Everything You Need to Know About EU AI Act Transparency Obligations (Article 50)

The EU AI Act’s transparency obligations come into effect on August 2, 2026. If you build or deploy AI systems that interact with people or generate content, Article 50 requires you to tell people what they’re interacting with. These obligations aren’t risk-tiered the way the rest of the Act is. A system doesn’t have to be high-risk to trigger them. If it fits one of the categories, disclosure applies.

The Digital Omnibus on AI pushed the high-risk deadlines back by more than a year, however, the transparency obligations still come into effect on August 2, 2026. If you were counting on the Omnibus to buy you time here, it doesn’t. There’s one narrow exception for generative systems already on the market, which we cover in the FAQ below.

Article 50 breaks into four obligations, split between two roles. Providers build systems and place them on the market. Deployers use those systems under their own authority. Here’s who owns what.

  • Providers of AI systems that interact directly with people must design the system so users know they’re dealing with AI, unless that’s already obvious to a reasonably well-informed person.
  • Providers of AI systems that generate synthetic content (audio, image, video, or text) must mark outputs as artificially generated in a machine-readable, detectable format.
  • Deployers of emotion recognition and biometric categorization systems must notify the people subject to them and process the data in line with EU data protection law.
  • Deployers of AI systems that generate deepfakes or publish AI-generated text on matters of public interest must disclose the artificial origin of that content. Limited exceptions apply for evidently artistic or satirical work, and for text that 1) goes through genuine human editorial review and 2) has a human who accepts responsibility for the work.

For every obligation, the disclosure has to reach the person in a clear and distinguishable way, in an accessible format, and no later than their first interaction with the system.

Two documents from the European Commission help you work out whether you’re in scope and what compliance looks like. The first is the Guidelines on the implementation of Article 50, published in final form on July 20, 2026, which function as the de facto standard for meeting the transparency requirements. The second is the Code of Practice on transparency of AI-generated content, published in June 2026, which sets out concrete measures for the marking and labeling obligations. Signing a code the AI Office deems adequate becomes a straightforward way to demonstrate compliance, though it isn’t the only route.

For most governance teams, the practical task is proving these disclosures are in place by August 2. Trustible tracks this through our controls. Systems flagged with transparency obligations get tasks in the use case profile that satisfy the requirements, such as uploading examples of the disclosures in use.

The Deadline and What Satisfies It

August 2, 2026 is the date all four obligations apply. There’s no separate registration step, no filing, and no certificate to obtain. The obligation is to have the disclosures in place and to be able to demonstrate compliance if a market surveillance authority asks.

What “satisfies” each obligation differs by role.

EU AI Act · Article 50
Trustible

One deadline, four obligations: August 2, 2026

No registration. No filing. No certificate — just disclosures you can prove are in place if a market surveillance authority asks.

Providers design & documentation
Article 50(1)

Disclose the interaction

Tell the user they’re talking to AI by the first interaction — clear, distinguishable, accessible. A chatbot greeting, a spoken intro, or a persistent label all work. Buried terms and conditions don’t.

Article 50(2)

Mark the output

Generated content needs a machine-readable mark plus a matching detection method — not just a visible “made with AI” label. Think signed metadata and watermarking, usually layered together.

Deployers process & evidence
Article 50(3)

Notify before profiling

Running emotion recognition or biometric categorization? Notify the people exposed to it, and handle the underlying data under EU data protection law.

Article 50(4)

Label the deepfake

Deepfakes and AI-generated public-interest text need a clear, perceivable label. An optional EU icon offers a ready pathway — an equivalent label works too.

Across all four obligations, evidence means documentation you hold: records of the technical solution and how it meets the quality requirements, a description of your disclosure method, concrete examples of it in use, and the internal process that keeps content labeled consistently. Adhering to an adequate code of practice is itself a recognized way to demonstrate compliance, and it narrows what authorities will scrutinize.

Article 50 FAQ

EU AI Act · Article 50

Work system by system against function, not risk tier. A system is in scope if it hits any of the four triggers, and it can hit more than one. First, does it interact directly with people (a chatbot, voice assistant, agent that talks to users)? That’s 50(1), on the provider. Second, does it generate or manipulate synthetic audio, image, video, or text beyond standard editing? That’s 50(2), on the provider. Third, is it an emotion recognition or biometric categorization system? That’s 50(3), on the deployer. Fourth, does a deployer use it to produce deepfakes or public-interest text? That’s 50(4), on the deployer.

Then apply two filters. Check the exceptions: obvious AI interaction, genuine standard editing, editorial control over published text, law enforcement authorization. The reliable way to run this is off a current AI inventory, screening each use case through those four questions and recording the determination and its basis, so that if a market surveillance authority asks, the scoping decision is documented rather than reconstructed.

Article 13 covers transparency for high-risk systems only. Article 50 covers a different set of transparency obligations that can apply to any system. Article 13 requires providers of high-risk systems to give deployers clear instructions for use, so a professional can operate the system correctly and meet their own obligations. Article 50 is about informing the people exposed to the system or its output that AI is involved.

Article 13 transparency is documentation flowing to a business user. Article 50 transparency is disclosure flowing to end users and the public. A single system can be subject to both at once, and the guidelines confirm the obligations apply cumulatively.

Yes. Article 50 is a separate transparency track that applies based on what the system does, not its risk classification. A system can fall under Article 50 without being high-risk, be high-risk without triggering Article 50, or be both. Don’t assume that dodging high-risk classification gets you out of transparency duties.

Yes, and often under two obligations at once. An agent that interacts directly with people falls under 50(1), so it has to make clear it’s an AI. The guidelines add a practical rule for agents: where you can’t reliably predict whether an agent will end up interacting with a natural person, instruct it to identify itself as AI in any situation where that’s likely. Coding agents and other agentic systems are named as in scope.

Separately, when an agent produces audio, image, video, or text that a person will see or hear, that output falls under 50(2) and has to be marked and detectable. Actions an agent takes that aren’t meant to be perceived by people, like a background web request or an API call, aren’t synthetic content and don’t need marking. The question isn’t whether you’re running an agent. It’s whether the agent talks to people and whether it emits content people perceive.

Mostly no. The Digital Omnibus postponed the high-risk deadlines, but the Article 50 transparency obligations stayed on the original August 2, 2026 schedule. The only Article 50 relief is a four-month grace period for providers of generative systems placed on the market before August 2, 2026. They would have until December 2, 2026 before the 50(2) machine-readable marking obligation applies. Systems placed on the market on or after August 2 get no grace period.

The grace period covers only the marking obligation, not the rest of Article 50. The duty to disclose AI interaction, to notify people subject to emotion recognition or biometric categorization, and to label deepfakes and public-interest text all proceed from August 2 regardless. If you build generative systems, design marking in now rather than banking on the runway.

For providers under 50(2), the marking has to be machine-readable and detectable, which means a visible “made with AI” label on its own does not satisfy it. The Code of Practice points to techniques like digitally signed metadata and imperceptible watermarking, generally layered together because no single technique currently meets all four quality requirements for content that can travel online. Providers also have to make a detection method available, not just mark the content.

This is separate from the visible label a deployer applies under 50(4). The two obligations stack.

The Commission's optional AI labeling icons and when each one applies.

Pick what meets the four requirements for your content type, not a particular brand. Article 50 is technology-neutral. It names no specific format, and Recital 133 lists watermarks, metadata, cryptographic provenance, fingerprints, and logging as acceptable techniques, alone or combined. What the standard has to do is meet the four quality requirements (effective, interoperable, robust, and reliable), track the state of the art, and come paired with a detection method.

C2PA Content Credentials is one common way to satisfy the provenance-and-metadata side, and it’s widely adopted enough to help with the interoperability requirement. However, it isn’t mandated, and metadata alone tends to be fragile once content travels, so in practice providers layer it with watermarking. The guidelines also push toward publicly available, industry-standard detection solutions where they exist.

It means a solution that can be implemented for the content type in question using currently available technology, methods, and engineering practices within your actual technical setup. It doesn’t flex to the resources or capabilities of an individual provider, so “we’re small” isn’t the argument. It means you aren’t required to use something that doesn’t exist yet or isn’t on the market.

You also have to track the generally acknowledged state of the art, meaning accepted good practice, not the newest experimental research. Cost can be weighed in narrow cases where the expense is out of proportion to how much it would actually help people tell AI content apart. And there are a few defined carve-outs, such as a generative system embedded in a closed, instructive product whose output never leaves it, like in-vehicle navigation, or strictly technical output seen only by a limited, predefined set of professionals inside one organization.

Often not. The guidelines carve out narrowly defined cases where a generative system’s output is strictly technical, stays inside a closed professional environment, and is only seen by a limited, predefined set of people acting in a professional capacity, with safeguards against it leaking out. Think internal engineering or production workflows. If the output is intended to leave the organization or be verifiable by outsiders, the exemption doesn’t hold.

The line is whether the AI changes the content’s meaning, style, or intent. If it only prepares existing content for publication, that’s exempt standard editing. If it shifts meaning, style, or intent, that’s a substantive change and needs marking. Standard editing includes grammar and spelling fixes, format conversion, noise reduction, minor cropping, or color correction.

The guidelines treat AI-generated translations and summaries, adding or removing objects from an image, or blurring a face as substantive changes that require marking. When a tool can do both, the obligation attaches only to the outputs that cross into substantive change.

Generally no. Content that was AI-generated or manipulated before August 2, 2026 doesn’t have to be marked or labeled retroactively. That covers both the machine-readable marking under 50(2) and deepfake labeling under 50(4). However, text on matters of public interest that was generated before the date but published on or after it does need labeling, because the trigger is publication.

The guidelines encourage but do not require applying labels to pre-existing deepfakes already in circulation, but they’re clear you aren’t expected to undertake disproportionate effort like auditing back catalogs or reprinting packaging.

A deepfake is an AI-generated or manipulated image, audio, or video that appreciably resembles real persons, objects, places, entities, or events and would falsely appear authentic or truthful. The resemblance has to be to something that could exist in reality. The guidelines’ own examples put clearly unrealistic content, such as a sphinx over the Eiffel Tower or mice arguing about cheese, outside the deepfake definition. However, a realistic AI video of a politician giving a speech is in scope.

Intent to deceive is not part of the test, and audience matters. If children or less digitally literate viewers might be fooled, that weighs toward it being a deepfake.

Only when the text is published to inform the public on matters of public interest, and only if it hasn’t had genuine human editorial control. The public-interest bar covers topics meriting public debate, such as public administration, health, the environment, consumer safety, or political and economic developments. It doesn’t cover fiction, entertainment, or ordinary advertising.

There’s a crucial exception. If the AI-generated text undergoes real human review or editorial control and a named person or entity holds editorial responsibility for it, no label is required. The guidelines are explicit that a superficial spellcheck or rubber-stamp approval doesn’t count as editorial control.

A provider develops an AI system (or has it developed) and places it on the market under its own name. A deployer uses a system under its own authority for professional purposes. The distinction matters because 50(1) and 50(2) land on providers, while 50(3) and 50(4) land on deployers.

And yes, you can be both at once, for instance if you build a system and also use it in your business. The guidelines note operators can hold more than one role for the same system, so you may carry provider and deployer obligations simultaneously.

Notification and disclosure only. Article 50 obligates you to inform people that they’re interacting with AI, that content is artificially generated, or that an emotion recognition or biometric system is operating. Consent can still be required, but it comes from elsewhere, chiefly EU data protection law: an emotion recognition or biometric categorization system under 50(3) will usually involve processing that needs its own lawful basis under the GDPR, which may mean consent.

Article 50 answers “did you tell them.” GDPR answers “were you allowed to.” And both can apply to the same system at once.

It can. The Act applies to providers and deployers outside the EU when the output of the AI system is used in the Union. A third-country provider whose generative system produces outputs used in the EU can fall under 50(2), and a third-country deployer generating a deepfake shown in the EU can fall under 50(4). Location of establishment isn’t the test. Where the output lands is.

The structures are opposite. Article 50 is horizontal: one regime, applying across all AI systems by function (interactive, generative, emotion/biometric, deepfake) regardless of sector. The US has no comprehensive federal AI-labeling law as of mid-2026. Federally, the TAKE IT DOWN Act targets non-consensual intimate imagery through platform takedown, not general labeling. At the state level, roughly 30 states regulate election-related deepfakes, and most states address sexual deepfakes.

California is the closest analog to the generative-content piece: SB 942, the AI Transparency Act, requires providers to offer watermarks, latent disclosures, and detection tools from August 2, 2026, and AB 3211 pushes platform-level provenance labeling with C2PA metadata. The practical upshot for a US company is that Article 50 gives you one clear obligation set to build to, while US compliance means tracking harm-specific rules jurisdiction by jurisdiction.

Evidence is documentation you hold and can produce on request. For the marking and detection obligation, that means records of the technical solution you use and how it meets the effectiveness, robustness, reliability, and interoperability requirements. For deployer labeling, it means a description of your disclosure method and concrete examples of it in use, plus the internal process that ensures content gets labeled consistently. Adhering to an adequate code of practice is itself a recognized way to demonstrate compliance.

Breaching Article 50 can draw fines up to EUR 15 million or 3% of total worldwide annual turnover, whichever is higher (lower caps apply to EU institutions). Enforcement runs through national market surveillance authorities, on their own initiative or after a complaint.

Signing a code of practice deemed adequate is the cleanest way to demonstrate compliance and lets authorities focus on whether you followed the code. Non-signatories have to show compliance by other adequate means and may face more detailed information requests.

Trustible treats Article 50 as a set of controls tied to your AI inventory. When a use case is flagged as carrying transparency obligations, the platform generates tasks in that use case’s profile that map to what Article 50 requires, such as documenting and uploading examples of the disclosures you’ve implemented. That gives you an audit trail showing the disclosures existed and were in place, which is exactly what a market surveillance authority will ask about.

Related posts

4 Ways to Prepare for Upcoming AI Regulations

Governments and regulators around the world are taking a closer look at how to manage the AI’s potential risks and

Trustible Emerges from Stealth to Enable Responsible AI Governance Amid Growing Regulatory Concerns

Read Trustible's press release about its emergence from stealth and fundraising announcement.

In this article

    AI Clarity Starts Here

    Share

    Newsletter
    Weekly AI governance insights from the Trustible team.

    AI clarity is a growth strategy

    See how Trustible helps governance teams approve more AI, faster.