On August 2, for the first time, ordinary businesses on both sides of the Atlantic owe legally binding honesty about their AI. The EU AI Act’s transparency rules (Article 50) start applying that day, and California’s AI Transparency Act takes effect the same day, a date its legislature chose deliberately to match Brussels. If your chatbot talks to anyone in the EU, or your AI-assisted content reaches the EU market, part of this is yours. The headline you probably remember from June, that Europe delayed its AI law, is true and does not help you: the delay covers the high-risk regime, not the labels.

The date that did not move

The Digital Omnibus on AI, which the European Parliament passed on June 16 and the Council approved on June 29, pushed the AI Act’s heavy machinery well into the future: stand-alone high-risk duties now start December 2, 2027, and rules for AI embedded in regulated products follow in August 2028. Article 50 was left exactly where it was. The adopted text grants one narrow mercy, a new transition clause giving generative systems already on the market before August 2 until December 2, 2026 to implement machine-readable marking of their outputs. A system placed on the market from August 2 onward complies from day one. Everything else lands on schedule, and so does something with sharper teeth: from the same day, the Commission can audit and fine general-purpose model providers, up to 3 percent of worldwide turnover, duties those providers have nominally carried since 2025 without an enforcer.

Who owes what

Most of the confusion around Article 50, and most of the bad advice, comes from mixing up three different jobs. The statute separates them cleanly.

The bot label is the provider’s job. A system that interacts with people must be designed so they know it is an AI, unless that is already obvious to a reasonably well-informed person. If you built the chatbot, or you run a vendor’s bot under your own name and brand, that provider is you, and the fix is almost embarrassingly cheap: a persistent line in the chat window. If the bot visibly runs under the vendor’s brand, the duty sits with the vendor, though checking their compliance before August is the kind of diligence your AI usage policy should already be forcing.

The watermark is the tool vendor’s job. The machine-readable marking duty falls on the provider of the generative system, which for most operators means OpenAI, Google, Adobe, and their peers, not you. This is the most misreported point in the whole cluster. Your marketing team does not owe Brussels a watermarking pipeline.

The disclosure on published content is yours. A deployer must clearly disclose deepfakes: AI-generated or manipulated image, audio, or video that a person would mistake for authentic, a definition that catches a real person placed in a scene that never happened and generally spares an invented product render. And AI-generated text published to inform the public on matters of public interest must be disclosed too, unless a human exercised editorial control and someone holds responsibility for it. Your ad copy is outside that clause. An AI-written, news-shaped explainer published under no one’s byline is inside it.

Breaches draw fines of up to EUR 15 million or 3 percent of worldwide turnover, though for small and medium-sized firms the Act applies whichever is lower, a detail that matters more than most coverage admits. The other honest caveat runs the opposite way: as of mid-June, only 9 of 27 member states had fully stood up the market-surveillance authorities who enforce this. The referee shortage will slow enforcement against a small Canadian or American firm. It does not change what the law requires, and a disclosure that costs nothing to add is poor ground to bet on regulatory slowness.

The plumbing arrived just in time

A fair objection to all of this used to be that the labelling infrastructure did not exist. In 2026 it mostly does. The Commission published the final Code of Practice on marking and labelling on June 10; it is voluntary (the underlying duties are not, as the Commission takes care to repeat), and it asks providers to layer techniques rather than trust any single one: embedded metadata, invisible watermarks, provenance credentials, and a detection route. The industry converged on the same answer this spring. OpenAI joined the C2PA steering committee in May and now pairs Content Credentials metadata with Google DeepMind’s SynthID watermark, whose detector portal launched with over ten billion marked items. The Content Authenticity Initiative passed six thousand members in January, and credentials now ship inside cameras, from the Pixel 10 to Sony’s newsroom camcorders.

Keep your skepticism anyway, because the limits are structural. Metadata is stripped by most platforms on upload, and a screenshot launders any file clean. Watermarks are proprietary and cover only participating generators. Detectors answer reliably only for their own ecosystems. The practical consequence for an operator is a single habit: publish AI-assisted assets with their provenance metadata intact, and stop using pipelines that strip it. You cannot make the whole internet verifiable. You can stop degrading the part you control.

The same clock, elsewhere

Europe is the loudest jurisdiction, not the only one. California’s SB 942, as amended last October, binds large generative-AI providers (those with over a million monthly users) to free detection tools and embedded disclosures from the same August 2 date, at $5,000 per violation per day. Utah has required since 2024 that a bot answer honestly when a consumer plainly asks whether they are talking to one, with proactive disclosure in licensed occupations. The FTC began enforcing the TAKE IT DOWN Act in May: platforms must remove non-consensual intimate imagery, real or synthetic, within 48 hours of a valid request. And at home, Canada still has no AI statute: the new federal privacy bill tabled on June 16, C-36, would extend deletion rights to deepfakes of identifiable people, but it sits at first reading, while Quebec’s Law 25 already obliges you to disclose fully automated decisions about individuals. The pattern across all of it is the one the compliance essay named in June: statutes wobble, disclosure duties keep arriving.

Three lines for the calendar

August 2: label the bot, or confirm in writing that your vendor does; check any AI text you publish that could read as news carries a named human editor; start publishing with provenance metadata intact. December 2: legacy generative tools run out of marking grace, and the EU’s outright ban on non-consensual sexualized imagery of real people takes effect, a line no policy should have let anyone near anyway. And sometime in the next few weeks: the Commission’s final Article 50 guidelines, which will settle the edge cases this piece has honestly flagged as still draft. The labels are cheap. The date is not moving. Write the three lines down.