Article 50 transparency: chatbots, deepfakes, and synthetic content

Most product teams that conclude "we have no high-risk AI" stop reading the AI Act too early. Article 50 attaches to ordinary features — support chatbots, image generators, AI-written content — and it applies from August 2, 2026.

Updated July 24, 2026 · Informational guidance, not legal advice

Why Article 50 is the obligation most teams actually have

The high-risk regime gets the attention, but Annex III is a list of specific use areas — hiring, credit, education, essential services — and plenty of AI-heavy products sit in none of them. Article 50 works differently: it attaches to interaction and content-generation patterns that are everywhere. A support chatbot, an AI copilot, a text-to-image feature, an AI-drafted newsletter — each can carry a duty under Article 50 even though nothing about the product is high-risk. These duties sit on top of any high-risk obligations, not instead of them.

The five duties, and who carries each

  • Providers of AI systems that interact directly with people must design them so those people are informed they are dealing with AI — unless that is obvious to a reasonably well-informed, observant person in the context. If users could plausibly believe your chatbot is a human agent, it needs to say otherwise.
  • Providers of systems generating synthetic audio, images, video, or text must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated — watermarking or provenance metadata, to the state of the art. Assistive functions and standard editing that does not substantially alter the input are excepted.
  • Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them, and handle the personal data involved per GDPR.
  • Deployers of deepfake systems — image, audio, or video content appreciably resembling real persons, places, or events that would falsely appear authentic — must disclose that the content is artificially generated or manipulated. For evidently artistic, creative, or satirical work, disclosure still applies, but in a way that does not hamper display or enjoyment of the work.
  • Deployers publishing AI-generated or manipulated text to inform the public on matters of public interest must disclose it is artificially generated — unless the content underwent human review or editorial control and a natural or legal person holds editorial responsibility for it.

Timing and delivery of the disclosure

The information must be provided clearly and distinguishably, at the latest at the time of the first interaction or exposure. A disclosure buried in terms of service is not "clear and distinguishable" at first interaction; a label in the interface at the moment of use is.

Dates and consequences

Article 50 applies from August 2, 2026, and was not deferred by the Digital Omnibus on AI — which moved the Annex III high-risk regime to December 2, 2027. For many product teams that makes Article 50 the nearest obligation in the Act rather than a footnote to the high-risk work.

One narrow grace period exists: systems placed on the market before August 2, 2026 have until December 2, 2026 to meet the Article 50(2) machine-readable marking and detection obligation. Every other limb — the 50(1) interaction duty, the 50(3) emotion-recognition information duty, and the 50(4) deepfake and public-interest-text duties — applies from August 2, 2026 regardless of when the system shipped.

What a breach costs

Infringement of Article 50 carries administrative fines of up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher, with proportionality considered for SMEs and small mid-caps. Enforcement sits with national market surveillance authorities.

What this means for a typical product portfolio

Walking a portfolio through Article 50 usually takes an afternoon, and it changes the launch checklist more often than the architecture:

  • Support chatbot or in-app copilot: usually not Annex III, but the 50(1) interaction duty applies — confirm the interface identifies it as AI where that is not already obvious.
  • Text-to-image, voice synthesis, or video generation features: as provider, machine-readable marking of outputs is your build item — check what your model vendor emits and what survives your pipeline.
  • Marketing or content teams publishing AI-drafted articles on matters of public interest: either add the disclosure or run genuine human editorial review with named responsibility — and record which one you chose per channel.
  • Any use of emotion inference in the product (interview analytics, call-centre sentiment on identified individuals): the deployer information duty applies, and check Article 5 first — some emotion-recognition contexts, like workplaces and schools, are prohibited outright rather than merely transparency-bound.

The evidence pattern is the same as everywhere else in the Act: a register entry per system, the applicable 50(x) duties mapped, the disclosure or marking mechanism described, and an owner who confirms it still works when the feature changes.

Common misreadings

  • "We're not high-risk, so nothing applies" — Article 50 attaches regardless of risk class, and Article 4 literacy applies to every organization using AI.
  • "It's obvious it's a bot" — the exception is for what is obvious to a reasonably well-informed person in context; a human-named agent persona with a profile photo undermines that argument.
  • "The model provider watermarks, so we're done" — check that the marking survives your post-processing, cropping, and export paths; the duty is that outputs are marked when they leave your system.
  • "Internal-only tools are exempt from everything" — the interaction duty concerns the people interacting with the system; employees count as people.

Walk your systems through Article 50 in one sitting

The free Attevera assessment covers Articles 4, 5, 6, and 50 plus Annex I and III — and tells you which transparency duties attach to each feature. No signup.

Run the free assessment

Frequently asked questions

Does Article 50 apply before August 2026?

The Article 50 transparency obligations apply from August 2, 2026. They were not deferred by the Digital Omnibus on AI, which moved the Annex III high-risk regime to December 2, 2027. Prohibitions (Article 5) and the literacy duty (Article 4) have applied since February 2025, so a portfolio review should check those at the same time.

Our chatbot is clearly labelled 'AI Assistant'. Is that enough for 50(1)?

A clear, visible label at the point of interaction is the pattern the duty describes — informed at first interaction, clearly and distinguishably. What undermines it is presenting the bot as a named human agent, or disclosing only in fine print. This is informational guidance, not legal advice.

We generate images with a third-party model API. Who owes the machine-readable marking?

The marking duty sits with the provider of the generating system. If you ship the generation feature under your own name, you are typically that provider — relying on the upstream model's watermark is fine only if it actually persists through your pipeline into what users download.

Does AI-assisted writing always need a disclosure label?

No. The text duty is scoped to content published to inform the public on matters of public interest, and it falls away where there is human review or editorial control with named responsibility. A product changelog drafted with AI and edited by your team is a different case from an unreviewed AI-written news feed.

Keep reading