Skip to content
RiskTemplates · The Daily Brief Saturday, July 25, 2026
Wire FinCEN's Student Aid Fraud Alert: The ACH Refund Pattern Banks Need to Tune Now JUL 23

Feature AI Risk

Sign or Skip: The EU AI Act Transparency Code of Practice Decision Financial Services Firms Have Three Days to Make

The EU Commission published the final Code of Practice on Transparency of AI-Generated Content on July 8, 2026, and the signatory deadline is July 22 at 18:00 CET. Signing gives you preferential regulatory positioning for Article 50 enforcement that begins August 2. Here's what financial services firms need to know before deciding.

By Rebecca Leung · July 18, 2026 ·
Table of Contents

The EU Commission published the final Code of Practice on Transparency of AI-Generated Content on June 30, 2026. On July 8, it issued a formal opinion concluding the Code adequately covers the obligations in Articles 50(2), 50(4), and 50(5) of the EU AI Act.

The deadline to submit a signatory form and appear on the initial published list: July 22, 2026 at 18:00 CET. That is three days from today.

For most financial services firms, this decision has been sitting in someone’s inbox since the final Code dropped. Most teams are focused on the August 2 deadline — the date Article 50 obligations actually take effect — and haven’t fully worked through whether signing the Code is worth the action.

It is. But it requires understanding exactly what the Code does and doesn’t cover, and what being a signatory actually gets you.

TL;DR

  • July 22 at 18:00 CET is the deadline to appear on the initial EU AI Act Code of Practice signatories list, published before Article 50 enforcement starts August 2
  • The Code covers Articles 50(2), 50(4), and 50(5) — machine-readable synthetic content marking, AI-generated public interest text disclosure, and certain other transparency obligations
  • Signing does NOT cover Article 50(1) (chatbot disclosure) or Article 50(3) (deepfake labeling) — those apply from August 2 regardless
  • Non-signatories face greater regulatory scrutiny and must demonstrate compliance independently; the Code is the primary reference point regulators will use
  • The Code has two independent sections — providers and deployers — and can be signed for one without the other

What Article 50 Actually Requires: The Four Obligations

The confusion in most financial services compliance teams starts here. Article 50 contains several distinct transparency obligations that apply to different parties. The Code of Practice covers some of them. Understanding which is which matters before you decide whether to sign.

Article 50(1): Chatbot disclosure at first interaction. If your firm deploys an AI system that interacts directly with users — a customer service chatbot, a digital assistant, an AI-powered support tool — users must be informed they’re interacting with an AI at the start of each interaction. This is not covered by the Code of Practice. It applies from August 2 regardless of whether you sign anything. If you have EU-facing customer interactions running through AI, this obligation needs to be implemented independently.

Article 50(2): Machine-readable marking of AI-generated synthetic content. Providers of AI systems that generate audio, images, video, or text must mark outputs in a machine-readable format. This is the core content provenance obligation — it’s about technical marking infrastructure, not visible labels. The Code covers this obligation for providers. The Digital Omnibus grandfathering applies here: existing generative AI systems already on market before August 2 have until December 2, 2026 to implement 50(2) compliance.

Article 50(3): Deepfake labeling by deployers. Companies that generate or disseminate deepfakes — AI-synthesized or AI-manipulated images, audio, or video depicting real people — must label the content as artificially generated. This applies to deployers. The Code does NOT directly address this obligation. If your firm produces or publishes deepfake-adjacent synthetic media, 50(3) compliance must be built separately.

Article 50(4): Disclosure on AI-generated text about matters of public interest. When AI systems are used to generate text published to inform the public on matters of public interest — think AI-generated market commentary, financial news, regulatory guidance summaries published externally — deployers must disclose that the content is AI-generated. The Code covers this obligation for deployers. This is probably the most relevant Article 50 provision for financial services firms that publish GenAI-assisted client communications, research, or public-facing analysis.

Article 50(5): Additional transparency obligations. The Commission’s July 8 opinion includes 50(5) in the Code’s scope. This provision addresses transparency requirements for AI systems performing emotion recognition or biometric categorization where used in professional contexts. Financial services firms using such systems in HR, security, or customer service contexts would be in scope.

The Code’s Coverage in Practice

Article 50 ObligationCovered by Code?Digital Omnibus Grace Period?
50(1): Chatbot discloses AI identity at first interactionNo — implement independentlyNo grace period
50(2): Machine-readable marking of AI-generated contentYes (provider section)Until Dec 2, 2026 for existing systems
50(3): Deepfake labeling by deployersNo — implement independentlyNo grace period
50(4): AI text on matters of public interestYes (deployer section)No grace period
50(5): Emotion recognition / biometric categorizationYesNo grace period

What Signing Actually Gets You

The Code is described as conferring a “presumption of conformity” but the Commission’s July 8 opinion is precise: adherence “does not constitute conclusive evidence of compliance.” The benefit is more operational than legal.

Here’s the practical difference:

If you sign and implement the Code: Regulators use the Code as the primary reference for assessing your compliance with 50(2), 50(4), and 50(5). The assessment asks whether your implementation matches the Code’s commitments. The burden of showing you’re doing what the Code requires sits on you, but the framework for what “doing it right” looks like is clear, pre-agreed, and publicly documented.

If you don’t sign: You still must comply with 50(2), 50(4), and 50(5). But you must demonstrate compliance through your own documentation, without the Code as your reference. Regulators have the flexibility to apply a broader range of criteria in their assessment. The Commission noted that non-signatories “may face greater scrutiny.”

For enforcement-risk management purposes, signing eliminates an open question about whether your compliance approach is accepted. Non-signatories invite regulators to construct their own assessment standard for your specific situation — a situation that rarely goes better than having signed the Code.

The July 22 timing adds another layer: the initial signatories list is published before August 2 enforcement begins. Counterparties — bank partners, institutional clients, EU-based customers — will look at that list. Being absent from the initial list is a soft signal about your AI transparency posture that’s worth considering in the context of your broader EU market presence.


Who Signs What: Provider vs. Deployer in Financial Services

The Code has two independent sections. You can sign one, the other, or both.

The provider section applies to companies that develop, train, or offer AI systems. In financial services, this covers:

  • Banks and fintechs that have built proprietary AI models for credit underwriting, fraud detection, or customer service
  • Firms that have fine-tuned foundation models on proprietary data for specific applications
  • Any organization that provides an AI system to downstream users — including other financial institutions

The deployer section applies to companies that put AI systems to use in products, services, or internal operations. Most financial services firms operate primarily as deployers:

  • Banks deploying chatbots from vendors like Salesforce, Kore.ai, or custom GPT-based implementations
  • Fintechs using third-party LLMs to draft client communications, underwriting memos, or compliance documentation
  • Asset managers using AI to generate market commentary or research summaries published to clients
  • Any institution producing GenAI-assisted content that reaches EU customers or counterparties

If your firm uses vendor AI tools but hasn’t built its own models, you sign the deployer section. If your firm has also built proprietary models, you sign both.

Note that the deployer section focuses on 50(4) compliance — ensuring AI-generated text on matters of public interest is properly disclosed. This is the obligation most directly relevant to financial services firms producing client-facing AI-assisted content. The compliance architecture for 50(4) requires disclosing, at the time of content delivery, that the text was AI-generated — not buried in a terms page.


Financial Services-Specific Implications

For most community banks and fintechs not serving EU customers, Article 50 has no direct reach. The EU AI Act applies to providers and deployers of AI systems used in the EU, regardless of where the firm is headquartered. If your customer base is entirely US-based and your operations have no EU nexus, you’re not in scope for Article 50.

For any financial services firm that does serve EU customers — and this includes US-headquartered firms with EU-resident customers accessing products digitally — several specific scenarios apply:

Customer-facing chatbots: 50(1) requires chatbot disclosure at first interaction regardless of whether you sign the Code. If your EU customer service chatbot doesn’t identify itself as AI at the start of each conversation, you’re noncompliant from August 2. This is independent of the Code.

GenAI-assisted client communications: If your firm uses LLMs to draft investor letters, market updates, compliance advisories, or other text about financial matters distributed to EU clients, 50(4) applies. These are “matters of public interest” in the financial context. Signing the deployer section covers your 50(4) compliance approach; not signing means demonstrating compliance independently.

AI-generated marketing content and synthetic media: If your firm produces AI-generated images, video, or audio for EU-facing marketing, 50(2) and potentially 50(3) come into play. The grandfathering allows until December 2 for machine-readable marking implementation on existing systems; new systems deployed after August 2 must comply immediately.

Vendor dependency on non-signing AI providers: If your AI model provider doesn’t sign the provider section of the Code, their 50(2) obligations remain — the Code is the default compliance framework, but the obligation itself doesn’t disappear with non-signing. Before August 2, verify that your primary AI model providers are either signed or have documented alternative compliance approaches for the machine-readable marking requirements.


The Gaps the Code Doesn’t Fill

Signing the Code does not mean your Article 50 compliance program is complete. Two significant gaps remain regardless of signatory status:

Article 50(1) chatbot disclosure: Your customer-facing AI interaction systems must disclose they’re AI at first interaction — from August 2, with no grace period for existing systems. The Code doesn’t cover this. If you haven’t already implemented chatbot disclosure, this is your most urgent near-term task.

Article 50(3) deepfake labeling: If your firm generates or deploys deepfake content for any purpose — synthetic media of real people — you must label it as AI-generated. This is a deployer obligation the Code doesn’t cover.

As covered in our Article 50 compliance checklist, the chatbot disclosure obligation — 50(1) — is the most operationally immediate for financial services firms with EU customer interactions, and the one most commonly underestimated in the August 2 preparation timeline.


What to Do in the Next Three Days

If your firm has EU market exposure, here’s the decision framework:

Step 1: Determine your scope. Does your firm serve EU customers, have EU employees accessing AI systems, or publish AI-generated content that reaches EU residents? If not, Article 50 doesn’t apply and this Code is not relevant.

Step 2: Identify your role. Do you deploy AI tools built by others (deployer section)? Have you also built proprietary AI models (provider section)? Both?

Step 3: Check your 50(4) exposure. Does your firm produce AI-generated text on financial matters published to EU clients or the public? If yes, this is your primary deployer obligation and signing the deployer section directly addresses it.

Step 4: Submit the signatory form. The Code of Practice signatory page has the submission form. Both sections can be signed independently. Submitting before July 22 at 18:00 CET places you on the initial published list.

Step 5: Regardless of Code decision — address 50(1) and 50(3) independently. These obligations apply from August 2 with no grace period and no Code coverage. Your chatbot disclosure review and deepfake labeling audit are not replaced by signing the Code.

The EU AI Act 30-item compliance checklist we published on July 1 covers the full August 2 readiness picture. For the specific content provenance and AI governance documentation your compliance program needs, the AI Risk Assessment Template & Guide includes an EU AI Act applicability assessment, AI use case inventory with transparency obligation mapping, and pre-deployment checklist sections that directly address Article 50 documentation requirements.


The Bottom Line on Signing

The Code of Practice is not a substitute for Article 50 compliance. But it is the regulatory reference framework that will define what compliant looks like when enforcement starts August 2 — and non-signatories are explicitly outside the framework regulators will use.

The benefits of signing are real and specific:

  • Your 50(2), 50(4), and 50(5) compliance is assessed against a known, pre-agreed framework
  • You appear on the initial signatories list that counterparties and regulators consult from day one
  • You have documented evidence that your compliance approach was reviewed and accepted before enforcement began

The cost is submitting a form before July 22.

The risks of not signing are also real: demonstrating compliance through independent means under a regulatory standard that hasn’t been pre-defined, and beginning August 2 enforcement without public documentation that your AI transparency approach has been evaluated.

For firms with genuine EU market exposure and any significant GenAI content deployment, the sign/skip calculus comes out strongly in favor of signing. The remaining question is which section — and for most financial services deployers, the deployer section addresses the obligations most directly relevant to your business.

Three days left.


Penalty exposure for Article 50 non-compliance: up to €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher, enforced by national market surveillance authorities in each EU member state.

◆ Need the working template?

Start with the source guide.

These answer-first guides summarize the required fields, evidence, and implementation steps behind the templates practitioners search for.

◆ Immaterial Findings · Weekly

Sharp risk & compliance insights. No fluff.

◆ FAQ

Frequently asked questions.

What is the EU AI Act Code of Practice on Transparency of AI-Generated Content?
It's a voluntary compliance framework published in final form by the European Commission on June 30, 2026, covering the transparency obligations in Articles 50(2), 50(4), and 50(5) of the EU AI Act. The Commission issued an opinion on July 8 concluding that the Code adequately covers those obligations. Companies that sign the Code and implement its commitments gain preferential regulatory positioning when enforcement begins August 2, 2026 — regulators use the Code as the primary compliance reference, and non-signatories must demonstrate compliance through other means and face greater scrutiny.
What is the July 22, 2026 deadline and what happens if you miss it?
July 22, 2026 at 18:00 CET is the deadline to submit the signatory form and appear on the initial published list of Code of Practice signatories — the list published before August 2 enforcement begins. Companies can sign after July 22, but they won't appear on the initial list that regulators and counterparties consult from day one. Signing later still provides the preferential treatment; it just means you start enforcement without the public signatory designation that the initial list confers.
Which Article 50 obligations does the Code cover and which does it not cover?
The Code covers Articles 50(2), 50(4), and 50(5) — machine-readable marking of AI-generated synthetic content, disclosure of AI-generated text on matters of public interest, and emotion recognition/biometric categorization system disclosures. It does NOT cover Article 50(1) (chatbot disclosure at first interaction) or Article 50(3) (deepfake labeling by deployers). Those obligations apply from August 2 regardless of whether you sign the Code.
Does signing the Code automatically mean you're compliant with Article 50?
No. The Commission's July 8 opinion clarifies that adherence to the Code 'does not constitute conclusive evidence of compliance.' What it does is establish the Code as the primary reference framework for enforcement assessments — regulators assess whether you followed the Code's commitments. Companies that sign and implement the Code's requirements will generally be found compliant; companies that don't sign must demonstrate compliance through independent means. Signing without implementing is not a defense.
Does the Digital Omnibus deferral affect the July 22 deadline?
The Digital Omnibus's May 2026 provisional agreement deferred the Annex III high-risk AI system obligations to December 2, 2027 and grandfathered existing generative AI systems already on the market before August 2, 2026 until December 2, 2026 to implement Article 50(2) machine-readable marking. This does NOT defer the July 22 Code of Practice signatory deadline, Article 50(1) chatbot disclosure requirements, or Article 50(3) deepfake labeling — those still apply from August 2 with no grace period for existing systems.
Should a financial services firm sign as a provider, a deployer, or both?
The Code has separate sections for providers (companies that develop and offer AI systems) and deployers (companies that put AI systems to use in their products or operations). Most financial services firms are deployers — they use AI tools and models built by third-party providers. Banks and fintechs that have also built their own AI systems or fine-tuned foundation models may qualify as providers for those specific systems. You can sign one section, the other, or both. A firm that uses a chatbot from a third-party vendor is a deployer; if that firm also built a custom fraud detection model, it's a provider for that model.
Rebecca Leung

Author

Rebecca Leung

Rebecca Leung has 8+ years of risk and compliance experience across first and second line roles at commercial banks, asset managers, and fintechs. Former management consultant advising financial institutions on risk strategy. Founder of RiskTemplates.

◆ Related framework

AI Risk Assessment Template & Guide

Comprehensive AI model governance and risk assessment templates for financial services teams.

Immaterial Findings · Newsletter

The brief, in your inbox.

Enforcement of the week, a framework breakdown, and the prompts that are actually worth running. Delivered to your inbox. Free.