Enforcement: 2 August 2026

EU AI Act Article 50: Complete Compliance Guide for Transparency Obligations

Everything your organisation needs to know and do before the enforcement date. Chatbot disclosure, deepfake labeling, synthetic content marking, and step-by-step compliance checklist.

Last updated: 2026-07-21 · Reviewed by Takayuki Sawai, Gyoseishoshi (行政書士)

The short answer: From 2 August 2026, four categories of AI systems must meet specific transparency obligations under Article 50 of the EU AI Act (Regulation 2024/1689).

(1) AI systems that interact with humans must disclose their AI nature. (2) AI systems that generate synthetic content must mark outputs in machine-readable format. (3) Emotion recognition and biometric categorisation systems must inform affected individuals. (4) Deepfake content must be disclosed as AI-generated.

Non-compliance: Up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher. SMEs are capped at the lower amount.

In This Guide

  1. What Article 50 Requires
  2. Who Must Comply: Providers vs Deployers
  3. The Four Transparency Obligations Explained
  4. Five-Step Compliance Checklist
  5. Code of Practice on Transparency (June 2026)
  6. European Commission Draft Guidelines (May 2026)
  7. Omnibus Update: What Changed, What Didn't
  8. Penalties and Enforcement
  9. SME Proportionality Rules
  10. Comparison: Article 50 vs Article 13 vs GDPR
  11. Complete Enforcement Timeline
  12. Frequently Asked Questions (16)
  13. Pre-Compliance Checklist

1. What Article 50 Requires

Article 50 sits within Chapter IV of the EU AI Act, titled "Transparency Obligations for Providers and Deployers of Certain AI Systems." Unlike the high-risk requirements of Chapter III (which apply to a defined list of use cases), Article 50 applies based on what an AI system does, not where it is used. Any AI system that interacts with humans, generates synthetic content, recognises emotions, or creates deepfakes is in scope.

The obligations are not about full algorithmic transparency or explainability. They are about ensuring that people know when they are dealing with AI and when content has been artificially created or manipulated. The European Commission describes these as "limited risk" transparency requirements, sitting between the unregulated minimal-risk category and the heavily regulated high-risk category.

Key distinction: Article 50 transparency obligations are separate from Article 13 transparency obligations. Article 13 requires providers of high-risk AI systems to provide technical documentation and instructions for use to deployers. Article 50 requires disclosure to end users and affected individuals. Both may apply simultaneously to the same AI system.

2. Who Must Comply: Providers vs Deployers

Article 50 divides obligations between two roles defined in Article 3 of the AI Act.

RoleDefinitionArticle 50 Obligations
ProviderThe entity that develops an AI system and places it on the market or puts it into service under its own name or trademarkArt. 50(1): Design chatbots to inform users of AI interaction
Art. 50(2): Mark synthetic content in machine-readable format
DeployerThe entity that uses an AI system under its authority in a professional contextArt. 50(3): Inform individuals about emotion recognition and biometric categorisation
Art. 50(4): Disclose deepfake content

An organisation can be both a provider and a deployer simultaneously. A company that develops its own AI chatbot and uses it for customer service is a provider (it designed the system) and a deployer (it uses the system). In this case, it must comply with both sets of obligations.

The obligations apply extraterritorially. If a provider outside the EU places an AI system on the EU market, or if the output of the system is used in the EU, Article 50 applies. US, UK, and Asian AI companies serving EU users must comply.

3. The Four Transparency Obligations Explained

1

AI-Human Interaction Disclosure (Article 50(1))

Who: Providers of AI systems intended to interact directly with natural persons.

What: Design and develop the system so that individuals are informed they are interacting with an AI system.

When: At the latest at the time of first interaction (Article 50(5)).

Exception: The obligation does not apply if the AI nature is obvious from the circumstances and context of use, from the point of view of a reasonably well-informed, observant, and circumspect person. It also does not apply to AI systems authorised by law for criminal offence detection, prevention, investigation, or prosecution.

Examples: Chatbots on websites, AI customer service agents, virtual assistants, AI-powered phone systems, conversational AI in apps.

Implementation: A clear notice such as "You are chatting with an AI assistant" displayed before or at the start of interaction. The notice must meet accessibility requirements (Article 50(5)).

2

Synthetic Content Marking (Article 50(2))

Who: Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video, or text content.

What: Ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated.

Technical requirements: Solutions must be effective, interoperable, robust, and reliable, as far as technically feasible, taking into account the state of the art.

Exception: Does not apply where the AI system performs an assistive function for standard editing or does not substantially alter the input data or its semantics. Also exempted for authorised law enforcement activities.

Code of Practice recommendation: Multi-layer approach combining C2PA cryptographically signed metadata and imperceptible watermarking (such as Google SynthID).

Transitional period: AI systems already on the market before 2 August 2026 have until 2 December 2026 to comply with this requirement (Omnibus amendment).

3

Emotion Recognition and Biometric Categorisation (Article 50(3))

Who: Deployers of emotion recognition systems or biometric categorisation systems.

What: Inform natural persons exposed to the system of its operation. Process personal data in accordance with GDPR (Regulation 2016/679), the EU Institutions Data Protection Regulation (2018/1725), and the Law Enforcement Data Protection Directive (2016/680).

Exception: Does not apply where the system is used for detecting, preventing, or investigating criminal offences as permitted by law, with appropriate safeguards.

Critical note: Emotion recognition in workplaces and educational institutions is entirely prohibited under Article 5(1)(f) since 2 February 2025, except for medical or safety purposes. This prohibition operates independently of Article 50.

4

Deepfake Disclosure (Article 50(4))

Who: Deployers of AI systems that generate or manipulate image, audio, or video content constituting a deepfake.

What: Disclose that the content has been artificially generated or manipulated.

Text obligation: Deployers who publish AI-generated text on matters of public interest must also disclose that the text was AI-generated or manipulated. However, this does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility.

Exception: Artistic, creative, satirical, fictional, or analogous works are subject to limited disclosure that does not hamper display or enjoyment. Authorised law enforcement activities are also exempt.

4. Five-Step Compliance Checklist

1

Inventory Your AI Systems

Map every AI system your organisation develops, deploys, or procures. For each system, determine: Does it interact with humans? Does it generate synthetic content (text, image, audio, video)? Does it perform emotion recognition or biometric categorisation? Could it be used to create deepfakes? Document each system and its Article 50 classification.

2

Implement Disclosure Notices

For every chatbot, virtual assistant, and conversational AI: add a clear, distinguishable disclosure at the time of first interaction. For emotion recognition and biometric systems: create a notice informing individuals that the system is in operation. Ensure all disclosures meet accessibility requirements (WCAG standards).

3

Deploy Content Marking

If your AI system generates synthetic audio, image, video, or text: implement machine-readable marking. The Code of Practice recommends C2PA metadata plus imperceptible watermarking as a minimum. Evaluate existing technical solutions (SynthID, C2PA, IPTC metadata). If your system was on the market before 2 August 2026, you have until 2 December 2026 for this step.

4

Establish Deepfake and Text Disclosure Procedures

Create workflows for disclosing AI-generated or manipulated media content. For AI-generated text published on public interest matters: implement editorial review processes and disclosure mechanisms. Document which content falls under the editorial control exception.

5

Document, Train, and Monitor

Maintain records of all transparency measures implemented. Train staff on their responsibilities. Establish a monitoring procedure to verify ongoing compliance. Prepare documentation for potential inspection by national competent market surveillance authorities.

5. Code of Practice on Transparency (June 2026)

On 10 June 2026, the European Commission published the final Code of Practice on Transparency of AI-Generated Content. This voluntary code helps providers demonstrate compliance with Article 50(2) marking requirements.

The Code mandates a multi-layer approach for marking AI-generated content:

LayerTechnologyPurpose
Layer 1C2PA metadataCryptographically signed provenance information embedded in content. Interoperable, verifiable, and human-inspectable.
Layer 2Imperceptible watermarkingInvisible markers embedded in content (e.g., Google SynthID). Survives format conversion, compression, and basic editing.
Layer 3Visible labeling (recommended)User-facing indicators such as icons, badges, or text labels identifying AI-generated content.

Adherence to the Code creates a presumption of conformity with Article 50(2), meaning that if a regulatory authority questions your compliance, having followed the Code shifts the burden to them to prove non-compliance. However, the Code is voluntary, and alternative technical approaches are permitted provided they meet the effectiveness, interoperability, robustness, and reliability criteria.

6. European Commission Draft Guidelines (May 2026)

On 8 May 2026, the European Commission published draft guidelines on the implementation of transparency obligations under Article 50. A public consultation ran until 3 June 2026. The final guidelines are expected before the 2 August 2026 enforcement date.

Key clarifications from the draft guidelines:

7. Omnibus Update: What Changed, What Didn't

The Digital Omnibus agreement, signed on 7 July 2026, introduced targeted amendments to the EU AI Act. For Article 50 specifically:

ProvisionOriginal DeadlineAfter OmnibusChange
Art. 50(1) AI-human interaction2 August 20262 August 2026No change
Art. 50(2) Synthetic content marking2 August 20262 August 2026 (new systems)
2 December 2026 (existing systems)
Grace period for systems already on market
Art. 50(3) Emotion recognition2 August 20262 August 2026No change
Art. 50(4) Deepfake disclosure2 August 20262 August 2026No change
Annex III High-risk (standalone)2 August 20262 December 2027Deferred 16 months
Annex I High-risk (products)2 August 20272 August 2028Deferred 12 months
Do not confuse the Omnibus deferrals

The 16-month deferral applies only to Annex III high-risk AI obligations, not to Article 50 transparency obligations. If your organisation uses chatbots, generates AI content, or deploys emotion recognition, you must comply from 2 August 2026 regardless of the Omnibus. The only transitional relief for Article 50 is the 4-month grace period for existing generative AI systems' content marking.

8. Penalties and Enforcement

Non-compliance with Article 50 falls under Tier 2 of the AI Act's three-tier penalty structure (Article 99):

Penalty TierApplies ToMaximum Fine
Tier 1Prohibited practices (Art. 5)€35,000,000 or 7% worldwide turnover
Tier 2Art. 50 transparency, high-risk obligations, GPAI€15,000,000 or 3% worldwide turnover
Tier 3Incorrect information to authorities€7,500,000 or 1% worldwide turnover

Enforcement is primarily by national competent market surveillance authorities in each EU Member State. The European AI Office has direct enforcement powers over GPAI model providers from 2 August 2026. EU institutions, bodies, offices, and agencies face fines up to €750,000 from the European Data Protection Supervisor.

9. SME Proportionality Rules

The AI Act includes specific protections for small and medium-sized enterprises. Under Article 99, for SMEs (including startups), each fine is capped at the lower of the fixed amount or the percentage of turnover, rather than the higher. This means:

Organisation SizeArt. 50 Maximum Fine Calculation
Large enterprise (turnover >€500M)3% of turnover = €15M+ (the higher amount applies)
Mid-size (turnover €100M)3% of turnover = €3M (the lower of €3M and €15M)
SME (turnover €10M)3% of turnover = €300,000 (the lower of €300K and €15M)
Startup (turnover €1M)3% of turnover = €30,000 (the lower of €30K and €15M)

Additionally, Article 62 requires Member States to provide SMEs with prioritised access to AI regulatory sandboxes, and the European Commission must provide guidance and templates tailored to SME needs.

10. Comparison: Article 50 vs Article 13 vs GDPR

AspectArticle 50 (AI Act)Article 13 (AI Act)GDPR Art. 13-14, 22
ScopeAI systems with specific functionalities (chatbots, generative AI, emotion recognition, deepfakes)High-risk AI systems onlyAny processing of personal data, including by AI
Who is informedEnd users and affected individualsDeployers (professional users of the system)Data subjects whose personal data is processed
Type of transparencyAwareness transparency ("you are interacting with AI" / "this content is AI-generated")Technical transparency (system capabilities, limitations, performance metrics)Data processing transparency (what data, why, how long, your rights)
Applies from2 August 20262 December 2027 (Annex III) / 2 August 2028 (Annex I)25 May 2018 (already in force)
Maximum penalty€15M or 3% turnover€15M or 3% turnover€20M or 4% turnover
Can overlap?Yes. A high-risk AI chatbot processing personal data may be subject to all three simultaneously.

11. Complete Enforcement Timeline

DateMilestone
1 Aug 2024AI Act enters into force
2 Feb 2025Prohibited AI practices (Art. 5) and AI Literacy (Art. 4) apply
2 Aug 2025GPAI model obligations (Chapter V) apply
8 May 2026Commission publishes draft Art. 50 guidelines
10 Jun 2026Final Code of Practice on Transparency published
7 Jul 2026Omnibus signed (Annex III deferred to Dec 2027)
2 Aug 2026Article 50 transparency obligations apply. AI Office enforcement powers for GPAI in effect. Notification rules for high-risk AI apply.
2 Dec 2026Transitional deadline for existing generative AI systems (Art. 50(2) content marking)
2 Dec 2027Annex III standalone high-risk AI obligations apply (Omnibus revised)
2 Aug 2028Annex I product-embedded high-risk AI obligations apply

12. Frequently Asked Questions

Article 50 transparency obligations apply from 2 August 2026. However, the Omnibus amendment grants providers of generative AI systems already on the EU market before that date a transitional period until 2 December 2026 to comply with the synthetic content marking requirement under Article 50(2). Systems placed on the market from 2 August 2026 onwards must comply immediately.

Both providers (developers) and deployers (business users) of AI systems have obligations under Article 50, but different ones. Providers must design systems to inform users of AI interaction and mark synthetic content in machine-readable format. Deployers must inform individuals about emotion recognition, biometric categorisation, and deepfake content. The obligations apply regardless of whether the provider is established in the EU, as long as the AI system is used in the EU.

Any AI system intended to interact directly with natural persons. This includes chatbots, virtual assistants, AI-powered customer service tools, AI agents, and conversational AI. The obligation does not apply if the AI nature is obvious from the circumstances, for example a clearly labeled chatbot widget on a website. The European Commission Guidelines clarify that the test is whether a reasonably well-informed, observant, and circumspect person would recognise they are interacting with AI.

Providers of AI systems that generate synthetic audio, image, video, or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. This applies to generative AI tools including large language models, image generators, voice cloning tools, and video synthesis systems. The Code of Practice recommends a multi-layer approach combining C2PA metadata and imperceptible watermarking such as Google SynthID.

Yes, but with nuance. Providers must mark AI-generated text in machine-readable format (Article 50(2)). Deployers who publish AI-generated text on matters of public interest must disclose that the text was AI-generated (Article 50(4)). However, this deployer obligation does not apply if the content has undergone human review or editorial control and a person holds editorial responsibility for the publication.

Deployers of AI systems that generate or manipulate image, audio, or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated. Exceptions exist for content that is part of an evidently artistic, creative, satirical, fictional, or analogous work, and for authorised law enforcement activities. The disclosure must not hamper the display or enjoyment of the work.

Deployers of emotion recognition systems or biometric categorisation systems must inform the natural persons exposed to them of the system's operation. They must also process personal data in accordance with GDPR (Regulation 2016/679). Note that emotion recognition AI is entirely prohibited in workplaces and educational institutions under Article 5(1)(f), except for medical or safety purposes.

Non-compliance with Article 50 transparency obligations can result in administrative fines of up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher. For SMEs and startups, the fine is capped at the lower of the two amounts (not the higher), providing relative protection for smaller operators. EU institutions face fines up to €750,000.

The Digital Omnibus agreement (signed 7 July 2026) deferred Annex III high-risk AI obligations by 16 months to 2 December 2027, and Annex I obligations to 2 August 2028. However, Article 50 transparency obligations remain on their original schedule of 2 August 2026. The only relief is a transitional period until 2 December 2026 for providers of generative AI systems already on the market before 2 August 2026 to comply with the content marking requirement.

On 10 June 2026, the European Commission published the final Code of Practice on Transparency of AI-Generated Content. It provides technical guidance for complying with Article 50(2) marking requirements. The Code mandates a multi-layer approach: at minimum, a combination of C2PA cryptographically signed metadata and imperceptible watermarking deployed simultaneously. Adherence creates a presumption of conformity but is voluntary.

Generally yes. While the AI Act provides certain exemptions for free and open-source AI models, the transparency obligations under Article 50 apply broadly. If an open-source model generates synthetic content, its provider must ensure outputs can be marked and detected as AI-generated. The key factor is whether the model is placed on the EU market or its outputs are used in the EU.

The European Commission Guidelines recommend clear and distinguishable disclosure at the latest at the time of first interaction. Practical implementations include a notice before conversation begins (e.g., 'You are chatting with an AI assistant'), a persistent label visible during interaction, and accessible formatting that meets WCAG standards. The disclosure must be proactive, not buried in terms of service.

While Article 50 does not prescribe specific record-keeping, the Commission Guidelines and Code of Practice recommend maintaining: an inventory of AI systems subject to transparency obligations, documentation of disclosure mechanisms implemented, evidence of machine-readable marking for synthetic content, training records for staff handling AI-generated content, and incident logs for transparency failures.

Article 50 operates alongside GDPR, not as a replacement. GDPR Article 22 gives individuals rights regarding automated decision-making. GDPR Articles 13-14 require disclosure of automated processing. Article 50 adds AI-specific transparency requirements on top. For emotion recognition and biometric categorisation, deployers must comply with both Article 50 disclosure and GDPR data processing requirements simultaneously.

Yes, through extraterritorial application. If a provider outside the EU places an AI system on the EU market, or if the output of an AI system is used in the EU, Article 50 obligations apply. This means US, UK, and Asian AI companies serving EU users must comply with chatbot disclosure, content marking, and other transparency requirements.

With enforcement beginning 2 August 2026, organisations should immediately: (1) Complete an AI system inventory identifying all systems subject to Article 50, (2) Implement chatbot and virtual assistant disclosure notices, (3) Begin deploying content marking for synthetic outputs, (4) Establish deepfake disclosure procedures, (5) Review and update privacy notices for emotion recognition systems, (6) Train staff on transparency obligations, and (7) Document all compliance measures for potential regulatory inspection.

13. Pre-Compliance Checklist

Use this checklist to verify your organisation's readiness for Article 50 enforcement on 2 August 2026:

Track Your AI Compliance

MmowW AI Compliance OS helps organisations manage EU AI Act obligations, including Article 50 transparency requirements. Record your compliance activities and build your Trust Profile.

Start free

Official Sources

Article 50 Full Text · Future of Life Institute AI Act Explorer

Guidelines on Transparency Obligations · European Commission (May 2026)

Code of Practice on Transparency of AI-Generated Content · European Commission (June 2026)

FAQ on Transparency Obligations · European Commission

Regulation (EU) 2024/1689 · Official Journal of the European Union