Article 50 has applied since 2 August 2026 and is risk-independent — it catches chatbots, synthetic content, emotion recognition and deepfakes whatever your risk tier. Four paragraphs, two on providers and two on deployers, with a €15M / 3% ceiling.
Applies now. Article 50 entered into application on 2 August 2026 and is enforced by national market surveillance authorities. The Commission published its interpretive guidelines on the Article 50 transparency obligations on 20 July 2026. One deadline is still ahead: machine-readable marking of pre-existing generative systems closes on 2 December 2026.
Article 50 of Regulation (EU) 2024/1689 requires providers and deployers of certain AI systems to tell people when they are dealing with AI. It is risk-independent — it applies whatever tier your system sits in — which makes it the broadest-reaching obligation in the Regulation. It has four substantive paragraphs: two on providers, two on deployers, with a ceiling of €15 million or 3% of worldwide turnover under Article 99(4).
The four obligations at a glance
| Paragraph | Obligation | Falls on | Status |
|---|---|---|---|
| Art. 50(1) | Systems interacting with people must disclose they are AI | Provider | Applies since 2 Aug 2026 |
| Art. 50(2) | Synthetic audio, image, video or text marked in a machine-readable format | Provider | Applies since 2 Aug 2026 — grace period to 2 Dec 2026 for systems already on the market |
| Art. 50(3) | People exposed to emotion recognition or biometric categorisation must be informed | Deployer | Applies since 2 Aug 2026 |
| Art. 50(4) | Deepfakes, and AI text published to inform the public on matters of public interest, must be disclosed | Deployer | Applies since 2 Aug 2026 |
Two further paragraphs govern how the duties are discharged rather than adding new ones: Art. 50(5) fixes the manner and timing of the information, and Art. 50(6) confirms that none of this displaces the high-risk requirements of Chapter III.
The provider/deployer split is where most programmes go wrong. Paragraphs 1 and 2 are design-stage duties on whoever places the system on the market. Paragraphs 3 and 4 are use-stage duties on whoever puts it into service. A marketing agency using a third-party video tool is a deployer and owes the deepfake disclosure itself — it cannot rely on the provider having marked the output. If you are unsure which you are, providers vs deployers settles it.
Who falls under Art. 50 (and not under the high-risk regime)
The AI Act is tiered. Most AI systems deployed today are not high-risk under Annex III or Annex I; they land in one of two lighter categories:
- Transparency obligations only (Art. 50) — chatbots, generative systems, deepfake tools, emotion recognition and biometric categorisation.
- Minimal risk — spam filters, AI in games, recommendation systems: voluntary codes of conduct only.
The distinction that matters is that transparency-only systems require disclosure, not conformity assessment, technical documentation or CE marking. The burden is far lower — but it is live today, whereas the high-risk regime is not. Working out which tier you occupy is the first step; the AI risk classifier walks the Annex III categories.
Art. 50(1) — Systems that interact with people
Provider duty. Any AI system designed to interact directly with natural persons must be built so that those persons are informed they are interacting with an AI system.
Scope. Customer service bots, virtual assistants, AI phone agents, conversational AI embedded in social media, AI-powered support chat, avatars and agentic interfaces. If a human-facing interface uses a language model to conduct dialogue, Art. 50(1) applies.
Exemption 1 — obviousness. No disclosure is required where it is obvious to a reasonably well-informed, observant and circumspect person that they are interacting with an AI. That is a high bar. Implicit UI cues alone are unlikely to clear it where a user could reasonably believe they are talking to a human.
Exemption 2 — law enforcement. Systems authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to safeguards for third-party rights.
Art. 50(2) — Machine-readable marking of synthetic content
Provider duty. Providers of AI systems — including general-purpose AI systems — that generate synthetic audio, image, video or text must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The technical solution must be effective, reliable, robust and interoperable as far as technically feasible.
Scope. Text-to-image and text-to-video generators, voice cloning systems, audio synthesis, and AI writing systems producing output at scale.
This is the obligation with a grace period. Generative systems already placed on the EU market before 2 August 2026 have until 2 December 2026 to comply with the marking duty. A system launched on or after 2 August 2026 has no grace period and must mark from day one. Record the evidence for your placing-on-the-market date — it is the fact that decides which regime you are in.
Exemption. Systems performing an assistive function for standard editing, or that do not substantially alter the input data provided by the deployer or its semantics.
The Commission's Code of Practice on Transparency of AI-generated Content, published in June 2026, is recognised as an adequate means of demonstrating compliance with the marking duty. Roughly 190 organisations had signed by the end of July 2026. Signing confers no legal immunity, but a signatory implementing the Code has a documented, Commission-recognised route; a non-signatory must construct and defend its own.
Art. 50(3) — Emotion recognition and biometric categorisation
Deployer duty. Deployers of an emotion recognition system or a biometric categorisation system must inform the natural persons exposed to it of the operation of the system, and process personal data in accordance with the GDPR and related instruments.
Emotion recognition covers systems that detect, classify or score emotional or psychological states — engagement, stress, anger, deception — from facial expression, voice, physiological signals or behaviour. Typical cases: HR interview analysis, call-centre sentiment monitoring, retail response tracking.
Biometric categorisation covers systems inferring characteristics from biometric data. Where the inference concerns sensitive attributes — race or ethnic origin, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation — the practice is prohibited outright under Art. 5, not merely subject to disclosure. See prohibited practices: where a system is banned, transparency is beside the point.
Not covered. Systems detecting physiological states purely for safety or medical purposes — drowsy-driver detection that triggers an alert without inferring or retaining emotional state. The carve-out is narrow: a system repurposed for profiling loses it.
Where the system is also high-risk under Annex III — emotion recognition in employment or education is — the full high-risk obligations stack on top from 2 December 2027.
Art. 50(4) — Deepfakes and AI-generated text on matters of public interest
Deployer duty, in two limbs.
Deepfakes. A deployer of an AI system that generates or manipulates image, audio or video content constituting a deep fake must disclose that the content has been artificially generated or manipulated. The disclosure is for the audience: visible for image and video, audible for audio — not metadata alone.
Public-interest text. A deployer publishing AI-generated or AI-manipulated text for the purpose of informing the public on matters of public interest must disclose it. This limb is narrower than it is often read: it targets published informational text, not internal drafting or marketing copy.
Exemptions.
- Editorial review — the text limb does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication.
- Artistic, creative, satirical or fictional works — the deepfake disclosure is limited to what is appropriate, presented in a way that does not hamper the display or enjoyment of the work.
- Law enforcement, where authorised by law.
Documenting intent matters for the artistic exemption: an authority will assess whether the artificial nature was genuinely apparent in context.
Art. 50(5) — How the disclosure must be presented
This paragraph is where enforcement will bite, because it is the one that turns a policy into an interface change. The information required by paragraphs 1 to 4 must be given to the persons concerned:
- in a clear and distinguishable manner,
- at the latest at the time of the first interaction or exposure,
- in conformity with the applicable accessibility requirements.
In practice that excludes burying the notice in terms of service, in a page footer, or behind a menu option on an online interface. For a chatbot, the disclosure belongs at the opening of the conversation. For a deepfake video, at the point of exposure — not in the description below it.
Practical compliance steps by system type
| System type | Obligation | Paragraph | Responsible party |
|---|---|---|---|
| Chatbot, virtual assistant, AI phone agent | Disclose AI interaction at start of session | 50(1) | Provider (design) |
| Text-to-image / video / voice generator | Machine-readable mark on every output | 50(2) | Provider |
| Large-scale AI text generation | Machine-readable mark on output | 50(2) | Provider |
| Emotion recognition (HR, call centre, retail) | Inform the persons exposed | 50(3) | Deployer |
| Biometric categorisation (non-prohibited) | Inform the persons exposed | 50(3) | Deployer |
| Deepfake image / audio / video published | Visible or audible "AI-generated" label | 50(4) | Deployer |
| AI text published to inform the public | Disclose artificial generation | 50(4) | Deployer |
Deployers carry their obligations independently of whether the provider has met its own. A deployer cannot rely on the provider's marking as a substitute for its own disclosure.
Relationship with the GDPR
Article 50 is legally independent of GDPR Article 22 on automated individual decision-making. The same system can trigger both.
A chatbot used as the first stage of a loan application must:
- disclose it is an AI system at the start of the conversation — Art. 50(1);
- if it makes or meaningfully contributes to a solely automated decision with legal or similarly significant effects, give the data subject the GDPR Art. 22 rights: not to be subject to the decision, to human review, and to an explanation.
Art. 50(3) also expressly requires emotion recognition and biometric categorisation deployers to process personal data in accordance with the GDPR — the two instruments are stitched together at that point rather than merely running in parallel. Organisations deploying AI in financial services, insurance or HR should map both in the same review. See AI Act vs GDPR for the full interaction.
Fines for non-compliance
Breaches of the Article 50 transparency obligations fall under Article 99(4): up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.
| Breach | Ceiling | Enforced by |
|---|---|---|
| Prohibited practices (Art. 5) | €35M or 7% of worldwide turnover | National market surveillance authorities |
| Article 50 transparency | €15M or 3% of worldwide turnover | National market surveillance authorities |
| GPAI model obligations (Art. 101) | €15M or 3% of worldwide turnover | European Commission / AI Office |
| Incorrect or misleading information to authorities | €7.5M or 1% of worldwide turnover | National authorities / Commission |
The ceiling is the higher of the fixed sum and the percentage; above roughly €500 million of turnover the percentage is always the operative figure. For SMEs and start-ups Article 99(6) caps the fine at the lower of the two. Full tiering on the penalties page.
Enforcement rests with the national market surveillance authorities designated under Art. 74, not with Brussels — the Commission's exclusive competence covers GPAI model providers only. Designation has been uneven across the 27 Member States; the national implementation tracker records where each one stands.
Next steps
- Read the Commission's Article 50 guidelines — C(2026) 5054 final, 20 July 2026 — for how authorities are expected to interpret each paragraph.
- Inventory by function, not by risk tier: every system that talks to a person, generates content, or infers emotions.
- Date every generative system against 2 August 2026 to decide whether the 2 December 2026 grace period is available to you.
- Use the AI risk classifier to confirm whether transparency is your only obligation or whether the high-risk regime also applies from December 2027.
- Check what changed on 2 August 2026 for the enforcement picture, and the Digital Omnibus analysis for what Regulation (EU) 2026/1744 did and did not move.
Editorial, not legal advice.
Official AI Act Compliance Deadline Calendar
Updated · Sources: Regulation (EU) 2024/1689 and the 2026 Digital Omnibus on AI.
| Obligation | Applies to | Original date | New date | Status | Countdown | Legal basis |
|---|---|---|---|---|---|---|
| Prohibited Practices (Art. 5) | All providers and deployers | active | — | AI Act Art. 5 | ||
| GPAI Rules (Chapter 5) | GPAI model providers | active | — | AI Act Art. 51-56 | ||
| Commission Enforcement Powers over GPAI | GPAI model providers | active | — | AI Act Art. 88-94, 101 | ||
| Transparency Obligations (Art. 50) | Providers and deployers of chatbots, generative, emotion recognition systems | active | — | AI Act Art. 50 | ||
| New Art. 5 Prohibition (CSAM / non-consensual intimate imagery) | Providers and deployers of generative AI systems | active | — | AI Omnibus 2026 Art. 5 | ||
| AI-Generated Content Marking (pre-existing systems) | Providers of generative AI systems on the market before 2 Aug 2026 | active | — | AI Act Art. 50(2) — transitional | ||
| Regulatory Sandboxes | National competent authorities | deferred | — | AI Omnibus 2026 Art. 57 | ||
| High-risk AI — Annex III (standalone) | Providers of standalone Annex III systems | deferred | — | AI Omnibus 2026 Art. 6(2) | ||
| High-risk AI — Annex I (embedded) | AI embedded in Annex I regulated products | deferred | — | AI Omnibus 2026 Art. 6(1) |
⬇ Download JSON · CC BY 4.0
AI Act meets DORA and NIS2
Is your organisation subject to both the AI Act and DORA? The two regulations intersect on the operational resilience of financial AI systems. Our sister site regulation-dora.eu covers DORA in depth — including what the AI Act adds on top of an existing DORA programme.
The AI Act for financial institutions ↗ Explore regulation-dora.eu ↗Frequently Asked Questions
Yes. Under Art. 50(1) a provider must design any AI system intended to interact directly with natural persons so those persons are informed they are dealing with an AI system. Art. 50(5) fixes the manner: clear, distinguishable, and given at the latest at the time of the first interaction or exposure. The only carve-outs are where it is obvious to a reasonably well-informed, observant and circumspect person, and where the system is authorised by law for criminal-offence purposes.
Paragraphs 1 and 2 bind providers: AI-interaction disclosure, and machine-readable marking of synthetic audio, image, video or text. Paragraphs 3 and 4 bind deployers: informing people exposed to emotion recognition or biometric categorisation systems, and disclosing deepfakes and AI-generated text published to inform the public on matters of public interest. Most organisations are deployers and most compliance programmes are written as if the whole article were a provider problem.
Up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher, under Article 99(4). Article 50 breaches sit in the same tier as provider and deployer obligations generally — not in the lower €7.5 million / 1% tier, which covers supplying incorrect or misleading information to authorities.
Yes, and this is the most common misreading. Article 50 is risk-independent: it attaches to what the system does — interacts with people, generates synthetic content, infers emotions, produces deepfakes — not to whether it is high-risk under Annex III or Annex I. A minimal-risk marketing chatbot is in scope. A high-risk CV-screening tool that never speaks to a candidate may not be.
No. Regulation (EU) 2026/1744 deferred the high-risk regime — Annex III to 2 December 2027 and Annex I to 2 August 2028 — and moved the national sandbox obligation to 2 August 2027. Article 50 kept its date and has applied since 2 August 2026. The single omnibus concession on transparency was a grace period to 2 December 2026 for machine-readable marking of generative systems already on the EU market before 2 August 2026.
The guidelines — C(2026) 5054 final, published 20 July 2026 — do not change the text of Article 50. They set out how the Commission expects national market surveillance authorities to interpret and enforce the four obligations consistently across the Union, covering the scope of each paragraph, the exemptions, and how disclosure must be presented. They were published less than two weeks before the obligation entered into application.
Art. 50(5) requires the information to be provided in a clear and distinguishable manner at the latest at the time of the first interaction or exposure. In practice that rules out burying it in terms of service, in a footer, or behind a menu option on an online interface. For a chatbot it belongs at the start of the conversation; for a deepfake video, at the point the viewer is exposed to the content.
Stay ahead of AI Act changes
Get compliance alerts when deadlines or obligations change.
No spam. One-click unsubscribe.
Take compliance further with the AI Act Academy
A free course, a server-graded exam, a verifiable certificate — and the working templates.