What the EU AI Act's transparency rules actually ask of a small agency

Most coverage tells agencies to label everything. That is not what Article 50 says.

View from a studio desk through a window onto a Lisbon street of tiled buildings with iron balconies

The transparency obligations in Article 50 of the EU AI Act apply from 2 August 2026. An agency using AI under its authority is generally a deployer. Its duties depend on the system, output and context. An agency developing or commissioning a system under its own name may also be a provider.

Most of what has been written about this is wrong in the same direction. It tells agencies to label everything. That is not what the regulation says.

The advice creates work nobody needs to do, and it makes the genuine disclosure cases harder to spot. Here is the accurate version.

What changed on 2 August 2026?

Two things. Article 50's transparency duties become applicable, covering chatbot disclosure, marking of synthetic content, and deepfake labelling. And the European Commission's enforcement powers over general-purpose AI models activate on the same date.

What is not happening is the high-risk regime. Those obligations were originally due on 2 August 2026.

The Digital Omnibus on AI moved standalone Annex III systems to 2 December 2027. The Council gave it final approval on 29 June 2026, and it has been in force since 27 July as Regulation (EU) 2026/1744. Annex III covers things like recruitment tools and credit scoring. AI embedded in regulated products under Annex I moved to 2 August 2028.

The delay to high-risk rules should not be read as a delay to the whole Act. It has not. Article 50 still applies from 2 August 2026. The main change is that providers of generative tools already on the market have until 2 December 2026 to add machine-readable marking. The AI literacy duty under Article 4 has applied since February 2025. The Omnibus softened its wording but kept it on businesses.

The dates that matter

February 2025: AI literacy duty, Article 4. Already in force and applies to you now.

2 August 2026: transparency duties, Article 50, become applicable. Commission enforcement powers over general-purpose AI models activate.

2 December 2026: providers of generative tools already on the market must mark their output in a machine-readable way.

2 December 2027: standalone high-risk systems under Annex III, moved back from 2026. Recruitment tools, credit scoring and similar.

2 August 2028: AI embedded in regulated products under Annex I.

Dates checked against the regulation and Commission guidance on 14 September 2026.

€15m or 3%, whichever is lower

The ceiling for transparency breaches by a small business: €15 million or 3% of worldwide turnover, whichever is lower. For larger companies it is whichever is higher. Authorities must also weigh a small firm's economic viability.

Does the AI Act apply to an agency that only uses AI tools?

The regulation splits responsibility between providers and deployers. A provider makes an AI system available. A deployer uses one under their own responsibility without having developed it.

Almost every agency is a deployer. Nobody in a twelve-person studio in Lisbon is training a language model. Plenty are drafting campaign copy with an assistant, building a service chatbot into a client's site, and generating visuals synthetically. That is squarely the practice Article 50 addresses.

Being a deployer is not a supporting role. It carries its own duties. You cannot inherit compliance from the tool vendor.

The regulation also has extraterritorial reach. It applies if your AI systems are used in the EU, or if their outputs are consumed there. That includes providers and deployers established outside the EU.

A UK agency serving EU clients is caught. So is a Portuguese agency serving UK ones, for the EU-facing portion of the work.

Which Article 50 duties apply to an agency?

Article 50 covers four situations. They are not evenly distributed between providers and deployers, and this is where most coverage goes wrong.

Systems that interact directly with people

Provider duty, treat as yours. People must be able to tell they are dealing with a machine, unless that is obvious from context. The duty sits with the provider of the system. If you build a client's chatbot and put it live under your own responsibility, treat this as yours to solve.

Marking synthetic output in machine-readable format

Provider duty, not yours. Providers of generative systems must mark audio, image, video and text outputs as artificially generated. This sits with the model companies. It is not a duty for you to hand-tag every draft. Systems already on the market on 2 August 2026 have until 2 December 2026 to comply.

Emotion recognition and biometric categorisation

Deployer duty, rarely relevant. Deployers must inform people exposed to these systems. Most agencies never touch this. If you are running audience research that infers emotional state from faces or voices, you do.

Deepfakes and certain published text

Deployer duty, this is the one. Deployers who generate or manipulate image, audio or video that constitutes a deepfake must disclose that it is artificially generated. The same applies to AI-generated text published to inform the public on matters of public interest. For public-interest text, the exception requires human review or editorial control, plus a person or organisation holding editorial responsibility for publication. It is not a general exemption for deepfakes.

Read that last one properly, because it is the one that matters to you and the one that gets overstated.

Assess a realistic synthetic person in an ad against the deepfake rules. For text, assess its purpose and the review arrangements. An email format alone does not decide whether a duty applies.

The text exception does not exempt every reviewed asset. The Commission's Article 50 questions and answers distinguishes substantive review from a spelling or grammar check. Check the review and responsibility conditions separately.

The Commission adopted its final guidelines on Article 50 on 20 July 2026, after a consultation that closed on 3 June. A Code of Practice on Transparency of AI-generated Content came first, on 10 June, and the Commission judged it adequate on 9 July. Most coverage still quotes the May draft, so the guidelines are worth reading directly.

How to check your agency in five steps

Use these steps for an initial assessment. They are not a complete compliance assessment, and the work depends on your systems and clients.

1. Inventory what you actually use

Every AI tool in the agency, including the ones individual people signed up for without telling anyone. You cannot assess what you cannot see. This is usually the step that surprises people.

2. Sort by output, not by tool

For each tool, ask what leaves the building. Internal notes and first drafts are a different risk category from published client assets. Group accordingly.

3. Flag the uses that need an Article 50 check

Check direct AI interactions, deepfakes, published public-interest text, and any emotion recognition or biometric categorisation. Establish which role and duty applies to each use.

4. Write down where you rely on the carve-out

For public-interest text, record the substantive review or editorial control and who holds responsibility for publication. Keep the reasoning with the content.

5. Fix your client contracts

Most agency agreements were written before any of this. They do not say what tools may be used, on what data, who owns AI-assisted output, or who carries the risk. Have appropriate terms checked for your services, data use and jurisdiction. A single generic clause does not resolve every disclosure or ownership question.

Step five is the one with commercial value beyond compliance. Clients are asking. Agencies that can answer clearly look like the adults in the room.

What does the AI literacy duty ask of an agency?

It asks you to take steps that help the people using AI on your behalf understand it. Article 4 has applied since February 2025. Since the Omnibus, providers and deployers must take measures to support the AI literacy of their staff. No specific level is guaranteed for any individual, and the Commission must publish practical examples, with small businesses in mind.

There is no certification and no register. In practice your team should understand what the tools do, where they fail, and when not to use them. You should also be able to show that this is deliberate rather than accidental.

A practical starting point is a short internal document and a recurring session. These measures can support safer work. They do not, by themselves, establish that an agency meets every applicable duty.

What is the real risk for a small agency?

Legal exposure and client trust both matter. This article cannot predict enforcement priorities or the consequence of a particular breach. Make the applicable duties and agreed uses clear before client work is delivered.

What to do next

Run the five-step check. Then talk to a lawyer about your standard client agreement, once, properly. The cost and work depend on your agreement and jurisdiction.

This article explains what the regulation says. It is not legal advice, and it is not an assessment of your setup. For anything with real money or a real client relationship attached, have it checked by someone qualified in your jurisdiction.

Catarina Mestre, founder of Viravesso

Written by Catarina Mestre, Founder of Viravesso. Over a decade in creative operations across agencies and studios in the UK and Portugal, now writing practical AI guidance for small marketing and creative teams.

Common questions

Not all of it. A deployer must disclose deepfakes, and AI-generated text published to inform the public on matters of public interest. The public-interest text exception requires human review or editorial control, plus a person or organisation responsible for publication. That exception does not remove deepfake duties. Assess the content and context, not just its format.

No. Article 50 applies from 2 August 2026. The Omnibus moved the high-risk rules to December 2027 and August 2028. For Article 50, the main change gives providers of generative tools already on the market until 2 December 2026 to mark their output.

An agency using AI under its authority is generally a deployer. It may also be a provider if it develops or commissions a system under its own name. Deployers carry their own duties, and an agency cannot inherit compliance from the tool vendor.

Up to €15 million or 3% of worldwide turnover, whichever is lower, because small businesses get the lower cap. The outcome depends on the breach and applicable rules; this is a maximum, not a prediction. Client agreements and trust also matter. Get advice on your specific use.

Read next

31 August 2026 · 8 min read

AI adoption for small teams: where to start, in order

A woman working on a laptop at a wooden desk in a small studio, with a print of Lisbon on the wall behind her

31 August 2026 · 9 min read

The five AI workflows that hold up in agencies, and where each breaks

Two people reviewing a row of printed layouts and moodboards laid out on a studio table