Regulation

What the EU AI Act's transparency rules require from AI in deal software

Article 50 of the EU AI Act applies from 2 August 2026, and the Digital Omnibus that delayed the high-risk regime left that date alone. Almost all of the work falls on the platform you run the deal on rather than on your deal team, so the useful question is what to ask a vendor. This sets out the two duties, who carries each one, and where the honest limits are.

By the CogniSuite team

What changes for your deal team on 2 August 2026

For most deal teams, the work sits with the vendor. If the platform you run the deal on has an AI chat or drafts responses to the other side, it is the provider of an AI system under the Act, and the two Article 50 duties are its duties: tell people they are dealing with an AI system, and mark generated content so it can be detected as generated. You do not have to build either. You do have to know whether your platform has.

Disclosure is the easy half. The question worth pressing a vendor on is what the AI is allowed to read and say, because that is what carries risk on a live deal. In CogniSuite, every AI feature that reads deal documents goes through one retrieval function, and it applies the asking user's folder permissions before a document is admitted to an answer. Each deal runs in its own database file, so retrieval cannot reach another deal. When the AI drafts a reply for the other side, the documents it may quote are scoped to what that side is permitted to read rather than what the person drafting can see, and the scoping denies rather than widens when it cannot resolve who the counterparty is. Every quote in that draft is checked against the real document text on the server before it is shown, and the draft stays with the deal team until a person reviews and sends it.

Article 50 does not require any of that. It is what a buyer of deal software should ask about anyway.

What Article 50 actually says

Article 50 of Regulation (EU) 2024/1689 applies whether or not a system is high-risk. Article 50(1) requires providers of AI systems intended to interact directly with natural persons to design them so people are informed they are interacting with an AI system, unless that is obvious to a person who is reasonably well-informed, observant and circumspect in the context of use. Article 50(5) requires that information to be given clearly at the latest at first interaction.

Article 50(2) requires providers of systems that generate synthetic audio, image, video or text to ensure the outputs are marked in a machine-readable format and detectable as artificially generated. The marking must be effective, interoperable, robust and reliable as far as this is technically feasible. It does not apply where the system performs an assistive function for standard editing, or does not substantially alter the input data or its semantics.

Breach sits in the middle penalty band under Article 99(4)(g): up to 15 million euros or 3 percent of worldwide annual turnover, whichever is higher, and the lower of the two for SMEs under Article 99(6). The Commission's FAQ on Article 50 is the clearest reference on scope.

Why the Digital Omnibus did not move the transparency date

Regulation (EU) 2026/1744 of 8 July 2026, published in the Official Journal on 24 July 2026, postponed the high-risk regime substantially. Obligations for Annex III systems move to 2 December 2027, and those for Annex I systems embedded in regulated products to 2 August 2028.

Article 50 was not part of that postponement. It still applies from 2 August 2026. The Omnibus made one narrow concession: four months, to 2 December 2026, for the Article 50(2) marking obligation, and only for providers whose systems were on the market before 2 August 2026. That is a grace period to retrofit marking, not a deferral. So when a vendor says the AI Act has been delayed, ask which obligations they mean. The delay does not touch the rules for an AI chat feature.

Which duties fall on the platform and which fall on your firm

Article 3(3) defines a provider as a body that develops an AI system, or has one developed, and places it on the market under its own name. Article 3(4) defines a deployer as a body using one under its authority in a professional capacity. A VDR that sells an AI-equipped platform under its own name is the provider. The bank, sponsor or corporate using it is the deployer.

Deployers carry Article 50(4), which covers deep fakes and AI-generated text published to inform the public on matters of public interest. A drafted answer sent to a bidder is not published text of that kind, so the duty rarely bites on M&A work. It can bite on a public announcement assembled with AI.

What the disclosure obligation means for an AI chat in a data room

An AI chat over deal documents interacts directly with a natural person. The disclosure has to be present at the first interaction, not buried in terms of service, and clear enough that an inattentive user understands what is answering.

The obligation is about the fact of the interaction. Article 50(1) does not require you to name the model, provider, version or architecture, so a platform that declines to disclose its model vendor is not in breach for that reason.

A user should also see where an answer came from. In CogniSuite, chat answers are instructed to cite the documents they rely on as links back to those documents in the room, using each document's own title as the link text. Retrieval re-runs server-side under the asking user's own permissions on every turn, so replayed conversation history cannot widen what the AI reaches, and each question is written to the deal audit log. The access model is set out on the security page.

What the machine-readable marking obligation covers

This is the harder duty. Marking is well understood for images, audio and video. For text it is not solved. Text watermarking is fragile under paraphrase, truncation and copy-paste, which is what happens to a drafted answer before it reaches a counterparty. The qualifier "as far as this is technically feasible" limits the standard of performance rather than excusing the duty.

The Commission's AI Office facilitated a voluntary Code of Practice on transparency of AI-generated content, which the Commission and the AI Board have confirmed is an adequate tool for demonstrating compliance. Signing it is not mandatory, but it is a fair question to put to any vendor that generates text.

There are two misreadings to avoid. The human review carve-out lives in Article 50(4), a deployer duty about published text, so it does not exempt a provider from Article 50(2). And the Article 50(2) exemptions do not rescue a drafting feature. Grammar correction and format conversion sit inside the exemption. Composing an answer to a diligence request does not.

What Article 50 does not require

It does not require consent, or telling a counterparty each time a draft was AI-assisted before a person edited it. It does not classify your AI system as high-risk, because Article 50(6) is a saving clause and not a classification trigger. It does not impose the Article 12 record-keeping duties, which attach to high-risk systems. It does not require labelling of internal drafts.

Limits worth stating plainly

Machine-readable marking of generated text is unsettled, and any vendor claiming a complete solution is overstating it. The realistic posture is to keep generated content where it stays attributable and treat the Code of Practice as the reference.

Our own limits are worth naming too. The instructions telling the model to stay grounded and ignore instructions embedded in documents are prompt-level, so they are mitigation and not enforcement. In chat, the citation rule is one of those instructions, not a verifier. The boundaries that hold are the per-deal database, the permission check before retrieval, and the server-side quote verification on counterparty-facing drafts. Retrieval admits any folder a user can read at all, including view-only and watermarked folders, so an answer can quote text from a document that user cannot download. Chat history is held in the browser, so a conversation is not part of the deal record beyond that audit entry. Document processing is best-effort and asynchronous, so an extraction failure can leave a document viewable but absent from AI retrieval until someone reprocesses it. The audit trail is readable by the advisor running the deal, not by all parties.

None of that is an Article 50 problem, but all of it is worth asking any vendor about directly, including us. This is a description of the regulation and not legal advice, and anyone assessing exposure across several products should take it to counsel.

General information, not legal, tax or financial advice. For how CogniSuite handles security and access, see Security. To see it on a live deal, book a walkthrough.

← All articles