The four Article 50 routes
Article 50 does not create one general duty to label everything made with AI. It creates four routes with different addressees, triggers and exceptions. Identify the route before choosing a notice, marking control or evidence record.
Article 50(1): direct AI interaction
The provider must design and develop an AI system intended to interact directly with natural persons so they are informed that they are interacting with AI, unless that is obvious to a reasonably well-informed, observant and circumspect natural person in the circumstances and context of use.
Article 50(2): machine-readable marking and detectability
The provider of an AI system, including a general-purpose AI system, that generates synthetic audio, image, video or text must ensure its outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, subject to the provision's qualifications and exclusions.
Article 50(3): emotion recognition and biometric categorisation
The deployer of an emotion recognition or biometric categorisation system must inform natural persons exposed to it of the system's operation. Article 5 prohibitions, data-protection law and sector rules must be checked separately.
Article 50(4): deepfakes and specified public-interest text
The deployer must disclose deepfake image, audio or video content as artificially generated or manipulated. A separate rule covers generated or manipulated text published to inform the public on matters of public interest, subject to the human-review, editorial-control and editorial-responsibility conditions.
Timing and scope
The four routes apply from 2 August 2026. Article 111(4) gives providers of systems covered by Article 50(2) that were placed on the market before that date until 2 December 2026 to take the necessary steps to comply with Article 50(2). It does not postpone Article 50(1), (3) or (4), and Article 50 does not replace other AI Act, data-protection or sector-law checks.
Which obligations apply to providers and which to deployers?
Article 50(1) and (2) assign duties to providers. Article 50(3) and (4) assign duties to deployers. An organisation may hold more than one role, including for the same system, so classify the role for each activity rather than relying on a single organisation-wide label.
| Scenario | Provider obligation | Deployer obligation |
|---|---|---|
| Chatbot / AI assistant | Design and develop the system so natural persons are informed they are interacting with AI, unless the interaction is objectively obvious (Art. 50(1)) | May operationally configure, preserve and evidence the provider-supplied notice where it controls deployment; this is not the direct Article 50(1) assignment |
| Synthetic audio, image, video or text | Implement machine-readable marking and detection using technically feasible, effective, interoperable, robust and reliable measures (Art. 50(2)) | May preserve and evidence provider-supplied marking where it controls the pipeline; apply Article 50(4) separately if that route is triggered |
| Emotion recognition / biometric categorisation | Article 50(3) does not assign the exposed-person notice to the provider | Inform exposed natural persons of the system's operation and complete separate Article 5, data-protection and sector-law checks (Art. 50(3)) |
| Deepfakes / public-interest text | Article 50(2) marking may separately apply to the generating system | Disclose deepfakes and qualifying public-interest text, subject to the specific statutory treatments and exceptions (Art. 50(4)) |
Table 1: Direct statutory assignment under Article 50. Operational configuration or evidence work does not transfer the underlying provider or deployer duty.
Article 50(1): direct interaction with natural persons
Article 50(1) applies where an AI system is intended to interact directly with natural persons. The provider must design and develop it so those people are informed that they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect natural person, taking account of the circumstances and context of use.
Background processing, machine-to-machine communications and systems without direct natural-person contact fall outside this specific route. Other AI Act or sector duties may still apply.
Legal timing
Article 50(5) requires the information under Article 50(1) to be clear, distinguishable and accessible, taking account of accessibility requirements, and provided no later than the first interaction or exposure.
Implementation recommendation
Where the exception is uncertain, use a first-interaction notice and a persistent visual indicator; for a voice-only interface, use an audible notice. These are practical design recommendations, not technologies or wording mandated by Article 50.
Assessing objective obviousness
Do not treat a bot icon, product category or internal team assumption as decisive. Record the interface, audience, context and evidence supporting the objective-obviousness conclusion. The Commission guidelines are non-binding guidance on scope and application; they do not replace the statutory test.
Article 50(2): machine-readable marking and detectability
Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text must ensure their outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The technical solutions must be effective, interoperable, robust and reliable as far as technically feasible, taking account of the characteristics and limitations of different content types, implementation costs and the generally acknowledged state of the art. The final Commission Guidelines call for proportionate application; proportionality is not a blanket exclusion.
Technology choices and provenance survival
Metadata, watermarking, fingerprints and cryptographic provenance approaches such as C2PA are examples used in technical practice or implementation material. Article 50 does not mandate one named technology. Test whether provider-supplied signals survive export, editing, transcoding and publication. Removing or losing metadata is an operational provenance and evidence risk; it is not automatically an Article 50 breach by a deployer without analysis of the specific role, route and facts.
Qualifications and exclusions
Article 50(2) does not apply to the extent an AI system performs an assistive function for standard editing or does not substantially alter the input data provided by the deployer or its semantics. This is a provider-side marking boundary, not the human-review and editorial-control condition for public-interest text under Article 50(4).
The Commission Q&A, reflecting the final guidelines, also identifies short sequences of numbers, symbols or letters, source code, outputs exclusively communicated machine-to-machine and processed automatically without human exposure, and non-final outputs used only in closed-loop industrial or product-development environments as outside this marking route. Apply those qualifications to the actual output and workflow; do not convert them into general content exemptions.
Narrow Article 111(4) transition
For an Article 50(2) system placed on the market before 2 August 2026, the provider must take the necessary steps to comply with Article 50(2) by 2 December 2026. The transition does not apply to Article 50(1), (3) or (4).
Figure: The content labelling workflow — from AI generation through metadata embedding, editorial review, and reviewed publication workflow.
Article 50(3): emotion recognition and biometric categorisation
Check Article 5 before Article 50(3). Article 5 prohibits AI systems used to infer emotions in workplace and education-institution contexts, except for uses intended for medical or safety reasons. An Article 50 notice does not make a prohibited use permissible.
Where a use is not prohibited, Article 50(3) assigns the deployer the duty to inform natural persons exposed to an emotion recognition or biometric categorisation system of its operation. Applicable data-protection and sector-law requirements must also be assessed.
Do not infer from this guide that a retail, security, healthcare or other scenario is lawful. The purpose, context, Article 5 position, personal-data processing and sector rules require separate review. This page does not determine a legal basis.
Article 50(4): deepfakes and public-interest text
Article 50(4) contains two distinct deployer routes. First, a deployer of an AI system that generates or manipulates image, audio or video content constituting a deepfake must disclose that the content was artificially generated or manipulated. Provider-side machine-readable marking under Article 50(2) does not replace this deployer disclosure.
Deepfake disclosure
The disclosure must be clear, distinguishable and accessible and provided no later than the first interaction or exposure. Use a visible disclosure for visual content and an audible disclosure where audio is the relevant mode. Retain the deepfake classification, wording, placement and publication evidence.
Text published to inform the public
The second route covers AI-generated or manipulated text published for the purpose of informing the public on matters of public interest. The disclosure duty does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for publication. Record evidence for both conditions before relying on this treatment.
Artistic, creative, satirical and fictional works
For an evidently artistic, creative, satirical, fictional or analogous work or programme, the duty is adapted rather than removed: disclose the existence of generated or manipulated content in an appropriate manner that does not hamper display or enjoyment of the work.
AI-generated advertising is not automatically subject to one blanket Article 50 rule or exemption. Apply the Article 50(2) provider test and each Article 50(4) deployer test to the content, purpose and publication context, then check advertising, consumer-protection and sector rules separately.
The Act, Commission Guidelines and voluntary Code
Use the three materials for different purposes. The legal obligation comes from the Act; the Guidelines explain the Commission's interpretation; the Code offers voluntary implementation measures for a limited set of routes.
| Material | Status and scope | How to use it |
|---|---|---|
| Article 50 of the AI Act | Binding obligations assigned by route to providers and deployers | Start with the statutory trigger, role, exception or modified duty and timing |
| Commission Guidelines | Final Commission guidance published 20 July 2026; non-binding; interprets scope and application | Use for the Commission's current interpretation, while keeping the Act controlling |
| Code of Practice | Final voluntary Code published 10 June 2026 for Article 50(2), (4) and (5); assessed as adequate by the Commission and AI Board | Use as implementation support. Adherence is not conclusive evidence of compliance and does not replace the Act or Guidelines |
The Code is not a substitute for Article 50(1) interaction notices or Article 50(3) emotion-recognition and biometric-categorisation notices.
Operational implementation recommendations
Classify the route and role
Record which Article 50 route applies, whether the organisation is acting as provider, deployer or both, and the exact trigger or exception being assessed. Do not reuse a conclusion from one route for another.
Test the notice or marking chain
For Article 50(1), test first-interaction timing, accessibility and objective obviousness. For Article 50(2), obtain provider evidence and test whether machine-readable signals survive the real content pipeline. For Article 50(3) and (4), test the deployer notice or disclosure in the actual exposure or publication context.
Keep decision evidence
Retain the system and content classification, role allocation, provider documentation, exception rationale, approved wording, accessibility review, technical test results, publication or interaction evidence, owner and review date. These are implementation recommendations; the required evidence will depend on the applicable law, system and supervisory context.
Existing EU AI Compass tools and evidence routes
Choose the existing route that matches the question or evidence task. These resources support triage and implementation planning; they do not make a legal determination.
| Existing resource | Use it for |
|---|---|
| Article 50 Transparency Evidence Validator | Review route signals and the evidence record |
| AI Content Marking Checker | Review content type, provider marking dependency, EU icon use and evidence |
| EU AI Act Quick Checker | Start an Act-wide classification and check Article 5 before Article 50(3) |
| Deployer Obligation Self-Assessment | Review obligations where the organisation acts as deployer |
| Article 50 Transparency Notice Templates | Prepare starting notice wording for review in the actual context |
| Article 50 Evidence File | Structure evidence for AI-generated-content labelling decisions |
Common mistakes and grey areas around Article 50
| Mistake | Why it's wrong | What to do instead |
|---|---|---|
| Using one test for Article 50(2) and (4) | The standard-editing boundary in Article 50(2) is different from Article 50(4)'s human-review, editorial-control and editorial-responsibility conditions | Record separate provider-marking and deployer-publication assessments |
| Treating “internal” as an exemption or trigger | Internal use is not itself a universal Article 50 exemption or a universal labelling duty | Apply each route to the actual interaction, system and publication context |
| Treating all advertising alike | Article 50 does not create one blanket rule or exemption for advertisements | Apply Article 50(2) and each Article 50(4) test, then check other applicable law |
| Assuming provider marking completes deployer disclosure | Article 50(2) machine-readable marking does not replace an Article 50(4) visible or audible deployer disclosure | Verify both routes where both are triggered |
| Treating Code adherence as complete coverage | The voluntary Code supports Article 50(2), (4) and (5), not Article 50(1) or (3), and adherence is not conclusive evidence of compliance | Start from the Act and use the Guidelines and Code within their stated roles |
Table 2: Five route-selection and implementation mistakes. Build the legal baseline from the consolidated Act, use the final Guidelines for Commission interpretation, and use the voluntary Code only within its Article 50(2), (4) and (5) scope.
FAQ: EU AI Act Article 50 transparency
Article 50(1) applies where a provider's AI system is intended to interact directly with natural persons. The provider must design and develop the system so those people are informed that they are interacting with AI, unless that is obvious to a reasonably well-informed, observant and circumspect natural person in the circumstances and context of use. Background processing, machine-to-machine communications and systems without direct natural-person contact fall outside this specific route. The information must be clear, distinguishable and accessible and provided no later than the first interaction or exposure.
Article 50(4) does not impose one blanket rule for every AI-assisted blog post or marketing text. Its public-interest-text route applies to AI-generated or manipulated text published to inform the public on matters of public interest. The disclosure duty does not apply where the text has undergone human review or editorial control and a natural or legal person holds editorial responsibility. Article 50(2) provider marking is a separate assessment, and advertising, consumer-protection and sector rules may also apply.
For Article 50(2), provider-side marking does not apply to the extent the system performs an assistive function for standard editing or does not substantially alter the deployer's input data or its semantics. Article 50(4) asks a separate question: for public-interest text, has the content undergone human review or editorial control, and does a natural or legal person hold editorial responsibility? Do not use one test as a substitute for the other.
A deployer publishing image, audio or video content that constitutes a deepfake must disclose that it was artificially generated or manipulated. The disclosure must be clear, distinguishable and accessible and provided no later than the first interaction or exposure, using a visible disclosure for visual content and an audible disclosure where audio is the relevant mode. Provider-side machine-readable marking under Article 50(2) is separate and cannot replace this deployer disclosure. Evidently artistic, creative, satirical, fictional or analogous works receive an adapted disclosure that must not hamper display or enjoyment.
“Internal” is not itself a universal Article 50 exemption or trigger. Apply the four routes to the actual facts: direct natural-person interaction under Article 50(1), synthetic-content marking by a provider under Article 50(2), exposure to emotion recognition or biometric categorisation under Article 50(3), and deployer publication of deepfakes or specified public-interest text under Article 50(4). Other employment, data-protection, sector and internal-governance requirements may apply separately.
Article 99(4)(g) places non-compliance with Article 50 in the administrative-fine tier of up to EUR 15 million or, for an undertaking, up to 3% of total worldwide annual turnover for the preceding financial year, if higher. A fine is not automatic. The applicable statutory factors, facts, proportionality rules, national procedure and due process govern any enforcement decision.
The Commission published the final Code of Practice on Transparency of AI-Generated Content on 10 June 2026. It is a voluntary implementation tool for Article 50(2), (4) and (5), and the Commission and AI Board assessed it as adequate. Adherence is not conclusive evidence of compliance. The Code does not replace the Act or the final Commission Guidelines published on 20 July 2026, and it is not a substitute for Article 50(1) or (3).
Check Article 5 before Article 50(3). Article 5 prohibits AI systems used to infer emotions in workplace and education-institution contexts, except for uses intended for medical or safety reasons. If a use is not prohibited, the Article 50(3) deployer notice and separate data-protection and sector-law requirements still need assessment. This guide does not determine a legal basis or make a scenario lawful.
No blanket Article 50 rule or exemption applies to every advertisement. Apply Article 50(2) to any provider-side synthetic-content marking duty. For the deployer, test separately whether image, audio or video content is a deepfake and whether generated or manipulated text is published to inform the public on a matter of public interest under Article 50(4), including its specific conditions. Advertising, consumer-protection and sector rules may apply separately.
Further reading
- Article 50 Code of Practice Analysis → — Implementation support for the voluntary Code.
- Article 5 Prohibited Practices → — The prohibition check that precedes Article 50(3).
Abhishek G Sharma
Founder & CEO, Move78 International Limited. 20+ years in cybersecurity and AI risk management. Certifications: ISO 42001 LA, ISO 27001 LA, CISA, CISM, CRISC, CEH, CCSK, CAIGO, CAIRO.
Need More Practical Guidance?
Explore the free EU AI Compass tools and guides to classify your use case, understand your obligations, and move to the next compliance step.
Disclaimer & educational purpose
This guide is published by Move78 International Limited for educational purposes only. It does not constitute legal advice. The EU AI Act (Regulation 2024/1689) is a complex legislative instrument with evolving guidance. The Article 50 Code of Practice was published by the European Commission on 10 June 2026 as voluntary implementation support. Article 50 obligations remain legal obligations where they apply, and the Commission published final Article 50 guidelines on 20 July 2026. Organisations should consult qualified legal counsel for Article 50 compliance decisions and should not treat this page as legal advice or certification.
Sources and legal basis
- Binding law — consolidated Regulation (EU) 2024/1689, version dated 27 July 2026
- Binding law — Regulation (EU) 2026/1744
- Non-binding guidance — Commission Article 50 Guidelines, published 20 July 2026
- Non-binding guidance — Commission Article 50 questions and answers
- Voluntary Code — Code of Practice on Transparency of AI-Generated Content, published 10 June 2026
- Official assessment — Commission opinion and AI Board adequacy assessment
- AI Act Service Desk — Article 99: Penalties
Source and review note: Last reviewed 3 September 2026 against Regulation (EU) 2024/1689 as consolidated on 27 July 2026, Regulation (EU) 2026/1744, the final Commission Article 50 Guidelines and Q&A, the final voluntary Code, and the Commission and AI Board adequacy assessments. The Act is binding law; the Guidelines are non-binding Commission guidance; the Code is voluntary. This guide supports operational triage and is not legal advice, certification or a compliance determination.