Regulation
What the EU AI Act's transparency rules require from AI in deal software
Article 50 of the EU AI Act applies from 2 August 2026, and the Digital Omnibus that pushed back the high-risk obligations left it on schedule. For any platform with an AI chat or an AI-drafted response, that creates two concrete duties: tell people when they are dealing with an AI system, and mark generated content so it can be detected as generated. This sets out what those duties cover, what they do not cover, and which of them fall on the platform rather than on your deal team.
By the CogniSuite team
What Article 50 of the AI Act actually says
Article 50 of Regulation (EU) 2024/1689 sets transparency duties that apply to certain AI systems regardless of whether those systems are classified as high-risk. Four paragraphs matter for software used on a deal.
Article 50(1) requires providers of AI systems intended to interact directly with natural persons to design and develop them so that the people concerned are informed that they are interacting with an AI system, unless that is obvious. Article 50(1) itself sets that exception against the standard of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. The Commission's FAQ applies the same test from the perspective of an average person.
Article 50(2) requires providers of AI systems that generate synthetic audio, image, video or text to ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The marking must be effective, interoperable, robust and reliable as far as this is technically feasible. The obligation does not apply where the system performs an assistive function for standard editing, or does not substantially alter the input data or its semantics.
Article 50(4) puts obligations on deployers rather than providers. Deployers must disclose deep fakes, and must disclose AI-generated or manipulated text published for the purpose of informing the public on matters of public interest. That second duty falls away where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility.
Article 50(5) says the information must be given in a clear and distinguishable manner at the latest at the time of the first interaction or exposure, and must meet applicable accessibility requirements.
Breach of Article 50 sits in the middle penalty tier under Article 99(4)(g): up to 15 million euros or 3 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs including start-ups, Article 99(6) applies whichever of those is lower.
The Commission maintains a FAQ on Article 50 that is the most useful plain-language reference on scope.
Why the Digital Omnibus did not move the transparency date
Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026, amends the AI Act to simplify its implementation. It postponed the high-risk regime substantially: obligations for Annex III systems move to 2 December 2027, and obligations for Annex I systems embedded in products covered by sectoral legislation move to 2 August 2028. Recital 40 attributes this to delayed standards, common specifications and the delayed establishment of national competent authorities.
Article 50 was not part of that postponement. It still applies from 2 August 2026. The Omnibus made one narrow concession: a transitional period of four months, running to 2 December 2026, for the Article 50(2) marking obligation, and only for providers whose systems were already placed on the market before 2 August 2026. That is a grace period for existing systems to retrofit marking, not a deferral of the obligation.
So a firm reading vendor claims about the AI Act being delayed should check which obligations are meant. The delay is real for high-risk classification work. It does not touch the disclosure and marking rules that apply to an AI chat feature.
Which obligations fall on the platform and which fall on your firm
Article 3(3) defines a provider as a person or body that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. Article 3(4) defines a deployer as a person or body using an AI system under its authority in a professional capacity.
On that reading, a VDR that builds AI features on top of a third-party model and sells the platform under its own name is the provider of that AI system. The bank, sponsor or corporate using the platform is the deployer. Article 50(1) and Article 50(2) therefore sit with the platform. The platform, not you, has to build the disclosure into the interface and has to solve the marking problem.
Article 50(4) sits with you, but only if you publish. A drafted answer sent to a bidder inside a data room is not text published to inform the public on a matter of public interest. Deal documents are private by construction. In practice the deployer-side text labelling duty rarely bites on M&A work, though it can bite on adjacent activity such as a public announcement or a market-facing document assembled with AI assistance.
What the disclosure obligation means for an AI chat in a data room
An AI chat over deal documents is an AI system that interacts directly with a natural person. The disclosure has to be present at the first interaction, not buried in terms of service, and it has to be clear enough that a user who is not paying close attention still understands what is answering them. Streamed answers that appear token by token are precisely the case the rule is aimed at.
The obligation is about the fact of the interaction. Article 50(1) does not require you to name the model, the provider, the version or the architecture. A platform that declines to disclose its model vendor is not thereby in breach.
In CogniSuite, chat answers carry citation links back to the source documents in the room, and AI-drafted replies to counterparty questions are held as drafts visible only to the deal team until a person reviews and sends them. Retrieval for the data-room chat runs under the asking user's own folder permissions. For a draft that will be shown to the other side it runs under what that side is permitted to read, which is narrower than the drafter's own access. In neither case can a generated answer quote a document the person who will read it is not permitted to see. More on the access model is on the security page.
What the machine-readable marking obligation covers
This is the harder duty, and it is worth being straightforward about why. Robust, machine-readable marking is a reasonably well-understood problem for images, audio and video. For short and medium-length text it is not solved. Text watermarking is fragile under paraphrase, truncation and copy-paste, which is exactly what happens to a drafted answer before it reaches a counterparty. The statutory qualifier "as far as this is technically feasible" acknowledges this, but it is a limit on the standard of performance, not a general excuse.
The Commission's AI Office facilitated a voluntary Code of Practice on transparency of AI-generated content, which the Commission and the AI Board have confirmed is an adequate voluntary tool for demonstrating compliance. Signing it is not mandatory and not signing it is not a breach, but it is a reasonable question to put to any vendor whose product generates text.
One misreading to avoid: the human review carve-out lives in Article 50(4), which is a deployer duty about published public-interest text. It does not exempt a provider from Article 50(2). A platform cannot argue that because a banker reviews every draft before sending, the generated output does not need marking. Those are different paragraphs binding different parties.
The exemptions in Article 50(2) also do not rescue a drafting feature. Generating a proposed answer to a diligence request from a set of source documents is not an assistive function for standard editing, and it substantially alters the input data and its semantics. Grammar correction, format conversion and minor cropping sit inside the exemption. Composing prose does not.
What Article 50 does not require
It does not require consent. It does not require you to stop using AI on a deal, or to notify a counterparty each time a draft was AI-assisted before a person edited it.
It does not classify your AI system as high-risk. Article 50(6) is explicit that these transparency duties are without prejudice to the high-risk requirements, which is a saving clause rather than a classification trigger.
It does not impose the logging and record-keeping duties of Article 12, which attach to high-risk systems. Recording AI interactions in a deal audit trail is good practice and useful in a dispute, but Article 50 does not mandate it.
It does not require any particular labelling of internal drafts that never leave your side of the deal.
Limits worth stating plainly
There are honest constraints here, on our own product and on the state of the art.
Machine-readable marking of generated text is an unsettled area, and any vendor claiming a complete solution is overstating it. The realistic posture is to keep generated content inside a system where it is labelled and attributable, and to treat the Code of Practice as the developing reference for what adequate marking looks like.
In CogniSuite, chat conversation history is held in the browser rather than server-side, so a conversation is not itself part of the permanent deal record beyond the per-question entry written to the deal audit log. AI document processing is best-effort and asynchronous, so an extraction failure can leave a document stored and viewable but absent from AI retrieval, and recovery is a manual reprocess action. Neither of those is an Article 50 problem, but both are things a buyer evaluating AI features should ask about directly.
This is a description of the regulation, not legal advice. Anyone assessing exposure across multiple products should take it to counsel.
This article is general information, not legal, tax, or financial advice. For how CogniSuite handles security and access, see Security.
← All articles