Skip to content
SimpleAct Logo

Art. 50 AI Act · Transparency obligations

As of 3 October 2026 · after the Digital Omnibus

AI Act Article 50: Transparency and Labelling Obligations

Chatbots must disclose that they are AI, AI-generated content needs a machine-readable mark, and deepfakes need a visible disclosure. Article 50 of the AI Act has applied since 2 August 2026. Here you will find who has to label what, a decision tree for your case and suggested wording to copy.

60 days until the Art. 50(2) transition ends (2 Dec 2026)

  • All 4 obligations with paragraph and date
  • Decision tree for your case
  • 9 wording templates per channel
app.simpleact.de

Transparency check

Customer service chatbot · website

A
Service assistantKI · AI

You are chatting with an AI assistant, not a human.

Hi! I can help with delivery and returns. To reach a person, just type “agent”.

Where is my order?

AI-generated
Illustrative image, created with AI

Art. 50 – checkpoints

  • Notice at first interaction (para. 1)
  • Machine-readable marking (para. 2)
  • Deepfake label visible (para. 4)
  • Accessible and distinguishable (para. 5)

4 of 4 checkpoints met

Overview

The 4 labelling obligations at a glance

Article 50 of the AI Act (Regulation (EU) 2024/1689) covers four situations. Two fall on providers – the makers of AI systems – and two on deployers, the organisations that use AI under their own authority. Paragraph 5 sets out what the notices must look like.

Scroll the table sideways →

The 4 labelling obligations at a glance
SituationWhoObligationApplies fromArt. 50
Chatbots, voice assistants, AI agents interacting with peopleProviderDesign the system so that people are informed they are interacting with AI – unless this is obvious to a reasonably well-informed, observant person.2 August 2026Para. 1
Synthetic audio, image, video and text contentProviderMark outputs in a machine-readable format and make them detectable as artificially generated or manipulated.2 August 2026; legacy systems by 2 December 2026Para. 2
Emotion recognition and biometric categorisationDeployerInform the people exposed to the system that it is in operation; process personal data in line with the GDPR.2 August 2026Para. 3
Deepfakes and AI text on matters of public interestDeployerDisclose that the content was artificially generated or manipulated. Lighter rule for art and satire; exemption for text under editorial responsibility.2 August 2026Para. 4
Form of every noticeProvider and deployerClear and distinguishable, at the latest at the first interaction or exposure, accessible.2 August 2026Para. 5

Simplified overview. Paragraphs 1 and 2 contain exceptions for AI systems authorised by law for law enforcement; the wording of the Regulation prevails.

60

days to 2 Dec 2026

Transition period: 2 December 2026

The Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) introduced a short transition period for the providers’ marking obligation. It covers paragraph 2 only – not chatbot notices, emotion recognition or deepfakes.

  • Systems placed on the market before 2 August 2026: machine-readable marking under para. 2 by 2 December 2026 at the latest.
  • Systems placed on the market from 2 August 2026: marking immediately.
  • Paragraphs 1, 3 and 4 have applied since 2 August 2026 without any transition.
All AI Act deadlines

Roles

Provider or deployer? Everything depends on it

Article 50 allocates obligations strictly by role. Before drafting notices, establish which role you play for each AI system – it is often different for different systems.

01

Provider

Anyone who develops an AI system, or has one developed, and places it on the market or puts it into service under their own name or trademark. That includes makers of language models and image generators, but also companies that build their own chatbot and offer it on their website.

Para. 1 (make AI interaction recognisable) and para. 2 (machine-readable marking)

02

Deployer

Anyone who uses an AI system under their own authority in a professional context – for example a company using a purchased tool for marketing images, press releases or videos. Purely personal, non-professional use is excluded.

Para. 3 (emotion recognition, biometric categorisation) and para. 4 (deepfakes, text on matters of public interest)

03

Both at once

A company that configures a chatbot on top of a language model, runs it under its own brand and publishes content with it may be the provider of the chatbot and, at the same time, the deployer for the published content. Both sets of obligations then apply.

depending on system and activity, paras. 1, 2 and 4

Whether your own modifications to a purchased system turn you into a provider is a case-by-case question. Record the role for each system – ideally in your AI register.

Interactive

Decision tree: do I have to label?

Answer up to four questions about a specific AI system or piece of content. At the end you will see which paragraph of Article 50 is likely to apply, from when – and the matching wording template.

Question 1
In what role are you dealing with the AI system?

Think of one specific system or piece of content. For several systems, run through the tree several times.

app.simpleact.de

Result

Art. 50 KI-VO / AI Act

A

In what role are you dealing with the AI system?

Simplified guidance based on your answers, not legal advice. Borderline cases – especially role questions and exceptions – should be reviewed individually.

In detail

The Article 50 obligations one by one

What each paragraph requires, who it applies to and what matters in practice.

Chatbots and AI assistants: people must know they are talking to AI

Providers must design and develop AI systems intended to interact directly with natural persons so that the people concerned are informed that they are interacting with an AI system. This covers classic website chatbots as well as voice assistants on the phone, AI avatars in video calls and AI agents that answer emails.

The obligation only falls away where this is obvious from the point of view of a reasonably well-informed, observant and circumspect person, taking into account the circumstances and context of use. Apply this exception with care: a voice assistant with a natural-sounding voice is precisely not obvious as AI to many people. Special rules apply to systems authorised by law for law enforcement.

Timing matters: the notice must be given at the latest at the first interaction (para. 5). A sentence in the legal notice or terms and conditions does not do the job. In practice, a combination of greeting text and a permanent label in the chat window works well, so the notice stays visible when someone joins the conversation later.

Synthetic content: machine-readable marking by providers

Providers of AI systems – including general-purpose AI systems – that generate synthetic audio, image, video or text content must ensure that the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. This obligation is aimed at the makers of generative AI, not at the companies that use it to create images or text.

The technical solutions must be effective, interoperable, robust and reliable as far as technically feasible, taking into account the specifics of the content types, the costs of implementation and the generally acknowledged state of the art. In practice several techniques are combined – such as metadata, invisible watermarks and logging – because each on its own is easily lost; metadata, for instance, is stripped by many platforms on upload.

Exempt are systems that only perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or its semantics, as well as systems authorised by law for law enforcement. For systems placed on the market before 2 August 2026, the Digital Omnibus grants a transition period until 2 December 2026.

Deepfakes: visible disclosure

Deployers of an AI system that generates or manipulates image, audio or video content constituting a deep fake must disclose that the content has been artificially generated or manipulated. A deep fake is content that appreciably resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.

Typical cases in business: a photorealistic image of a “customer” who never existed, a video in which the CEO speaks to staff in several languages via a voice clone, or a product photo in a setting that does not exist. The obligation is not limited to publication – an internal training video with a synthetic presenter is also covered if it could falsely appear authentic.

Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work, the obligation is limited to disclosure in an appropriate manner that does not hamper the display or enjoyment of the work. The Commission’s guidelines read this exception narrowly. They also stress that where it is foreseeable that people will not perceive content from the start – such as videos people join midway – a one-off notice at the beginning is not enough.

AI text on matters of public interest

Deployers of an AI system that generates or manipulates text which is published with the purpose of informing the public on matters of public interest must disclose that the text has been artificially generated or manipulated. This covers news and reports on politics, health, the economy or public safety – including on company websites when they cover such topics in an informative way.

The key exception: the obligation does not apply where the AI-generated text has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for its publication. For press offices and newsrooms with a clear approval process, that is the norm. Automatically published text, such as AI-generated market reports or news feeds without review, is the critical case.

Advertising copy, product descriptions and internal documents are generally not covered, because they do not serve to inform the public on matters of public interest. The line can blur, though – think of a corporate blog on health topics. If in doubt, a short voluntary note or a documented editorial process helps.

Emotion recognition and biometric categorisation

Deployers of an emotion recognition system or a biometric categorisation system must inform the natural persons exposed to it about the operation of the system. The provision also expressly requires that personal data be processed in accordance with the GDPR and other data protection rules.

Before thinking about notice texts, there is a prior question: is the use allowed at all? Emotion recognition in the workplace and in educational institutions is prohibited in principle under Art. 5(1)(f) AI Act, with exceptions only for medical or safety reasons. That includes features in meeting tools or call-centre software that analyse employees’ “mood”. Certain forms of biometric categorisation are prohibited too.

Where the use is permitted – for example in market research with consent or drowsiness detection in vehicles – the notice must be given before, or at the latest when, capture begins and must be perceivable by everyone affected, including people with disabilities. Since biometric data may be involved, a data protection impact assessment is usually part of the package.

Templates

Wording templates to copy

Suggested wording for the most common channels. Adapt the parts in square brackets and check that the text is clear and visible in time in your context.

Suggested wording, not legal advice. The Regulation prescribes no specific text. What matters is that the notice is clear, distinguishable, timely and accessible.

Chatbot – greeting

First message in the chat window

Para. 1

Hi! I’m an AI assistant from [company], not a human. I can help with questions about [topic]. If you’d rather talk to a member of our team, just type “agent”.

Chatbot – permanent label

Chat window header, below the bot name

Para. 1

AI assistant · Answers are generated automatically and may contain errors.

Voicebot / phone

Announcement before the conversation

Para. 1

Hello, you are speaking with [company]’s automated AI voice assistant. To speak to a person, say “agent” or press zero.

Image on a website or brochure

Caption and alt text

Para. 4 / voluntary

Illustrative image, created with AI. Alt text: AI-generated image: [short description of the subject]

Social media post

In the image and in the post text

Para. 4 / voluntary

Image: created with AI ([tool]). #AIgenerated

Video with a deepfake

Opening caption plus persistent corner label

Para. 4

This video contains footage and audio generated or altered with AI. [Name] did not personally speak these words. Persistent label: AI-generated

Audio / podcast with a synthetic voice

Spoken at the start, repeated in long episodes

Para. 4

Please note: the following voice was generated with artificial intelligence.

Art, satire, fiction

Credits, description or image credit

Para. 4, first subpara., 2nd sentence

Satire. Some scenes were generated or altered with AI.

Press text / public information without editorial review

At the start of the text

Para. 4, second subpara.

This text was produced with the help of artificial intelligence and was not editorially reviewed before publication.

Text under editorial responsibility

At the end of the text

voluntary

Produced with AI assistance, editorially reviewed and published under the responsibility of [name / desk].

Emotion recognition / biometric categorisation

Before capture begins, e.g. entry screen

Para. 3

Notice: in this area we use an AI system that analyses [facial expressions / voice] in order to [purpose]. Information on how we process your data and on your rights: [link to privacy notice].

Code of Practice and guidelines

What the EU has published on implementing Article 50

The text of the Regulation leaves many practical questions open. Two Commission documents help with interpretation: the Code of Practice on marking and labelling of AI-generated content, and the guidelines on the scope of Article 50.

  1. 17 Dec 2025

    First draft of the Code of Practice

  2. 3 Mar 2026

    Second draft

  3. May 2026

    Draft guidelines on Article 50

  4. 10 Jun 2026

    Final Code of Practice

  5. Jul 2026

    Final guidelines on Article 50

  6. 2 Aug 2026

    Article 50 applies

The Code of Practice on marking and labelling of AI-generated content is voluntary. The Commission and the AI Board have confirmed it as an adequate voluntary instrument for demonstrating compliance. Signing up to and implementing it gives you recognised guidance – it is not a guarantee that every individual implementation is sufficient.

The Code has two sections. The first addresses providers and covers marking and detection of AI-generated content (para. 2). The second addresses deployers and covers labelling of deepfakes and of text on matters of public interest (para. 4). For deployers, the EU also provides a set of icons for labelling.

The Commission’s guidelines on the scope of Article 50 clarify terms and exceptions. Two points matter most in practice: where it is foreseeable that people will not perceive content from the start, a one-off notice at the beginning is not enough. And the relief for artistic, creative and satirical works is to be interpreted narrowly.

What this means for you

  • Providers: use the Code as the benchmark for technical marking
  • Deployers: review the EU labelling icons and use them consistently
  • Place notices so they are visible to people who join late
  • Rely on the art and satire relief only with restraint
Code of Practice (EU)

Practical examples

Examples: when labelling is required – and when it is not

Typical situations in businesses. The assessment is guidance and depends on role, content and context in each case.

Scroll the table sideways →

Examples: when labelling is required – and when it is not
SituationArt. 50 obligation?Reason
Your own customer service chatbot on the websiteYesAs the bot’s provider: notice of AI interaction under para. 1, at the latest in the first message.
Chatbot bought from a software vendorIt dependsThe duty lies with the provider. Check that the notice stays visible in your integration.
Photorealistic AI image of a “customer” in an adYesFalsely appears authentic: deepfake, disclosure under para. 4.
Drawn AI illustration in a blog articleNoClearly artificial, not a deepfake. A voluntary note is possible.
CEO video with an AI voice clone in five languagesYesA real person’s voice saying things they never said: deepfake, disclosure under para. 4.
Press release drafted with AI and approved by the press officeNoEditorial control and responsibility: exception under para. 4, second subpara.
Automatically published AI news feed on economic topicsYesText on matters of public interest without editorial control.
AI-generated product descriptions in an online shopNoNot text informing the public on matters of public interest. Consumer and competition law still apply.
Staff use ChatGPT for internal email draftsNoNo publication, no deepfakes. Article 4 (AI literacy) still applies.
Satirical video with an AI double of a politicianIt dependsDisclosure in an appropriate form that does not spoil the work. The exception is narrow.
Mood analysis of call-centre employeesProhibitedEmotion recognition in the workplace is prohibited in principle under Art. 5(1)(f).
Software maker with its own image generatorYesProvider: machine-readable marking under para. 2, legacy systems by 2 Dec 2026.

Simplified examples, not legal advice.

GDPR

Article 50 and the GDPR: two transparency duties, one notice

Almost every AI use that triggers labelling also processes personal data. The obligations under both laws apply side by side – plan them together.

Chatbot logs are personal data

Chat histories contain names, order numbers and often more. You need a legal basis, a privacy notice under Art. 13 GDPR, defined retention periods and usually a data processing agreement with the provider.

Retention and deletion

One notice, two layers

The AI notice under Article 50 and the privacy notice can be combined: a short notice directly in the chat or on the content, with a link to the full privacy information. The AI notice must not be hidden in the privacy policy, though.

Emotion recognition touches Art. 9 GDPR

Systems that analyse faces or voices may process biometric data and therefore special categories of personal data. The strict conditions of Art. 9 GDPR then apply, and a data protection impact assessment is generally called for.

Data protection impact assessment

Deepfakes of real people

Synthetically generating a real person’s image or voice processes their personal data and affects their personality rights. Disclosure under Article 50 does not replace consent.

International transfers and processors

Many AI services process data outside the EU. Check the data processing agreement, the transfer mechanism and whether inputs are used for training.

Data processing agreements

Record of processing activities

AI systems that handle personal data belong in the record of processing. Link that entry to your AI register so labelling and data protection line up.

Record of processing

Fines and supervision

What breaches of Article 50 can cost

Breaches of the transparency obligations fall into the middle tier of the AI Act’s penalties.

For breaches of Article 50, Art. 99(4) AI Act provides for fines of up to €15 million or up to 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. For small and medium-sized enterprises, including start-ups, the lower of the two amounts applies. These are ceilings; the actual amount depends on factors such as the nature, gravity and duration of the breach.

Each Member State designates its market surveillance authorities. In Germany, the Federal Network Agency (Bundesnetzagentur) is, as things stand, earmarked as the competent authority. Separately from AI Act fines, data protection authorities may act on related GDPR breaches, and missing labels can lead to claims under unfair competition law.

maximum under Art. 99(4)
€15m
maximum under Art. 99(4)
of worldwide annual turnover, if higher
3%
of worldwide annual turnover, if higher
whichever of the two is lower
SMEs
whichever of the two is lower

Checklist

Checklist up to 2 December 2026

Paragraphs 1, 3 and 4 already apply. Use this list to close gaps and prepare marking under para. 2. Tick off what is done.

0 of 10 done

FAQ

Frequently asked questions on AI labelling

Article 50 of the AI Act has applied since 2 August 2026. For the providers’ machine-readable marking (para. 2), the Digital Omnibus added a transition period: systems placed on the market before 2 August 2026 must comply by 2 December 2026 at the latest. The obligations for chatbots (para. 1), emotion recognition (para. 3) and deepfakes and text on matters of public interest (para. 4) have applied since 2 August 2026 without any transition.
It depends on the image. If it is a deepfake – realistic content resembling real people, places or events that could falsely appear authentic – your organisation must disclose that it is AI-generated (Art. 50(4)). An obviously drawn or abstract illustration is generally not a deepfake, so Article 50 imposes no obligation. Platforms such as LinkedIn may have their own labelling rules, though, and a voluntary note builds trust.
In most cases, no. For deployers, the text obligation only covers published text on matters of public interest – and not even then if a human has reviewed the translation and someone holds editorial responsibility. If an unreviewed AI translation on such a topic is published, you should disclose it. Whether translation services, as providers, fall under the exception for “no substantial alteration” has not yet been settled.
Internal texts such as minutes, concepts or email drafts generally trigger no labelling obligation, because they are not published to inform the public. Deepfakes are different: the disclosure obligation for image, audio and video content that falsely appears authentic is not limited to publication and also applies internally, for example to training videos with synthetic people.
For providers, machine-readable marking is mandatory (para. 2), and it must be effective, robust and reliable as far as technically feasible. Metadata alone is easily lost on upload or compression, so several methods are combined in practice. For deployers, metadata marking is not enough for deepfakes: para. 4 requires a disclosure that people actually perceive – a visible or audible label.
Generally not. Advertising copy, product descriptions and promotional newsletters do not serve to inform the public on matters of public interest, so Art. 50(4) requires no disclosure. Still pay attention to accuracy, consumer and competition law, and whether images in the same material are deepfakes.
Usually not for internal use. The notice that you are chatting with an AI is owed by the provider. When staff publish results, it depends on the content: deepfakes must be disclosed, and text on matters of public interest only where there is no human review and editorial responsibility. Separately, Article 4 AI Act requires AI literacy measures, and the GDPR applies to inputs containing personal data.
Article 50 allocates the obligations clearly: providers are responsible for the notice of AI interaction (para. 1) and machine-readable marking (para. 2); deployers for informing people about emotion recognition and biometric categorisation (para. 3) and disclosing deepfakes and AI text (para. 4). Each is liable for its own obligations. Anyone who heavily modifies a system and offers it under their own name may become a provider. Clarify responsibilities in your contracts too.
The Regulation prescribes no wording. Under Art. 50(5), the information must be clear and distinguishable, be given at the latest at the first interaction or exposure, and meet accessibility requirements. A notice only in the terms or legal notice is therefore not enough. For deployers, the EU additionally provides a set of labelling icons.
A voluntary EU code of practice whose final version was presented on 10 June 2026. It has one section for providers (marking and detection) and one for deployers (labelling deepfakes and text on matters of public interest). The Commission and the AI Board have confirmed it as an adequate voluntary instrument for demonstrating compliance.

More questions? We're happy to help. Send email · Get started

Sources and status

Last reviewed on · SimpleAct editorial team

This page is for guidance only and is not legal advice. The wording templates are suggestions. The text published in the Official Journal of the EU prevails.

Changes to this page

  • 3 October 2026 – First published: all Article 50 obligations after the Digital Omnibus, decision tree, wording templates, Code of Practice and guidelines, GDPR links.

Labelling obligations under control – for every AI system

SimpleAct records your AI systems, assigns roles and Article 50 obligations, links them to your GDPR documentation and reminds you of deadlines such as 2 December 2026.