What the AI Office published on 10 June.
While the Digital Omnibus debate held everyone's attention on the high-risk stack, the AI Office published the Code of Practice on Transparency of AI-Generated Content on 10 June 2026. Six independent experts, appointed by the AI Office, drafted it through a multi-stakeholder process that ran from September 2025 with over 187 participants and three rounds of consultation. The code is voluntary. The obligations it maps are not.
The structure is two sections, and the section numbers matter because each maps to a different addressee and a different paragraph of Article 50. Section 1 addresses providers of generative AI systems under Article 50(2): the marking and detection of AI-generated or manipulated audio, image, video and text, including machine-readable solutions. Section 2 addresses deployers under Article 50(4): the labelling of deepfakes and of AI-generated text published to inform the public on matters of public interest. Annex I supplies an optional EU icon in three variants for the labelling duty.
The statutory hook is Article 50(7), and this is the one paragraph of Article 50 the Omnibus did rewrite. Article 1(20) of Regulation (EU) 2026/1744 replaced it. As replaced, it is the Commission — no longer the AI Office — that "shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection, marking and labelling of artificially generated or manipulated content". The word "marking" was added to the pre-existing "detection and labelling". And the approval route changed: instead of approving a code by implementing act, the Commission, "taking utmost account of the opinion of the Board, shall assess whether adherence to those codes of practice is adequate to ensure compliance with the obligations laid down in paragraphs 2 and 4 of this Article, in accordance with the procedure laid down in Article 56(6)". Only if it deems the code inadequate may it adopt an implementing act specifying common rules, under the Article 98(2) examination procedure. That assessment has been made. The Commission opinion on the assessment of the Code of Practice on Transparency of AI-generated Content, published 9 July 2026 on a conclusion of 8 July 2026, records that the code "adequately covers the obligations provided for in Articles 50(2), (4) and (5) AI Act and facilitates their effective implementation". The same opinion states that "adherence to the code does not constitute conclusive evidence of compliance with these obligations", so signature is a route to demonstrating compliance and not a safe harbour. The code does not replace the Commission's guidelines on Article 50, and those are issued as well: the Guidelines on transparency obligations for providers and deployers of certain AI systems are published on the Commission's transparency page as at 2026-08-06. Neither instrument moves the application date.
One duty the code does not map is worth stating before anything else, because it is the paragraph most operators of chat and voice agents overlook and it starts on the same date. Article 50(1) is a design obligation on providers, and it is not about content at all:
Note what the exception is measured against. It is not the provider's own view that the AI nature of the system is obvious. The test is the perspective of a natural person who is "reasonably well-informed, observant and circumspect", taking the circumstances and the context of use into account — an objective standard, applied per deployment context, that a provider asserting the exception has to be able to defend. Article 50(1) is a provider duty and Article 111(4) does not touch it: it applies from 2 August 2026.
Section 1 · the provider marking duty under Article 50(2).
The provider duty is machine-facing. The output of a generative system — audio, image, video or text — must carry a marking that software can read, so that the content is detectable as artificially generated downstream. General-purpose AI systems are named in scope. Section 1 of the code turns this into commitments on marking and detection that account for the type of content, the state of the art and relevant technical standards, with compliance proportionate to what is technically feasible.
The carve-outs sit in the same paragraph. The duty does not apply to the extent the system performs an assistive function for standard editing, does not substantially alter the input the deployer provided or its meaning, or where the use is authorised by law for the detection and prosecution of criminal offences. The marking question for a provider is binary and auditable: can a third party's tooling detect that this output was machine-generated?
Section 2 · the deployer disclosure duty under Article 50(4).
Article 50(4) carries two deployer duties. The first subparagraph covers deepfakes: a deployer of a system that generates or manipulates image, audio or video constituting a deep fake must disclose that the content was artificially generated or manipulated. The second covers text: where the system's text is published with the purpose of informing the public on matters of public interest, the deployer must disclose its origin. This is the paragraph that reaches newsrooms, public bodies, financial communications and any organisation whose published text shapes public understanding.
Section 2 of the code gives the practical layer: guidance on the design, placement and presentation of labels, disclaimers and icons, with specific regimes for artistic, creative, satirical and fictional work — where the statute itself limits disclosure to a manner that does not hamper the display or enjoyment of the work. For deployers who want a ready-made label, the Annex I icon exists precisely so the duty can be met consistently across the EU.
The exemption is a process claim.
The interesting clause in Article 50(4) is the second limb of the exemption. The text duty falls away where the content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication. Both limbs must hold. A newsroom that routes AI-drafted copy through editorial review and publishes under a named editor does not have to label the text.
But read what the exemption actually is: a claim about a process. When the question arrives — from a market surveillance authority, or from opposing counsel — "a human reviewed it" has to exist as something you can show: who reviewed the content, and which natural or legal person held editorial responsibility at publication. An organisation that relies on the exemption without being able to evidence the review has not exited the obligation; it has converted a labelling duty into an evidentiary one.
For AI agents that draft or assemble published text at scale, the operational question is where that record lives. A per-publication record of the review step — who held it, when, against which version of the text — is the artifact that makes the exemption stand up. The shape of that record is the same shape regulators ask of agent records generally: see what records an AI agent must keep to satisfy a regulator.
The dates that did not move.
The Digital Omnibus moved one set of dates and left another alone, and conflating the two is the most common error in current coverage. The deferral covers the Annex III high-risk stack — Article 12 record-keeping and Article 26 deployer duties among them — to 2 December 2027 (Regulation (EU) 2026/1744, OJ L 2026/1744, 24 July 2026). The full Omnibus picture is in the Omnibus, read against the record.
Article 50 sits in Chapter IV. The third paragraph of Article 113 lists the carve-outs from the general 2 August 2026 application date — Chapters I and II at 2 February 2025; Chapter III Section 4, Chapter V, Chapter VII, Chapter XII and Article 78 at 2 August 2025; Chapter III Sections 1 to 3 at 2 December 2027 for Annex III standalone high-risk systems or 2 August 2028 for Annex I embedded high-risk systems, the latter subject to Article 2(13); Articles 102 to 110 at 27 July 2026. Chapter IV is in none of them. Article 50 applies from 2 August 2026, undeferred, in all seven paragraphs.
One softening exists and it is narrower than most coverage reports. The Omnibus does not touch the Article 50 duties that bind providers and deployers — paragraphs 1 to 6 are unamended, and the only paragraph it replaced is paragraph 7, a Commission function. What it adds for operators is a paragraph to the transitional article. New Article 111(4) of Regulation (EU) 2024/1689 reads in full:
Three limiters sit on the face of that text. It reaches providers only — a deployer gets nothing from it. It reaches systems that generate synthetic audio, image, video or text content only. And it reaches Article 50(2) only, the machine-readable marking duty. A fourth condition gates entry: the system must already have been placed on the market before 2 August 2026.
So if you are a deployer, read the date carefully and do not plan around December. Your Article 50(4) duty to disclose a deepfake, and your Article 50(3) duty to inform people exposed to emotion-recognition or biometric-categorisation systems, are live on 2 August 2026. Article 50(1) — designing a system that interacts with people so that they are informed they are interacting with an AI system — is live on 2 August 2026. Recital 38 of the Omnibus describes the relief it grants as "a transitional period of four months"; four months from 2 August 2026 is 2 December 2026, and it belongs to one duty held by one class of operator. Article 96(1)(d) empowers the Commission to issue guidelines on the practical implementation of the Article 50 transparency obligations, and those guidelines are published: the Guidelines on transparency obligations for providers and deployers of certain AI systems, on the Commission's transparency page as at 2026-08-06.
Penalties, and what signing buys.
Non-compliance with Article 50 sits under Article 99(4), which names the transparency obligations for providers and deployers directly: administrative fines of up to EUR 15 million or, for an undertaking, up to 3 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. The same ceiling that applies to the record-keeping and deployer-duty breaches in the high-risk stack applies here — the difference is that this clock runs in 2026.
Adherence to the code is voluntary, and the code itself distinguishes the measures required for compliance with Article 50(2) and 50(4) from measures that are purely voluntary. What signature buys, per the AI Office, is a recognised route to demonstrate compliance: future enforcement will focus on monitoring adherence to the code, with predictability and legal certainty across the EU as the stated return. Providers and deployers sign by sending the Signatory Form to the AI Office, under the hand of someone with authority to bind the organisation.
Questions a compliance officer asks first.
Read the source directly.
- Code of Practice on Transparency of AI-Generated Content · European Commission FAQ (10 June 2026)
- Regulation (EU) 2024/1689 · EUR-Lex CELEX:32024R1689
- Regulation (EU) 2024/1689 · permanent ELI identifier · Articles 50, 99, 111 and 113 as enacted
- Regulation (EU) 2026/1744 · Digital Omnibus on AI, as published · OJ L, 24.7.2026 · EUR-Lex — Article 1(39)(b) inserts Article 111(4); Article 1(40) replaces the third paragraph of Article 113; recital 38 states the four-month transitional; Article 4 sets entry into force
- The Digital Omnibus, read against the record · what was deferred and what was not
- Article 12, line by line · the record obligation in the deferred stack
- Article 26 deployer obligations · the deferred deployer duties
- The records an AI agent must keep · the artifact shape the exemption demands
Authored by Warrant Compliance, the regulatory-analysis function at Warrant. [email protected]. Editorial commentary on regulatory text. Not legal advice. The verbatim quotations of Article 50(1), 50(2) and 50(4) reflect the official English-language text of Regulation (EU) 2024/1689 as published in the Official Journal of the European Union on 12 July 2024, checked against the OJ text on 28 July 2026. The quotation of Article 111(4) is the text inserted by Article 1(39)(b) of Regulation (EU) 2026/1744, published in the Official Journal, L series, on 24 July 2026 and in force from 27 July 2026 under its Article 4; the four-month characterisation is that of recital 38 of the same regulation. Neither instrument amends Article 50(1) to (6); Article 1(20) of Regulation (EU) 2026/1744 replaced Article 50(7), which is a Commission function and imposes no operator duty. Statements about the Code of Practice on Transparency of AI-Generated Content reflect the European Commission's FAQ, read on 6 August 2026; the code itself was published 10 June 2026. The Annex III deferral to 2 December 2027 was adopted by the European Parliament on 16 June 2026 and the Council on 29 June 2026.