AI Act transparency rules applied from 2 August 2026 — medtech's first hard AI deadline arrived while the high-risk clock reset to 2028
Article 50 of the EU AI Act became applicable on 2 August 2026, requiring disclosure whenever people interact with AI or encounter AI-generated content. It applies irrespective of risk class — so many medical device manufacturers now carry live AI Act duties two years before the high-risk regime reaches them in August 2028.
Date of development: 2 August 2026 (Article 50 becomes applicable). Supporting events: Commission guidelines adopted 20 July 2026; Regulation (EU) 2026/1744 in force 27 July 2026; Commission confirmation of Code of Practice signatories 31 July 2026. Date of publication: 5 August 2026
Key takeaways
Article 50 of Regulation (EU) 2024/1689 (the AI Act) applies from 2 August 2026. It is not limited to high-risk AI systems.
Regulation (EU) 2026/1744 (the "Digital Omnibus on AI"), in force since 27 July 2026, moved the application date for high-risk AI embedded in Annex I regulated products — which includes AI-enabled devices under the MDR and IVDR — to 2 August 2028, and stand-alone Annex III systems to 2 December 2027.
The practical consequence is a two-year interval in which the AI Act's only directly applicable obligations for many device manufacturers are transparency (Article 50), AI literacy (Article 4) and the prohibitions (Article 5).
A limited transitional period runs to 2 December 2026 for the machine-readable marking and detection obligation, and only for generative AI systems already on the market before 2 August 2026.
Non-compliance with Article 50 can attract administrative fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.
What happened
On 2 August 2026, Article 50 of Regulation (EU) 2024/1689 became applicable across the European Union. The European Commission's own policy page for the accompanying guidelines states the position plainly: "Article 50 of the AI Act applies from 2 August 2026."
Article 50 imposes transparency obligations in four situations, split between providers (those who develop an AI system and place it on the market under their own name) and deployers (those who use an AI system under their own authority):
AI systems that interact directly with natural persons — the provider must design the system so that individuals are informed they are interacting with AI, unless that is obvious to a reasonably well-informed, observant and circumspect person.
AI systems generating synthetic audio, image, video or text — the provider must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated.
Emotion recognition and biometric categorisation systems — the deployer must inform the natural persons exposed to the system.
Deep fakes, and AI-generated text published to inform the public on matters of public interest — the deployer must disclose that the content is artificially generated or manipulated.
Two supporting instruments landed in the fortnight before the deadline. The Commission adopted Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act on 20 July 2026. And on 31 July 2026 the Commission reported that approximately 190 organisations had signed the voluntary Code of Practice on Transparency of AI-generated Content — 82 signatories to Section 1 (providers) and 152 to Section 2 (deployers), with roughly half of all signatories being small or recently founded companies.
What is new compared with the previous position
Until 2 August 2026, most medical device manufacturers had no directly applicable AI Act obligation beyond the Article 5 prohibitions (applicable since 2 February 2025) and the Article 4 AI literacy duty. The high-risk regime — technical documentation, risk management, data governance, human oversight, logging, conformity assessment — was a future problem.
Two things changed within eight days of each other. First, Regulation (EU) 2026/1744 entered into force on 27 July 2026, formally rewriting the high-risk timetable. Second, Article 50 became applicable on 2 August 2026, creating a live obligation that does not depend on high-risk classification at all.
| Provision | Previous date | Current date | Applies to |
|---|---|---|---|
| Article 5 prohibitions | 2 February 2025 | 2 February 2025 | All actors |
| Article 4 AI literacy | 2 February 2025 | 2 February 2025 | Providers and deployers |
| Article 50 transparency | 2 August 2026 | 2 August 2026 | Providers and deployers, any risk class |
| Article 50(2) marking and detection, systems already on the market before 2 August 2026 | n/a | 2 December 2026 | Providers of generative AI systems placed before 2 August 2026 |
| Annex III stand-alone high-risk systems | 2 August 2026 | 2 December 2027 | Providers and deployers of listed use cases |
| Annex I embedded high-risk systems (including MDR/IVDR devices) | 2 August 2027 | 2 August 2028 | AI in MDR/IVDR devices subject to notified body assessment |
Why this matters in practice
The temptation across medtech will be to read "2028" and stand down. That reading is wrong on the facts.
Article 50 is deliberately class-agnostic. It attaches to a situation, not to a risk classification. A Class I device with a conversational interface is caught. A wellness app that never touches MDR is caught. A manufacturer's website chatbot — nothing to do with the device at all — is caught. The obligation follows the interaction, not the CE mark.
Four medtech scenarios sit squarely inside it. Patient-facing conversational agents — symptom checkers, triage assistants, adherence coaches, in-app support bots — engage Article 50(1), which requires disclosure at or before the first interaction, conveyed clearly and distinguishably and meeting accessibility requirements. A line in the terms and conditions will not do. Clinical documentation and reporting assistants produce synthetic text, so where the manufacturer is the provider of that generative system, the Article 50(2) marking and detection obligations are engaged. Emotion recognition in digital mental health and pain assessment triggers Article 50(3) for deployers, though manufacturers should screen first against the Article 5 prohibition, which already bars emotion inference in workplace and education settings. And manufacturer-published AI-written content falls under Article 50(4) where it is published to inform the public on matters of public interest — health information plausibly qualifies — unless it has undergone substantive human review with a named person holding editorial responsibility.
There is also a commercial dimension. Hospitals are deployers in their own right, and procurement teams will increasingly ask suppliers to evidence Article 50 conformity. Manufacturers who cannot answer will lose time in tenders regardless of whether an enforcement authority ever calls.
Who is affected
Manufacturers of AI-enabled medical devices and IVDs placing products on the EU market, in any risk class
Developers of health software that falls outside MDR/IVDR but interacts with patients or generates content
EU authorised representatives, importers and distributors of AI-enabled devices, who are named in the AI Act's actor framework
Healthcare providers and health systems acting as deployers
PRRCs, RA/QA leaders and software quality teams who will own the documentation trail
Providers established outside the EU whose AI systems are placed on the EU market or whose outputs are used in the EU — the AI Act applies extraterritorially on that basis
Deadlines and effective dates
2 August 2026 — Article 50 obligations apply to all in-scope systems, regardless of when they were placed on the market. Content generated and published before this date does not need retrospective labelling.
2 December 2026 — end of the transitional period for the Article 50(2) marking and detection obligation, and only for generative AI systems already on the market before 2 August 2026.
2 December 2027 — application date for Annex III stand-alone high-risk systems.
2 August 2028 — application date for high-risk AI embedded in Annex I regulated products, including AI-enabled devices under the MDR and IVDR.
Practical actions to consider
Inventory every AI system you provide or deploy, including AI in supplier components and in commercial and support functions. The scope question is not "is this a medical device?" but "does this hit one of the four Article 50 situations?"
Classify your role for each system. Provider and deployer obligations differ. Where hospitals deploy your system, allocate the Article 50(3) and 50(4) duties contractually.
Design the disclosure, then document it. Treat it as a design input, run it through usability evaluation, and record it in the technical documentation.
Assess change control before you ship. Adding a disclosure to a device user interface is a design change, and for CE-marked devices should be assessed against your notified body's significant-change criteria and your ISO 13485 change control procedure.
Decide on the Code of Practice. Providers who decline must demonstrate compliance with the marking and detection obligations by alternative, equivalently adequate means.
Do not defer the Annex I programme. Two years is roughly one development cycle, harmonised standards for high-risk AI are still maturing, and notified body capacity for AI Act conformity assessment is unproven.
Uncertainties and open questions
Does AI image reconstruction count as "synthetic content"? Article 50(2) exempts systems performing an assistive function for standard editing, or not substantially altering input data or its semantics. Whether AI-based reconstruction, denoising or enhancement in a CT or MR pipeline sits inside that carve-out is unsettled, and the answer materially affects imaging manufacturers.
How far does the "obvious" exception stretch for clinician-facing tools? A radiologist using a known AI triage tool arguably needs no disclosure. The guidelines set out a two-step audience assessment, but the boundary for professional users is untested.
Is health information "a matter of public interest"? The Article 50(4) trigger turns on the publisher's purpose rather than subject matter alone. Manufacturers publishing AI-drafted clinical or educational content should assume it may be in scope until this is clarified.
How will enforcement be allocated? Enforcement rests with national market surveillance authorities, the AI Office for systems under its supervision, and the European Data Protection Supervisor for EU institutions. Whether a manufacturer's Article 50 compliance will be examined by the same national authority that supervises it under the MDR should be confirmed against the AI Act's market surveillance provisions and national implementing arrangements.
The high-risk guidelines are still draft. The Commission's guidelines on high-risk classification under Article 6 remain in draft as at 5 August 2026, following a consultation that closed in July 2026.
QLE perspective
The deferral to 2 August 2028 is being read across the sector as breathing space. Our view is that it changes the sequencing of the work, not its volume — and that Article 50 is the more immediate operational risk precisely because it is easy to miss. It does not arrive through the notified body. It does not appear on a certificate. It attaches to product behaviour that RA/QA teams may not have inventoried, and to marketing and support systems that sit outside the QMS entirely.
The organisations that handle this well will be those that resist building a parallel "AI compliance" function. Article 50 disclosure is a labelling and human-factors requirement with a legal deadline attached, and it belongs in design controls, usability engineering, risk management and change control — the machinery you already run under ISO 13485 and ISO 14971. Manufacturers who route it through existing processes will produce defensible evidence as a by-product; those who treat it as a separate legal exercise will produce a memo and no evidence. The same logic applies to the 2028 date: data governance, logging and human oversight evidence for high-risk AI cannot be retrofitted late, so any AI-enabled device entering design freeze in 2027 should be designed against the high-risk requirements now.
This is the structural problem QLE was built around. A medical AI company would normally instruct one adviser for the MDR and another for the AI Act, then reconcile two sets of advice itself. We cover both in a single engagement — EU AI Act consultancy covering role classification, risk classification and gap assessment, alongside ISO 13485 QMS support and technical documentation work under the MDR. If you need to establish which Article 50 obligations attach to your system and who holds them, a 20-minute scoping call will usually settle it.
Conclusion
Did anything actually happen for medical device manufacturers on 2 August 2026? Yes. Article 50 of the AI Act became directly applicable, and it applies regardless of whether a device is high-risk, low-risk, or not a device at all. The high-risk regime for AI embedded in MDR and IVDR products has moved to 2 August 2028, but that deferral does not touch the transparency duties that are live today. Manufacturers with any patient-facing conversational interface, any generative capability, or any AI-drafted published content should treat this as an immediate compliance question with a 2 December 2026 backstop for legacy generative systems.
Sources
European Commission, Guidelines on transparency obligations for providers and deployers of certain AI systems — https://digital-strategy.ec.europa.eu/en/policies/guidelines-transparency-ai-generated-content
European Commission, Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act (library record, publication 20 July 2026, with downloads) — https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems
European Commission, Strong backing for the Code of Practice on Transparency of AI-generated Content (31 July 2026) — https://digital-strategy.ec.europa.eu/en/news/strong-backing-code-practice-transparency-ai-generated-content
European Commission, Code of Practice on Transparency of AI-generated Content — https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content
Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex ELI record — https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
Article 50, Regulation (EU) 2024/1689, AI Act Service Desk — https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-50
European Commission, Q&A on transparency obligations under Article 50 — https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
Cooley, EU AI Act: Transparency Obligations Take Effect 2 August 2026 (3 August 2026) — https://www.cooley.com/news/insight/2026/2026-08-03-eu-ai-act-transparency-obligations-take-effect-2-august-2026
Hunton, EU Digital Omnibus on AI Enters Into Force (28 July 2026) — https://www.hunton.com/privacy-and-cybersecurity-law-blog/eu-digital-omnibus-on-ai-enters-into-force
Future of Life Institute, The EU AI Act's Transparency Rules: A Practical Guide to Article 50 — https://artificialintelligenceact.eu/transparency-rules-article-50/