Briefing · updated 20 August 2026

What the EU AI Act requires, and what it costs to get wrong

This page is written for the people who carry the exposure rather than the people who run the models. It explains the obligations, the penalties and the evidence a regulator expects. It is useful whether or not you ever buy anything from us, which is the point of publishing it.

Nothing here is legal advice. It is a plain reading of the legislation with links to the text, so you can check every statement against the source.

The dates that already passed

2 August 2026

Article 50 transparency obligations apply. Systems that interact with people must make clear that a person is dealing with AI. Generative outputs must carry machine-readable marks that allow them to be detected as AI-generated. Deployers must disclose deepfakes and certain AI-generated public-interest text.

This is not a future deadline. It is in force now.

10 June 2026

The Article 50 Code of Practice was published. Codes and guidelines are how the detail of the obligation gets settled, and they move. An assessment that was accurate against the draft is not automatically accurate against the final text.

Continuously

Your own systems change. A model is swapped, a prompt is edited, a workflow is extended. Each of those can move a system in or out of scope, and none of them file a ticket telling compliance that it happened.

What non-compliance costs

Article 99 sets three tiers. The figures are the higher of a fixed amount or a percentage of worldwide annual turnover. Turnover is revenue, not profit, which is why the numbers are larger than people expect.

TierCeilingWhat triggers it
Prohibited practices €35 million or 7% Breach of Article 5, the practices the Act bans outright.
Most other obligations €15 million or 3% Breach of the Act's other obligations, including the transparency duties.
Misleading information €7.5 million or 1% Supplying incorrect, incomplete or misleading information to authorities.

Article 99(6) works in the opposite direction for small and medium enterprises: the fine is the lower of the fixed amount and the percentage, not the higher. If you are an SME, use the lower figure. Quoting the headline maximum at your own board is not a stronger argument, it is a less credible one.

The part that catches people

Most organisations can answer "do we disclose that this is AI". Far fewer can answer the three questions underneath it, and those are the ones an auditor asks second.

Why was this allowed?

A model returns a probability. An auditor wants a reason. A confidence score of 0.94 does not say which rule was applied, so the evidence you are asked for does not exist as a by-product of running the system.

The evidence changed. What does that affect?

A reference record, a protocol version or a source dataset is superseded. Which earlier decisions are now invalid? Most teams cannot say, so they redo everything or redo nothing. One is expensive and the other is dangerous.

The rules changed. What does that affect?

Guidance is updated. Which of your assessments, approvals and running workflows were built on the superseded version? Work usually continues on the old rule until somebody notices, and that somebody is often the auditor.

What we do about it, briefly

EcoKure sits after your model and decides what is allowed to proceed. Every decision returns a categorical verdict, allow, block, review or abstain, with the reason recorded and signed. When your evidence or your rules change, the affected work is identified and held, and the work that is unaffected stays valid instead of being redone.

The output is an evidence pack you can hand to an auditor and they can verify offline, against a published key, without our source code and without contacting us.

What we do not claim

We cannot guarantee compliance

Compliance is determined by a regulator, not by a vendor. Any supplier who offers you guaranteed compliance is either misunderstanding the obligation or hoping you will not ask what indemnity sits behind the word. We produce evidence. Deciding whether that evidence satisfies the obligation is your counsel's call and ultimately your regulator's.

We do not interpret the law

We do not tell you what a rule means, and we are not a substitute for legal advice, a GRC platform or your quality system. We govern the computational consequences of a decision and a change, which is a narrower job, and the one that currently has no evidence trail.

We do not mark or watermark content

Article 50(2) requires machine-readable marking of synthetic content in the cases it covers. EcoKure does not provide that and has no plans to build it. It is a different technology — provenance signalling embedded in the artefact itself — and it needs a specialist provider such as a C2PA implementation.

What we do is the layer beside it: record that the marking step ran, on which artefact, under which control version, and who signed it off. If you need the marking itself, you need a second supplier, and you should hear that from us before you hear it from your counsel.

Sources: the consolidated Act and the Commission's own guidance. We link to the text rather than paraphrasing it, because a briefing you cannot check against the source is a sales document wearing a briefing's clothes. Article 50 · Article 99 · Commission transparency guidelines

Where it sits in what you already run

Nothing is replaced. The runtime deploys in your own account, so the only thing crossing the seam is a decision request one way and a verdict with its evidence coming back.

Your EU-facing systems unchanged, nothing replaced The AI systems in scope Your content and publishing pipeline Legal and compliance review Your identity provider Existing disclosure controls output + context evidence + control state no agent installed no data leaves your boundary EcoKure Assurance Runtime deployed in your account · 11 dependencies Article 50 transparency control pack Applicability decisions, recorded Evidence that the disclosure step ran Reviewer sign-off bound to the decision Reconstruction when guidance changes EcoKure never touches • Legal interpretation — your counsel's, never ours • Content marking — needs a specialist provider • Any compliance determination — that is a regulator's • Your publishing pipeline — evidenced, not controlled
This records that a disclosure step happened, on what, under which control version, and who signed it — evidence and reconstruction, not a compliance determination. Article 50(2) machine-readable marking is a different technology and is named in the never list for that reason.

What one decision actually does

The same runtime and the same evidence contract as every other pathway. What changes is the control pack and the workflow.

your EU deployment — evidence never leaves it In scope AI-generated output reaching a person EcoKure Disclosure state and claim checks Decision ALLOW / BLOCK / ABSTAIN Your rules Article 50 transparency pack binds version + hash entry 77 ABSTAIN signed, append-only evidence chain signs every outcome applicability unclear, Queue Held for review with the reason Person Your compliance reviewer entry 203 ALLOW sign-off — commitment only, no identity references, never rewrites Evidence pack export Independent verifier no EcoKure code runs offline
This records that a disclosure step ran, on what, under which control version, and who signed it. It is evidence and reconstruction, not a compliance determination — and it is NOT content marking. Article 50(2) machine-readable marking needs a specialist provider; EcoKure does not do it and says so.
Next · Map the obligation Standards crosswalk