Docento.app
Color swatches fanned out
All Posts

The AI Act Transparency Rules Are Live and Documents Are In Scope

By The Docento.app TeamPublished 5 min read
Try Docento's free PDF editorNo sign-up, 100% private — sign, annotate, and stamp PDFs in your browser.Open the editor

The EU AI Act's transparency obligations started applying on 2 August 2026, six days after a separate regulation quietly moved the deadline for high-risk AI systems out to December 2027. One deadline slipped, the other did not, and the one that did not is the one that touches everyday document work.

Two things happened in ten days

On 24 July 2026 the Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal. It entered into force on 27 July. Its headline effect was to defer compliance with the AI Act's high-risk obligations from 2 August 2026 to 2 December 2027, which is a very large amount of breathing room for anyone building credit scoring, recruitment screening or biometric systems.

Article 50, the transparency article, was not deferred. It applied from 2 August 2026 as originally scheduled, and the Commission's enforcement powers over general-purpose AI models and the penalty regime came into effect on the same date. Fines for general-purpose model providers can reach 15 million euro or 3 percent of global turnover.

There is one carve-out with a short fuse: reporting on the omnibus notes a transition to 2 December 2026 for machine-readable marking by generative systems already on the EU market. Everything else in Article 50 is live now.

What Article 50 actually asks for

Four duties, roughly, and they split between the people who build AI systems and the people who use them.

Providers have to tell a person when they are interacting with an AI system rather than a human, unless it is obvious. Providers of generative systems have to mark their synthetic output in a machine-readable format so it can be detected as AI-generated.

Deployers, which is most readers of this blog, carry the other two. If you produce a deepfake, you have to disclose that the content is artificially generated or manipulated. And if you publish AI-generated text to inform the public on matters of public interest, you have to disclose that too, unless a human reviewed the content and someone holds editorial responsibility for it.

That last exemption is the interesting one. It does not say "a human glanced at it". It says a human took responsibility. If your workflow is a model drafting a public consultation response and a person clicking approve without reading, you are relying on an exemption you have not really earned.

Where this bumps into document workflows

Most document work is nowhere near this. Summarising a contract for yourself, extracting a table, drafting an internal memo with an assistant: no public, no deepfake, no disclosure duty. Your internal Slack post is not a matter of public interest, however strongly you feel about the printer.

The place it does bite is anything published outward on a topic the public has a stake in. Council communications. Health guidance. Investor updates. Safety notices. Regulatory filings. If a model wrote the first draft of a public-facing document, the question is not whether anyone will notice. The question is whether a named person read it and would defend it.

The second place it bites is subtler and worth watching. Machine-readable marking has to survive as the file moves around, and documents are unusually good at losing that kind of thing. Marking of this sort is generally expected to travel in file metadata and embedded provenance data, and metadata is exactly what gets stripped, flattened or recompressed when a file is converted, merged, or run through a compression tool. Nobody is doing that maliciously. They are trying to get a file under an email attachment limit.

We have written before about what metadata a PDF carries and how to strip it, which until now has mostly been a privacy story. It is about to be a compliance story too, in the opposite direction: the metadata you were happily discarding may be the thing a regulator expects to find.

What to do this month, if anything

For most teams, honestly, very little.

Write down which of your published documents are AI-drafted and who signs off on each. That list is the whole compliance artefact for the editorial responsibility exemption, and it takes an afternoon.

If you publish anything synthetic that depicts real people, label it. This is not a close call.

If you build on top of a general-purpose model and pass its output to the public, ask your provider what marking they apply and whether it survives a round trip through PDF export. As of August 2026 the answers vary a lot, and some of them are "we are working on it".

And if you were counting on the high-risk deferral to buy you time on everything, read Regulation (EU) 2026/1744 rather than the summaries. Deferred is not the same as cancelled, and the transparency clock has already started.

Try Docento's free PDF editor

No sign-up, 100% private — sign, annotate, and stamp PDFs in your browser.

Open the editor

Related Posts