6 min read
July 2026
What the EU AI Act's transparency rules actually ask of a small agency
Most coverage tells agencies to label everything. That is not what Article 50 says.
The transparency obligations in Article 50 of the EU AI Act apply from 2 August 2026. If your agency uses AI to make work for clients, you are in scope. Not as a developer. As a deployer, which is a different role with a much shorter list of duties.
Most of what has been written about this is wrong in the same direction. It tells agencies to label everything. That is not what the regulation says.
The advice creates work nobody needs to do, and it makes the genuine disclosure cases harder to spot. Here is the accurate version.
What is actually happening on 2 August
Two things. Article 50's transparency duties become applicable, covering chatbot disclosure, marking of synthetic content, and deepfake labelling. And the European Commission's enforcement powers over general-purpose AI models activate on the same date.
What is not happening is the high-risk regime. Those obligations were originally due on 2 August 2026.
The Digital Omnibus on AI moved standalone Annex III systems to 2 December 2027. The Council gave it final approval on 29 June 2026. Annex III covers things like recruitment tools and credit scoring. AI embedded in regulated products under Annex I moved to 2 August 2028.
That delay is why several agencies we have spoken to think the whole thing has been pushed back. It has not. Article 50 was untouched. The AI literacy duty under Article 4 has been in force since February 2025 and was also untouched.
The dates that matter
February 2025
AI literacy duty, Article 4. Already in force and applies to you now.
2 August 2026
Transparency duties, Article 50, become applicable. Commission enforcement powers over general-purpose AI models activate.
2 December 2027
Standalone high-risk systems under Annex III, moved back from 2026. Recruitment tools, credit scoring and similar.
2 August 2028
AI embedded in regulated products under Annex I.
€15m or 3%
The ceiling for transparency breaches: €15 million or 3% of worldwide turnover, whichever is higher.
Why you are in scope when you built nothing
The regulation splits responsibility between providers and deployers. A provider makes an AI system available. A deployer uses one under their own responsibility without having developed it.
Almost every agency is a deployer. Nobody in a twelve-person studio in Lisbon is training a language model. Plenty are drafting campaign copy with an assistant, building a service chatbot into a client's site, and generating visuals synthetically. That is squarely the practice Article 50 addresses.
Being a deployer is not a supporting role. It carries its own duties. You cannot inherit compliance from the tool vendor.
The regulation also has extraterritorial reach. It applies if your AI systems are used in the EU, or if their outputs are consumed there. That includes providers and deployers established outside the EU.
A UK agency serving EU clients is caught. So is a Portuguese agency serving UK ones, for the EU-facing portion of the work.
The four duties, and which ones are yours
Article 50 covers four situations. They are not evenly distributed between providers and deployers, and this is where most coverage goes wrong.
Provider duty · treat as yours
Systems that interact directly with people
People must be able to tell they are dealing with a machine, unless that is obvious from context. The duty sits with the provider of the system. If you build a client's chatbot and put it live under your own responsibility, treat this as yours to solve.
Provider duty · not yours
Marking synthetic output in machine-readable format
Providers of generative systems must mark audio, image, video and text outputs as artificially generated. This sits with the model companies. It is not a duty for you to hand-tag every draft. Systems already on the market on 2 August 2026 have until 2 December 2026 to comply.
Deployer duty · rarely relevant
Emotion recognition and biometric categorisation
Deployers must inform people exposed to these systems. Most agencies never touch this. If you are running audience research that infers emotional state from faces or voices, you do.
Deployer duty · this is the one
Deepfakes and certain published text
Deployers who generate or manipulate image, audio or video that constitutes a deepfake must disclose that it is artificially generated. The same applies to AI-generated text published to inform the public on matters of public interest. There is a carve-out where a human holds editorial responsibility for the content.
Read that last one properly, because it is the one that matters to you and the one that gets overstated.
A synthetic person in a client's ad who looks real is very likely caught. A campaign email is not. Drafted with an assistant, edited by your copywriter, signed off by your account director: that is reviewed work.
The public-interest limb is aimed at published informational content. The editorial responsibility carve-out exists precisely so that normal reviewed work does not need a disclaimer on every asset.
The Commission adopted its final guidelines on Article 50 on 20 July 2026, after a consultation that closed on 3 June. They arrive alongside a Code of Practice on Transparency of AI-generated Content. Most coverage still quotes the May draft, so the guidelines are worth reading directly.
The five-step check
Work through this once. It takes an afternoon and it is the whole job for most small agencies.
1
Inventory what you actually use
Every AI tool in the agency, including the ones individual people signed up for without telling anyone. You cannot assess what you cannot see. This is usually the step that surprises people.
2
Sort by output, not by tool
For each tool, ask what leaves the building. Internal notes and first drafts are a different risk category from published client assets. Group accordingly.
3
Flag the two categories that trigger duties
Anything that talks to a person as if it were a person. Anything synthetic that depicts a real-seeming person, place or event. Those are your live items. Most other output is not.
4
Write down where you rely on the carve-out
If you are treating reviewed editorial work as outside the disclosure duty, record who reviews it and what sign-off looks like. Keeping a record of the reasoning is what turns a judgement call into a defensible position.
5
Fix your client contracts
Most agency agreements were written before any of this. They do not say what tools may be used, on what data, who owns AI-assisted output, or who carries the risk. A single clause covering tool use, disclosure and IP turns an awkward client question into a straight answer.
Step five is the one with commercial value beyond compliance. Clients are asking. Agencies that can answer clearly look like the adults in the room.
The AI literacy duty nobody mentions
Article 4 has been in force since February 2025. It requires providers and deployers to ensure a sufficient level of AI literacy among the staff who use these systems.
There is no certification and no register. In practice your team should understand what the tools do, where they fail, and when not to use them. You should also be able to show that this is deliberate rather than accidental.
For most small agencies, that is a short internal document and a recurring session. It is also, not coincidentally, the thing that stops bad AI output reaching clients in the first place.
What we would actually worry about
Not the fine. Enforcement against a fifteen-person agency for an unlabelled campaign asset is not where regulators will start. The real exposure is a client discovering something they did not agree to. That conversation costs a retainer, and retainers are worth more than the compliance work. The agencies that come through this well are the ones who already told their clients what they use and why.
What to do next
Run the five-step check. Then talk to a lawyer about your standard client agreement, once, properly. That is a few hundred euros that removes a recurring risk.
This article explains what the regulation says. It is not legal advice, and it is not an assessment of your setup. For anything with real money or a real client relationship attached, have it checked by someone qualified in your jurisdiction.
The check also exists as a working document inside ViraOps, with the tool inventory and contract clause sections already laid out.
Sources
- Regulation (EU) 2024/1689, Article 50 and Article 4
- European Commission, draft guidelines on Article 50 transparency obligations, 8 May 2026
- European Parliament amendments to the AI Act (Digital Omnibus on AI), June 2026
- Sidley Austin, Data Matters, EU AI Act transparency obligations, June 2026
- Bratby Law, AI Act transparency obligations, June 2026