IT Governance1. August 202615 min

EU AI Act Article 50: What Applies to Chatbots and AI Content from 2 August 2026

While the Digital Omnibus debate keeps the Annex III high-risk dates in flux, one deadline runs on regardless: Article 50 of the AI Act. It does not hit the exotic systems, it hits the everyday ones — the support chatbot, the AI-written marketing copy, the synthetic voice in your service line. This piece sets out who carries which of the four duties, what "machine-readable" means technically, and how to plug the work into the control set you already run.

R&D

R&D Team

Alev-B Research & Development

In short

Article 50 of the AI Act has applied since 2 August 2026 and governs transparency, not high risk: users must be able to tell they are talking to an AI, synthetic content must carry machine-readable marking, and deepfakes must be disclosed. It covers AI in customer contact and content production, including bought-in systems.

Why Article 50 is the deadline you cannot defer

Most AI compliance programmes in German-speaking Europe are currently calibrated to the high-risk question: does our system fall under Annex III? Do we need a risk management system, technical documentation, human oversight? That question matters — and it is precisely the question whose timeline the Digital Omnibus debate has put into motion. The practical effect: programmes stretch, budgets shift, decisions get postponed.

What gets lost in that shuffle is a date that concerns neither Annex III nor the deferral discussion. heise online frames 2 August 2026 as the day the transparency obligations under Article 50 of the EU AI Act begin to bite — for chatbots and AI-generated content, organisations must disclose that AI is involved; at the same time, it notes, the European Commission is discussing possible deadline extensions in the context of the Digital Omnibus regulation (see https://www.heise.de/news/EU-AI-Act-Was-bis-August-2026-in-Unternehmen-erledigt-sein-muss-11289793.html). The official EUR-Lex summary of the AI Act likewise names 2 August 2026 as the general date of application, with the known earlier dates for prohibitions, definitions and AI literacy since 2 February 2025 and for the governance structure, penalties and GPAI obligations since 2 August 2025 (see https://eur-lex.europa.eu/EN/legal-content/summary/rules-for-trustworthy-artificial-intelligence-in-the-eu.html).

The decisive difference from the high-risk debate: Article 50 does not target the unusual systems, it targets the mundane ones. Almost any organisation running a support chatbot, an AI-assisted newsletter or a generated image in a campaign is an addressee — usually as a deployer, and more often than expected also as a provider. And unlike high-risk duties, non-compliance is immediately visible from the outside. An unlabelled chatbot is not a documentation gap you can close during an audit; it is a live condition on your own website.

To get a rough position fix before you set up a programme, start with the free AI Act quick check — it sorts roles and risk class in a few minutes. The full systematics of the regulation, from the four risk tiers to the six roles across the value chain, sit in our EU AI Act compliance guide.

Article 50 is the transparency layer of the AI Act. It applies from 2 August 2026, covers AI in customer contact and content production rather than Annex III high-risk systems, and is not what the Digital Omnibus discussion around high-risk dates is about.

The four duties in Article 50 — and who carries each one

Article 50 of the AI Act is headed "Transparency obligations for providers and deployers of certain AI systems", and that duality in the title is half the answer: two of the four duties fall on the provider, two on the deployer. Confuse the allocation and you build the control in the wrong place — then wonder why your software vendor is not delivering it.

Duty 1 (Article 50(1)) falls on the provider: AI systems intended to interact directly with natural persons must be designed and developed so that the natural persons concerned are informed they are interacting with an AI system. The text carves out cases where this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use (see https://www.artificial-intelligence-act.com/Artificial_Intelligence_Act_Article_50.html).

Duty 2 (Article 50(2)) also falls on the provider, expressly including providers of general-purpose AI systems: anyone generating synthetic audio, image, video or text content must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Article 50 requires those technical solutions to be effective, interoperable, robust and reliable as far as technically feasible, taking into account the specificities and limitations of content types, the costs of implementation and the generally acknowledged state of the art.

Duty 3 (Article 50(3)) falls on the deployer: anyone operating an emotion recognition system or a biometric categorisation system must inform the natural persons exposed to it of the operation of the system, and must process the personal data in accordance with the GDPR. This duty does not stand alone — it is wired into data protection law.

Duty 4 (Article 50(4)) also falls on the deployer and splits in two. First: anyone using an AI system to generate or manipulate image, audio or video content constituting a deep fake must disclose that the content has been artificially generated or manipulated. Second: anyone using an AI system to generate or manipulate text that is published for the purpose of informing the public on matters of public interest must disclose that artificial generation as well.

Cutting across all four is Article 50(5): the information must be provided to the natural persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure, and must conform to applicable accessibility requirements. Paragraph 6 clarifies that these duties leave the requirements of Chapter III — the high-risk obligations — untouched and are without prejudice to other transparency obligations in Union or national law. Article 50 is additive, not alternative.

DutyLegal basisAddresseeOperational core
Disclosure of AI interactionArt. 50(1)ProviderDesign the system so users can tell they are talking to an AI
Machine-readable marking of synthetic contentArt. 50(2)Provider (incl. GPAI providers)Mark outputs machine-readably and make artificial origin detectable
Notice for emotion recognition / biometric categorisationArt. 50(3)DeployerInform exposed persons, process personal data GDPR-compliantly
Deepfake and public-interest text labellingArt. 50(4)DeployerDisclose artificial generation or manipulation — visible to humans
Form and timing of the informationArt. 50(5)Provider + deployerClear, distinguishable, at first interaction, accessible

What this means for an ordinary mid-market company

The role logic of the AI Act regularly produces surprises. A company that buys a chatbot from a vendor and runs it on its own website is a deployer — the disclosure duty under paragraph 1 formally sits with the provider, who must design the system accordingly. The moment that same company rolls the bot out under its own name and brand or substantially modifies it, however, it can slide into the provider role under the structure of the regulation. This role shift is the most common silent misassumption in Article 50 projects.

The support chatbot is the clearest case. If users cannot tell at first contact that they are writing to a machine, paragraph 1 applies. The text allows the obviousness exemption — but "obvious" is judged from the perspective of a reasonably well-informed, observant and circumspect person, not from the perspective of the product team. A bot with a human first name, a profile picture and a typing animation is the opposite of obvious.

AI-generated marketing copy and imagery is the case marketing teams underestimate. Paragraph 2 addresses the provider of the generating system, so the marking normally originates with the model or tool vendor, not inside your company. That does not automatically let you off, though: as soon as visual material constitutes a deep fake within the meaning of paragraph 4, or a text is published to inform the public on matters of public interest, a separate deployer duty arises inside your organisation.

AI voice agents and synthetic avatars combine both. A voice agent in the service centre falls under paragraph 1 (interaction with natural persons) and simultaneously produces synthetic audio within the meaning of paragraph 2. A synthetic avatar modelled on a real person additionally engages the deepfake rule in paragraph 4. Run these formats in production and you need marking in three places: in the system, on the output artefact, and in the published presentation.

Job ads and press texts are the borderline case that needs a clean ruling. The text rule in paragraph 4 attaches to publication for the purpose of informing the public on matters of public interest. A conventional job advertisement typically is not that; a press release about a site closure, a product recall or a security situation may well be. Note also the carve-out for AI-generated text: it does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for its publication. That is a process question, not a technology question — and it only holds if the editorial responsibility is genuinely named and documented.

A separate note on recruitment: automated pre-screening of applications is not an Article 50 topic. According to heise online it may trigger the stricter requirements for high-risk AI systems under Annex III, with duties around risk management, technical documentation and human oversight. Ticking off Article 50 and declaring the HR use case closed conflates two regimes.

  • Support chatbot on the website or in a messenger → Art. 50(1) provider duty, which the deployer must enforce contractually
  • AI-generated marketing copy and campaign imagery → Art. 50(2) at the tool vendor; check the deepfake rule in Art. 50(4) internally
  • AI voice agent in the service centre → paragraphs 1 and 2 apply at the same time
  • Synthetic avatar based on a real person → paragraphs 1, 2 and deepfake disclosure under paragraph 4
  • Press text on a matter of public interest → Art. 50(4) text rule, unless editorial control with named responsibility applies
  • Emotion analytics on call centre recordings → Art. 50(3) deployer duty plus a GDPR assessment

The marking question: what "machine-readable and detectable" means in practice

The operationally hardest sentence in Article 50 sits in paragraph 2: outputs must be marked in a machine-readable format and detectable as artificially generated or manipulated. Two properties, not one. Machine-readable means an automated system must be able to read the marking. Detectable means the artificial origin must be establishable. A visible caption under an image satisfies neither, because it is lost at the first reuse — crop, repost, screenshot — and was never attached to the artefact in a form a machine could read.

Which technique qualifies is deliberately left open. Recital 133 of the AI Act lists watermarks, metadata identifications, cryptographic methods for proving provenance and authenticity of content, logging methods, fingerprints or other techniques as examples, and makes clear these can be implemented at the level of the AI system or at the level of the model, including general-purpose AI models generating content, which eases compliance for the downstream provider (see https://eur-lex.europa.eu/eli/reg/2024/1689/oj).

In practice, the cryptographic provenance category is most commonly implemented through C2PA and its Content Credentials: provenance and edit information is signed and embedded into the file and can be verified programmatically. The AI Act names neither this nor any other format — Article 50 demands effectiveness, interoperability, robustness and reliability in line with the generally acknowledged state of the art, as may be reflected in relevant technical standards. For governance that means one thing: the choice of technique is a documented decision, not an accident. If you do not record the rationale, you cannot later show that you took the state of the art into account.

The second practical insight: marking under paragraph 2 and disclosure under paragraph 4 are two different things serving two different audiences. Paragraph 2 addresses machines — platforms, detectors, downstream systems. Paragraph 4 addresses humans and requires deepfake disclosure that viewers can perceive. A company that only embeds metadata does not satisfy the deepfake disclosure; a company that only adds a visible caption does not satisfy machine-readable marking. Where both paragraphs apply, both layers are required.

Third insight, and it is a procurement matter: because the marking duty in paragraph 2 falls on the provider of the generating system, the most effective lever for a user organisation is the contract. Ask your AI tool vendors in writing whether and how their outputs are marked machine-readably, whether the marking survives common processing steps, and how it can be verified. Those answers belong in the same vendor file as your other third-party evidence — the same logic NIS2, DORA and the Cyber Resilience Act demand, described in detail in Regulatory Collision 2026.

Finally, Article 50(7) provides that the AI Office shall encourage and facilitate the drawing up of codes of practice at Union level to support effective implementation of the detection and labelling obligations, and that the Commission may approve such codes by implementing act or, if it deems them inadequate, specify common rules. For planning purposes: the technical detail may still sharpen. Choose a documented, standards-adjacent solution now and you stay compatible; wait, and you have neither marking nor rationale.

Machine-readable marking under Art. 50(2) and human-perceptible disclosure under Art. 50(4) are two duties with two audiences. A visible caption alone does not satisfy paragraph 2 — and embedded metadata alone does not satisfy paragraph 4.

  • Watermarks embedded in the content itself (robust to re-encoding, not to every edit)
  • Metadata identifications in the file (easy to implement, frequently stripped on platform upload)
  • Cryptographic provenance and authenticity proofs (in practice mostly C2PA / Content Credentials)
  • Logging methods on the generating side (evidence, but no substitute for marking the artefact)
  • Fingerprints or content-based detection features (for after-the-fact detection)

The exemptions — and where teams over- or under-apply them

Article 50 contains precisely drafted exemptions. That is exactly why they get misapplied in practice: they sound broader than they are.

The obviousness exemption in paragraph 1 applies where the AI interaction is obvious from the point of view of a reasonably well-informed, observant and circumspect natural person, taking into account the circumstances and context of use. It is routinely over-applied with the argument that "everybody knows this by now". But the standard is contextual, not statistical: a widget labelled "AI assistant" is obvious; a bot that introduces itself with a human name and simulates typing delays is not — not even in 2026.

The assistive-editing exemption in paragraph 2 is the second over-application zone. Per the text, the marking duty does not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof. Spell checking, reformatting, denoising a photo: assistive standard editing. A prompt that produces an entire text or a new image: not an assistive function. The line runs at substantial alteration of input data or semantics — and anyone claiming the exemption should record, per tool, why.

The artistic and satirical exemption in paragraph 4 is under-applied and misunderstood at the same time. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations of that paragraph are limited to disclosing the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work. Note the mechanics: the duty is not removed, its form is softened. And it only applies to evidently artistic work — not to a commercial with a joke in it.

The editorial exemption for AI-generated text in paragraph 4 is the only exemption an organisation can actively create: it applies where the AI-generated content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for its publication. That is designable — but only where the review step and the responsible party genuinely exist in the approval process and can be evidenced. A four-eyes principle that lives only in the wiki will not carry.

Finally, the law-enforcement carve-outs provided in paragraphs 1 to 4 for systems authorised by law to detect, prevent, investigate or prosecute criminal offences concern authorities and their contractors — not a company detecting fraud attempts in its own shop. That confusion happens and it is expensive, because it justifies an entire control gap.

ExemptionReferenceTypical mistake
Obviousness of the AI interactionArt. 50(1)Over-applied: "everyone knows" — the test is the actual context of use
Assistive standard editing / no substantial alterationArt. 50(2)Over-applied: generative creation declared to be "editing"
Evidently artistic, satirical or fictional workArt. 50(4)Misread: the duty is softened in form, not removed
Editorial control with named responsibilityArt. 50(4)Underused: designable, but only with a genuinely lived approval process
Law-enforcement authorisationArt. 50(1)–(4)Confused: does not cover a company's own fraud detection

Ten implementation steps with owners — embedded, not a new silo

The checklist below is deliberately cut so that each item has exactly one owner. The most common implementation failure with Article 50 is not missing knowledge but shared responsibility: product treats it as a legal topic, legal as a product topic, and marketing does not notice it is in scope at all.

Equally important is where these controls live. Article 50 does not create a new management system family. The marking decision is a documented technical decision and belongs in your architecture and change regime. The vendor question about marking capability belongs in your existing third-party assessment. Editorial responsibility belongs in the content approval process. The evidence belongs in the existing evidence repository of your ISMS or AI governance. Build a separate register, separate policies and separate reviews for Article 50 and you create a parallel operation that will produce contradictory states at the next audit.

For the system inventory, one piece of groundwork pays off and many organisations already have it: the AI use case inventory. Where it is missing, our AI Use Case Assessment provides the structure and the AI Readiness Assessment positions organisational maturity. Scope and prices are transparent on the pricing page; the full catalogue sits under Templates.

  1. 1Product: build an AI touchpoint inventory. Capture every point where an AI system interacts directly with natural persons — website chat, in-app assistant, messenger bot, phone voicebot, email autoresponder.
  2. 2Legal: determine the role per touchpoint. Record for each system whether the company is provider or deployer, and document the reasoning — especially for white-label rollouts under your own brand.
  3. 3Product: anchor the Art. 50(1) disclosure in the UI. Notice at the latest at first interaction, clear and distinguishable, accessible per Art. 50(5) — not buried in terms and conditions or a privacy notice.
  4. 4IT delivery: survey the marking capability of every generation tool in use. Document per tool whether outputs are marked machine-readably, by which method, and how the marking can be verified.
  5. 5IT delivery: take and justify the technical marking decision. Choose a method from the categories listed in Recital 133, test robustness against common processing steps, and store the decision under version control.
  6. 6Marketing: define the visible disclosure for deepfake content. For image, audio and video content depicting real persons, objects or events, set a label pattern that viewers can perceive.
  7. 7Marketing: formalise the editorial process for AI-generated text. Review step, named editorial responsibility and logging — the only exemption in Art. 50(4) you can actively create.
  8. 8Legal: assess emotion recognition and biometric categorisation. Identify existing systems, implement the notice duty under Art. 50(3), and document the GDPR legal basis cleanly.
  9. 9IT delivery: update vendor clauses. Fold marking commitments, verifiability and change notifications into the existing third-party assessment — not into a separate AI contract folder.
  10. 10Legal: hook the evidence into the existing control set. File the marking decision, UI evidence, approval logs and vendor responses in the existing evidence repository of your ISMS or AI governance, and assign a control owner.

Enforcement reality: who supervises, from when, and what a breach costs

Responsibility for Article 50 sits nationally. Article 70 of the AI Act requires each Member State to establish or designate at least one notifying authority and at least one market surveillance authority as national competent authorities; Member States had to make information on how to contact those authorities and the single point of contact publicly available through electronic means by 2 August 2025 (see https://eur-lex.europa.eu/eli/reg/2024/1689/oj). The EUR-Lex summary confirms that the governing bodies — national competent authorities and the AI Office inside the European Commission — have been active since 2 August 2025. For Article 50 cases, then, your counterpart is not the AI Office in Brussels but the national market surveillance authority; per the summary, the AI Office acts as regulator for general-purpose AI models.

The penalty frame is unambiguously allocated. Article 99(4) of the AI Act lists, in point (g), the "transparency obligations for providers and deployers pursuant to Article 50" and subjects them to administrative fines of up to EUR 15 000 000 or, if the offender is an undertaking, up to 3 % of total worldwide annual turnover for the preceding financial year, whichever is higher. Article 50 therefore expressly does not sit in the top tier: that one is reserved under Article 99(3) for non-compliance with the prohibited practices in Article 5 and runs up to EUR 35 000 000 or 7 % of worldwide annual turnover.

For smaller organisations the arithmetic inverts: under Article 99(6), for SMEs including start-ups each fine is capped at whichever of the percentage or the fixed amount is lower. The EUR-Lex summary phrases this as proportional administrative fines for small and medium-sized enterprises and start-ups. The substantive duties, however, do not shrink accordingly.

On expectations: 2 August 2026 is the start of applicability, not the start of blanket inspections. Realistically, market surveillance will act on triggers first — complaints, publicly visible cases, referrals from other proceedings. That is precisely what makes Article 50 uncomfortable: these duties are verifiable from the outside, without anyone entering your premises. An unlabelled chatbot and an unmarked deepfake in a campaign are visible to any complainant. There is no preparation window between complaint and finding.

For the timeline and the deferral question, see our Digital Omnibus update; the Commission documents the overall regulatory framework on its AI policy page (see https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai). And if you are navigating several EU regimes at once this year, put the Article 50 controls into the shared control set from the start rather than running them separately — the reasoning sits in our quick check hub and in the regulatory collision article.

QuestionAnswer per the regulationReference
From when does Article 50 apply?From the general date of application of the regulation, 2 August 2026EUR-Lex summary of the AI Act
Who supervises?The national market surveillance authority of the Member StateArt. 70(1) and (2)
Since when are the authorities active?Governing bodies since 2 August 2025EUR-Lex summary of the AI Act
Penalty frame for Article 50 breachesUp to EUR 15 000 000 or up to 3 % of worldwide annual turnover, whichever is higherArt. 99(4)(g)
Special rule for SMEs and start-upsWhichever of the two values is lowerArt. 99(6)

Key Takeaways

  • Article 50 of the AI Act applies from 2 August 2026 per the EUR-Lex summary and heise online, and covers AI in customer contact and content production — not the Annex III high-risk cases.
  • Four duties, two addressees: chatbot disclosure (para. 1) and machine-readable marking (para. 2) fall on the provider; emotion recognition notice (para. 3) and deepfake / public-interest text disclosure (para. 4) on the deployer.
  • Machine-readable marking and human-perceptible disclosure are two separate requirements — a visible caption alone does not satisfy Article 50(2).
  • The exemptions are narrow: obviousness is contextual, the assistive carve-out ends at substantial alteration of data or semantics, and the artistic carve-out softens the duty rather than removing it.
  • Breaches of Article 50 fall under Article 99(4)(g) with fines of up to EUR 15 000 000 or 3 % of worldwide annual turnover — enforced by the national market surveillance authority, not the AI Office.

Continue Reading

Frequently Asked Questions

The disclosure duty in Article 50(1) addresses the provider, who must design the system so users recognise the AI interaction. As a pure user organisation you are a deployer and formally the addressee of paragraphs 3 and 4. In practice that does not mean you do nothing: you are responsible for the purchased bot actually surfacing a recognisable notice in your channel, and you should secure that contractually. There is also the role question: rolling out a purchased system under your own name and brand, or substantially modifying it, can move you into the provider role under the structure of the regulation. That assessment belongs in writing, not in an assumption.

For deepfake disclosure under Article 50(4), a visible and clearly distinguishable notice can be exactly right — that duty addresses humans. For the marking duty in paragraph 2 it is not enough: there the regulation explicitly requires marking in a machine-readable format from which artificial generation or manipulation is detectable. A caption survives neither a crop nor a repost nor a screenshot, and was never attached to the file itself. Where both paragraphs apply you need both layers: the machine-readable mark on the artefact and the human-perceptible disclosure in the publication.

The text rule in Article 50(4) attaches to text published for the purpose of informing the public on matters of public interest. A conventional job advertisement typically does not meet that. Two caveats still apply. First, the carve-out for editorially controlled content only holds where human review has taken place and a natural or legal person holds editorial responsibility — worth setting up properly regardless. Second, automated pre-screening of applications is a different matter: according to heise online it can trigger the stricter high-risk requirements under Annex III.

The AI Act prescribes no format. Recital 133 lists watermarks, metadata identifications, cryptographic methods for proving provenance and authenticity, logging methods and fingerprints as possible techniques, singly or in combination. Article 50(2) requires the solution to be effective, interoperable, robust and reliable as far as technically feasible, taking into account implementation costs and the generally acknowledged state of the art. In practice, C2PA with Content Credentials is the most widespread approach for cryptographic provenance; the regulation does not name it. What matters for auditability is that you document your choice with reasoning and under version control.

Article 99(4) of the AI Act names, in point (g), the transparency obligations under Article 50 and provides for administrative fines of up to EUR 15 000 000 or, for undertakings, up to 3 % of total worldwide annual turnover for the preceding financial year, whichever is higher. The top tier of up to EUR 35 000 000 or 7 % is reserved under Article 99(3) for the prohibited practices in Article 5 and does not apply here. For SMEs including start-ups, Article 99(6) caps the fine at whichever of the two values is lower.

The Digital Omnibus discussion concerns possible deadline extensions within the simplification of existing digital regulation; heise online describes it in the same breath as noting that the Article 50 transparency obligations apply from 2 August 2026. The EUR-Lex summary names the same day as the general date of application of the regulation. The defensible planning assumption is therefore: implement Article 50, and treat any later relief as buffer rather than as a basis. The effort is modest enough that waiting does not pay.

Article 70 of the AI Act requires each Member State to designate at least one notifying authority and at least one market surveillance authority, and to name one market surveillance authority as the single point of contact; contact information had to be made publicly available by 2 August 2025. Your counterpart for Article 50 cases is therefore the relevant national market surveillance authority, not the Commission's AI Office — which, per the EUR-Lex summary, regulates general-purpose AI models. Check the currently designated body for your Member State via the list of single points of contact published by the Commission.

EU AI ActArtikel 50TransparenzpflichtenKI-KennzeichnungComplianceIT Governance

Ready for Your Assessment?

Use our interactive templates to measure your IT organization's maturity — with automatic scores, AI-powered recommendations, and professional PDF reports.