Article 50 Goes Live in Five Days — and It Stopped Being a Legal Problem
On 2 August, the EU AI Act's transparency obligations become enforceable. Six concrete scenarios from a bank's floor — chatbot, RM emails, market commentary, campaigns, call centre, agents — show why nobody owns this yet.
The next phase of AI regulation in banking may not be decided in legal departments. It may be decided in deployment pipelines.
This week's signal was clear: AI transparency is moving from policy-deck material to a production requirement — with a date attached. Article 50 of the EU AI Act applies from 2 August 2026. Five days from now. And on 20 July, less than two weeks before the deadline, the European Commission adopted its final Guidelines on how those obligations actually work: 51 pages, published while most of the industry was still treating this as a Q4 topic.
The fines are real — up to €15 million or 3% of worldwide annual turnover, whichever is higher. But the fines are not the interesting part. The interesting part is what the obligations require in practice, and who in your organisation can actually deliver them.
What changes on 2 August
Strip away the legal language and Article 50 asks four concrete things:
🤖 Tell people when they're talking to a machine (Art. 50(1)). Any AI system interacting with a natural person must disclose it — unless it's obvious from context.
🏷️ Mark synthetic content at the source (Art. 50(2)). AI-generated audio, image, video and text must carry machine-readable marking. A provider obligation — but if you've fine-tuned or white-labelled a system under your own brand, you may be the provider.
📰 Label AI-generated text on matters of public interest (Art. 50(4)). With a twist in the final Guidelines: for text, the cut-off is the publication date, not the generation date.
🕵️ Disclose deepfakes and inform people about emotion recognition (Art. 50(4) and 50(3)). The Commission reads "deepfake" broadly — anything closely resembling real people, places or events that could mislead.
⚙️ And one line that should stop every agent builder mid-sprint: agentic AI systems are in scope where their actions produce outputs directly perceived by users.
Abstract? Let's walk the floor of a bank on Monday 3 August.
What this looks like on Monday morning
The e-banking chatbot. Your portal assistant answers a client's question about a wire transfer. From Sunday, it must clearly identify itself as AI — and the Guidelines say regulators will judge whether the disclosure is clear, accessible and effective in context. A line buried in the terms and conditions doesn't pass. The label in the chat window itself does.
The relationship manager's drafted email. An RM uses your internal copilot to draft a reply to a client, tweaks two sentences, and hits send. Is that "AI-generated text"? The Guidelines do offer a way out: content that has undergone human editorial review, with an authorised person taking responsibility, can fall outside the marking obligation. But that carve-out only works if you can show who reviewed what — which means the boundary between "internal tool" and "client-facing output," crossed quietly one copy-paste at a time, now needs a documented review policy behind it. Today, in most institutions, nobody has written it.
The weekly market commentary. Your CIO office uses GenAI to produce the first draft of market views distributed to clients and posted publicly. Text touching matters of public interest needs labelling — and because the trigger is publication date, a piece generated on 30 July but published on 4 August needs the label. Your content pipeline has no field for that today.
The marketing campaign. An AI-generated video of a "client family" discussing their wealth journey, or a synthetic voiceover in your brand film. Under the broad deepfake reading, realistic synthetic people and scenes need disclosure — and the underlying content needs machine-readable marking that survives your CMS, your compression, your social-media exports. That's watermark persistence. It's an engineering property, not a policy.
The call centre. A voice bot handles first-line calls: it must announce itself. And if your fraud or quality tooling analyses caller emotion or stress, Article 50(3) requires informing the people exposed to it. Two obligations, one phone call.
The portfolio agent. The genuinely new one. An agent that monitors positions and autonomously sends a client an alert — "your concentration limit in tech was breached, here's a suggested rebalancing" — is producing output directly perceived by a user. In scope. Every agent we build that talks past the perimeter now ships with a disclosure requirement attached.
Six scenarios, six different owners in today's org chart — channel, RM desk, CIO office, marketing, operations, platform. That's the problem.
The nuance nobody reads to page 40 for
There is relief in the fine print. The AI Omnibus package — adopted by the Council in June, still awaiting publication in the Official Journal — gives generative systems already on the market before 2 August until 2 December 2026 to implement the technical marking and detection measures of Art. 50(2), and there's no retroactive labelling of old content.
But read what the grace period covers: the marking machinery, for existing systems. Everything else — chatbot and agent disclosure, deepfake labelling, public-interest text labelling — still lands on 2 August. Anything new ships compliant from day one. It's a runway, not an exemption.
The geopolitical twist: Brussels isn't alone on this
The reflex take is that this is Europe regulating itself out of the race while the US and China build. On transparency specifically, the map looks different.
China got there first — and has been iterating for years. Since 1 September 2025, under the Measures for Labeling of AI-Generated Synthetic Content, all AI-generated content in China must carry both a visible "AI-generated" label and implicit machine-readable marking in the metadata, backed by a mandatory national standard, with platforms like WeChat and Douyin required to verify and display the labels on content users upload. And 2025 wasn't the starting gun: the Deep Synthesis Provisions already required labelling of synthetic content from January 2023, themselves built on the 2022 algorithm rules and the CAC's filing registry. By the time Brussels starts enforcing, Beijing will have been running — and refining — the marking machinery for three and a half years.
Worth being precise about intent, though. The difference isn't that Beijing ignores the consumer — its rules explicitly target fraud, impersonation, algorithmic price discrimination, even gig-worker scheduling. It's that consumer protection is one objective among several, layered alongside a decade of information-order policy. Brussels built a transparency rule with one beneficiary: the person exposed to the content. Beijing built a governance stack serving several at once — which is why the Chinese regime bundles labelling with algorithm filing and registration obligations the EU doesn't ask for.
The US is the outlier. No federal AI statute, a deregulatory administration actively pushing to preempt state AI laws — and, precisely because of that, a patchwork of binding state obligations from California to Texas that changes every quarter. Less regulation at the top, more fragmentation underneath.
For a bank serving clients across these markets, that's three regimes: mandatory labelling in China, enforceable transparency in the EU, moving targets in the US. The practical consequence cuts against the fatalism: the disclosure and marking infrastructure you build for Article 50 is largely the same machinery China already requires. The overlap is the marking layer, not the full stack — a bank active in China still faces filing and registry duties Article 50 knows nothing about — but build the labelling machinery once, properly, and the hardest technical requirement of the world's two strictest regimes is covered. The banks that treat this as an EU-only annoyance will end up building it three times.
And a note for my Swiss network: Article 50 applies wherever the AI output is used in the EU. Being outside the Union is not being outside scope.
The real question: will this be applied — or shelved like PSD2?
Banking has seen this movie before. PSD2 forced every bank in Europe to build open-banking APIs. Everyone complied — to the letter. Interfaces shipped, sandboxes opened, evidence binders filled. And then much of it just sat there: minimal quality, thin usage, compliance treated as a ceiling rather than a floor. Technically applied, practically hollow.
So the honest question about Article 50 isn't "are we compliant?" It's: is this going to be genuinely applied and used, or become another PSD2 — a feature that exists because the law said so?
The bet on the PSD2 outcome is not irrational. The Guidelines are non-binding. Reliable watermarking that survives compression and re-sharing doesn't fully exist yet — the Commission's own material concedes the technology gap, especially for text. And enforcement sits with 27 national market surveillance authorities of very uneven appetite and resources. A minimal label, a buried disclosure and a thin evidence file might survive unchallenged for years.
But two things are structurally different from PSD2. First, failure is public. An unlabelled deepfake or an undisclosed bot in a client channel is visible to journalists, clients and competitors the moment it surfaces — PSD2 API quality was invisible to everyone outside fintech circles. Second, the same machinery already has a second market. China mandates it today, and clients increasingly ask for provenance regardless of what regulators do. PSD2's APIs never had that pull; nobody outside the regulation wanted them.
And here ownership becomes the tell, not the question. If legal owns Article 50 alone, you will get the PSD2 outcome almost by definition: a policy, a clause, a binder — compliant on paper, dead in practice. If platform engineering owns it together with the channel owners, the disclosure and marking layer becomes reusable infrastructure: provenance for client content, audit trails for agents, trust signals in the interface. The same regulation, two completely different assets.
Bottom line
Article 50 will be exactly as real as the ownership behind it. Treat it as a legal filing and it joins PSD2 on the shelf of things banks built and never used. Treat it as an engineering requirement — inventory, disclosure UX, marking pipeline, evidence — and you've built, once, the trust infrastructure that Brussels demands, Beijing already requires, and clients are starting to expect.
The deadline is Sunday.
So, honestly: in your bank, is Article 50 heading for real usage — or for the PSD2 shelf? And who owns the answer?