EU AI Act Article 50 Is in Force: What US SMBs That Buy or Build Software Must Do Now

Artificial Intelligence SaaS Development
Abstract navy illustration of a compliance checklist, a shield with a check mark, and an AI-disclosure card

Table of Contents

If you are a US founder who “only sells software from Texas” and assumed the EU AI Act for small business was a Brussels problem, the date that matters is already behind you. On 2 August 2026, the European Commission’s AI Office and national authorities began enforcing Regulation (EU) 2024/1689, and the Article 50 transparency rules started to apply the same day (Commission press release, 31 July 2026).

That does not mean every hiring model or credit-score feature is suddenly illegal. The 2026 Digital / AI Omnibus pushed most high-risk product duties out to late 2027 and 2028. It does mean that if EU users chat with your bot, see your synthetic media, or consume your AI-written public-interest copy, you now have specific disclosure and marking jobs.

This guide is for product and ops leaders who buy or build software, not for marketing teams writing another deepfake policy. Softix’s earlier piece on deepfake safeguards for agencies covers brand risk. This one covers what changed when Article 50 became enforceable—and what your ticket queue should look like this month. It is not legal advice.

What started on 2 August 2026 (and what did not)

Use the Commission’s own timeline, last restated on the AI Act policy page (updated 3 August 2026):

Obligation When it applies Why SMBs mix this up
Prohibited practices + AI literacy 2 February 2025 Already live; not new this month
General-purpose AI (GPAI) model duties 2 August 2025 Hits model providers (OpenAI-scale), not every chatbot reseller
Article 50 transparency (chatbot notice, synthetic marking, deepfake labels, some public-interest text) 2 August 2026 This is the late-summer change
Machine-readable marking for generative systems already on the market before 2 Aug 2026 Grace until 2 December 2026 Only Article 50(2); not a free pass on chatbot disclosure
High-risk stand-alone uses (Annex III: employment, education, credit access, etc.) 2 December 2027 Delayed by the AI Omnibus
High-risk AI inside already-regulated products (Annex I) 2 August 2028 Same Omnibus delay

The Omnibus political agreement (7 May 2026; in force 27 July 2026) is why some summer explainers still say “high-risk starts 2 August 2026.” The Commission’s 3 August 2026 page is the correction. Do not staff a full Annex III conformity project this week unless counsel says your use is otherwise in scope. Do staff disclosure and labeling.

The legal text is Regulation (EU) 2024/1689 (adopted 13 June 2024; Official Journal 12 July 2024). Article 50 is the transparency chapter. The Commission adopted implementation guidelines on 20 July 2026; the Article 50 FAQ was last updated 24 July 2026. Prefer those two over any vendor “AI Act in 5 slides” deck.

You can be in scope from the United States

The FAQ is explicit: a provider is the person or company that develops an AI system (or has it developed) and places it on the EU market or puts it into service under their own name or trademark—whether they sit in the Union or not. Providers outside the EU are also covered if the output of their AI system is used in the Union.

A deployer is anyone using an AI system under their own authority in a professional capacity. Your agency or contractor running the model on your behalf does not make them the deployer; you remain the deployer if it is your authority and control.

Practical US SMB examples:

  • You sell a SaaS helpdesk with an AI agent to a German retailer → you are likely a provider.
  • You white-label a US vendor’s chatbot on your site for EU shoppers, under your brand → you may be a provider (own name/trademark) and a deployer.
  • You use a third-party writer tool to draft a blog, then a human editor rewrites it → usually a deployer question, and the public-interest text rule may not fire if real editorial control exists (see below).
  • A staff member uses ChatGPT on a personal account for a one-off joke image → personal, non-professional use is carved out.

If EU users can reach the feature, “we have no EU entity” is not a complete answer. Confirm with counsel; do not treat this paragraph as a determination.

The four Article 50 jobs (plain English)

The Commission and a 3 August 2026 Cooley alert describe the same four buckets. Cooley is secondary commentary; the duties live in Article 50 and the FAQ.

1. Tell people they are talking to AI (providers)

If the system is designed for a genuine two-way exchange with a natural person—chatbots, AI agents, avatars—people must be informed they are interacting with AI from the first interaction, clearly, accessibly, and in a distinguishable way—unless it is already obvious.

The FAQ lists four cumulative tests (AI system; two-way exchange; direct interaction; natural persons). Background scoring, machine-to-machine APIs, and “AI that only drafts a reply for a human to send” sit outside this notice duty. The “obvious” exception is narrow. A generic avatar that could pass as a night-shift agent is not obvious. A clearly named “Virtual assistant (AI)” banner usually is the point.

Product task: first-message disclosure in the UI, and the same signal in voice/IVR. Do not bury it in the privacy policy.

2. Machine-readable marks on synthetic output (providers)

Article 50(2) requires providers of systems that generate or manipulate audio, image, video, or text to embed effective, reliable, robust, interoperable machine-readable marks so the output can be detected as AI-generated or manipulated, and to support detection.

FAQ carve-outs include short sequences of numbers/symbols, source code, purely machine-to-machine outputs never shown to humans, closed-loop production (for example film pipelines) until a final public output, and standard editing (assistive grammar/crop). A narrow B2B/industrial exemption exists when guideline conditions are met.

Dates: new in-scope systems from 2 August 2026 must mark immediately. Systems already on the market before that date have until 2 December 2026 for 50(2) marking/detection only. Content published before 2 August 2026 does not need retroactive labels; the Commission still encourages labeling where possible.

Product task: pick a marking approach you can defend (the voluntary Code of Practice on transparency of AI-generated content is the Commission-endorsed path; the 31 July press release says more than 180 organisations had signed). If you do not sign, you must show “alternative adequate means” and should expect more information requests.

3. Emotion recognition / biometric categorisation (deployers)

If you deploy emotion recognition or biometric categorisation, you must inform people exposed to it—real-time or after the fact. Most SMB products should not be in this bucket. If a vendor slipped “sentiment from webcam” into your web app, treat it as a stop-ship until counsel and a DPIA say otherwise. Some of these uses are restricted or prohibited in other articles; transparency is not permission.

4. Deepfakes and public-interest text (deployers)

Deepfakes (Article 3(60)): AI-generated or manipulated image, audio, or video that resembles existing persons/objects/places/events and would falsely appear authentic. Deployers must disclose in a way a person can see or hear without special tools—a hidden watermark is not enough. Artistic/satirical works get a lighter, “appropriate” disclosure that does not spoil the work.

AI text on public-interest matters: if you publish AI-generated or manipulated text to inform the public on politics, public services, justice, health, safety, and similar debate topics, you must label it—unless it had human review or editorial control by someone with substance-level judgment and editorial responsibility. Spell-check is not review. “A human glanced at it” is not control.

If you are a software vendor, your job is often to give deployers the toggle and the label, not to decide their newsroom policy.

What this is not

  • Not a US federal AI Act. The United States still does not have an EU-style horizontal AI law. Existing US rules (for example FTC Act Section 5 on deceptive practices, state biometric laws, sector rules) already punish undisclosed deception. Do not tell the board “the US copied Article 50.”
  • Not automatic high-risk classification for a support bot or a copy assistant.
  • Not a requirement to open-source your model or publish training data (those are GPAI-provider topics under other articles).
  • Not a reason to rip out AI. The Commission’s stated goal is trustworthy use, including for SMEs; the FAQ notes proportionality for SMEs and small mid-caps when fines are set. Headline maxima for these transparency breaches can reach €15 million or 3% of worldwide turnover (FAQ). That is a ceiling, not your invoice.

A 30-day checklist for a US product team

  1. Inventory. List every AI feature EU users can reach: in-app chat, email drafter, image tools, voice agents, marketing generators. Tag each as provider, deployer, or both. Include contractor-run systems under your authority.
  2. Ship the chatbot notice. First-turn, accessible, not “by using this site you agree.” Screenshot it for the compliance folder.
  3. Decide the marking path. Sign the Code of Practice or document an alternative. Calendar 2 December 2026 if the generative system was already in market on 1 August 2026.
  4. Give deployers labels they can actually show. Visible/audible deepfake and public-interest text labels, not only C2PA in a file header.
  5. Write the editorial-control rule. If your app publishes text, require a named human action that can approve, edit, or reject substance—and log it. That log is how you defend the exemption.
  6. Vendor packet. Ask each AI vendor: Article 50 markings, detection API, EU representative, and whether they consider themselves the provider. Put answers next to your build-vs-buy notes.
  7. Do not start a fake Annex III program. If you do use AI for hiring, credit, education access, or essential-services eligibility, start a separate track with counsel for the 2027 date. Do not conflate it with chatbot copy.

Limits, uncertainty, and when to update this page

National market surveillance authorities do the bulk of Article 50 enforcement; the AI Office’s role is narrower (GPAI-tied systems, certain very large platforms). Early enforcement will be uneven. The guidelines are new (20 July 2026). Definitions such as “obvious,” “standard editing,” and “public interest” will move as authorities publish examples.

Update this article when: the Commission revises the Article 50 guidelines; your target Member State names a lead authority with sector guidance; or a high-risk date changes again.

If you are building a custom AI system, design disclosure and marking as product requirements now. Retrofitting a silent agent in November is more expensive than a first-message banner in September.

What Softix will and will not do

Softix can implement the engineering side—notice UX, content credentials, audit logs, role-based “human approved” gates—in a SaaS or web application. We do not replace your EU counsel, and we will not invent a “certified AI Act badge.”

If you want a build plan after legal scoping, contact Softix with: (1) where EU users sit, (2) whether the AI is customer-facing, (3) whether you ship under your brand or a vendor’s.

Top-Rated Software Development Company

ready to get started?

get consistent results, Collaborate in real time