission has described a validation layer without using the product term. The machine can generate, classify, and mark. A qualified person must be able to inspect the consequential output, compare it with policy and evidence, change or reject it, and remain identifiable as the decision owner. That is augmented AI: the machine proposes, the gates verify, and a human stays accountable.
AuthorityGate Keystone applies the same pattern to operational changes. AI content can mislead a customer; an AI agent with credentials can change a firewall, deploy code, or expose data. Both need more than a notice after the fact. They need a configurable validation path before effect: identity, policy, environment, risk, evidence, and a named human approval for consequential action. Article 50 makes the publication gate explicit. Enterprises should extend that discipline to every agent action that can touch production.
The deadline is close, but the design principle is durable. Transparency is not the claim that an organization reviews AI. It is the ability to show where disclosure happens, where provenance is preserved, where a qualified person can say no, and who is accountable when the output goes live. On August 2, that difference becomes enforceable.
Sources
- European Commission, Guidelines on transparency obligations for providers and deployers of AI systems (July 20, 2026)
- European Commission, Transparency obligations under Article 50 of the AI Act - questions and answers (July 20, 2026)
- Official Journal of the European Union, Regulation (EU) 2024/1689, Article 50
- European Commission, Code of Practice on Transparency of AI-Generated Content
Go deeper
Every agent action, validated before it takes effect
AuthorityGate's newsletter breaks down real AI incidents and the governance failures behind them. Our configurable 8-gate validation model is how organizations keep a named human accountable for what their AI actually does.