AI transparency obligations are the duties imposed by Article 50 of Regulation (EU) 2024/1689. They apply to whoever develops or uses artificial intelligence systems. They have been enforceable since 2 August 2026. Breaching them can cost up to 15,000,000 euros or 3 % of worldwide turnover.
The Digital Omnibus on AI Regulation, published on 24 July 2026, postponed the obligations for high-risk systems. It did not touch Article 50. Many recent headlines have suggested that every company must now label the content it generates with AI. That is not the case. The real allocation depends on whether your company acts as a provider or as a deployer. That distinction completely changes what you have to do.
If you need an AI lawyer in Spain for your business, request a free initial assessment.
On 2 August 2026 the transparency obligations in Article 50 of the AI Act became enforceable. They cover four situations. Systems that interact with natural persons, the generation of synthetic content, emotion recognition and biometric categorisation, and deepfakes. The Digital Omnibus did not postpone any of them.
Regulation (EU) 2026/1744 of 8 July 2026 was published in the Official Journal on 24 July. It came into force on 27 July 2026. It changed the AI Act timeline on several points. In Article 50 it only amended paragraph 7, on codes of practice. The substance of the obligation was left intact.
It did introduce a significant transitional regime. The new Article 111(4) covers providers of generative systems already placed on the market before 2 August 2026. It gives them until 2 December 2026 to comply with the marking requirement in Article 50(2). It is extra time for the system provider, not for the company that uses it.
A provider is whoever develops an AI system and places it on the market under its own name or trademark. A deployer is whoever uses it under its authority in a professional activity. The vast majority of Spanish companies working with AI are deployers, not providers.
The difference is not academic. Article 50 assigns very different burdens to each. Confusing them leads to two opposite mistakes, taking on obligations that are not yours or ignoring those that are.
| Obligation | Provider | Deployer |
|---|---|---|
| Disclose that people are interacting with an AI (Art. 50(1)) | Yes, through the system’s design | No |
| Machine-readable marking of synthetic content (Art. 50(2)) | Yes | No |
| Inform people in emotion recognition and biometric categorisation (Art. 50(3)) | No | Yes |
| Disclose a deepfake (Art. 50(4)) | No | Yes |
| Disclose generated text on matters of public interest (Art. 50(4)) | No | Yes, with exceptions |
A company can be both at once. If you integrate a third-party model into your product and market it under your brand, you act as the provider of that system. It makes no difference that you did not train the model.
The duty to label content does not fall generally on the company that uses AI. Article 50(2) requires the provider to apply machine-readable technical marking. Article 50(4) only requires professional users to act in two cases. Deepfakes and text published to inform the public on matters of public interest.
The text of Article 50 separates four scenarios that should not be mixed up.
The fourth scenario is the one generating the most attention and the one that has been explained worst. A corporate blog post, a product page or a commercial newsletter do not fall within Article 50(4). They do not inform the public on matters of public interest.
Article 50(4) itself switches off the obligation when AI-generated content has undergone human review or editorial control. A natural or legal person must also hold editorial responsibility for the publication. It is the exception that leaves companies the most room and the one almost no headline mentions.
Its scope has limits. It only works for text, not for image, audio or video deepfakes. And it requires a real review with an identifiable person responsible, not a generic line in the footer. Documenting who reviews and on what criteria is what makes the exception defensible.
There is an additional adjustment for creative works. Where the content is part of an evidently creative, satirical, artistic or fictional work, disclosure is limited to flagging its existence. It must be done in a way that does not hamper the enjoyment of the work.
Take a Spanish SaaS scaleup with 60 employees. It publishes two articles a week drafted with an AI assistant and reviewed by its head of content. It has a support chatbot built on a third-party model and integrated into its platform. And it generates synthetic images for social media.
The analysis gives three different answers. The blog articles do not require labelling, because they are corporate content and there is human review with an identified person responsible. The chatbot does trigger the obligation. The company offers it under its own brand and acts as the provider of that system. It must tell users they are talking to an AI. The social media images require no disclosure as long as they do not impersonate an identifiable person.
Of three fronts the company assumed were problematic, only one was. The confusion tends to arise at the same point. People assume that using AI triggers the obligation. What triggers it is the role you play and the type of content you publish.
Article 99(4)(g) of the AI Act penalises breaches of the transparency obligations in Article 50. The fine reaches 15,000,000 euros or 3 % of worldwide turnover for the preceding financial year. The percentage only applies when the infringer is an undertaking. Whichever amount is higher applies.
| Case | Maximum amount | Basis |
|---|---|---|
| Prohibited AI practices | €35,000,000 or 7 % | Art. 99(3) |
| Transparency obligations in Article 50 | €15,000,000 or 3 % | Art. 99(4)(g) |
| Incorrect information to authorities or notified bodies | €7,500,000 or 1 % | Art. 99(5) |
| SMEs and start-ups | The lower amount applies | Art. 99(6) |
Article 99(6) changes the order of magnitude for much of the Spanish business landscape. For SMEs and start-ups the fine is calculated on whichever of the percentage or the amount is lower, not higher. The Digital Omnibus added a paragraph 6a that extends that criterion to small mid-cap companies.
Spain has not passed the law that confers sanctioning powers on AI matters. The Organic Law bill on the proper use and governance of artificial intelligence lapsed when the Spanish Parliament was dissolved, as published in the Official State Gazette (BOE) on 6 October 2026, and will have to be reintroduced in the next legislature. The Article 50 obligation is enforceable all the same, because the regulation applies directly.
The Spanish Agency for the Supervision of Artificial Intelligence (AESIA) has existed and operated since February 2025, with its seat in A Coruña. Its current role focuses on coordination, awareness and preparing the framework, not on imposing fines under Article 50. Any content claiming otherwise is anticipating a scenario that does not exist today.
That does not make this period a vacuum without consequences. Non-compliance still has contractual, reputational and due diligence effects. Article 50 compliance documentation is already being requested in funding rounds and in acquisition due diligence. And when the law comes into force, there will be no grace period for obligations that had been enforceable for months.
Do you want to get this in order before the Spanish penalty framework is in place? At Innovatech Legal we work on the role analysis, the map of obligations and the documentation of the editorial exception.
Regulation (EU) 2026/1744 postponed the obligations for high-risk AI systems. Annex III systems move to 2 December 2027 and Annex I systems to 2 August 2028. It also softened Article 4 on AI literacy and simplified registration in the EU database.
In the other direction, it added new obligations. The prohibitions added to Article 5 will apply from 2 December 2026. They cover non-consensual intimate material and synthetic child sexual abuse material. Articles 102 to 110 have applied since 27 July 2026.
The full timeline and the allocation of obligations by risk level are set out in our AI Act compliance guide for businesses.
Watch the name, because there are two omnibus packages. The artificial intelligence one is the one you have just read about. The Digital Omnibus on data is a separate file, would rewrite the GDPR and is still stuck in the Council.
No, if they are corporate or commercial content. Article 50(4) only requires disclosure of AI-generated text published to inform the public on matters of public interest. A brand post, a product page or a commercial newsletter are outside it. Even if they were inside, the obligation falls away if there is human review and someone holds editorial responsibility.
There is no retroactive obligation to label content already published. The extra time until 2 December 2026 was introduced by Article 111(4) of the AI Act. It is aimed at providers of generative systems that were already on the market before 2 August 2026. It only concerns the technical marking in Article 50(2).
Yes. Article 50(1) of the AI Act covers systems intended to interact directly with natural persons. They must be designed so that users know they are talking to an AI. The only exception is where this is obvious to a reasonably well-informed and observant person. An assistant with its own name and natural language rarely meets that exception.
Not today. Spain has not passed the law that confers sanctioning powers on AI matters. The Organic Law bill on the proper use and governance of artificial intelligence lapsed when the Spanish Parliament was dissolved in October 2026. The Article 50 obligation has been enforceable since 2 August 2026 because the regulation applies directly. Non-compliance accumulated in the meantime may be examined once the penalty framework is in place.
Do you know whether your company acts as a provider or as a deployer? Book a free initial assessment and receive a map of your Article 50 obligations, the gaps identified and a clear compliance plan.
Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.
