EU AI ActJuly 25, 202612 min read

EU AI Act August 2026: GPAI Enforcement and Article 50 Transparency

Article 50 transparency and the Commission fining powers over GPAI providers apply from 2 August 2026. A checklist by role for providers, deployers, and buyers.

Antonella Serine

Antonella Serine

Founder, KLA

Founder of KLA, building the independent runtime governance control plane for regulated AI agents under the EU AI Act.

Lands on 2 August 2026

The Article 50 transparency duties for providers and deployers, and Article 101, the power the Commission uses to fine providers of general-purpose AI models. The Digital Omnibus left both dates alone.

GPAI enforcement

Chapter V obligations have applied since 2 August 2025. From 2 August 2026 the Commission can fine a general-purpose AI model provider up to 3% of worldwide annual turnover or EUR 15 million, whichever is higher.

Legacy models

Providers of general-purpose AI models placed on the market before 2 August 2025 have until 2 August 2027 to comply, under Article 111(3).

Then December 2026

Machine-readable marking closes out for generative systems already on the market, and two new Article 5 prohibitions start to apply. Both on 2 December 2026.

The Digital Omnibus on AI moved the high-risk deadlines. Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 and enters into force on 27 July 2026; stand-alone Annex III obligations now apply from 2 December 2027, and high-risk AI embedded in Annex I products from 2 August 2028. Two things still land on 2 August 2026. The Article 50 transparency duties apply to every AI system that talks to a person or produces synthetic content. And Article 101, the Commission power to fine providers of general-purpose AI models, starts to apply, twelve months after the obligations it enforces. This article covers what each of those means, what a GPAI provider, a deployer and an enterprise buyer each need finished, and the two dates that follow in December 2026. Orientation only; not legal advice.

The obligations that kept their 2 August 2026 date

The Omnibus reopened Article 113, the article that sets when each part of the EU AI Act starts to apply, and moved the high-risk application dates. It left the transparency chapter and the general-purpose AI enforcement machinery on the original clock. The table below is the full picture around 2 August 2026.

EU AI Act application dates around 2 August 2026, after the Digital Omnibus
ObligationApplies fromMoved by the Omnibus
Article 50 transparency duties for providers and deployers2 August 2026No
Article 101 Commission fines for providers of general-purpose AI models2 August 2026No
Chapter V obligations for general-purpose AI models2 August 2025No
Prohibited practices under Article 5 as originally enacted2 February 2025No
Machine-readable marking for generative systems already on the market2 December 2026Four-month transitional period added
New Article 5 prohibitions on CSAM and non-consensual intimate imagery2 December 2026Added by the Omnibus
General-purpose AI models placed on the market before 2 August 20252 August 2027No
At least one operational AI regulatory sandbox per Member State (Article 57)2 August 2027Moved from 2 August 2026
Chapter III obligations for stand-alone high-risk systems (Annex III)2 December 2027Moved from 2 August 2026
High-risk AI as a safety component of an Annex I product2 August 2028Moved from 2 August 2027

Article 101 turns the GPAI rulebook into fines

Chapter V has applied since 2 August 2025. Since that date, a provider of a general-purpose AI model has owed technical documentation of the training and testing process under Article 53(1)(a), documentation for the downstream providers that integrate the model under Article 53(1)(b), a policy for complying with EU copyright law, and a public summary of the content used for training. Models trained above the Article 51 compute threshold carry the additional systemic-risk duties in Article 55: model evaluation with adversarial testing, risk assessment and mitigation, serious-incident reporting to the AI Office, and cybersecurity protection.

What arrives on 2 August 2026 is the instrument that enforces all of it. Article 113 applied Chapter XII from 2 August 2025 and excepted Article 101 from that date. The exception runs out on 2 August 2026. From then the Commission can impose a fine on a provider of a general-purpose AI model of up to 3% of its annual total worldwide turnover in the preceding financial year or EUR 15 million, whichever is higher. The Commission has to find that the provider acted intentionally or negligently, on any of four grounds: infringing the relevant provisions of the Regulation, failing to comply with a request for a document or information under Article 91, failing to comply with a measure requested under Article 93, or failing to give the access needed to evaluate the model under Article 92.

Providers of general-purpose AI models placed on the market before 2 August 2025 have until 2 August 2027 to bring those models into compliance, under Article 111(3). That date came through the Omnibus unchanged. The window is a transition with an expectation of demonstrable progress inside it, and the fining power reaches every model a provider has placed on the market since 2 August 2025 from the first day.

The General-Purpose AI Code of Practice is the route the Commission points signatories to. The AI Office treats a signatory working through its commitments in good faith as adhering to the Code, and Article 101(1) requires the Commission to take commitments made under a code of practice into account when it fixes a fine. The statutory duties in Article 53 and Article 55 stay.

Article 50 lands for everything customer-facing

Article 50 applies from 2 August 2026 to providers and to deployers, at every risk tier. It reaches ordinary chatbots, copilots, and agents that a high-risk classification never touches.

  • Provider, direct interaction. Article 50(1) puts this on the provider. An AI system built to interact with people has to be designed so that they are informed they are dealing with an AI system, in a clear and distinguishable way, no later than the first interaction. The exception a commercial deployer relies on is narrow: the situation has to be obvious to a reasonably well-informed, observant and circumspect person, taking the circumstances and the context of use into account.
  • Provider, synthetic content. A system that generates synthetic audio, image, video, or text has to mark its output in a machine-readable format and make it detectable as artificially generated or manipulated, as far as that is technically feasible. Article 50(2) lifts the duty where the system performs an assistive function for standard editing or leaves the input data and its semantics substantially unaltered.
  • Deployer, deepfakes. A deployer publishing image, audio, or video content constituting a deep fake, meaning content generated or manipulated to resemble real people, places, or events, has to disclose that the content is artificial. Where the content forms part of an evidently artistic, creative, satirical or fictional work, the duty narrows to disclosing that the generated content exists, in a way that does not hamper the display or enjoyment of the work.
  • Deployer, public-interest text. AI-generated or manipulated text published to inform the public on matters of public interest has to be disclosed. The exception needs both limbs: the content went through a process of human review or editorial control, and a natural or legal person holds editorial responsibility for the publication.
  • Deployer, emotion recognition and biometric categorisation. People exposed to those systems have to be informed of their operation, with the data protection duties that come with it.

The one concession, and the penalty behind it

Generative AI systems already placed on the market before 2 August 2026 have a four-month transitional period, to 2 December 2026, for the machine-readable marking duty. A system placed on the market on or after 2 August 2026 has no transitional period for it, and none of the other Article 50 duties carry one.

Article 99(4)(g) puts non-compliance with the Article 50 transparency obligations in the middle penalty tier: up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. Where the offender is an SME, including a start-up, Article 99(6) caps each fine under that article at whichever of the percentage and the fixed amount is lower. The national market surveillance authorities apply the tier. The headline figure matches an Article 101 fine on a model provider, and the Article 99(6) cap reaches only the fines set in Article 99. The Article 50 checklist for chatbots, copilots and agents covers the control design in detail.

Checklist: provider of a general-purpose AI model

This is the role with the shortest runway. The obligations have been live for a year, and only the enforcement is new.

  • Technical documentation of the training and testing process and the evaluation results, held to the Annex XI content list and ready to hand to the AI Office on request.
  • Downstream documentation under Article 53(1)(b), enough for an integrator to understand the capabilities and limitations of the model and to meet its own obligations, with the Annex XII elements present.
  • A copyright policy that identifies and respects reservations of rights expressed under the Directive (EU) 2019/790 text and data mining exception.
  • The public summary of training content, in the AI Office template.
  • For a model above the Article 51 threshold, the Article 55 package: model evaluation with adversarial testing, systemic-risk assessment and mitigation, serious-incident tracking and reporting, and cybersecurity protection for the model and its physical infrastructure.
  • A named owner for Commission correspondence and a tested path for producing requested information inside the deadline. Failing to supply requested information is its own ground for a fine under Article 101.
  • A documented decision on the Code of Practice. Signing changes how the Commission supervises the model and can reduce a fine. The statutory obligations stay where they are.
  • For a model placed on the market before 2 August 2025, a plan that lands compliance by 2 August 2027, with evidence of progress along the way.

Checklist: deployer running customer-facing chatbots, copilots, and agents

A deployer is an organisation using an AI system under its own authority. Most enterprises are deployers, and most of the 2 August 2026 work sits here.

  • An inventory of every surface where an AI system speaks to a person: web chat, in-product copilots, voice, email and messaging agents, and anything a partner embeds on your behalf.
  • Article 50(1) assigns the direct-interaction disclosure to the provider. Where the organisation controls the interface, serving it is an operational responsibility; where a vendor controls it, the contract has to carry it. On each of those surfaces it lands no later than first interaction, clear and distinguishable, and meeting the accessibility requirements that apply to the rest of the interface.
  • Disclosure copy in each language the surface serves. A notice served in English to a French-speaking customer is not a clear disclosure to that customer.
  • Deepfake disclosure on published image, audio, or video the organisation generates or manipulates that constitutes a deep fake, meaning content resembling real people, places, or events. Marketing assets are in scope where they meet that trigger.
  • A rule for AI-generated text published to inform the public on matters of public interest. Relying on the exception takes both limbs on the record: the human review or editorial control the content went through, and the natural or legal person holding editorial responsibility for the publication.
  • Notices for any emotion recognition or biometric categorisation in use, and a check that the underlying practice is clear of the Article 5 prohibitions.
  • Evidence that each control fired. Article 50 requires that the person be informed and sets no per-session logging duty. A record that the disclosure was served is a control worth keeping to prove it later, sized to what data protection law lets the organisation retain.
  • A regression check, because the failure mode is a redesign that quietly drops the notice. Tie the disclosure to a test that runs on every release.

Checklist: enterprise buyer

A buyer picks up deployer duties on the day a system goes live, and inherits nothing useful from the vendor unless the contract asks for it.

  • Ask which general-purpose AI models sit under the product, who their providers are, and whether those providers have signed the Code of Practice.
  • Ask for the Article 53(1)(b) downstream documentation, or the vendor summary built on it. A vendor that cannot produce it has an upstream problem that becomes yours.
  • Confirm in writing which Article 50 duties the vendor discharges in the product and which land on you. The direct-interaction disclosure is the provider duty under Article 50(1), so name who builds it and who serves it. Deepfake and public-interest text disclosure are deployer duties and land on you.
  • For any generative feature, ask whether outputs carry machine-readable marking today, and get the 2 December 2026 date written into the plan for products that shipped before 2 August 2026.
  • Ask for the logs. Establish before signing that you can export evidence that a disclosure was served and that a control fired, in a form you can hand to a supervisor.
  • Keep the high-risk questions in the contract even though Annex III now applies from 2 December 2027. Specify classification, logging, and human oversight at purchase; retrofitting them in 2027 costs more.

Two more dates in December 2026

The Omnibus added two prohibited practices to Article 5. AI systems that generate or manipulate child sexual abuse material, and AI systems that generate or manipulate realistic sexual or intimate imagery of an identifiable person without their consent, are prohibited from 2 December 2026. The prohibition reaches a provider where that output is the intended purpose of the system, or a reasonably foreseeable and reproducible result without significant technical modification.

Article 5 breaches sit in the top penalty tier under Article 99(3): up to EUR 35 million or 7% of total worldwide annual turnover, whichever is higher. For an SME, including a start-up, Article 99(6) caps the fine at whichever of the two is lower. Any team shipping image or video generation should be running red-team work against these two categories now and keeping the results.

The second December date is the machine-readable marking close-out for generative systems that were already on the market. Both fall on 2 December 2026, which makes Q4 2026 a single delivery window.

Where the evidence comes from

At inspection time each duty above resolves into one question. Show that the control ran on the day it mattered. A record of the individual interaction, written while the interaction happened, is what answers it.

The Article 50 controls themselves live in the surface that faces the customer. The chat window renders the disclosure; the generation pipeline applies the marking. Those belong to the team that owns the product. What sits underneath, once a conversation turns into action, is where KLA operates. The Article 50 and Article 101 duties are not modelled as controls in the product today.

  • `KLA Policy Engine` evaluates a Decision Request before a governed tool call runs, and again on the tool output before it reaches the model. The outcome is allow, warn, require_approval, or block.
  • When the decision service is unreachable, the enforcement point returns a held or blocked outcome carrying the reason code `policy_engine_unavailable`. It has no path that resolves an unreachable decision to allow.
  • `Decision Desk` is where a require_approval outcome waits. The run stays paused until an approver decides, the requester is refused their own request on separation-of-duties grounds, and the record keeps who decided, when, and the roles they held at that moment.
  • `Evidence Room` produces a Sealed Evidence Bundle: a canonical manifest, a SHA-256 per artifact under a Merkle root, two ES256 signatures, and the public keys needed to check them. A standalone verifier re-runs those checks with no network access.
  • `Control Mapping` covers EU AI Act Articles 9, 10, 11, 12, 14, 15, 17 and 72 alongside SOC 2, ISO 27001, DORA and AMLR controls. Articles 9, 10, 11, 12, 14 and 15 are the Chapter III requirements for high-risk systems, Article 17 is the Chapter III provider quality-management obligation, and Article 72 is the Chapter IX post-market monitoring obligation. All three groups follow the high-risk schedule to 2 December 2027 for Annex III systems, and the August work feeds them.

Frequently Asked Questions

Did the Digital Omnibus delay the EU AI Act deadline of 2 August 2026?

It moved the high-risk obligations. Chapter III duties for stand-alone Annex III systems apply from 2 December 2027, and high-risk AI embedded in Annex I products from 2 August 2028. The Article 50 transparency duties still apply from 2 August 2026, and the Commission power to fine providers of general-purpose AI models under Article 101 also starts on 2 August 2026.

What changes for GPAI providers on 2 August 2026?

The obligations are unchanged. Chapter V has applied since 2 August 2025. Article 113 excepted Article 101 from that date, so until 2 August 2026 the Commission had no power to fine a general-purpose AI model provider. From 2 August 2026 it can impose fines of up to 3% of annual total worldwide turnover or EUR 15 million, whichever is higher.

How large are the fines for breaching Article 50?

Up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher, under Article 99(4)(g). Market surveillance authorities in the Member States apply that tier. Breaches of the Article 5 prohibitions sit higher, at EUR 35 million or 7% under Article 99(3). Where the offender is an SME, including a start-up, Article 99(6) caps each fine set in Article 99 at whichever of the percentage and the fixed amount is lower.

Is there a grace period for marking AI-generated content?

Generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty in Article 50(2). Systems placed on the market on or after 2 August 2026 have no transitional period, and the other Article 50 duties have none.

Our model was released in 2024. When do we have to comply?

Providers of general-purpose AI models placed on the market before 2 August 2025 have until 2 August 2027 under Article 111(3), a date the Digital Omnibus left unchanged. That window is a transition with an expectation of demonstrable progress, and it does not cover models placed on the market from 2 August 2025 onward.

Does signing the GPAI Code of Practice remove the risk of a fine?

No. The Code is a voluntary route to demonstrating compliance with the Chapter V obligations. The AI Office treats a signatory working through its commitments in good faith as adhering to the Code, and Article 101(1) requires the Commission to take commitments made under a code of practice into account when it fixes a fine. The statutory obligations in Article 53 and Article 55 apply to signatories and non-signatories alike.

We are only a deployer. What do we owe on 2 August 2026?

Deepfake disclosure on published synthetic media, disclosure of AI-generated text published to inform the public on matters of public interest unless the content went through human review or editorial control and a natural or legal person holds editorial responsibility for the publication, and notices for emotion recognition or biometric categorisation. Article 50(1) assigns the direct-interaction disclosure to the provider; where you control the chat surface, serving it is an operational responsibility, and where the vendor controls it, put it in the contract. Article 50 sets no logging duty for any of these. A record that the control fired is worth keeping to prove it later.

Key Takeaways

The Digital Omnibus on AI moved Chapter III to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products. It left 2 August 2026 in place for the Article 50 transparency duties and for the Commission power to fine providers of general-purpose AI models under Article 101. For most enterprises the August work is disclosure, content marking, and the evidence that both happened. December 2026 closes the marking transition and brings two new Article 5 prohibitions. Check your own dates on the deadline timeline, or start from the EU AI Act hub for the full phased picture. This article is general information and not legal advice; confirm your obligations with qualified counsel and check the Official Journal text before relying on any date.

See It In Action

Ready to automate your compliance evidence?

Book a 20-minute demo to see how KLA helps you prove human oversight and export audit-ready Annex IV documentation.

EU AI Act August 2026: GPAI Enforcement and Article 50 Transparency | KLA Blog