The European Commission published agent disclosure rules two weeks before enforcement. The industry compliance code that covers every other transparency obligation under Article 50 of the AI Act deliberately excludes them.
That is the structural reality as of August 7, 2026 — five days into mandatory enforcement. The Art. 50 FAQ page, live since at least July 24, provides substantive operational guidance for when AI agents must identify themselves to users. The Code of Practice on Transparency of AI-generated Content, signed by approximately 190 companies including Amazon, Anthropic, Google, Microsoft, Mistral, and OpenAI, says nothing about it.
What the Art. 50 Page Actually Says
Article 50(1) of the AI Act requires providers to inform users when they are interacting with an AI system, unless this is obvious. The Commission’s FAQ specifies four cumulative criteria that trigger this obligation.
First, the system must qualify as an AI system under the Act. Second, it must be designed for a genuine two-way exchange with people — not merely collecting data or providing automated responses. Third, the interaction must be direct: the AI itself communicates with the person rather than through a human intermediary. Fourth, the interaction must be with a natural person, whether a consumer, professional, or other user.
Systems operating solely in the background, through machine-to-machine communication, or without direct contact with people fall outside the scope. But any conversational AI system that meets all four criteria — which includes the growing class of autonomous agents that plan, invoke tools, and communicate on a user’s behalf — triggers the disclosure obligation.
The FAQ also addresses the obvious exception that providers often invoke. The Commission has set a high bar: providers must evaluate their systems against the standard of an average person, reasonably well-informed, circumspect, and observant. If a system does not inherently make its AI nature clear to that hypothetical person, the provider must disclose. The guidelines interpret this exception restrictively, given that it deprives people of transparency.
What the Code Covers — and What It Doesn’t
The Code of Practice, published June 10, 2026, addresses marking and labelling obligations under Articles 50(2), 50(4), and 50(5). These cover provider duties to mark AI-generated content in machine-readable formats, deployer duties to label deepfakes, and deployer duties to label AI-generated text published on matters of public interest.
It explicitly excludes Article 50(1) — agent and chatbot disclosure — and Article 50(3), which covers emotion recognition and biometric categorisation.
The Commission’s adequacy assessment, concluded July 8 with the AI Board adopting its own assessment July 9, confirmed that the Code adequately covers 50(2), (4), and (5). Adherence does not constitute conclusive evidence of compliance, but signatories benefit from a more predictable enforcement posture across member states.
For Article 50(1), the FAQ states explicitly: providers and deployers can determine adequate compliance measures themselves, while taking into account the Commission’s transparency guidelines. There is no standardized industry framework. No vetted compliance pathway. No collective interpretation of the four cumulative criteria or the obvious exception.
A Two-Tier Compliance Regime
This creates an asymmetry that matters more now than it did a week ago. Before July 24, one could argue that the absence of dedicated Art. 50 guidance left agent builders without a reference point. That defense no longer holds. The guidance exists. It specifies when agent disclosure is required, what the four triggering criteria are, and how narrowly the obvious exception should be interpreted.
The Code of Practice that approximately 190 companies signed provides a standardized framework for content marking and deepfake labelling. For agent disclosure, those same companies must individually interpret and implement compliance — without the benefit of a Commission-vetted standard, without the predictability that comes from a shared framework, and without the reduced supervisory burden that signatories enjoy for the obligations the Code does cover.
The companies that signed the Code have standardized their approach to the obligations that are technically straightforward — marking content, labelling deepfakes. They have collectively declined to standardize the obligation that is operationally complex: telling users when they are talking to an AI agent.
Enforcement Has No Grace Period
Article 50 has been in force since August 2, 2026. The AI Omnibus, which entered into force in July 2026, provided a limited grace period only for the Article 50(2) marking obligation on systems placed on the market before August 2 — extending that deadline to December 2, 2026.
Article 50(1) has no such grace period. It applies now. Violations can result in fines of up to €15 million or 3% of total worldwide turnover for the preceding financial year, enforced by national market surveillance authorities rather than a centralized EU body. This means different member states may interpret the average-person standard and the obvious exception with varying degrees of strictness — precisely the kind of fragmentation a collective code was supposed to prevent.
The Open Question
Will any signatory voluntarily adopt the Article 50(1) criteria that the Code excludes? Or will enforcement actions be the only mechanism that defines the boundaries of agent disclosure compliance?
In the United States, courts have already begun to address agent liability — the 9th Circuit recently treated an AI agent as a browser-like tool, shifting responsibility to the user. Europe has placed the disclosure burden squarely on the provider. The Commission has now published the guidance to apply that burden. The industry’s collective compliance instrument chose not to include it.
The guidance exists. The industry opted out. The question is how long that choice remains costless.
