AI Act Article 50: the transparency obligations applicable on 2 August 2026
What Article 50 says
Article 50 of Regulation (EU) 2024/1689 is the “limited risk” regime. It requires no certification, no CE marking, no risk management system. It requires one thing: that people know when an artificial intelligence is at work.
The legislator's reasoning is simple. Some systems pose no intrinsic danger to fundamental rights, but they create a risk of illusion: believing you are talking to a human, believing a photograph is authentic, believing a text was written by a person. Article 50 corrects that information asymmetry.
It is the obligation touching the largest number of organizations, because it covers the most ordinary uses: the website chatbot, the visuals generated for a campaign, the synthetic voice of a phone menu, the AI-produced demo video.
The date to remember: 2 August 2026. That is the general date of application of the Regulation, which includes Article 50. There is no grace period for bringing interfaces into line: a missing notice on 3 August 2026 is a breach.
Who is bound: provider, deployer, or both
Article 50 splits the obligations between two actors, and this is the most common source of error.
The provider is targeted by paragraphs 1 and 2: it must design the system so that the user knows they are interacting with an AI, and it must mark generated outputs in a machine-readable format.
The deployer is targeted by paragraphs 3 and 4: it must inform persons exposed to an emotion recognition or biometric categorisation system, and it must disclose that a piece of content is a deepfake, or that a text published to inform the public on matters of public interest was artificially generated.
In other words: if you publish an image generated by an off-the-shelf tool, the vendor is responsible for the technical watermark, but you are responsible for the notice visible to your audience. Your provider's compliance does not discharge yours.
The four obligations, one by one
1. Interaction with an AI — Article 50(1)
Systems intended to interact directly with natural persons must be designed so that those persons are informed that they are interacting with an AI system, unless this is obvious from the point of view of a reasonably well-informed person, taking into account the circumstances.
In practice: every support chatbot, every conversational assistant, every voice agent. The information must be given at the latest at the first interaction, not in the terms and conditions. The “it's obvious” exception is narrow: it does not cover an agent introducing itself with a human first name.
2. Marking of synthetic content — Article 50(2)
Providers of systems generating synthetic content (audio, image, video, text) must mark the outputs in a machine-readable format, detectable as artificially generated or manipulated. Technical solutions must be effective, interoperable, robust and reliable — watermarks, identification metadata, cryptographic methods, logging.
The paragraph exempts systems performing an assistive function for standard editing, or which do not substantially alter the input data. A spell-checker is out of scope; an image generator is in.
3. Emotion recognition and biometric categorisation — Article 50(3)
The deployer of an emotion recognition or biometric categorisation system must inform the persons exposed to it of its operation, and process personal data in accordance with the GDPR.
Mind the interaction with Article 5: emotion recognition in the workplace and in education institutions is a prohibited practice, save for medical or safety reasons. Article 50(3) therefore applies only to uses that do not already fall under the prohibition.
4. Deepfakes and texts of public interest — Article 50(4)
A deployer generating or manipulating images, audio or video constituting a deepfake must disclose that the content has been artificially generated or manipulated. Where the content is part of an evidently artistic, creative, satirical or fictional work, the obligation is limited to a disclosure that does not hamper the display or enjoyment of the work.
The same paragraph covers text published to inform the public on matters of public interest: it must be disclosed as artificially generated, unless the content underwent human review or editorial responsibility.
Deadlines and the “AI Omnibus” transition
The Regulation applies in stages:
| Date | What becomes applicable |
|---|---|
| 2 February 2025 | Prohibited practices (Article 5) and AI literacy (Article 4) |
| 2 August 2025 | General-purpose AI model obligations, governance, penalties |
| 2 August 2026 | General application, including Article 50 and Annex III high-risk |
| 2 August 2027 | High-risk systems embedded in already-regulated products (Annex I) |
One current point few sources cover: the provisional “AI Omnibus” agreement of May 2026 introduces a targeted transition for Article 50(2). Generative AI systems already placed on the market before 2 August 2026 would have until 2 December 2026 to meet the machine-readable marking requirement for synthetic content.
Three caveats. First, the transition concerns only the technical marking of paragraph 2: the duty to disclose AI interaction (§1) and the duty to disclose a deepfake (§4) are not postponed. Second, it targets providers, not deployers. Third, until the final text is published in the Official Journal of the European Union, the only enforceable date remains 2 August 2026. Plan for that date; treat the delay as a safety net, never as a plan.
Concrete wording
Notices must be clear, distinguishable and provided at the latest at the first interaction or exposure. A few examples you can use as-is:
- Chatbot: “You are chatting with an automated assistant powered by artificial intelligence. Type ‘human’ to reach an adviser.”
- Generated image: “Image generated by artificial intelligence.”
- Altered video: “This video has been artificially generated or manipulated.”
- News article: “This text was generated by an AI system and reviewed by our editorial team.” (documented human review may lift the obligation, but the notice remains the safest route)
- Emotion analysis in a call centre (outside the Article 5 prohibition): “This call is analysed by an AI system assessing tone of voice. Your data is processed in accordance with our privacy policy.”
The notice must be visible where the exposure happens. A line buried in the legal notice does not satisfy Article 50 for a chatbot displayed in the corner of a product page.
Penalties
Breaching Article 50 falls into the second category of Article 99: up to €15 million or 3% of worldwide annual turnover, whichever is higher (whichever is lower for SMEs and start-ups). Not the ceiling reserved for prohibited practices, but exposure far above the cost of displaying one sentence.
Checklist before 2 August 2026
- Inventory the AI systems that touch people: chatbots, assistants, content generators, synthetic voices, biometric analysis. An AI system register makes this step mechanical.
- Qualify your role for each: provider (§1, §2) or deployer (§3, §4). See the deployer obligations.
- Draft the notices and have them validated by your legal department or counsel.
- Place them where exposure occurs — first chatbot bubble, image caption, video credits.
- Ask your providers about machine-readable marking (§2) and keep their written answers: they are part of your compliance file.
- Check Article 5: no emotion recognition at work or in education.
- Timestamp the compliance of each system and schedule at least an annual review.
The notice generator. AI Act Register Pilot infers, for each detected system, the applicable transparency obligations and produces the matching notice text, ready to paste into your interface. Detection is local: no page is read, no URL is stored.
Get the register template
AI system register template (XLSX + CSV)
With a dedicated column for Article 50 transparency obligations.
Keep reading
This content is provided for information only. It reflects Regulation (EU) 2024/1689 and the legislative work in progress as at the update date, and does not constitute legal advice.