Article 50 of the EU AI Act has been enforceable since 2 August 2026. It requires disclosure whenever a person interacts with AI or is exposed to AI-generated or manipulated content. This page sets out what it requires, who it binds, the real deadlines, and how compliance looks in practice.

Quick Overview

Article 50 is the EU AI Act’s transparency provision. It has applied since 2 August 2026 and is not affected by the Digital Omnibus delays to the high-risk system requirements (December 2027 / August 2028).

Article 50 requires these four things:

  1. Tell people when they’re talking to an AI
  2. Mark AI-generated content so it’s machine-detectable
  3. Tell people when they’re exposed to emotion-recognition or biometric categorisation
  4. Label deepfakes and AI-generated public-interest text.

The only extension is a narrow one — until 2 December 2026 — for machine-readable marking of generative systems already on the market before 2 August 2026.

Need your systems checked against Article 50? Book a 15-minute consultation.

What is Article 50 of the EU AI Act?

Article 50 sits in the AI Act’s general obligations chapter, separate from the high-risk system rules in Articles 6–17. Where the high-risk regime asks “is this system dangerous enough to need conformity assessment,” Article 50 asks a narrower, more universal question: “does a person need to know AI is involved here?” It applies regardless of a system’s risk classification. A low-risk marketing chatbot and a high-risk hiring tool are both caught if either talks to a person or generates synthetic content.

The provision creates four separate transparency duties, split across providers (who build and place AI systems on the market) and deployers (who use those systems in their own operations):

  1. Article 50(1) — providers must design AI systems intended to interact directly with natural persons so that those people are informed they are interacting with an AI system, unless this would be obvious to a reasonably informed person.
  2. Article 50(2) — providers of AI systems that generate synthetic audio, image, video or text (including general-purpose AI systems) must ensure the output is marked in a machine-readable format and detectable as artificially generated or manipulated.
  3. Article 50(3) — deployers of an emotion-recognition system or a biometric categorisation system must inform the natural persons exposed to it of the system’s operation.
  4. Article 50(4) — deployers who use AI to generate or manipulate deepfakes, or AI-generated/manipulated text published to inform the public on matters of public interest, must disclose that the content is artificially generated or manipulated.

Article 50(5) sets the how: all of the above disclosures must be clear, distinguishable, provided at the latest at the time of first interaction or exposure, and accessible in line with EU accessibility requirements.

Who does Article 50 apply to?

Providers are the natural or legal persons, public authorities or bodies that develop an AI system (or have one developed) and place it on the EU market or put it into service under their own name or trademark, whether they’re established in the EU or a third country. A US or Ukrainian company whose chatbot or image generator is used by people in the EU is a provider for this purpose, exactly as under GDPR’s extraterritorial reach.

Deployers are the natural or legal persons, public authorities or bodies using an AI system under their own authority in the course of a professional activity. Personal, non-professional use (someone making a deepfake for their own social media, unrelated to any economic activity) falls outside the deployer definition. Using AI as part of your job, your business, or any activity that generates recurring economic benefit does not.

A single AI-powered chat widget on a company website can trigger obligations for both the software vendor who built it (Article 50(1) — provider) and the business that deployed it on their site and is having the actual conversation with the customer (Article 50(1) — deployer’s disclosure duty in practice, since the vendor cannot control every deployment context).

What Is Article 50 Effective Date?

2 August 2026 — Article 50 becomes enforceable in full. This is the date that matters for the disclosure and interaction-transparency duties in Article 50(1), 50(3) and 50(4). There is no phase-in and no grace period for these.

2 December 2026 — a narrow, four-month extension applies only to the machine-readable marking obligation in Article 50(2), and only for generative AI systems that were already placed on the market before 2 August 2026. If your system launched, or launches, after 2 August 2026, this extension does not apply to you. In fact, you are required to comply from the day the system goes live.

Content generated before 2 August 2026 does not need to be labelled retroactively, though the European Commission encourages doing so where practical.

This distinction is the single most commonly misreported fact about Article 50. Coverage of the AI Act’s 2027/2028 delays (from the Digital Omnibus package) is often conflated with Article 50, leading businesses to believe the entire Act, including transparency duties, has been pushed back. It hasn’t.

The high-risk system requirements (classification, conformity assessment, technical documentation under Articles 6–17 and 43) are delayed to December 2027 and August 2028.

Article 50 transparency obligations are not part of that delay and have applied since 2 August 2026.

Examples: what compliant labelling looks like in practice

There is no single EU-mandated icon or wording yet. The Code of Practice on Transparency of AI-Generated Content is still being finalised.

What exists today is a functional test (clear, timely, reaches the person) rather than a fixed visual standard. Don’t let your UI designer round that off into a fixed visual standard.

That said, several real, already-deployed implementations illustrate the pattern regulators are pointing to:

Chatbot disclosure (Article 50(1))

This is the most common disclosure, usually a short statement before the first exchange begins — “You’re chatting with [Brand]’s AI assistant” — rather than the bot simply answering with no framing. This is the pattern used by most enterprise chat widgets and by assistants like ChatGPT and Claude, which identify themselves by name before any substantive response. A good example could look like this:

For best practice, you may want to add a link to your Privacy Policy before the chat begins.

Machine-readable marking (Article 50(2)): C2PA Content Credentials

This is an open provenance standard adopted by Adobe, Microsoft, OpenAI’s image tools, Google and Truepic — embeds cryptographically signed metadata recording that content was AI-generated, plus an optional visible “Cr” icon viewers can click to inspect.

Google SynthID embeds an invisible watermark directly into pixels or audio for Imagen, Veo and Gemini-generated media, detectable even after cropping or compression.

Visible platform labels

YouTube’s “Altered or synthetic content” label overlay on realistic AI-generated video. TikTok’s in-stream “AI-generated” tag, auto-applied or creator-toggled and shown on the video itself. Meta’s “AI info” label on Facebook and Instagram posts where C2PA metadata is detected or an advertiser discloses AI use.

Public-interest text (Article 50(4))

This is an emerging pattern of byline disclosure — “This article was drafted with AI assistance and reviewed by [named editor]” — placed at the top or bottom of the piece itself, not buried in a general editorial policy page.

The common failure mode across all of these: putting the disclosure in a footer, a terms-of-use page, or file metadata nobody looks at.

Article 50(5) requires the disclosure to reach the person at the point of interaction or exposure, not just to exist somewhere on the site.

Article 50 Exemptions

Article 50 is not absolute. The main carve-outs:

  • Obviousness exception (50(1)): no disclosure is needed if a reasonably informed person would immediately recognise they’re dealing with AI. This is interpreted narrowly, and not something to rely on for genuinely ambiguous interactions.
  • Short technical sequences (50(2)): numbers, symbols, letters, or source code are exempt from marking.
  • Machine-to-machine outputs (50(2)): content automatically processed by another system without human exposure, or closed-loop industrial/product-development outputs, unless they become the final output shown to a person.
  • Assistive editing functions (50(2)): AI performing grammar correction or similar minor editing assistance is not treated as “generating” content for marking purposes.
  • Law enforcement (50(2)): systems authorised by law for criminal investigation are exempt from the marking duty.
  • Human review / editorial control (50(4)): AI-generated public-interest text is exempt from labelling if it underwent substantive human review with editorial responsibility properly assigned. Superficial checks do not count.
  • Artistic and satirical works (50(4)): deepfakes in evidently artistic, creative, satirical or fictional works only require disclosure “in an appropriate manner that does not hamper the display or enjoyment of the work.” This is a lighter-touch standard than for other deepfakes.
  • Personal, non-professional use: an individual generating content for their own private purposes, unconnected to any economic activity, is not a “deployer” and falls outside Article 50(3) and 50(4).

Article 50 Definitions to Know

AI system — software developed with machine learning, logic- or knowledge-based approaches, or statistical approaches, that can generate outputs such as content, predictions, recommendations or decisions influencing physical or virtual environments, and that operates with some degree of autonomy (Article 3(1) AI Act).

Provider — a natural or legal person, public authority, agency or other body that develops an AI system or a general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark, whether for payment or free of charge (Article 3(3)).

Deployer — a natural or legal person, public authority, agency or other body using an AI system under its authority, except where the system is used in the course of a personal, non-professional activity (Article 3(4)).

Deepfake — AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events, and that would falsely appear to a person to be authentic or truthful (Article 3(60)). Three cumulative criteria apply: resemblance to a real or plausible subject, sufficient similarity to deceive, and a genuine capacity to mislead a viewer about authenticity.

Machine-readable marking — a technical means of signalling that content is artificially generated or manipulated, embedded in a way that can be automatically detected by other systems (metadata, cryptographic provenance signals, watermarking), distinct from a visible label aimed at a human viewer.

Emotion recognition system — an AI system for the purpose of identifying or inferring emotions or intentions of natural persons on the basis of their biometric data (Article 3(39)).

Biometric categorisation system — an AI system for the purpose of assigning natural persons to specific categories on the basis of their biometric data, such as sex, age, hair colour, tattoos, or behavioural or personality traits (Article 3(40)).

Human review / editorial control (the exemption for public-interest text) — the deliberate examination of the substance of AI-generated content by a natural person with relevant knowledge and professional judgement, exercised by a responsible editorial entity with the authority to approve, alter or reject the content on substantive grounds. Spell-checking, grammar correction or other superficial formal checks do not qualify.

FAQ

Is Article 50 of the EU AI Act in force yet?

Yes. Article 50 has applied since 2 August 2026. It is not part of the Digital Omnibus delays that pushed high-risk system requirements to December 2027 and August 2028.

What is the Article 50 EU AI Act effective date?

2 August 2026, for the core transparency obligations. A separate, narrower deadline of 2 December 2026 applies only to machine-readable marking of generative systems already on the market before 2 August 2026.

Does the 2 December 2026 date apply to my AI system?

Only if your system was already placed on the market before 2 August 2026, and only for the machine-readable marking requirement specifically. If your system launched after 2 August 2026, you must comply from day one, with no extension.

What counts as a deepfake under the EU AI Act?

AI-generated or manipulated image, audio or video content that resembles a real or plausible person, object, place, entity or event, and that would falsely appear authentic or truthful to a viewer. All three elements — resemblance, plausibility, and capacity to deceive — must be present.

Do I need to label AI-generated text?

Only if it is published to inform the public on a matter of public interest (politics, public administration, justice, health, safety, or similar) or has not undergone genuine human editorial review. Internal drafts, marketing copy not framed as news or analysis, and content substantively reviewed by a responsible editor are generally exempt.

Is a chatbot required to say it’s an AI at every message, or just once?

Disclosure must occur at the latest at the time of the first interaction — it does not need to be repeated at every subsequent message, but it must be clear and distinguishable from the outset, not something the user must seek out.

Does Article 50 apply to companies outside the EU?

Yes. Like the GDPR, the AI Act has extraterritorial reach. A provider or deployer established outside the EU is still bound by Article 50 if the AI system’s output is used by people within the EU.

What is the difference between Article 50 and the high-risk system rules?

Article 50 is a transparency obligation that applies regardless of a system’s risk classification and has been enforceable since 2 August 2026. The high-risk system rules (Articles 6–17, 43) require classification, conformity assessment and technical documentation, and were delayed by the Digital Omnibus to December 2027 and August 2028. They are separate obligations on separate timelines within the same regulation.

What happens if content was generated before Article 50 took effect?

It does not need to be labelled retroactively. The obligation applies to content generated or content interactions occurring from 2 August 2026 onward, though retroactive labelling is encouraged where feasible.

Who enforces Article 50 and what are the penalties?

National market surveillance authorities in each EU member state, with the EU AI Office and the European Data Protection Supervisor holding jurisdiction in specific cases. Penalties can reach €15 million or 3% of global annual turnover, whichever is higher.

Disclaimer

This page reflects the EU AI Act (Regulation (EU) 2024/1689) and related European Commission guidance as of 22 September 2026. It is regulatory and compliance analysis, not legal advice.

Fact Checked & Editorial Guidelines
Reviewed by: Subject Matter Experts