Checklist: is your organization ready for Article 50 of the EU AI Act on 2 August 2026?

Compliance8 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

On 2 August 2026 the transparency obligations of Article 50 of the EU AI Act become applicable. Unlike the high-risk obligations, which were postponed through the Digital Omnibus, this date is fixed. The obligations themselves are manageable, but they touch more departments than just IT: customer service, marketing, HR and communications all use AI systems that may fall under the article. This checklist walks through the steps you want completed before 2 August. For each step we indicate what should minimally be in place and what a supervisor or auditor would want to see. Prefer an interactive check? Our EU AI Act self-assessment shows which obligations apply to your organization and how compliant you currently are (in Dutch).

Step 1: inventory which AI systems fall under Article 50

Start with an inventory of AI systems in four categories: systems that interact directly with people (chatbots, voicebots, virtual assistants), systems generating synthetic content (text, image, audio, video), systems for emotion recognition or biometric categorization, and published content that may qualify as a deepfake. Do not forget AI features built into existing software: a customer service platform with an AI reply feature or a design tool with image generation counts. Ask the departments themselves, not just IT. Without this inventory, every next step is guesswork.

Step 2: determine your role per system

Article 50 divides the obligations between providers (whoever develops the system or offers it under their own name) and deployers (whoever uses the system under their own responsibility). Record your role per system. Watch for the cases where you are both, for example your own customer bot built on an external language model. The role determines what you must do: the design requirement for interaction transparency and the marking duty rest with the provider, informing people about emotion recognition and labelling deepfakes rest with the deployer.

Step 3: arrange the chatbot disclosure

For every system interacting with people: verify that the user clearly sees or hears, at the latest at the first interaction, that they are communicating with AI. Also check the channels where this is less self-evident, such as voicebots and bots in messaging apps, and the handover between bot and employee in hybrid channels. Record with a screenshot or test report that the disclosure works.

Step 4: verify the marking of generative output

If you are the provider of a system generating synthetic content, the output must be marked in a machine-readable way. This is where the only postponement within Article 50 plays: for systems placed on the market before 2 August 2026, the marking obligations take effect on 2 December 2026 through the Digital Omnibus. For new systems the duty applies immediately. The law prescribes no standard; C2PA is the most common in practice. Document which technique you use and why that choice is defensible. If you only use third-party generative tools, this duty rests with your vendor, but then verify it (step 7).

Step 5: set up the information duty for emotion recognition

If you use emotion recognition or biometric categorization, for example sentiment analysis on customer calls, you must inform the persons involved. First check whether the application is allowed at all: emotion recognition in the workplace and in education has been prohibited under Article 5(1)(f) since 2 February 2025, with an exception for medical and safety reasons. For permitted applications: record how and when people are informed, and align the wording with privacy, because the GDPR runs through this.

Step 6: arrange labels for deepfakes and AI text

If your organization publishes AI-generated image, audio or video resembling existing persons, places or events, it must be disclosed that the content is artificial. For AI text on matters of public interest a disclosure duty applies, unless there is human editorial control and responsibility. Define standard labels per content type and include the check in your content review process. Think beyond marketing: HR, sales and internal communications also publish synthetic media.

Step 7: record agreements with vendors

For purchased AI systems you want it contractually settled who fulfils which obligation. Ask your chatbot vendor where the transparency feature sits and whether it is on. Ask your generative AI vendor how output is marked. Record the answers. When a supervisor asks, "our vendor does that" only counts as an answer if you can show you verified it.

Step 8: anchor it in your management system and keep evidence

Complying once is not enough; new systems and new features keep arriving. Assign ownership for Article 50, include the transparency check in the process for approving new AI applications, and keep the evidence per system: disclosure flows, marking choices, labels and vendor agreements. Organizations with an ISO 42001 management system can attach this almost one to one to their existing AI inventory, usage policy and internal audit.

What if you are not fully ready on 2 August?

Violating the transparency obligations can lead, under Article 99(4)(g), to a fine of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher; for SMEs, Article 99(6) caps the fine at the lower of the two. How quickly and strictly national authorities will enforce remains to be seen. But the order of this checklist is also designed to cover the biggest risk first: the visible, customer-facing systems. A chatbot disclosure takes days to arrange. The deeper anchoring in contracts and management system can follow, as long as it is demonstrably in progress. Starting after the first question from a supervisor or a major customer is the expensive variant.

Want to know where your organization stands right now? Take the EU AI Act self-assessment: it shows which obligations apply to you and where your gaps are (in Dutch).

Source: this article is based on Regulation (EU) 2024/1689 (the AI Act), in particular Article 50, Article 5(1)(f) and Article 99(4)(g). The full legal text is available at https://eur-lex.europa.eu/eli/reg/2024/1689/oj

Frequently asked questions

What deadline applies to Article 50 of the EU AI Act?+

The transparency obligations apply from 2 August 2026. Only the machine-readable marking obligations for AI systems placed on the market before that date have been postponed to 2 December 2026 through the Digital Omnibus.

Which systems should I inventory for Article 50?+

Four categories: AI systems that interact with people (chatbots, voicebots), systems generating synthetic content, systems for emotion recognition or biometric categorization, and published content that may qualify as a deepfake. Built-in AI features in existing software count.

What should I arrange contractually with AI vendors?+

Who delivers the transparency feature and whether it is switched on, and how generative output is marked in a machine-readable way. Record the answers: when a supervisor asks, pointing to your vendor only counts if you can show you verified it.

What do I risk if I am not fully compliant on 2 August 2026?+

Violating the transparency obligations can lead, under Article 99, to a fine of up to EUR 15 million or 3% of worldwide annual turnover. Cover the visible, customer-facing systems first, such as the chatbot disclosure, and demonstrably work through the deeper anchoring afterwards.

Need help with compliance?

Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.

Explore Compliance Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us