Reglog

← Guides & analysis

EU AI Act transparency rules (Article 50): what you must disclose, and by when

· 8 min read

Most coverage of the EU AI Act fixates on the "high-risk" tier — the heavy engineering and governance duties, and the largest fines. But there is a second set of obligations that reaches far more companies, and it is easy to miss precisely because it sits outside the high-risk regime. It is Article 50: the transparency rules.

If you run a chatbot, generate images or text with AI, or publish AI-manipulated media, Article 50 almost certainly applies to you — even if none of your systems are high-risk. And unlike the high-risk obligations, which were pushed back to 2027 and 2028, the transparency duties still apply from 2 August 2026.

This is an information service to help you orient, not legal advice. When you want the specific obligations for your own AI use, answer three questions and see which apply.

Why Article 50 catches companies the high-risk rules miss

The AI Act sorts systems by risk. Most business AI — a support chatbot, a marketing image generator, a drafting assistant — is limited-risk: not banned, not high-risk, but subject to transparency. The logic is simple. People have a right to know when they are talking to a machine, and when audio, images, video, or text were made or altered by AI.

So a company can correctly conclude that it has no high-risk system — and still owe real obligations under Article 50. If you have been working out which obligations apply to your company and breathed a sigh of relief at "not high-risk," this is the part to read twice.

The four transparency duties

Article 50 contains four distinct obligations. Two fall on the provider (whoever develops the system and puts it on the market) and two fall on the deployer (whoever uses it in a professional context).

# Obligation Falls on Applies to
50(1) Tell people they are interacting with an AI Provider Chatbots, virtual assistants, automated voice systems
50(2) Mark AI-generated output in a machine-readable, detectable format Provider Systems generating synthetic audio, image, video, or text (incl. general-purpose AI)
50(3) Tell people an emotion-recognition or biometric-categorisation system is being used on them Deployer Systems inferring emotions or sorting people by biometric data
50(4) Disclose deepfakes, and disclose AI-generated text published to inform the public Deployer Deepfake media; AI-written articles on matters of public interest

50(1) — chatbot disclosure. If an AI system is meant to interact directly with people, the provider must design it so a person is informed they are dealing with an AI — unless that is already obvious to a reasonably informed user.

50(2) — marking synthetic content. Providers of generative AI must mark outputs (audio, image, video, text) so they are detectable as artificially generated or manipulated, in a machine-readable format. This is the "watermarking" obligation, and it is the one with the special date below.

50(3) — emotion and biometric systems. A deployer using emotion recognition or biometric categorisation must inform the people exposed to it.

50(4) — deepfakes and public-interest text. A deployer that produces a deepfake must disclose that the content is artificially generated or manipulated. A deployer that publishes AI-generated text to inform the public on matters of public interest must also disclose it — unless the text went through human editorial review with someone holding editorial responsibility.

The two dates that matter

For the transparency duties, there are effectively two deadlines.

  • 2 August 2026 — the main date. All four Article 50 obligations apply from here. The Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk deadlines to 2 December 2027 (stand-alone) and 2 August 2028 (embedded products) — but it left the transparency duties in place.
  • 2 December 2026 — the marking grace period. The Digital Omnibus added one narrow extension: for generative AI systems already placed on the market before 2 August 2026, the machine-readable marking obligation in Article 50(2) applies from 2 December 2026 instead. It is a short runway for existing systems, not a general reprieve.

If you are a provider putting a new generative system on the market on or after 2 August 2026, the marking obligation applies immediately — the grace period does not help you.

The exceptions you can actually rely on

Article 50 has genuine carve-outs. The important ones:

  • Obviousness (50(1)). No chatbot disclosure is needed where it is already obvious to a reasonably informed person that they are interacting with AI.
  • Assistive and non-substantive editing (50(2)). The marking duty does not bite where the AI performs an assistive function that does not substantially alter the input — think grammar or spelling correction.
  • Artistic and satirical work (50(4)). For deepfakes in evidently artistic, creative, satirical, or fictional works, the disclosure is lighter — it must not spoil the display or enjoyment of the work.
  • Human editorial review (50(4)). AI-generated public-interest text is exempt where a person or organisation reviewed it and holds editorial responsibility for publication.

These are real, but narrow. "It was mostly the AI, but a human glanced at it" is not the same as editorial responsibility, and "obvious to us" is not the same as obvious to a reasonably informed member of the public.

What the Commission's guidelines actually require

On 20 July 2026 the Commission adopted its final, 51-page Guidelines on the implementation of the transparency obligations under Article 50. Most coverage works from the bare article; the guidelines add the practical detail that decides whether a disclosure actually complies. The parts that change how you build:

  • Chatbots (50(1)) — one clear notice, up front. A single, prominent notification before the first interaction is likely to suffice in most cases — a plain-language banner or first-turn message such as "You are interacting with an AI system." It must be clear and distinguishable, given at the latest at the first interaction, accessible to people with disabilities, and child-friendly where children may use it. The "obvious interaction" exception is read restrictively, and the law-enforcement carve-out does not apply if the system is public and lets people report a crime.
  • Marking (50(2)) — marking and detection, not just a watermark. The provider must implement a technical solution that does two things: mark the output in a machine-readable format and provide the means to detect it. Doing only one — a machine-readable mark with no way to detect it — does not comply. "Machine-readable" means structured so software can identify and extract it without human intervention; the guidelines cite watermarks, metadata, cryptographic provenance, logging, and fingerprints (or a combination). Deployers may rely on an upstream model provider's marking, if it is compliant.
  • Emotion & biometric systems (50(3)). Inform the people exposed to the system — but note that emotion recognition in the workplace or in education is prohibited outright under Article 5, so there the issue is the ban, not the notice.
  • Deepfakes (50(4)) — the label is separate from the mark. The deepfake label must be clear and perceivable to a human. A provider's machine-readable 50(2) mark does not replace it — you may owe both.
  • The trap the guidelines spell out: if you build and use your own generative system, you are both provider and deployer — on the hook for the machine-readable marking (50(2)) and the perceivable labelling (50(4)). And the rules reach beyond the EU: a non-EU company whose AI-generated ad or deepfake is shown in the EU is a deployer in scope.

What to do before 2 August 2026

  1. Inventory every place AI touches a person or produces content. Chatbots, voice systems, image and video generators, AI drafting for public-facing text, any emotion or biometric feature.
  2. Assign each to a duty and a role. Which of 50(1)–(4) applies, and are you the provider, the deployer, or both? Roles decide who acts — see which obligations apply to your company.
  3. Ship the disclosures. A clear "you're chatting with an AI" notice, machine-readable marking on generative output, notices for emotion/biometric use, and deepfake/public-interest labels.
  4. Check the marking date. New generative system on or after 2 August 2026: marking applies now. Already on the market before then: you have until 2 December 2026.
  5. Separate this from high-risk. Not high-risk does not mean no obligations. Confirm your high-risk position too — is your AI system high-risk?

Transparency is often the AI Act's most reachable near-term deadline — the one that arrives on 2 August 2026 whether or not you have a high-risk system. The fastest way to see your own list: answer three questions about your AI use and we'll show the verified obligations that match, sorted by deadline. To be told the moment any of them change, join the waitlist.

The official text is Regulation (EU) 2024/1689 (Article 50), read together with the Commission's Guidelines on the transparency obligations for providers and deployers of certain AI systems (adopted 20 July 2026). This article is an information service to help you orient — it is not legal advice.

Frequently asked questions

What do the Commission's Article 50 transparency guidelines say?

On 20 July 2026 the Commission adopted 51-page guidelines on implementing Article 50. Key points: a single, prominent notice before a chatbot interaction usually suffices; providers of generative AI must implement both machine-readable marking AND a means of detection (one alone is not enough); a deepfake's human-perceivable label is separate from that machine-readable mark, so you may owe both; and a company that builds and uses its own generative AI is both a provider and a deployer.

What does Article 50 of the EU AI Act require?

Article 50 sets four transparency duties. Providers must tell people when they are interacting with an AI system (50(1)) and mark AI-generated audio, image, video, and text so it is machine-readable and detectable (50(2)). Deployers must tell people when an emotion-recognition or biometric-categorisation system is used on them (50(3)), and must disclose deepfakes and AI-generated text published to inform the public on matters of public interest (50(4)).

When do the EU AI Act transparency obligations apply?

The Article 50 transparency duties apply from 2 August 2026. The Digital Omnibus on AI did not delay them. There is one narrow extension: for generative AI systems already on the market before 2 August 2026, the machine-readable marking obligation in Article 50(2) applies from 2 December 2026 instead.

Did the Digital Omnibus delay the transparency rules?

No. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026) delayed the high-risk obligations, not the transparency duties. Article 50 still applies from 2 August 2026, with only a short grace period to 2 December 2026 for marking content from generative systems that were already on the market.

Does Article 50 apply even if my AI is not high-risk?

Yes. The transparency obligations are separate from the high-risk regime. A customer chatbot or an image generator is usually not high-risk, but it still has to meet Article 50. This is why many companies with no high-risk system still have a real 2 August 2026 deadline.

See which obligations apply to your company → or join the waitlist

This is an information service, not legal advice.