GovCompass

Art. 50 EU AI Act, transparency: inform users about AI interaction

By GovCompass.ai· Last updated August 2026· Aligned with the consolidated EU AI Act, including the 2026 Omnibus amendments.

Art. 50 of the EU AI Act sets four transparency duties: providers must ensure people know they are interacting with an AI system and must mark AI-generated content in a machine-readable way; deployers must inform people exposed to emotion recognition or biometric categorization and must disclose deep fakes and AI-generated text on matters of public interest. The obligations apply from 2 August 2026, with fines up to €15 million or 3% of global annual turnover, whichever is higher. One transition applies: generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty.

Part of the wider governance context. This article explains one provision of the EU AI Act. How that provision fits into AI governance as a whole, from the seven pillars of responsible AI to the controls that keep systems inside agreed boundaries, starts at What is AI governance.

Among all EU AI ActEU AI ActRegulation (EU) 2024/1689, the European Union's law on artificial intelligence. It takes a risk-based approach: prohibited practices, requirements for high-risk AI systems, transparency obligations for specific uses, and a separate regime for general-purpose AI models. Obligations are divided between providers and deployers. See general-purpose AI, conformity assessment.Open full entry → obligations, Art. 50 is the next to take effect for most organizations: 2 August 2026. Organizations that provide or deploy chatbots, generative AIgenerative AIAI systems that produce new content (text, images, audio, code) rather than only classifying or predicting. Large language models are the prominent example.Open full entry → tools, emotion recognitionemotion recognitionAn AI system that infers a person's emotions from biometric data; its use in workplaces and education is restricted under the AI Act.Open full entry → or synthetic content face a concrete deadline, not a theoretical obligation.

What is Art. 50 and who does it apply to?

Art. 50 contains transparencytransparencyOpenness about the fact that AI is used and how it operates in general: disclosures, documentation, notices. Pairs with explainability, which addresses individual outcomes.Open full entry → obligations for AI systemsAI systemA machine-based system that, for explicit or implicit objectives, infers from input how to generate outputs (predictions, content, recommendations or decisions) that can influence physical or virtual environments. The OECD-style definition followed by the EU AI Act.Open full entry → that interact directly with people or generate content that could be mistaken for real. The law distinguishes three groups of obligated parties:

  • ProvidersproviderThe actor who develops an AI system (or has it developed) and places it on the market or into service under its own name. It carries manufacturer-style duties: design controls, documentation, conformity.Open full entry →: organizations that place AI systems on the market, they must technically enable systems to fulfill the information obligation
  • DeployersdeployerAn organization using an AI system under its own authority in its activities. It carries the operator duties: use per instructions, oversight, input relevance, monitoring, notices.Open full entry →: organizations using AI systems in their processes, they are responsible for actually informing users
  • Not covered: parties that only host, transmit, or disseminate AI-generated content made by others, including online platforms. The Commission guidelines confirm they are not deployers when they have no authority over the AI system, though they are encouraged to preserve any marking the content carries.

For most organizations, the deployer role is most relevant.

Which systems does Art. 50 cover?

Art. 50 targets four categories of AI applications:

1. Chatbots and conversational AI (Art. 50(1), provider duty)
Any AI system intended to interact directly with people must be designed so the person knows they are interacting with AI, unless that is obvious to a reasonably well-informed and observant person in the context. This applies to customer service bots, HR assistants, digital coaches, legal information systems and similar applications.

2. AI-generated content marking (Art. 50(2), provider duty)
Providers of AI systems that generate synthetic audio, image, video or text, including general-purpose AIgeneral-purpose AIA model trained on broad data that can be adapted to many downstream tasks; the AI Act sets specific obligations for it, with extra duties when it poses systemic risk.Open full entry → systems, must mark the outputs in a machine-readable format and make them detectable as artificially generated or manipulated. Techniques include watermarks, metadata and cryptographic methods; the solution must be effective, interoperable, robust and reliable as far as technically feasible, and providers may rely on marking implemented at the model level upstream. The duty does not apply where the system only performs an assistive function for standard editing or does not substantially alter the input. Organizations that integrate a third-party model into their own user-facing tool are providers of that system and carry this duty themselves.

3. Emotion recognition and biometric categorizationbiometric categorizationSorting people into categories such as ethnicity or political views from their biometric data; restricted or prohibited under the AI Act.Open full entry → (Art. 50(3), deployer duty)
Deployers must inform the people exposed to an emotion recognition or biometric categorization system of its operation, and must process the personal data involved in line with the GDPRGDPRRegulation (EU) 2016/679, the General Data Protection Regulation, the EU's law on the processing of personal data. It applies to AI wherever personal data enters training, inputs, outputs, or logs, and it operates alongside the EU AI Act rather than being replaced by it. See controller, processor, lawful basis, DPIA.Open full entry →. The exception covers systems permitted by law to detect, prevent or investigate criminal offences. First check Art. 5: several emotion recognition and biometric categorization uses are prohibited outright before Art. 50(3) ever becomes relevant.

4. Deep fakes and AI-generated text (Art. 50(4), deployer duty)
Deployers of a system that generates or manipulates image, audio or video constituting a deep fake must disclose the artificial origin. For evidently artistic, creative, satirical or fictional work the duty is reduced: disclosure in a way that does not spoil the work. Deployers must also disclose AI-generated or manipulated text that is published to inform the public on matters of public interest.

What must you communicate, and how?

The information obligation has two dimensions: what you communicate and when you communicate it.

What: Users must know they are interacting with an AI system. You do not need to disclose how the system works, but you may not hide or actively deny the AI nature.

When: The information must reach the user at the moment of the interaction or before it. Informing afterwards is not enough. A footnote in the privacyprivacyThe principle that personal data used by or produced through an AI system stays within the purpose and the legal basis it was collected for. Three routes cause most of the trouble: personal data in training material that was never intended for it, model output that reproduces what the model retained, and purpose creep, where a system built for one use drifts into another the original basis never covered. The GDPR governs this in full, and the EU AI Act adds data governance duties for high-risk systems (Article 10). See DPIA, purpose limitation, responsible AI.Open full entry → policy is not enough. The communication must be active, comprehensible and timely. The Commission guidelines add that disclosures hidden in manuals or shown only once may not be enough; for systems people interact with over time, repeated disclosure can be required.

How: The law prescribes no specific format. Common approaches include a visible badge ("You are speaking with an AI assistant"), an opening message when a chat starts, or a clear visual marker on AI-generated content. The average user must understand it without legal training.

Exception: internal business processes

Art. 50.1 includes an important exception: the information obligation does not apply when it is evident to the natural personnatural personA living human individual, as distinct from a legal person such as a company; the holder of data-protection and AI-Act rights.Open full entry → that they are interacting with an AI system. This is relevant for internal applications where employees explicitly work with an AI tool and know its AI nature.

But note: the Commission guidelines interpret "obvious" narrowly, using the average user of the intended audience as the benchmark and weighing whether vulnerable groups are part of that audience. A code assistant available only to professional developersdeveloperThe actor who technically builds and trains an AI model or system; in most laws this function is absorbed into the provider role.Open full entry → may meet the threshold; a public-facing chatbot rarely will. If there is any doubt, the information obligation applies. Document explicitly why you consider an application to fall under the exception.

Relationship to Art. 26(11), deployer transparency towards those affected

Art. 50 is not the only transparency obligation. Art. 26(11) requires deployers using high-riskriskIn the EU AI Act's terms, the combination of the likelihood that a harm occurs and the severity of it if it does. The link between a principle (via the harm that would breach it) and a control (the measure that reduces it). Naming the harm and assessing its risk is required by Art. 9 before any mitigation measure is chosen. See harm, control, residual risk.Open full entry → AI to inform affected personsaffected personsThe individuals or groups who are subject to or impacted by an AI system's outputs or decisions, and whose rights the governance regime aims to protect.Open full entry → about the deployment of that system. This goes further than Art. 50: it also covers systems where no direct interaction occurs but where a person is directly assessed (such as CV screening or credit scoring).

For high-risk AI, you must comply with both at once: Art. 50 (interaction transparency) and Art. 26(11) (assessment transparency). They complement each other.

Deadline and enforcement

Art. 50 takes effect on 2 August 2026 for all systems in scope, regardless of when they were first placed on the market. One transition applies: under the digital omnibusDigital OmnibusAn EU amending package that adjusts parts of the EU AI Act, including the application dates for high-risk obligations. As of July 2026 it has been adopted by the European Parliament and the Council and awaits publication in the Official Journal; verify the current status and dates against the official text. See EU AI Act.Open full entry →, adopted and awaiting publication in the Official Journal as of July 2026, providers of generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking duty of Art. 50(2). Systems placed on the market from 2 August 2026 must comply from day one, and content already published before that date does not need to be marked retroactively. The maximum fine for a violation of Art. 50 is €15 million or 3% of global annual turnover, whichever is higher; verify the transition dates against the official text once the omnibus is published.

Beyond direct enforcement, there is the risk of complaints from consumers and affected individuals through national supervisory authorities.

The Commission guidelines and the Code of Practice

Two instruments make Art. 50 concrete. The Commission guidelines cover the whole article and interpret its scope: the consultation on the draft closed on 3 June 2026 and the final version is expected before the August deadline. The Code of Practice on Transparency of AI-Generated Content covers only Art. 50(2) and 50(4): it was finalized in June 2026, is voluntary, and once assessed as adequate lets signatories demonstrate compliance through adherence, including uniform EU icons and text labels for deep fakes. Providers and deployers can sign the two sections separately; the first list of signatories closes on 22 July 2026.

The guidelines settle several questions that mattered in practice. Open-source AI systems fall fully under Art. 50. The personal-use exception stops where content affects public debate. Actors that only disseminate third-party AI content are not deployers. A narrow carve-out exists for strictly technical outputs used inside a closed professional group, and for synthetic content generated as part of gameplay where the fictional context is obvious. And for agentic AIagentic AISystems where a model takes actions (calling tools, executing multi-step plans), amplifying both capability and every failure mode; governed with action allowlists, approvals and full logging.Open full entry →, the guidelines take a wide view: when a provider cannot reliably assess whether an AI agentAI agentA system that perceives its environment, decides and takes actions toward a goal (calling tools, executing plans). Autonomy of action demands allowlists, approval gates, sandboxing, logging and a kill switch.Open full entry → will interact with a person, the agent should disclose its artificial nature wherever such interaction is reasonably foreseeable. What that means for governing agents more broadly is covered in the agentic AI cornerstone.

Practical steps for compliance before 2 August 2026

Step 1, Inventory all AI systems with direct user interaction. List all chatbots, generative AI tools, emotion analysis systems and synthetic content tools your organization provides, uses or publishes. Include built-in AI in existing software, AI functions in CRM, customer service platforms or communication tools.

Step 2, Assess per system whether the information obligation applies. Does the exception apply (evident to the user)? Or is informing required? Record the reasoning.

Step 3, Implement the information disclosure. Make the AI nature visible at the moment of interaction. Test whether the average user understands it. Record what you implemented and when.

Step 4, Coordinate with your vendors. Providers must make their systems technically suitable for Art. 50 compliance. Verify with your SaaS vendors whether they have implemented the required functionality. Establish contractually who is responsible for which part of the information provision.

Step 5, Document for your compliance file. The supervisory authority may request evidenceevidenceThe concrete proof that a control is designed, implemented, and working: a test report, an audit trail, an impact assessment, a monitoring log. Each link in the governance chain produces an artifact, and together they are what an organization hands to its own board, a regulator, a customer, or an affected person to show, not say, that a system is governed. Its absence is itself the failure: a risk register without test results, or a mitigation claimed without validation, is a governance gap, not a paperwork one. The closing link of the governance chain. See control, governance.Open full entry → of compliance. Keep screenshots, process descriptions and vendor confirmations. A compliance file with timestamps is your strongest defense.

The deadline is close

Art. 50 is not a heavy technical implementation, but it does require action before 2 August 2026. Most organizations need to review and adjust their chatbots, customer service systems and content pipelines, and providers of generative systems need their marking solution in place. If vendors must act as well, the remaining weeks are tight. Start now.

Frequently asked questions

When does Article 50 of the EU AI Act apply?
From 2 August 2026, for every AI system in scope, regardless of when it was first placed on the market. The only transition is the machine-readable marking duty of Art. 50(2): generative AI systems already on the market before 2 August 2026 have until 2 December 2026.
Does the December 2026 transition apply to new AI systems?
No. Generative AI systems placed on the market or put into service from 2 August 2026 must meet the marking duty from day one. The transition only covers systems already on the market before that date.
Who must mark AI-generated content?
The provider of the AI system that generates it, including organizations that build a user-facing tool on top of a third-party model. Deployers carry the separate duty to disclose deep fakes and AI-generated text on matters of public interest.
Are open-source AI systems exempt from Article 50?
No. The Commission guidelines confirm that systems released under free and open-source licenses fall fully under the transparency obligations.
What is the fine for violating Article 50?
Up to €15 million or 3% of total worldwide annual turnover, whichever is higher. EU institutions face fines up to €750,000.
Legal referencesArt. 50
Share Share on LinkedIn