The document that landed thirteen days early
The Commission does not often publish guidance with this little room to spare. On 20 July 2026 it approved and published the Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act. The obligations those guidelines explain apply from 2 August 2026. That is thirteen days between the final text and the date it describes.
The draft had been public since 8 May and the consultation on it closed on 3 June, so none of this is a surprise to anyone who was reading. What changed on Monday is that the interpretation stopped being provisional. Guidelines of this kind do not create obligations, because Article 50 already did that. They set out how the Commission and the national authorities intend to read it, which is the part a European operator needs before it commits money to a process.
Two duties, and they land on different desks
The split is the whole story. Article 50 puts one set of duties on providers and a different set on deployers. Providers have to make sure a system built to interact directly with a person tells that person they are dealing with an AI, and they have to mark AI-generated or manipulated output so that it is detectable in a machine-readable form. Deployers carry a narrower but more personal list: tell people when they are looking at a deepfake, when they are exposed to an emotion recognition or biometric categorisation system, and when they are reading AI-generated text published on a matter of public interest without human review or editorial control.
Most European businesses have spent the past year reading the AI Act as a supplier problem, and our own coverage of the 2 August date has pointed the same way, because the general-purpose model rules that bite on that day are aimed squarely at the labs. The guidelines close that comfort. The deployer half of Article 50 attaches to the company that puts the system in front of its own public, and there is no size threshold underneath it.
The marking you cannot do for yourself
The machine-readable marking requirement is worth isolating, because it is the one duty an operator cannot discharge by changing its own behaviour. Embedding provenance so that a third party can detect that output was machine-generated has to happen where the output is produced, which is inside the vendor system. If the tool you licensed does not mark what it emits, no policy written internally will put the mark there.
That turns a technical question into a procurement question with a date on it. Ask every generative vendor in your stack, in writing, whether their output carries machine-readable marking today, in what form, and whether they have signed the Commission Code of Practice on Transparency of AI-Generated Content. Those answers are cheap to collect now and expensive to reconstruct after an authority asks for them. A vendor that cannot answer inside a fortnight is telling you something about the next twelve months.
The carve-out is really an instruction
Read the deployer duty on AI-generated text closely and you find a condition rather than a prohibition. The disclosure obligation attaches when text on a matter of public interest is published without human review or editorial control. Where a named person reviews the piece and takes responsibility for it before it goes out, the duty does not arise the same way. The law is describing an editorial process and pricing the absence of one.
For anyone running a content operation, a corporate blog, a newsroom or a customer-facing knowledge base, that is a cleaner instruction than most regulation delivers. Work out which channels have a human editor of record and which do not. The ones that do not are either labelled or given a reviewer. There is no third option that survives an inspection, and building the reviewer role is the version of this that also improves the output.
What to have in place before 2 August
Three artefacts, none of which needs a lawyer to start. A one-page inventory of every place your organisation shows AI output to a person outside it, recording for each whether a human reviews it before publication. A written answer from each generative vendor on machine-readable marking. A short internal note recording who decided which channels get a label and when, because a dated decision is most of what an authority wants to see from a company of ordinary size.
None of that is expensive. The expense arrives if 2 August passes with nobody in the building able to say which of your public-facing text is machine-written and who checked it. Thirteen days was not much notice. It is enough for a list, and a list is where the next conversation will start.
Read next: Brussels Moves to Vet AI Before It Reaches You | August 2 Is When the EU AI Fines Become Real



