Article 50 of the EU AI Act entered into force on 2 August 2026, bringing new transparency obligations for anyone providing or deploying generative AI systems across the bloc.

The headline requirement: people must be told when they're interacting with an AI system, unless it would already be self-evident to a sensible, attentive person paying reasonable attention to the context. Law enforcement systems used for detecting or investigating crime are exempt, provided third-party safeguards are in place.

AI-generated audio, image, video and text now need a machine-readable mark identifying them as artificial, wherever technically feasible. Deepfakes carry their own disclosure duty, though artistic and satirical works get a lighter touch. AI-generated text published on matters of public interest must be flagged too, unless a human has reviewed it under standard editorial responsibility. Emotion recognition and biometric categorisation tools also now require upfront disclosure to anyone exposed to them.

Beyond the Benchmark- Governing AI in Critical Infrastructure
Fabrizio Degni, AI & Data Governance Manager at Webuild, joins Stewart Tinson to look at how a company building dams, tunnels and metro systems governs AI in practice. Degni argues the best available AI model isn’t always the best fit, and that critical infrastructure often calls for deterministic algorithms over generative AI, because predictable, estimable outputs matter more than raw capability when failure isn’t an option. He challenges reliance on benchmarks, comparing them to an open-book exam where vendors already know the questions and publish only flattering results, arguing true intelligence lies in merging judgement across domains, not excelling at one narrow test. On governance, Degni explains why he built PALO, his own framework, not to add a new paradigm but to harmonise standards already on the market, including ISO 42001, ISO 9001, NIST and the OECD principles, into one auditable process. He details Webuild’s multidisciplinary sign-off model, where cybersecurity, compliance and human-impact specialists each hold a veto, and where failure on regulation, policy or data sovereignty is a dealbreaker regardless of how strong a solution is. The conversation also covers the EU AI Act’s Article 50 obligations, in force since August 2, 2026, and Degni’s closing view that AI adoption should never be driven by fear of missing out. Security posture and data governance must be ready first. AI, he says, is the last mile, not the start.

Every disclosure has to land at the first point of interaction, in plain and accessible form. Retrospective notice isn't an option; people need to know before or as it happens, not afterwards.

Enforcement sits across three bodies: national market surveillance authorities, the AI Office, and the European Data Protection Supervisor, depending on who's involved. Signing the EU's Code of Practice on Transparency of AI-generated Content is one way to demonstrate compliance with the marking obligation, but it doesn't cover the other three duties, so organisations still need their own approach for those.

If you're building or deploying generative AI in the EU, this is no longer a future compliance date on the calendar. It's live now.


Who Owns AI Security in the Enterprise? Governance Is Still in Its Infancy
Who actually owns AI security in your organisation — and how mature is your governance around it? Two senior CISOs from vastly different environments give a straight answer: ownership sits with the CISO for now, and governance, even in well-run programmes, is still in its infancy. AI is shifting enterprise risk from defending infrastructure to defending decisions. Agentic AI operates semi- or fully autonomously, traditional security controls don’t fit probabilistic systems, and no single vendor covers the full attack surface. Speakers: Andy Holliday, CISO at Petrofac, Lester Godsey, CISO at Arizona State University and Stewart Tinson, Project Director, AI-360 You’ll learn: • Why the CISO is the only realistic owner of AI security risk for the next 5 years • Why agentic AI breaks deterministic security controls and what to do about it • How ASU built an actionable AI framework supporting 60+ large language models • Practical controls: API key hygiene, command whitelists, blast radius reduction • Why no single vendor can cover AI security end-to-end Key topics: Agentic AI risk • AI governance maturity • Threat model transformation • CISO ownership • Incident response for AI • Ethics & training data bias • Vendor landscape reality • Probabilistic vs deterministic controls For CISOs, CIOs, and risk leaders making decisions about AI adoption now.
Share this post
The link has been copied!