Starting August 2, 2026, every AI system that interacts with humans in the EU must tell users it is AI, and every generative AI system must mark its outputs as machine-created. That is the core of Article 50 of the EU AI Act (Regulation (EU) 2024/1689), and unlike the high-risk AI deadlines that were deferred to 2027 by the Digital Omnibus, Article 50 landed on schedule with no general grace period. If you deploy chatbots, generate AI content, or use emotion recognition for EU users, compliance is already legally required. Fines reach €15 million or 3% of global annual turnover, whichever is higher.
Last verified: 2026-08-04
- Article 50 transparency obligations are enforceable from 2 August 2026.
- Four duties: chatbot disclosure, synthetic content marking, emotion-recognition notice, deepfake labeling.
- Fines up to €15M or 3% of worldwide turnover (€35M/7% is for prohibited practices, a different tier).
- ~190 organizations signed the voluntary Code of Practice, earning a presumption of conformity.
- Content created before August 2, 2026 does NOT need retroactive labeling.
- Existing generative AI systems get a transitional period until December 2, 2026 for content marking only.
- Volatile facts: enforcement timelines, signatory count, and technical standards may change.
What does EU AI Act Article 50 require?
Article 50 imposes four distinct transparency obligations on two groups: providers (companies that build and place AI systems on the market) and deployers (organizations that use those systems). Each obligation has a different trigger, a different responsible party, and a different technical requirement. The European Commission's final guidelines, published July 20, 2026, clarify how each applies in practice.
| Obligation | Article | Who is responsible | What it requires |
|---|---|---|---|
| Chatbot / interaction disclosure | 50(1) | Provider | Inform users they are interacting with AI, "at the latest at the time of the first interaction" |
| Synthetic content marking | 50(2) | Provider | Mark AI-generated outputs in machine-readable format, detectable as artificially generated |
| Emotion recognition / biometric categorization | 50(3) | Deployer | Inform exposed individuals that an emotion-recognition or biometric-categorization system is in use |
| Deepfake and public-interest text disclosure | 50(4)–(5) | Deployer | Disclose that content was artificially generated or manipulated |
The "obviously AI" exception
Article 50(1) does not require disclosure when a "reasonably well-informed, observant and circumspect person" would already recognize they are dealing with AI. The Commission's guidelines clarify that a clearly labeled chatbot widget may qualify, but a voice assistant that sounds human likely does not. The test is whether the user could reasonably believe they are talking to a human. If there is any doubt, disclose.
The "standard editing" exception
Article 50(2) does not apply to AI features that merely assist with spelling, grammar, or formatting without substantially altering content or its semantics. If your tool fixes typos but does not change meaning, the content-marking obligation does not trigger. However, if your tool rewrites paragraphs, generates new sections, or restructures the text, marking is required.
The editorial-control exception
Article 50(4) exempts AI-generated text that has undergone substantive human review with a person assuming editorial responsibility. A newsroom where an editor reviews, fact-checks, and takes responsibility for an AI-assisted article does not need a "this was AI-generated" label. But the provider's machine-readable marking obligation under 50(2) still applies — the exemption is specifically for the deployer's disclosure obligation.
When did EU AI Act transparency rules become enforceable?
Article 50 obligations became enforceable on August 2, 2026, and apply immediately to all in-scope AI systems regardless of when they entered the market. The AI Act entered into force on August 1, 2024, and is rolling out in phases through 2028. Prohibited AI practices (Article 5) took effect on February 2, 2025. General-purpose AI model obligations (Chapter V) applied from August 2, 2025. Article 50 is the first broad enforcement phase affecting everyday generative AI deployments.
The Digital Omnibus, which reached provisional agreement in May 2026 and was approved by the Council in June 2026, deferred Annex III high-risk AI obligations to December 2, 2027 — a 16-month reprieve that dominated headlines. But Article 50 was never bundled into that relief. If your organization assumed all AI Act deadlines were pushed back, the transparency obligations arrived on schedule.
What is the transitional period and who qualifies?
A limited transitional period applies only to the machine-readable marking obligation under Article 50(2) for generative AI systems already placed on the EU market before August 2, 2026. Providers of such systems have until December 2, 2026 to comply with the content-marking requirement. New systems launched after August 2 must comply immediately with all obligations.
The chatbot disclosure obligation under Article 50(1) has no transitional period. It applies from August 2, 2026 to all interactive AI systems, including those already deployed. Emotion-recognition and deepfake disclosure obligations likewise have no grace period.
Does AI content created before August 2, 2026 need retroactive labeling?
No. The European Commission confirms that content generated and published before August 2, 2026 does not need to be retroactively labeled. The Commission does encourage deployers to label older AI-generated content where possible, since it contributes to the goals of Article 50, but there is no legal requirement to go back and mark existing content.
How much are the fines for Article 50 non-compliance?
Non-compliance with Article 50 transparency obligations falls under Tier 2 of the AI Act's three-tier penalty structure (Article 99). The maximum fine is €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher.
| Penalty tier | Applies to | Maximum fine | Maximum % of turnover |
|---|---|---|---|
| Tier 1 | Prohibited AI practices (Article 5) | €35,000,000 | 7% |
| Tier 2 | Article 50 transparency, high-risk, GPAI obligations | €15,000,000 | 3% |
| Tier 3 | Supplying incorrect information to authorities | €7,500,000 | 1% |
For small and medium-sized enterprises (SMEs) and startups, the fine is capped at the lower of the fixed euro amount or the percentage of turnover, rather than the higher. This proportionality safeguard means a small company with €500,000 in turnover would face a maximum fine of €15,000 (3% of €500,000), not €15 million.
Fines are calculated on global annual turnover, not EU-only revenue. A US company with €1 billion in global revenue but only €20 million in EU revenue would have the fine calculated on the €1 billion figure. The threshold applies to irrespective of where the business is established.
Who enforces Article 50 — and how?
Enforcement is primarily by national competent market surveillance authorities in each EU member state. The European AI Office has a limited direct role: it is competent only for AI systems built on general-purpose AI models where the same entity provides both the system and the model, or where the AI system is integrated into a very large online platform designated under the Digital Services Act. The European Data Protection Supervisor enforces the rules vis-à-vis AI systems used by EU institutions, bodies, and agencies.
In practical terms, this means a French company using a chatbot falls under French market surveillance authority jurisdiction, while a global GPAI model provider like OpenAI or Google falls under the AI Office's direct oversight for the model layer.
What is the Code of Practice on AI Transparency?
The AI Office published a voluntary Code of Practice on Transparency of AI-Generated Content on June 10, 2026. By the end of July 2026, approximately 190 organizations across IT, telecom, education, and retail sectors had signed. Signatories include major AI providers such as Amazon, Anthropic, Google, Microsoft, Mistral AI, and OpenAI.
Signing the Code carries a key benefit: a presumption of conformity. The Commission confirmed on July 9, 2026 that the Code adequately covers the obligations in Articles 50(2), 50(4), and 50(5). Signatories benefit from increased trust from the Commission and other stakeholders, and the Commission focuses its enforcement activities on monitoring their adherence to the Code. Non-signatories are not relieved of their obligations by declining to sign — they must demonstrate compliance through other adequate means and face closer regulatory scrutiny.
The Code's scope is limited to marking, detection, and labeling obligations. Two Article 50 obligations fall outside the Code: the chatbot disclosure duty (Article 50(1)) and the emotion-recognition notification duty (Article 50(3)). Compliance with those must be assessed directly against the Commission's guidelines.
What the Code requires technically
The Code adopts a layered approach: providers must generally implement both digitally signed metadata (such as C2PA content credentials) and imperceptible watermarking (such as Google SynthID). Simplified requirements apply where outputs remain within physically controlled, closed environments or where the content type (like free-form text) cannot carry embedded metadata. Providers must also offer detection tools, generally free of charge, and implement interoperability solutions for watermark detection by February 2, 2027.
How to comply: a 5-step checklist for businesses
If you build or deploy AI systems that touch EU users, here is what to do:
Inventory your AI systems. Identify every AI system you provide or deploy that interacts with EU users, generates synthetic content, uses emotion recognition, or produces deepfake-style media. Document each system's function, its provider/deployer status, and where its outputs go.
Classify by Article 50 sub-obligation. Map each system against the four obligations: 50(1) chatbot disclosure, 50(2) content marking, 50(3) emotion-recognition notice, 50(4) deepfake/text disclosure. A single system may trigger multiple obligations.
Implement disclosures. For chatbots: add a pre-conversation disclosure ("You are chatting with an AI assistant") at the first interaction point — not buried in terms of service. For synthetic content: ensure outputs carry machine-readable marks (C2PA metadata, watermarking, or both). For emotion recognition: notify exposed individuals before or during deployment. For deepfakes: label content as AI-generated at publication.
Assess the Code of Practice. Decide whether to sign the Code for Articles 50(2)/(4)/(5). Signing earns a presumption of conformity for those obligations. If you do not sign, prepare to demonstrate compliance independently.
Update vendor contracts. If you deploy third-party AI systems, confirm the provider's Article 50 compliance status in your vendor agreements. Deployers should request documentation confirming the provider has implemented compliant disclosure, and where providers have not, implement an overlay disclosure at the deployment layer.
EU AI Act enforcement timeline at a glance
| Date | Milestone | Status |
|---|---|---|
| August 1, 2024 | AI Act enters into force | Done |
| February 2, 2025 | Prohibited AI practices (Article 5) and AI literacy (Article 4) apply | Done |
| August 2, 2025 | GPAI model obligations (Chapter V) apply | Done |
| June 10, 2026 | Code of Practice on Transparency published | Done |
| July 9, 2026 | Commission confirms Code adequacy for 50(2), (4), (5) | Done |
| July 20, 2026 | Final Article 50 guidelines published | Done |
| August 2, 2026 | Article 50 transparency obligations enforceable | In effect |
| December 2, 2026 | Transitional deadline for pre-existing systems' content marking | Upcoming |
| February 2, 2027 | Interoperability solutions for watermark detection required (Code signatories) | Upcoming |
| December 2, 2027 | Annex III standalone high-risk AI obligations (deferred by Omnibus) | Upcoming |
| August 2, 2028 | Annex I product-embedded high-risk AI obligations | Upcoming |
What this means for you
If you run a small business with a chatbot: You are a deployer. Your chatbot provider must ensure the system discloses its AI nature at first interaction. Your job is to verify the provider has implemented this and request documentation. If they have not, add your own overlay disclosure ("This assistant is powered by AI") until the provider complies. Fine exposure: up to 3% of global annual turnover.
If you build AI tools or APIs: You are a provider. You must design disclosure into the system itself — it cannot be left to the deployer. Synthetic content outputs must carry machine-readable marks. Consider signing the Code of Practice to benefit from the presumption of conformity.
If you publish AI-generated content: AI-generated text on matters of public interest must be disclosed as AI-generated unless it has undergone substantive human editorial review with someone assuming editorial responsibility. For content that does not address public-interest matters, the provider's machine-readable marking obligation still applies, but the deployer disclosure duty may not. If you think your content falls under the editorial-control exemption, document the review process and who is responsible.
For a deeper dive on detecting AI-written content on your own site (which intersects with the marking obligations), see our guide on how to spot AI-written content before your readers do. If you are using AI agents that operate autonomously, the containment and safety concerns are covered in our analysis of when AI agents escape containment. And if you are building with free AI APIs — many of which now need to support Article 50 marking — start with our list of free AI API providers for 2026.
FAQ
Q: Does Article 50 apply to companies outside the EU?
A: Yes. The EU AI Act has extraterritorial reach. If the AI system's output is used in the EU, the obligations apply regardless of where the provider or deployer is established. A US-headquartered company whose chatbot serves EU users must comply.
Q: Does my chatbot need to disclose it is AI if it is obviously a chatbot widget?
A: Possibly not. Article 50(1) does not require disclosure where a "reasonably well-informed, observant and circumspect person" would recognize they are dealing with AI. A clearly labeled chatbot widget may qualify. A voice assistant that sounds human likely does not. When in doubt, disclose.
Q: What happens to AI content I published before August 2, 2026?
A: It does not need to be retroactively labeled. The European Commission confirms content generated before the enforcement date is not subject to retroactive marking. You are encouraged to label it where possible, but there is no legal requirement.
Q: Is there a grace period for existing chatbots?
A: No. The chatbot disclosure obligation under Article 50(1) applies from August 2, 2026 to all systems, including those already deployed. The only transitional period is for the machine-readable content marking under Article 50(2), and only for systems already on the market before August 2, 2026 (deadline: December 2, 2026).
Q: What is the difference between Article 50 and GDPR transparency?
A: Article 50 requires disclosure of the AI nature of a system and the synthetic nature of content. GDPR Articles 13 and 14 require transparency about personal data processing. If an AI system both interacts with users and processes personal data, both sets of obligations apply independently. One does not substitute for the other.
Q: Do open-source AI models need to comply with Article 50?
A: Open-source model providers are not automatically exempt. The AI Act's open-source exemption (Article 53) applies to certain obligations for GPAI model providers releasing models under open-source licenses, but Article 50 transparency obligations attach to the system, not the model. If you deploy an open-source model in a system that interacts with EU users or generates content, the system must comply.

Discussion
0 comments