What Article 50 requires
Article 50 requires that people know when they are dealing with AI. It does that through four duties: disclose an AI interaction, mark synthetic output so machines can detect it, notify people exposed to emotion or biometric systems, and disclose deep fakes and AI-written public-interest text.
The provision is short, and that brevity is what makes it hard. It sets outcomes rather than methods, leaves its key qualifier “obvious” undefined, and splits the four duties across two different operator roles without saying so explicitly. Most compliance failures here are not failures of intent. They are a provider assuming the publisher will label the output, or a publisher assuming the model vendor already did.
| Paragraph | Duty | Owed by | Trigger |
|---|---|---|---|
| Article 50(1) | Interaction notice | Provider | Any AI system intended to interact directly with natural persons: customer support chatbots, voice agents, AI receptionists, conversational assistants embedded in products |
| Article 50(2) | Machine-readable mark | Provider | Generative systems producing audio, images, video or text, including general-purpose AI systems |
| Article 50(3) | Emotion / biometric notice | Deployer | Operating an emotion recognition or biometric categorisation system on identifiable people |
| Article 50(4) | Deep fake disclosure | Deployer | Publishing a deep fake, or publishing AI-written text intended to inform the public on a matter of public interest |
Two further paragraphs govern how all four are performed. Article 50(5) requires the information to be given clearly and distinguishably, at the latest at the time of the first interaction or exposure, and to conform to the applicable accessibility requirements. Article 50(6) confirms that none of this displaces the Chapter III high-risk requirements or any other transparency obligation in Union or national law.
Who owes which duty
Providers owe the interaction notice and the machine-readable marking duty. Deployers owe the emotion and biometric notice and the deep fake disclosure. One organization can be both, and then owes all four.
The split follows the logic of the Regulation as a whole: duties that require changing how a system is built sit with the provider, and duties that depend on how a system is used sit with the deployer. A model vendor cannot know whether its image generator will be used for a satirical cartoon or a fabricated political endorsement, so the disclosure duty for that output cannot sensibly sit with the vendor. Equally, a publisher cannot retrofit a durable watermark into content the model has already emitted, so the marking duty cannot sit with the publisher.
Each duty in detail
Each duty below sets out what triggers it, what satisfies it, and the carve-outs written into the paragraph itself.
Tell people they are dealing with an AI system
Providers must design AI systems that interact directly with people so that those people are informed they are interacting with an AI system, unless that fact is already obvious to a reasonably well-informed observer.
What satisfies it
- A disclosure shown at or before the first interaction, not buried in terms of service
- Wording a non-specialist understands: “You are chatting with an AI assistant”, not “powered by machine learning”
- Persistent labelling in voice channels, where there is no screen to carry a badge
- Meeting the accessibility requirements that Article 50(5) cross-applies
What triggers it
Any AI system intended to interact directly with natural persons: customer support chatbots, voice agents, AI receptionists, conversational assistants embedded in products.
Carve-outs in the paragraph
- Where it is obvious from the point of view of a reasonably well-informed, observant and circumspect person, taking the circumstances and context of use into account
- AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to safeguards for third-party rights
Mark synthetic output in a machine-readable format
Providers of AI systems that generate synthetic audio, image, video or text must mark the output in a machine-readable format and make it detectable as artificially generated or manipulated.
What satisfies it
- A marking technique that is effective, interoperable, robust and reliable as far as is technically feasible
- Accounting for the specificities and limitations of each content type: text is far harder to mark durably than images
- Proportionate implementation cost, and the generally acknowledged state of the art as reflected in relevant technical standards
What triggers it
Generative systems producing audio, images, video or text, including general-purpose AI systems. The duty sits with the provider of the generating system, not the person who later publishes the output.
Carve-outs in the paragraph
- Where the AI system performs an assistive function for standard editing
- Where the system does not substantially alter the input data supplied by the deployer, or its semantics
- Where use is authorised by law for criminal-offence detection, prevention, investigation or prosecution
Notify people exposed to emotion or biometric categorisation
Deployers of an emotion recognition system or a biometric categorisation system must inform the people exposed to it that it is operating, and process the personal data in line with the GDPR and the Law Enforcement Directive.
What satisfies it
- Notice to the exposed person, not only to the contracting customer
- A lawful basis and the full GDPR information duties, since biometric and emotion data are in play
- Records showing how notice was given, for market-surveillance requests
What triggers it
Operating an emotion recognition or biometric categorisation system on identifiable people. Note that emotion inference in the workplace and in education is separately prohibited outright by Article 5.
Carve-outs in the paragraph
- Systems permitted by law to detect, prevent or investigate criminal offences, subject to safeguards for third-party rights and in accordance with Union law
Disclose deep fakes and AI-written public-interest text
Deployers who generate or manipulate image, audio or video content constituting a deep fake must disclose that it is artificially generated, and deployers publishing AI-generated text to inform the public on matters of public interest must disclose that too.
What satisfies it
- A disclosure a reader or viewer actually sees, alongside the content
- For artistic, creative, satirical or fictional work: disclosure limited to noting that such content exists, in a way that does not spoil the work
- An editorial policy recording who decides when the duty bites
What triggers it
Publishing a deep fake, or publishing AI-written text intended to inform the public on a matter of public interest. This duty is on the publisher, and it is separate from the provider's marking duty under 50(2).
Carve-outs in the paragraph
- Use authorised by law to detect, prevent, investigate or prosecute criminal offences
- For text: where the content has been through human review or editorial control and a natural or legal person holds editorial responsibility for the publication
Marking synthetic content in practice
Article 50(2) sets an outcome, not a method: the mark must be machine-readable, and the output detectable as artificially generated or manipulated, using solutions that are effective, interoperable, robust and reliable as far as is technically feasible.
That wording does real work. “As far as is technically feasible” is a moving standard tied to the acknowledged state of the art as reflected in relevant technical standards, which means what was defensible in 2026 will not be defensible in 2029. It also means no single technique discharges the duty, because each of the three available approaches fails in a different way.
| Approach | Example | What it carries | How it fails |
|---|---|---|---|
| Signed provenance manifest | C2PA / Content Credentials | Who made it, with what tool, and what was edited since | Stripped by most re-encoding, screenshotting and social-platform upload pipelines |
| Embedded signal | Invisible pixel or audio watermarking; token-level text watermarks | A detectable “this is synthetic” signal inside the content itself | Needs a detector to read; weakest by far on short text, where it can be paraphrased away |
| File metadata | XMP, EXIF and container-level tags | A declarative flag on the file | Removed by almost any processing step, and trivially forged |
Why layering is the defensible position
A signed provenance manifest carries by far the richest information: the tool, the model, the edit history, cryptographically bound and verifiable. It is also the most fragile. Take a screenshot, or upload through a pipeline that re-encodes, and the manifest is gone. An embedded signal survives that handling much better but carries almost no information beyond “synthetic”, and it needs a detector, which means an ecosystem question rather than an engineering one. File metadata is trivial to write and trivial to strip.
Applying all three costs little more than applying one, and it is the combination that lets you argue you did what was technically feasible. Document that reasoning at the time. When a market surveillance authority asks why you chose a given approach, a contemporaneous note comparing the options is worth considerably more than a retrospective justification.
Where the marking duty stops
Article 50(2) does not apply where the AI system performs an assistive function for standard editing, or does not substantially alter the input data supplied by the deployer or its semantics. This is the carve-out that keeps ordinary tooling out of scope: autocorrect, denoise, color grading, a grammar suggestion. The test is substantial alteration of the data or its meaning, so the boundary is a question about your specific feature, not about your product category. Generative fill that invents new objects in a photograph is not standard editing, even though it lives in an editing tool.
When “obvious” removes the duty
The Article 50(1) disclosure duty falls away only where the AI nature of the interaction is obvious to a reasonably well-informed, observant and circumspect person, taking the circumstances and context of use into account.
This is an objective test measured against a notional careful user, not against your most sophisticated customer and not against your own team. Three features of the wording matter in practice.
- Context is part of the test. The same assistant may be obvious inside a developer console and non-obvious in a consumer messaging app, because the population interacting with it differs.
- Design choices can destroy the exemption. A human name, a photographic avatar, first-person phrasing and simulated typing latency all push an interface away from obvious. If you have invested in making a bot feel human, you have argued yourself out of the carve-out.
- Obviousness is not durable. Conversations get forwarded, embedded and resumed days later. A cue that was obvious at the start of a session may not be present at the point a decision is taken.
The practical answer is that the exemption is rarely worth relying on. A one-line disclosure at the top of a conversation is cheap; a dispute about whether your interface was obvious is not.
How it sits with other duties
Article 50 is additive. Article 50(6) states expressly that it does not affect the Chapter III high-risk requirements and is without prejudice to other transparency obligations in Union or national law.
| Regime | What it adds | Relationship to Article 50 |
|---|---|---|
| Chapter III high-risk | Article 13 transparency to deployers, plus risk management, data governance and logging | Cumulative. A high-risk chatbot owes Article 13 to its deployer and Article 50(1) to end users. |
| GPAI obligations | Article 53 documentation, copyright policy and training-content summary | Cumulative. Article 50(2) expressly covers generative general-purpose AI systems. |
| Article 5 prohibitions | Outright bans, including emotion inference at work and in education | Prior. If a practice is banned, no amount of disclosure makes it lawful. |
| GDPR | Lawful basis, information duties, data subject rights | Parallel. Article 50(3) explicitly points back to the GDPR for the personal data processing. |
An implementation checklist
Work role by role. Establish whether you are provider, deployer or both for each system, then discharge only the duties that attach to that role.
| Step | If you are a provider | If you are a deployer |
|---|---|---|
| 1. Scope | List every system that interacts with people or generates audio, image, video or text | List every system you operate that infers emotion or biometric categories, and every channel where you publish AI output |
| 2. Decide | For each generative system, choose and record a marking approach and the reasoning behind it | For each publishing channel, decide who determines when the deep fake or public-interest text duty bites |
| 3. Build | Ship the interaction notice and the machine-readable marking; verify the mark survives your own export paths | Ship the exposure notice and the visible disclosure; make sure it travels with syndicated content |
| 4. Contract | Warrant your marking behaviour to downstream customers | Require marking warranties from vendors, and test rather than trust them |
| 5. Evidence | Keep the state-of-the-art assessment that justifies your technique | Keep records showing notice was actually given, for market-surveillance requests |
Frequently asked questions
- When did Article 50 of the EU AI Act start to apply?
- 2 August 2026. Article 50 was part of the general application date and was not affected by the 2026 amendments that extended the high-risk deadlines. The transparency obligations are in force now.
- Does Article 50 require a visible label on AI-generated images?
- Not from the provider. Article 50(2) requires the provider of the generating system to mark output in a machine-readable format so it is detectable as artificially generated: a machine-readable mark, not necessarily a visible one. The separate visible-disclosure duty falls on the deployer under Article 50(4), and only where the content is a deep fake or is AI-generated text published to inform the public on a matter of public interest.
- Does the EU AI Act require C2PA or Content Credentials?
- No. Article 50 names no standard and mandates no specific technique. It requires marking solutions that are effective, interoperable, robust and reliable as far as is technically feasible, judged against the generally acknowledged state of the art as reflected in relevant technical standards. C2PA is one way to meet that; it is not a legal requirement, and on its own it is unlikely to be sufficient because provenance manifests are stripped by most re-encoding and upload pipelines.
- Do I have to disclose that my customer support chatbot is AI?
- Yes, unless it is obvious. Article 50(1) requires providers to design systems that interact directly with people so those people are informed they are interacting with an AI system, unless that is obvious from the point of view of a reasonably well-informed, observant and circumspect person taking the context of use into account. A bot named after a person, using a human avatar and writing in the first person is not obvious.
- Who is responsible when I use someone else's model in my product?
- Both of you, for different things. The provider of the generating system owes the Article 50(2) machine-readable marking duty. If you put that system to use under your own name, you may also be a provider in your own right under Article 25. And when you publish the output as a deep fake or as public-interest text, you owe the Article 50(4) disclosure duty as deployer. Contract for the marking; do not assume you inherit it.
- Does Article 50 apply to AI-generated text on my blog?
- Only in a narrow case. Article 50(4) covers AI-generated or manipulated text published for the purpose of informing the public on matters of public interest. It does not apply where the text has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. Ordinary marketing copy is not caught; an unreviewed AI-written news item is.
- What are the penalties for breaching Article 50?
- Up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. Article 50 breaches sit in the middle penalty tier under Article 99, not the €35 million tier reserved for the Article 5 prohibitions.
- Are satire and art exempt from the deep fake disclosure duty?
- Partially. Where a deep fake forms part of an evidently artistic, creative, satirical or fictional work or program, the Article 50(4) duty is limited to disclosing the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work. The duty is narrowed, not removed.
Sources and verification
Every date and provision cited here was checked against the consolidated text on 11 August 2026. The EU AI Act is being amended as it is implemented; where this page and EUR-Lex disagree, EUR-Lex governs.
- Regulation (EU) 2024/1689: consolidated text on EUR-Lex (controlling source)
- Regulation (EU) 2026/1744: Digital Omnibus on AI, amending the AI Act (in force 27 July 2026)
- Article 50: Transparency obligations for certain AI systems
- Article 25: Responsibilities along the AI value chain
- Article 99: Penalties
- European Commission: transparency obligations under Article 50 (FAQ)
- C2PA: Coalition for Content Provenance and Authenticity
This page is an independent information resource. It is not legal advice, and it does not create a lawyer–client relationship. Take advice on your own facts before making a compliance decision.
Next: see how Article 50 fits the wider schedule in every EU AI Act compliance deadline, or read the provision itself at Article 50.