The short answer: From 2 August 2026, four categories of AI systems must meet specific transparency obligations under Article 50 of the EU AI Act (Regulation 2024/1689).
(1) AI systems that interact with humans must disclose their AI nature. (2) AI systems that generate synthetic content must mark outputs in machine-readable format. (3) Emotion recognition and biometric categorisation systems must inform affected individuals. (4) Deepfake content must be disclosed as AI-generated.
Non-compliance: Up to €15,000,000 or 3% of worldwide annual turnover, whichever is higher. SMEs are capped at the lower amount.
In This Guide
- What Article 50 Requires
- Who Must Comply: Providers vs Deployers
- The Four Transparency Obligations Explained
- Five-Step Compliance Checklist
- Code of Practice on Transparency (June 2026)
- European Commission Draft Guidelines (May 2026)
- Omnibus Update: What Changed, What Didn't
- Penalties and Enforcement
- SME Proportionality Rules
- Comparison: Article 50 vs Article 13 vs GDPR
- Complete Enforcement Timeline
- Frequently Asked Questions (16)
- Pre-Compliance Checklist
1. What Article 50 Requires
Article 50 sits within Chapter IV of the EU AI Act, titled "Transparency Obligations for Providers and Deployers of Certain AI Systems." Unlike the high-risk requirements of Chapter III (which apply to a defined list of use cases), Article 50 applies based on what an AI system does, not where it is used. Any AI system that interacts with humans, generates synthetic content, recognises emotions, or creates deepfakes is in scope.
The obligations are not about full algorithmic transparency or explainability. They are about ensuring that people know when they are dealing with AI and when content has been artificially created or manipulated. The European Commission describes these as "limited risk" transparency requirements, sitting between the unregulated minimal-risk category and the heavily regulated high-risk category.
Key distinction: Article 50 transparency obligations are separate from Article 13 transparency obligations. Article 13 requires providers of high-risk AI systems to provide technical documentation and instructions for use to deployers. Article 50 requires disclosure to end users and affected individuals. Both may apply simultaneously to the same AI system.
2. Who Must Comply: Providers vs Deployers
Article 50 divides obligations between two roles defined in Article 3 of the AI Act.
| Role | Definition | Article 50 Obligations |
|---|---|---|
| Provider | The entity that develops an AI system and places it on the market or puts it into service under its own name or trademark | Art. 50(1): Design chatbots to inform users of AI interaction Art. 50(2): Mark synthetic content in machine-readable format |
| Deployer | The entity that uses an AI system under its authority in a professional context | Art. 50(3): Inform individuals about emotion recognition and biometric categorisation Art. 50(4): Disclose deepfake content |
An organisation can be both a provider and a deployer simultaneously. A company that develops its own AI chatbot and uses it for customer service is a provider (it designed the system) and a deployer (it uses the system). In this case, it must comply with both sets of obligations.
The obligations apply extraterritorially. If a provider outside the EU places an AI system on the EU market, or if the output of the system is used in the EU, Article 50 applies. US, UK, and Asian AI companies serving EU users must comply.
3. The Four Transparency Obligations Explained
AI-Human Interaction Disclosure (Article 50(1))
Who: Providers of AI systems intended to interact directly with natural persons.
What: Design and develop the system so that individuals are informed they are interacting with an AI system.
When: At the latest at the time of first interaction (Article 50(5)).
Exception: The obligation does not apply if the AI nature is obvious from the circumstances and context of use, from the point of view of a reasonably well-informed, observant, and circumspect person. It also does not apply to AI systems authorised by law for criminal offence detection, prevention, investigation, or prosecution.
Examples: Chatbots on websites, AI customer service agents, virtual assistants, AI-powered phone systems, conversational AI in apps.
Implementation: A clear notice such as "You are chatting with an AI assistant" displayed before or at the start of interaction. The notice must meet accessibility requirements (Article 50(5)).
Synthetic Content Marking (Article 50(2))
Who: Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video, or text content.
What: Ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated.
Technical requirements: Solutions must be effective, interoperable, robust, and reliable, as far as technically feasible, taking into account the state of the art.
Exception: Does not apply where the AI system performs an assistive function for standard editing or does not substantially alter the input data or its semantics. Also exempted for authorised law enforcement activities.
Code of Practice recommendation: Multi-layer approach combining C2PA cryptographically signed metadata and imperceptible watermarking (such as Google SynthID).
Transitional period: AI systems already on the market before 2 August 2026 have until 2 December 2026 to comply with this requirement (Omnibus amendment).
Emotion Recognition and Biometric Categorisation (Article 50(3))
Who: Deployers of emotion recognition systems or biometric categorisation systems.
What: Inform natural persons exposed to the system of its operation. Process personal data in accordance with GDPR (Regulation 2016/679), the EU Institutions Data Protection Regulation (2018/1725), and the Law Enforcement Data Protection Directive (2016/680).
Exception: Does not apply where the system is used for detecting, preventing, or investigating criminal offences as permitted by law, with appropriate safeguards.
Critical note: Emotion recognition in workplaces and educational institutions is entirely prohibited under Article 5(1)(f) since 2 February 2025, except for medical or safety purposes. This prohibition operates independently of Article 50.
Deepfake Disclosure (Article 50(4))
Who: Deployers of AI systems that generate or manipulate image, audio, or video content constituting a deepfake.
What: Disclose that the content has been artificially generated or manipulated.
Text obligation: Deployers who publish AI-generated text on matters of public interest must also disclose that the text was AI-generated or manipulated. However, this does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility.
Exception: Artistic, creative, satirical, fictional, or analogous works are subject to limited disclosure that does not hamper display or enjoyment. Authorised law enforcement activities are also exempt.
4. Five-Step Compliance Checklist
Inventory Your AI Systems
Map every AI system your organisation develops, deploys, or procures. For each system, determine: Does it interact with humans? Does it generate synthetic content (text, image, audio, video)? Does it perform emotion recognition or biometric categorisation? Could it be used to create deepfakes? Document each system and its Article 50 classification.
Implement Disclosure Notices
For every chatbot, virtual assistant, and conversational AI: add a clear, distinguishable disclosure at the time of first interaction. For emotion recognition and biometric systems: create a notice informing individuals that the system is in operation. Ensure all disclosures meet accessibility requirements (WCAG standards).
Deploy Content Marking
If your AI system generates synthetic audio, image, video, or text: implement machine-readable marking. The Code of Practice recommends C2PA metadata plus imperceptible watermarking as a minimum. Evaluate existing technical solutions (SynthID, C2PA, IPTC metadata). If your system was on the market before 2 August 2026, you have until 2 December 2026 for this step.
Establish Deepfake and Text Disclosure Procedures
Create workflows for disclosing AI-generated or manipulated media content. For AI-generated text published on public interest matters: implement editorial review processes and disclosure mechanisms. Document which content falls under the editorial control exception.
Document, Train, and Monitor
Maintain records of all transparency measures implemented. Train staff on their responsibilities. Establish a monitoring procedure to verify ongoing compliance. Prepare documentation for potential inspection by national competent market surveillance authorities.
5. Code of Practice on Transparency (June 2026)
On 10 June 2026, the European Commission published the final Code of Practice on Transparency of AI-Generated Content. This voluntary code helps providers demonstrate compliance with Article 50(2) marking requirements.
The Code mandates a multi-layer approach for marking AI-generated content:
| Layer | Technology | Purpose |
|---|---|---|
| Layer 1 | C2PA metadata | Cryptographically signed provenance information embedded in content. Interoperable, verifiable, and human-inspectable. |
| Layer 2 | Imperceptible watermarking | Invisible markers embedded in content (e.g., Google SynthID). Survives format conversion, compression, and basic editing. |
| Layer 3 | Visible labeling (recommended) | User-facing indicators such as icons, badges, or text labels identifying AI-generated content. |
Adherence to the Code creates a presumption of conformity with Article 50(2), meaning that if a regulatory authority questions your compliance, having followed the Code shifts the burden to them to prove non-compliance. However, the Code is voluntary, and alternative technical approaches are permitted provided they meet the effectiveness, interoperability, robustness, and reliability criteria.
6. European Commission Draft Guidelines (May 2026)
On 8 May 2026, the European Commission published draft guidelines on the implementation of transparency obligations under Article 50. A public consultation ran until 3 June 2026. The final guidelines are expected before the 2 August 2026 enforcement date.
Key clarifications from the draft guidelines:
- •The "obvious" exception (Art. 50(1)): The test is whether a "reasonably well-informed, observant and circumspect" person would recognise they are dealing with AI. A clearly labeled chatbot widget may qualify. A voice assistant that sounds human likely does not.
- •"Standard editing" exception (Art. 50(2)): AI features that assist with spelling, grammar, or formatting (without substantially altering content or semantics) are not subject to content marking requirements.
- •Editorial control exception (Art. 50(4)): AI-generated text that has undergone human review with editorial responsibility is exempt from the deployer disclosure obligation. However, the provider's content marking obligation under 50(2) still applies.
- •Accessibility: All disclosures must conform to applicable accessibility requirements, including for persons with disabilities. The guidelines reference the European Accessibility Act and WCAG standards.
7. Omnibus Update: What Changed, What Didn't
The Digital Omnibus agreement, signed on 7 July 2026, introduced targeted amendments to the EU AI Act. For Article 50 specifically:
| Provision | Original Deadline | After Omnibus | Change |
|---|---|---|---|
| Art. 50(1) AI-human interaction | 2 August 2026 | 2 August 2026 | No change |
| Art. 50(2) Synthetic content marking | 2 August 2026 | 2 August 2026 (new systems) 2 December 2026 (existing systems) | Grace period for systems already on market |
| Art. 50(3) Emotion recognition | 2 August 2026 | 2 August 2026 | No change |
| Art. 50(4) Deepfake disclosure | 2 August 2026 | 2 August 2026 | No change |
| Annex III High-risk (standalone) | 2 August 2026 | 2 December 2027 | Deferred 16 months |
| Annex I High-risk (products) | 2 August 2027 | 2 August 2028 | Deferred 12 months |
The 16-month deferral applies only to Annex III high-risk AI obligations, not to Article 50 transparency obligations. If your organisation uses chatbots, generates AI content, or deploys emotion recognition, you must comply from 2 August 2026 regardless of the Omnibus. The only transitional relief for Article 50 is the 4-month grace period for existing generative AI systems' content marking.
8. Penalties and Enforcement
Non-compliance with Article 50 falls under Tier 2 of the AI Act's three-tier penalty structure (Article 99):
| Penalty Tier | Applies To | Maximum Fine |
|---|---|---|
| Tier 1 | Prohibited practices (Art. 5) | €35,000,000 or 7% worldwide turnover |
| Tier 2 | Art. 50 transparency, high-risk obligations, GPAI | €15,000,000 or 3% worldwide turnover |
| Tier 3 | Incorrect information to authorities | €7,500,000 or 1% worldwide turnover |
Enforcement is primarily by national competent market surveillance authorities in each EU Member State. The European AI Office has direct enforcement powers over GPAI model providers from 2 August 2026. EU institutions, bodies, offices, and agencies face fines up to €750,000 from the European Data Protection Supervisor.
9. SME Proportionality Rules
The AI Act includes specific protections for small and medium-sized enterprises. Under Article 99, for SMEs (including startups), each fine is capped at the lower of the fixed amount or the percentage of turnover, rather than the higher. This means:
| Organisation Size | Art. 50 Maximum Fine Calculation |
|---|---|
| Large enterprise (turnover >€500M) | 3% of turnover = €15M+ (the higher amount applies) |
| Mid-size (turnover €100M) | 3% of turnover = €3M (the lower of €3M and €15M) |
| SME (turnover €10M) | 3% of turnover = €300,000 (the lower of €300K and €15M) |
| Startup (turnover €1M) | 3% of turnover = €30,000 (the lower of €30K and €15M) |
Additionally, Article 62 requires Member States to provide SMEs with prioritised access to AI regulatory sandboxes, and the European Commission must provide guidance and templates tailored to SME needs.
10. Comparison: Article 50 vs Article 13 vs GDPR
| Aspect | Article 50 (AI Act) | Article 13 (AI Act) | GDPR Art. 13-14, 22 |
|---|---|---|---|
| Scope | AI systems with specific functionalities (chatbots, generative AI, emotion recognition, deepfakes) | High-risk AI systems only | Any processing of personal data, including by AI |
| Who is informed | End users and affected individuals | Deployers (professional users of the system) | Data subjects whose personal data is processed |
| Type of transparency | Awareness transparency ("you are interacting with AI" / "this content is AI-generated") | Technical transparency (system capabilities, limitations, performance metrics) | Data processing transparency (what data, why, how long, your rights) |
| Applies from | 2 August 2026 | 2 December 2027 (Annex III) / 2 August 2028 (Annex I) | 25 May 2018 (already in force) |
| Maximum penalty | €15M or 3% turnover | €15M or 3% turnover | €20M or 4% turnover |
| Can overlap? | Yes. A high-risk AI chatbot processing personal data may be subject to all three simultaneously. | ||
11. Complete Enforcement Timeline
| Date | Milestone |
|---|---|
| 1 Aug 2024 | AI Act enters into force |
| 2 Feb 2025 | Prohibited AI practices (Art. 5) and AI Literacy (Art. 4) apply |
| 2 Aug 2025 | GPAI model obligations (Chapter V) apply |
| 8 May 2026 | Commission publishes draft Art. 50 guidelines |
| 10 Jun 2026 | Final Code of Practice on Transparency published |
| 7 Jul 2026 | Omnibus signed (Annex III deferred to Dec 2027) |
| 2 Aug 2026 | Article 50 transparency obligations apply. AI Office enforcement powers for GPAI in effect. Notification rules for high-risk AI apply. |
| 2 Dec 2026 | Transitional deadline for existing generative AI systems (Art. 50(2) content marking) |
| 2 Dec 2027 | Annex III standalone high-risk AI obligations apply (Omnibus revised) |
| 2 Aug 2028 | Annex I product-embedded high-risk AI obligations apply |
12. Frequently Asked Questions
13. Pre-Compliance Checklist
Use this checklist to verify your organisation's readiness for Article 50 enforcement on 2 August 2026:
- Completed AI system inventory identifying all systems subject to Article 50
- Classified each system by applicable sub-obligation (50(1), 50(2), 50(3), 50(4))
- Determined provider vs deployer role for each system
- Implemented chatbot and virtual assistant disclosure notices (Art. 50(1))
- Deployed machine-readable content marking for synthetic outputs (Art. 50(2)), or confirmed transitional period eligibility
- Reviewed C2PA and watermarking implementation options against Code of Practice
- Established deepfake disclosure procedures (Art. 50(4))
- Created editorial review process for AI-generated text on public interest matters
- Updated privacy notices for emotion recognition and biometric categorisation systems (Art. 50(3))
- Verified GDPR compliance for all systems processing personal data alongside Art. 50
- Trained relevant staff on their transparency responsibilities
- Documented all compliance measures for potential regulatory inspection
- Identified national competent authority for your primary EU Member State
- Confirmed accessibility compliance for all disclosures (WCAG, European Accessibility Act)
- Established monitoring and review schedule for ongoing compliance
Track Your AI Compliance
MmowW AI Compliance OS helps organisations manage EU AI Act obligations, including Article 50 transparency requirements. Record your compliance activities and build your Trust Profile.
Start freeOfficial Sources
Article 50 Full Text · Future of Life Institute AI Act Explorer
Guidelines on Transparency Obligations · European Commission (May 2026)
Code of Practice on Transparency of AI-Generated Content · European Commission (June 2026)
FAQ on Transparency Obligations · European Commission
Regulation (EU) 2024/1689 · Official Journal of the European Union