On 2 August 2026, Article 50 of the EU AI Act starts to apply. It is the part of the Regulation that forces organisations to signal when a machine has generated or manipulated what a user sees, hears or reads. This is not guidance or a set of good practices; it is a directly applicable obligation across the Union, backed by fines that can reach 3% of worldwide turnover. And unlike most of the Regulation, it reaches systems already in production from day one.
The usual reaction in a board meeting is to assume this is a problem for the model builders — OpenAI, Google, Anthropic. That assumption falls apart on a closer read: the Article splits duties between the organisation that develops a system (the provider) and the one that uses it under its own authority — the deployer. If your organisation runs a customer chatbot, produces marketing material with generative AI, or publishes text written by a model, the transparency duty lands on you as well.
At a glance
- From 2 August 2026, Article 50 requires you to disclose four things: that someone is talking to an AI, that a piece of content is synthetic, that a system recognises emotions or categorises biometric data, and that an image, audio, video or text is a deepfake or otherwise AI-generated.
- The duties are shared between the provider (which develops) and the deployer (which uses the system). An organisation with no high-risk AI can still have obligations simply by operating a chatbot or publishing generated content.
- The European Commission published its final guidelines on Article 50 on 20 July 2026 and confirmed the Code of Practice on Transparency of AI-Generated Content as adequate.
- Non-compliance carries fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher; for SMEs and start-ups the lower figure applies.
- Content generated before 2 August does not need retroactive labelling — the date of generation is what counts. For marking systems already on the market, the obligation applies from 2 December 2026.
What Article 50 actually requires
The Article sets out four situations and, in each, names who has to speak up. The first is direct interaction: a chatbot, an agent or an avatar talking to a person. Here the duty falls on the provider, which must design the system so that it is clear the user is dealing with an AI, unless that is obvious from the context.
The second is synthetic content. Whoever produces images, audio, video or text with generative AI must mark the output in a machine-readable format — a watermark, metadata, C2PA-style provenance — so that a third party can detect it as artificial. This is a technical obligation on the model or tool provider, and the most engineering-heavy part of the Article.
The third covers emotion recognition and biometric categorisation: when an organisation runs one of these systems, the deployer must inform the people exposed to it. The fourth is the most discussed: deepfakes and public-interest text. An organisation that deploys a system generating or manipulating realistic-looking images, audio or video must disclose it; and AI-generated or AI-manipulated text published to inform the public on matters of public interest must be flagged as such, with some carve-outs where there is genuine human editorial control or review.
The calendar shapes how much room there is to manoeuvre: application begins on 2 August 2026 under Article 113 of the Regulation. For marking and detecting content in systems already on the market before that date, compliance is required from 2 December 2026. And the Commission published its final guidelines barely two weeks before the obligations began to bite — a window that leaves little room to improvise.
The objection: “this is for big tech”
The objection deserves to be taken seriously, because it is the one you hear most and it is not entirely baseless. Plenty of mid-sized organisations reason like this: we do not train models, we have nothing on the high-risk list, and the AI tools we use — the support chatbot, the agency's image generator, the assistant that summarises email — belong to third parties. From there they conclude that compliance is the vendor's problem.
There is a real basis to that. For two years the public debate on the Regulation revolved around foundation models and the list of high-risk uses, not the chat widget on a corporate website. And the word “AI” conjures a lab, not the assistant that has quietly been answering customer questions for months. The trouble is that Article 50 does not work on that logic.
Why it does apply to you
The first point is scope: Article 50 is not limited to high-risk AI. As the Commission's guidance sets out, and as analysis from the firm Bird & Bird confirms, it covers chatbots, generative AI, emotion recognition and deepfakes regardless of their risk level. A system that is not on the high-risk list is not thereby outside Article 50.
The second is how the duties are split. Marking the output is the provider's job, true, but disclosing a deepfake and public-interest text falls on the deployer. In other words, even if the chatbot or the image generator belongs to an outside vendor, the organisation that puts it in front of EU customers, or publishes its output, is responsible for making sure the disclosure reaches the user. There is no automatic transfer of responsibility to the maker.
The third is geographic. The Regulation reaches providers and deployers established outside the Union when the system's output is used inside it. A non-EU business running AI-generated campaigns aimed at European audiences, or operating an assistant that serves customers in the Union, is in scope. A concrete example makes it clear: a marketing team producing synthetic material for a European campaign engages Article 50(2), and where a real person appears in the piece, the deepfake labelling duty in Article 50(4). The same technology that makes those pieces also feeds voice-cloning CEO fraud — even though no labelling duty will ever reach that criminal use.
Getting ready in practice
The work is not legal so much as a matter of inventory and process. The first step is knowing where user-facing AI lives: conversational assistants, content generators, tools that publish automatically, biometric systems. You cannot label what nobody knows exists, and this runs straight into a problem many organisations already carry — shadow AI, teams that have adopted generative tools without going through security or legal.
With an inventory in hand, four checks make the difference: that the conversational assistant states plainly, up front, that it is an AI, rather than in the small print; that the output of generative AI tools carries a machine-readable mark, required of the vendor by contract and tested to survive a crop or a re-compression; that a procedure exists to disclose deepfakes and AI-generated public-interest text; and that all of it is documented — which systems exist, which notices are given, which vendors mark their output — because that is what a market surveillance authority will ask for.
Folding this transparency into an AI management system under ISO/IEC 42001 avoids building a parallel process, and an organisation already working through EU AI Act compliance can treat Article 50 as one more control inside that framework. It is also worth coordinating with whoever already runs NIS2, DORA or national security schemes: the same committees, the same evidence cadence, so AI governance does not grow up as a separate silo. The same holds for the vendor relationship, which overlaps with third-party risk management.
One duty tends to be overlooked, and it lands on the very people operating these systems: Article 4 of the Regulation requires providers and deployers to ensure a sufficient level of AI literacy among their staff. It has applied since 2 February 2025, regardless of risk tier, and carries no fine of its own — but the Commission has made clear that a single onboarding video is not enough, and since 2 August 2025 inadequate training can weigh on liability if misuse causes harm. Whoever inventories their systems for Article 50 has already done half the work for Article 4: the same systems, the same people.
What ignoring it costs
The EU fine for breaching Article 50 reaches, under Article 99 of the Regulation, up to €15 million or 3% of total worldwide annual turnover, whichever is higher; for SMEs and start-ups the lower of the two applies, which changes the real exposure considerably. It is not the top tier of the Regulation — that is reserved for prohibited uses — but it is far from symbolic.
National regimes add a second layer. In Spain, for instance, a draft organic AI law still going through parliament would introduce its own penalties of up to €35 million or 7% for the most serious infringements — failing to label a deepfake among them — and names the national supervisory agency as coordinating authority. The distinction to keep in mind is that the European Regulation applies directly from 2 August whatever happens with national law, so waiting for a domestic statute does not defer the obligation. That immediacy is underscored by independent legal analysis of the Commission's final guidelines.
Beyond the fine there is a trust cost. Publishing synthetic content without marking it, or fielding an assistant that passes for human, are practices that can do brand damage hard to undo once exposed. Compliance costs less than rebuilding lost trust.
Article 50 does not require you to stop using AI; it requires you to say when you are using it. For an organisation that already treats security and compliance as one discipline — rather than two departments that only cross paths in the hallway — it is one more governance control: knowing which systems speak on its behalf, what they publish, and what mark they carry. Having that inventory in place on 2 August is what separates a minor adjustment from a scramble. To place this duty within Europe's wider direction, it helps to read it alongside the EU Action Plan on cybersecurity and AI and the accountability that NIS2 already puts on the board.