Module 6 of the AI Act Deployer certification: Art. 50(3) and 50(4) as deployer duties in force since August 2026, Art. 26(11) information to affected persons, and the Art. 86 right to explanation.
Everything in the previous modules attaches to high-risk systems and mostly bites from December 2027. This module is different: most of it is in force now, and most of it applies whatever tier your system sits in.
If your organisation has an AI Act obligation today, it is probably in here.
The four Art. 50 duties, and who owes each
| Paragraph | Duty | Owed by |
|---|---|---|
| 50(1) | Tell people they are interacting with an AI system | Provider |
| 50(2) | Mark synthetic output in a machine-readable format | Provider |
| 50(3) | Inform people exposed to emotion recognition or biometric categorisation | Deployer |
| 50(4) | Disclose deepfakes; disclose AI-generated text published on matters of public interest | Deployer |
Art. 50 has applied since 2 August 2026. It was not deferred by the Digital Omnibus. A transitional rule gives providers of generative systems already on the market before that date until 2 December 2026 to apply the machine-readable marking of Art. 50(2).
50(3) — emotion recognition and biometric categorisation
Deployers of an emotion recognition system or a biometric categorisation system must inform the natural persons exposed to it of its operation, and process personal data in accordance with the data protection acquis.
Before you plan the notice, check whether the deployment is lawful at all. Art. 5(1)(f) prohibits AI to infer emotions of a natural person in the areas of workplace and education institutions, save where the system is intended for medical or safety reasons. That prohibition has applied since 2 February 2025 and sits in the highest fine band — Art. 99(3), 35 million euro or 7% of worldwide turnover.
So the sequence is: is this the workplace or an education institution? If yes, and the purpose is not medical or safety, it is prohibited and no notice cures it. If no — a retail analytics deployment, say — Art. 50(3) applies and you owe the information.
The same order applies to biometric categorisation: Art. 5 prohibits categorisation systems that categorise natural persons on the basis of biometric data to deduce or infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation. Outside those categories, Art. 50(3) governs.
50(4) — deepfakes and public-interest text
Two distinct duties in one paragraph.
Deepfakes. Deployers of an AI system that generates or manipulates image, audio or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated. There are exceptions: where use is authorised by law to detect, prevent, investigate or prosecute criminal offences, and — the one that matters commercially — where the content forms part of an evidently artistic, creative, satirical or fictional work, in which case the disclosure obligation is limited to disclosing the existence of such content in an appropriate manner that does not hamper the display or enjoyment of the work.
Text on matters of public interest. Deployers of an AI system that generates or manipulates text published with the purpose of informing the public on matters of public interest must disclose that the text was artificially generated or manipulated. The exceptions are where the use is authorised by law, or where the AI-generated content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication.
That editorial-control exception is the one most organisations will rely on, and it is worth reading precisely. It is not enough that a human glanced at the output. There must be a review or editorial control process, and an identified person or entity bearing editorial responsibility for the publication. If you rely on it, document who that is.
Note also the boundary of the duty: it concerns text published to inform the public on matters of public interest. Your AI-assisted product descriptions and internal reports are outside it. Your AI-assisted press releases and policy commentary are not obviously outside it.
Art. 50(5) adds that the information must be provided at the latest at the time of the first interaction or exposure, clearly and distinguishably, and in a way that conforms to accessibility requirements.
26(11) — telling the person they are subject to the system
Deployers of high-risk AI systems referred to in Annex III that make decisions or assist in making decisions related to natural persons shall inform the natural persons that they are subject to the use of the high-risk AI system.
This is separate from Art. 50 and narrower: it attaches to Annex III high-risk deployments, and it fires whether the system decides or merely assists in deciding. A human-in-the-loop arrangement does not switch it off — if anything, assisting is the normal case.
Where a system is used in the context of Art. 6(1) — AI as a safety component of a regulated product — the paragraph works differently, but for Annex III deployments the rule is straightforward: the person on the other side of the decision is told.
86 — the right to explanation
Art. 86 gives any affected person subject to a decision taken by the deployer on the basis of the output of a high-risk Annex III system, where that decision produces legal effects or similarly significantly affects them in a way they consider adversely impacts their health, safety or fundamental rights, the right to obtain from the deployer clear and meaningful explanations of the role of the AI system in the decision-making procedure and the main elements of the decision taken.
Four points that decide how you implement it.
It is exercised, not published. Unlike Art. 26(11), this is a right someone asserts. You need a route for the request, an owner, and a response time.
It explains the role of the system, not the model. The obligation is to explain what part the system played in the procedure and the main elements of the decision. It is not a demand for model internals, feature weights, or the training data.
It is not an annulment right. Art. 86 gives an explanation. Whether the decision itself can be challenged comes from elsewhere — sectoral law, contract, or Art. 22 of the GDPR where the decision was solely automated.
It interacts with the GDPR but is not the same. Where the decision was based solely on automated processing with legal or similarly significant effects, GDPR Art. 22 applies with its own safeguards — including a right to obtain human intervention, to express a point of view and to contest the decision. Art. 86 does not replace that. Map both, once, and build one response procedure that satisfies the stricter of the two.
What this looks like as an artefact
Per system: which of the four Art. 50 duties apply and to whom; the wording of each notice and where in the journey it appears; the Art. 5 check that was done before concluding a deployment was lawful; the editorial-responsibility holder if you rely on that exception; the Art. 26(11) notice; and the Art. 86 request procedure with its owner and its clock.
Because these duties are already in force, this is also the part of the file a supervisory authority can ask about today.
Check yourself
- We want engagement analytics on staff video calls, with a clear notice. — Art. 5(1)(f) prohibits inferring emotions in the workplace. No notice cures a prohibition.
- Our marketing team publishes AI-drafted commentary on regulatory developments, reviewed by our head of communications. — Potentially Art. 50(4) text on a matter of public interest, but the editorial-control exception may apply. Document who holds editorial responsibility.
- A human makes the final call, so Art. 26(11) does not bite. — It does. The paragraph covers systems that make decisions or assist in making them.
- An applicant asks why they were rejected. What does Art. 86 require? — A clear and meaningful explanation of the role the system played and the main elements of the decision — not the model's internals, and not necessarily a reversal.
Previous: Module 5 — The Article 25 trap Next: Module 7 — The evidence file →
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
Paragraphs 3 and 4. Art. 50(3) obliges deployers of emotion recognition or biometric categorisation systems to inform the natural persons exposed to them. Art. 50(4) obliges deployers who generate or manipulate deepfake content to disclose that it is artificially generated or manipulated, and deployers publishing AI-generated text on matters of public interest to disclose it. Paragraphs 1 and 2 — interaction disclosure and machine-readable marking of synthetic output — sit on the provider.
Yes, and that is the point of them. Art. 50 is a transparency regime that operates independently of the risk tier. A minimal-risk chatbot still triggers Art. 50(1) for its provider; an ordinary marketing team producing a synthetic video triggers Art. 50(4) for the deployer. These duties have been in application since 2 August 2026, well ahead of the Chapter III high-risk regime.
Art. 26(11) is a duty you owe proactively: inform natural persons that they are subject to the use of a high-risk Annex III system that makes or assists in making decisions about them. Art. 86 is a right they exercise: an affected person may obtain from the deployer a clear and meaningful explanation of the role the system played in the decision procedure. One is a notice you publish; the other is an answer you must be able to give when asked.
Take compliance further with the AI Act Academy
A free course, a server-graded exam, a verifiable certificate — and the working templates.