The Digital Omnibus did not pause the EU AI Act. It deferred the high-risk obligations and left Article 50 untouched, so the transparency duties have applied since 2 August 2026. Two of the four paragraphs are written as duties on deployers, which means a hospital owes them directly. And the one concession the Omnibus did grant, a transition for machine-readable marking, expires on 2 December 2026.
Coverage of Regulation (EU) 2026/1744 was almost entirely about dates moving to 2027 and 2028. The most consequential thing about Article 50 is that it is not in that story. It arrived on schedule, it is in force now, and its obligations are distributed differently from the high-risk ones. This guide covers which paragraph binds whom, the clinical systems most likely to be caught, and why one system can carry two deadlines sixteen months apart.
What the Omnibus actually left alone
Regulation (EU) 2026/1744 moved the Chapter III high-risk obligations: Annex III standalone systems to 2 December 2027 and Annex I embedded systems, the medical device route, to 2 August 2028.[1] We covered how to tell which of those is yours in Annex I or Annex III.
Article 50 was not part of that deferral. Its transparency obligations applied from 2 August 2026 as originally scheduled.[1] The Omnibus made exactly one adjustment in this area, and it is narrow: providers of generative systems already placed on the EU market before 2 August 2026 have until 2 December 2026 to satisfy the machine-readable marking requirement in Article 50(2).[1]
So the practical position today is that the transparency regime is live, and the only part of it still in a grace period is marking, for systems that predate August, for about fourteen more weeks.
Who owes what, and why the split matters
Article 50 is not a single duty. It is four, and they are addressed to different parties. This is the distinction that decides whether a given obligation is your vendor's problem or yours.
| Paragraph | Duty | Owed by | Applies from |
|---|---|---|---|
| 50(1) | Inform people they are interacting with an AI system | Provider | 2 August 2026 |
| 50(2) | Mark synthetic output in a machine-readable, detectable format | Provider | 2 August 2026, or 2 December 2026 if already on the market |
| 50(3) | Inform people exposed to emotion recognition or biometric categorization | Deployer | 2 August 2026 |
| 50(4) | Disclose deep fakes, and certain published AI-generated text | Deployer | 2 August 2026 |
A hospital, a practice, or a health system running a purchased tool is normally a deployer rather than a provider. That means paragraphs 3 and 4 are yours directly. Your vendor cannot discharge them for you, and a procurement conversation about whether their chatbot announces itself does not touch them.
50(1): the disclosure your vendor owes
Article 50(1) requires providers to ensure that AI systems "intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system."[2] In a care setting that reaches symptom checkers, patient-facing scheduling and triage assistants, and portal chat tools.
There is an exemption where the fact is obvious "from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use."[2]
That exemption deserves care in medicine. The standard imagines a reasonably well-informed and observant person. A patient using a portal at two in the morning while unwell, or an older patient unfamiliar with conversational software, is not reliably that person, and "taking into account the circumstances and the context of use" cuts toward disclosure rather than away from it in a clinical context. The exemption exists for cases where nobody could sensibly be confused. It is not a general license to stay quiet.
50(3): the duty that is yours, and is live now
Article 50(3) requires that "deployers of an emotion recognition system or a biometric categorisation system shall inform the natural persons exposed thereto."[2] This is the paragraph most likely to be missed in a hospital, for three reasons.
It sits with the deployer, so no vendor is going to raise it during a renewal. It uses a category, emotion recognition, that many clinical teams do not associate with the products they have bought. And it has been in force since August while attention was on 2028.
Systems worth checking include tools that infer pain from facial expression in patients who cannot self-report, behavioral health monitoring that flags agitation or distress, delirium detection that reads affect or movement, and any patient experience analytics that scores sentiment from voice or video. Whether a specific product meets the definition is a determination to make with counsel. The point is that the question has to be asked now, not in 2027.
The same system, two clocks
Emotion recognition is also the clearest example of something the single-deadline framing hides. Annex III point 1(c) lists "AI systems intended to be used for emotion recognition" among the standalone high-risk categories.[3] That places the same system on the Annex III route, applying from 2 December 2027.
So one emotion recognition system carries an Article 50(3) transparency duty that has applied since 2 August 2026, and a full set of Chapter III high-risk obligations that apply from 2 December 2027. Sixteen months separate them. Anyone who filed the system under a single date has the earlier duty running unattended right now.
The general lesson is that the AI Act assigns obligations by function, not by product. One system can sit in more than one place at once, and the deadlines attached to those places do not have to agree.
50(4) and the text exemption worth knowing
Article 50(4) requires deployers of AI that generates or manipulates image, audio or video constituting a deep fake to disclose that the content has been artificially generated or manipulated.[2] For AI-generated text published to inform the public on matters of public interest, the same paragraph requires disclosure, with an exemption where "the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content."[2]
Two clarifications matter for health organizations. That text duty is about publication to inform the public, so ordinary clinical documentation is not what it targets: an ambient scribe note is not a public-interest publication, and the separate question of whether that note is genuine is an evidentiary one we cover in proving an AI scribe note is genuine. But a health system that publishes AI-assisted patient education, public health explainers, or newsroom-style content is squarely inside it, and the exemption turns on real human editorial control with a named person responsible, not on a reviewer glancing at a draft.
What to do in the next fourteen weeks
Inventory by function rather than by vendor. The question is not which products are AI. It is which of them interact directly with a person, infer emotional state, categorize people biometrically, or generate synthetic media or published text. Those four questions map onto the four paragraphs.
Then assign each duty to the party that owes it, and for anything landing on 50(3) or 50(4), treat it as already overdue rather than upcoming, because it is. If you build or supply a generative tool that was on the EU market before 2 August 2026, put the 2 December 2026 marking date on an engineering roadmap now; machine-readable marking is not a policy change, it is work.
Finally, record what you decided and why. The reason a duty did not apply, particularly a reliance on the obviousness exemption in 50(1), is exactly the reasoning you will be asked to reproduce later, and reconstructing it from memory is worse than writing it down while it is fresh. That is the same argument that makes the record-keeping duty in Article 12 urgent well before its own date, which we cover in Article 12 logging and the 2028 deadline.
What we are careful never to claim
RankShieldMD does not determine whether Article 50 applies to your system, does not write your disclosures, and is not legal advice. Whether a product is an emotion recognition system within the meaning of the regulation is a legal determination for your regulatory counsel. We are not a medical device, we do not render or score clinical decisions, and we never see PHI.
What we do is narrower and checkable. When you later need to show which model version produced a given output, and that the record of it has not been altered since, the ledger provides that in a tamper-evident, externally anchored, PHI-free form. That supports an evidentiary question that transparency duties can raise. It is not compliance and it is not a conformity assessment.
References
- [1] Hunton Andrews Kurth. EU Digital Omnibus on AI Enters Into Force. Confirms Article 50 applies from 2 August 2026 and the 2 December 2026 marking transition for systems already on the market. hunton.com
- [2] EU Artificial Intelligence Act. Article 50: Transparency Obligations for Providers and Deployers of Certain AI Systems. artificialintelligenceact.eu/article/50
- [3] EU Artificial Intelligence Act. Annex III: High-Risk AI Systems Referred to in Article 6(2) (point 1(c), emotion recognition). artificialintelligenceact.eu/annex/3
- [4] Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026 (Digital Omnibus on AI), OJ 24 July 2026. eur-lex.europa.eu/eli/reg/2026/1744