Since August 2026, Article 50 of the EU AI Act has required businesses to tell people when they are interacting with AI or viewing certain AI-generated content. Skadden counsel Jonathan Stephenson and Elva Cullen join host Deborah Kirk to discuss what compliance looks like in practice. Elva distinguishes AI providers from deployers, while Jonathan notes that a generic line in the terms and conditions is unlikely to suffice. He also discusses the European Commission's voluntary Code of Practice on Transparency and AI-Generated Content, which offers businesses a recognized route to meeting the Article 50 requirements. Looking ahead, existing generative AI systems face a December 2026 marking deadline, and Deborah walks through the high-risk deadlines, now set for December 2027 and August 2028, and how the extra time can serve as a runway for preparation. The conversation then widens to the U.S., where a voluntary pledge with no enforcement mechanisms contrasts with the EU's binding framework.
☑️ Elva Cullen
☑️ Jonathan Stephenson | LinkedIn
☑️ Deborah Kirk | LinkedIn
☑️ Skadden | LinkedIn | X | Facebook
☑️ Subscribe Apple Podcasts | Spotify | Amazon Music
“SkadBytes” is presented by Skadden, Arps, Slate, Meagher & Flom LLP and Affiliates. This podcast is provided for educational and informational purposes only and is not intended and should not be construed as legal advice. This podcast is considered advertising under applicable state laws.
Welcome to “SkadBytes," a podcast from Skadden exploring the latest developments shaping today's rapidly evolving tech landscape. Join host Deborah Kirk and colleagues as they deliver concise insights on the pressing regulatory issues that matter to tech businesses, investors and industry leaders worldwide.
Deborah Kirk (:Hello there and welcome back to “SkadBytes.” I'm Deborah Kirk and I'm joined today by the two counsel in our team here at Skadden in London — Jonathan Stephenson and joining us on “SkadBytes” for the first time, Elva Cullen. Elva, welcome.
Elva Cullen (:Thanks Debs. Great to be here.
Deborah Kirk (:So today we are focusing on something businesses and their customers are increasingly going to see in practice, the EU AI Act's transparency rules. So Article 50 of the AI Act is now in force and has been since the 2nd of August this year. Now at its simplest, Article 50 is about making sure people know when they are interacting with AI or looking at certain AI-generated or AI-manipulated content. Now, why does that matter? That matters because generative and interactive AI is now so elevated that it is becoming increasingly more difficult to ascertain what is human created and what is not. And that creates obvious risks around deception, manipulation, fraud, impersonation and ultimately consumer trust. And there is an interesting wider policy story here too. At the same time as the EU is actively encouraging businesses to adopt AI through initiatives like the Apply AI Strategy, it is also putting in place rules designed to make sure people can tell when AI is being used. So greater adoption and greater transparency are increasingly being developed in parallel.
(:Now, unlike some parts of the EU AI Act, these obligations are not confined to the more narrow category of high-risk AI systems. They can apply to everyday uses of AI from chatbots and customer facing tools through to synthetic images, video, audio and text. So this is not just a point for AI developers. It can affect businesses deploying AI in their products, communications, content workflows, and raises very practical questions about product design, about labeling, about internal governance and about record keeping. So we're going today to try and unpack what Article 50 requires, who has to do what in order to comply with it, and what that compliance really looks like in practice. Then we're going to step back and look at the wider AI Act timetable because the AI Omnibus has changed some of the deadlines that businesses may have previously been working towards. And then look just briefly at the sort of wider global picture. So Elva, a useful place to start is the distinction between providers and deployers because quite a lot turns on which side of that line you sit, right?
Elva Cullen (:Absolutely. So a provider is broadly the entity that develops an AI system or puts it on the market under its own name or trademark. In practical terms, think of the company that builds the tool or puts a name to it. A deployer is the entity using an AI system under its own authority in a business or professional context. So that might be a company taking somebody else's AI product and using it in its own operations just to avoid one potential source of confusion at the outset. The Article 50 rules we're discussing are different from the separate transparency obligations for general purpose AI models, meaning large multipurpose models that can sit underneath and support many different applications. Article 50 is principally concerned with interactions with people and the origin of AI-generated or -manipulated outputs. The separate general purpose AI regime deals with things like model documentation and training-content transparency.
Deborah Kirk (:Okay, so perhaps what's happening behind the scenes versus my knowing when I'm looking at something that's AI-generated.
Jonathan Stephenson (:Yeah, exactly. And I think what's really interesting about that point is within Article 50 itself, the provider and the deployer distinction really matters because the obligations are different. Broadly, the provider needs to build transparency into the system itself and the deployer needs to think about what the people actually encountering the system or its outputs need to be told.
Deborah Kirk (:And businesses also should not assume they will always sit neatly in one of those categories, and of course they may move. The commission's July guidelines make it really clear that the role analysis should be periodically reassessed, particularly if you move from developing an AI system through to then putting it into use. Let's say where a business takes a third-party AI system, slaps its own brand on it or makes material changes to it, then you need to consider whether the categorization of your role in the AI chain has changed, which of course could then impact the obligations that apply to you. So the practical point I think is to assess the role by reference to the particular system and use case and watch where that begins to change rather than assuming you are a deployer simply because you started with someone else's technology. And so then on the provider side, Elva, there are really, I think two obligations worth pulling out.
Elva Cullen (:Yes. So the first is direct interaction with people. So if you provide an AI system intended to interact directly with individuals, the system has to be designed so that they're informed they're interacting with AI. There is an exception where that is already obvious to a reasonably well-informed observant person taking the circumstances and context into account. In straightforward terms, if somebody could reasonably think they're dealing with a human when they're actually dealing with AI, the system needs to tell them.
Jonathan Stephenson (:And that immediately becomes a product design question because I guess it's not enough to ask whether your terms and conditions somewhere say that AI is involved. You then really need to think about what the user sees at the point of interaction and whether the disclosure actually reaches them.
Elva Cullen (:Yeah. And so the second provider obligation is about synthetic content. Providers of AI systems generating synthetic audio, images, video or text, including general purpose AI systems, have to ensure outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated. By machine-readable, we mean that the content carries information that software can recognize as signaling AI generation or manipulation, even where there may be nothing immediately visible to a person looking at it. So there are four things that a technical solution needs to achieve. It needs to be effective, so actually identifies AI-generated content. Interoperable, so the marking works across different systems. Robust, so it cannot easily be removed or tampered with. And reliable, so it doesn't really routinely label human content as AI-generated or miss content that is actually AI-generated. There is also an important carve-out. The obligation doesn't apply where the AI system is essentially performing a standard editing or assistive function and doesn't substantially alter the input data or its meaning.
(:So correcting grammar or adjusting the brightness of an image, that's not what this obligation is aimed at. The commission guidance also addresses some limited, closed business-to-business and industrial context. The important point is that where the marking obligation applies depends on the particular circumstances and the conditions in the guidance rather than every AI-generated output automatically requiring the same treatment.
Deborah Kirk (:Okay. And those carve-outs are important because without them, routine digitally assisted editing or certain closed development uses could have been swept into a regime that was designed principally to make genuinely synthetic or manipulated content, I guess, identifiable by the individuals engaging with it. And the marking point also raises, I suppose, the question of how providers actually do this in practice in technical terms.
Jonathan Stephenson (:Yeah, and I think that's where the commission's Code of Practice on Transparency and AI-Generated Content becomes really useful. One important point up front is that the code is voluntary. It's not in and of itself the legal obligation, but the commission and the AI board have assessed that it's an adequate EU-wide means of facilitating compliance. And so for signatories, it provides a more streamlined and predictable route for showing how they meet those Article 50 requirements. By the end of July, around 190 organizations had already signed the code across sectors, including technology, telecoms, education and retail, and the flexibility in how businesses comply is really deliberate. Article 50 largely tells providers the result they need to achieve rather than prescribing one particular technology for getting there.
Elva Cullen (:Exactly. So this is helpful as the technology develops, but it also means a business can't simply point to one prescribed technical solution and assume the analysis is finished. There is a reason for that. The commission's own work on marking and detecting AI-generated text, audio, images and video recognizes that the available technologies have different strengths and limitations depending on the medium. In practice, the different techniques broadly involve putting information alongside the file, embedding something within the content itself or keeping a separate record that can later be matched back to the output. In technical terms, the code refers to digitally signed metadata, meaning information attached to a file recording its AI origin, imperceptible watermarking, meaning machine-readable markers embedded directly into the content, but invisible or inaudible to people, and fingerprinting or logging, which can provide an output record as a fallback, particularly for short or heavily transformed content.
(:The important point is not that every business must use one prescribed technology, it's that the approach chosen has to satisfy the underlying Article 50 requirements. This isn't necessarily a one-off implementation exercise. The code is intended to evolve as standards and technology develop, so organizations will need to keep their technical approach under review rather than treating compliance in August 2026 as the end of the exercise.
Jonathan Stephenson (:And voluntary does not mean irrelevant. A business does not have to sign the code as we've previously said, but if it does not, it still has to comply with Article 50 and must be able to demonstrate that its alternative measures are equivalently adequate. That is potentially a demanding exercise in practice. An organization taking an alternative route needs to be able to substantiate that its chosen approach meets the underlying requirements rather than simply asserting that it does, which means this is not just a legal team exercise. There's other elements. Engineering, product, security and compliance teams may all need to be involved because for providers, the transparency obligation is being implemented in the technology itself.
Deborah Kirk (:Right. And I suppose the practical point there is fairly simple. If you can build a system that generates synthetic content, you need a reliable way for that content to carry its AI origin within it. If you use AI-generated content, you need to think separately about what the person seeing it needs to be told. And I guess that brings us to the deployer side. So one obligation applies to emotion recognition and biometric categorization systems. If an organization deploys those types of AI systems, it must inform the individuals that they are exposed to them. And then of course you need to think about your usual data protection law requirements as those continue to apply to the extent that personal data is being processed as part of that. And the content obligations are probably the more visible part of the regime. So Jonathan, maybe let's start with deepfakes.
Jonathan Stephenson (:Yeah, so deepfakes in this context are AI-generated or manipulated images, audio or video content that resembles real people, objects, places, entities or even events and would falsely appear authentic or truthful. Deployers using AI systems to generate or manipulate that kind of content have to disclose that it's been artificially generated or manipulated. There is a more flexible rule for evidently artistic, creative, satirical, fictional or those types of similar works. The disclosure still has to be made, but it can be done in a way that does not hamper the display or the enjoyment of that work. And that concern goes beyond Article 50. The commission is also addressing AI-generated content and deepfakes through its Democracy Shield work, particularly around misinformation and electoral integrity. And so provenance, meaning being able to understand where content comes from and how it was created, is increasingly becoming a theme across the EU's wider digital policy.
Elva Cullen (:There is also a similar but a distinct rule for AI-generated text used to inform the public on matters of public interest. The starting point is that deployers must disclose that the text has been artificially generated or manipulated, but there is an important exception where the content has undergone human review or editorial control, and a natural or legal person holds editorial responsibility for publication. For businesses seeking to rely on that exception, the practical issue is being able to show what the human review and editorial responsibility actually looked like. Informal sign-off may be harder to rely on if there's no evidence of the process behind it.
Deborah Kirk (:Right. And I guess across these obligations, timing and formats, they matter. Article 50 requires the information to be provided in a manner that is clear and distinguishable at the latest at the time of the first interaction or exposure, and it also needs to comply with applicable accessibility requirements. So the rule is really about disclosure at the point that a person encounters the AI or the content. So putting a generic statement somewhere in the terms and conditions and assuming that your job is done is unlikely to be adequate and unlikely to address what Article 50 is trying to achieve. And the commission has made this more tangible by publishing optional EU icons that deployers can use to identify or flag AI-generated or manipulated content. So, helpful practical labeling tool, but it's important to say not a safe harbor. In other words, using one of these icons does not by itself establish compliance. So, businesses need to make their own determination as to whether the disclosure is clear, distinguishable, and accessible in the particular context.
Jonathan Stephenson (:And that's probably the most useful way for organizations to think about this operationally. Map where your AI touches a customer, employee or another person. Map where AI-generated content enters a workflow. Then ask what that person sees, what the system record and whether you could evidence the process later.
Elva Cullen (:Exactly. And that last point is important because compliance here is not just about the front-end disclosure. Organizations should know which systems they provide and which they deploy, where direct AI interaction takes place, where synthetic content is created or published, which obligation applies and who owns it internally. For providers, that may mean technical documentation showing how machine-readable marking works and how its effectiveness has been tested. For deployers, it may mean documenting how labels are presented, how human review operates and who holds editorial responsibility where an exception is being relied on.
Deborah Kirk (:So I guess the broader theme here is audit readiness and then documentation. So you've got evidence ready to allow you to tell your story through date-marked paper should the regulators ever come knocking. And I think that's what I'm hearing — it’s not just about whether you think you comply, it's about asking what would you actually produce if a regulator asks tomorrow, how does the system work, what disclosure was made, and why and how your approach satisfies the requirements of Article 50? And that also helps to explain why the code matters. So signing is not conclusive proof of compliance, but it gives organizations a recognized route through the requirements. And if you choose an alternative route, okay, but you need to be ready to substantiate it.
Jonathan Stephenson (:There is one other practical point worth making before we move on. The rules do not require businesses to go back and retrospectively label content generated before the 2nd of August 2026. Voluntary labeling of historic content may still make sense in some circumstances, but there is, as said, no mandatory requirement to do that.
Deborah Kirk (:Okay. This feels maybe like a good point to step back and look at the AI Act landscape more broadly. Spent some time on what Article 50 means now, but the timetable for some of the other AI Act obligations has changed quite significantly. And Jonathan, remind us where we are with that and where the AI Omnibus now sits.
Jonathan Stephenson (:So the commission originally proposed the AI Omnibus in November 2025, almost a year ago, as part of the wider Digital Omnibus package. The important distinction is that the AI Omnibus is the targeted legislation amending the AI Act itself. It's now completed the legislative process and entered into force on the 27th of July this year. The wider Digital Omnibus is broader. It proposes changes across other parts of the EU digital rule book, including areas such as data protection, cybersecurity and non-personal data legislation. That should not be confused with the now enacted AI Omnibus.
Elva Cullen (:That's right. And the relationship between the two parts of this episode is actually quite neat. Article 50 shows the part of the EU AI Act that businesses now have to operate in practice. The omnibus shows that elsewhere the EU has recognized that some of the more demanding obligations needed more runway. So this isn't a rollback from AI regulation, it's a more uneven implementation timetable.
Deborah Kirk (:Exactly. Some obligations are already live and visible in day-to-day product use while some high-risk requirements have been pushed further out. So what does the road ahead actually look like for you for businesses? So rather than throwing another wall of dates at you, I think perhaps there are three useful buckets. What is live now, what's coming next and what has been pushed further out so it can perhaps go a little lower on your list of priorities? So I'll start with what is live now.
(:As we've said, the Article 50 transparency obligations apply from the 2nd of August this year. The national market-surveillance authorities, broadly the national regulators responsible for supervising compliance with the AI Act, now have enforcement powers for those transparency obligations with the EU AI office. They're the more centralized regulator having a more limited role for systems within its remit. Other parts of the regime started earlier. So the governance rules and obligations for general purpose AI models began applying from the 2nd of August last year while certain prohibited practices and AI literacy requirements had already applied from February of last year. So businesses are now firmly in an implementation and enforcement phase, even though important aspects of the act still have later dates. So Jonathan, tell us what's coming next.
Jonathan Stephenson (:Yeah, the nearest date after this is the 2nd of December 2026 this year. There are two things in particular to hold onto. Number one, that the new prohibitions concerning nonconsensual intimate imagery and child sexual abuse material, they begin to apply. Those provisions address AI systems designed for generating that content, systems without the required reasonable safety measures to prevent that content and the use of AI systems by deployers to create prohibited content. Second point, bear in mind, providers of synthetic content AI systems that were already on the market before the 2nd of August 2026 have until the 2nd of December 2026 to bring those systems into compliance with the Article 50 machine-readable marking requirement that we've discussed today. And so for businesses with existing generative AI products, that is therefore a near-term, both engineering and compliance, deadline to bear in mind.
Elva Cullen (:And then by the 2nd of August 2027, each member state should have at least one operational AI regulatory sandbox. What is a regulatory sandbox? It's essentially a supervised environment in which businesses can develop and test AI systems with regulatory involvement. For companies developing new AI products, that potentially gives them a structured way to test systems and regulatory assumptions before full deployment.
Jonathan Stephenson (:And Debs, you mentioned the high-risk delays earlier. That's where the recalibration becomes maybe the most obvious.
Deborah Kirk (:That's right. So the first high-risk date is now the 2nd of December 2027. That is when the rules apply to standalone high-risk uses in particularly sensitive areas. So we're talking biometrics, we're talking critical infrastructure, education and employment, and these are known as the Annex III systems, unsurprisingly, because they sit in Annex III. And then on the 2nd of August 2028, the rules apply to high-risk AI embedded in physical products already subject to EU product safety rules. So they're known as Annex 1 systems, so certain types of machinery, lifts or toys. And the important practical change I think is certainty. Businesses potentially within those categories now have clear fixed dates against which they can build their compliance programs and plan their route to compliance. And so the extra time therefore should be treated as an implementation runway, not as a reason to stop preparing. I think there's a reason that they've been pushed out. So again, while you can perhaps put it a little lower on your list of priorities, still keep those dates in mind rather than ceasing the journey.
Elva Cullen (:Exactly. And that distinction captures the broader position quite well. So as we've said earlier, the EU has not and isn't stepping away from AI regulation. It's just adjusted when some obligations apply while allowing other obligations, including Article 50, to take effect. For organizations operating across the AI value chain, the result is that different parts of the same regulatory framework are now at very different stages of maturity.
Jonathan Stephenson (:Yeah, exactly as you both said, which is why the practical work definitely needs to be prioritized rather than treated as one enormous EU AI Act project. So we know that Article 50 is live now, the December 2026 transition is close, and so businesses potentially caught by the high-risk rules, while they have a bit longer, they should know whether they're in scope at least and use that additional time deliberately.
Deborah Kirk (:I wonder whether it's worth briefly actually widening the lens here because transparency is not only a European conversation and the approach that we've been discussing sits within a much broader international picture and there's a fair amount of contrast with what is happening now elsewhere. I think it's particularly striking at this point. Jonathan, do you want to speak a bit about the U.S. position?
Jonathan Stephenson (:It is. Recently, President Trump announced the Joint Commitment on Frontier Responsibilities voluntary agreement signed by the heads of the largest U.S. AI and tech companies. It outlines four layers of controls and audits from internal safety monitoring through to an independent review board. But the agreement is described as morally binding. It carries no enforcement mechanisms, no legal implications and no requirement for government regulators to be involved. Companies can therefore select their own evaluators, appoint their own oversight boards and decide whether or not to publish their findings.
Elva Cullen (:And I think it's interesting to compare that with the EU's Code of Practice. That is also voluntary, but it sits underneath the binding legal obligation in Article 50. So if a business doesn't sign the code, it still needs to demonstrate that its alternative approach meets the same statutory requirements. The US commitment, however, doesn't actually sit under any comparable framework.
Deborah Kirk (:Right. And the broader policy direction is just generally quite different. The Trump administration has rejected calls for more AI regulation, citing competition with China and economic growth as its background reasons. And the EU, by contrast, is pursuing adoption and regulation in parallel. And for businesses, I suppose, operating across both jurisdictions, which will be many, that divergence is challenging and it matters. Meeting one jurisdiction's expectations will not necessarily satisfy the other, which makes it more important to understand precisely what each regime requires. And so before we wrap up, maybe three practical takeaways. I'll take the first one and I'll hand it over to you guys. So first, transparency is now an operational requirement. Businesses should know where users interact with AI, where synthetic content enters their workflows and what disclosures or markings are required. Elva, over to you for number two.
Elva Cullen (:So this is not a purely legal-notice exercise. For providers, Article 50 can require changes to system design and technical marking. For deployers, it can affect user interfaces, content review processes, editorial governance and record keeping. And if you're relying on an exception or an alternative technical approach, you should be able to evidence why it works. So Jonathan, over to you for the third point.
Jonathan Stephenson (:I think the third would be keep the wider implementation timetable in view. Article 50 is live now. Second of December transition is close, as we've said, and businesses potentially within the high-risk regime should use that additional runway to prepare for December 2027 or August 2028 or otherwise rather than treating those dates as a reason to defer the work. And that preparation is broader as we've discussed than just technical compliance. Depending on the role and use case, it can cut across product design and safety measures, staff AI literacy, data governance, sectoral mapping and even contracts.
Deborah Kirk (:Perfect. So that is the current position as we see it. The EU is simultaneously trying to increase AI adoption and build greater trust around how AI is used. And Article 50 is a part of that trust infrastructure. It is already affecting how AI systems interact with people and how AI-generated content is created, labeled and published. At the same time, the AI Omnibus has given businesses a clearer timetable for what comes next. And so for you, for organizations and businesses, the practical question is increasingly not simply whether the AI Act applies, but where it touches their products and workflows now and whether they can demonstrate that they've dealt with it properly. If any of the issues we've discussed align with challenges you are working through, we would be happy to continue the conversation. But for now, thank you for listening to “SkadBytes.” We'll see you next time.
Voiceover (:Thank you for joining us for today's episode of “SkadBytes.” If you like what you're hearing, be sure to subscribe in your favorite podcast app so you don't miss any future conversations. Additional information about Skadden can be found at skadden.com.