Article 50 operational checklist | Updated August 3, 2026

EU AI Act Transparency Checklist

Triage whether an AI interaction or content workflow needs a user notice, machine-readable marking, a visible label, or documented human review.

Operational planning aid only. Not legal advice, certification, a conformity assessment, or a substitute for qualified review.

4 obligation groups Provider and deployer split Evidence-first workflow
AI policy and workflow planning materials on a digital operations workbench

Four first-pass checks

Classify the workflow before choosing the control.

InteractionDoes AI communicate directly with a person?Providers generally need a clear notice from the start of the first interaction unless the AI nature is obvious.
Synthetic outputDoes the system generate or manipulate content?Providers may need effective machine-readable marking so synthetic audio, image, video, or text can be detected.
Sensitive exposureIs emotion or biometric categorisation used?Deployers must assess the duty to inform natural persons exposed to those systems.
Published contentIs it a deepfake or public-interest text?Deployers must assess clear, perceivable labelling and whether substantive human review or editorial control applies.

Seven-field evidence record

Make each transparency decision reviewable.

Use one row per AI interaction or content workflow. Keep the decision close to the operating system, publishing process, or release record instead of relying on a policy statement alone.

Role Audience Control Owner

Record these fields

One row per workflow or content class
  • System, feature, and business purpose
  • Provider, deployer, and accountable owner
  • People or audience exposed to the system or output
  • Required notice, mark, label, or review control
  • Placement, timing, language, and accessibility method
  • Exception or out-of-scope rationale with source
  • Verification record, approval date, and next review date

Role-specific controls

Turn the legal category into an operating task.

Deployer

Exposure and publication controls

Identify emotion recognition, biometric categorisation, deepfakes, and public-interest publishing workflows.

  • Inform exposed people where required
  • Use clear, perceivable labels rather than relying only on metadata
  • Retain the published version and disclosure evidence
Review

Human-review evidence

For public-interest text, record substantive review and editorial responsibility where that basis is used.

  • Name the reviewer and relevant subject-matter role
  • Record what was checked, changed, approved, or rejected
  • Do not treat spelling or grammar checks as substantive review

Application date and limited grace period

Article 50 applies from August 2, 2026.

The Commission's current FAQ says providers and deployers must comply from that date. It also describes a limited grace period to December 2, 2026 for the machine-readable marking obligation for certain generative AI systems placed on the market before August 2, 2026.

Do not generalize that limited marking transition into a blanket grace period for every Article 50 duty.

Choose the next step

Start self-serve or get a bounded policy draft.

Free

AI policy generator

Generate a first-pass acceptable-use policy with organization, tool, data, approval, and incident fields.

Open Free Generator
$499

Customized policy starter

TinyOps drafts the policy, register, approval workflow, incident rules, and rollout checklist for one small organization.

Buy Policy Starter
Need use-case prioritization and a broader governance roadmap?

Compare the $2,500 diagnostic and $5,000 governance sprint for a bounded readiness and operating-control engagement.

Compare Governance Offers