Article 50 Transparency: the marking duty is a provider duty, so it misses us. The text-labelling duty is a deployer duty, and it lands on Sanity Check.
Not legal advice. This is an operational read of primary text by a non-lawyer. Anything that would change a shipping surface should get a lawyer's eyes before it becomes policy.
The question
Verbatim: "What does the Commission's ADOPTED Article 50 transparency guidelines document (published 20 July 2026) actually require, and does the Article 50(2) machine-readable marking duty reach RDCO's own published surfaces - Sanity Check, the rdco.dev sites, and agent-generated artifacts?"
Context: the AI Act thread has flagged the Article 50(2) marking duty twice as an untested "assumed no" without ever testing it. This is the first pass that tests it against operative text and against the adopted guidance.
Answer, up front
Premise: CONFIRMED. The document exists, is adopted, is final, and applies now.
| Claim | Verdict | Evidence tier |
|---|---|---|
| Guidelines published 20 July 2026, adopted, final, non-binding | TRUE | VERIFIED-FROM-PRIMARY (C(2026) 5054 final, 51pp, fetched and read) |
| Article 50 applies from 2 August 2026 | TRUE | VERIFIED-FROM-PRIMARY (consolidated Art. 113, second para; not carved out by points (a)-(d)) |
| Article 50(2) machine-readable marking reaches RDCO's published surfaces | FALSE | VERIFIED-FROM-PRIMARY (Art. 50(2) binds providers; guidelines ¶13 lists deployer duties as 50(3) and 50(4) only) |
| Article 2 territorial scope moots the question for a Florida company | FALSE | VERIFIED-FROM-PRIMARY (Art. 2(1)(c) + guidelines ¶13: posting on the globally accessible internet counts as foreseeing use in the Union) |
| Something on a shipping RDCO surface needs to change | TRUE, one thing | VERIFIED-FROM-PRIMARY (guidelines ¶138: publicly findable editorial-responsibility statement) |
The two-line version: the marking duty everybody worries about is the wrong duty to worry about. RDCO is a deployer, not a provider, so Article 50(2) never attaches. Article 50(4) second subparagraph does attach, Sanity Check meets its elements, and the editorial carve-out that saves us has a publication requirement we do not currently satisfy.
What we already know (from the vault)
- [[2026-08-26-ai-act-article-6-classification-guidelines]] verified the Commission's library listing for a 20 July 2026 item titled Guidelines on transparency obligations for providers and deployers of AI systems and tagged it "adopted... final... applies now" - but the listing only. The document itself was never fetched or read. This brief closes that gap.
- [[2026-08-21-ai-act-article-113-operative-text-check]] surfaced new Article 111(4): generative systems on the market before 2 August 2026 get until 2 December 2026 for Article 50(2), and flagged the marking duty as "the more plausible contact point given Sanity Check and published sites."
- [[2026-08-02-agents-as-employees-regulatory-labor-framing]]: "The genuine near-term obligation is transparency, and it lands in days, not years. Article 50 goes live 2 August 2026 (today) unchanged by the Omnibus." Directionally right, one detail wrong - see the correction below.
- [[2026-08-27-ai-act-113-3c-registration-deferral-gap]] established that the private-sector Annex III question is a provider-side question. The same asymmetry runs through Article 50, in our favour this time.
- Nothing in the vault has ever discussed Article 2. Four passes into this thread, nobody asked whether the Regulation reaches a Florida company at all. That gap is closed below, and the answer is not the comfortable one.
What the web says
- The adopted instrument is C(2026) 5054 final, ANNEX - Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689, dated Brussels, 20.7.2026, 51 pages, 9 sections. Fetched directly from the Commission newsroom document store.
- The guidelines are non-binding; only the CJEU gives authoritative interpretation. National market surveillance authorities and the AI Office can be expected to follow them (Bird & Bird, first-impressions note).
- Article 50(2) rests with the provider of the AI system that generates the content, not the provider of an upstream model, and not the deployer. Hosting providers, platforms and broadcasters who merely disseminate are expressly not deployers (McCann FitzGerald Part 1, reporting the guidelines).
- The Code of Practice on Transparency of AI-Generated Content was published 10 June 2026 and has been assessed as adequate by the Commission - the guidelines call it "the only Union-wide recognised practical framework" for demonstrating compliance with 50(2) and 50(4). Deployers can sign it, not just providers. ~190 organisations signed by late July 2026.
- Penalties for Article 50 non-compliance: up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher, with SME/startup fines capped at the lower of the two. Art. 99 routes Article 50 breaches through Art. 79(6)(d).
- The guidelines expanded the 50(2) carve-outs versus the May draft: AI translation moved into "standard editing"; short outputs (single words, captions, alt-text, UI labels) are out of scope entirely; source code and configuration are out, defined broadly. AI-generated summaries and substantive rewrites still require marking - on the provider, not us.
Convergences and contradictions
- Convergence, and the key one: operative text, the guidelines, and both law-firm reads agree that 50(2) is a provider duty and 50(4) is the deployer duty, and that the two are non-substitutable. Machine-readable marking does not satisfy the perceivable-disclosure duty, and a visible label does not satisfy the marking duty. The vault's "assumed no" on 50(2) is now tested and confirmed - but for a reason nobody in the thread had identified. It is not that the content is out of scope. It is that the role is wrong.
- Contradiction with the vault: [[2026-08-02-agents-as-employees-regulatory-labor-framing]] says Article 50 is "unchanged by the Omnibus." Article 50(1)-(6) is indeed unchanged (consolidated text carries the base marker throughout). Article 50(7) was replaced by the Omnibus: the facilitation role moved from the AI Office to the Commission, and "may adopt implementing acts to approve those codes" became "shall assess whether adherence to those codes of practice is adequate," taking utmost account of the Board's opinion. Plus new Article 111(4). Minor, but the claim as written is not accurate.
- Contradiction with the backlog premise: the entry framed this as a 50(2) question. 50(2) is the one paragraph in Article 50 that structurally cannot reach us. The live exposure is 50(4), which the thread had never raised.
The operative text that drives each verdict
Article 50(2) (unchanged by the Omnibus):
"Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated."
Article 50(4), second subparagraph (unchanged):
"Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest shall disclose that the text has been artificially generated or manipulated. This obligation shall not apply ... where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content."
Guidelines ¶13 (the deployer scope sentence, and the territorial answer):
"Deployers fall within the scope of the transparency obligations in Article 50(3) and (4) AI Act if their place of establishment or location is within the Union, or if they are established or located in a third country where the output of the AI system is used in the Union. In the latter case, the transparency obligations apply to entities located or established outside the Union where the deployer itself foresees dissemination and use of the AI outputs in the Union (i.e. by directing or authorising distribution within the Union, including by posting deep fakes on the globally accessible internet). However, third country deployers are not bound by the transparency obligations where the content of the AI system reaches audiences in the Union through channels that are unforeseeable and outside their control."
Two things follow. First, the enumeration is closed: a deployer's Article 50 duties are 50(3) and 50(4). 50(2) is not on the list. Second, "posting on the globally accessible internet" is enough to foresee use in the Union. There is no targeting requirement, no EU-nexus threshold, no de-minimis. Territorial scope does not moot this. A public rdco.dev page and a newsletter that any EU resident can subscribe to both clear the bar. The softening language about "incidental, unforeseeable or unauthorised downstream use" appears in ¶10, and ¶10 is about providers.
Guidelines ¶131 (what "matters of public interest" means):
"such matters should be understood to cover those relevant to society at large, whether at a local, national, Union or international level, and meriting public debate or scrutiny ... texts should be considered to address public interest matters if they cover topics on politics and democratic processes, public administration and services, the administration of justice and law enforcement, the protection of fundamental rights, public security, public health, environmental protection, consumer safety, and any economic, financial, political, scientific, or cultural development that may be relevant subject of public debate."
And the express out-of-scope example in the same paragraph:
"AI-manipulated text that is part of a company's advertisement or product descriptions (not including any claims related to e.g. health, consumer safety or sustainability)."
Plus, also out of scope: "AI-manipulated text by a consultant for a client advice regarding measures to be taken for regulatory compliance." Client deliverables are safe twice over - they are not "published" under ¶131(i) either, which excludes "organisation-internal texts" and anything restricted to a closed group.
Guidelines ¶134-¶138 (the editorial carve-out, both cumulative conditions):
"Human review refers to the deliberate examination of the substance of the content by one or more natural persons possessing relevant knowledge and professional judgement pertaining to the subject matter under scrutiny ... Fact-checking the accuracy of the content is a minimum requirement that should be part of that review."
"Superficial, solely formal or procedural checks (e.g. spell-checking or grammatical correction), the mere existence of an editorial policy, automated review processes or cursory editorial approval without substantive engagement ... cannot fulfil the conditions."
"Where AI systems are used to modify, supplement, or reformulate content following editorial sign-off ... Any substantive AI intervention occurring after the human review or editorial control process has taken place will therefore cause the exception to become void."
"the identity and contact details of the legal person, the natural person or the function with editorial responsibility should be made publicly available on an easily findable location (if not yet otherwise available). This can happen online through e.g. a website's terms and conditions or other user-facing legal information."
Per-surface verdict
| Surface | 50(2) marking | 50(4) 1st subpara (deep fakes) | 50(4) 2nd subpara (public-interest text) |
|---|---|---|---|
| Sanity Check newsletter | OUT - provider duty | OUT at current aesthetic | IN on the elements. Carve-out available but not yet satisfied. ACTION REQUIRED. |
| rdco.dev marketing / product sites | OUT - provider duty | OUT at current aesthetic | OUT - advertisement and product-description example |
| Generated artifacts / lead magnets | OUT - provider duty | OUT at current aesthetic | SPLIT - promotional out; analytical/commentary pieces in on the elements, same carve-out |
| Narrated audio + mascot video | OUT - provider duty | UNCERTAIN for the synthetic narration voice; mascot animation out | n/a |
| Any public chatbot/agent RDCO ships | role flips to provider - IN, plus 50(1) | - | - |
Sanity Check. All three elements of ¶131 are met. Published: a subscription newsletter reaches "an indeterminate, fairly large number of unrelated, potential readers ... whether or not against payment (e.g. subscriptions)" - the guidelines say so explicitly. Informing the public: it communicates knowledge and opinions, and it is long-form, not the "short texts which do not materially communicate knowledge" exclusion. Matters of public interest: agentic AI and its effect on data work is an "economic ... or scientific development that may be relevant subject of public debate." I am reading this as in-scope rather than out. It is not the advertisement example - the vault's own editorial standard, adopted from Data Engineering Weekly, explicitly excludes "content published primarily to promote a product, platform, or company," which is precisely the line that keeps Sanity Check out of the advertisement carve-out and therefore in scope.
Then the carve-out. Condition (i), human review, is almost certainly met in substance - the founder writes and substantively edits, and /draft-review plus the fact-checking pass go well beyond "cursory editorial approval." Condition (ii), editorial responsibility, is met in substance too: Ray Data Co LLC and Ben Wilson hold it. What is missing is the publication requirement in ¶138 - the identity and contact details of the person or function holding editorial responsibility must be publicly available in an easily findable location. A byline is not obviously that; ¶138 points at terms and conditions or user-facing legal information.
There is a second, sharper exposure in ¶136: any substantive AI intervention after editorial sign-off voids the exception entirely. The /remix pipeline generates LinkedIn and X derivatives from published issues, and those are separate publications with their own sign-off. But if any agent step substantively rewrites an approved Sanity Check issue between founder approval and send, the carve-out is gone for that issue.
rdco.dev sites. Marketing and product pages land on the guidelines' express out-of-scope example. Two carve-out-to-the-carve-out watch items: claims about health, consumer safety or sustainability pull an advertisement back into scope, and any rdco.dev property that is editorial rather than promotional shifts toward in-scope-on-elements and then depends on the same ¶138 publication step.
Generated artifacts and lead magnets. The MAC info-product and similar sales assets read as product descriptions and are out. A lead magnet that is genuinely analytical commentary on an economic or technical development is in on the elements, and needs the same editorial-responsibility line. Client deliverables are out on two independent grounds.
Images, video, audio. The RDCO house aesthetic is hand-drawn, engraving, glitch and Memphis - deliberately non-photoreal. The guidelines' fourth criterion asks whether content "would falsely appear to a person to be authentic or truthful," assessed holistically against the foreseeable audience, and add that "where the audience does not expect content to be authentic in a given context, the content may fall outside the definition even though it is synthetic." A doodle mascot fails the test comfortably. Two live trip-wires: photorealism "makes deep fake status more likely but is not determinative," and an invented-but-photorealistic person is still in scope, so any move toward generated headshots, testimonial avatars or product photography flips this. And the synthetic narration voice is genuinely uncertain - ¶113(iii) reads "persons" to include "personal characteristics or expressions, such as image, voice, behaviour, performances." A stock synthetic voice narrating an explainer probably fails the fourth criterion because nobody is being led to believe a specific real person is speaking, but I would not call that settled.
The role trip-wire, which is the real one. Guidelines ¶11 gives as an example of a provider: "a company or another organisation ... that has developed an interactive AI system (e.g. chatbot) in-house and puts it into service in the Union for its own use and under its name or trademark." And ¶11 again: taking an existing generative system, modifying it, and putting it into service under your own name makes you the provider of the new system. RDCO ships agent-built software. The day a public-facing RDCO chatbot or agent surface goes live to EU-reachable users under the RDCO name, the role changes, and 50(1) and 50(2) both attach - including the machine-readable marking duty this brief just cleared us of.
What would actually have to change
One thing on a shipping surface, and it is small:
- Publish an editorial-responsibility statement naming the legal or natural person holding editorial responsibility for Sanity Check, with contact details, in an easily findable place (newsletter footer, sc.raydata.co terms/legal page, or both). This is the only ¶138 element we do not currently satisfy, and it is the thing standing between us and the carve-out. Low cost, no design change, no content change.
Two things that are policy rather than surface changes:
- Do not let agents substantively rewrite an issue after founder sign-off. ¶136 voids the exception. The founder-approves-then-Ray-posts pattern is fine as long as the post is the approved text. Any post-approval substantive rewrite needs to be a new review.
- Watch the role line. Treat "RDCO ships a public AI interaction surface under its own name" as the event that changes our classification, not as a product decision only.
Not required, worth knowing: RDCO could sign the Code of Practice on Transparency of AI-Generated Content. Deployers are eligible, it has been assessed as adequate, and the guidelines call it the only Union-wide recognised framework for demonstrating compliance. It is not necessary, since the carve-out is available on its own, but ¶137 specifically flags the code as a route for "deployers that are not media service providers subject to existing editorial professional or deontological standards" - which is exactly what a one-person newsletter is.
Nothing retroactive. Guidelines ¶154: content generated before 2 August 2026 does not need to be marked or labelled retroactively. For public-interest text the cut-off is date of publication, not generation, so anything written before 2 August but published after it is in scope.
Synthesis for RDCO
The thread has been chasing the wrong paragraph for three briefs. Article 50(2) was flagged twice as the plausible contact point with published RDCO output, on the intuition that a marking duty attaches to marked content. It does not. It attaches to the person who built the generator. Anthropic, OpenAI, ElevenLabs and Kling owe that duty on their outputs; RDCO owes nothing under 50(2) and would not owe anything even if every word we published were machine-generated. The role classification did all the work, and the role classification was never checked. That is the reusable lesson: in this Regulation, "who are you" resolves more questions than "what did you publish," and the thread's habit of reasoning from subject-matter scope has now missed the answer twice in the same direction.
The corollary is uncomfortable in the other direction. Article 2 does not save us. The instinct that a Florida LLC is outside a European regulation is wrong on the text and wrong on the guidance, and the guidance is broader than the text - "posting on the globally accessible internet" as sufficient evidence of foreseeing use in the Union collapses the territorial filter for anything published on the open web. Bird & Bird's read is that this makes it "challenging to shield online content ... unless some form of geo-blocking can be applied." We are not going to geo-block Sanity Check. So we are inside the scope of a European transparency regime, today, on a shipping surface, and the only thing standing between us and a labelling obligation is an editorial carve-out we qualify for in substance but have not documented in form.
That is a genuinely good position to be in, and it is worth naming why. The carve-out rewards exactly the thing RDCO already does: a human who substantively engages with the content, fact-checks it, and takes named responsibility for publishing it. The founder-approves-then-Ray-posts pattern is not just a taste preference or a trust boundary. It is, as of 2 August 2026, the compliance architecture for the newsletter. The IC-mode versus production-mode distinction and the "content: founder approves, Ray posts" rule are load-bearing in a way nobody designed them to be. The failure mode that would break it is precisely the one the guidelines call out in ¶136 - an agent making a substantive edit after sign-off - which is also the failure mode our own workflow-integrity memory already warns about under a different name.
For positioning, there is a small sellable asset here that did not exist a week ago. Every consultancy and content shop publishing agent-assisted analysis to a globally accessible audience is now in the same position RDCO is, and almost none of them know it, because the coverage has been about the marking duty and the marking duty is not theirs. "Your AI-assisted content is fine, and here is the two-line thing you need on your site to keep it fine" is a real, specific, checkable claim, and it is the kind of narrow concrete finding that reads as competence rather than fear-selling. It is not a service line. It is a paragraph in a Sanity Check issue with a legitimate original re-frame: the regulation everybody read as a technology requirement is actually an editorial-accountability requirement, and the companies that will fail it are the ones that removed the human from the last step.
Why this is in the vault
This is the first item in the AI Act thread that produces a concrete change to a shipping surface: Sanity Check needs a publicly findable editorial-responsibility statement to hold its Article 50(4) carve-out, and the post-sign-off no-substantive-AI-edit rule now has a regulatory reason attached to it, not just a quality reason. It also closes the "assumed no" on Article 50(2) that [[2026-08-21-ai-act-article-113-operative-text-check]] and [[2026-08-26-ai-act-article-6-classification-guidelines]] both left open, and corrects the unexamined assumption running through the whole thread that a US-based company is outside the Regulation's territorial reach.
Open follow-ups
- Does Sanity Check have any EU-resident subscribers, and does it matter? Under guidelines ¶13 the trigger is the deployer foreseeing dissemination in the Union, not actual EU readership, so the answer is probably "it does not matter." Not filed as a research question because it is a list query, not research.
- Whether the synthetic narration voice used in RDCO audio and video meets the Article 3(60) "would falsely appear to a person to be authentic or truthful" test. Genuinely unresolved on the primary text; the guidelines address the criterion but give no voice-specific example.
- Whether other Union transparency instruments (DSA, the Political Advertising Regulation, the European Media Freedom Act) impose overlapping labelling duties that the Article 50 carve-out does not reach. Guidelines sections 3.3, 4.4, 6.1.5 and 6.2.5 all cover "interplay with other Union legal acts" and were not read in this pass.
Related
- [[2026-08-26-ai-act-article-6-classification-guidelines]]
- [[2026-08-21-ai-act-article-113-operative-text-check]]
- [[2026-08-27-ai-act-113-3c-registration-deferral-gap]]
- [[2026-08-02-agents-as-employees-regulatory-labor-framing]]
- [[2026-08-23-ai-act-annex-iii-employment-entries]]
- [[2026-08-15-eu-digital-omnibus-ai-official-journal-check]]
- [[2026-04-15-data-engineering-weekly-editorial-scope-context-engineering]]
Sources
Primary
- Regulation (EU) 2024/1689 (AI Act), original OJ text. CELEX 32024R1689, fetched via Cellar content negotiation:
curl -H 'Accept: application/xhtml+xml' -H 'Accept-Language: eng' http://publications.europa.eu/resource/celex/32024R1689(200, 1,262,391 bytes). Articles 2, 50, 99, 111, 113; recitals 133, 134. - Consolidated AI Act as amended by the Digital Omnibus, CELEX 02024R1689-20260727, same route (200, 851,286 bytes). Confirms Art. 50(1)-(6) unamended, Art. 50(7) replaced (M1), Art. 111(4) new (M1), Art. 113 points (a), (c), (d) amended (M1).
- European Commission, C(2026) 5054 final, ANNEX - Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689, Brussels, 20.7.2026, 51pp. https://ec.europa.eu/newsroom/dae/redirection/document/131215 - paragraphs 10-14, 71-74, 113, 131-138, 146-147, 153-154.
- European Commission, Guidelines on transparency obligations for providers and deployers of AI systems, Shaping Europe's digital future library listing. https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems
- European Commission, Code of Practice on Transparency of AI-generated Content (published 10 June 2026). https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
Secondary
- Bird & Bird, European Commission adopts final Guidelines on AI Act Article 50 transparency obligations - first impressions (2026). https://www.twobirds.com/en/insights/2026/european-commission-adopts-final-guidelines-on-ai-act-article-50-transparency-obligations-first-impr - HTTP 402 to WebFetch; retrieved via curl with a browser User-Agent.
- McCann FitzGerald, AI Transparency: European Commission's Guidelines on Article 50, Parts 1 (Provider Obligations) and 2 (Deployer Obligations). https://www.mccannfitzgerald.com/knowledge/data-privacy-and-cyber-risk/ai-transparency-european-commissions-guidelines-on-article-50-part-1-provider-obligations
Vault
~/rdco-vault/06-reference/research/2026-08-26-ai-act-article-6-classification-guidelines.md~/rdco-vault/06-reference/research/2026-08-21-ai-act-article-113-operative-text-check.md~/rdco-vault/06-reference/research/2026-08-27-ai-act-113-3c-registration-deferral-gap.md~/rdco-vault/06-reference/research/2026-08-02-agents-as-employees-regulatory-labor-framing.md~/rdco-vault/06-reference/research/2026-08-23-ai-act-annex-iii-employment-entries.md~/rdco-vault/06-reference/2026-04-15-data-engineering-weekly-editorial-scope-context-engineering.md
Method note. The Cellar content-negotiation route recommended in the backlog entry worked first try on both CELEX documents; the EUR-Lex front end was not attempted. The guidelines PDF was downloaded and converted locally with pdftotext -layout rather than passed to WebFetch, which avoids the summarisation-horizon failure [[2026-08-21-ai-act-article-113-operative-text-check]] flagged for long legal documents. Every paragraph quoted above is from the PDF itself, not from a law-firm characterisation of it - the two residual gaps the secondary sources could not fill ("matters of public interest" and non-photorealistic imagery) were both answered from primary text.
Assumptions labelled as such. (a) That Sanity Check's subject matter qualifies as "an economic ... or scientific development that may be relevant subject of public debate" - I read it as in-scope, but a reasonable reader could put a data-engineering trade newsletter on the other side of that line, and the guidelines give no trade-press example either way. (b) That the founder's editing of Sanity Check constitutes "deliberate examination of the substance ... fact-checking the accuracy of the content" per ¶134 - I believe it does, but I have not audited an actual issue's review trail against that standard. (c) That RDCO currently ships no public-facing AI interaction surface under its own name to EU-reachable users. A grep across the vault's project notes surfaced no deployed chatbot or embedded-assistant widget, only newsletter copy discussing them, but that is not an audit of the live properties. If any rdco.dev site has an embedded chatbot, the provider analysis changes and this brief's headline verdict does not hold for that property.