Local AI: Governance Before Hardware Purchase
Benedikt Langer
10 min readFour developments over two weeks show that locally operated AI goes far beyond the tech stack. ...
Article 50 of the AI Act has bound providers and deployers to concrete transparency obligations since August 2, 2026. Fines of up to EUR 15,000,000 or 3 percent of global annual turnover from the prior year sit in the penalty framework of Article 99 paragraph 4. Digital officers are now settling roles, inventory and substantial review – labeling alone doesn’t carry the load.
Key Takeaways
RelatedAI Act Omnibus delays high-risk rules: governance stays / EU AI Act 2026: what companies need to implement now
What is Article 50 of the AI Act? Article 50 of Regulation (EU) 2024/1689 bundles the transparency obligations for AI: disclosure of AI interaction, information on emotion recognition and biometric categorization, labeling of deepfakes and of AI-generated texts on matters of public interest. It has applied since August 2, 2026, and covers providers and deployers in separate roles.
The EU Commission confirms the application date of August 2, 2026. For the deployer obligations under paragraphs 1, 3 and 4, there is no grace period. Only the machine-readable provider marking under paragraph 2 has a transition period until December 2, 2026, and only for systems that were on the market before the deadline.
The roles split sharply. Providers carry the disclosure obligation for chatbots and interaction systems under paragraph 1. Deployers face three burdens. Paragraph 3 requires information on emotion recognition and biometric categorization. Paragraph 4 subparagraph 1 requires labeling of deepfakes. Paragraph 4 subparagraph 2 requires labeling of AI-generated texts on matters of public interest without human review. Anyone who puts an AI system into circulation under their own name or trademark can become a provider themselves under Article 25. This own-branding trap shifts liability and burden of proof onto the organization that presents the system externally.
The management question is role clarity per system. CIOs and CDOs decide together with legal and business units who counts as provider and who as deployer. An inventory without role labels stays dead weight. The law firm Gleiss Lutz puts the starting point the same way: map AI systems and clarify the role as provider or deployer for each one.
Article 50(4), second subparagraph, shields organizations that publish AI-generated content on matters of public interest, but only under strict conditions. The obligation lapses when two requirements come together. First, the AI-generated content has undergone a process of human review or editorial control. Second, a natural or legal person bears editorial responsibility for publishing the content. The wording demands both a process and an accountable party.
The Commission’s FAQ from July 24, 2026 sets the substance standard. Human review means deliberate scrutiny of the content’s substance by one or more natural persons with relevant knowledge and professional judgment. Superficial, purely formal, or procedural checks do not count as human review or editorial control. Spellchecking and grammar cleanup fall short. Anyone relying on the exception documents named responsible parties, the scope of review, and the approval status. Evidence preparation beats box-ticking.
Editorial teams and corporate publishing feel the pressure first. Marketing teams signing off on AI-generated statement copy about regulatory or political topics need the same standard as journalists. A nod of approval inside a workflow app does not meet the Commission’s bar.
Germany sharpened its market surveillance just days before the deadline. The German AI Market Surveillance and Innovation Promotion Act was signed on July 22, 2026, promulgated on July 28, 2026, and took effect on July 29, 2026. Section 2(1) names the Bundesnetzagentur as the central market surveillance authority. Section 2(8) leaves jurisdiction over media services for journalistic or advertising purposes with the authorities responsible under state law, the Landesmedienanstalten.
The BNetzA press release from July 29, 2026 puts the role more succinctly: the Bundesnetzagentur becomes the market surveillance authority, point of contact, and complaints office. The Coordination and Competence Center for the AI Act (KoKIVO) operates within the BNetzA. Corporate publishing and advertising often sit right at this intersection. Digital leads should clarify early whether a given case belongs with the BNetzA or the relevant Landesmedienanstalt. Dual jurisdiction costs time and weakens the defense line.
The Commission’s Article 50 guidelines (C(2026) 5054 final, content approved July 20, 2026) are legally non-binding. In practice, they serve as an enforcement reference. The Code of Practice on Transparency of AI-generated Content has been final since June 10, 2026. By late July, the EU Commission counted roughly 190 signatories. Signatories can point to these measures as compliance evidence, cutting administrative burden while raising legal certainty.
Article 99(4) sets the ceiling: up to EUR 15,000,000 or 3 percent of worldwide annual turnover from the prior year, whichever is higher. For SMEs, the lower of the two amounts applies under Article 99(6). The EUR 35 million and 7 percent figures apply only to the prohibitions under Article 5. Conflating these numbers with Article 50 distorts the risk calculation and needlessly rattles the board.
As of August 3, 2026, no fine proceedings or enforcement actions by the BNetzA are publicly documented. An initial enforcement phase favoring guidance over sanctions is plausible, but it is not guaranteed. Compliance teams should therefore plan for full obligation from the deadline onward and exclude leniency from their planning assumptions.
August 2, 2026 was not the high-risk deadline. The Digital Omnibus (Regulation (EU) 2026/1744) pushed high-risk obligations to December 2027 and August 2028 respectively. What’s live now is Article 50, the European AI Office, and national market surveillance. Governance energy belongs where obligations already bite.
Five steps matter in the first 90 days. First: an AI inventory with role clarification per system – provider or deployer, including a check on the own-branding trap under Article 25. Second: a labeling policy for deepfakes with disclosure at first exposure and for AI-generated text on matters of public interest. Third: a review process for the editorial exception with named owners, substantive review and a documented approval record. Fourth: a decision on whether signing the Code of Practice simplifies the compliance burden. Fifth: a responsibility map distinguishing the BNetzA contact point from the state media authorities for corporate publishing and advertising.
Legal and compliance build the policy. Business units supply the use cases. IT and data teams document systems and data flows. Leadership names who carries editorial responsibility wherever the exception applies. Without that assignment, every label stays fragile.
The deadline is now behind organizations. The work starts with clarity on roles and review, and it only ends once the inventory and review process hold up in daily operations.
Article 50 of the AI Act (EU) 2024/1689 requires transparency for certain AI systems and content. Providers must disclose AI interaction. Deployers must inform users about emotion recognition and biometric categorization, and must label deepfakes as well as certain AI-generated text on matters of public interest. The obligations have applied since August 2, 2026.
The exception applies when AI-generated content undergoes human review or editorial control and a natural or legal person carries editorial responsibility. The Commission requires substantive review involving professional judgment. Formal checks such as spell-checking are not enough.
Article 99(4) provides for fines of up to EUR 15,000,000 or 3 percent of global annual turnover for the prior financial year, whichever is higher. For SMEs, the lower of the two amounts applies. The higher rates of EUR 35 million and 7 percent apply only to violations of the prohibitions under Article 5.
Read more on Digital Chiefs
Digital ChiefsYou are paying for the R&D of the next competitorDigital ChiefsModel Harness Instead of Model Marriage: Who Controls the AI Chain?Digital ChiefsWashington decides which AI is allowed to run hereMore from the MBF Media Network
cloudmagazinGoogle Hands Sovereign Cloud Over to Thales mybusinessfutureCheap AI from China: What Procurement Must Check securitytodayThe AI Act Is Really a Security LawImage source: AI-generated (August 2026)