<NESway/>
Skipping the slide deck0%

Atif Raza4 min read

Two EU deadlines just passed: what Article 50 and the CRA now require

The short version. Since 2 August 2026, EU AI Act Article 50 requires chatbots to disclose they are AI and generative AI output to be machine-readably marked. Since 11 September 2026, the Cyber Resilience Act requires manufacturers to report actively exploited vulnerabilities within 24 hours. Both are engineering problems: content provenance in your AI pipelines, and an SBOM-driven reporting process.

24h
to send an early warning on an actively exploited vulnerability under the CRASource 2: Jones Day

Two EU rules that had been “coming soon” for years became live obligations six weeks apart. On 2 August 2026, the transparency obligations in Article 50 of the AI Act started to apply.1 On 11 September 2026, the vulnerability and incident reporting duties of the Cyber Resilience Act followed.2 Both apply to companies outside the EU that sell into it, and both are mostly engineering problems wearing legal clothes.

This note covers what each rule now requires and what has to be built to meet it. It isn’t legal advice: scope depends on your products and role, and your counsel should confirm which duties apply to you.

AI Act Article 50: tell people, and mark the output

Article 50 is about transparency, not risk classification, so it reaches far more systems than the Act’s high-risk rules.3 In practice it asks three things:

  • Systems that interact directly with people, such as chatbots and voice agents, must make clear the person is dealing with AI.
  • Providers of systems that generate synthetic audio, images, video or text must mark the output in a machine-readable format, detectable as artificially generated or manipulated.
  • Deployers who publish deepfake images, audio or video must disclose that the content was artificially generated or manipulated.

Breaches can bring fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.1 There’s one timing wrinkle: under the EU’s Digital Omnibus changes, the marking duty in Article 50(2) applies from 2 December 2026 for systems already on the market before 2 August, a four-month transition.1 New systems don’t get it.

What to build for Article 50

The disclosure duty is a product change: a clear notice at the start of an AI conversation, and in voice channels at the start of the call. The marking duty is the harder one, because it has to survive in the file, not just on your website. Content credentials based on the open C2PA standard record what made a piece of content and how it was changed, as signed metadata that travels with the file.4 Because metadata can be stripped, pair it with a watermark embedded in the content itself, and give partners a way to verify both.

Start with an inventory. Most companies don’t know every place they generate text, images or audio with AI: marketing tools, support macros, product features and agents. Each of those is a place where marking has to happen.

The CRA: 24 hours to raise your hand

The Cyber Resilience Act covers hardware and software products with digital elements sold in the EU.5 Most of its obligations, including secure-by-design requirements, apply from 11 December 2027. The reporting duties started early, on 11 September 2026.6

Manufacturers must now report actively exploited vulnerabilities in their products, and severe incidents affecting product security, through ENISA’s Single Reporting Platform. The clock is tight: an early warning within 24 hours, a notification within 72 hours, and a final report within 14 days of a fix being available for a vulnerability, or within a month of the notification for a severe incident.2 Fines for breaching CRA obligations reach €15 million or 2.5% of worldwide annual turnover.2

What to build for the CRA

You can’t report within 24 hours on a vulnerability if it takes you a week to find out whether you’re affected. That’s why the practical foundation is a Software Bill of Materials (SBOM) for every product version you ship: a machine-readable list of every component, generated in the build pipeline, stored somewhere searchable and matched continuously against vulnerability feeds. With it, “are we affected?” becomes a query that takes minutes.

Around the SBOM, you need a decision process, because someone has to decide quickly whether a vulnerability is actively exploited, who files the report and who approves it. Write that playbook now, rehearse it once, and make sure it covers weekends. A 24-hour clock doesn’t pause for Saturday.

The order of work

  • Confirm scope with counsel: which AI systems and which products are in, and in which role.
  • Inventory every place you generate content with AI, and every product version on the EU market.
  • Ship the Article 50 disclosures, then content credentials and watermarking in generation pipelines.
  • Generate SBOMs in every build and connect them to vulnerability monitoring.
  • Write and rehearse the 24/72-hour reporting playbook.

Both deadlines have passed, so for most companies this is catch-up work, not preparation. The upside is that none of it is exotic. It’s inventory, pipelines and a rehearsed process, the same engineering habits that make a company faster at shipping anyway.

Recognise the problem? Bring it to us.

One call with a senior engineer. You’ll leave with a straight answer on what it would take.

Let's Build Together