EU AI Act Article 50: which transparency obligations apply from 2 August 2026?

Compliance7 min read·
K

Kees van der Vlies

Partner | IT Auditor

Also available in:Nederlands

On 2 August 2026, Article 50 of the EU AI Act becomes applicable. While the debate about the AI Act often focuses on prohibited practices and high-risk systems, Article 50 affects a much broader group of organizations: anyone offering a chatbot, generating or publishing AI content, or using emotion recognition. The obligations themselves are manageable, but the division of roles matters. In this article we set out which obligation applies to whom, what has been postponed via the Digital Omnibus, and how to prepare in practice.

What is Article 50 about?

Article 50 contains transparency obligations for AI systems that do not need to be high-risk, but where people must be able to know they are dealing with AI. The idea: prevent deception. The article contains four main obligations, divided over two roles from the AI Act: the provider (the party that develops the AI system or places it on the market under its own name) and the deployer (the organization using the system under its own responsibility). Many organizations are both at once, for example when you build your own customer service bot on top of an external language model and offer it to users.

Obligation 1: say that it is AI (providers of interactive systems)

Providers of AI systems that interact directly with people, such as chatbots and voicebots, must design those systems so users know they are communicating with AI. The exception: when this is already obvious to a reasonably informed person from the context. In practice, the safe route is an explicit notice at the start of the interaction. A customer service bot posing as an employee, or a voicebot indistinguishable from a human, is exactly what this provision aims to prevent.

Obligation 2: mark synthetic content in a machine-readable way (providers of generative systems)

Providers of AI systems that generate synthetic audio, image, video or text must ensure the output is marked in a machine-readable format and detectable as artificially generated or manipulated. The technique must be effective, interoperable, robust and reliable as far as technically feasible. The AI Act does not prescribe a specific standard; in practice, C2PA is the most widely used standard for content credentials, often combined with watermarks. How this works technically, and where the pitfalls are, we cover in a separate article.

Important for planning: this is the obligation for which the Digital Omnibus arranges a partial postponement. For AI systems placed on the market before 2 August 2026, the marking obligations will only apply from 2 December 2026. For systems placed on the market from 2 August onwards, the obligation applies immediately. Note: the Digital Omnibus agreement (provisional agreement of 7 May 2026, adopted by the European Parliament on 16 June 2026) still awaits formal completion by the Council at the time of writing.

Obligation 3: inform people about emotion recognition and biometric categorisation (deployers)

Organizations using an emotion recognition or biometric categorisation system must inform the people exposed to it. Think of software estimating caller emotions in a contact center. This obligation rests with the deployer, the organization using the system, not the vendor. Keep in mind that some applications of emotion recognition (in the workplace and in education) have been prohibited since February 2025; Article 50 is only relevant for the applications that remain permitted.

Obligation 4: label deepfakes and AI text for the public (deployers)

Deployers who use AI to generate or manipulate image, audio or video that qualifies as a deepfake must disclose that the content has been artificially generated or manipulated. The same applies to AI-generated text published to inform the public on matters of public interest, unless there is human editorial control and a person or organization holds editorial responsibility. For art, satire and fiction there is a softer regime: the disclosure must not hamper the display of the work.

For the day-to-day practice of many companies this provision is more relevant than it seems. A marketing department publishing an AI-generated video of a recognizable person, or a communications team publishing AI news items without editorial control, quickly falls within its scope.

How must you inform?

For all obligations: the information must be provided no later than the first interaction or exposure, in a clear and distinguishable manner, and must be accessible. A reference buried in the terms and conditions is not sufficient. The European Commission has adopted guidelines on Article 50 that flesh out the open norms, and a Code of Practice for marking AI content is being developed. Following that code gives you a concrete way to demonstrate compliance.

What are the risks of non-compliance?

Violations of the transparency obligations can result in fines of up to EUR 15 million or 3% of global annual turnover, whichever is higher. For most organizations, reputational risk is at least as relevant: a chatbot posing as a human or an unlabeled deepfake is publicly sensitive. In addition, customers and regulators increasingly ask during audits and vendor assessments how transparency obligations have been secured.

Practical preparation in five steps

Start with an inventory: which AI systems interact with people, generate content, or perform emotion recognition? Use the AI inventory from your ISO 42001 program if you have one. Then determine your role per system: provider, deployer or both. Next, test per obligation what is already in place: does the chatbot have an AI notice, does your generation tooling mark its output, are disclosures present on published AI content? Record agreements with vendors: if you deploy an external generative system, you want contractual clarity on how the provider fulfils the marking obligation. And anchor everything in your management system: include the transparency obligations in your AI policy, assign owners and verify operation periodically, for example in your internal audit.

Want to know where your organization stands, or include Article 50 in a broader AI Act or ISO 42001 gap analysis? Feel free to contact us.

Frequently asked questions

Who does Article 50 of the EU AI Act apply to?+

To providers of AI systems that interact with people or generate synthetic content, and to deployers that use emotion recognition or biometric categorisation, publish deepfakes or publish AI-generated text on matters of public interest. Many organizations fulfil both roles at once.

When does Article 50 become applicable?+

On 2 August 2026. Via the Digital Omnibus one element has been postponed: the machine-readable marking obligations for AI systems placed on the market before 2 August 2026 will apply from 2 December 2026. For new systems the obligation applies immediately.

Does every chatbot have to disclose that it is AI?+

Providers must design interactive AI systems so users know they are communicating with AI, unless this is already obvious to a reasonably informed person from the context. In practice, an explicit notice at the start of the interaction is the safe route.

What are the fines for violating Article 50?+

Up to EUR 15 million or 3% of global annual turnover, whichever is higher. Reputational risk and questions from customers and regulators during audits increasingly matter as well.

Does the AI Act prescribe a specific marking standard?+

No. The marking must be machine-readable, effective, interoperable, robust and reliable as far as technically feasible. In practice, C2PA is the most common standard for content credentials, often combined with watermarks. A European Code of Practice is also being developed.

Need help with compliance?

Need to comply with ISO 27001, ISO 42001, NEN 7510, NIS2 or DORA, or do you need a SOC 2 report? We guide you through the entire process: from gap analysis to implementation.

Explore Compliance Services

About the author

K
Kees van der Vlies

Partner | IT Auditor

Back to knowledge base

Have a question?

Get in touch for advice on IT audit, compliance and information security.

Contact us