REP27REP27
CategoriesCompliance manager reviewing the AI Act transparency notices of her company

Article 50 · Regulation (EU) 2024/1689 · Transparency in force since 2 August 2026

Marking deadline for existing systems in —

Your chatbot talks to Europeans.Since 2 August 2026, it has to say so.

The AI Act is in force. Article 50 already requires every company whose AI talks to people, or generates text, images, audio or video, to tell them clearly. Providers of AI models and high-risk systems established outside the Union need an authorised representative inside it. We give you the notices, the register and the representative, in eight languages, at a fixed price.

See the three plans

Europe Services, SE — Prague, Czech Republic. Active since 2014. Article 27, Article 16, CRA and AI Act mandates signed for companies in 24 countries.

AI Act checker
1
obligations apply
  • Chatbot, voice or email agent talking to people
  • Text, images, audio or video generated by AI
  • You sell your own AI model or system in the EU
  • Hiring, credit, education, biometrics, safety

A first orientation, not legal advice. The classification of your system stays your decision.

Who the AI Act reaches, and who it does not

The AI Act follows the AI, not the server. If people in the European Union meet your AI system, or use its output, the rules reach you, wherever the company is. What you owe depends on your role: the provider who builds or sells the system, or the deployer who uses it.

SituationWhat the law asksWhat we do
Website or app with an AI chatbot or voice assistantArticle 50(1): tell people they are talking to an AI, unless it is obvious.We write the notice in eight languages and keep every version.
AI-generated images, video, audio or text published to the publicArticle 50(2) and (4): mark it as artificially generated; disclose deep fakes.Notices, marking guidance and a public badge.
Provider of a general-purpose AI model, outside the EUArticle 54: appoint an authorised representative in the Union by written mandate.We are the representative and hold your documentation.
Provider of a high-risk AI system, outside the EUArticle 22: authorised representative, from 2 December 2027 for Annex III systems.We sign the mandate now, so the address is ready.
Company that only uses internal AI tools, no contact with the publicFew duties under Article 50; AI literacy and good governance still expected.We tell you honestly that you may not need us.
Developer screen with the code of an AI system subject to the AI Act

The two things that decide what you owe

Almost every question about the AI Act comes down to two facts about your system. Get them right and the rest follows.

Does it meet people?

A chatbot on your site, a voice on your phone line, an AI that writes to customers or creates images they will see. If people meet it or its output, Article 50 applies to you as deployer or provider.

Is it yours, and is it high-risk?

If you build or sell the AI under your name, you are its provider. If it decides on jobs, credit, education, access to services or safety, it may be high-risk under Annex III, with the heaviest duties.

We record your answers in the mandate. The classification is yours; we make sure the paperwork matches it.

What is really due, and what is not yet

A lot of what is being sold as "AI Act compliance" is not due yet. Regulation (EU) 2026/1744, the Digital Omnibus on AI, moved several dates. We would rather tell you which ones.

Already binding

Prohibited practices since February 2025. General-purpose AI models since 2 August 2025. Article 50 transparency since 2 August 2026, with marking of content from systems already on the market by 2 December 2026.

Coming later

High-risk systems listed in Annex III (employment, credit, education, biometrics, critical infrastructure): 2 December 2027. High-risk AI inside regulated products (Annex I): 2 August 2028.

The practical catch: an authority does not ask whether you knew the date. It asks where your notice is, since when, and who answers for it. That is what we keep.

The desk. What you actually receive.

Not a PDF of generic advice. A set of texts in your name, a record that proves them, and a person who answers when someone asks.

Notices ready to publish

The chatbot notice, the AI-content label, the deep-fake disclosure and, where needed, the emotion-recognition notice. Written for your systems, in English plus up to seven languages.

Placement, not just wording

Where each notice goes: first message of the chat, under the image, in the video, in the email footer. The law cares about the moment people meet the AI.

A dated record of every version

Each change of each notice, with its date. If an authority asks what users saw in March, you have the answer in one minute.

The register of your AI systems

What each system does, whether you are provider or deployer, where people meet it, which notice applies, when it was last reviewed. Kept by us, available to you and to an authority.

The representative question, answered

For providers outside the Union, the authorised representative is the address the AI Office and national authorities write to. We sign the mandate, hold the documentation for ten years and answer.

A badge that can be checked

A public verification page under your AI27- code, and a badge for your site. Buyers and partners can check it themselves.

AI model provider placing a general-purpose AI model on the EU market
If people in the Union meet your AI, the AI Act meets you.

What counts as an AI system

Wider than people expect. A machine-based system that works with some autonomy and infers from its inputs how to generate outputs such as predictions, content, recommendations or decisions. A chatbot built on someone else's model is an AI system; so is a scoring model in your back office.

Outside: systems used only for military, defence or national security, pure research before placing on the market, and personal non-professional use. Free and open-source models have lighter duties, but not when they are placed on the market as high-risk or used in prohibited practices.

The deadlines, one table

DateWhoWhat appliesEnforced by
24h2 Feb 2025 · everyoneProhibited practices (Article 5) and AI literacy (Article 4).National authorities
72h2 Aug 2025 · model providersGeneral-purpose AI models: documentation, copyright policy, training-data summary, authorised representative for non-EU providers.AI Office
14d2 Aug 2026 · deployers and providersArticle 50 transparency: chatbots, AI-generated content, deep fakes, emotion recognition. Content from systems already on the market: by 2 Dec 2026.Market surveillance authorities
1m2 Dec 2027 · high-riskAnnex III high-risk systems: risk management, data governance, logging, human oversight, registration, authorised representative. Annex I systems: 2 Aug 2028.Market surveillance authorities

Dates as amended by Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force since 27 July 2026.

Three European rules, three different questions

Companies often think a GDPR representative covers AI. It does not. The three rules ask different things of different people.

AI ActGDPRCRA
Who is boundProvider or deployer of the AIController of personal dataManufacturer of connected products
What it asks firstTransparency to people; representative for non-EU providersRepresentative for non-EU controllers (Article 27)24-hour vulnerability reporting
First deadline24h24h72h
Enforced byAI Office and market surveillance authoritiesData protection authoritiesCSIRTs and ENISA
Applies from2025 – 2028, in stagesIn force11 September 2026

One chatbot can trigger all three: it talks to people (AI Act), it processes their data (GDPR), and it runs in an app with a data connection (CRA). We handle each as a separate mandate on the same account.

What it costs to get it wrong

Transparency breaches sit in the band of up to €15 million or 3% of worldwide annual turnover. Prohibited practices reach €35 million or 7%. For small and medium companies the lower of the two amounts applies, which is still more than any plan on this page.

The commercial damage comes first. Platforms, app stores and enterprise buyers already ask for AI disclosures in their questionnaires. A missing label is a lost contract before it is a fine.

Compliance manager responsible for AI Act transparency at a company
Someone has to own the notices. Usually they already have another job.

Inside the desk

Three moments of the same duty: the code that runs the AI, the notice people read, and the person who answers for it.

The notice is written for the moment people meet the AI.
The notice is written for the moment people meet the AI.
A named person answers every question about your notices.
A named person answers every question about your notices.
A model sold on its own is a product in its own right.
A model sold on its own is a product in its own right.

Plans

One price, one renewal, no hourly billing. Large firms quote €2,000 – €5,000 a year for the representative alone.

AI TRANSPARENCY

€290

Renewal €240

Article 50 · deployers and providers

  • Chatbot and AI-content notices in 8 languages
  • Placement guide for each place people meet the AI
  • Dated record of every version
  • Public badge and verification page

REGISTER + TRANSPARENCY

€590

Renewal €490

Companies with several AI systems

  • Everything in AI Transparency
  • Register of your AI systems, kept by us
  • Provider or deployer role recorded for each
  • Review at each change and at least yearly
  • Verifiable certificate of the mandate

AI ACT REPRESENTATIVE

€1490

Renewal €1190

Providers outside the Union · per model or system

  • Written mandate under Articles 22 and 54
  • Technical documentation held for ten years
  • Requests from the AI Office and authorities handled
  • Transparency notices for the same system
  • Bundled with Article 27 and CRA mandates

We do not sell audits, conformity assessments, AI testing or model evaluations, and we are not a notified body. When you need one, we tell you.

How the AI Act arrived

We have followed the text since the proposal and revise this page each time the dates move, as they did in July 2026.

DateMilestoneWhat changed
2024-10-23AdoptionRegulation (EU) 2024/1689 published on 12 July 2024. The world's first horizontal AI law.
2024-12-10Entry into force1 August 2024. Nothing enforceable yet; the clock for every later stage starts here.
2026-06-11Prohibitions2 February 2025: prohibited practices and AI literacy apply.
2026-09-11 ←GPAI and Article 502 August 2025 for general-purpose models; 2 August 2026 for transparency to people.
2027-12-11Digital OmnibusRegulation (EU) 2026/1744, in force 27 July 2026: high-risk deadlines moved to December 2027 and August 2028; Article 50 unchanged.

The words, defined the way an authority uses them

Most arguments about the AI Act are arguments about five or six definitions. These are the ones that decide what you owe.

AI system
A machine-based system designed to operate with some autonomy that infers from its inputs how to generate outputs — predictions, content, recommendations or decisions — that can influence physical or virtual environments.
Provider
Whoever develops an AI system or model, or has it developed, and places it on the market or puts it into service under its own name or trademark, paid or free.
Deployer
Whoever uses an AI system under its authority in a professional activity. A company using a chatbot on its website is its deployer.
General-purpose AI model
A model trained on large amounts of data that can perform a wide range of distinct tasks and can be integrated into many downstream systems.
High-risk AI system
A system used as a safety component of a regulated product (Annex I) or in one of the Annex III areas, such as recruitment, credit scoring, education, biometrics or critical infrastructure.
Authorised representative
A person established in the Union who has accepted a written mandate from a non-EU provider to carry out its AI Act obligations and procedures on its behalf.
AI Office
The European Commission service that supervises general-purpose AI models and coordinates enforcement of the AI Act across the Union.
Deep fake
AI-generated or manipulated image, audio or video that resembles real people, objects, places or events and would falsely appear authentic.
Transparency obligation
The Article 50 duty to tell people they are interacting with AI, to mark synthetic content in a machine-readable way, and to disclose deep fakes and emotion recognition.
Placing on the market
The first making available of an AI system or model on the Union market. For a non-EU provider, the moment the representative is needed.
Prohibited practice
The uses banned outright by Article 5, such as manipulative techniques, social scoring and untargeted scraping of facial images.
AI literacy
The Article 4 expectation that staff dealing with AI have enough understanding of it for their role.
Machine-readable marking
A technical signal in the file or stream — metadata, watermark or similar — that lets software detect content as AI-generated.
Open-source model
A model released under a free and open licence. Lighter duties apply, but not for models with systemic risk.
Systemic risk
The category of the most capable general-purpose models, with extra duties on evaluation, incident reporting and cybersecurity.
Market surveillance authority
The national body that can demand documentation, restrict an AI system, or order it withdrawn from the market.

Read the primary sources yourself

Everything on this page comes from the regulation and the official pages of the Commission. Where we interpret, we say so.

Regulation (EU) 2024/1689

The consolidated text of the AI Act on EUR-Lex, in all official languages.

AI Act — European Commission

The Commission's page on the regulatory framework and its timeline.

Our AI Act representative page

What the Article 54 mandate covers for general-purpose AI models.

The AI Act Services Agreement

The full terms of the three plans, in English and Italian.

AI Act compared with GDPR

Two representatives, two different duties.

Verify an AI27- mandate

Check any certificate we issued, with its code.

Page maintained continuously since the regulation entered into force. Last revision: 26 September 2026.

Questions companies actually ask

Does the whole AI Act apply now?
No. Prohibitions and AI literacy apply since February 2025, general-purpose models since August 2025, transparency under Article 50 since 2 August 2026. High-risk duties come in December 2027 and August 2028.
We only use ChatGPT-style tools internally. Do we need anything?
Probably very little. Article 50 is about people meeting the AI. If nobody outside the company talks to it or sees its output as published content, your duties are mostly AI literacy and good governance.
Our website chatbot runs on a third-party model. Who is responsible?
You, as deployer, for telling visitors they are talking to an AI. The model provider has its own duties, but it cannot put the notice on your website for you.
What exactly must the chatbot notice say?
That the person is interacting with an AI system, clearly and at the latest at the first interaction, unless it is obvious from the context. We write it so it is both clear and short.
Do we have to label every AI-generated image?
Content generated by AI must be marked in a machine-readable way by the provider of the generating system. Deployers who publish deep fakes, or AI-generated text on matters of public interest, must disclose it, unless the text was reviewed under human editorial control.
We are outside the EU. Do we need a representative?
If you provide a general-purpose AI model used in the Union, yes, under Article 54. If you provide a high-risk system, yes, under Article 22, from December 2027. For transparency alone, no representative is required.
Is the representative the same as a GDPR representative?
No. Different regulation, different tasks, different authorities. We can hold both, as separate mandates on the same account.
What documents do you need for the representative mandate?
The technical documentation of the model or system, the EU declaration of conformity where required, and a contact who can answer technical questions. In English.
Is our system high-risk?
Only if it falls in Annex III — for example recruitment, credit scoring, education, access to essential services — or is a safety component of a regulated product. The decision is yours; we record it.
What if the rules change again?
We update your notices and the service at no extra cost for the current year, and tell you what changed.
Can you certify our AI?
No, and nobody honest will do it for €290. Conformity assessment for high-risk systems is done by the provider or a notified body. We keep the mandate, the notices and the paperwork straight.
Which languages do the notices come in?
English plus up to seven of: Italian, Spanish, French, German, Portuguese, Dutch, Polish. More on request.
Do open-source models escape the AI Act?
Partly. Free and open-source models have lighter documentation duties, but not when they carry systemic risk, and Article 50 still applies to the systems that use them.
Who can ask us for our AI documents?
The AI Office for general-purpose models, and national market surveillance authorities for AI systems. With the representative plan, they write to us first.
What are the penalties?
Up to €35 million or 7% of worldwide turnover for prohibited practices, up to €15 million or 3% for most other breaches, including transparency. For SMEs, the lower amount applies.
Does the UK have the same rule?
No. The United Kingdom has no equivalent AI statute; its regulators apply existing law. UK companies serving EU users are still caught by the AI Act.
We already have an AI policy. Is that enough?
A policy says what you intend. Article 50 asks what people actually see. The notices and the dated record are the evidence.
Can you answer the authorities for us?
On the notices, yes. As representative, we receive and answer requests on documentation. On the substance of your system's decisions, the answer stays with you, and we pass it on.
How fast is it live?
Notices within five working days of the completed form; the verification page and badge on approval.
What do you need from us to start?
The list of your AI systems, where people meet them, your role for each, and the person who answers AI questions. The form takes ten minutes.
Do you also handle GDPR, CRA or product safety?
Yes, as separate mandates on the same account: Article 27 for personal data, Article 16 for product safety, Article 14 CRA for connected products.
What if we stop the service?
You cancel before renewal from your account. As representative, we hand the documentation to the successor you name, or keep it for the ten years the law requires.

The notices are due today

Tell us which AI you use and where people meet it. We answer with the one thing you need first: whether the AI Act asks you for anything at all.

See our other mandates
Your AI Act mandate is not active yet

Payment received. One ten-minute form is missing: your AI systems and who answers for them.

Complete it now