Regulation (EU) 2024/1689 (“AI Act”), which has been undergoing progressive implementation for almost two years, will reach one of its particular milestones on 2 August 2026.
From that date, companies established in the EU, or companies outside the Union whose AI systems or respective outputs are used in the European market, will need to assess, among other regulatory points, whether their activities fall within the transparency obligations set out in Article 50.
But what does your company have to do with this?
Simple. From that date, the transparency rules under Article 50 will apply to both companies that provide generative AI services, known as “providers” (such as Claude, ChatGPT, Midjourney), and companies that use such services, known as “deployers” or organizational users.
Does your company use Gen AI to recognize emotions or perform biometric categorization, such as metrics designed to measure behaviors, reactions, trends, and emotions of customers, students, or candidates?
Does your company use AI to create hyper-realistic customers or present an artificial spokesperson?
Does your company use AI to issue financial alerts or publish reports on regulated markets without rigorous editorial control?
If so, the obligations under Article 50 and the applicable duties under the AI Act must be brought into compliance within 2 weeks.
What will be required? The main mission will be to promote transparency in two dimensions: internal and external.
Externally, companies should update public-facing notices to explain how AI is used in the cases mentioned above, making the “how” (methodology) and the “why” (purpose) transparent. Also, user interactions with AI in those situations should include the appropriate notices.
Internally, your company needs to:
a) map the AI systems that are being used, including to determine whether the AI Act applies;
b) identify which obligations are necessary, through risk classification;
c) define guidelines, best practices, and internal responsibilities in the use of AI, through normative documents;
d) identify and control AI risks;
e) ensure that suppliers also follow AI good practices through clauses;
f) raise awareness across the organization as a whole.
Whew. A lot of things, right? And I don’t know if you noticed, but everything can be summarized in one word: VISIBILITY.
Now is the moment when I connect all of this to the image in this publication.
What the AI Act expects from European companies, or from their suppliers acting as organizational users of AI, is that, through governance methodologies, Senior Management and the general public are able to see how AI resources are being and will be used.
All of this in less than two weeks. Is your business prepared?
Here at B10SEC, we are moving full speed ahead in strengthening our clients’ AI maturity.

Cibersegurança
Did you know that the corporate use of ChatGPT, Claude, or similar tools may trigger obligations under the European AI Act?
Regulation (EU) 2024/1689 (“AI Act”), which has been undergoing progressive implementation for almost two years, will reach one of its particular milestones on 2 August


