In short
  • The Code of Practice on Transparency of AI-generated Content is a final instrument, read at source on 28 August 2026. Its publication date is not stated here: two Commission pages give two different dates for it, and until one is confirmed as the publication date this desk states neither.
  • Guidelines on transparency obligations for providers and deployers of certain AI systems are published and final. Same position on the date: the news item and the resources index disagree, so no date is asserted.
  • Signing is voluntary and the window for the initial signatories list closed on 27 July 2026 at 18:00 CEST. Organisations may still sign; they will not appear on that initial list.
  • The Commission's own framing: adherence to the Code is voluntary, and the Article 50 transparency requirements are legal obligations. The Code is a way of showing compliance, not a way of having it.
  • The guidelines on classification of high-risk AI systems remain a draft. A targeted consultation closed on 23 July 2026 and feedback is to be incorporated before adoption. Read on 28 August 2026, no adopted version and no date for one.
  • The Article 73 guidance and reporting template are still labelled draft on the Service Desk index, under 5 November 2025, and the consultation page still says the rules "will only become applicable from August 2026", a sentence written before the Omnibus proposal existed.

A correction to our own record, and how it happened. On 17 August 2026 this desk searched for an Article 50 code of practice on the marking and labelling of AI-generated content, and for a Commission Article 50 implementation guidance. Neither could be found at the Commission's domain, so both claims were withdrawn from this site under a dated sourcing note rather than restated. Both instruments exist and both are final. The reason the search failed is worth recording because it will happen again: the instrument was renamed between draft and final. The drafts circulated as a Code of Practice on Marking and Labelling of AI-generated content. The adopted instrument is the Code of Practice on Transparency of AI-generated content. A search built on the draft title returns nothing, and returning nothing is indistinguishable from the thing not existing. The lesson we are keeping: when an instrument cannot be found under the title you know, search the issuing body's resources index by date before concluding it is absent.

Section 1. What is final, and what it says

Two instruments now sit behind Article 50, and both were read at source on 28 August 2026.

The Code of Practice on Transparency of AI-generated Content. The Commission's policy page describes a final instrument with two sections. Its publication date is discussed, and deliberately not stated, in section five. Section one is addressed to providers and sets out rules for marking and detection of AI-generated and manipulated content. Section two is addressed to deployers and sets out rules for labelling of deepfakes and of AI-generated and manipulated text. The page states plainly that "Even though adherence to the code is voluntary, the transparency requirements under article 50 of the AI Act are legal obligations", and describes the effect of signing as being able to rely on the code's measures to demonstrate compliance with the AI Act's rules for labelling and detection of AI-generated content, deepfakes and certain text publications, which "will reduce their administrative burden and give them predictability, legal certainty and trust across all Member States".

The guidelines on transparency obligations. These were announced under the headline "Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems", and the same date caveat applies. They address the obligations applying from 2 August 2026 and clarify, among other things, the requirements for interactive AI systems, the marking and labelling of AI-generated content, and when a deployer must inform people about deepfakes, about AI-generated content published on matters of public interest without human review, and about emotion recognition or biometric categorisation systems. The announcement states that "AI providers will have to design AI systems to inform users when they are directly interacting with an AI and they will have to add machine-readable marks to enable the detection of AI-generated or manipulated content."

The obligations these instruments support are the ones set out at Article 50 transparency and labelling for deployers. The division between them is unchanged and worth restating in one line, because it decides which section of the Code applies to you: Article 50(1) and 50(2) bind providers, Article 50(3) and 50(4) bind deployers.

Section 2. Signing, and what signing is

The Commission's FAQ on signing sets out a mechanism that is more formal than most voluntary instruments and worth reading before anyone assumes their organisation has already adhered.

Eligible signatories are providers and deployers of generative AI systems subject to the obligations in Article 50(2) or Article 50(4), together with technology providers of marking and detection solutions. The process is a signature form returned by email to the AI Office mailbox named on the FAQ, signed by a senior executive with authority to bind the organisation. The deadline for appearing on the initial list of signatories was 27 July 2026 at 18:00 Central European Summer Time. Organisations may sign after that date and will not be included in the initial published list.

One point deserves to be flagged as unresolved rather than smoothed over. The policy page describes the Commission as having confirmed the code as an adequate voluntary tool to demonstrate compliance with the AI Act transparency obligations. The signing FAQ, read the same day, describes the assessment under Article 56(6) as the mechanism that will determine whether adherence to the code adequately ensures compliance, without giving a date on which that determination was made. Two Commission pages, one describing an assessment as done and one describing it as the applicable process. We record both and resolve neither, because a confident reconciliation would read exactly like a correct one.

The distinction to hold. Signing a code of practice is evidence of a route to compliance. It is not compliance. An organisation that signed and then did not implement the measures is in a worse position than one that never signed, because it has documented an intention against which its conduct can be measured.

Section 3. What is still a draft

Against those two finished instruments sit two unfinished ones, both bearing directly on the high-risk regime.

The guidelines on classification of high-risk AI systems. The Commission's page on guidelines for high-risk AI systems describes a draft, states that "Following the publication of the draft, another targeted stakeholder consultation is open until 23 July 2026", and continues: "Feedback received is going to be incorporated in the final version of the guidelines before adoption by the Commission." Read on 28 August 2026, more than a month after that consultation closed, no adopted version is listed and no date for adoption is given. The page also notes that other guidelines intended to facilitate compliance with high-risk obligations will be developed later, and that the draft is not legally binding.

This matters more than it looks. Classification is the first question in the whole high-risk analysis. An operator cannot decide what to document until it knows whether it is inside Annex III, and the instrument that would settle the harder edges of that question is not yet adopted. The sector-by-sector map as the Act itself sets it out is at Annex III high-risk categories, and the classification rules in the Act are at Article 6.

The guidance and reporting template for serious incidents. The AI Act Service Desk maintains a resources index with a status column, and read on 28 August 2026 it lists "Draft guidance and reporting template on serious AI incidents" under the date 5 November 2025 with the status draft and consultation. The consultation itself was published on 26 September 2025 under the title "AI Act: Commission issues draft guidance and reporting template on serious AI incidents, and seeks stakeholders' feedback", and closed on 7 November 2025. Nearly ten months after the consultation closed, the instrument is still labelled a draft by the Commission's own index.

There is a final counterpart, and the contrast is instructive. The "Report for Serious Incidents under the AI Act (General-Purpose AI Models with Systemic Risk)", published 4 November 2025, is a finished template. It operationalises the reporting obligation in Article 55 for providers of general-purpose AI models with systemic risk, and Commitment 9 of the GPAI Code of Practice. So the Commission has shipped a final incident template for the systemic-risk population, whose obligations have applied since 2 August 2025, and a draft one for the high-risk population, whose obligations move to 2 December 2027. The pattern is consistent.

Section 4. The sentence written before the Omnibus

The consultation page for the serious incident guidance still carries this line: "While the rules will only become applicable from August 2026, you can already download the draft guidance and reporting template below."

That sentence was written on 26 September 2025. The Commission's proposal to amend the AI Act, COM(2025) 836, was not presented until 19 November 2025, and the amending act, Regulation (EU) 2026/1744, did not enter into force until 27 July 2026. So the page is not wrong in the sense of having been careless. It is a page that was accurate when written and has not been revisited, and it now states an application date that the Commission's own implementation timeline no longer gives for the Annex III high-risk population.

We are not going to tell you which date governs Article 73 reporting for a given system, because the Commission has not said so on either page and this is precisely the class of question where a plausible answer is indistinguishable from a correct one. What we will say is what the two pages show. The implementation timeline, which the Service Desk states incorporates the Omnibus amendments, gives 2 December 2027 for the rules on high-risk AI systems in Annex III and 2 August 2028 for Annex I. The consultation page gives August 2026 for the reporting rules. A compliance calendar built from one of those pages does not match a compliance calendar built from the other, and nothing on either page tells a reader that.

This is the second instance of the same failure mode this desk has recorded in a week. The first was on 24 August, when we found that the Service Desk article pages for Articles 5, 6, 50, 111 and 113 each carry a notice saying the displayed text has not been updated for the Omnibus, while the Article 26 page carries no notice at all. The full record is at the Commission's own article pages are not the amended AI Act text. The Article 73 page, read on 28 August, likewise carries no notice. As we said then and repeat now: presence of the notice is informative, absence of it is not.

InstrumentStatus on 28 August 2026Date as shown
Code of Practice on Transparency of AI-generated ContentFinalTwo Commission pages disagree. Not stated here. See section 5
Guidelines on transparency obligations for providers and deployersFinalTwo Commission pages disagree. Not stated here. See section 5
Report template, serious incidents, GPAI models with systemic riskFinal4 November 2025
Guidelines on classification of high-risk AI systemsDraft, consultation closed 23 July 2026No adoption date published
Guidance and reporting template, serious AI incidents (high-risk)Draft and consultation5 November 2025 on the resources index

Section 5. Why this article does not give you a publication date

You will have noticed that neither final instrument has been dated above. That is deliberate and it is the most practically annoying finding in this piece, so it is worth setting out plainly.

For each of the two instruments, two European Commission pages give two different dates. In each case they are a few days to a few weeks apart, which is roughly the interval you would expect between a text being adopted and being indexed, or between finalisation and a formal act of publication. That is a plausible reconciliation. It is also exactly the kind of plausible reconciliation this desk has learned not to publish, because a confident wrong answer in a footnote is indistinguishable in appearance from a correct one, and footnotes are where these numbers end up.

So the rule we apply, which is the same rule we apply to any fact where two reads disagree, is to state the qualitative fact and withhold the figure. Both instruments are final. Both were read at source on 28 August 2026. The date on which each was published is an open question that can be settled by anyone with a browser and five minutes, and it should be settled before either is cited in a policy, a board paper or a contract.

The practical habit that survives this class of problem costs nothing: cite the instrument, the page you read it on, and the date you read it. A citation recording where and when it was taken remains true whatever the discrepancy turns out to be. A citation recording only a publication date is a coin flip in this instance, and the reader cannot tell which side it landed on.

Section 6. What a deployer should conclude

The distribution of finished and unfinished work is not an accident and it is not a criticism. Article 50 obligations became applicable on 2 August 2026, so the Commission finished the instruments that support them and put a signing process behind one of them. The Annex III high-risk obligations moved out to 2 December 2027, so the instruments that support those obligations are still moving. Any regulator with finite drafting capacity would sequence it the same way.

What follows for an operator is a single sequencing decision, and it is the same argument this desk made about the deferral window on 21 August. There is evidence that can be produced at any time, and there is evidence that can only be accumulated forward from the day you start keeping it. Guidance changes the first category and cannot change the second. A team that defers its high-risk evidence work until final classification guidelines exist will start accumulating logs, change records, oversight records and incident records later, and no amount of subsequently published guidance will fill in the months it did not record. The full version of that argument is at sixteen extra months, and what a deployer should do with them.

So, concretely, from this month:

  1. Treat Article 50 as settled and act on it. The obligations apply, final guidelines exist, and a voluntary code exists with a stated route to demonstrating compliance. The transitional period for the Article 50(2) machine-readable marking obligation, for systems placed on the market before 2 August 2026, ends on 2 December 2026. Our note on what lands then is at what lands on 2 December 2026.
  2. Decide about the Code without waiting. The initial signatories window has closed, so the decision now is whether to sign at all, and the answer turns on whether your organisation is inside Article 50(2) or 50(4) and whether you can actually implement the measures in the relevant section.
  3. Do not schedule high-risk work against a guidance publication date. There is not one. Schedule it against 2 December 2027, and start the forward-accumulating parts now.
  4. Build your incident reporting process against the Act, not the template. The Article 73 page as displayed on 28 August 2026 gives the deadlines: not later than 15 days in the general case, not later than 2 days for a widespread infringement or a serious and irreversible disruption of critical infrastructure, and not later than 10 days in the event of death. A process that can meet a two day deadline is a process, and it does not depend on which form the Commission eventually publishes. The obligations walkthrough is at Article 73 serious incident reporting, and the monitoring duty that feeds it is at Article 72 post-market monitoring.
  5. Re-check the two drafts on a schedule. The resources index carries a status column, which makes it the cheapest single page in the whole corpus to monitor. A monthly look at it costs a minute and would have caught both of this week's findings.

The certification response to all of this, meaning what an assessment expects an operator to hold while the guidance is unfinished, is set out at agentcertified.eu, on the evidence deployers need now. The underwriting consequence, which is that an insurer prices what you can evidence rather than what the Commission has published, is at agentinsured.eu, on the compliance to evidence chain. Operators outside the Union asking whether any of this reaches them should start at agentliability.co, on the Omnibus dates for non-EU operators. The SME-facing version of the transparency question is at insureyouragent.com, on whether clients have a right to know.

Section 7. The wider point

Three weeks ago this desk would have told you there was no final Article 50 code of practice, because we looked for one and did not find it. We were wrong, and the reason we were wrong is instructive: we searched for a title that had been superseded, got nothing back, and treated nothing as an answer.

That is the same error in the opposite direction from the one this stack is built to avoid. The familiar failure is asserting something that is not there. The failure we made is denying something that is. Both come from treating the output of a search as evidence about the world rather than as evidence about the search. The fix is the same in both directions and it is unglamorous: go to the issuing body's own index, sort by date, and read what is actually listed.

Questions

Is there a final Code of Practice for Article 50 transparency obligations?

Yes. The Code of Practice on Transparency of AI-generated Content is published as a final instrument, on the digital strategy portal and on the AI Act Service Desk resources index, both read at source on 28 August 2026. It has two sections: rules for providers on marking and detection of AI-generated and manipulated content, and rules for deployers on labelling of deepfakes and AI-generated and manipulated text. Adherence is voluntary, and the stated position is that even though adherence is voluntary, the transparency requirements under Article 50 are legal obligations. One caveat on citation: two official pages give two different publication dates, so this desk states neither until one is confirmed.

Can we still sign the Code of Practice on Transparency of AI-generated Content?

Yes, but not onto the initial list. The signing FAQ states that organisations wishing to appear on the initial list of signatories had to submit the signature form by 27 July 2026 at 18:00 Central European Summer Time, and that organisations may sign afterwards without being included in that initial published list. Eligible signatories are providers and deployers of generative AI systems subject to Article 50(2) or Article 50(4), and technology providers of marking and detection solutions. The form must be signed by a senior executive with authority to bind the organisation.

Are the guidelines on classification of high-risk AI systems final?

No, not as at 28 August 2026. The Commission's page describes a draft, states that a targeted stakeholder consultation was open until 23 July 2026, and says feedback is going to be incorporated in the final version before adoption by the Commission. Read over a month after the consultation closed, no adopted version is listed and no publication date for one is given. The page also notes that further guidelines on high-risk obligations will be developed later, and that the draft is not legally binding.

Is the Article 73 serious incident reporting template final?

Not for high-risk AI systems. The AI Act Service Desk resources index lists the guidance and reporting template on serious AI incidents under 5 November 2025 with the status draft and consultation, read on 28 August 2026. The consultation opened 26 September 2025 and closed 7 November 2025. There is a final template for a different addressee: the report for serious incidents involving general-purpose AI models with systemic risk, published 4 November 2025, operationalising Article 55 and Commitment 9 of the GPAI Code of Practice.

Does the Article 73 page say whether the Omnibus changed it?

It says nothing either way. Read on 28 August 2026, the AI Act Service Desk page for Article 73 carries no amendment notice of the kind found on the Articles 5, 6, 50, 111 and 113 pages. Absence of that notice is not a statement that the displayed text is current. What the page does display are the deadlines: not later than 15 days after the provider or deployer becomes aware of the incident in the general case, not later than 2 days for a widespread infringement or a serious and irreversible disruption of critical infrastructure, and not later than 10 days in the event of death.

What should a deployer take from the difference between them?

That the finished instruments track obligations that already apply and the unfinished ones track obligations that were deferred. Article 50 has applied since 2 August 2026 and now has a final code, final guidelines and a signing process. The Annex III high-risk obligations moved to 2 December 2027 and have a draft classification guideline and a draft incident template. The operational consequence is that a readiness plan which waits for final high-risk guidance is waiting on something with no published date, while the evidence that can only be accumulated forward is not accumulating.

Section 9. Sources

Sources

  • "Code of Practice on Transparency of AI-generated Content", policy page describing the final code, its two sections, the voluntary nature of adherence and the effect of signing. digital-strategy.ec.europa.eu (read 28 August 2026). No publication date is cited: see section 5.
  • "Commission publishes guidelines on transparency obligations for providers and deployers of certain AI systems", news item on the same domain. digital-strategy.ec.europa.eu (read 28 August 2026). No publication date is cited: see section 5.
  • European Commission, "Signing the Code of Practice on Transparency of AI-generated Content", FAQ giving eligible signatories, the signature process, and the 27 July 2026 18:00 CEST deadline for the initial signatories list. digital-strategy.ec.europa.eu (read 28 August 2026).
  • European Commission, "Transparency obligations under Article 50 of the AI Act", FAQ giving the 2 August 2026 application date, the provider and deployer split across paragraphs 1 to 4, and the Article 50(2) transitional period ending 2 December 2026 for systems placed on the market before 2 August 2026. digital-strategy.ec.europa.eu (read 28 August 2026).
  • European Commission, "Guidelines for providers and deployers of AI high-risk systems", stating that the targeted stakeholder consultation on the draft classification guidelines was open until 23 July 2026 and that feedback is to be incorporated in the final version before adoption. digital-strategy.ec.europa.eu (read 28 August 2026).
  • European Commission, "AI Act: Commission issues draft guidance and reporting template on serious AI incidents, and seeks stakeholders' feedback", published 26 September 2025, consultation closed 7 November 2025, carrying the sentence quoted in this article. digital-strategy.ec.europa.eu (read 28 August 2026).
  • European Commission, "AI Act: Commission publishes a reporting template for serious incidents involving general-purpose AI models with systemic risk", published 4 November 2025, operationalising Article 55 and Commitment 9 of the GPAI Code of Practice. digital-strategy.ec.europa.eu (read 28 August 2026).
  • AI Act Service Desk, resources index, carrying a status column and the dates cited in this article for each instrument. ai-act-service-desk.ec.europa.eu (read 28 August 2026).
  • AI Act Service Desk, Article 73, "Reporting of serious incidents", displaying the 15 day, 2 day and 10 day deadlines and carrying no Omnibus amendment notice. ai-act-service-desk.ec.europa.eu (read 28 August 2026).
  • AI Act Service Desk, "Timeline of the implementation of the EU AI Act", stating that the timeline incorporates the amendments of the Digital Omnibus on AI, and giving 2 August 2026 for Article 50 transparency, 2 December 2026 for the new prohibitions and the end of the Article 50(2) transitional period, 2 August 2027 for national regulatory sandboxes, 2 December 2027 for Annex III and 2 August 2028 for Annex I. ai-act-service-desk.ec.europa.eu (read 28 August 2026).
  • Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence, Articles 50, 55, 72 and 73. Regulation (EU) 2026/1744, the AI Omnibus, in force 27 July 2026, amending Regulation (EU) 2024/1689. Commission proposal COM(2025) 836 presented 19 November 2025.