AI Act Article 50: Transparency and the Article 14 Line
AI Act Article 50 through an oversight lens: who must label AI content and deepfakes, the editorial exemption, and where Article 14 takes over.
What does AI Act Article 50 actually require, and when?
From 2 August 2026, Article 50 of the EU AI Act asks for one fairly simple thing in four specific situations: people should be able to tell when they are dealing with a machine or with machine-made content. Concretely, providers must build systems that generate synthetic audio, image, video or text so the output is marked as artificially generated; providers must design chatbots and other AI that talks to people so a user knows they are not speaking to a human; deployers who publish a deepfake must say so; and deployers who use AI to generate or manipulate published text on matters of public interest must disclose that too. There is no requirement to hide the AI or to apologise for it. The duty is disclosure, not abstinence.
That is the whole shape of it. Article 50 sits in the “limited risk” tier of the AI Act, which is a much lighter regime than the high-risk rules that govern things like medical triage or recruitment scoring. It is about honesty in the interaction, not about proving your system is safe. So the right reaction to the date is preparation, not alarm. If you run a customer chatbot, generate marketing imagery with a model, or produce synthetic voiceovers, you have concrete and limited work to do — mostly labelling and a few lines of clear notice — and a year-plus of runway already largely spent to do it.
One distinction does the heavy lifting throughout this article, so it is worth pinning down early. A provider is whoever develops an AI system and puts it on the market under their name; a deployer is whoever uses such a system under their own authority in a professional context. Article 50 splits its duties between these two roles, and which one you are decides what you owe. Many organisations are both at once — they build an internal tool and also use it — so read each obligation against the role you are actually playing in that moment.
Who must label AI-generated content, and how?
The labelling duty for synthetic content falls on the provider under Article 50(2). If you make an AI system — including a general-purpose model — that produces synthetic audio, image, video or text, you have to ensure its outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The point is that downstream systems and platforms can recognise the content automatically, not just that a human might guess. Think watermarking, cryptographic provenance signals, or embedded metadata, rather than a small caption a user can crop off.
The law is realistic about technical limits. The marking has to be “effective, interoperable, robust and reliable” only “as far as this is technically feasible,” and the chosen method should account for the specifics of the content type and the cost of implementation. That phrasing is deliberate: provenance technology is young and imperfect, and the legislator did not want to mandate something that does not yet exist. The expected anchor here is the work on standards and codes of practice that the AI Office is encouraging — including techniques aligned with provenance standards like C2PA — which is where “good enough” will get defined in practice.
A useful mental separation: the provider marks the output at the source (machine-readable provenance), while the deployer may carry a separate, human-facing disclosure duty when the same content happens to be a deepfake or public-interest text. The two can stack on one piece of content without being the same obligation.
When do you have to disclose a deepfake?
Here the duty shifts to the deployer under Article 50(4). If you use an AI system to generate or manipulate image, audio or video content that constitutes a deep fake — content resembling real people, objects, places or events that would falsely appear authentic — you must disclose that it has been artificially generated or manipulated. The disclosure has to be clear and given no later than the first exposure. In plain terms: if you publish a synthetic video of a recognisable person doing something they did not do, you label it as synthetic. The threshold is appearance of authenticity, not intent to deceive.
There is a parallel duty for text. Deployers who use AI to generate or manipulate text published to inform the public on matters of public interest must disclose that the text is artificially generated — unless the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. That carve-out is significant for newsrooms and publishers: a human editor taking responsibility for AI-assisted copy removes the disclosure trigger for that text.
The deepfake rule also bends for creative work. Where the content is part of an evidently artistic, creative, satirical or fictional work, the disclosure must be made in a way that does not hamper the display or enjoyment of the work — typically a notice in the credits or context, rather than a watermark scrawled across the frame. The obligation does not disappear; it is just delivered proportionately.
When must you tell people they are talking to a chatbot?
Chatbot disclosure lives in Article 50(1), and it is the provider’s design duty. AI systems intended to interact directly with natural persons must be designed and built so that those persons are informed they are interacting with an AI system — unless that is already obvious to a reasonably well-informed, observant and circumspect person, given the context. So a chat widget that clearly announces itself as a virtual assistant, or a voice line that opens with “you’re speaking with an automated assistant,” satisfies the spirit and the letter of the rule.
The “unless obvious” clause keeps this from being theatrical. You do not have to interrupt a context where no reasonable person would think they were talking to a human. But the safe default, especially as synthetic voices and conversational agents get more lifelike, is to disclose plainly at the first interaction. Notice required by Article 50 must be given at the latest at the time of the first interaction or exposure, in a clear and distinguishable manner, and be accessible — including to people with disabilities. A one-time, legible “I’m an AI assistant” up front is usually all it takes.
This is also the cheapest obligation to get right. It is a copy-and-design decision, not an engineering project. If your conversational product does not already say what it is, that is the first thing to fix before the date.
Who is exempt from the transparency rules?
Article 50 carries real exemptions, and reading them honestly matters as much as reading the duties.
| Obligation | Who carries it | Core duty | Main exemptions |
|---|---|---|---|
| Chatbot disclosure (50.1) | Provider | Design so users know they’re interacting with AI | When it’s obvious to a reasonable person; uses authorised by law to detect/prevent/investigate crime |
| Synthetic content marking (50.2) | Provider | Mark output as AI-generated, machine-readable | Where it only assists standard editing or doesn’t substantially alter input; technical-feasibility limits |
| Deepfake disclosure (50.4) | Deployer | Disclose content is artificially generated/manipulated | Artistic/creative/satirical/fictional works (proportionate notice); law-enforcement uses authorised by law |
| Public-interest text disclosure (50.4) | Deployer | Disclose AI-generated published text | Where content had human review and someone holds editorial responsibility |
Two threads run across the table. First, law enforcement: where use is authorised by law to detect, prevent, investigate or prosecute criminal offences, several disclosure duties are lifted, subject to safeguards for third-party rights. Second, proportionality: the synthetic-marking duty does not bite where AI only performs an assistive editing function or does not substantially alter the deployer’s input data, and creative works get a lighter-touch form of disclosure. None of these exemptions is a loophole to launder deception through; they are narrow accommodations for context.
How does Article 50 interact with human oversight?
Article 50 is a transparency rule, not an oversight rule — and confusing the two is the most common mistake I see. Telling someone they are talking to a chatbot does not make the chatbot safe, accurate or fair. Those qualities come from meaningful human oversight and, for high-risk systems, from the separate design duties of Article 14. Transparency tells a person what they are dealing with; oversight governs whether the system should have been allowed to decide at all. You can be fully Article 50-compliant and still have an under-governed system.
Worth keeping the timelines distinct, because they are easy to merge. Article 50’s transparency duties apply from 2 August 2026. The high-risk obligations — including the Article 14 human-oversight requirements — sit on a later and separate timeline, which the Commission’s Digital Omnibus simplification package has proposed pushing toward December 2027. The labelling and disclosure rules are not delayed by that; they stand on their own date. (As with all of this, dates are still being finalised, so confirm against the current consolidated text before you act on a deadline.)
It is also a different instrument from GDPR. GDPR Article 22 gives individuals a right not to be subject to decisions based solely on automated processing that significantly affect them, with safeguards including a human in the loop. That is about the consequences of a decision. Article 50 is about disclosure of the interaction or the content. A single product can trigger all three regimes — Article 22, Article 50, and high-risk oversight — and each one needs its own answer. For the foundations of where a human belongs in an automated workflow, see our human-in-the-loop guide.
A practical compliance checklist for Article 50
Calm, concrete, and front-loaded toward the parts that take longest:
- Map your role per system. For each AI system you touch, write down whether you are the provider, the deployer, or both. The obligation follows the role.
- Inventory synthetic output. List every place you generate audio, image, video or text with AI. For provider-built systems, confirm outputs carry machine-readable provenance marking; track the relevant standards and codes of practice rather than inventing your own.
- Flag your deepfakes. Identify any AI content that depicts real people, places or events convincingly. Add clear disclosure at first exposure; for creative works, use a proportionate notice that does not ruin the piece.
- Check published text. Where AI generates text on matters of public interest, either disclose it or establish documented human editorial responsibility — and record who holds it.
- Fix chatbot notice. Make every conversational agent announce itself as AI at first interaction, in clear, accessible language, unless it is genuinely obvious.
- Document exemptions you rely on. If you lean on the law-enforcement, assistive-editing, or creative-work carve-outs, write down why it applies. An unrecorded exemption is hard to defend.
- Keep it accessible. Ensure disclosures meet accessibility expectations, including for users with disabilities.
- Separate transparency from oversight. Treat Article 50 as a labelling layer on top of your oversight design, not a substitute for it.
- Watch the dates, lightly. Note 2 August 2026 for Article 50; keep an eye on the Digital Omnibus track for high-risk timing; verify against the consolidated text before relying on any deadline.
Article 50 rewards organisations that were already honest about their AI. If your users have always known when they were talking to a machine, and your synthetic media has always been marked, the date arrives as paperwork rather than panic. That is the intended outcome: not less AI, just AI you do not have to pretend is something else. And when you are ready to look beyond transparency, an independent review of your AI Act compliance will show how the rest of the regulation lands on your organisation.
Frequently asked
When do AI Act Article 50 transparency obligations start to apply?
They apply from 2 August 2026. That is a separate, earlier date than the high-risk obligations of the AI Act (including Article 14 human oversight), which sit on a later timeline that the Commission's Digital Omnibus package has proposed pushing toward December 2027. Dates are still being finalised, so confirm against the current consolidated text before relying on a deadline.
Does Article 50 require me to label content or stop using AI?
Label, not stop. Article 50 is a transparency rule, not a ban. It asks that synthetic content be marked as AI-generated, that deepfakes be disclosed, that certain AI-generated public-interest text be disclosed, and that people be told when they are interacting with a chatbot. There is no obligation to avoid AI or to hide that you use it — only to be honest about it.
Who is responsible: the provider or the deployer?
It depends on the obligation. Providers carry the chatbot-design disclosure (50.1) and the machine-readable marking of synthetic output (50.2). Deployers carry the deepfake disclosure and the public-interest text disclosure (50.4). Many organisations are both provider and deployer at once, so map each system to the role you are actually playing for that obligation.
What counts as a deepfake under Article 50?
A deepfake is AI-generated or manipulated image, audio or video content that resembles real people, objects, places, entities or events and would falsely appear to a person to be authentic. The trigger is the convincing appearance of authenticity, not the intent to deceive. If you publish such content, you must disclose that it was artificially generated or manipulated, clearly and at the latest at first exposure.
Do I have to disclose AI-written articles?
Only in a specific case. Deployers using AI to generate or manipulate text published to inform the public on matters of public interest must disclose it — unless the text has undergone human review and a natural or legal person holds editorial responsibility for the publication. A responsible human editor in the chain removes the disclosure trigger for that text.
Are there exemptions to the chatbot disclosure rule?
Yes. You do not have to announce the AI where it is already obvious to a reasonably well-informed, observant and circumspect person given the context. There is also an exemption for uses authorised by law to detect, prevent, investigate or prosecute criminal offences, subject to safeguards for third-party rights. As a default, though, disclosing plainly at first interaction is the safe choice.
What are the penalties for breaching Article 50?
Article 50 sits in the limited-risk tier, and its breaches fall under the AI Act's general fine band — up to 15 million euro or 3% of total worldwide annual turnover, whichever is higher, enforced by national authorities. That is distinct from the heaviest penalties, which attach to prohibited practices, not to transparency duties. Treat compliance as routine housekeeping rather than as a high-stakes threat.
Is Article 50 the same as GDPR Article 22?
No. GDPR Article 22 concerns the right not to be subject to decisions based solely on automated processing that significantly affect you, with safeguards including human intervention — it is about the consequences of a decision. Article 50 is about transparency: disclosing the AI interaction or the synthetic content. A single product can trigger both, plus high-risk oversight duties, and each needs its own answer.