Date: 28 August 2026
Product: Article 50 Ship Checklist
For: Founders and operators of a SaaS product with an AI assistant or generative output that people in the EU can reach
Not legal advice. Operator template from the 27 August 2026 Money Brief (official EU pages). Get counsel if classification or a fine is on the line.
The Digital Omnibus, Regulation (EU) 2026/1744, moved the high-risk stack. It did not move Article 50. The Commission said so on 31 July 2026. Its enforcement page, last updated 24 August 2026, still lists chatbot disclosure, deepfake labels, and machine-readable marks among the rules that became enforceable on 2 August 2026. A US, Canadian, or UK headquarters does not take you out (Article 2). Tick as you ship. Keep a dated screenshot and the commit hash.
Every EU-reachable surface that talks back, generates media, scores a person, or infers emotion or a biometric category.
Wrapping a frontier model does not label your first message.
Notice at the start of the first interaction, in the product, not a privacy policy. Visible without a click. The “obvious” exception is narrow. A product named “AI Copilot” is not automatically obvious if someone could think they reached support staff. A footer or a line in the Terms will not match “first interaction, clear and distinguishable.”
Exact notice line:
This is an AI assistant. You are not speaking with a person.
Deployer duties you already owe. A hidden vendor watermark is not enough. Do not assume a vendor’s mark covers your UI.
Content generated before 2 August 2026 does not have to be labelled retroactively.
Recital 38 is the only Article 50 concession: four extra months, only for providers who had already placed a generative system on the market before 2 August, and only for the marking duty in Article 50(2). Chatbot notice and deepfake labels are already due. Marks on systems launched on or after 2 August are already due.
Signing is voluntary and is not conclusive proof of compliance. It does not operationalise the Article 50(1) notice.
High-risk rules apply from 2 December 2027 for stand-alone Annex III systems, and from 2 August 2028 for high-risk AI inside Annex I products. If the inventory says Annex III, stop and get counsel.
Buyer answer. Article 50 in force since 2 August 2026; high-risk Annex III from 2 December 2027; you disclose AI interaction in-product; legacy marking is scheduled by 2 December 2026.
Article 50-type fines can reach €15 million or 3% of worldwide turnover, whichever is higher. As of 27 August 2026 there was no official announcement of a first Article 50 fine or a named investigation against a specific startup.
The cheap move is a notice and a screenshot. The expensive move is explaining why you thought 2027 applied to a chatbot.
Sources: same official EU pages as the parent brief. This template invents no new duties.
# Article 50 ship checklist **Date:** 28 August 2026 **Product:** Article 50 Ship Checklist **For:** Founders and operators of a SaaS product with an AI assistant or generative output that people in the EU can reach **Not legal advice.** Operator template from the 27 August 2026 Money Brief (official EU pages). Get counsel if classification or a fine is on the line. The Digital Omnibus, Regulation (EU) 2026/1744, moved the high-risk stack. It did not move Article 50. The Commission said so on 31 July 2026. Its enforcement page, last updated 24 August 2026, still lists chatbot disclosure, deepfake labels, and machine-readable marks among the rules that became enforceable on 2 August 2026. A US, Canadian, or UK headquarters does not take you out (Article 2). Tick as you ship. Keep a dated screenshot and the commit hash. --- ## 1. Inventory Every EU-reachable surface that talks back, generates media, scores a person, or infers emotion or a biometric category. - [ ] Listed every such surface - [ ] Marked provider vs deployer; shipped before or after 2 August 2026 - [ ] Tagged likely 50(1), 50(2), 50(3), 50(4), or Annex III - [ ] Unsure plus EU users: assumed Article 2(1)(a) or (c) Wrapping a frontier model does not label your first message. ## 2. 50(1) notice copy Notice at the start of the first interaction, in the product, not a privacy policy. Visible without a click. The “obvious” exception is narrow. A product named “AI Copilot” is not automatically obvious if someone could think they reached support staff. A footer or a line in the Terms will not match “first interaction, clear and distinguishable.” **Exact notice line:** > This is an AI assistant. You are not speaking with a person. - [ ] First message or persistent chrome uses that line (or the same two facts) - [ ] Visible without a click - [ ] Dated screenshot and commit hash saved ## 3. Deepfake labels Deployer duties you already owe. A hidden vendor watermark is not enough. Do not assume a vendor’s mark covers your UI. - [ ] AI image, audio, or video that could pass as real: human-readable label on first view (Article 50(4)); a person can see or hear it - [ ] Artistic or satirical work still disclosed - [ ] Emotion recognition or biometric categorisation: people exposed are told the system is running (Article 50(3)) - [ ] AI-written public-interest text with no editor on the substance is labelled (spell-check is not review) Content generated before 2 August 2026 does not have to be labelled retroactively. ## 4. 2 December marking ticket Recital 38 is the only Article 50 concession: four extra months, only for providers who had already placed a generative system on the market before 2 August, and only for the marking duty in Article 50(2). Chatbot notice and deepfake labels are already due. Marks on systems launched on or after 2 August are already due. - [ ] Ticket opened if you generate user-facing content and the system was on the market before 2 August 2026 - [ ] Owner assigned - [ ] Decide this month: sign the Code of Practice, or document an equivalent method Signing is voluntary and is not conclusive proof of compliance. It does not operationalise the Article 50(1) notice. ## 5. Annex III skip - [ ] Inventory does **not** show stand-alone Annex III (employment, education, credit, essential services, certain biometrics) or high-risk AI inside an Annex I product - [ ] No high-risk build this quarter — that is a 2027 programme and a lawyer, not this week’s ship High-risk rules apply from 2 December 2027 for stand-alone Annex III systems, and from 2 August 2028 for high-risk AI inside Annex I products. If the inventory says Annex III, stop and get counsel. --- **Buyer answer.** Article 50 in force since 2 August 2026; high-risk Annex III from 2 December 2027; you disclose AI interaction in-product; legacy marking is scheduled by 2 December 2026. Article 50-type fines can reach €15 million or 3% of worldwide turnover, whichever is higher. As of 27 August 2026 there was no official announcement of a first Article 50 fine or a named investigation against a specific startup. The cheap move is a notice and a screenshot. The expensive move is explaining why you thought 2027 applied to a chatbot. Sources: same official EU pages as the parent brief. This template invents no new duties.