ChatGPT wants to read the Mac
Eva Mickler
6 min read On 13 August 2026, OpenAI described Computer History for the ChatGPT Mac app in its release ...
On 2 August 2026, the transparency obligations under Article 50 of the AI Regulation come into force. The European Commission will begin enforcing transparency and GPAI obligations with national authorities via the AI Office. For CIOs, CDOs and digital leaders in large DACH organisations, this primarily translates into deployer obligations for chatbots, agents and publicly visible AI-generated content.
Key Takeaways
RelatedAI Regulation: fines of up to 3 percent of group turnover / Model harness instead of model marriage: who controls the AI chain?
According to European Commission press release IP/26/1714, the AI Office and national authorities will begin enforcing the AI Act on 2 August 2026. On the same day, the transparency obligations under Article 50 come into force. For digital leaders, this shifts operational pressure forward: many organisations already run customer-facing chatbots, internal agents, emotion recognition systems or publicly visible AI-generated text-and as deployers they fall under the new rules before the central high-risk compliance requirements kick in.
What are the transparency obligations under Article 50? Article 50 of the AI Regulation requires that people can recognise when they are interacting with AI or viewing AI-generated content. This includes clear indicators for chatbots, machine-readable labelling of synthetic media and disclosure of deepfakes. These obligations apply to both providers and deployers.
The AI Omnibus has deferred the application of high-risk rules-including those in Annex III-to 2 December 2027. For high-risk AI in regulated products, the deadline is 2 August 2028. Transparency and GPAI enforcement, however, remain on the August 2026 schedule. Misinterpreting the deferral as a buffer for the entire portfolio risks leaving gaps precisely where regulators and market surveillance will focus first.
From 2 December 2026, additional bans on AI systems generating non-consensual sexually explicit content and abusive material also take effect. The phased timeline through 2028 is therefore structured as follows: transparency and GPAI first, followed by further bans, and later high-risk requirements. Portfolio management here means mapping deadlines to specific use cases rather than waiting for a single compliance date.
Under the AI Act, deployers-according to the Commission’s FAQ on Article 50-are natural or legal persons, authorities, agencies or other bodies that use an AI system under their authority. Excluded is purely private, non-professional use. The legal entity remains the deployer even if freelancers or contractors operate the systems. For large organizations in the DACH region, this means: outsourcing to agencies, shared-service centers or IT service providers does not absolve responsibility for deployer obligations as long as the systems operate under the organization’s own authority.
The obligation to disclose AI interaction only applies when four cumulative criteria are met: it involves an AI system, there is genuine two-way interaction, the AI communicates directly, and the counterparty consists of natural persons. Background processes or machine-to-machine communication fall outside this disclosure requirement. This distinction is crucial for inventory management and role clarification, as it determines which chatbots, voicebots and agent interfaces fall within the scope of Article 50(1).
Provider and deployer roles can coexist within a supply chain. Organizations that purchase models, embed them into their own channels and operate them under their own brand often act as deployers-and must manage labeling, editorial processes and documentation, even if the model provider fulfills its own GPAI obligations. Clarifying roles with procurement, legal, marketing and customer channels must therefore be on the agenda of digital leaders before regulatory scrutiny arrives.
According to the Commission, chatbots and other interactive AI systems falling under Article 50 must clearly indicate that users are interacting with AI. Deepfakes must be labeled; AI-generated or -altered content requires machine-readable tags. Users must be informed clearly, distinguishably and accessibly from the very first interaction. The exception where the AI nature is “obvious” is narrowly interpreted-visual similarity to human interfaces does not replace disclosure.
For deepfakes, deployers must disclose the AI nature no later than first exposure. The information must be clear and recognizable without technical aids; a purely machine-readable provider tag is insufficient. In addition, labeling obligations per the Commission include images, audio and video in deepfakes, emotion recognition and biometric categorization, as well as text on matters of public interest without human editorial responsibility. For communications, HR and customer channels, this necessitates a consistent editorial and approval workflow.
According to legal analysis, Article 50 applies from 2 August 2026 to all covered systems, regardless of market entry date. Content published before this date does not need retrospective labeling. Operational focus should remain on ongoing output and interfaces used from the compliance date onward. Inventories and approval processes should therefore distinguish between live systems and archival content.
The AI Office will be empowered to enforce rules for providers of General-Purpose AI models starting from the deadline date, including systemic risks such as cyber offensives, loss of control, and manipulation. All GPAI providers must document and provide certain information to authorities and downstream providers, maintain a copyright policy, and publish a sufficiently detailed summary of training content. For companies integrating GPAI models into products and processes, supplier documentation becomes a control instrument: without reliable upstream information, deployer risks in their own portfolio increase.
The Commission has published an initial list of more than 180 organizations that have signed the Code of Practice on Transparency of AI-generated Content. Signatories receive, according to available assessments, a presumption of conformity and a more favorable enforcement stance; non-signatories face stricter scrutiny. For procurement and vendor management, it is worth verifying whether strategic providers support the code-as a signal of maturity and willingness to cooperate with regulators, not as a substitute for internal deployer controls.
Enforcement of transparency rules and prohibited practices is divided between the AI Office, national authorities, and the European Data Protection Supervisor (EDPS) for EU institutions. Large organizations with EU-wide channels and mixed operating models must therefore prepare for parallel points of contact and reporting formats. Consistent internal documentation reduces friction when multiple authorities examine the same issue from different perspectives.
According to the Commission, companies violating transparency obligations face fines of up to €15 million or 3% of global annual turnover-whichever is higher. For EU institutions, the framework is capped at €750,000; SMEs and small mid-caps benefit from proportionality. The available sources do not specify concrete fines or inspections immediately after 2 August 2026. However, the strategic takeaway for the board is clear: transparency is now enforceable and sanctionable, while high-risk obligations are staggered over time.
Traceability means inventoried systems, documented roles (provider versus deployer, including service providers), approved labeling components, and verifiable editorial workflows for deepfakes and public AI-generated text. Organizations operating customer interfaces, HR tools with emotional analytics, or content-rich generative systems require clear ownership across Digital, Legal, Compliance, Marketing, and business units. Regulators will ask who holds authority over the system-and that authority rests with the organization that uses it in the course of business under its control.
For CIOs and CDOs in large DACH organizations, the August 2026 deadline is more than a legal matter. It demands portfolio transparency, supplier governance, and disciplined communication before the high-risk wave arrives in 2027 and 2028. Those who finalize inventories, role definitions, and labeling processes now build the foundation on which later high-risk compliance can be established-with less duplication of effort and fewer conflicts between product velocity and regulatory oversight.
From 2 August 2026, the transparency obligations under Article 50 of Regulation (EU) 2024/1689 take effect. At the same time, the European Commission’s AI Office and national authorities will begin enforcing the AI Act, including rules for providers of general-purpose AI models.
The AI Omnibus has postponed the application of high-risk rules to 2 December 2027. For high-risk AI in regulated products, the deadline is 2 August 2028. Transparency and GPAI enforcement remain unaffected and follow the August 2026 timeline.
Deployers are natural or legal persons, public authorities, agencies or other bodies that use AI systems under their authority in a professional capacity. The organization remains the deployer even if freelancers or contractors operate the systems. Many large enterprises in the DACH region are therefore directly responsible when deploying customer-facing chatbots or high-profile AI-generated content.
Companies face fines of up to €15 million or 3 percent of global annual turnover-whichever is higher. For EU institutions, the cap is €750,000. SMEs and small mid-caps benefit from proportional penalties.
No. Deployers must disclose deepfakes clearly and without technical aids at the first point of exposure. A provider-side machine-readable tag alone does not satisfy the deployer’s disclosure obligation.
Read more on Digital Chiefs
Digital ChiefsAmazon and Alphabet: Negative Cash Flow, Long-Term CommitmentsDigital ChiefsLocal AI: Governance Before Hardware PurchaseDigital ChiefsAI Regulation: Up to 3 Percent of Corporate RevenueMore from the MBF Media Network
cloudmagazinClaude Code now also integrates Alibaba’s Qwen mybusinessfutureCheap AI from China: What procurement must check securitytodayffmpeg is everywhere: PixelSmash forces an auditImage source: AI-generated (August 2026)