Article 50 splits four duties across two roles. One organisation can be both provider and deployer of the same system, and then owes all four.
4Distinct duties in Article 50
2Fall on providers, two on deployers
€15mPenalty ceiling, or 3% of turnover
0Marking standards named in the text

What Article 50 requires

Article 50 requires that people know when they are dealing with AI. It does that through four duties: disclose an AI interaction, mark synthetic output so machines can detect it, notify people exposed to emotion or biometric systems, and disclose deep fakes and AI-written public-interest text.

The provision is short, and that brevity is what makes it hard. It sets outcomes rather than methods, leaves its key qualifier “obvious” undefined, and splits the four duties across two different operator roles without saying so explicitly. Most compliance failures here are not failures of intent. They are a provider assuming the publisher will label the output, or a publisher assuming the model vendor already did.

The four transparency duties in Article 50
ParagraphDutyOwed byTrigger
Article 50(1)Interaction noticeProviderAny AI system intended to interact directly with natural persons: customer support chatbots, voice agents, AI receptionists, conversational assistants embedded in products
Article 50(2)Machine-readable markProviderGenerative systems producing audio, images, video or text, including general-purpose AI systems
Article 50(3)Emotion / biometric noticeDeployerOperating an emotion recognition or biometric categorisation system on identifiable people
Article 50(4)Deep fake disclosureDeployerPublishing a deep fake, or publishing AI-written text intended to inform the public on a matter of public interest

Two further paragraphs govern how all four are performed. Article 50(5) requires the information to be given clearly and distinguishably, at the latest at the time of the first interaction or exposure, and to conform to the applicable accessibility requirements. Article 50(6) confirms that none of this displaces the Chapter III high-risk requirements or any other transparency obligation in Union or national law.

Who owes which duty

Providers owe the interaction notice and the machine-readable marking duty. Deployers owe the emotion and biometric notice and the deep fake disclosure. One organization can be both, and then owes all four.

The split follows the logic of the Regulation as a whole: duties that require changing how a system is built sit with the provider, and duties that depend on how a system is used sit with the deployer. A model vendor cannot know whether its image generator will be used for a satirical cartoon or a fabricated political endorsement, so the disclosure duty for that output cannot sensibly sit with the vendor. Equally, a publisher cannot retrofit a durable watermark into content the model has already emitted, so the marking duty cannot sit with the publisher.

Each duty in detail

Each duty below sets out what triggers it, what satisfies it, and the carve-outs written into the paragraph itself.

Article 50(1)Provider duty

Tell people they are dealing with an AI system

Providers must design AI systems that interact directly with people so that those people are informed they are interacting with an AI system, unless that fact is already obvious to a reasonably well-informed observer.

What satisfies it

  • A disclosure shown at or before the first interaction, not buried in terms of service
  • Wording a non-specialist understands: “You are chatting with an AI assistant”, not “powered by machine learning”
  • Persistent labelling in voice channels, where there is no screen to carry a badge
  • Meeting the accessibility requirements that Article 50(5) cross-applies

What triggers it

Any AI system intended to interact directly with natural persons: customer support chatbots, voice agents, AI receptionists, conversational assistants embedded in products.

Carve-outs in the paragraph

  • Where it is obvious from the point of view of a reasonably well-informed, observant and circumspect person, taking the circumstances and context of use into account
  • AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to safeguards for third-party rights
Article 50(2)Provider duty

Mark synthetic output in a machine-readable format

Providers of AI systems that generate synthetic audio, image, video or text must mark the output in a machine-readable format and make it detectable as artificially generated or manipulated.

What satisfies it

  • A marking technique that is effective, interoperable, robust and reliable as far as is technically feasible
  • Accounting for the specificities and limitations of each content type: text is far harder to mark durably than images
  • Proportionate implementation cost, and the generally acknowledged state of the art as reflected in relevant technical standards

What triggers it

Generative systems producing audio, images, video or text, including general-purpose AI systems. The duty sits with the provider of the generating system, not the person who later publishes the output.

Carve-outs in the paragraph

  • Where the AI system performs an assistive function for standard editing
  • Where the system does not substantially alter the input data supplied by the deployer, or its semantics
  • Where use is authorised by law for criminal-offence detection, prevention, investigation or prosecution
Article 50(3)Deployer duty

Notify people exposed to emotion or biometric categorisation

Deployers of an emotion recognition system or a biometric categorisation system must inform the people exposed to it that it is operating, and process the personal data in line with the GDPR and the Law Enforcement Directive.

What satisfies it

  • Notice to the exposed person, not only to the contracting customer
  • A lawful basis and the full GDPR information duties, since biometric and emotion data are in play
  • Records showing how notice was given, for market-surveillance requests

What triggers it

Operating an emotion recognition or biometric categorisation system on identifiable people. Note that emotion inference in the workplace and in education is separately prohibited outright by Article 5.

Carve-outs in the paragraph

  • Systems permitted by law to detect, prevent or investigate criminal offences, subject to safeguards for third-party rights and in accordance with Union law
Article 50(4)Deployer duty

Disclose deep fakes and AI-written public-interest text

Deployers who generate or manipulate image, audio or video content constituting a deep fake must disclose that it is artificially generated, and deployers publishing AI-generated text to inform the public on matters of public interest must disclose that too.

What satisfies it

  • A disclosure a reader or viewer actually sees, alongside the content
  • For artistic, creative, satirical or fictional work: disclosure limited to noting that such content exists, in a way that does not spoil the work
  • An editorial policy recording who decides when the duty bites

What triggers it

Publishing a deep fake, or publishing AI-written text intended to inform the public on a matter of public interest. This duty is on the publisher, and it is separate from the provider's marking duty under 50(2).

Carve-outs in the paragraph

  • Use authorised by law to detect, prevent, investigate or prosecute criminal offences
  • For text: where the content has been through human review or editorial control and a natural or legal person holds editorial responsibility for the publication

Marking synthetic content in practice

Article 50(2) sets an outcome, not a method: the mark must be machine-readable, and the output detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust and reliable as far as is technically feasible.

That wording does real work. “As far as is technically feasible” is a moving standard tied to the acknowledged state of the art as reflected in relevant technical standards, which means what was defensible in 2026 will not be defensible in 2029. It also means no single technique discharges the duty, because each of the three available approaches fails in a different way.

Durability of three synthetic-content marking techniquesEmbedded signals such as invisible watermarks survive ordinary content handling best. Signed provenance manifests such as C2PA Content Credentials carry the richest information but are stripped by most re-encoding and upload pipelines. File metadata is the easiest to apply and the easiest to lose.SURVIVES ORDINARY CONTENT HANDLING: RE-ENCODING, SCREENSHOTS, PLATFORM UPLOADSigned provenance manifestC2PA / Content CredentialsStripped by most re-encoding, screenshotting and social-platform upload pipelinesEmbedded signalInvisible pixel or audio watermarking; token-level text watermarksNeeds a detector to read; weakest by far on short text, where it can be paraphrased awayFile metadataXMP, EXIF and container-level tagsRemoved by almost any processing step, and trivially forged
Relative durability of the three marking approaches. These are editorial judgements of how each technique behaves in ordinary content handling, not measured benchmarks, and the Regulation mandates none of them by name.
Marking approaches, what each carries, and how each fails
ApproachExampleWhat it carriesHow it fails
Signed provenance manifestC2PA / Content CredentialsWho made it, with what tool, and what was edited sinceStripped by most re-encoding, screenshotting and social-platform upload pipelines
Embedded signalInvisible pixel or audio watermarking; token-level text watermarksA detectable “this is synthetic” signal inside the content itselfNeeds a detector to read; weakest by far on short text, where it can be paraphrased away
File metadataXMP, EXIF and container-level tagsA declarative flag on the fileRemoved by almost any processing step, and trivially forged

Why layering is the defensible position

A signed provenance manifest carries by far the richest information: the tool, the model, the edit history, cryptographically bound and verifiable. It is also the most fragile. Take a screenshot, or upload through a pipeline that re-encodes, and the manifest is gone. An embedded signal survives that handling much better but carries almost no information beyond “synthetic”, and it needs a detector, which means an ecosystem question rather than an engineering one. File metadata is trivial to write and trivial to strip.

Applying all three costs little more than applying one, and it is the combination that lets you argue you did what was technically feasible. Document that reasoning at the time. When a market surveillance authority asks why you chose a given approach, a contemporaneous note comparing the options is worth considerably more than a retrospective justification.

Where the marking duty stops

Article 50(2) does not apply where the AI system performs an assistive function for standard editing, or does not substantially alter the input data supplied by the deployer or its semantics. This is the carve-out that keeps ordinary tooling out of scope: autocorrect, denoise, color grading, a grammar suggestion. The test is substantial alteration of the data or its meaning, so the boundary is a question about your specific feature, not about your product category. Generative fill that invents new objects in a photograph is not standard editing, even though it lives in an editing tool.

When “obvious” removes the duty

The Article 50(1) disclosure duty falls away only where the AI nature of the interaction is obvious to a reasonably well-informed, observant and circumspect person, taking the circumstances and context of use into account.

This is an objective test measured against a notional careful user, not against your most sophisticated customer and not against your own team. Three features of the wording matter in practice.

  • Context is part of the test. The same assistant may be obvious inside a developer console and non-obvious in a consumer messaging app, because the population interacting with it differs.
  • Design choices can destroy the exemption. A human name, a photographic avatar, first-person phrasing and simulated typing latency all push an interface away from obvious. If you have invested in making a bot feel human, you have argued yourself out of the carve-out.
  • Obviousness is not durable. Conversations get forwarded, embedded and resumed days later. A cue that was obvious at the start of a session may not be present at the point a decision is taken.

The practical answer is that the exemption is rarely worth relying on. A one-line disclosure at the top of a conversation is cheap; a dispute about whether your interface was obvious is not.

How it sits with other duties

Article 50 is additive. Article 50(6) states expressly that it does not affect the Chapter III high-risk requirements and is without prejudice to other transparency obligations in Union or national law.

Article 50 alongside neighboring obligations
RegimeWhat it addsRelationship to Article 50
Chapter III high-riskArticle 13 transparency to deployers, plus risk management, data governance and loggingCumulative. A high-risk chatbot owes Article 13 to its deployer and Article 50(1) to end users.
GPAI obligationsArticle 53 documentation, copyright policy and training-content summaryCumulative. Article 50(2) expressly covers generative general-purpose AI systems.
Article 5 prohibitionsOutright bans, including emotion inference at work and in educationPrior. If a practice is banned, no amount of disclosure makes it lawful.
GDPRLawful basis, information duties, data subject rightsParallel. Article 50(3) explicitly points back to the GDPR for the personal data processing.

An implementation checklist

Work role by role. Establish whether you are provider, deployer or both for each system, then discharge only the duties that attach to that role.

Article 50 implementation checklist by role
StepIf you are a providerIf you are a deployer
1. ScopeList every system that interacts with people or generates audio, image, video or textList every system you operate that infers emotion or biometric categories, and every channel where you publish AI output
2. DecideFor each generative system, choose and record a marking approach and the reasoning behind itFor each publishing channel, decide who determines when the deep fake or public-interest text duty bites
3. BuildShip the interaction notice and the machine-readable marking; verify the mark survives your own export pathsShip the exposure notice and the visible disclosure; make sure it travels with syndicated content
4. ContractWarrant your marking behaviour to downstream customersRequire marking warranties from vendors, and test rather than trust them
5. EvidenceKeep the state-of-the-art assessment that justifies your techniqueKeep records showing notice was actually given, for market-surveillance requests

Frequently asked questions

When did Article 50 of the EU AI Act start to apply?
2 August 2026. Article 50 was part of the general application date and was not affected by the 2026 amendments that extended the high-risk deadlines. The transparency obligations are in force now.
Does Article 50 require a visible label on AI-generated images?
Not from the provider. Article 50(2) requires the provider of the generating system to mark output in a machine-readable format so it is detectable as artificially generated: a machine-readable mark, not necessarily a visible one. The separate visible-disclosure duty falls on the deployer under Article 50(4), and only where the content is a deep fake or is AI-generated text published to inform the public on a matter of public interest.
Does the EU AI Act require C2PA or Content Credentials?
No. Article 50 names no standard and mandates no specific technique. It requires marking solutions that are effective, interoperable, robust and reliable as far as is technically feasible, judged against the generally acknowledged state of the art as reflected in relevant technical standards. C2PA is one way to meet that; it is not a legal requirement, and on its own it is unlikely to be sufficient because provenance manifests are stripped by most re-encoding and upload pipelines.
Do I have to disclose that my customer support chatbot is AI?
Yes, unless it is obvious. Article 50(1) requires providers to design systems that interact directly with people so those people are informed they are interacting with an AI system, unless that is obvious from the point of view of a reasonably well-informed, observant and circumspect person taking the context of use into account. A bot named after a person, using a human avatar and writing in the first person is not obvious.
Who is responsible when I use someone else's model in my product?
Both of you, for different things. The provider of the generating system owes the Article 50(2) machine-readable marking duty. If you put that system to use under your own name, you may also be a provider in your own right under Article 25. And when you publish the output as a deep fake or as public-interest text, you owe the Article 50(4) disclosure duty as deployer. Contract for the marking; do not assume you inherit it.
Does Article 50 apply to AI-generated text on my blog?
Only in a narrow case. Article 50(4) covers AI-generated or manipulated text published for the purpose of informing the public on matters of public interest. It does not apply where the text has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. Ordinary marketing copy is not caught; an unreviewed AI-written news item is.
What are the penalties for breaching Article 50?
Up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. Article 50 breaches sit in the middle penalty tier under Article 99, not the €35 million tier reserved for the Article 5 prohibitions.
Are satire and art exempt from the deep fake disclosure duty?
Partially. Where a deep fake forms part of an evidently artistic, creative, satirical or fictional work or program, the Article 50(4) duty is limited to disclosing the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work. The duty is narrowed, not removed.

Sources and verification

Every date and provision cited here was checked against the consolidated text on 11 August 2026. The EU AI Act is being amended as it is implemented; where this page and EUR-Lex disagree, EUR-Lex governs.

This page is an independent information resource. It is not legal advice, and it does not create a lawyer–client relationship. Take advice on your own facts before making a compliance decision.

Next: see how Article 50 fits the wider schedule in every EU AI Act compliance deadline, or read the provision itself at Article 50.