EU AI Act update: the Council adopted the Digital Omnibus on AI on 29 June 2026. Official Journal publication is still pending; review the official Council update before relying on older high-risk deadline references. Council update EU AI Act update: Council adopted the Digital Omnibus; OJ publication pending. Council update

EU AI Act · Pillar Guide 1C

EU AI Act Article 50: Transparency and Labelling for Chatbots, Deepfakes and AI‑Generated Content

Article 50 transparency obligations remain route-specific and are generally scheduled around 2 August 2026 for in-scope duties, with a specific adopted-pending-OJ Article 50(2) provider transition to 2 December 2026 for certain synthetic-content systems already placed on the market before 2 August 2026. A chatbot, synthetic-content system, emotion-recognition use, biometric-categorisation use, deepfake workflow, or public-interest text workflow can trigger different provider or deployer duties. Start by identifying the correct route.

Check your Article 50 obligations → Content labelling checklist →

10 June 2026 Article 50 Code update

The Code is voluntary. Article 50 is not. The European Commission published the Code of Practice on Transparency of AI-Generated Content on 10 June 2026. The Code's operational sections address Article 50(2) provider marking and Article 50(4) deployer labelling. Article 50(5) supplies the cross-cutting requirements for clear, distinguishable and accessible information at the latest at first interaction or exposure. The Code remains voluntary implementation support; Article 50 obligations remain legal obligations where they apply.

Deployers should now record whether Code measures, EU icons, provider marking dependencies, label wording, first-interaction or first-exposure timing, accessibility, and public-interest text review were considered. Do not treat the Code, an icon, or a checklist as legal approval.

Published: 18 March 2026| Last reviewed: 23 June 2026|By Abhishek G Sharma
EU AI Act Article 50 transparency framework — four obligation categories: chatbot disclosure, content marking, deepfake labelling, and biometric notification

Article 50 timing watch

Under the current AI Act, Article 50 transparency obligations remain route-specific and are generally scheduled around 2 August 2026 for in-scope duties, with a specific adopted-pending-OJ Article 50(2) provider transition to 2 December 2026 for certain synthetic-content systems already placed on the market before 2 August 2026. PE-CONS 30/26 describes a specific adopted-pending-OJ transition until 2 December 2026 for providers of AI systems generating synthetic audio, image, video or text content placed on the market before 2 August 2026 to comply with Article 50(2). It is not a blanket transition for every Article 50 deployer disclosure route. The Council adopted the Digital Omnibus on AI on 29 June 2026, but Official Journal publication and the exact entry-into-force date remain pending. Treat the adopted text as an adopted-pending-OJ planning baseline, not as a blanket delay for all Article 50 duties.

Article 50 timing note, 10 June 2026

The Commission Q&A states that Article 50(2) and Article 50(4) obligations apply from 2 August 2026 for providers and deployers in scope, with a transitional period until 2 December 2026 for AI systems placed on the market before that date. The Council-adopted Digital Omnibus text separately tracks a 2 December 2026 planning date for providers of synthetic-content systems placed on the market before 2 August 2026 to comply with Article 50(2), pending Official Journal publication. Do not treat either point as a general postponement of Article 50 readiness work.

What EU AI Act Article 50 requires in plain language

Article 50 is the EU AI Act's transparency layer. It applies to AI systems that aren't necessarily high-risk but still interact with people or produce content that could be mistaken for human-made. It covers four distinct AI content labelling and disclosure obligation categories, all requiring route-specific review around 2 August 2026, with the adopted-pending-OJ Article 50(2) provider transition to 2 December 2026 for certain existing synthetic-content systems.

1. Tell people when they're talking to AI

If an AI system is intended to interact directly with natural persons, Article 50(1) requires the provider to design and develop the system so the person is informed that they are interacting with AI, unless this is obvious to a reasonably well-informed, observant and circumspect person in the circumstances. Article 50(5) requires the information to be clear, distinguishable and accessible, at the latest at first interaction.

2. Mark AI-generated content in a machine-readable way

Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Technical solutions must be effective, interoperable, robust and reliable as far as technically feasible. The Act does not prescribe one mandatory technology.

3. Inform people exposed to emotion recognition or biometric categorisation

If your system performs emotion recognition or biometric categorisation, the people being analysed must be informed. This intersects with Article 5 prohibitions — emotion recognition in workplaces and schools is banned outright (with narrow exceptions). But where it's permitted — retail analytics, security screening, healthcare — the transparency duty applies.

4. Disclose deepfakes and AI-generated public-interest text

Article 50(4) requires deployers to disclose deepfake image, audio or video content as artificially generated or manipulated. It also covers generated or manipulated text published to inform the public on matters of public interest, subject to the human-review and editorial-responsibility exception. Artistic, creative, satirical, fictional or analogous works are not a blanket exemption: disclosure is limited to an appropriate form that does not hamper display or enjoyment.

What Article 50 does NOT do

It doesn't reclassify your system as high-risk. It doesn't replace GDPR transparency duties — it adds to them. And it doesn't cover every use of AI. If your system simply processes data internally without interacting with people or producing content, Article 50 probably doesn't apply. But the moment your AI talks to someone or creates something someone else will see, you're in scope.

Which obligations apply to providers and which to deployers?

Article 50 assigns different duties by route. Providers carry the Article 50(1) interaction-design duty and Article 50(2) machine-readable marking and detection duty. Deployers carry the Article 50(3) exposed-person notification duty and Article 50(4) deepfake or public-interest text disclosure duty. An organisation can hold both roles for the same or different systems.

Scenario Provider obligation Deployer obligation
Chatbot / AI assistant Design and develop the system so natural persons are informed they are interacting with AI, unless the interaction is objectively obvious (Art. 50(1)) Operationally configure and evidence the provider's notice mechanism where the organisation controls deployment
Synthetic audio, image, video or text Implement machine-readable marking and detection using technically feasible, effective, interoperable, robust and reliable measures (Art. 50(2)) Request and preserve provider evidence; apply a separate Article 50(4) label only when the deployer's publication route triggers it
Emotion recognition / biometric categorisation No separate Article 50(3) provider notice duty; provide instructions and information needed for lawful deployment where applicable Inform exposed natural persons about operation of the system and complete the separate data-protection review (Art. 50(3))
Deepfakes / public-interest text Article 50(2) marking may apply to the generating system; give deployers usable marking and detection evidence Disclose deepfakes and qualifying public-interest text, subject to the specific statutory treatments and exceptions (Art. 50(4))

Table 1: Article 50 obligation split between providers and deployers. For the full overview of deployer obligations, see our Complete EU AI Act Compliance Guide.

How to implement chatbot and AI assistant disclosure

For direct-interaction systems, the provider must build the Article 50(1) notice capability into the system. The deploying organisation should confirm that the notice is enabled, visible and retained as operational evidence. The exact treatment depends on role, context and whether the AI nature is objectively obvious.

Design pattern: persistent + first-message

The most robust approach is a two-layer disclosure. First, a persistent visual indicator — a small badge or icon near the chat interface that reads "AI Assistant" or "Powered by AI." Second, a first-message notice: the chatbot's opening message explicitly states it's an AI system. Something like: "I'm an AI assistant. I can help with [topic]. For complex issues, I'll connect you with a human agent." This pattern satisfies the "timely, clear, and intelligible" standard the regulation implies.

Voice assistants

For voice-based systems, the disclosure must be audible. An opening statement at the start of each interaction: "You're speaking with an AI assistant." Don't bury it after 30 seconds of conversation. Front-load it.

The "obvious AI" exception

Article 50(1) exempts cases where AI use is "obvious from the circumstances and context of use." A robotic character in a video game might qualify. A customer service chatbot that uses natural language and human-like responses doesn't — even if it has a bot icon. The exception is narrow, and regulators haven't published detailed guidance on its boundaries yet. My recommendation: disclose anyway. The cost of a small notice is usually low. The cost of getting the "obvious" judgment wrong can fall within the Article 99(4)(g) maximum tier for Article 50 transparency obligations: EUR 15 million or 3% of global annual turnover, subject to national enforcement rules, proportionality, facts, and due process.

Marking AI-generated images, video, audio and text

Article 50(2) targets the output side of generative AI. Providers of systems that generate synthetic content must mark that content in a machine-readable format. This isn't about visible watermarks on images (though those help) — it's about embedded metadata that downstream systems and platforms can detect.

Technical marking options

Three main approaches are emerging. Metadata embedding (XMP, IPTC) — the most mature, already used in photography and publishing. Invisible watermarks — imperceptible to humans but detectable by specialised tools. Cryptographic provenance — systems like C2PA (Coalition for Content Provenance and Authenticity) that create a tamper-evident chain of custody for content. The regulation doesn't prescribe a specific standard, but the marking must be "effective, interoperable, robust, and reliable." Could your content pipeline implement any of these today? If the answer is no, that's the project to start.

Assistive edits: where's the line?

Article 50(2) does not apply to the extent an AI system performs an assistive function for standard editing or does not substantially alter the input data or its semantics. Record the actual function and degree of alteration rather than relying on a generic label such as “AI-assisted”.

Provider scope includes general-purpose AI systems

Article 50(2) applies to providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text. Record which entity controls the output marking and detection measures and what evidence is available to downstream deployers.

Article 50 content labelling workflow — from AI generation through metadata embedding, editorial review, and publication with visible and machine-readable labels

Figure: The content labelling workflow — from AI generation through metadata embedding, editorial review, and reviewed publication workflow.

Deepfakes and AI text on matters of public interest

The EU AI Act defines a deepfake as AI-generated or manipulated content — image, audio, or video — that resembles existing persons, objects, places, or events and would falsely appear authentic to a reasonable person. Article 50(4) requires deployers to disclose when they publish such content.

What triggers the deepfake disclosure duty

Review whether the image, audio or video constitutes a deepfake under the Act, whether it is being disclosed to others, and whether a statutory law-enforcement or creative-work treatment applies. Retain the classification rationale, disclosure wording, placement and publication evidence.

AI-generated text on public interest topics

Article 50(4) also covers generated or manipulated text published for the purpose of informing the public on matters of public interest. The disclosure duty does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for publication. Record both the publication purpose and the evidence supporting any reliance on that exception.

Artistic and satirical exceptions

For evidently artistic, creative, satirical, fictional or analogous works or programmes, Article 50(4) limits the obligation to an appropriate disclosure of the existence of generated or manipulated content that does not hamper display or enjoyment. This is a modified disclosure treatment, not a blanket exemption.

Emotion recognition and biometric categorisation transparency

Article 50(3) requires that individuals exposed to emotion recognition or biometric categorisation systems are informed of the system's operation. But there's a critical sequencing issue most compliance teams miss: check Article 5 prohibitions before you worry about Article 50 transparency.

Article 5 prohibits AI systems used to infer emotions in workplace and education contexts, except where the use is intended for medical or safety reasons. Check the prohibited-practice route before planning an Article 50(3) notice. Use the EU AI Act Checker as an initial triage aid.

Where emotion recognition or biometric categorisation is permitted, Article 50(3) requires deployers to inform exposed natural persons of operation of the system and to process personal data in accordance with applicable data-protection law. Any objection, opt-out or data-subject-rights process must be assessed separately under the applicable privacy and sector framework.

Design patterns and workflow changes for compliance

For product teams

Build disclosure into your design system, not as an afterthought. Create a standard AI disclosure component — badge, tooltip, or banner — that can be dropped into any interface where AI interacts with users. Define toggle defaults: AI disclosure should be on by default and require a documented justification to disable it. For generative features, route all AI outputs through a content marking pipeline before they reach the user. If a third-party system generates synthetic content, request evidence of the provider's Article 50(2) marking and detection approach, technical limitations and available downstream signals.

For editorial and marketing teams

Establish a clear policy: when can AI be used to draft, edit, or generate content? Who reviews it before publication? How is AI involvement disclosed — footnote, byline qualifier, metadata? The policy should distinguish between AI-assisted (human edits substantially) and AI-generated (AI produced the substance). For CMS workflows, add a mandatory field: "AI involvement level" — None / Assisted / Generated. This creates an audit trail that you can produce when a regulator or customer asks.

Documentation for audits

Keep a transparency decisions register. For every AI system or generative tool your organisation uses, record: what disclosure mechanism is in place, when it was implemented, who approved it, and the rationale for any exception claims (e.g., "obvious AI" under Article 50(1)). This register becomes your compliance evidence if a national competent authority comes asking.

Use EU AI Compass tools to check your Article 50 readiness

These free tools support Article 50 triage and evidence preparation. They run in the browser and do not make a legal or compliance determination.

Article 50 Transparency Validator

Classify your AI system against Article 50 categories and get a disclosure checklist. Covers chatbots, generative content, emotion recognition, and deepfakes.

Launch Validator →

AI Content Marking Checker

Check whether your content pipeline meets machine-readable marking requirements. Covers metadata, watermarks, and provenance standards.

Launch Checker →

Common mistakes and grey areas around Article 50

Mistake Why it's wrong What to do instead
Assuming AI-assisted text is always exempt If AI substantially changed the content's meaning or structure, it's "manipulated" under Article 50 Apply the substance test: did the AI change what the text says? If yes, it's in scope
Assuming internal-only content needs no labelling If internal AI content influences decisions about employees, deployer duties may apply Label internal AI content anyway — zero cost, eliminates ambiguity
Relying on vendor defaults without internal policy Deployers carry their own Article 50 obligations regardless of what the provider configured Verify vendor marking works; create your own content policy and disclosure standards
Claiming "obvious AI" exception without documentation If a regulator disagrees, you need evidence showing why the exception was reasonable Document the rationale in your transparency register; default to disclosure
Stripping metadata from AI-generated images before publishing Removes the machine-readable marking the provider embedded, potentially violating both provider and deployer duties Preserve AI provenance metadata through your entire content pipeline

Table 2: Five common Article 50 compliance mistakes. Further guidance from the Commission, AI Office, and the Article 50 Code of Practice is expected throughout 2026.

Guidance is still evolving. The Article 50 Code of Practice was published by the European Commission on 10 June 2026. Treat the Code as voluntary implementation support. Build the legal baseline from Regulation (EU) 2024/1689 Article 50, then use the Code to structure marking, labelling, signatory status, EU icon decisions, and evidence records. Final Article 50 Commission guidelines are still a separate watch item.

Related compliance tools

All tools run 100% in your browser. No login, no data collection.

FAQ: EU AI Act Article 50 transparency

Further reading

AG

Abhishek G Sharma

Founder & CEO, Move78 International Limited. 20+ years in cybersecurity and AI risk management. Certifications: ISO 42001 LA, ISO 27001 LA, CISA, CISM, CRISC, CEH, CCSK, CAIGO, CAIRO.

Need More Practical Guidance?

Explore the free EU AI Compass tools and guides to classify your use case, understand your obligations, and move to the next compliance step.

Disclaimer & educational purpose

This guide is published by Move78 International Limited for educational purposes only. It does not constitute legal advice. The EU AI Act (Regulation 2024/1689) is a complex legislative instrument with evolving guidance. The Article 50 Code of Practice was published by the European Commission on 10 June 2026 as voluntary implementation support. Article 50 obligations remain legal obligations where they apply, and final Commission Article 50 guidelines remain a separate watch item. Organisations should consult qualified legal counsel for Article 50 compliance decisions and should not treat this page as legal advice or certification.

Sources and legal basis