Since August 2, 2026, Article 50 of the AI Act applies; its violations are sanctionable under national sanctions rules adopted by Member States. Criteria and practical means of demonstration exist in the Commission’s guidelines and, for the labeling of generative content, in the voluntary code of conduct. Organizations may be affected by Article 50, but no official figure of “thousands” has been established here and official compliance tools exist.

The essentials

  • Article 50 of the AI Act has been in force since August 2, 2026, but no technical audit standards allow companies to prove their compliance.
  • Sanctions reach €35 million or 7% of global turnover, a ceiling higher than the GDPR maximum (€20 million or 4%) (HR Partner, K&L Gates, February 2026).
  • European standardization bodies are behind schedule: the harmonized standards supposed to guide the implementation of the AI Act are not yet available.
  • Companies must therefore demonstrate compliance whose verification criteria remain to be written.
  • The European Commission has published non-binding guidelines, but their legal value in case of dispute remains uncertain.

The concrete requirements of Article 50

The Commission presents four main cases of transparency obligations under Article 50. Providers of interactive systems must inform people that they are interacting with an AI; deepfakes and certain generated or manipulated content are subject to separate marking or disclosure obligations. Providers of generative systems must mark their content in a machine-detectable way. Article 50 does not impose a general obligation to document uses by deployers; it imposes targeted obligations of information and labeling.

These requirements appear clear at the regulatory level. Article 50 does not create a general obligation to document uses; for its generative content obligations, the voluntary code provides a means of demonstrating compliance. Bases for interpretation and demonstration exist in the guidelines and code of conduct, even if they do not all constitute harmonized standards.

The texts in force address a significant portion of these questions; certain technical modalities remain technologically open or rely on voluntary tools.

The Commission has asked CEN (European Committee for Standardization) and CENELEC to develop standards in areas of the AI Act, mainly related to high-risk systems; Article 50 is not conditioned on the publication of such standards. Harmonized standards were mainly intended to support obligations relating to high-risk systems, whose application has been postponed; they were not a condition for the entry into force of the first obligations of the AI Act. Companies seeking to build a structured compliance program may encounter the absence of an enforceable reference framework.

Sanctions higher than GDPR, for a less mature body of law

The GDPR produced a significant fine less than a year after its entry into force: CNIL imposed €50 million on Google on January 21, 2019, after GDPR applicability from May 25, 2018. The AI Act provides a higher maximum ceiling for prohibited practices, but the absence of certain harmonized standards does not mean the absence of a framework for interpretation or compliance tools.

The comparison is illuminating. When the GDPR entered into force in May 2018, data protection authorities had at least two years of G29 guidelines (which became EDPB) covering legal bases for processing, individual rights and consent conditions. These guidelines did not have the force of law, but they created a body of reference that companies could use to build their defense and that regulators could invoke to justify their decisions.

For the AI Act, the Commission published guidelines on prohibited AI practices on February 4, 2025 and guidelines for providers of general-purpose AI models on July 18, 2025. These documents are useful. The published guidelines address the transparency obligations of Article 50 and are complemented by a code of conduct on the marking and labeling of AI-generated content. Recruitment tools, credit tools and certain medical systems are primarily covered by the high-risk systems regime, not by a general documentation obligation of Article 50; their application timeline is separate.

The obligations have been applicable since August 2, 2026; their concrete sanctions regime also depends on enforcement rules adopted by each Member State. The regulation provides for €35 million or 7% of global turnover for AI practices prohibited by Article 5 and €7.5 million or 1% for providing incorrect information to authorities; it directly sets, in Article 99, paragraph 4, point g), a ceiling for violations of Article 50: up to €15 million or, for a company, up to 3% of the total annual global turnover of the previous year, whichever is higher. These ceilings apply to large companies; SMEs benefit from reduced ceilings, but remain exposed.

The gap between text and enforcement tools

This type of gap between the ambition of a regulation and its operational enforcement capacity is not unique to AI. Cybersecurity regulation, the NIS2 Directive, and supply chain due diligence obligations have all gone through similar phases where obligations existed on paper and verification tools remained to be built.

The specificity of the AI Act lies in the nature of the regulated object. Verifying that a company has indeed informed its users that they were interacting with a chatbot is, in theory, verifiable. Verification does not depend exclusively on harmonized standards: the Commission has published guidelines and a voluntary code that provides a means of demonstrating compliance. Article 50 imposes an observable outcome, a machine-readable label allowing the detection of artificial content, while leaving a framed technological margin.

The stratifications of employment linked to AI add a layer of complexity: HR and recruitment systems are primarily likely to fall under the high-risk systems regime, not Article 50 unless they also fall into one of its specific categories. Documentation obligations for high-risk HR tools fall under the chapter on high-risk systems, not Article 50; technical standards are being prepared to support these requirements.

The Commission is asking CEN and CENELEC to develop harmonized standards; the AI Office has notably facilitated the code of conduct related to Article 50. Several industry consortiums, including actors from France, Germany and the Netherlands, have undertaken standardization work with CEN and CENELEC. These processes are underway. Initial harmonized standards could become available later.

Company practices pending standards

Faced with the absence of enforceable standards, companies are adopting various strategies, all imperfect. The most widespread consists of abundant documentation, decision logs, deployment registers, internal AI governance policies, hoping that demonstrating a good-faith approach will constitute a defensible position in case of inspection. According to Cimplifi and HR Partner, several large groups have established internal AI governance committees, designated dedicated compliance officers and launched internal audits even before external reference frameworks exist.

This precautionary approach is reasonable. It carries a systemic risk: if each organization builds its own internal standard in the absence of a common reference framework, practices will diverge and national authorities will find themselves applying a European regulation heterogeneously across Member States. This is exactly what the AI Act sought to avoid by opting for a regulation, directly applicable throughout the Union, rather than a directive.

Specialized law firms, Nixon Peabody in particular, advise their clients to treat the Commission’s non-binding guidelines as if they had quasi-normative scope, as a precaution. This is a defensible position, but it does not resolve the question of the legal value of these documents in case of litigation. A national judge or the Court of Justice of the European Union could very well consider that a company that followed the Commission’s guidelines to the letter has nevertheless violated the regulation if a harmonized standard, once published, reveals more precise requirements.

A problem of legislative method

The AI Act was adopted in record time for a text of this complexity, approximately three years of negotiations for a regulation covering systems ranging from spam filters to general-purpose models. Speed was necessary: the explosion in the use of generative AI since late 2022 put pressure on a legislative process originally designed for much less powerful and less widespread AI.

This acceleration has a cost. European Union technical regulations typically operate on a two-stage model: the high-level text defines the principles and categories, harmonized standards define the technical verification criteria. Standardization was initiated before the regulation was adopted and the deadlines for high-risk rules were adjusted to take into account the availability of supporting tools.

The European regulatory approach in the digital sector follows a different logic from that of the United States, where fragmentation between states produces its own incoherencies. Harmonized standards remain under development, but high-risk obligations have been postponed and Article 50 already has guidelines and a code of conduct; harm to uniformity is not established.

The European AI Office, created in 2024 within the Commission and whose role is precisely to coordinate the application of the regulation, will be at the center of this moment of truth. Its effectiveness in harmonizing national practices and in accelerating standardization work will largely determine whether the AI Act becomes a credible worldwide standard or a text whose application will remain uncertain for a long time.

One year to build the foundations

The planned regulatory calendar gives an indication of what is to come. The high-risk rules of Annex III will apply on December 2, 2027; those concerning systems integrated into regulated products will apply on August 2, 2028. Harmonized standards are voluntary; they provide a presumption of compliance. High-risk rules have been postponed to account for the availability of standards and other supporting measures.

Organizations that anticipated by building internal compliance programs are not wasting their time. The documentation produced today, the governance processes put in place, the deployment registers maintained: all of this will form the basis on which technical standards, when they exist, can apply. The standardization work itself will benefit from emerging practices documented by pioneering companies, which is indeed one of the reasons why industry consortiums actively participate in CEN and CENELEC working groups.

The positioning of national competent authorities, designated by each Member State to apply the AI Act, remains to be clarified. Sanctions are possible since Article 50 applied, but the criteria for compliance do not “remain” entirely to be written: the Commission has published guidelines and a code of conduct. This legal uncertainty weighs on both companies and regulators.


Sources

  1. EW Solutions – Data Compliance (June 2026)
  2. HR Partner – AI Act Compliance Overview (February 2026), link not verified
  3. K&L Gates – AI Act Transparency Obligations (February 2026), link not verified
  4. Cimplifi – AI Act Readiness (April 2026), link not verified
  5. Nixon Peabody – AI Regulation Update (February 2026), link not verified