Clef · Try the live demo →
EU AI Act · Article 50

The obligation that arrived while everyone watched the one that left

2 August 2026 was supposed to bring two things: the high-risk regime and the transparency duties. Only the first moved. Article 50 has applied since that date, and unlike the high-risk machinery it reaches ordinary organisations the moment they run a chatbot or publish something a machine helped write.

What Article 50 requires

Five paragraphs with obligations, addressed to different parties. The role column decides whether the duty sits with you or with your supplier.

Article 50(1)Provider

People must know they are talking to a machine

Systems intended to interact directly with natural persons must disclose that fact, unless it is obvious from the circumstances. Assembling a chatbot from a model API makes you the provider of that chatbot, and the duty is yours.

Article 50(2)Provider

Mark generated content machine-readably

Synthetic audio, image, video and text must be marked in a machine-readable format and detectable as artificially generated or manipulated. This is the file-level marking, not the visible notice.

Article 50(3)Deployer

Disclose emotion recognition and biometric categorisation

Persons exposed to such systems must be informed. In the workplace, emotion inference is prohibited outright under Article 5 — this covers the remaining permitted cases.

Article 50(4)Deployer

Disclose deepfakes and public-interest text

Image, audio or video resembling real persons or events must be disclosed as artificially generated. So must published text informing the public on matters of public interest — unless the content underwent human review and a person bears editorial responsibility for it.

Article 50(5)both

At first interaction, clearly

The information must be provided no later than the first interaction or exposure, in a clear and distinguishable manner. Not in a document the person would have to go looking for.

Who it actually reaches

The common assumption is that transparency is the vendor's problem. For the machine-readable marking that holds — the generating tool supplies it. For two situations it does not, and both occur in ordinary organisations.

First, the assistant you assembled. Wiring a model API to your own instructions and exposing the result to customers or applicants is not merely operating someone else's software. For that system you are the provider, with the disclosure duty of paragraph 1. In practice this is one sentence in the right place — but it has to be in the right place.

Second, what you publish. Paragraph 4 reaches text published to inform the public on matters of public interest. That is narrower than it first sounds — a product page is not caught — and wider than most would like: a post on a regulatory topic, a position statement, a technical article can be. The duty falls away where a human reviewed the content and someone bears editorial responsibility. That, rather than labelling, is the workable route.

What is rarely caught: the internal draft, the note, the summary for your own use. Article 50 attaches to publication and to encounters with third parties, not to use inside the building.

Three questions, one afternoon

Does anything of ours speak directly to people — a website chatbot, a phone assistant, an automated mailbox reply? If so, is the notice at the start of the conversation rather than in a policy page?Do we publish text or images a model helped produce? If so, who reviews them, and is it written down that they did?Does any bought-in software infer emotion or categorise biometrically?

The documented review step is worth more than the notice itself. It satisfies the exception in paragraph 4, it evidences diligence if the question is ever asked, and it is the better way to work in any case. One line per published item is enough — who reviewed it, when, and that they stand behind it.

Frequently asked

When did Article 50 start to apply?+

2 August 2026, as originally scheduled. This is worth stating plainly because the same date was supposed to bring the Annex III high-risk obligations, which Regulation (EU) 2026/1744 moved to 2 December 2027. Article 50 was left untouched. Reading the date as fully postponed means missing the only obligation that actually arrived in 2026 for ordinary deployers.

Is this the vendor’s problem or ours?+

Both, split by paragraph. The machine-readable marking under 50(2) is owed by the provider of the generating system. Disclosure for deepfakes and for published public-interest text under 50(4) is owed by the deployer — by you, the moment you publish. And anyone who assembles a chatbot from an API is the provider of that chatbot for the purposes of 50(1).

Do we have to label every AI-assisted text?+

Far from every one. Paragraph 4 covers text published to inform the public on matters of public interest, and even there the duty falls away where the content underwent human review and a natural or legal person holds editorial responsibility. A draft quotation, an internal note, a product description do not fall under it.

What about AI-generated images in marketing?+

The test is whether the image appreciably resembles real persons, objects, places or events. An obviously synthetic illustration is not a deepfake within the meaning of paragraph 4. A photorealistic image staging a situation that never happened is, and its origin must be disclosed. The machine-readable marking normally comes from the generating tool.

Is there still a grace period for watermarking?+

For systems placed on the market before 2 August 2026 a four-month transition runs to 2 December 2026. It concerns only the machine-readable marking under paragraph 2; the remaining transparency duties have applied since August without transition.

Does a line in the privacy policy satisfy this?+

No. Paragraph 5 requires the information at the latest at the point of first interaction, clearly and distinguishably. A reference in a document the person would have to seek out does not meet that — the notice belongs where the encounter happens.

What is the exposure for getting this wrong?+

Up to €15 million or 3 % of total worldwide annual turnover, whichever is higher — for SMEs and start-ups, whichever is lower. That is the middle tier of Article 99: below the prohibited-practices ceiling, well above the one for incorrect information to authorities.

What is the cheapest way to comply?+

Documented human review. It satisfies the exception in paragraph 4 for published text, it supports the human-oversight requirement elsewhere in the Regulation, and it is a better way to work regardless — text nobody stands behind should not leave the building. The documentation is a line per item, not a process.