The EU AI Act (Regulation (EU) 2024/1689) supplies the core duties recorded here.
Article 50 requires disclosure of AI interaction, machine-readable marking of synthetic output, and labeling of deepfakes and AI-generated public-interest text, effective 2 August 2026; the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) left it largely untouched, adding only a four-month transition, to 2 December 2026, for the machine-readable marking sub-duty on generative systems already on the market before 2 August 2026.
Article 53 requires providers of general-purpose AI models to publish a training-content summary, adopt a copyright-compliance policy honoring Text and Data Mining opt-outs, and, for a model carrying systemic risk, test for and report serious incidents, effective 2 August 2025.
Article 55 adds a second, separate incident-reporting duty on a different bound party: a provider of a general-purpose AI model the Commission has classified as carrying systemic risk must keep track of, document, and report relevant information about serious incidents and corrective measures to the AI Office, and as appropriate to national competent authorities, without undue delay, effective 2 August 2025.
That duty states no number of days and no explicit moment it runs from; the day counts a signatory provider works to sit in the AI Office's General-Purpose AI Code of Practice rather than in the Regulation.
Article 73 requires providers of high-risk AI systems, and deployers who identify one, to report a serious incident to the market surveillance authority of the Member State where it occurred, on a clock of 15 days in the ordinary case, 10 days where the incident caused a person's death, and 2 days for a widespread infringement or an incident causing a serious and irreversible disruption to critical infrastructure, effective on the Regulation's general 2 August 2026 application date; the Digital Omnibus left Article 73's own text and clocks unchanged, and its deferral of Chapter III's high-risk-system obligations to 2027 and 2028 does not reach Article 73, which sits in Chapter IX, though the Omnibus did add a narrow Article 75 derogation redirecting the report to the AI Office, on the same clocks, for providers under the AI Office's own exclusive supervisory competence.
Articles 9, 10, 14 and 15 add the core Chapter III, Section 2 duties for a high-risk AI system itself: risk management, training data governance, human oversight, and accuracy, robustness and cybersecurity, each deferred by the same Digital Omnibus schedule to 2 December 2027 for a system classified high-risk under Article 6(2) and Annex III and to 2 August 2028 for one classified under Article 6(1) and Annex I. A narrower, platform-side duty sits in Digital Services Act Article 35(1)(k): very large online platforms and search engines must, as one item on an illustrative list of systemic-risk mitigation measures, consider making manipulated content that appreciably resembles real persons or events distinguishable through prominent markings.
The Political Advertising Regulation (Regulation (EU) 2024/900) is excluded here: its labeling duties concern ad sponsorship and targeting, not AI generation.
Digital Services Act Article 37 is carried here as the audit machinery over that platform-side duty and the rest of Chapter III: a designated very large online platform or search engine must submit to an independent audit at its own expense at least once a year, and the audit report and the provider's implementation report both go to the Digital Services Coordinator of establishment and the Commission and are then published. Article 37 is not itself an AI law; it is how compliance with the obligations that include Article 35(1)(k) is checked.