Article 50 of the EU AI Act entered into force on 2 August 2026, imposing transparency obligations on providers and deployers of certain AI systems operating across the European Union. The rules require that individuals be informed when they are interacting directly with an AI system, when they are exposed to emotion recognition or biometric categorisation tools, and when they encounter AI-generated or manipulated content such as deepfakes or synthetic text published on matters of public interest. Providers of generative AI systems must also embed machine-readable marks in their outputs so that such content can be detected as artificially generated.
The obligations apply to a broad range of actors along the AI value chain. Providers — those who develop or place AI systems on the market — must design systems so that users know they are interacting with AI, unless the interaction is obvious to a reasonably well-informed, observant, and circumspect person given the context. Deployers — those who use AI systems under their authority — carry separate duties to disclose the use of emotion recognition, biometric categorisation, deepfakes, and unreviewed AI-generated public-interest text. The European Commission links these requirements to growing risks of manipulation at scale, fraud, impersonation, and consumer deception as generative systems make it increasingly difficult to distinguish AI interaction from human conversation and synthetic media from authentic content.
What's New / Specs
The regulation sets out four distinct transparency obligations under Article 50, each targeting a different risk scenario. First, providers of AI systems intended to interact directly with natural persons must ensure those persons are informed they are interacting with an AI system, with exemptions for obvious interactions and for law-enforcement systems used to detect, prevent, investigate, or prosecute criminal offences — provided safeguards protect third-party rights, unless the public can use the system to report a crime. Second, providers of systems that generate synthetic audio, image, video, or text must mark outputs in a machine-readable way that enables detection of artificially generated or manipulated content. The marking must be effective and interoperable "as far as this is technically feasible," balancing implementation cost against the state of the art. Assistive editing that leaves deployer-supplied input essentially untouched — such as routine photo touch-ups — falls outside the requirement; wholesale AI-generated replacements do not.
Third, deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them. Personal data gathered through such systems remains governed by the GDPR, the EU institutions data protection regulation, or the Law Enforcement Directive, depending on the context. Fourth, deployers of deepfakes — image, audio, or video content that has been artificially generated or manipulated — must disclose that fact. Artistic, satirical, or fictional works receive a lighter touch: the disclosure need only flag the content's existence in a way that does not interfere with enjoyment of the work. For text published to inform the public on matters of public interest, deployers must disclose AI generation or manipulation unless a human has reviewed the content and someone holds editorial responsibility for the publication; standard newsroom review clears the bar, while unedited AI output published straight to a public-interest story does not.
- Effective date: 2 August 2026
- Scope: Providers and deployers of interactive AI systems, generative AI systems, emotion recognition systems, biometric categorisation systems, and deepfake content
- Provider obligations: Design for AI interaction disclosure; embed machine-readable marks in synthetic outputs
- Deployer obligations: Inform individuals exposed to emotion recognition or biometric categorisation; disclose deepfakes; disclose unreviewed AI-generated public-interest text
- Exemptions: Obvious interactions; law-enforcement systems with safeguards; assistive editing leaving input intact; artistic/satirical/fictional works (lighter disclosure); human-reviewed public-interest text with editorial responsibility
- Enforcement authorities: National market surveillance authorities (most cases); AI Office (systems under its supervision); European Data Protection Supervisor (EU institutions as provider/deployer)
- Compliance path: Adherence to the Code of Practice on Transparency of AI-generated Content, or demonstration of alternative equivalently adequate means for marking obligations; other transparency duties rely on self-determined adequate measures guided by Commission guidelines
Why It Matters
The entry into force of Article 50 marks a significant milestone in the EU's regulatory framework for artificial intelligence. By targeting transparency at the point of interaction and exposure, the rules aim to give individuals the information they need to calibrate trust, avoid deception, and make informed decisions when encountering AI systems or synthetic content. The obligations reach beyond high-risk AI classifications, capturing a wider set of "limited-risk" systems that nonetheless pose societal risks through scale and opacity. For enterprises deploying generative AI tools — chatbots, content generators, synthetic media pipelines — the requirements introduce concrete product-design and operational duties: interaction disclosures must be built into user interfaces, marking mechanisms must be integrated into generation pipelines, and deployment workflows must include disclosure steps for emotion recognition, biometric categorisation, deepfakes, and public-interest text.
The compliance landscape is shaped by a split enforcement model. National market surveillance authorities handle the majority of cases, while the AI Office supervises systems falling under its remit — notably general-purpose AI models with systemic risk — and the European Data Protection Supervisor steps in when an EU institution acts as provider or deployer. The Commission has issued guidelines that clarify definitions (directly interactive AI systems, synthetic content, deepfakes, standard editing exceptions) and the provider-deployer distinction along the value chain, including situations where both roles sit with the same organisation. Organisations that sign on to the Code of Practice on Transparency of AI-generated Content gain a Commission-endorsed reference point for meeting marking obligations; those that do not must demonstrate compliance through alternative means deemed adequate by market surveillance authorities. For the other three transparency duties — interaction disclosure, emotion recognition/biometric categorisation disclosure, and deepfake/public-interest text disclosure — no equivalent code exists, leaving providers and deployers to determine adequate measures themselves with the guidelines as a reference.
Our Take
The Article 50 transparency rules represent a pragmatic but ambitious attempt to address the erosion of informational integrity caused by increasingly capable generative and interactive AI. By focusing on disclosure at the point of human exposure — rather than banning categories of technology outright — the EU seeks to preserve innovation while giving individuals agency. The machine-readable marking requirement for synthetic outputs is particularly forward-looking: it creates a technical foundation for downstream detection, provenance tracking, and platform-level enforcement that could scale beyond the EU's borders. However, the "as far as technically feasible" qualifier introduces ambiguity that enforcement authorities will need to resolve case by case, and the absence of a code of practice for three of the four obligations means compliance certainty will vary across member states in the near term.
For businesses, the immediate priority is mapping their AI systems against the four obligation categories and determining whether they act as provider, deployer, or both. The provider-deployer distinction is not merely academic — it dictates which duties apply and where liability sits. Organisations that both fine-tune models and deploy them in customer-facing applications may need to satisfy both provider and deployer obligations simultaneously. The guidelines' clarification that standard editing and assistive functions fall outside scope provides a useful boundary, but the line between "assistive editing" and "wholesale AI-generated replacement" will be contested in practice. Signing the Code of Practice on Transparency of AI-generated Content offers a clearer compliance path for marking obligations, but it also commits organisations to a collective standard that may evolve. Companies should treat the guidelines as a living reference and build disclosure and marking capabilities that can adapt as enforcement practice matures.
FAQ
When did Article 50 of the EU AI Act enter into force?
Article 50 entered into force on 2 August 2026. The transparency obligations apply from that date; there is no grace period for informing individuals after the fact — disclosures must land no later than the first interaction or exposure.
Which AI systems are covered by the interaction disclosure requirement?
Providers of AI systems intended to interact directly with natural persons must ensure those persons are informed they are interacting with an AI system. The requirement does not apply where the interaction is obvious to a reasonably well-informed, observant, and circumspect person given the context, or for law-enforcement systems used to detect, prevent, investigate, or prosecute criminal offences, provided safeguards protect third-party rights (unless the public can use the system to report a crime).
What does the machine-readable marking obligation require for AI-generated content?
Providers of systems generating synthetic audio, image, video, or text must embed marks in outputs that enable detection of artificially generated or manipulated content. The marking must be effective and interoperable "as far as this is technically feasible," weighing implementation cost against the state of the art. Assistive editing that leaves deployer-supplied input essentially untouched — such as routine photo touch-ups — is excluded; wholesale AI-generated replacements are not.
How are deepfakes and AI-generated public-interest text treated differently?
Deployers of deepfakes (artificially generated or manipulated image, audio, or video) must disclose that fact. Artistic, satirical, or fictional works need only flag the content's existence in a way that does not interfere with enjoyment. For text published to inform the public on matters of public interest, deployers must disclose AI generation or manipulation unless a human has reviewed the content and someone holds editorial responsibility — standard newsroom review clears the bar, while unedited AI output published straight to a public-interest story does not.
What are the enforcement mechanisms and compliance paths for Article 50?
Three bodies split enforcement: national market surveillance authorities handle most cases; the AI Office supervises systems under its remit; the European Data Protection Supervisor acts when an EU institution is the provider or deployer. For marking obligations, organisations can adhere to the Code of Practice on Transparency of AI-generated Content or demonstrate alternative equivalently adequate means judged by market surveillance authorities. The other three transparency duties have no equivalent code; providers and deployers determine adequate measures themselves, guided by the Commission's guidelines.