What actually changed on 2 August 2026
Article 50 of the AI Act became applicable on 2 August 2026. It was not delayed. That single fact invalidates most of what is currently published about AI-generated advertising in the EU, because the Digital Omnibus on AI did delay something, and it is routinely reported as having delayed everything. The Omnibus is Regulation (EU) 2026/1744, adopted 8 July 2026, published in the Official Journal on 24 July 2026, in force since 27 July 2026.
What it deferred was the high-risk regime. Annex III moved from 2 August 2026 to 2 December 2027, and Annex I embedded products to 2 August 2028. These are fixed calendar dates; the conditional, standards-readiness trigger the Commission originally proposed was dropped in negotiation. Annex III point 4 is the employment entry, which is why so much recruitment-technology content built its 2026 urgency on the wrong provision.
Article 50 sits outside that structure entirely. It attaches to a functional category (systems that interact with people, generate synthetic content, infer emotions, or produce deep fakes) rather than to a risk classification. That is precisely why the deferral missed it.
The one grace period, and its exact boundaries
A new Article 111(4) gives generative systems that were already on the market before 2 August 2026 until 2 December 2026 to comply. Read the scope carefully, because three limits all apply at once:
- It is provider-side. It relieves the vendor of the generation tool, not the employer or agency using it.
- It covers the Article 50(2) machine-readable marking duty only. The Commission's guidelines add that a system which is partly interactive and partly generative gets the extension for marking alone; the Article 50(1) duty to make clear a person is dealing with an AI bound it from 2 August regardless.
- It applies to legacy systems only. Anything placed on the market on or after 2 August 2026 had no transition at all.
The Article 50(4) deployer disclosure duty has no grace period. If you are an employer or an agency running AI-generated creative in the EU, you have been obliged since 2 August 2026. There is nothing to wait for.
One related point on retroactivity, because it is the first question finance asks: content generated before 2 August 2026 does not have to be marked or labelled retroactively. Text generated before that date but published on or after it does. Holders of pre-existing unlabelled deep fakes are encouraged, not required, to label them, and the Commission expressly does not expect disproportionate efforts such as auditing back catalogues or reprinting packaging.
Two obligations, two different parties
Almost every confusion in this area comes from collapsing two duties that the AI Act keeps rigidly apart.
Article 50(2) is the provider's duty. Providers of systems generating synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, effective and robust so far as technically feasible. Recital 133 lists the acceptable techniques: watermarks, metadata identification, cryptographic provenance, logging, fingerprints, or combinations. Providers are not required to maintain a full provenance chain, which means C2PA-style provenance is sufficient but not mandatory. A separate detection duty runs alongside it: the provider must give people exposed to the content a way to check, producing human-readable results.
Article 50(4) is the deployer's duty. Deployers of a system that generates or manipulates image, audio or video content constituting a deep fake must disclose that the content has been artificially generated or manipulated. Article 50(5) then governs how: clearly and distinguishably, at the latest at the time of first exposure, accessibly.
A recruitment marketer is a deployer. Your generation vendor is a provider. Discharging their obligation does not discharge yours, and the Commission says so in terms: deployers "cannot rely on the machine-readable marking embedded in the content by the provider under Article 50(2)", because those markings are not immediately clear and distinguishable (guidelines C(2026) 5054, para 117).
That sentence is the whole answer to the platform question, and we will come back to it.
A photorealistic presenter who is nobody at all is still a deep fake
This is the finding most commentary gets wrong, and it decides whether the obligation applies to you.
Article 3(60) defines a deep fake as AI-generated or manipulated image, audio or video content that "resembles existing persons… and would falsely appear to a person to be authentic or truthful". Read casually, "existing persons" sounds like it means a real, identifiable individual, so a wholly invented synthetic presenter would be outside the regime.
The Commission's guidelines of 20 July 2026 read it far more broadly. At para 113, it is enough that a simulated person resembles someone who "can plausibly exist", with the exclusion drawn only at content defying the laws of nature or physics. And "persons" is defined to include "realistic AI-generated human avatars or personas", alongside digital replicas of real people and personal characteristics such as image, voice and behaviour.
The Commission's own list of worked examples includes a realistic synthetic avatar of a company CEO addressing employees about the year's results. That is, structurally, the employer-brand video half this industry is currently producing.
Three further points from the same guidelines change how you assess your own creative:
- No intention to deceive is required. The assessment is objective.
- The audience is the reasonably foreseeable one, not an average viewer, with explicit attention to people with lower digital and AI literacy. A candidate audience is broad by definition.
- Photorealism is indicative, not determinative. This is the practical lever, and the only clean exit: a deliberately stylised or illustrated treatment can take an asset outside Article 50(4) altogether.
Minor manipulation stays out. Background edits, lighting, colour correction and cosmetic adjustments have only a minor impact, and the guidelines expressly include background replacement for clearly aesthetic purposes in product advertising. Composite scenes that change how people are represented do not benefit from that.
The artistic carve-out will not rescue a job ad
Article 50(4) softens the disclosure where content is evidently artistic, creative, satirical or fictional: the disclosure must then be given in a way that does not hamper enjoyment of the work. It is widely over-read.
The guidelines say these categories are interpreted strictly, that content whose nature is exclusively informative or commercial and recognisable as such is excluded, and that where characters mix, the informative character prevails. Advertisements might qualify in specific situations, but not as a class. A vacancy advertisement is commercial and informative at the same time. Assume the full label applies.
Does the platform's automatic AI label discharge your obligation?
This is the question everyone in recruitment marketing actually has, and it has two independent answers, both of which are no.
The legal answer is para 117: a deployer cannot lean on provider-side marking, because the label has to be understandable and perceivable by people without any specific technical tools. A platform tag derived from embedded metadata is exactly the thing the Commission ruled out. Add para 142 to 143, which say a disclosure is not clear and distinguishable where it can be easily overlooked under normal conditions (naming menus and terms of use as examples), and platform labels that live behind a three-dot menu or in an expanded description fail on placement as well as on principle.
The engineering answer is worse, and almost nobody has checked it: the label will not appear at all.
Automatic platform labelling is not detection. It is manifest reading. Meta labels an ad because the file carries C2PA or IPTC provenance saying it is synthetic. If the file carries nothing, nothing happens. And no mainstream AI-avatar tool embeds C2PA: Synthesia, HeyGen, D-ID, Colossyan, Elai and Argil are all absent from the conformance list, as are Midjourney, Runway, Stability AI, ElevenLabs and Canva. A synthetic employee testimonial made in any of them ships with no cryptographic provenance whatsoever. There is no manifest for LinkedIn or Meta to read, so no automatic label is generated.
Which means the reassuring mental model ("the platform will flag it, so we're covered") is wrong twice over. It would not be sufficient if it fired, and it does not fire.