Art. 50(2) marking deadline: 2 Dec 2026 · 57 days

EU AI Act

Dates and answers

What applies when, under Regulation (EU) 2026/1744, and what each question about scope, data and cost comes down to in practice.

EU AI Act · Regulation (EU) 2024/1689

Article 50 applies now. High-risk follows in 2027.

Article 50 transparency obligations apply since 2 August 2026; generative AI systems placed on the market before that date must meet the Art. 50(2) output-marking duty by 2 December 2026, the same day the nudifier ban takes effect. The Regulation (EU) 2026/1744 (Digital Omnibus on AI) moved high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I products).

Regulation (EU) 2024/1689 amended by Regulation (EU) 2026/1744, Digital Omnibus on AI, in force 27 July 2026.

Countdown · Art. 50(2) output marking

00
Days
:
00
Hours
:
00
Min

Art. 50(2) output-marking deadline for generative AI already on the market, 2 December 2026 (nudifier ban takes effect 2 December 2026).

Article 50 breaches fall under the Article 99(4) tier: up to €15M or 3% of global annual turnover · Read the Omnibus breakdown →

  1. 01in force

    2 August 2026

    Article 50 in force

    Disclosure, deepfake labelling and output-marking obligations apply. Not delayed by the Omnibus.

  2. 02upcoming

    2 December 2026

    Output marking · nudifier ban

    Generative AI already on the market must meet the Art. 50(2) output-marking duty. The nudifier ban takes effect 2 December 2026.

  3. 03upcoming

    2 December 2027

    was Aug 2026

    Annex III high-risk

    Conformity assessment, technical documentation and risk management for Annex III high-risk systems.

  4. 04upcoming

    2 August 2028

    was Aug 2027

    Annex I products

    AI embedded in regulated products (medical devices, machinery delegated acts, automotive).

Start your alignment assessment

Get a free EU AI Act alignment report for your organisation. A 30-minute assessment gives you a clear picture of where you stand.

EU-built. EU-headquartered. Your data stays in Frankfurt (eu-central-1). No vendor lock-in.

FAQ

Common questions

The questions enterprises ask before putting an evidence layer under their AI, from integration to board approval.

INTEGRATIONDo we need to replace our existing AI systems (Microsoft Copilot, AWS Bedrock, Google Vertex AI)?

No. TRACE is a middleware layer that sits between your existing AI platform and your outputs. Your systems continue running as today. TRACE intercepts outputs, wraps them with the evidence layer, generates the audit trail and returns the result with its audit record. Three integration patterns: (1) API gateway: route AI outputs through the TRACE endpoint, no code changes to your existing system, live in about 2 days. (2) SDK wrapper: 3 lines of code around your existing LLM client, live in about 1 week. (3) Async audit pipeline: your AI runs normally and TRACE processes outputs asynchronously, live in about 2 weeks. No vendor lock-in. Works with any AI system that produces text output.

Plug-and-play

MYTHWe already have Microsoft, AWS or Google compliance tools. Aren't we covered?

Not for the EU AI Act. Hyperscalers provide infrastructure compliance: SOC 2, ISO 27001, GDPR data processing agreements. They do not produce EU AI Act evidence for your use of their models. Microsoft Responsible AI Toolkit is a framework, not a conformity system. AWS AI compliance covers data security. Google Vertex AI has no EU AI Act conformity output. None of them produce Article 12 records, Article 17 quality management evidence, conformity assessment documentation or a TRACE score. TRACE fills the gap every hyperscaler leaves open, because it is a regulatory problem, not an infrastructure problem.

Myth busted

MYTHOur AI system is low-risk. The EU AI Act doesn't apply to us.

Not necessarily. Annex III lists the high-risk use cases, among them creditworthiness assessment and access to essential services, employment and worker management, education, and certain uses in law enforcement and public services. Fraud detection may fall under Annex III (creditworthiness, essential services), subject to the Article 6 exceptions; classification is case by case. If you use Copilot, Bedrock or any LLM for an Annex III use case, you need a documented classification. Annex III conformity assessment obligations apply from 2 December 2027 (Regulation (EU) 2026/1744, Digital Omnibus on AI, in force 27 July 2026). GPAI obligations have applied since August 2025 and Article 50 transparency obligations since 2 August 2026.

Case-by-case classification

DATAWhat about data sovereignty and GDPR? We cannot send data to a third party.

TRACE runs in AWS eu-central-1 (Frankfurt). Customer data is stored and processed in the EU and no customer data is transferred to US regions. TRACE processes AI outputs, the text responses from your AI system, rather than the source data that produced them. GDPR rights can apply to outputs that contain personal data; TRACE records support those requests rather than replace them. We provide a Data Processing Agreement (Article 28 GDPR), EU Standard Contractual Clauses, explicit data residency commitments and a right-to-audit clause. For organisations with sovereign cloud requirements, we also support deployment into your own AWS EU account.

EU data residency

PROCESSWe need board approval. This will take months internally.

TRACE generates a board-ready TRACE score report in 6 hours, showing your current gap across the five TRACE properties, the penalty tier that applies to each system in your AI inventory, and the remediation case. The report makes the risk concrete and boardroom-legible, which is what shortens approval cycles. We offer it as a pre-approval diagnostic: no commitment, no cost, just evidence. You walk into the board meeting with a quantified risk assessment rather than an abstract regulatory summary.

6-hour board report

TIMELINEHow long until we have the evidence in place? We have a deadline.

Weeks 1 to 2: discovery and TRACE baseline. We inventory your AI systems, classify risk and run the first TRACE score. Weeks 3 to 6: TAMR+ integration. Regulatory corpus ingested, multi-agent reasoning live, first benchmark validated. Weeks 7 to 10: GraQle live. Real-time gap detection active, knowledge graph populated, audit trail running. Weeks 11 to 13: evidence pack ready. Documentation designed to support an ISO 42001 audit and an EU AI Act conformity assessment, board presentation prepared. First evidence output: 14 days. Whether you are compliant, and any certification, is decided by your own assessment, your auditors or a notified body, not by TRACE. GPAI obligations (in force since August 2025) are addressed in the first 2-week sprint.

14 days to first output

COSTWe cannot afford this right now. Budget is frozen.

Penalties under the EU AI Act go up to €35M or 7% of global turnover, the Act's highest tier, which applies to prohibited practices. Most other obligations carry a lower tier, up to €15M or 3% (Article 99(4)). The budget question is therefore which tier your systems sit in and what the evidence pack would cost to assemble by hand. We start with a no-cost diagnostic briefing so you can put a number on both before any spend.

No-cost diagnostic first

AUDITWhat actually happens during a real EU AI Act audit? What will regulators ask for?

Regulators request five things: (1) evidence that your AI systems were correctly classified under Article 6; (2) logs of AI decisions with human oversight records per Articles 12 to 14; (3) a conformity assessment or technical documentation showing the system meets the Act's requirements; (4) a quality management system showing ongoing monitoring, as required by Article 17; (5) post-market surveillance data. Assembling this by hand after the fact is slow and usually surfaces gaps. With TRACE the evidence pack exports from records kept at the time of each decision. The TRACE score is an internal indicator of where the gaps are; whether you pass an audit is for the auditor or the authority to decide.

Evidence pack on demand

TEAMWe already have a legal and compliance team. Why do we need TRACE?

The EU AI Act has already generated many guidance updates, national measures and GPAI Code of Practice iterations since it entered into force. TRACE does not replace your compliance team. It automates evidence collection, gap detection and report generation so the team can spend its time on judgment calls, stakeholder management and remediation decisions. TRACE handles the evidence chain, the regulatory mapping and the audit trail that would otherwise consume weeks of their time.

Supports the team

POCCan we start with a proof of concept before committing?

Yes, and we recommend it. Standard POC: 2 weeks, one AI system, full TRACE score report delivered at the end. You see where your gaps are across the five TRACE properties and what the remediation roadmap looks like. No commitment required after the POC. The report shows the gap in a board-legible, deadline-mapped format, which is usually enough evidence to secure budget approval internally.

2-week no-commitment POC

Still have a question? Book a diagnostic briefing and we will answer it for your stack.

Book a diagnostic briefing