Data governance and sovereignty
Legal framework, GDPR, AI Act, technological sovereignty.
Attention goes to high-risk systems and prohibited practices. Yet it is Article 50, the transparency obligations, that reaches the largest number of organisations: it applies to any generative AI system, whatever its risk level, and open-source systems are not exempted.
A system designed to interact with natural persons must inform them that they are dealing with an AI, unless obvious from context. The draft guidelines specify this also covers agentic systems.
Providers of systems generating audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated.
Deployers must inform exposed persons of the operation of the system.
Deployers producing a deepfake must disclose that the content was artificially generated or manipulated; an AI-generated text published to inform the public must be disclosed too.
The checklist details each check: what it covers, who owns it in the organisation (general management, legal, communication, IT), the typical mistake seen in practice, and a model notice or clause to adapt. Including the most neglected check (your own conversational interfaces, already in production) and the most sensitive one (your published texts on matters of public interest). Document in French.
Application of the transparency obligations: 2 August 2026. That is settled. Upstream, the Commission published draft guidelines (8 May 2026) then a code of practice (10 June 2026). A deferral to 2 December 2026 was envisaged for the machine-readable marking obligation only, for systems already on the market; the checklist explains why pausing your preparation on that basis would be a disproportionate risk.
For general management, legal, communication, compliance and IT. Written in July 2026. AI law moves fast; check the state of the text before any decision.
Epistemic Security and Information Resilience
Article 50 mandates a minimum of transparency. But deciding in an environment where information is manipulated (deepfakes, synthetic content, coordinated campaigns) takes more than compliance. That is the purpose of our executive track, grounded in doctoral research.
Four tracks for the teams concerned by Article 50: governance and legal framework, deepfake detection, generative AI for executives, and executive information security. All OPCO-eligible.
Legal framework, GDPR, AI Act, technological sovereignty.
Recognise synthetic content (voice, image, video), assess the risk to the organisation and trigger the right protocol under attack.
Understand, govern and deploy generative AI in your organisation.
One day to understand disinformation mechanics, detect manipulated content and protect both decision-making and reputation.