Article 50 of the EU
AI Act creates transparency duties for defined interactive, generative, biometric and synthetic-media uses. The rules began applying on August 2, 2026.
The provision is often summarized as “label AI content,” but that is too broad and too vague. Article 50 separates:
- provider duties to design direct-interaction notices;
- provider duties to place machine-readable marks in generated or manipulated content;
- deployer duties to notify people exposed to emotion recognition or biometric categorization;
- deployer duties to disclose deepfakes;
- and deployer duties for certain AI-generated or manipulated public-interest text.
Not every AI-assisted document needs a visible label. Not every machine-readable mark is visible to a person. Provider and deployer responsibilities can also apply to different companies in the same workflow.
For the full regulatory map, start with our
EU AI Act guide. For role allocation, use the
providers and deployers guide.
Article 50 at a glance
| Use | Main obligated actor | Core duty |
| Person interacts directly with AI | Provider | Design the system so the person is informed, unless AI nature is obvious |
| System generates or manipulates synthetic audio, image, video or text | Provider | Ensure output is marked in a machine-readable format and detectable as AI-generated or manipulated |
| Emotion recognition or biometric categorization is deployed | Deployer | Inform exposed people and meet applicable data-protection rules |
| Deepfake image, audio or video is deployed | Deployer | Disclose that the content is artificially generated or manipulated |
| AI text is published to inform the public on matters of public interest | Deployer | Disclose artificial generation/manipulation unless the human-review and editorial-responsibility exception applies |
| Legacy generative system already on market before August 2, 2026 | Provider | Article 50(2) marking transition ends December 2, 2026 |
When did Article 50 become applicable?
Article 50 applies from August 2, 2026.
The 2026 Digital Omnibus introduced one narrow transition: providers of systems—including general-purpose AI systems—generating synthetic audio, image, video or text that were placed on the market before August 2, 2026 have until December 2, 2026 to comply with Article 50(2)’s machine-readable marking duty.
This is not a general grace period for:
- chatbot disclosure;
- emotion-recognition notice;
- biometric-categorization notice;
- visible deepfake disclosure;
- or public-interest text disclosure.
Content generated before August 2, 2026 does not have to be labeled retroactively under Article 50, although voluntary disclosure may still be useful.
The complete sequence appears in our
EU AI Act timeline.
Article 50(1): direct interaction with AI
Providers of AI systems intended to interact directly with natural persons must design and develop them so people are informed that they are interacting with an AI system, unless this is obvious to a reasonably well-informed, observant and circumspect person in the circumstances and context.
This can cover:
- customer-service chatbots;
- voicebots and automated call systems;
- virtual assistants;
- conversational avatars;
- AI reception or booking agents;
- and other interfaces that could reasonably be mistaken for a person.
What should the notice look like?
The law does not prescribe one phrase for every interface. The notice should be:
- clear;
- distinguishable;
- timely;
- accessible;
- and delivered no later than the first interaction or exposure.
Examples include:
- “You are chatting with an AI assistant” above the input box;
- a spoken disclosure at the start of an automated call;
- an persistent but unobtrusive interface indicator;
- or a first-use notice in a virtual avatar experience.
A disclosure hidden in general terms and conditions is unlikely to achieve the purpose when the user can interact without seeing it.
When is the AI nature obvious?
A clearly fantastical game character in an environment that no reasonable user would understand as human may not need the same notice as a lifelike customer-service agent using a human name and voice.
Obviousness should be tested from the user’s perspective, including age, language, interface design, channel and vulnerability. Do not use “people know AI exists” as a blanket exception.
Article 50(2): machine-readable marking of synthetic content
Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated.
This is a system-design duty. The provider should use technical solutions that are effective, interoperable, robust and reliable as far as technically feasible, taking into account:
- the content type;
- technical limitations;
- implementation cost;
- the state of the art;
- and relevant standards.
Possible techniques include:
- embedded metadata;
- cryptographic provenance credentials;
- robust watermarks;
- model- or service-level signaling;
- and combinations of origin and detection mechanisms.
The legal requirement is not satisfied merely by placing “made with AI” in a product’s marketing page. The generated output needs the technical marking capability.
Machine-readable does not mean visibly labeled
A machine-readable mark is intended for automated detection and provenance. It can be invisible to an ordinary viewer.
Visible disclosure is a separate deployer duty for deepfakes and certain public-interest text. In some workflows both apply:
- the provider embeds a technical signal when the content is generated;
- the publisher or other deployer adds a visible disclosure when the context requires it.
Editing and non-substantial alteration
Article 50 contains exceptions for systems performing only an assistive function for standard editing or not substantially altering input data or its semantics. Ordinary noise reduction, formatting or limited technical enhancement is not automatically treated like generative fabrication.
The boundary depends on what changed. A tool that merely crops or improves brightness is different from one that creates a realistic event or statement that did not occur.
Article 50(3): emotion recognition and biometric categorization
Deployers of emotion-recognition or biometric-categorization systems must inform natural persons exposed to the operation of the system. They must also process personal data in accordance with GDPR, the Law Enforcement Directive and other applicable law.
Examples can include:
- a venue categorizing people using biometric traits;
- a service estimating emotional state from voice or face;
- or a permitted safety system analyzing a person’s condition.
Some uses are already prohibited. Emotion recognition in workplaces and educational settings is generally prohibited except for medical or safety reasons, and sensitive biometric categorization can also be prohibited. Article 50 notice does not legalize a prohibited practice.
The notice should occur before or at exposure and explain enough for a person to understand that the system is operating. A small privacy-policy clause published after collection is not a substitute.
Article 50(4): deepfake disclosure
Deployers of AI systems that generate or manipulate image, audio or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated.
A deepfake generally involves AI-generated or manipulated media resembling existing persons, objects, places, entities or events in a way that would falsely appear authentic or truthful.
The duty falls on the deployer making use of the system and exposing or publishing the content. The model or tool provider can supply labeling features, but the publisher controls the final context.
What is a suitable visible disclosure?
The final Commission materials and voluntary Code support clear, accessible labels. Depending on the medium, this can include:
- an on-screen label on video;
- a spoken and written notice for audio;
- a caption adjacent to an image;
- a persistent icon or standardized disclosure;
- or a prominent description accompanying the content.
The EU has published icons that deployers can use. An icon should complement, not obscure, the meaning for users.
Artistic, creative, satirical and fictional works
Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or program, the disclosure duty is applied in an appropriate manner that does not hamper display or enjoyment.
That is a flexibility rule, not an automatic exemption. A film can disclose synthetic performance in credits or contextual information rather than placing a disruptive banner across every frame.
Law-enforcement exceptions
Article 50 contains tailored exceptions for systems authorized by law to detect, prevent, investigate or prosecute criminal offenses, subject to appropriate safeguards and third-party rights. These should be interpreted with the underlying legal authorization, not as a general public-sector exemption.
Public-interest text disclosure
Deployers of AI systems generating or manipulating text that is published with the purpose of informing the public on matters of public interest must disclose that the text was artificially generated or manipulated.
This can affect:
- news and current-affairs publishing;
- government communications;
- public-health information;
- election information;
- financial or economic reporting;
- and other content intended to inform the public on consequential matters.
Human review and editorial responsibility exception
Disclosure is not required under this paragraph where:
- the AI-generated content has undergone human review or editorial control; and
- a natural or legal person holds editorial responsibility for publication.
This is why a newsroom using AI as a drafting or research tool does not necessarily need an “AI-generated” banner on every article. The exception depends on real review and responsibility, not a nominal editor listed on the website.
A defensible editorial process can record:
- who reviewed the text;
- what sources were checked;
- what material changes were made;
- who approved publication;
- and which person or organization accepted editorial responsibility.
Our news report on
mandatory EU AI labels gives the immediate policy context. This evergreen guide owns the full rule and implementation details.
Provider and deployer responsibilities in one workflow
Consider an agency creating a synthetic video for a client:
- A model company provides a generative video system and embeds machine-readable provenance under Article 50(2).
- The agency uses the system and is a deployer.
- The client publishes the realistic manipulated video and can also be a deployer depending on control and use.
- The responsible deployer adds a visible deepfake disclosure.
- The platform carrying the content may have separate duties under other law and its own policies.
Contracts should specify who preserves technical marks, who adds visible labels, who reviews final content and who responds to complaints. The statutory role still depends on the facts.
Article 50 and GPAI are not the same
A model’s GPAI documentation duties concern the model, training information, downstream support, copyright and systemic risk.
Article 50 concerns system interactions and outputs. A provider of a GPAI model may help downstream companies comply by supplying marking technology, but a GPAI model card does not itself tell a chatbot user that they are speaking to AI.
Read our
GPAI guide for the model-level obligations.
The Transparency Code of Practice
The
Code of Practice on Transparency of AI-generated Content is a voluntary tool developed to support compliance with Article 50(2), (4) and (5).
It contains two main sections:
- provider measures for marking and detection of AI-generated or manipulated content;
- deployer measures for labeling deepfakes and AI-generated or manipulated public-interest text.
The Commission and AI Board have confirmed the Code as an adequate voluntary route to demonstrate compliance. Signatories can rely on its measures; non-signatories must demonstrate compliance through alternative adequate means.
The Code does not replace the direct-interaction and biometric notices in Article 50(1) and (3), for which providers and deployers determine appropriate measures with the final guidelines in mind.
The earlier AI World Today article on
technical approaches to flagging AI content remains useful background, but the Code and final guidelines are now the operative implementation references.
A practical Article 50 implementation matrix
| Control | Owner | Evidence |
| Direct-interaction notice | System provider, implemented with deployer interface as needed | UX specification, screenshots, voice scripts, accessibility test |
| Obviousness assessment | Provider | User research, context analysis, approval record |
| Machine-readable mark | Generative-system provider | Technical specification, robustness tests, sample outputs, interoperability evidence |
| Preservation of technical mark | Provider and downstream deployers | Processing tests, contract requirements, media pipeline controls |
| Emotion/biometric notice | Deployer | Notice text, timing, signage or interface, deployment record |
| Visible deepfake disclosure | Deployer | Published label, media archive, release approval |
| Public-interest text review | Deployer/publisher | Editorial workflow, reviewer and responsible publisher record |
| Code adherence or alternative means | Relevant provider/deployer | Signed commitment, control mapping, audit evidence |
| Complaint and correction | Provider/deployer | Contact route, tickets, remediation, re-publication records |
Implementation examples
Customer-service chatbot
- Display a clear AI notice before or at first interaction.
- Maintain the notice when the conversation moves channels.
- Give users a human escalation route where appropriate.
- Test whether the chosen name, avatar and tone could mislead.
- Record accessibility and language behavior.
AI voice agent on a phone line
- Use a spoken disclosure at the start.
- Repeat or maintain the disclosure after transfer or reconnection where needed.
- Avoid a lifelike human identity that undermines the notice.
- Document call scripts and system versions.
AI-generated product image
- Provider embeds the required technical mark.
- The retailer preserves it through resizing and content management.
- A visible label is not automatically required unless the content constitutes a deepfake or another law demands it.
- Consumer law still prohibits misleading presentation.
Synthetic political video
- Preserve machine-readable provenance.
- Add a clear visible disclosure.
- Assess election law, platform rules and manipulation risks.
- Escalate for legal and editorial approval.
Newsroom using an AI writing assistant
- Train staff under Article 4.
- Require source verification and human editorial review.
- Name the person or entity with editorial responsibility.
- Preserve evidence of review for public-interest content.
- Disclose where the review exception is not met or where editorial policy chooses greater transparency.
Fictional film using synthetic performance
- Preserve provider technical marks where feasible.
- Use an appropriate disclosure in credits, metadata or contextual materials.
- Avoid a presentation that falsely suggests real documentary footage without adequate notice.
Accessibility and timing
Article 50 disclosures must be clear and distinguishable and provided no later than the first interaction or exposure. Accessibility requirements apply.
Test:
- screen-reader compatibility;
- spoken alternatives;
- contrast and placement;
- language;
- mobile and embedded views;
- duration on video;
- and whether the label remains after sharing or reformatting.
A disclosure that disappears before a user can perceive it is not effective transparency.
Article 50 and other laws
Article 50 does not displace:
- GDPR and biometric-data restrictions;
- the Digital Services Act;
- audiovisual and election law;
- consumer-protection rules;
- copyright and personality rights;
- advertising standards;
- accessibility law;
- or national criminal law.
A labeled deepfake can still be defamatory, fraudulent, non-consensual or prohibited. Disclosure is not a permission slip.
Enforcement and fines
National authorities enforce most Article 50 obligations, with the AI Office holding competence for specified systems under the amended governance framework.
Breach of Article 50 generally falls within the tier allowing maximum administrative fines of up to €15 million or 3% of total worldwide annual turnover, subject to Article 99 and the rules for smaller businesses and small mid-caps.
Authorities can also require corrective action. For a publisher, an effective response may include adding disclosure, removing content, correcting misleading presentation, preserving evidence and improving the workflow.
The full enforcement sequence appears in our
EU AI Act compliance checklist.
Common Article 50 mistakes
Labeling everything visibly
The machine-readable provider duty and visible deployer duty are different. Blanket visible labels can be unnecessary while still missing technical marking.
Treating December 2026 as a universal grace period
The transition applies only to Article 50(2) marking for systems already on the market before August 2, 2026.
Putting disclosure only in terms and conditions
The notice must be timely and clear to the person interacting with or exposed to the AI.
Removing provenance during editing
Downstream media pipelines should preserve technical marks where possible and test what transcoding, cropping or compression does to them.
Claiming human review without real review
Editorial responsibility must be meaningful. Automatic approval or a hurried glance may not support the public-interest text exception.
Assuming disclosure legalizes prohibited content
Article 5, criminal law, privacy and other rules can still prohibit or restrict the content.
Frequently asked questions
Do all chatbots need to say they are AI?
Providers must ensure direct-interaction notice unless the AI nature is obvious to a reasonably informed and observant person in context. A clear notice is the safer default for ordinary service chatbots.
Must every AI-generated image have a visible label?
No. Providers generally need machine-readable marking. Visible disclosure is required for deepfakes and other specified deployer uses, not every synthetic image.
Is a watermark mandatory?
Article 50(2) requires effective machine-readable marking and detectability, but does not mandate one universal watermark technology. Metadata, credentials and other methods can form part of the solution.
Do AI-generated news articles need labels?
Public-interest text generally requires disclosure, but there is an exception where the text undergoes human review or editorial control and a person or organization holds editorial responsibility.
Must old content be labeled retroactively?
Content generated before August 2, 2026 does not have to be labeled retroactively under Article 50, although voluntary disclosure is encouraged where possible.
What is the December 2, 2026 deadline?
It is the end of the limited transition for Article 50(2) machine-readable marking on generative systems already placed on the market before August 2, 2026.
Are fictional deepfakes exempt?
The law permits an appropriate, non-disruptive form of disclosure for evidently artistic, creative, satirical, fictional or analogous works. It is not a blanket absence of disclosure.
Who labels a deepfake: the tool or the publisher?
The system provider handles machine-readable marking; the deployer exposing or publishing a deepfake handles visible disclosure. Both duties can apply in one chain.
Is the Transparency Code mandatory?
No. It is a voluntary endorsed route. Non-signatories must demonstrate compliance through alternative adequate means.
Can Article 50 apply to a high-risk system?
Yes. Transparency duties can overlap with high-risk, GPAI and Article 4 obligations.
Bottom line
Article 50 is a role-specific transparency architecture, not a universal sticker rule. Providers need to design notice and technical marking into systems; deployers need to disclose defined biometric uses, deepfakes and certain public-interest text.
Map each workflow from generation to publication, preserve machine-readable provenance, make visible disclosures timely and accessible, and document any exception—especially human editorial review and the narrow legacy transition.