Meet the Authors

Key Takeaways What you need to know
  1. Article 50 of the EU AI Act takes effect August 2, 2026, introducing new transparency duties for covered enterprise AI systems and outputs.

  2. SAP and GRC teams must distinguish provider controls from business-deployer responsibilities across applications, integrations, and user-facing processes.

  3. The voluntary Code of Practice gives organizations a recognized framework for demonstrating compliance with AI content-marking and labeling requirements.

Article 50 of the EU AI Act takes effect on August 2, 2026, bringing new transparency obligations for organizations that provide or use certain AI systems. The rules require businesses to make AI involvement visible when systems interact with people or produce content that could be mistaken for human work or authentic material.

The Commission has paired the August 2 deadline with final guidelines and a voluntary code of practice. Most transparency duties apply to AI systems and outputs that interact with, analyze, or inform people. Older generative AI systems have until December 2 to add machine-readable content markers.

Providers outside the EU can fall within scope when their system outputs are used in the EU.  Violations can draw fines of up to €15 million (about $17.1 million) or 3% of worldwide annual turnover, with proportionality for small and midsize enterprises companies.

Explore related questions

Providers and Deployers Carry Different Transparency Duties

Article 50 applies when people interact directly with AI or encounter certain AI-generated content and sensitive AI tools.

Technology providers must:

  • Tell users when they are interacting directly with an AI system.
  • Add machine-readable markers to applicable AI-generated or altered content so its AI origin can be detected.

Businesses using those systems must:

  • Notify people when emotion-recognition or biometric-categorization tools are used on them.
  • Clearly identify applicable AI-generated or altered images, audio, or video as deepfakes.
  • Label AI-generated public-interest text unless it has received substantive human review and editorial oversight.

This creates a control-ownership challenge for GRC teams overseeing SAP environments. They must identify where covered AI appears in business processes, distinguish provider controls from business responsibilities, and determine where disclosures are required.

SAP Processes Determine Which Transparency Duties Apply

An AI capability may enter an SAP process through an embedded feature, an extension, or a connected third-party service. The relevant transparency duty depends on what the business does with its output and who encounters it.

A result used only for background processing may fall outside a disclosure requirement. But the same output may require a notice once it appears in a chatbot, employee interface, customer document, or public communication. Alternatively, AI-generated public-interest text may not require a label when it receives substantive editorial oversight.

GRC teams need visibility into where the output originates, how it moves between applications, whether it changes along the way, and which system presents it to a person.

While these details help distinguish a provider’s responsibility from the business’s responsibility, different parties may control different parts of an SAP-enabled process. The technology provider may add the machine-readable marker, while the business determines how the output is used, who receives it, and whether a visible disclosure is required. GRC teams need to understand that division of responsibility across the process.

Targeted Exemptions Narrow Article 50’s Scope

Machine-to-machine activity falls outside the direct-interaction requirement when no person communicates directly with the AI system.

The same applies to systems operating only in the background. Integration middleware and scheduled processing may therefore avoid an interaction notice when they do not support a direct exchange with employees, customers, or other individuals.

Separate exemptions apply to machine-readable content marking. Source code, short sequences of numbers or symbols, and standard editing assistance generally fall outside the requirement. Outputs confined to closed-loop industrial or product-development environments are also excluded unless they become final outputs.

The Commission recognizes a narrower exemption for certain business-to-business and industrial uses. However, that does not remove enterprise AI from Article 50 compliance.

These boundaries narrow the compliance workload, but they also make process context important. GRC teams must distinguish background activity from direct interaction and intermediate output from final content before deciding whether Article 50 applies.

The Code of Practice Offers a Recognized Compliance Framework

The Code of Practice on Transparency of AI-Generated Content gives providers and deployers a recognized way to demonstrate compliance with Article 50. Signing is voluntary, but the underlying transparency obligations remain mandatory.

The code’s provider section covers machine-readable marking and detection of AI-generated or altered content. The deployer section addresses labels for deepfakes and AI-generated or manipulated public-interest text.

Signatories can rely on the code’s measures across EU member states. Organizations that choose another approach must demonstrate that their controls are adequate, with market-surveillance authorities assessing those measures individually.

The decision therefore affects how GRC teams document and defend compliance. The code provides a standardized evidence path, while an alternative approach places more responsibility on the business to explain how its controls meet Article 50 requirements.

What This Means for SAPinsiders

  • Process context can change the duty. An output may remain outside Article 50 during background processing but enter scope when presented to people. GRC teams therefore need controls that follow it through the full SAP workflow.
  • Vendor compliance does not resolve business responsibility. A provider may supply the required technical controls, but the business still controls how the AI is used. GRC teams must confirm which obligations remain with the enterprise.
  • Evidence choices shape the compliance burden. The Code of Practice gives businesses a recognized way to demonstrate compliance. Organizations using another approach must be prepared to explain and defend their controls.

Events

15Oct
SAPinsider Summit Philadelphia 2026Philadelphia, PA, United States
View All