Article 50 of the EU AI Act became enforceable on August 2, 2026, and the scope is broader than most of the deployment-side conversation has acknowledged. It’s not a rule for frontier labs. It’s a rule for anyone running a chatbot, a generative feature, or a deepfake-adjacent tool that touches the European market.

Three obligations went live simultaneously. Chatbots have to disclose they’re AI. Deepfakes have to be labelled. AI-generated or altered content has to carry machine-readable marks so downstream systems can identify it. Only the last of those got a transition window, and a narrow one: under the AI Omnibus, providers of systems placed on the market before August 2 have until December 2, 2026 to comply with the marking requirement in Article 50(2). Everything else is already in force.

The extraterritorial reach is the part the compliance memos keep circling. As Cooley put it, “the AI Act applies globally to providers, deployers, importers and distributors of AI systems that place AI on the EU market or whose AI outputs are used within the European Union.” A US company with a support bot serving European users is inside the perimeter.

Penalties top out at €15 million or 3% of global annual turnover, enforced by national market surveillance authorities, the European AI Office, and the European Data Protection Supervisor. Proportionality provisions exist for SMEs, but they’re a hedge, not a shield.

The Commission has endorsed a voluntary Code of Practice on Transparency of AI-Generated Content as an adequate compliance pathway. Firms that don’t sign on have to document their alternative measures, which is its own workload.

The interesting structural read is where the burden lands. Frontier labs already have policy teams. The exposed population is the mid-market: companies that bolted a chatbot onto their site last year and never thought of themselves as AI providers. That’s the constituency governance-oriented platforms like Glean, Dust, and LemonLime have been quietly positioning for, and August 2 is the date their pitch decks stopped being speculative.

GDPR produced an entire compliance-tech sector within eighteen months of enforcement. Article 50 has just started that clock.

Sources