Key takeaways
- EU AI Act Article 50 has applied since 2 August 2026. It is the transparency chapter, and it reaches almost every organisation that puts a chatbot, a generative model or a synthetic image in front of the public.
- The Digital Omnibus, Regulation (EU) 2026/1744, pushed Annex III high-risk duties to 2 December 2027 and left this article exactly where it was. For most companies, EU AI Act Article 50 is the only part of the Regulation that binds today.
- One deadline is still ahead: systems already on the market before 2 August 2026 have until 2 December 2026 to satisfy the machine-readable marking duty in Article 50(2).
- Two duties fall on providers, two on deployers, and the split does not follow who owns the budget. A company that publishes output from someone else’s model is a deployer with its own obligations.
- Breach is priced at up to EUR 15 million or 3 percent of worldwide annual turnover. What an authority will actually ask for is not the label, it is the record showing you decided, tested and documented.

EU AI Act Article 50: the four duties in plain terms
EU AI Act Article 50 is short, and it is built from four separate duties plus one rule about how the information is delivered. Reading it as a single “transparency obligation” is the most common way teams get it wrong, because each duty attaches to a different actor and a different trigger.
What providers owe
Article 50(1) applies to providers of AI systems intended to interact directly with natural persons. The system must be designed so that the person is informed they are dealing with an AI system. The duty sits in the design, not in a support script, which means it belongs to whoever builds or rebrands the assistant rather than to the team that later switches it on. Article 50(2) applies to providers of systems that generate synthetic audio, image, video or text, including general-purpose AI systems. Outputs must be marked in a machine-readable format and detectable as artificially generated or manipulated. The Regulation asks that the technical solution be effective, interoperable and reliable as far as this is technically feasible, taking account of the state of the art and the limitations of each content type.
What deployers owe
Article 50(3) applies to deployers of an emotion recognition system or a biometric categorisation system, who must inform the people exposed to it that the system is operating, and process any personal data in line with the GDPR. Article 50(4) applies to deployers in two situations. First, where an AI system generates or manipulates image, audio or video content that constitutes a deep fake, the deployer must disclose that the content is artificially generated. Second, where AI-generated or manipulated text is published to inform the public on matters of public interest, the deployer must disclose that too. Article 50(5) is the delivery rule that governs all four. The information must reach the person in a clear and distinguishable manner, at the latest at the time of first interaction or exposure, and it must meet the applicable accessibility requirements. A line in the terms of service does not satisfy it. Neither does a grey caption that appears after the user has already acted on the output.
The dates: 2 August 2026, 2 December 2026, and what the Omnibus did not move
Timelines are where most published guidance on EU AI Act Article 50 is now wrong, because a large share of it was written before the summer of 2026. EU AI Act Article 50 became applicable on 2 August 2026, on the schedule set in the original Regulation. On 20 July 2026, less than two weeks earlier, the European Commission adopted its final Guidelines on transparency obligations, a 51-page document addressed to competent authorities as well as to providers and deployers. The Guidelines are not binding, and only the Court of Justice can give an authoritative reading of the Regulation, but national market surveillance authorities can be expected to work from them. There is one transitional window still open. Providers of systems that generate synthetic audio, image, video or text and that were already placed on the market before 2 August 2026 have until 2 December 2026 to comply with the marking duty in Article 50(2). That date is the single most useful thing to know about EU AI Act Article 50 right now, and it is absent from almost every guide currently ranking on the term. The contrast with the rest of the Regulation is what makes this urgent rather than routine. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026. It moved standalone Annex III high-risk obligations to 2 December 2027 and Annex I embedded obligations to 2 August 2028. It did not touch EU AI Act Article 50. So a company that has been pacing its EU AI Act compliance programme against the high-risk calendar has quietly been running late on the one chapter that is already enforceable.
Provider or deployer: who owes which duty
The provider and deployer roles are defined in Article 3, and EU AI Act Article 50 allocates duties strictly along that line. A provider develops an AI system, or has one developed, and places it on the Union market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority in a professional capacity.
The value chain in practice
Most organisations sit on both sides at once. A software company that fine-tunes a foundation model and ships it as a product is a provider for Articles 50(1) and 50(2). The same company, publishing an AI-written market commentary on its own blog, is a deployer for Article 50(4). The two duties are assessed separately and neither absorbs the other. The role can also shift underneath you. Putting your own name or trademark on a third-party system, or substantially modifying it, can make you the provider of that system with the full set of provider duties attached. Teams that treat model integration as a procurement decision rather than a governance one tend to discover this late. This is one of the places where a live AI system inventory stops being a nice-to-have.
The case of the company that only uses a commercial assistant
The most common real situation is an organisation that builds nothing and simply uses a commercial generative assistant. It is tempting to conclude that all the duties belong to the model vendor. That is half right. Article 50(2) marking is indeed the vendor’s duty. But if that organisation publishes AI-generated text on a matter of public interest without human editorial control, Article 50(4) is its own duty and no vendor contract transfers it. If it deploys an AI receptionist that answers the phone, it should still verify that the provider actually built the Article 50(1) disclosure, because an authority investigating a complaint will start with the system the public touched. Vendor attestations belong in the file, next to the vendor due diligence record, and they are evidence rather than a discharge.
Machine-readable marking is a technical claim, not a checkbox
Article 50(2) is the duty most often reduced to a line in a project plan. It should not be, because the Regulation frames it as a performance claim about a technical artefact, not as a formality. The marking must be machine-readable and must make the content detectable as artificially generated or manipulated. The Regulation’s own qualifiers, that solutions be effective, interoperable and reliable as far as technically feasible, do real work. A metadata field that any re-encode strips is arguably none of those things. A visible watermark that a screenshot removes fails the machine-readability test outright, because a person reading a caption is not a machine parsing a signal. The state of the art differs sharply by content type, and the Regulation acknowledges as much. Images and video have credible options, from cryptographically signed provenance manifests to statistical watermarks embedded at generation time. Audio is workable. Text is the hard case, and honest engineering teams say so: no widely deployed method survives paraphrasing, translation or a copy-paste into a different editor. The Regulation asks for what is technically feasible, which means the defensible position for text is a documented assessment of the available options, the choice made, and the reasons the discarded options were not adequate. Two practical consequences follow. First, marking has to be applied at generation, inside the pipeline, rather than bolted on at publication, where the content has already been separated from its provenance. Second, marking needs to be tested rather than assumed. A short, repeatable test that runs the marked output through the transformations your content actually undergoes, a re-encode, a crop, a platform upload, and confirms the mark survives, is the artefact that turns a claim into evidence.
The exemptions are narrower than they look
Every exemption in EU AI Act Article 50 is drafted tightly, and each one is a decision that has to be recorded rather than a door to walk through quietly.
Obviousness, assistive editing, art and satire
The Article 50(1) duty falls away where the interaction is obvious to a reasonably well-informed, observant and circumspect person. That is an objective standard, not a judgement about your own users, and it gets harder to satisfy as conversational systems get better at sounding human. Article 50(2) does not apply where the system performs an assistive function for standard editing and does not substantially alter the input data or its semantics. Grammar correction is inside. A model that rewrites a paragraph into a different argument is not. The Commission’s own FAQ also puts short character sequences, source code, machine-to-machine outputs and closed-loop industrial use outside the marking duty. Where a deep fake forms part of an evidently artistic, creative, satirical or fictional work, the Article 50(4) duty is reduced rather than removed: the deployer still discloses that generated or manipulated content exists, in a manner that does not spoil the work.
Human editorial review and editorial responsibility
The text exemption in Article 50(4) is the one most often overstated. AI-generated text published to inform the public on matters of public interest does not need a disclosure where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. Both limbs matter. A reviewer who skims and approves is not obviously exercising editorial control, and an unnamed process holds no responsibility. Organisations relying on this exemption should be able to name the person, show the review actually happened, and show it happened before publication. That is a workflow question before it is a legal one, and it sits close to the human oversight arrangements already required elsewhere in the Regulation.
Article 50(3) is a trap: check Article 5 first
Article 50(3) tells deployers of emotion recognition and biometric categorisation systems to inform the people exposed. Read on its own, it reads like permission with paperwork attached. It is not. Article 5(1)(f) prohibits placing on the market, putting into service or using AI systems that infer emotions of a natural person in the workplace or in education institutions, with narrow exceptions for medical or safety reasons. That prohibition has been in force since 2 February 2025 and the Commission published Guidelines on prohibited practices on 4 February 2025 explaining its scope. So for the two settings where vendors most often pitch emotion analytics, staff monitoring and classrooms, the first question is not how to notify. It is whether the deployment is lawful at all. Article 50(3) governs only the space that Article 5 leaves open, such as a lawful biometric categorisation in a context outside work and education. Getting the order wrong produces a compliant notice attached to a prohibited practice, and the penalty band for Article 5 breaches is considerably higher. This is the sequencing that a risk classification exercise should settle before any notification design work starts.
The Code of Practice, the icons, and what adherence buys you
Article 50(7) asked the AI Office to facilitate codes of practice on detecting and labelling artificially generated content, and one now exists. The Code of Practice on Transparency of AI-generated Content was assessed as adequate by the Commission on 8 July 2026 and by the AI Board on 9 July 2026, covering Articles 50(2), 50(4) and 50(5). By the end of July 2026, roughly 190 organisations had signed it. Two things are worth understanding about it. First, it is currently the only EU-wide practical compliance instrument that has been formally assessed as adequate for those paragraphs, which makes adherence the cheapest available way to show a market surveillance authority that your approach is reasonable. Providers and deployers who do not sign are not in breach, but they carry the burden of demonstrating equivalently adequate means of their own. Second, it ships a shared visual vocabulary. Signatories commit to disclosing the existence of AI markings using a generalised icon set supplied by the AI Office, together with an indication of whether content was created or manipulated with AI. A common icon set matters more than it sounds: transparency that every organisation expresses differently is not transparency the public can read. Adopting the icons is a small design decision that removes an argument later, and it slots naturally into an existing AI policy.
The evidence a market surveillance authority will ask for
This is where EU AI Act Article 50 stops being a content question and becomes a governance one. Member States were required to designate market surveillance authorities by 2 August 2025, and roughly 2,000 national authorities are now notified across the Union. When one opens a file, it will not ask whether you believe you are compliant. It will ask what you can show. Six records carry most of the weight:
- A disclosure inventory. Every system in scope, its Article 50 sub-paragraph, your role for that system, and the disclosure actually implemented, with a screenshot or a link.
- A marking test log. For each generative system, the technique used, the date tested, the transformations tested against, and the result. This is the record that converts “we watermark” into a defensible claim.
- A deep fake decision record. For each publication involving generated or manipulated image, audio or video, who decided a disclosure was required, and where it appears.
- An editorial responsibility record. For AI-assisted public-interest text published without disclosure, the named person who held editorial responsibility, and proof that human review preceded publication.
- Exemption justifications. Written reasoning for each exemption relied on, dated, with the person who signed it. An exemption asserted at inspection time and an exemption documented before deployment are treated very differently.
- Vendor attestations. For third-party systems, what the provider states about its Article 50(1) and 50(2) implementation, and when you last verified it.
None of this is exotic. It is the same discipline that any AI compliance operating model already applies to risk assessments and incident logs, applied to a chapter that most teams have been treating as a design task. The organisations that will struggle in 2027 are not the ones without labels. They are the ones with labels and no idea who decided to put them there.
FAQ
What is Article 50 of the EU AI Act? EU AI Act Article 50 is the Regulation’s transparency chapter. It requires providers to tell people when they are interacting directly with an AI system and to mark synthetic audio, image, video and text in a machine-readable way. It requires deployers to notify people exposed to emotion recognition or biometric categorisation, and to disclose deep fakes and AI-generated text published to inform the public on matters of public interest. It has applied since 2 August 2026 and is separate from the high-risk regime in Chapter III. Does EU AI Act Article 50 apply to companies outside the EU? Yes, in the situations the Regulation covers. The AI Act applies to providers placing systems on the Union market regardless of where they are established, and to deployers established in the Union. It also reaches providers and deployers in third countries where the output produced by the system is used in the Union. A US company whose chatbot serves European users is inside the scope, and location of incorporation does not change the answer. What are the Commission guidelines on Article 50? They are the final Guidelines on transparency obligations for providers and deployers of certain AI systems, adopted on 20 July 2026 and running to 51 pages. They explain how the Commission reads each sub-paragraph, the exemptions and the interaction with the Code of Practice. They are not legally binding, and only the Court of Justice can settle the meaning of the Regulation, but market surveillance authorities and the AI Office can be expected to apply them in practice. What happens on 2 December 2026? The transitional window for the machine-readable marking duty closes. Providers of generative systems that were already placed on the market before 2 August 2026 were given until 2 December 2026 to bring those systems into line with Article 50(2). Systems placed on the market on or after 2 August 2026 had no such window. After that date, the marking duty applies across the board. What are the penalties for breaching Article 50? Non-compliance with the transparency obligations can attract fines of up to EUR 15,000,000 or 3 percent of total worldwide annual turnover for the preceding financial year, whichever is higher. That is the mid-tier band, below the level reserved for prohibited practices under Article 5, and it applies per infringement rather than per organisation. Is a watermark enough to comply with Article 50(2)? Not by itself. The duty is for outputs to carry marks that are machine-readable and that make the content detectable as artificially generated, using solutions that are effective, interoperable and reliable as far as technically feasible. A purely visible watermark is readable by people, not machines, and does not survive a screenshot. A workable approach usually combines an embedded signal with a provenance manifest, applied at generation, and supported by a test log showing the mark survives the transformations your content actually goes through.
Conclusion
The interesting thing about EU AI Act Article 50 is not its difficulty. Four duties, one delivery rule, a handful of tightly drafted exemptions. It is the timing. The Digital Omnibus bought European organisations sixteen extra months on high-risk classification and nothing at all on transparency, which means the chapter most teams skipped as the easy one is the chapter currently in force, with a marking deadline in December. The work that pays off is not the label. It is deciding your role per system, checking Article 5 before Article 50(3), testing your marking rather than asserting it, and keeping the six records above so the decision is legible a year from now. That is ordinary governance discipline pointed at a new obligation, and it is what turns a compliance claim into something you can hand to an authority. If you want the same discipline applied across the rest of the Regulation, start with the AI governance operating model.