Skip to content
AIAC AI ASSURANCE COUNCIL

EU AI Act

Article 50 — Transparency obligations for providers and deployers of certain AI systems

Article 50 requires people to be told when they are dealing with AI: that they are interacting with a system, that content was artificially generated, that emotion recognition is running. It applies whatever the risk tier, it was not deferred by the Digital Omnibus, and it has been in application since 2 August 2026.

§ 1 — Who it binds

Who it binds — providers mark, deployers disclose

ProviderDeployer

No risk tier and no Annex. Four functional triggers: a system intended to interact directly with natural persons (50(1), provider); any system, including general-purpose, generating synthetic audio, image, video or text (50(2), provider); an emotion recognition or biometric categorisation system (50(3), deployer); and deep fakes, or AI-generated text published to inform the public on matters of public interest (50(4), deployer). The free and open-source exclusion does not apply here.

§ 2 — In practice

Four disclosure duties, and which one is yours

The most consequential fact about Article 50 in 2026 is that it is already in force. It sits in Chapter IV, and the Digital Omnibus deferred only Chapter III Sections 1 to 3 — so while the high-risk obligations moved to December 2027 and August 2028, the transparency duties did not move at all. Organisations that paused an AI Act programme on the strength of the extension paused a Chapter III programme. Article 50 was never in it and is enforceable now.

It also has no risk-tier gateway. There is no Annex to check and no classification to run: the triggers are functional. A system intended to interact directly with people, a system generating synthetic audio, image, video or text, an emotion recognition or biometric categorisation system, a deep fake. A perfectly ordinary customer-service chatbot that is high-risk under nothing at all still owes 50(1), and the open-source exemption elsewhere in the Act expressly does not reach here. That independence cuts both ways: a high-risk system carries these duties *and* the Chapter III ones, so a deployer working through Article 26 has not finished when it reaches the end of that list.

The distinction that decides most assessments is between 50(2) and 50(4), because they bind different parties and are discharged by different artefacts. Article 50(2) is a provider duty to mark outputs in a machine-readable format so they are detectable as artificially generated — provenance metadata, watermarking, cryptographic signing. It need not be perceptible to anyone. Article 50(4) is a deployer duty to disclose to human beings that content is artificial. A visible "made with AI" badge does not discharge 50(2); an embedded provenance manifest does not discharge 50(4). Organisations routinely ship one and report both. Establishing which of the two you owe starts from which role you occupy, which is the same question that decides everything else in the Regulation — see what AI assurance actually means.

The exceptions are narrower than their shorthand. The editing carve-out in 50(2) reaches assistive functions for *standard* editing and changes that do not substantially alter the input or its semantics — generative fill and voice cloning alter semantics, contrast adjustment does not. The artistic exception in 50(4) does not remove disclosure, it reduces it to disclosing the existence of generated content in a way that does not spoil the work. And the exception for edited text is conjunctive: there must be human review or editorial control and a person holding editorial responsibility.

§ 3 — What discharges it

Evidence that content marking is robust and machine-readable

The artefacts an assessor asks to see, and what makes each one sufficient rather than merely present.

  1. 01

    The disclosure itself, with its position and timing

    Article 50(5) requires the information at the latest at the time of first interaction or exposure, clearly and distinguishably, and conforming to accessibility requirements. A disclosure discoverable only in a policy page has already missed the moment the provision names.

  2. 02

    A recorded obviousness assessment for 50(1)

    The exemption applies where the AI nature is obvious to a reasonably well-informed, observant and circumspect person in context. That is a judgement someone has to have made and written down; relying on it silently leaves nothing to show.

  3. 03

    Evidence that machine-readable marking actually survives

    Provenance metadata is routinely stripped by resizing, re-encoding or upload to a third-party platform. The artefact is a test showing the marking is still detectable at the point content reaches an audience, not a statement that it was applied at generation.

  4. 04

    For edited text, both limbs of the exception

    A named person holding editorial responsibility, and evidence that human review actually occurred. The exception is conjunctive, so a newsroom with a sub-editor but no accountable person fails it, as does a named person who never reads the output.

§ 4 — Worked example

Worked example — two systems, two different duties

A retailer runs a support chatbot that says "Assistant" in the header and nothing else, and a marketing team that uses a generative tool to produce product imagery, publishing it with no label. The retailer is not a provider of either system, buys both off the shelf, and neither is high-risk under Annex I or Annex III.

Which of the two exposes the retailer, and to what?

Both do, and neither exposure depends on the high-risk regime. The chatbot engages Article 50(1): people must be informed they are interacting with an AI system unless that is obvious to a reasonably well-informed, observant and circumspect person in the context. "Assistant" is not obviously a machine — plenty of support desks label a human agent that way — so the question is genuinely arguable and the retailer has no record of having asked it. That obligation runs to the provider of the system, which is where the retailer’s procurement should have looked. The imagery is the retailer’s own exposure: as deployer it owes disclosure under 50(4) if the images constitute a deep fake, and the marking duty in 50(2) sits with the tool’s provider regardless. Both duties have been live since 2 August 2026, and both are fineable at €15 million or 3%. Fixing this is a labelling and procurement exercise, not a compliance programme — which is why leaving it undone is hard to explain.

§ 5 — What a weak answer looks like

A footer disclaimer offered as a transparency measure

A privacy notice doing the work of a disclosure. Organisations treat the AI Act’s transparency duties as a variation on data-protection information duties, and answer them with a paragraph in a policy nobody reads at the moment of interaction. The Act asks for something narrower and harder: a clear, distinguishable statement at first exposure, in the interface, meeting accessibility requirements. Compliance with it also establishes nothing about lawfulness — the Regulation says so expressly.

§ 6 — When it applies

From 2 August 2026, with one grace period to December

  1. 2 August 2026

    The general application date. Chapter IV was not deferred by the Digital Omnibus, which moved only Chapter III Sections 1 to 3 — so these duties are in force while the high-risk regime is not.

  2. 2 December 2026

    Article 50(2) only, for providers of generative systems placed on the market before 2 August 2026. A four-month transitional inserted by the Digital Omnibus. Systems placed on the market after that date owed the marking duty immediately.

§ 7 — Exposure

Exposure under Article 99(4)(g)

€15 million or 3% of worldwide annual turnover, whichever is higher

Article 99(4)(g), which names the transparency obligations of providers and deployers under Article 50 directly — the only paragraph of 99(4) covering both roles in one line. Article 99(6) gives SMEs the lower of the two figures and Article 99(6a) extends that to small mid-cap companies. Since the penalty architecture has applied since 2 August 2025, the ceiling was available from the day the obligation attached.

§ 8 — Elsewhere

The same requirement elsewhere

Where another instrument addresses the same obligation. These are correspondences, not comparisons — the Council does not rank one framework against another.

  • GDPR and data-protection law

    GDPR Articles 13 and 14 require the data subject to be told about automated decision-making and the logic involved. The trigger differs — personal data processing rather than any interaction or output — as does the addressee and the remedy.

A correspondence indicates that two instruments address the same underlying obligation. It is not a mapping endorsed by either body, not a statement that one satisfies the other, and not a judgement about which is more demanding.

§ 9 — Where this is assessed

Where this is assessed

Examined in 2 credentials, in the domains named on each card.

AIAC-EUCFCompliance

Certified AI Compliance Fundamentals — EU AI Act

General-purpose AI and transparency · 15% of the paper

The EU AI Act as enacted: the risk-tier structure, the roles the Act defines, the obligations attaching to each, and the timeline on which they apply.

Compliance
AIAC-AGTEEndorsement

Agentic AI Oversight Endorsement

End-user responsibility and multi-agent risk · 20% of the paper

For practitioners assuring systems that take actions rather than produce outputs. Authorisation boundaries, reversibility, and audit trails for software that acts.

Agentic systems

§ 10 — provenance

The provision itself

This page sets out what the instrument requires and what discharges it. The official text is the authority — these go straight to it.