EU AI Act Article 50 Transparency, Labeling, and User Disclosures
Article 50 is not one generic notice requirement. It separates provider duties for AI systems that interact with people or generate synthetic content from deployer duties for emotion recognition, biometric categorisation, deepfakes, and certain public-interest text.
This page helps decide which disclosure belongs in the product interface, content workflow, model-output pipeline, workplace or public-facing notice, and which high-risk AI instructions for use must still be handled separately.
transparency duties apply from 2 August 2026. A limited grace period applies only to Article 50(2) marking and detection for systems placed on the market before that date: providers must comply from 2 December 2026. Content generated before 2 August 2026 does not require retroactive labelling. The final Code of Practice on Transparency of AI-Generated Content was published on 10 June 2026 as a voluntary implementation tool. On 8 July 2026 the Commission concluded that the Code adequately covers Articles 50(2), 50(4), and 50(5), and the AI Board adopted its assessment the next day. Adherence is not conclusive evidence of compliance. The Commission published final, non-binding Article 50 guidelines on 20 July 2026; the Regulation remains controlling law.
1
Section 1
Article 50 duties at a glance
creates several distinct transparency duties. Providers must design direct-interaction AI systems so natural persons are informed that they are interacting with an AI system, unless that is obvious in context. Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video, or text content must ensure outputs are machine-readable and detectable as artificially generated or manipulated, subject to the Article 50 exceptions.
Deployers carry separate duties where their use exposes people to emotion recognition or biometric categorisation systems, creates or manipulates image, audio, or video content constituting a , or publishes AI-generated or manipulated text to inform the public on matters of public interest. also requires the information in paragraphs 1 to 4 to be clear, distinguishable, accessible, and given no later than the first interaction or exposure.
Provider interaction notice: applies to AI systems intended to interact directly with natural persons, unless the interaction is obvious to a reasonably well-informed, observant, and circumspect person in context.
Provider synthetic-content marking: applies to AI systems, including GPAI-based systems, that generate synthetic audio, image, video, or text content, with machine-readable and detectable marking as far as technically feasible. Systems placed on the market before 2 August 2026 have until 2 December 2026 for this duty only.
Deployer exposure notice: applies when natural persons are exposed to an or .
Deployer content disclosure: applies to image, audio, or video content and to certain AI-generated or manipulated text published to inform the public on matters of public interest.
Timing and accessibility: the notice must reach the natural person concerned by the first interaction or exposure and conform to applicable accessibility requirements.
Interaction with users: when people must know they are dealing with AI
For a chatbot, voice assistant, agent, embedded support flow, or similar interface, first decide whether the system qualifies as AI, supports a genuine two-way exchange, interacts directly rather than through a human intermediary, and communicates with natural persons. Background systems, machine-to-machine communication, one-way data collection, and systems without direct contact fall outside this particular notice duty. If all four conditions are met, place the disclosure where the person first interacts with the system.
The notice can be unnecessary only when the AI nature is obvious from the viewpoint and context described in . That exception should be used narrowly in product review: record the interface, the user group, the context of use, and why the AI interaction would be obvious before relying on it.
Place the notice where the person starts the interaction, such as the chat entry point, voice prompt, intake form, or generated-response surface.
Use plain wording that identifies the interaction as involving an AI system without overstating capability, autonomy, accuracy, or human review.
Keep localization and accessibility in scope when the interface is available across languages, channels, or assistive technologies.
Retain screenshots, release notes, UI copy approvals, localization records, and accessibility checks as evidence that the notice was available by first interaction.
If the feature is also high-risk, keep this user-facing notice separate from Article 13 instructions for use supplied to deployers.
Synthetic content, deepfakes, and public-interest text
separates provider-side technical marking from deployer-side public disclosure. Providers of systems that generate synthetic audio, image, video, or text content must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated, as far as technically feasible and taking account of content type, implementation cost, and the state of the art.
The provider marking duty does not apply where the AI system performs an assistive function for standard editing or does not substantially alter the input data or its semantics. It also has a law-enforcement exception where use is authorised by law to detect, prevent, investigate, or prosecute criminal offences. Record the function and output comparison before using either exception.
Deployers have a different obligation when they generate or manipulate image, audio, or video content constituting a : disclose that the content has been artificially generated or manipulated. For evidently artistic, creative, satirical, fictional, or analogous works, the obligation is limited to disclosure of the existence of generated or manipulated content in an appropriate way that does not hamper the display or enjoyment of the work. For AI-generated or manipulated text published to inform the public on matters of public interest, deployers must disclose the AI generation or manipulation unless 's law-enforcement or human-review/editorial-responsibility exceptions apply.
Provider evidence should cover watermarking or other marking design, detectability testing, known limitations by content type, interoperability assumptions, and release controls.
Deployer evidence for deepfakes should identify the content asset, audience, publication channel, disclosure wording, placement, timing, and any creative-work rationale.
For public-interest text, record whether it was published to inform the public, whether a knowledgeable natural person substantively reviewed it or an editorial entity could approve, change, or reject it, and who held ultimate legal responsibility. Spell-checking, grammar correction, and other superficial checks do not amount to human review or editorial control.
Do not treat provider machine-readable marking as a substitute for a deployer disclosure where (4) applies to a publication or content release.
If using the final June 2026 Code of Practice, record signature and implemented commitments. The Commission and AI Board found the Code adequate for Articles 50(2), 50(4), and 50(5), but adherence is not conclusive evidence of compliance.
Emotion recognition and biometric categorisation notices
Deployers of emotion recognition systems or biometric categorisation systems must inform the natural persons exposed to the operation of the system, whether the operation occurs in real time or after the biometric data was captured. That disclosure duty is separate from data-protection duties: expressly states that personal data must be processed under the applicable EU data-protection instruments.
The notice record should therefore answer two questions at once. First, did the exposed person receive clear information about the operation of the system by the time of exposure? Second, did the privacy team assess the lawful basis, data categories, safeguards, and documentation required by the applicable data-protection regime?
Define the exposure point: camera zone, kiosk, workplace process, educational process, access-control process, customer journey, or other system context.
Separate notice wording from privacy-notice wording, then check that both are consistent and available before exposure.
Record whether any law-enforcement exception is being relied on and require legal approval before omitting a notice on that basis.
Keep signage, interface notices, DPIA or privacy-assessment references, vendor specifications, and deployment maps with the evidence record.
Screen the use case against Article 5 prohibitions and Annex III high-risk categories before treating notice as the only control.
transparency duties operate alongside Chapter III high-risk AI requirements. Article 50(6) says paragraphs 1 to 4 do not affect Chapter III obligations, while Article 13 requires high-risk AI systems to be sufficiently transparent for deployers and accompanied by concise, complete, correct, clear, relevant, accessible, and comprehensible instructions for use.
That means the same AI product can need two different transparency artifacts: a user-facing notice or label, and a deployer-facing Article 13 instruction set. Article 26 then requires deployers of high-risk AI systems to use the system in accordance with the instructions for use, assign competent human oversight, monitor operation based on those instructions, and keep logs where the logs are under their control.
Use for notices and labels aimed at natural persons or published content audiences.
Use Article 13 for provider instructions that let deployers understand intended purpose, capabilities, limitations, output interpretation, human oversight, maintenance, logging, and relevant risks.
Use Article 26 to check whether the deployer has operating procedures, trained oversight, monitoring, incident escalation, and log retention aligned with the instructions for use.
For high-risk systems that also generate content or interact directly with people, link the two evidence sets but do not merge them into a single generic transparency checklist.
When a deployer changes intended purpose or makes substantial modifications, review whether responsibilities along the AI value chain have changed before reusing old notices.
This checklist covers product release, content publication, procurement onboarding, or deployment approval when may apply. The goal is to prove that the correct actor delivered the correct notice, label, or technical marking to the correct audience at the correct moment.
Do not use this checklist as a substitute for high-risk classification, prohibited-practice screening, privacy review, or sector-specific disclosure rules. transparency can sit beside those duties, and Article 50(6) preserves other transparency obligations under Union or national law.
Does an EU AI Act chatbot notice replace high-risk AI instructions for use?
No. covers user-facing transparency for direct interaction with an AI system. If the system is high-risk, Article 13 instructions for use and Article 26 deployer operating duties still need their own evidence and controls.
Who discloses AI-generated content under EU AI Act ?
The deployer of the AI system that generates or manipulates image, audio, or video content constituting a must disclose that the content was artificially generated or manipulated, subject to the exceptions and special treatment for evidently artistic, creative, satirical, fictional, or analogous works.
What should providers keep as evidence for AI-generated content marking under EU AI Act ?
Providers should keep the marking design, machine-readable format decision, detectability testing, content-type limitations, robustness and interoperability assumptions, release approvals, and records showing why any exception was or was not used.
What should deployers tell people exposed to emotion recognition or biometric categorisation systems?
Deployers should inform the natural persons exposed to the operation of the emotion recognition or by the time of exposure, and keep the notice aligned with applicable EU personal-data compliance records.
Does every duty have a grace period after 2 August 2026?
No. The limited grace period applies only to the (2) marking and detection duty for systems placed on the market before 2 August 2026; providers of those systems must comply from 2 December 2026. Interaction notices, exposed-person notices, and deployer content disclosures do not receive that grace period. Content generated before 2 August 2026 does not need retroactive labelling, although the Commission encourages it where possible.
Classify the trigger: direct interaction, synthetic content generation, emotion recognition exposure, biometric categorisation exposure, content, or public-interest text publication.
Name the actor with the duty: provider for direct-interaction design and synthetic-output marking; deployer for exposed-person notices, disclosure, and public-interest text disclosure.
Define the audience and timing: natural person at first interaction or exposure, content viewer at publication, or deployer receiving high-risk instructions for use.
Approve the exact disclosure text, placement, language coverage, accessibility treatment, and exception analysis.
Save evidence: UI screenshots, marking specifications, detectability tests, publication records, signage or notice copies, editorial review records, DPIA references, Article 13 instructions, Article 26 operating procedures, and change approvals.
Set review triggers for new modalities, publication channels, user groups, supplier model changes, high-risk classification changes, revisions to the final Commission guidelines, and any change to the code's adequacy status.
Review your EU AI Act transparency labels before launch
Sorena can help separate provider marking duties, deployer disclosure duties, high-risk instructions for use, and privacy evidence into a practical Article 50 review record.
Commission overview identifies emotion recognition and biometric categorisation in the AI Act risk framework, including prohibited and high-risk examples.
Official explanation of actor scope, direct-interaction criteria, deepfake and public-interest-text tests, human-review meaning, the limited 2 December 2026 marking grace period, and the rule against retroactive labelling.
Final non-binding Commission guidance published on 20 July 2026 supports the scope, actor, exception, timing, and implementation distinctions used in this section.
Records the Commission's 8 July 2026 adequacy conclusion, the AI Board's following-day assessment, and the warning that adherence is not conclusive evidence of compliance.
Articles 13, 25, 26, and 50 support the checklist fields for triggers, actor allocation, timing, high-risk instructions, deployer operation, exceptions, and evidence.