ANALYSIS: The AI Act, Brussels Publishes the Final Manual Three Days Out
At the end of this cross-check, the July 20, 2026 publication does not create a new obligation: it locks in, days before the August 2 entry into application, the practical interpretation of an obligation already written into law since the AI Act's adoption, and confirmed once more by every source consulted for this report, from the Commission's own pages to the law firms tracking its rollout in real time. Companies that adopt the Code of Practice benefit from a presumption of compliance confirmed by the AI Board itself, while those choosing another path will have to demonstrate compliance without that shortcut, within a framework where interpretive authority remains split between the AI Office and 27 national authorities. A 51-page manual, published thirteen days before the deadline, is not a calm clarification.
- At the end of this cross-check, the July 20, 2026 publication does not create a new obligation: it locks in, days before the August 2 entry into application, the practical interpretation of an obligation already written into law since the AI Act's adoption, and confirmed once more by every source consulted for this report, from the Commission's own pages to the law firms tracking its rollout in real time. Companies that adopt the Code of Practice benefit from a presumption of compliance confirmed by the AI Board itself, while those choosing another path will have to demonstrate compliance without that shortcut, within a framework where interpretive authority remains split between the AI Office and 27 national authorities. A 51-page manual, published thirteen days before the deadline, is not a calm clarification.
- A technical text that locks in a legal deadline
- What the Commission claims to have produced
Facts, quotes, and cited links remain in the body. Interpretations are framed as analysis or opinion according to the format.
A technical text that locks in a legal deadline
What the Commission claims to have produced
According to the European Commission, the published guidelines "help providers and deployers of AI systems and competent authorities in ensuring compliance with the transparency obligations under Article 50 of the AI Act." This is not a new rule: it is an interpretive document that claims to clarify an obligation already written into European law since the AI Act's adoption.
The Commission states that these guidelines "clarify these obligations" and provide "legal certainty" on their scope, complementing the Code of Practice on Transparency of AI-Generated Content. A manual published three days before a deadline is never just an administrative gesture.
Why the calendar matters as much as the content
According to the Commission, Article 50 of the AI Act "applies from 2 August 2026." Publishing the final version of the guidelines on July 20, 2026 — thirteen days before entry into application — leaves companies an extremely short window to bring their AI systems into compliance, without the buffer a longer runway would normally provide.
Article 50 demands a double transparency
The direct disclosure obligation
According to the Commission, providers must explicitly inform people when they are interacting directly with an AI system, and add machine-readable markers so AI-generated or manipulated content can be detected. This double obligation — inform the human, mark the machine — structures the core of the transparency framework.
Deployers, for their part, must inform individuals when they are exposed to emotion recognition tools, biometric categorization, deepfakes, or text publications on matters of public interest without human review or editorial oversight.
What the provider/deployer distinction means in practice
Separating provider obligations from deployer obligations spreads responsibility across the whole chain: whoever builds the AI system is not necessarily whoever uses it in front of the public, and Article 50 demands transparency at every link, not just at the technical origin of the system. A chain of responsibility only works if every link actually knows it is one.
A risk-based approach, not a technology-based one
Four categories, one hierarchy
According to the Commission, implementing the guidelines fits within a "risk-based" approach to the AI Act, which sorts AI systems into four risk categories. This structure means required transparency is not uniform: it varies by the risk level tied to a system's specific use, not by the underlying technology itself.
Sorting by risk rather than technology means refusing to freeze the law onto a tool that changes too fast.
What this approach protects, and what it leaves open
A risk-based classification guards against the rapid obsolescence of a law tied to one specific technology. But it also leaves room for interpretation by supervisory authorities, who must decide case by case which category a new or hybrid AI system belongs in, a judgment call that will likely produce inconsistent results across the bloc in the first months after the deadline.
July 20 replaces a May consultation draft
What the publication actually changed
According to the Commission, the July 20, 2026 publication put online the final version of the guidelines, replacing the May 2026 consultation draft. This shift from a consultative draft to a final text means the public comment period is closed: economic actors must now work with the definitive text, not a still-negotiable version.
According to law firm Faegre Drinker, on July 20, 2026, the European Commission published the final version of its guidelines and the AI Board confirmed that the Code of Practice on Transparency of AI-Generated Content is "adequate" for demonstrating compliance with Article 50.
What this double confirmation means for businesses
A company that already adopts the Code of Practice benefits from a presumption of compliance recognized by the AI Board itself. One that chooses another path will have to demonstrate compliance through other means, without benefiting from this procedural shortcut.
Fifty-one pages, a shared interpretive authority
The scale of the final document
According to law firm Bird & Bird, the final version of the guidelines runs 51 pages, and practical interpretive authority should fall to national market surveillance authorities and, within its exclusive scope, to the AI Office. Fifty-one pages to interpret a single legal article gives a sense of the real complexity behind an apparently simple obligation: telling someone they're talking to a machine.
Fifty-one pages for one obligation: the article's simplicity says nothing about its real complexity.
What splitting authority between the AI Office and national bodies complicates
Splitting authority between a central European body and national authorities scattered across 27 member states creates a risk of slightly divergent interpretations depending on the country of application, even though the European text remains theoretically singular. A company operating across several member states could, in theory, face a stricter reading of Article 50 in one jurisdiction and a more lenient one in another, simply because the national authority tasked with day-to-day enforcement interprets the same 51-page guideline document differently, absent a single European court ruling that would settle the disagreement definitively. One law interpreted by twenty-seven different authorities is no longer quite one law.
The non-binding status, a crucial nuance
An interpretive document, not a new law
The sources note that these guidelines remain non-binding in the strict sense: they add no new legal obligation beyond the text of the AI Act itself. They offer a reading, a method, a manual — but the legal foundation remains Article 50 as adopted by the European legislator, not the 51-page document published July 20.
This report therefore avoids any phrasing that would suggest these guidelines create a standalone norm. A manual is never the law; it is only the law's practical translation, always revisable.
Why this legal distinction protects businesses as much as citizens
If the guidelines carried standalone legal force, revising them would require a full, complex legislative process. Their non-binding status lets the Commission adjust them more quickly if real-world application reveals blind spots, without going through the European Parliament for every tweak.
Penalties, a subject institutional pages avoid
What only law firms detail
Penalty amounts and the AI Act's extraterritorial reach are mentioned by law firms like Faegre Drinker and Bird & Bird, but not directly by the Commission's institutional pages consulted for this report. This communication asymmetry — financial risks documented mainly by private advisors rather than the institution enforcing the law — deserves to be flagged.
When the institution that legislates leaves law firms to quantify the risk, public communication stays incomplete.
What this asymmetry means for an unadvised business
A small business without specialized legal counsel could rely solely on the Commission's pages and underestimate the real scale of the financial risk tied to non-compliance, for lack of easy access to information that only specialized firms seem to document in detail. A founder running a five-person startup, without a general counsel on staff, is far more likely to stop reading at the Commission's official summary than to commission a 51-page legal memo from a firm like Bird & Bird, simply because the latter costs money the former startup may not yet have budgeted for compliance work. Access to legal information becomes, in practice, an advantage reserved for those who can afford a law firm.
The silence of French-language sources
An absence that raises questions
Discover
No French-language primary source dated within the July 28–August 1, 2026 window could be identified for this specific event, despite its European institutional origin. That gap is paradoxical: a text produced by an institution that counts French among its official working languages does not, at this stage, benefit from any identified French-language primary journalistic coverage for this specific window, even though French remains one of the European Union's central procedural and administrative languages across nearly all of its main institutions and administrative bodies today.
This French-language silence on a European topic may reveal that coverage of technology regulation remains, even in French-speaking Europe, heavily dependent on English-language sources and law firms, even though Belgium and Luxembourg are among the member states directly affected by this August 2 deadline. A European text with no immediate French-language echo isn't a minor anomaly; it's a symptom.
The May-to-July calendar reveals an opaque process
Two months of consultation, a transformed text
Between the May 2026 consultation draft and the July 20, 2026 final version, roughly two months passed. None of the sources consulted for this report details precisely what substantive changes were made between the two versions, which limits this report's ability to assess whether the public consultation actually shaped the final outcome. That documentary gap is not unique to this report: it reflects a broader opacity in European consultation processes, where intermediate drafts of a text are rarely published side by side with the final text to allow an accessible line-by-line comparison for the general public, leaving outside observers to rely on secondhand legal commentary rather than a transparent paper trail of the negotiation itself.
This lack of a detailed comparison between the May draft and the July text remains a documentary limit of this report, not a claim that no substantive change occurred, and readers seeking that level of textual granularity should consult the Commission's own archive directly rather than rely on this report's synthesis alone.
What this two-month gap means for the process's legitimacy
A two-month gap between consultation and final version can signal either a serious revision process or a largely formal consultation whose outcome was already settled. The available sources do not allow us to settle between these two readings, and this report refuses to pretend otherwise simply because a firm conclusion would read more satisfyingly than an honestly acknowledged uncertainty.
Deepfakes and public-interest content, singled out
A category of its own among deployment obligations
Among the obligations cited by the Commission, the one covering text publications on matters of public interest without human review or editorial oversight potentially applies to media outlets themselves if they publish AI-generated content without adequate human supervision. This provision links the AI Act to disinformation concerns that go beyond the strict technology framework.
Deepfakes are the subject of a distinct, specific mention, which suggests the European legislator considers them a risk category particular enough not to be diluted into a generic transparency obligation. Separating deepfakes from the rest means admitting they form a danger category of their own.
The GDPR precedent hangs over this deadline
A comparison the sources do not explicitly draw
Article 50's entry into application echoes, in structure, the GDPR's entry into force in 2018: a European text published years before its application, followed by a final scramble of practical clarifications in the weeks before the deadline. None of the sources consulted for this report explicitly draws this GDPR parallel; it remains this report's own editorial observation, not a direct quote.
That parallel, even unconfirmed by the sources, helps explain why European businesses have already lived through this scenario multiple times over the past decade: an ambitious law, a compliance grace period that looks long on paper, then a real scramble in the final weeks, fueled by consulting firms selling, under pressure, what the transition period should have let companies plan for calmly. History doesn't repeat, but European regulatory calendars seem to keep the same rhythm.
What this comparison does not license us to claim
On the same topic
This report does not claim the AI Act will produce the same economic or legal effects as the GDPR. The comparison serves only to illuminate a compliance rhythm already observed elsewhere, not to predict a precise economic or legal outcome for the AI Act.
American businesses face a law that does not spare them
A reach that extends beyond European borders
According to the firms consulted for this report, the AI Act's extraterritorial reach potentially touches non-European companies that deploy AI systems accessible to European Union citizens, regardless of where the company itself is established. This extraterritorial reach echoes, again, GDPR logic.
An American company offering an AI service accessible in Europe cannot ignore Article 50 on the grounds that it isn't European, however small its European user base or however far removed its headquarters from Brussels. For this law, the European border isn't geographic: it follows the user, not the headquarters.
What this extraterritoriality means in practice
In practice, a company based outside the European Union must build Article 50's transparency obligations into its operations as soon as it targets, even partially, European users, or risk facing the same exposure as competitors based on European soil. This user-based territorial logic, rather than one based on corporate headquarters, forces businesses of every size to audit their actual markets, market by market, rather than relying solely on their incorporation address to determine whether the AI Act applies to them. A U.S. startup with a few thousand European users among a mostly North American user base remains, despite that minority share, fully subject to Article 50 for that specific slice of its activity.
The Code of Practice, a fast lane to compliance
What the word "adequate" actually means
When the AI Board confirms the Code of Practice is "adequate" for demonstrating compliance with Article 50, it effectively creates a privileged compliance lane. A company that voluntarily joins this code benefits from a favorable presumption before supervisory authorities, without having to prove compliance point by point using a method it invented itself.
This mechanism resembles a form of voluntary certification that, without being mandatory, becomes in practice the lowest-risk path for any company wanting to avoid a prolonged compliance dispute. The cost of stepping outside this marked path isn't strictly legal, since the law doesn't force anyone to join the code; it is mainly a cost of proof, with each dissenting company having to build, case by case, its own demonstration of compliance. A non-mandatory path that becomes the only truly safe one isn't, in practice, really optional anymore.
What this presumption does not guarantee
Joining the Code of Practice does not guarantee total immunity: the presumption of compliance remains rebuttable if a supervisory authority demonstrates that a company, despite its formal adherence to the code, does not actually meet Article 50's substantive obligations in day-to-day practice.
The coming months will reveal the real-world application
The distance between the text and practice
A 51-page text, however precise on paper, does not guarantee uniform application starting August 2, 2026. The first weeks following entry into application will likely reveal areas of uncertainty that neither the Commission nor the firms consulted for this report anticipated in detail, simply because confronting real cases always reveals situations that abstract legislative drafting cannot fully foresee.
None of the sources consulted for this report offers an estimate of how many European or foreign companies are already compliant as of this report's publication date. That absence of hard numbers on real readiness levels limits this report's ability to assess whether the August 2 deadline will be experienced as a formality or as a regulatory shock for a significant share of the market. Nobody knows how many companies will be ready on August 2; that gap says a lot.
Why this statistical gap deserves to be named
A statistical gap is not neutral: it means that neither European institutions nor the specialized firms consulted have, at this stage, a reliable overall picture of how prepared the economic actors covered by Article 50 actually are, whether large technology platforms, regional media outlets using generative tools, or small businesses that may not even yet realize they are covered by this deadline at all, let alone have a compliance plan in place before it arrives.
A manual that locks in, without inventing anything
At the end of this cross-check, the July 20, 2026 publication does not create a new obligation: it locks in, days before the August 2 entry into application, the practical interpretation of an obligation already written into law since the AI Act's adoption, and confirmed once more by every source consulted for this report, from the Commission's own pages to the law firms tracking its rollout in real time. Companies that adopt the Code of Practice benefit from a presumption of compliance confirmed by the AI Board itself, while those choosing another path will have to demonstrate compliance without that shortcut, within a framework where interpretive authority remains split between the AI Office and 27 national authorities. A 51-page manual, published thirteen days before the deadline, is not a calm clarification.
Sources
Primary sources
European Commission — Guidelines on transparency obligations for providers and deployers
Secondary sources
Faegre Drinker — EU AI Act: Commission Confirms Transparency Code of Practice as Adequate
Bird & Bird — European Commission adopts final Guidelines on AI Act Article 50
Stibbe — The AI Act's Transparency Obligations: Rules, Scope and Timeline
artificialintelligenceact.eu — The EU AI Act's Transparency Rules: A Practical Guide
Practical Law — EU AI Act transparency requirements: checklist
Get the geopolitics analyses
Conflicts, powers, alliances: the MadMax thread without the noise.
Cite this article
Maxime Marquette (2026). ANALYSIS: The AI Act, Brussels Publishes the Final Manual Three Days Out. MadMax. https://mad-max.co/en/article/the-ai-act-brussels-publishes-the-final-manual-three-days-out
Enjoyed this piece? Get the next one.
One chronicle a week, straight to your inbox. No noise.
This article was generated with AI assistance, under human supervision.
Comments
Be the first to weigh in.