Summary: Four disclosure duties that attach to specific situations, not to risk tiers — AI interaction, synthetic content marking, emotion/biometric disclosure, and deepfake labelling. Relevant to almost every organisation using generative AI.
Sources: raw/AI-regulations/Regulation - EU - 2024_1689.md (Article 50); raw/Laws/The EU AI Act's Transparency Rules_ A Practical Guide to Article 50...md
Last updated: 2026-07-28
These obligations “apply to all AI systems used in the four situations set out in Article 50, not just to high-risk systems” (source: The EU AI Act’s Transparency Rules…md). Article 50 is the part of the Act with the broadest practical reach.
The four obligations
50(1) — Tell people they are talking to an AI. Providers must ensure systems “intended to interact directly with natural persons” inform those persons they are interacting with an AI system, “unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect.” Law-enforcement exemption applies unless the system is publicly available for reporting offences (source: Regulation - EU - 2024_1689.md).
50(2) — Mark synthetic content machine-readably. Providers of systems “generating synthetic audio, image, video or text content, shall ensure that the outputs… are marked in a machine-readable format and detectable as artificially generated or manipulated.”
The obligation is qualified: solutions must be “effective, interoperable, robust and reliable as far as this is technically feasible,” accounting for content-type limitations, implementation costs and state of the art. Does not apply where the system “perform[s] an assistive function for standard editing” or does not substantially alter input data or its semantics.
This falls on providers, and it is a provider-side watermarking mandate. The robustness qualifier is doing real work — watermark removal is an adversarial problem, and the Act does not pretend otherwise.
50(3) — Disclose emotion recognition and biometric categorisation. Deployers must inform exposed persons of the system’s operation and process personal data per GDPR / Regulation 2018/1725 / Directive 2016/680. Law-enforcement exemption for permitted crime detection/prevention/investigation.
Note the stacking with Article 5: emotion inference at work and in education is banned (5(1)(f)); biometric categorisation inferring protected attributes is banned (5(1)(g)). Article 50(3) governs what remains.
50(4) — Label deepfakes and AI-generated public-interest text. Deployers generating or manipulating “image, audio or video content constituting a deep fake, shall disclose that the content has been artificially generated or manipulated.”
Artistic carve-out: where content is part of “an evidently artistic, creative, satirical, fictional or analogous work,” disclosure is “limited to disclosure of the existence of such generated or manipulated content in an appropriate manner that does not hamper the display or enjoyment of the work.”
Second limb: deployers of systems generating text published to inform the public on matters of public interest must disclose it — unless the content “has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication.”
The editorial-responsibility exemption is the key detail for anyone publishing AI-assisted content: accountable human review removes the labelling duty.
Timing and manner
50(5) — information must be provided “in a clear and distinguishable manner at the latest at the time of the first interaction or exposure,” conforming to applicable accessibility requirements.
50(6) — Article 50 does not displace Chapter III obligations or other transparency duties in Union or national law. It stacks.
Dates
Chapter IV applies from 2 August 2026. The explainer records that “the AI Omnibus provisional agreement of May 2026 grants generative AI systems already on the market before that date until 2 December 2026 to meet the machine-readable marking requirement under Article 50(2)” (source: The EU AI Act’s Transparency Rules…md).
That four-month extension applies only to 50(2) marking, only to systems already on the market, and derives from a provisional agreement — treat it as subject to change until final. See ai-act-timeline.
Code of practice
50(7) — the AI Office “shall encourage and facilitate the drawing up of codes of practice at Union level to facilitate the effective implementation of the obligations regarding the detection and labelling of artificially generated or manipulated content.” The Commission may approve them by implementing act, or specify common rules if it finds a code inadequate.
A dedicated Code of Practice on AI-generated content is in progress (source: The EU AI Act’s Transparency Rules…md).
Penalty tier
Article 99(4)(g) puts Article 50 breaches in the 3% / €15M tier, alongside provider and deployer obligations. See enforcement-and-penalties.
Security angle
Article 50 is a provenance regime, and provenance is a defence against a threat this corpus catalogues from the offensive side: T67 Fake-Citation Grounding manufactures fake papers, DOIs, repos and CVEs to ground harmful requests, and the Code of Practice names “harmful manipulation” — “strategic persuasion or deception targeting populations or decision-makers” — as a specified systemic risk (source: raw/Laws/Overview of the Code of Practice...md).
Machine-readable marking is the infrastructure that would let a downstream system distinguish generated from attested content. Its effectiveness depends entirely on the robustness qualifier in 50(2), which is where an adversary works.