VERIK / V102 / 22 JUL 2026
Mythos AsymmetryGovernance

The Guidance That Was Retained, The Enforcement That Was Not

On 20 July 2026, less than a fortnight before Article 50 of the EU AI Act becomes applicable, the European Commission published its final Guidelines on the implementation of the transparency obligations for providers and deployers of certain AI systems under Article 50, reference C(2026) 5054. Together with the Code of Practice on Transparency of AI-Generated Content published on 10 June 2026, they complete the interpretive framework for the first AI Act obligations most organisations will have to meet. Fines for violation are set at up to fifteen million euro or three percent of total worldwide annual turnover, whichever is higher.

The document runs to more than one hundred pages. It is the Commission's first comprehensive interpretation of the provision that will, from 2 August 2026, determine how chatbots and AI agents identify themselves, how AI-generated content is marked and detected, and how deepfakes and certain AI-generated text publications are labelled. It is also non-binding.

What Article 50 Says And What The Guidelines Add

Article 50 divides transparency into five sub-obligations. Providers of AI systems intended to interact directly with natural persons must ensure users are informed they are dealing with AI. Providers of generative systems must mark synthetic audio, image, video, or text output in a machine-readable format. Providers of emotion recognition and biometric categorisation systems must notify the persons exposed to them. Deployers of systems producing deepfakes or generating text on matters of public interest must disclose the artificial nature of that content. Providers of general-purpose AI models must equip downstream providers with the information needed to fulfil their own obligations.

The William Fry analysis published 21 July 2026 identifies the interpretive posture that stands out. The Commission gives Article 50(1) a decisively agentic reading. AI agents must disclose both their artificial nature and the person on whose behalf they are acting. Where a provider cannot reliably predict whether an agent will encounter natural persons once deployed, the agent must be designed at the architecture level to disclose itself in every situation where interaction is reasonably likely. Disclosures buried in terms and conditions, generic references to an assistant, and machine-readable marks that users cannot perceive are all identified as insufficient on their own.

The Article 50(4) reading is equally firm. Deployers cannot discharge the labelling duty by pointing to the provider's machine-readable marks. Labels must be perceivable by natural persons without technical tools or dedicated actions. The attenuated regime for evidently artistic or fictional works is to be construed strictly. Where content combines informative and creative characters, the informative character prevails and full labelling applies.

The Two Layers That Do Not Touch

Provider marking and deployer labelling live at different layers, and the Guidelines confirm that neither substitutes for the other. Machine-readable marking is a signal that automated detection systems can act on. Perceivable labelling is a signal that a natural person can act on. A deepfake video shared on a public platform carries both obligations. The provider must embed the mark. The deployer must apply the visible label. If either is missing, the transparency architecture the AI Act envisions does not close.

The Dastra practitioner brief frames the split cleanly. For a company using an AI-generated video of its own executive for a product announcement, the tool provider must embed a machine-readable marker in the output; the company publishing it, as deployer, must separately disclose to viewers that the footage was AI-generated, since it depicts a real person in a way that could otherwise pass as authentic. Two different actors, two different artifacts, no shared verification path. Whether the mark and the label agree in enforcement proceedings is a question the Guidelines do not answer, because they cannot; both are non-binding interpretations of a regulation whose enforcement power sits with member state market surveillance authorities not yet fully stood up.

The Non-Binding Character

The Guidelines are issued under Article 96(1)(d) of the AI Act to assist providers, deployers, and competent authorities in applying Article 50 consistently. They are, by design, non-binding. The authoritative interpretation of the AI Act ultimately rests with the Court of Justice of the European Union. The Guidelines frame supervisory expectations. They do not themselves impose obligations.

For signatories of the Code of Practice on Transparency of AI-Generated Content, a presumption of conformity attaches from 2 August 2026 for the technical marking and labelling duties. Signatory registration closed on 22 July 2026 at 18:00 CET. The presumption shifts the evidentiary burden in enforcement proceedings. It does not replace compliance. Organisations that did not sign are expected to demonstrate compliance through equivalently adequate means, including a documented gap analysis against the Code. Whether market surveillance authorities in twenty-seven member states will read that gap analysis the same way is a question the Guidelines cannot resolve.

The Deployment Tempo And The Instrument Tempo

The generative AI industry deploys at a tempo the regulatory instruments are not aligned with. The Digital Omnibus on AI provisional agreement of 7 May 2026 already carved a grace period for the machine-readable marking obligation under Article 50(2), extending the compliance deadline for systems already on the market from 2 August to 2 December 2026, according to reporting from the Record of Record. The interaction disclosure obligation under Article 50(1) and the deepfake labelling obligation under Article 50(4) are not covered by that extension. Agents in scope on 2 August must disclose themselves on 2 August.

Between 20 July, when the Guidelines were published, and 2 August, when the obligations apply, thirteen days elapse. In that window, providers and deployers are expected to inventory every interactive, generative, emotion recognition, and biometric categorisation system reaching EU users, classify their role for each, redesign disclosure surfaces to meet the perceivability standard, contract for upstream marking warranties, and document a compliance record. The Guidelines describe what compliance looks like. They do not describe how a national market surveillance authority will verify it, because the answer varies by member state.

What Remains On The Table

The governance artifact is retained. The governance function is not.