What the EU AI Act Means for Agencies Using AI Translation
EU AI Act translation rules explained for agencies: who counts as a deployer, what Article 50 disclosure covers, and the AI literacy duty enforced since August.

Most EU AI Act translation questions we get come from the same place. An agency owner has a procurement form on the desk, a client asking whether AI touched the files, and no clear sense of which parts of a hundred-article regulation are actually theirs to worry about. The honest answer is narrower than most people expect. Very little translation work falls into the high-risk category the regulation was mostly written for, and the duties that do reach a working agency are organisational rather than technical. One of them has been enforceable since 2 August 2026. What follows is how we read the rules after a year of these conversations. We are not lawyers, and anything with real money attached deserves a real legal opinion.
eu ai act translation obligations: what actually applies to an agency
The regulation sorts AI systems by risk, not by industry. A short list of practices is banned outright under Article 5. A larger set of uses is classed as high-risk under Annex I and Annex III, and those carry the heavy machinery: risk management systems, data governance, technical documentation, human oversight, conformity assessment. Below that sits a transparency layer in Article 50. Below that sits everything else, which the regulation leaves largely alone.
Translation as a service does not appear in Annex III. Producing a translated DOCX, XLSX or PPTX for a client is not, by itself, a high-risk use. That one fact removes most of what agencies are afraid of.
Two things complicate the picture. The first is timing. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and pushed the high-risk deadlines back. Stand-alone Annex III systems now have until 2 December 2027, and AI embedded in regulated products under Annex I until 2 August 2028. Several agencies we spoke to in August read that as the whole regulation being postponed. It was not. Article 50 transparency and Article 4 AI literacy were untouched by the deferral, and both have applied since 2 August 2026.
The second complication is geography. The Act reaches you if you place an AI system on the EU market, put one into service in the EU, or if the output the system produces is used in the Union. An agency in Kazakhstan or Argentina translating a manual for distribution to EU customers is not automatically outside the scope. In practice the pressure arrives through a client's procurement questionnaire long before it arrives through a regulator.
provider or deployer? the distinction that sets your obligation list
The Act assigns duties by role, and the role you occupy changes your obligation list more than anything else in the text.
A provider develops an AI system and places it on the market under its own name or trademark. A deployer uses an AI system under its own authority in a professional context. Almost every translation agency is a deployer. You send files to a commercial tool, you get translated files back, and the vendor who built and sells that tool carries the provider duties.
This matters because the obligation agencies worry about most, the machine-readable marking of synthetic text in Article 50(2), is a provider duty. It is not yours to implement. Your job is to know whether your vendor does it, and to be able to answer when a client asks.
You can become a provider without intending to. Two routes are common. The first is branding: put your name or trademark on an AI system and offer it to clients as your own, and you inherit provider obligations for it. The second is substantial modification. An agency that fine-tunes a model on client translation memory, wraps it in a portal and sells self-service access has built something new, and the AI Act treats it that way.
The boundary is not always sharp. Adding a prompt template and a glossary injection step on top of a vendor's API is closer to configuration than to building a system. Training a model on your own data and marketing the result is not. If your agency is anywhere near the second case, that is the point where a legal opinion stops being optional.
article 4 ai literacy is the duty that reaches nearly every agency
Article 4 has applied since 2 February 2025, and the Commission confirmed that supervision and enforcement began on 2 August 2026. It requires providers and deployers to take measures ensuring a sufficient level of AI literacy among their staff and anyone else operating AI systems on their behalf. There is no prescribed curriculum, no certificate, no examining body. That flexibility is why so many agencies have quietly ignored it.
For a translation agency, the people in scope are your project managers who decide when AI runs, your in-house reviewers who post-edit the output, and any freelancer using your tools under your instruction and your account. A freelancer working on their own subscription, under their own responsibility, is a deployer in their own right and carries their own obligation.
The AI Office published a Q&A and a living repository in 2025 making clear that a single onboarding video does not satisfy Article 4, and that organisations should keep documentation of the measures they put in place. Our reading of what a proportionate version looks like for a twelve-person agency: a two-page internal note explaining what the translation engine does and does not do, a short list of the failure modes your reviewers should expect, a named escalation path when output looks wrong, and a record of who read it and when.
The failure modes are the part worth spending time on. In documents we have seen come back from AI translation, the recurring problems are dropped negation in safety instructions, numbers and units that survive as digits but shift meaning in context, and terminology drift across a long file where one source term arrives in three different forms. A reviewer told to check those specific things catches more than a reviewer told to check quality.
what article 50 actually says about translated text
Article 50(2) requires providers of AI systems generating synthetic text to mark outputs in a machine-readable format and make them detectable as artificially generated. It carries a carve-out that matters here: the obligation does not apply where the system performs an assistive function for standard editing, or does not substantially alter the input data provided by the deployer or the semantics thereof.
Translation sits in a genuinely arguable position under that carve-out. It rewrites the surface form completely while the entire purpose of the exercise is to preserve the semantics. We would not build a compliance position on that argument alone, and neither should you, but it explains why the marking question has not produced the panic some people expected. Systems already on the EEA market before 2 August 2026 have until 2 December 2026 to comply.
The provision agencies actually ask about is the second subparagraph of Article 50(4). Deployers of an AI system that generates or manipulates text published to inform the public on matters of public interest must disclose that the text was artificially generated or manipulated. Two limits are built into that sentence, and both are load-bearing.
The first limit is subject matter. It covers text published to inform the public on matters of public interest. A municipal health authority's advisory, translated into five languages and posted on a public website, is squarely inside. A distributor's product catalogue, an internal HR handbook, a supplier contract, a set of financial statements going to three named stakeholders: none of those are published to inform the public on a matter of public interest, and the disclosure duty does not reach them.
The second limit is the exception. The obligation does not apply where the AI-generated content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication. A standard MTPE workflow with a named post-editor and a client sign-off sits inside that exception. This is the most useful sentence in Article 50 for an agency, and it rewards you for something you were probably doing anyway, provided you can show the review happened.
Penalties for non-compliance with Article 50 reach €15 million or 3% of worldwide annual turnover, whichever is higher. For most agencies the practical risk is not a fine but a failed procurement round.
when a translation project does touch high-risk territory
Translation is not in Annex III. Your output can still become a component of something that is.
Two patterns come up. The first is recruitment. If you translate candidate assessments, screening questionnaires or scored application forms for a platform that uses AI to filter or rank applicants, your text is feeding a use listed in Annex III. The second is education: translating exam content or admissions materials for a system that evaluates learning outcomes.
In both cases the high-risk obligations sit with the provider of that downstream system, not with you. What happens in practice is that the provider pushes requirements down the chain through the contract. We have seen the resulting clauses. They ask for documented QA on the translated content, records identifying which human reviewed which segments, version traceability so a deployed string can be traced back to a specific delivery, and a commitment to notify on errors found after delivery. None of that is exotic for an agency with a functioning process. All of it is painful for one that does not track who reviewed what.
The Digital Omnibus deferral gives you until 2 December 2027 on the Annex III side. That is a reprieve rather than a cancellation, and the buyers preparing for it are writing the clauses now.
Worth separating from all of this: sworn, certified and notarised translation. Those are governed by national law on official documents rather than by the AI Act, and the rules on whether a machine may touch the text at all vary by country. If you deliver certified work, that question is answered somewhere other than in this regulation.
what to put in your contracts and your internal ai policy
The documents that resolve most client conversations are shorter than agencies assume.
In client-facing contracts, state plainly whether AI is used, at which step of the process, and whether human post-editing is included. Vague language here is what turns a routine question into a trust problem later. Name which vendor processes the content, where it is processed, and what the retention period is. Our earlier piece on data privacy in AI translation covers what clients tend to ask about that step.
Keep a human review record per project: who reviewed, when, and what changed. This is the evidence that supports the Article 50(4) editorial-responsibility exception, and it is the first thing an enterprise buyer asks to see. A column in your project tracker is enough. Reconstructing it from email six months later is not.
Ask your AI translation vendor two direct questions and keep the answers in writing. Does the vendor consider itself a provider under Article 50(2), and what marking does it apply to generated text? The AI translation vendor security checklist we published earlier covers the adjacent data-handling questions that belong in the same conversation.
One thing to avoid: marketing yourself as "AI Act compliant". Compliance under this regulation attaches to specific obligations for a specific role, and a blanket claim reads to an informed buyer as a sign that nobody at the agency has read the text. Saying "we are a deployer, here is our AI literacy documentation, here is our human review record" is both more accurate and more persuasive.
what to do this quarter
Four things, in order, none of which needs a lawyer to start.
Write down your role. In one paragraph, state that your agency is a deployer of AI translation systems, name the vendors, and note that you do not place any AI system on the market under your own name. If that last part is not true, that is the item to take to counsel.
Produce the AI literacy note. Two pages covering what your engine does, its known failure modes, and who to escalate to. Circulate it and record who confirmed reading it. This is the obligation that has been enforceable since August, and it is the cheapest one to close.
Add the human review column to your project tracker, starting with the next project rather than retroactively. Reviewer name, review date, whether changes were made.
Send your vendor the two Article 50(2) questions and file the reply. If the vendor cannot answer, that answer is also information.
None of this makes an agency compliant in some final sense, because the regulation does not work that way. It does mean that when the next procurement form arrives with an AI section, you fill it in from records rather than from memory.