The European Commission published its final guidelines on Article 50 of the EU AI Act on 20 July 2026. The obligations apply from 2 August. Twelve days between the clarification and the deadline it clarifies.
Almost all of the reading of those guidelines has been about what they demand. The more useful paragraph is the one that lets you off.
What landed, precisely
Three things are worth stating carefully, because the coverage has blurred them.
The guidelines are not new law. They are non-binding. They set out how the Commission reads Article 50. They add no obligation and they remove none. If you were compliant on 19 July you were compliant on 21 July. What changed is that a large amount of the ambiguity people were budgeting for has gone.
They cover four situations, not one. Direct interaction with an AI system. Synthetic audio, image, video and text. Emotion recognition and biometric categorisation. Deepfakes, together with AI-generated text on matters of public interest. Most organisations are exposed to the first and the last, and have thought hardest about the middle.
An adequate route has been named. The Code of Practice on Transparency of AI-generated Content, drawn up by independent experts, has been confirmed as an adequate voluntary means by the Commission and the AI Board. You can adhere to it, or you can demonstrate alternative equivalently adequate means. Both are legitimate. The difference is that an alternative now has to be argued against a published benchmark rather than into an empty room. Penalties for Article 50 failures reach 15 million euro or 3% of worldwide annual turnover.
Read paragraph 4
Article 50(4) puts its obligation on deployers, which is to say on the organisations using these systems rather than the handful training them. If you publish AI-generated text to inform the public on a matter of public interest, you have to disclose that it was artificially generated.
Unless. And the unless is the interesting part:
where the AI-generated content has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content
Two conditions, and neither of them is a label. A human reviewed it. A named party owns it.
Consider what the drafters did not write. Not "unless you disclose it more prominently". Not "unless the watermark is stronger". They went looking for the property that makes AI-generated text safe to put in front of the public, and they landed on a person in the loop and a name on the publication.
An exemption describes the target better than an obligation does
An obligation tells you the least you can do. An exemption tells you what the regulator considers good enough that the obligation stops being necessary at all. If you want to know what a trustworthy AI content pipeline looks like in the Commission's view, the carve-out is more informative than the rule.
And the carve-out is specific. A process of human review is not somebody glancing at a draft. A process has steps, and steps leave a trace. Editorial responsibility is not a general feeling of ownership. It is a party who can be asked, later, why this was published, and who cannot reasonably answer that they assumed somebody else had checked.
Both conditions are claims you may have to evidence long after the fact, to a person who was not in the room. That narrows who can actually rely on the exemption. It is available to organisations that can reconstruct, for a given piece of published content, what produced it, who reviewed it, what they changed, and who signed it off. If you cannot answer those four questions about something you published in March, you do not qualify, however confident you are that somebody did look at it.
The limits, stated plainly
The temptation over the next fortnight will be to read this as a general escape. It is not, and we would rather say so than let a useful argument overreach.
The human review exemption sits in Article 50(4) and applies to text published to inform the public on matters of public interest. It does not reach Article 50(1), where providers must tell people they are interacting with an AI system unless that is obvious to a reasonably well-informed, observant and circumspect person. It does not reach Article 50(2), where providers of generative systems must mark their outputs in a machine-readable format. For deepfakes it does not apply at all: where the content forms part of an evidently artistic, creative, satirical or fictional work the obligation is reduced to disclosure, not removed.
A governed pipeline does not make Article 50 disappear. It settles the part that turns on judgement and leaves the rest as engineering. That is still the better half of the problem to have solved.
What we would ask a client this week
We have written about this Act three times: on provenance rather than labelling, on the depth of the regime behind Article 50, and on the calendar running out. The awareness argument is made. What follows is narrower and more practical.
Where does AI-generated text leave the organisation and reach the public? Not where AI is used, which is everywhere and useless as a question. The published surface is the one Article 50(4) attaches to. Most teams that run this exercise find one or two channels they had not counted, usually in marketing or in client reporting.
For each of those, can you name the reviewer and the owner? For a specific item, published on a specific day, from a record rather than from recollection.
If you cannot, is the honest answer to fix the pipeline or to add the disclosure? Both are legitimate, and disclosure is not a confession of failure. For a good deal of content it is simply the correct answer, and it is far better than claiming an exemption you cannot evidence. The failure worth avoiding is asserting a human review that no record supports, because that is a governance claim you have made about yourself and cannot back.
Why this generalises
The pattern is not confined to this Act. When a regulator writes down the conditions under which it stops requiring you to warn people about your AI output, and those conditions turn out to be that a human looked at it and somebody's name is on it, that is worth noticing. It is the same answer that arrives in procurement questionnaires, in professional indemnity conversations, and in the room after something has gone wrong.
Not a better model. Not a louder disclaimer. A reviewer, an owner, and a record that survives both of them leaving.
Two days is not long enough to build that. It is long enough to find out whether you have it.