On August 2, 2026, the transparency obligations in Article 50 of the EU AI Act — Regulation (EU) 2024/1689 — became applicable across the European Union, with the European Commission's guidelines adopted just two weeks earlier, on July 20. Unlike Singapore's nonbinding model framework, this is binding law, applying globally regardless of where the business itself is based. Article 50(1) places the core design obligation on providers of AI systems intended to interact directly with individuals — chatbots, voice assistants, and explicitly, agentic AI systems that autonomously contact people, making calls or sending emails on a business's behalf; deployers carry their own, related duties under 50(3) and 50(4). Noncompliance carries fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. The obligation at the center of it is specific: the provider must ensure the person on the other end knows they are dealing with AI, unless it is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking account of the circumstances and context of use.

This is the closest regulatory formalization yet of an argument already made

Does the Customer Need to Know? argued that concealing autonomous operation is not a neutral design choice once a decision passes a specific consequentiality test, and named the Disclosure Threshold as the point where that concealment becomes a trust liability. Article 50's own standard is not identical to that test, and the difference is worth stating precisely rather than blurred for effect. Article 50 asks whether disclosure would be obvious to the system's actual intended audience, in context — a design-and-information duty assessed against an average member of that audience. The Disclosure Threshold asks whether the decision's stakes and verifiability make concealment a liability — a consequentiality test. The two overlap heavily in practice: a customer whose password was reset correctly has no reasonable expectation that matters under either test; a customer receiving a call from an agent negotiating a payment plan is owed disclosure under both. But they are not the same test, and a low-stakes interaction can still require disclosure under Article 50 if it would not be obvious to the relevant audience, just as a high-stakes interaction in a sufficiently sophisticated professional context might be judged obvious and therefore exempt. Article 50 operationalizes a closely related consequentiality logic, not a restatement of the Threshold itself.

The Commission's guidelines sharpen the audience side of that logic specifically: the assessment of what counts as obvious is tied to the system's actual intended or reasonably foreseeable audience, meaning more disclosure is expected wherever children, older users, or other vulnerable groups are likely to be present in that audience — a more granular version of a related consequentiality logic, applied to who is on the other end of the interaction rather than only to what the interaction is about.

The difference worth naming honestly is enforcement, not principle. The Disclosure Threshold was architectural guidance for building the right thing. Article 50 is now the reason a business in scope has to.

What the guidelines add that sharpens the existing argument

Two details from the Commission's July 20 guidelines are worth folding directly into how the Disclosure Threshold gets applied going forward. First, the "obvious" exception is read narrowly, not broadly — a provider cannot assume disclosure is unnecessary just because a system is well known to be AI-driven in general; the standard is whether disclosure would be obvious to this specific system's actual intended audience, in this specific interaction. Second, where a provider cannot be confident an autonomous agent will avoid contacting a vulnerable person, the guidelines direct that the disclosure obligation should be treated as applying by default rather than assumed away. The guidelines do not use the phrase "bias toward disclosure under uncertainty" — that is this piece's own characterization of the practical effect — but the underlying direction is real, and it is the same posture the Disclosure Threshold's own practical test already implies.

The part of the framework this body of work has not yet addressed

Article 50 also covers marking and labelling obligations for AI-generated content under 50(2) — deepfakes, manipulated media, synthetic content on public-interest matters — which sits outside what the Disclosure Threshold was built to answer. Systems already on the market as of August 2 have a transitional window for machine-readable marking, running to December 2, 2026; the interaction-disclosure duty under 50(1) carries no equivalent grace period. That memo addressed disclosure of the actor in an interaction; Article 50's content-labelling provisions address disclosure of the origin of a piece of content, a related but distinct obligation this body of work has not yet named its own architecture for. That is a genuine gap worth naming honestly rather than claiming coverage that does not exist.

Why this is the sharper of the two frameworks to build toward first

Singapore's framework is guidance a regulator hopes the market adopts voluntarily. Article 50 is a legal requirement, already applicable since August 2, 2026, with a fine schedule attached. For any autonomous business with EU-facing operations — and given the regulation's extraterritorial reach, that is a wider set of businesses than "based in the EU" — the Disclosure Threshold is no longer only an architectural best practice. It is necessary architecture for compliance, not automatic sufficiency: Article 50 additionally requires specific information design, disclosure at latest at the first interaction and in the modality of that interaction — spoken for a voice agent, written for text — and, for an agent acting on a principal's behalf, guidelines pushing toward disclosing that principal's identity as well. Machine-to-machine interaction with no direct human on the other end falls outside the obligation's scope entirely. A business that specified the Threshold correctly, at Full-System Design time, has built the design judgment Article 50 now requires it to act on. It still needs to implement the specific timing, form, and identification the regulation separately demands. A business that treated disclosure as an afterthought has had exposure accumulating since August 2 — and counting.

KEY TAKEAWAY

What does Article 50 of the EU AI Act require, and how does it relate to the Disclosure Threshold?

Article 50 of the EU AI Act — binding law, applicable since August 2, 2026 — requires providers of AI systems that interact directly with individuals, including agentic AI systems that autonomously contact people, to ensure the person knows they are dealing with AI unless it is obvious to a reasonably well-informed, observant and circumspect natural person given the circumstances and context of use. This operationalizes a closely related consequentiality logic to the Disclosure Threshold's own test, though the two are not identical: Article 50 assesses obviousness against the system's actual intended audience, while the Disclosure Threshold assesses stakes and verifiability directly. The European Commission's July 20, 2026 guidelines read the 'obvious' exception narrowly and direct that disclosure should apply by default when a provider cannot be confident an autonomous agent will avoid contacting a vulnerable person. Noncompliance carries fines up to €15 million or 3% of global annual turnover. Article 50 additionally requires specific timing, form, and — for agents acting on a principal's behalf — identification of that principal; the Disclosure Threshold is necessary architecture for compliance, not a complete legal safe harbor on its own. Article 50 also covers content-labelling obligations for AI-generated media, a related but distinct requirement the Disclosure Threshold does not yet address. Source: Arco Venture Studio.