Four transparency obligations take effect on August 2, 2026: (1) AI chatbots must disclose they are AI, (2) synthetic content must be machine-readably marked, (3) emotion recognition systems must inform users, and (4) deepfakes must be labeled. Non-compliance carries fines up to €15 million or 3% of global turnover. The Omnibus amendment deferred high-risk deadlines, but Article 50 is not deferred.
The 4 Transparency Obligations Explained
Article 50 of Regulation (EU) 2024/1689 establishes four distinct transparency requirements. Each targets a specific type of AI system and assigns the obligation to either the provider (the entity that builds or places the system on the market) or the deployer (the entity that uses the system under its own authority).
Chatbot and Interactive AI Disclosure
Providers must design AI systems that directly interact with natural persons so that users are informed they are interacting with an AI system. This applies to customer service chatbots, AI assistants, voice-based AI agents, and any system where a person might reasonably believe they are communicating with another human.
The disclosure must be provided at the latest at the time of the first interaction, in a clear and distinguishable manner. It must be accessible to persons with disabilities.
Art. 50(1) — Obligation on: Provider
Exception: Disclosure is not required when it is obvious from the circumstances and context of use that the person is interacting with an AI system, as assessed from the perspective of a reasonably well-informed, observant, and circumspect natural person.
Synthetic Content Marking
Providers of AI systems that generate synthetic audio, image, video, or text content must ensure outputs are marked as artificially generated or manipulated in a machine-readable format. The marking must be effective, interoperable, robust, and reliable, as far as is technically feasible.
This applies to generative AI tools including large language models, image generators, voice synthesis tools, and video generation systems. The technical implementation should follow state-of-the-art approaches such as C2PA metadata, watermarking, or embedded provenance markers.
Art. 50(2) — Obligation on: Provider
Omnibus transition: AI systems already on the market before August 2, 2026 receive a grace period until December 2, 2026 for machine-readable marking compliance.
Emotion Recognition and Biometric Categorization
Deployers of emotion recognition systems or biometric categorization systems must inform the natural persons exposed to the system about its operation and must process personal data in accordance with the GDPR, the Law Enforcement Directive, and other applicable EU and national law.
Emotion recognition systems infer emotional states (joy, anger, stress, fear) from biometric data such as facial expressions, voice patterns, or physiological signals. Biometric categorization systems assign persons to specific categories based on biometric data.
Art. 50(3) — Obligation on: Deployer
Deepfake and Public Interest Text Labeling
Deployers who use AI to generate or manipulate image, audio, or video content that constitutes a deep fake must disclose that the content has been artificially generated or manipulated. When AI-generated text is published for the purpose of informing the public on matters of public interest, the deployer must disclose its artificial origin.
The disclosure must not hamper the display or enjoyment of the content for artistic, creative, satirical, fictional, or analogous works.
Art. 50(4) — Obligation on: Deployer
Provider vs Deployer: Who Must Do What
The AI Act distinguishes between providers and deployers. Understanding which role your organization occupies determines which Article 50 obligations apply to you.
A provider is any natural or legal person that develops an AI system or a general-purpose AI model, or that has an AI system or model developed, and places it on the market or puts it into service under its own name or trademark. A deployer is any natural or legal person that uses an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity.
| Obligation | Provider | Deployer | Practical Action |
|---|---|---|---|
| Art. 50(1) Chatbot Disclosure | Applies | N/A | Build disclosure into the AI system design. Inform users at first interaction. |
| Art. 50(2) Synthetic Content Marking | Applies | N/A | Implement machine-readable marking in outputs (C2PA, watermarks, metadata). |
| Art. 50(3) Emotion / Biometric | N/A | Applies | Inform exposed persons. Ensure GDPR compliance for all biometric data. |
| Art. 50(4) Deepfake Labeling | N/A | Applies | Label all deepfake content. Disclose AI origin for public interest text. |
Exemptions and Carve-outs
Article 50 includes targeted exemptions. These are narrower than many organizations assume. A careful reading reveals that most commercial uses of AI remain fully within scope.
- Artistic, creative, satirical, and fictional works. Art. 50(4) provides that deepfake disclosure for these works may be made in a way that does not hamper the display or enjoyment of the work. This is a reduced disclosure requirement, not a full exemption. Some form of labeling is still required.
- Human editorial control. Text that has been generated by AI but substantially reviewed and published under human editorial responsibility is exempt from Art. 50(2) machine-readable marking. The human editor must exercise genuine editorial control, not merely rubber-stamp the output.
- Law enforcement and national security. Certain biometric categorization systems operated by law enforcement may be subject to modified transparency requirements where full disclosure would compromise ongoing investigations. This exemption is tightly scoped and subject to judicial oversight.
- Obvious AI systems. Art. 50(1) chatbot disclosure is not required when it is obvious to a reasonably well-informed person that they are interacting with AI. A character in a video game, for instance, would not require a disclosure label. A customer service chat widget generally would.
- Personal, non-professional use. The deployer obligations in Art. 50(3) and 50(4) do not apply to AI systems used in the course of purely personal, non-professional activity.
Penalties for Non-Compliance
Non-compliance with Article 50 transparency obligations falls under the Tier 2 penalty framework established in Article 99 of the AI Act.
Maximum fine, or 3% of total worldwide annual turnover from the preceding financial year — whichever is higher.
For SMEs and startups, the lower of the two amounts applies. A company with €2M revenue faces a maximum of €60K (3%), not €15M.
Mitigating Factors
Article 99 identifies several mitigating factors that national authorities must consider when determining the appropriate fine:
- Documented compliance efforts. Evidence that the organization took reasonable steps toward compliance, even if the implementation was incomplete, can substantially reduce penalties.
- Proactive disclosure. Organizations that voluntarily reported non-compliance or brought it to the attention of the competent authority benefit from more favorable treatment.
- Cooperation with authorities. Full and timely cooperation during the investigation process is weighed in the organization's favor.
- Size and market share. The economic capacity of the organization, particularly for SMEs, is factored into penalty calculations to ensure proportionality.
- Nature and gravity of the infringement. A minor labeling gap on an internal tool is treated differently from systematic, deliberate concealment of AI-generated content in consumer-facing applications.
SME-Specific Provisions
The EU AI Act explicitly acknowledges that small and medium-sized enterprises face different compliance realities than large corporations. Several provisions address this directly.
Proportionality Principle
The Act applies a proportionality principle throughout. For Article 50, this means that the scale and cost of compliance measures should be proportionate to the organization's size, resources, and the nature and extent of its AI use. An SME deploying a single chatbot is not expected to implement the same compliance infrastructure as a multinational technology platform.
Compliance Cost Context
The European Commission's CEPS study estimated that a high-risk AI quality management system under Annex III could cost between €193,000 and €330,000. Article 50 obligations are significantly less burdensome. For most SMEs, compliance involves implementing disclosure labels, reviewing content marking processes, and documenting decisions — efforts that can be accomplished with internal resources and reasonable investment.
Documentation as Defense
The single most effective compliance strategy for an SME is documentation. Recording which AI systems are in use, what transparency measures have been implemented, and which decisions were made (and why) creates a demonstrable record of good faith effort. In enforcement proceedings, this record is the best available defense.
5-Step Compliance Checklist
These five steps provide a practical framework for preparing for the August 2, 2026 deadline. They apply to both providers and deployers.
Map all AI systems in your organization
Create a complete inventory of every AI system you develop, distribute, or use. Include chatbots, content generation tools, analytics systems with AI components, biometric tools, and any system that generates or manipulates images, audio, video, or text. This inventory is the foundation of everything that follows.
Classify each system against Article 50 categories
For each AI system in your inventory, determine which Article 50 category applies: interactive AI (50(1)), generative/synthetic content (50(2)), emotion recognition or biometric categorization (50(3)), or deepfake/public interest text (50(4)). Some systems may fall under multiple categories.
Implement disclosure mechanisms
For each classified system, implement the appropriate transparency measure: UI disclosure labels for chatbots, machine-readable metadata or watermarks for synthetic content, user notification for emotion/biometric systems, and content labels for deepfakes. Follow the Code of Practice guidelines where available.
Document compliance decisions and steps taken
Maintain a written record of all compliance decisions: which systems were classified under which categories, what transparency measures were implemented, which exemptions were relied upon (and why), and the timeline of implementation. This documentation serves as evidence of good faith in any enforcement proceeding.
Monitor Code of Practice updates and Commission guidelines
The European Commission and the AI Office are actively developing detailed guidance, including the Code of Practice on transparency. Subscribe to updates from the AI Office and review new guidance as it is published. Compliance is an ongoing process, not a one-time activity.
EU AI Act Implementation Timeline
The AI Act phases in over multiple deadlines. Understanding where Article 50 sits in the broader timeline helps contextualize what is required and when.
Frequently Asked Questions
Article 50 of the EU AI Act (Regulation 2024/1689) establishes transparency obligations for specific categories of AI systems. It requires that users be informed when they interact with AI, that AI-generated content be machine-readably marked, that emotion recognition and biometric systems disclose their operation, and that deepfakes be labeled. These are distinct from the high-risk obligations in Annex III and apply regardless of risk classification.
Article 50 transparency obligations take effect on August 2, 2026, exactly 24 months after the AI Act entered into force on August 1, 2024. However, the Omnibus amendment grants legacy systems an extension until December 2, 2026 specifically for the machine-readable marking requirement under Art. 50(2).
Yes, the EU AI Act has extraterritorial reach under Article 2. If the output of your AI system is used within the EU, or if you place an AI system on the EU market, Article 50 obligations apply regardless of where your company is headquartered. This includes providers and deployers established in third countries whose AI system output is used in the EU.
Article 50(1) applies to AI systems designed to directly interact with natural persons. This includes customer service chatbots, AI assistants, voice-based AI agents, and any interactive system where a person might reasonably believe they are communicating with a human. The obligation is on the provider to design the system so that users are informed they are interacting with AI, unless this is obvious from the circumstances and context of use.
Under Article 50(2), providers must mark AI-generated audio, image, video, and text outputs in a machine-readable format. The European Commission is developing harmonized standards and a Code of Practice on transparency. Current recommended approaches include C2PA metadata for images and video, watermarking techniques for audio, and structured metadata embedded in file headers. The marking must be effective, interoperable, robust, and reliable, as far as technically feasible.
Article 50(4) includes a limited exemption for artistic, creative, satirical, fictional, or analogous works. For deepfakes used in such contexts, the disclosure may be made in a way that does not hamper the display or enjoyment of the work, but some form of disclosure is still required. This is not a blanket exemption: content must genuinely constitute an artistic or creative work, and the disclosure obligation is reduced rather than removed entirely.
Non-compliance with Article 50 transparency obligations falls under the Tier 2 penalty framework: up to €15 million or 3% of the total worldwide annual turnover of the preceding financial year, whichever is higher. For SMEs and startups, the lower of the two amounts applies. Mitigating factors include documented compliance efforts, proactive disclosure, cooperation with authorities, and the size and market share of the organization.
The Omnibus amendment (agreed May 7, 2026) makes targeted adjustments. It defers the Annex III high-risk deadline from August 2, 2026 to December 2, 2027, but does not defer Article 50 itself. For Art. 50(2) specifically, legacy AI systems that were already on the market receive a transition period until December 2, 2026 for machine-readable marking compliance. The Omnibus also introduced new prohibited practices related to CSAM and non-consensual intimate AI imagery, effective December 2, 2026.
Article 50 references a Code of Practice that the European Commission is developing with industry stakeholders. This Code of Practice will provide detailed guidance on implementing transparency obligations, particularly for synthetic content marking under Art. 50(2). It will cover technical standards for watermarking, metadata formats, interoperability requirements, and best practices. Organizations should monitor developments through the AI Office for updates.
SMEs should take five practical steps: (1) Map all AI systems currently used in the organization, (2) Classify each system against Article 50 categories (interactive, generative, emotion/biometric, deepfake), (3) Implement disclosure mechanisms proportionate to the system type, (4) Document all compliance decisions and steps taken as evidence of good faith, (5) Monitor the Code of Practice and Commission guidelines for updates. The proportionality principle in the AI Act means SMEs are not expected to implement the same scale of compliance infrastructure as large enterprises. Documentation is the best defense in enforcement proceedings.
Is Your Organization Ready for August 2?
Take the free AI Act readiness assessment, or start recording your compliance efforts with AI Compliance OS.