Article 50 Transparency Guidelines — How the Commission Reads the Rules
The European Commission adopted its guidelines on the Article 50 transparency obligations on 20 July 2026 (C(2026) 5054), less than two weeks before those obligations began to apply on 2 August 2026. The guidelines are not legally binding — only the Court of Justice gives an authoritative reading of the Act — but they set out how the Commission and national authorities intend to apply Article 50. Three points matter most:
AI agents. The guidelines treat AI agents under Article 50(1): where an agent is likely to interact with a natural person, that person must be told they are dealing with an AI system, including when the agent acts on someone else's behalf.
Audio deep fakes. The deep-fake definition in Article 3(60) covers audio as well as image and video, so a synthetic or cloned voice that would falsely appear authentic falls within the Article 50(4) disclosure duty.
A narrower business-to-business carve-out. Strictly technical outputs intended only for a limited, predefined set of professionals remain outside the marking duty, but only where three cumulative conditions are met — including that the output is not meant to be shared outside the organisation. Public and consumer-facing systems cannot rely on it.
What it means for you
If your AI system's outputs leave your organisation, or reach consumers or the public, do not rely on the business-to-business carve-out. If you provide an AI agent that interacts with people, each person it reaches must be told they are dealing with an AI system. These obligations have applied since 2 August 2026.
Sources
- Guidelines on AI transparency obligations C(2026) 5054 — European Commission (20.07.2026)
- EU AI Act Transparency Obligations Take Effect 2 August 2026 — Cooley (03.08.2026)
- EU AI Act Article 50 Transparency Obligations: First Impressions — Bird & Bird (01.08.2026)
EN 18286 — First European Standard Written for the AI Act Published
CEN/CENELEC published EN 18286 on 31 July 2026, titled "Quality management system for EU AI Act regulatory purposes." It addresses the Article 17 quality management system requirements and is the first standard delivered by CEN-CENELEC JTC 21 under the Commission's AI Act standardisation request. EN 18286 is not yet cited in the Official Journal, so complying with it does not currently confer presumption of conformity. Further JTC 21 standards remain in development.
What it means for you
EN 18286 is the first auditable, AI Act-specific quality management framework available to any organisation preparing for Article 17 compliance. Because it is not yet OJ-cited, it cannot be used to claim presumption of conformity; but implementing its controls now builds a documented compliance position ahead of any citation. ISO/IEC 42001 is complementary rather than duplicative: EN 18286 is specific to AI Act quality management obligations; ISO/IEC 42001 is a general AI management system standard.
Sources
- EN 18286 — AI Quality Management standard — CEN/CENELEC (31.07.2026)
- First European standard supporting the AI Act — ANEC (31.07.2026)
GPAI Enforcement — After 2 August, National Readiness Is Uneven
No new enforcement actions were announced in the week ending 7 September 2026. National readiness remains uneven: a number of Member States had still not confirmed their national competent authorities when the Commission's enforcement powers took effect on 2 August 2026. Germany's Bundesnetzagentur confirmed on 29 July 2026 that it takes the central market surveillance role there.
What it means for you
If your organisation is established in a Member State whose authorities are not yet in place, near-term national enforcement is less likely — but that is not a safe harbour. The AI Office enforces the general-purpose AI rules directly, whatever the state of national readiness, and the 2 December 2027 date for Annex III high-risk systems does not move with it.
Sources
- Commission starts enforcing AI Act rules and new transparency requirements — 2 August 2026 — European Commission (02.08.2026)
- EU AI Act Enforcement Phase Begins — Wilson Sonsini (01.08.2026)
- Bundesnetzagentur takes on key role in AI Act implementation — Bundesnetzagentur (29.07.2026)
ISO/IEC 42001 — No Material Change
ISO/IEC 42001:2023 remains the current edition. The "EN ISO/IEC 42001:2026" designation appearing in some national standards body catalogues is a European transposition — adoption without substantive change — not a new edition; requirements are identical to the 2023 standard. ISO/IEC 42001 does not currently confer AI Act presumption of conformity; no Official Journal citation has been issued. ISO/IEC 42006:2025 (requirements for bodies providing ISO/IEC 42001 certification) enables third-party certification pathways but introduces no new substantive obligations for implementing organisations.
What it means for you
Nothing to change this week. If you are pursuing certification, ISO/IEC 42006:2025 is the standard your certification body should be accredited against. ISO/IEC 42001 does not confer presumption of conformity under the AI Act — no Official Journal citation has been issued.
Sources
- ISO/IEC 42001:2023 — ISO (18.12.2023)
- ISO/IEC 42006:2025 — ISO (08.07.2025)
DPC Ireland — HSE Enforcement Decision: €645,000 Fine
Ireland's Data Protection Commission published its final decision in the Health Service Executive inquiry on 2 September 2026, imposing a €645,000 fine across four violations: Article 5(1)(f)/32(1) (security), Article 5(1)(e) (storage limitation), Article 33(1) (breach notification), and Article 34(1) (communication to data subjects). The DPC is simultaneously the lead supervisory authority under the one-stop-shop mechanism for several major AI providers. The decision confirms active GDPR enforcement position going into Q4 2026.
What it means for you
Breach notification readiness (Article 33) and data storage limitation (Article 5(1)(e)) — two of the four violation grounds — are obligations frequently undermined by AI system deployments where logs, inference outputs, and training data are retained without explicit retention schedules. If your organisation uses AI systems that generate or process personal data, review whether your data retention schedules, breach notification workflows, and security controls remain adequate for the additional data volumes and categories that AI introduces.
Sources
- Data Protection Commission: Final Decision following inquiry into the Health Service Executive (HSE) — Data Protection Commission Ireland (02.09.2026)
EDPB Guidelines 02/2026 and 03/2026 — Anonymisation and Web Scraping for Generative AI (Consultation Open Until 30 October 2026)
The EDPB adopted two sets of guidelines at its plenary on 7 July 2026 that bear directly on AI:
Guidelines 02/2026 on Anonymisation (adopted 7 July 2026): Establishes a three-criteria test — isolation, linkage, inference — for assessing whether data is truly anonymised. AI re-identification tools must be assessed as part of the anonymisation risk evaluation. Generative AI outputs that "describe, reproduce, or could be traced back to" a natural person may themselves constitute personal data, even if no original personal data was input. Consultation closes 30 October 2026.
Guidelines 03/2026 on Web Scraping for Generative AI (adopted 7 July 2026): Confirms GDPR applies in full to training-data scraping regardless of technical access method. robots.txt compliance is explicitly not a GDPR safe harbour. Special-category data embedded in scraped text must be identified and handled under Article 9. Data accuracy obligations (Article 5(1)(d)) require timestamping and source recording for training datasets. Consultation closes 30 October 2026.
What it means for you
If your organisation uses AI to process personal data and assumes outputs are anonymised, the 02/2026 three-criteria test is likely stricter than your current assessment. If you have built an AI system using a model trained on scraped data, or you are a downstream system provider (Article 3(3)) building on such a model, the 03/2026 guidelines are the governing framework for your training-data lineage documentation. "Legitimate interests" under Article 6(1)(f) is not straightforwardly available as the lawful basis for scraping publicly available personal data for AI training.
Sources
- Guidelines 02/2026 on Anonymisation — public consultation — EDPB (07.07.2026)
- Guidelines 03/2026 on Web Scraping in the Context of Generative AI — public consultation — EDPB (08.07.2026)
- What Do the EDPB's Web Scraping Guidelines Mean for AI Training Datasets? — Sidley (23.07.2026)
- EDPB adopts guidelines on anonymous data, web scraping, and blockchain — Hunton Andrews Kurth (08.07.2026)
Belgian APD — GDPR Findings on AI Chatbot Deployments
The Belgian Data Protection Authority (APD) published investigative findings in May 2026 on GDPR compliance in AI chatbot deployments. Key findings: (a) free-text input fields routinely capture special-category data (health information, political opinion) without adequate safeguards; (b) data minimisation failures are structural — most deployments collect and log far more data than necessary; (c) transparency to data subjects about use of inputs for retraining is systematically absent; (d) a Data Protection Impact Assessment (DPIA) is required before deploying any AI chatbot that processes personal data.
What it means for you
If your organisation has deployed an AI chatbot or AI assistant that accepts free-text input, the Belgian findings suggest you may be processing special-category data under Article 9 GDPR without having assessed it. A DPIA is a legal requirement before processing likely to result in a high risk to natural persons, and the APD's view is that free-text chatbots will often meet that threshold. "High risk" is not a self-assessment; it derives from the nature of the processing.
Sources
- Europe Data Protection: July 2026 — Belgian APD chatbot investigation findings — Gibson Dunn (01.07.2026)
- A View from Brussels: A Sneak Peek into Upcoming Guidelines on GDPR-AI Act Interplay — IAPP (01.08.2026)
What to do this week
- Review every surface where your AI system outputs reach natural persons (even via a professional intermediary); add a minimum-viable Article 50 disclosure block (AI nature, human review availability) where one is absent.
- If you provide an AI agent that interacts with people, make sure each person it reaches is told they are dealing with an AI system — Article 50(1) has applied since 2 August 2026.
- Obtain EN 18286 from your national standards body (NSAI in Ireland, BSI in UK, DIN in Germany, AFNOR in France) and map its quality management controls against your AI systems' Article 17 obligations.
- Check whether your organisation has conducted a DPIA for each AI system that processes personal data, including AI chatbots and assistants that accept free-text input; if not, initiate one.
- Review data retention schedules for AI system logs, inference outputs, and any training data; set documented storage limitation deadlines.
- Apply EDPB Guidelines 02/2026 anonymisation criteria: if you rely on anonymisation as a lawful basis for AI-related data processing, test your data against the isolation-linkage-inference framework.
- Request training-data provenance documentation from your GPAI model provider and record it; this is your Article 5(1)(d) data accuracy due diligence under Guidelines 03/2026.
- Submit a response to the EDPB consultations on Guidelines 02/2026 and 03/2026 before 30 October 2026 if your organisation has operational experience with AI anonymisation or training data practices.
Quick reference
| Topic | Change | Action |
|---|---|---|
| EU AI Act — Art. 50 | Commission Guidelines C(2026) 5054 (20 Jul): AI agents within Art. 50(1); audio deep fakes; narrower business-to-business carve-out | Audit where AI output reaches people; add disclosures, including for AI agents |
| EU AI Act — Standards | EN 18286 published 31 July 2026; no OJ citation yet; not presumption of conformity | Obtain from national standards body; map to Art. 17 obligations |
| EU AI Act — GPAI | National authority designations still uneven after 2 Aug 2026 | Map operations by jurisdiction; note AI Office has direct jurisdiction independent of national MSAs |
| ISO/IEC 42001 | No material change; 2023 standard current; no OJ citation | No immediate action |
| GDPR — Enforcement | DPC Ireland HSE €645,000 fine (2 Sept 2026): breach notification + storage limitation | Review AI system data retention schedules; verify breach notification readiness |
| GDPR — Guidelines | EDPB 02/2026 (anonymisation) + 03/2026 (web scraping): consultation closes 30 Oct 2026 | Update anonymisation assessments; add training-data lineage documentation; consider consultation submission |
| GDPR — Chatbots | Belgian APD: DPIA required before AI chatbot deployment; free-text input = special-category risk | Add DPIA to AI chatbot deployment checklist; review existing deployments |
Every source in this issue
- Guidelines on AI transparency obligations C(2026) 5054 — European Commission (20.07.2026)
- EU AI Act Transparency Obligations Take Effect 2 August 2026 — Cooley (03.08.2026)
- EU AI Act Article 50 Transparency Obligations: First Impressions — Bird & Bird (01.08.2026)
- EN 18286 — AI Quality Management standard — CEN/CENELEC (31.07.2026)
- First European standard supporting the AI Act — ANEC (31.07.2026)
- Commission starts enforcing AI Act rules and new transparency requirements — European Commission (02.08.2026)
- EU AI Act Enforcement Phase Begins — Wilson Sonsini (01.08.2026)
- EU AI Omnibus Enters Into Force: Amending the AI Act — White & Case (15.07.2026)
- EU AI Act Update: Digital Omnibus Finalizes 8 Compliance Changes — Orrick (15.07.2026)
- EU AI Act Unpacked #34: The Final Digital Omnibus on AI — Freshfields (15.07.2026)
- High-Risk AI Classification Guidelines — 6 July 2026 — European Commission (06.07.2026)
- GPAI Provider Guidelines — 28 April 2026 — European Commission (28.04.2026)
- ISO/IEC 42001:2023 — ISO (18.12.2023)
- ISO/IEC 42006:2025 — ISO (08.07.2025)
- DPC Ireland — HSE Final Decision — Data Protection Commission Ireland (02.09.2026)
- Bundesnetzagentur takes on key role in AI Act implementation — Bundesnetzagentur (29.07.2026)
- Guidelines 02/2026 on Anonymisation — EDPB (07.07.2026)
- Guidelines 03/2026 on Web Scraping in the Context of Generative AI — EDPB (08.07.2026)
- EDPB 2026 Coordinated Enforcement Framework (transparency) — EDPB (01.11.2025)
- What Do the EDPB's Web Scraping Guidelines Mean for AI Training Datasets? — Sidley (23.07.2026)
- EDPB adopts guidelines on anonymous data, web scraping, and blockchain — Hunton Andrews Kurth (08.07.2026)
- Anonymous or not? EDPB's new draft guidelines on anonymisation — Freshfields (08.07.2026)
- Europe Data Protection: July 2026 — Belgian APD chatbot findings — Gibson Dunn (01.07.2026)
- A View from Brussels: GDPR-AI Act Interplay — IAPP (01.08.2026)
Compiled by Relay Labs Ltd from the sources above, which remain the authoritative text. General information about EU law, not legal advice.
The EU AI governance brief
One email a week. Sourced and dated. Unsubscribe in one click, from any of them.
Relay Labs Ltd is the controller. Your address is used to send you this brief and nothing else. Privacy notice.