Skip to content

EU AI Act

Article 50: AI disclosure, synthetic-content marking and transparency

Article 50 generally applies from 2 August 2026. It assigns different transparency duties to providers and deployers. These include informing people of direct AI interaction, embedding machine-readable information in synthetic output and making that output detectable, notifying people exposed to emotion recognition or biometric categorisation, and disclosing deepfakes and qualifying public-interest text. The transition to 2 December 2026 for an older system concerns paragraph 2 only.

As of 2026-09-15. Generally applicable from 2 August 2026; paragraph 2 has a specific transition for older systems. General information, not legal advice.

Why this matters now

A transparency program needs to reach interfaces, output generation and publication. These are different technical and business activities. A customer notice cannot demonstrate that generated files retain machine-readable marking. A model supplier's technical report cannot establish that a publisher delivered a deepfake disclosure. Organizations need to identify who controls each activity and test the implementation there.

Article 50 is also independent of high-risk classification. Its obligations do not wait for the principal 2027 and 2028 high-risk dates simply because a system might later qualify under Annex III or Annex I.

The law by paragraph

ProvisionResponsible roleDirect requirementImportant limit
Article 50(1)ProviderEnsure people are informed that they are interacting with AI.Contextual obviousness and a qualified law-authorised crime-purpose exception.
Article 50(2)Provider of a system, including a GPAI systemEnsure synthetic audio, image, video or text output is machine-readably marked and detectable as generated or manipulated.Technical feasibility and specified editing/crime-purpose exceptions.
Article 50(3)DeployerInform people exposed to emotion-recognition or biometric-categorisation systems.Applicable data protection law and qualified crime-purpose exceptions; Article 5 remains separate.
Article 50(4), first subparagraphDeployerDisclose artificial generation or manipulation of image, audio or video that constitutes a deepfake.Qualified crime-purpose exception and adjusted disclosure manner for specified creative works.
Article 50(4), second subparagraphDeployerDisclose generated or manipulated text published to inform the public on matters of public interest.Qualified human-review/editorial-control and crime-purpose exceptions.
Article 50(5)Relevant provider or deployerSupply clear, distinguishable and accessible information by first interaction or exposure.Applies to the information duties in paragraphs 1 through 4.

Read provider vs deployer if responsibility is unclear. The role analysis must concern the actual system and activity.

Direct human-AI interaction

Paragraph 1 addresses systems intended to interact directly with natural persons. The provider must ensure people are informed of AI interaction unless that is obvious to a reasonably well-informed, observant and circumspect person in the circumstances and context of use. The test is contextual. A product team cannot replace it with its own assumption that everyone recognizes a chatbot.

The law also contains an exception for systems authorised by law for specified criminal-offence purposes. The exception does not apply to systems available for the public to report criminal offences. Paragraph 2 has a separate crime-purpose exception without that same public-reporting carve-back. Keep the two tests distinct.

Our operational recommendation is to examine the first point of contact in each supported channel. That may include a website, mobile interface, embedded widget or voice service. Test the released version, not only a design mockup. Record the notice and the circumstances in which it appears. This channel review is an implementation method, not a statutory checklist of interfaces.

Synthetic-output marking and detectability

Paragraph 2 requires two technical outcomes. The provider must embed machine-readable information that marks output as artificially generated or manipulated, and the output must be detectable as such. The paragraph covers systems, including GPAI systems, that generate synthetic audio, images, video or text. It does not name standalone GPAI models as such, so a model supplier and a provider integrating that model into a system need distinct analyses.

The solutions must be effective, interoperable, robust and reliable insofar as technically feasible, with account taken of content limitations, implementation costs and the generally acknowledged state of the art. That qualification does not establish a blanket permission to omit implementation whenever it is inconvenient.

The editing exception concerns systems performing an assistive function for standard editing or not substantially altering input data or its semantics. It belongs to paragraph 2. Do not extend it automatically to every rewriting or summarisation feature or to separate deployer disclosure duties.

Operationally, identify where output is created, transformed, exported and distributed. A generation component may add marking that an export step strips. Test representative files and transformations, document limits, and retain the output version examined. These tests support an implementation conclusion; they do not establish compliance for every future output.

Deepfakes and public-interest text

Article 3(60) defines a deepfake as AI-generated or manipulated image, audio or video content that resembles an existing person, object, place, entity or event and would falsely appear authentic or truthful to a person. A deployer using a system to generate or manipulate content that meets that definition must disclose the artificial generation or manipulation, subject to the statutory qualifications. The duty does not label every generated image a deepfake.

For evidently artistic, creative, satirical, fictional or analogous works, the duty is adjusted to disclosure of the existence of generated or manipulated content in an appropriate manner that does not hinder display or enjoyment. This changes the manner of disclosure. It is not a complete creative-work exemption.

The text branch concerns generated or manipulated text published for the purpose of informing the public on matters of public interest. It does not cover every public text merely because it appears on a website. The exception requires human review or editorial control and editorial responsibility held by a natural or legal person. Both parts matter. Review alone, without the responsibility condition, does not establish the exception.

The public-interest-text exception does not waive the provider's paragraph 2 marking duty. The provider and publisher may be different actors; a single enterprise may also need to examine both roles.

We recommend recording the publication purpose, final content version, responsible publisher or editor, and reasons for any exception. A generic "human in the loop" label does not say who reviewed the text, what they reviewed or who held editorial responsibility. The quality of review needed in a disputed case remains a legal question; unresolved guidance cannot supply a binding test.

Emotion recognition and biometric categorisation

Paragraph 3 requires deployers to inform exposed people and comply with applicable personal-data protection law. It includes qualified law-authorised crime-purpose exceptions with safeguards. A transparency notice does not override a separate Article 5 prohibition, including the workplace/education emotion-inference prohibition or sensitive biometric categorisation conditions.

Operational review should therefore screen the purpose before designing the notice. If a use is prohibited within Article 5, adding disclosure cannot make it permissible. This distinction is especially important when a vendor describes a biometric feature primarily as analytics.

Timing, accessibility and older systems

Paragraph 5 requires clear and distinguishable information at the latest by first interaction or exposure, with accessible presentation. A notice hidden in general terms does not demonstrate that the relevant information reached the person at that point. Implementation testing should follow the actual user journey.

Article 111(4) gives specified generative systems placed on the market before 2 August 2026 until 2 December 2026 to comply with paragraph 2. It does not postpone all Article 50 disclosures. The research records an unresolved mismatch for internally developed own-use systems: the statutory wording refers to placement on the market, while inspected guidance also refers to putting into service. Do not assume the transition covers that edge case.

SituationDate analysis
Direct interaction or deployer disclosure within Article 50General application is 2 August 2026, subject to its particular conditions and exceptions.
Qualifying older generative system, paragraph 2Compliance by 2 December 2026 under the specific placement transition.
Internally developed older own-use systemTransition coverage requires review; no categorical answer in this baseline.

Commission materials and their limits

The research found a conflict between the Article 50 landing page, which uses adoption wording, and the inspected 20 July 2026 document, which approves draft content and reserves later formal adoption. The review did not locate a separate later adoption act, so the guidance's formal status remains unresolved. The statute supplies the obligations and exceptions described here.

The final Transparency Code was published on 10 June 2026. The Commission adequacy opinion dated 8 July 2026 says adherence is not conclusive evidence of compliance. The Code is voluntary assistance for covered marking and content-disclosure areas. It does not replace Article 50 or resolve every paragraph.

The unresolved guidance does not support a settled exemption for internal intermediates, closed professional groups, ephemeral outputs or historical content. These questions still need targeted research and legal review.

Controls and evidence, as operational recommendations

Implementation areaEvidence worth examiningLimit of that evidence
Interaction noticeReleased UI capture, notice configuration and first-interaction testA screenshot alone cannot show delivery to every user.
Output markingConfiguration, generated samples, export artifacts and detection testsSuccess in one format does not establish robustness through all transformations.
Publication disclosureFinal published version, label placement and timing testA draft label is not evidence of the published version.
Editorial exceptionReview record, final text and editorial-responsibility recordThe record does not automatically establish the legal exception.
AccessibilityTest method, supported channels, findings and fixesResults have a defined audience, version and test scope.

These are suggested evidence types, not additional statutory document names or universal retention periods. Separate the requirement, the control, the evidence and the assessment conclusion.

Start by assigning paragraph-specific roles. Map interaction and publication paths, review exceptions, implement the relevant notices or marking, then test released behavior. Record unresolved supplier dependencies and transition questions. Maintain a review trigger for new guidance and changed interfaces.

FAQ

Is a visible AI label enough for paragraph 2?

Paragraph 2 requires machine-readable marking and detectability. A human-readable label does not by itself demonstrate those properties. Other paragraphs may separately require information for people.

Does human review eliminate all transparency obligations?

No. The qualifying exception concerns the public-interest-text disclosure branch and includes editorial responsibility. It does not remove provider marking or unrelated interaction and deepfake duties.

Must every organization follow the Transparency Code?

The Code is voluntary. The underlying law remains applicable, and adherence is not conclusive compliance evidence.

Can an older system wait until December for its chatbot notice?

The transition for an older system concerns paragraph 2 marking and detection only. It is not a general delay for paragraph 1 interaction disclosure.

Next step

Use the role analysis and implementation timeline to scope the relevant paragraphs. Then follow the operational readiness sequence.

Primary sources

Use the consolidated text to navigate provisions and the authentic original and amending Official Journal acts for the legislation. Guidance and Q&A retain their separate legal status.