EU AI Act Article 50 is live: the disclosure rules every AI product must follow
The EU's AI transparency obligations took effect on 2 August 2026, with final Commission guidance adopted in July. Chatbot disclosures and synthetic-content marking are now enforceable, with fines of up to €15 million or 3% of global turnover.
On 2 August 2026, one of the most practically consequential parts of the EU AI Act came into force: Article 50, the transparency chapter. Unlike the high-risk requirements that have grabbed the compliance headlines — many of which have been delayed — the disclosure obligations were not postponed. As of this month, any AI product that chats with users, generates images, voices a phone call, or touches emotion recognition is subject to enforceable transparency duties across the EU, with penalties of up to €15 million or 3% of worldwide annual turnover, whichever is higher.
And there is no longer much room to argue about what the rules mean. The European Commission adopted its implementation guidelines on 20 July 2026, settling the practical questions that had been open since a draft was circulated for consultation on 8 May (the consultation closed on 3 June). For AI teams, the period of "wait for guidance" is over.
What Article 50 actually requires#
Article 50 splits obligations between providers (those who develop and place an AI system on the market) and deployers (those who use an AI system under their own authority, such as an enterprise shipping a customer-support chatbot). The Commission's guidance organizes the duties into four scenarios:
1. Disclosing that you are talking to an AI. Providers of AI systems designed to interact directly with people — chatbots, voice assistants, AI agents — must tell users they are engaging with an AI system, unless that fact is already obvious to a reasonably informed person. A plain line in the interface, such as "You are chatting with an AI assistant," satisfies this. The disclosure must be given in a clear and distinguishable manner, at the latest at the time of the first interaction, and it must meet accessibility requirements.
2. Marking synthetic content so it can be detected. Providers of systems that generate synthetic audio, image, video, or text must embed machine-readable markings in the output and provide a way for those outputs to be detected as artificially generated or manipulated, using state-of-the-art techniques. The law does not name a specific standard — it does not, for instance, mandate C2PA — but content-provenance formats like C2PA are the most commonly cited implementation path. Limited exceptions apply for standard editing and non-substantial alterations.
3. Informing people exposed to emotion recognition or biometric categorisation. Deployers of emotion recognition or biometric categorisation systems must inform the individuals exposed to them. This obligation targets systems that read or classify people — retail analytics cameras, automated interview tools — and puts the duty on whoever operates them, not the vendor that built them.
4. Labelling deepfakes and AI-generated public-interest text. Deployers must disclose when content has been artificially generated or manipulated in two cases: deepfakes, and AI-generated text published on matters of public interest. Notably, the deepfake disclosure applies even without an intent to deceive. The exception here is content that has undergone substantive human editorial review, where a person assumes editorial responsibility.
The dates that matter#
- 2 August 2026 — Article 50 obligations became applicable. Chatbot disclosure and deployer duties apply from this date.
- 2 December 2026 — End of the grandfathering period for the technical marking obligation. Generative AI systems already on the market before 2 August 2026 have until this date to comply with the machine-readable marking requirement; systems placed on the market after 2 August 2026 must comply immediately. (This grace period came via the Digital Omnibus; the chatbot disclosure requirement was not delayed.)
| Obligation | Who owes it | Deadline |
|---|---|---|
| Disclose AI interaction (chatbots, agents, voice) | Providers | 2 Aug 2026 |
| Machine-readable marking of synthetic output | Providers | 2 Dec 2026 for pre-existing systems |
| Inform people exposed to emotion/biometric systems | Deployers | 2 Aug 2026 |
| Disclose deepfakes and AI-generated public-interest text | Deployers | 2 Aug 2026 |
What compliance looks like in practice#
For most product teams, the practical work breaks down into three streams.
UI disclosure. If your product has a conversational interface — support chat, voice agent, AI copilot — audit every entry point. The disclosure needs to be clear and distinguishable, not buried in a tooltip, and presented no later than the first interaction. The "obvious to a reasonably informed person" exception is narrow: if there is any plausible chance a user might think they are talking to a human, disclose.
Content provenance. If your product generates or manipulates audio, images, video, or text, you need a machine-readable marking mechanism — watermarks, metadata, provenance records — plus a detection route. "State of the art" is doing real work here: the Commission expects techniques to evolve, so a static, one-time implementation is unlikely to age well. One lower-friction option flagged in guidance: signing the Commission's Code of Practice on Transparency of AI-Generated Content offers a streamlined, lower-scrutiny route to demonstrating compliance.
Deployer-side duties. Enterprises are the most likely to be caught out here, because the duties apply to ordinary usage, not just to AI vendors. A company using an AI vendor's model through an API does not inherit the vendor's provider obligations, but it is fully responsible for its own deployment — including chatbot disclosure, deepfake labelling, and emotion-recognition notices. If your marketing team generates synthetic imagery or your support team runs an AI voice agent, those deployer duties sit with you.
The fine print teams tend to miss#
Territorial scope is broader than you think. The Act applies not only to systems placed on the EU market, but to deployers whose AI outputs are used within the EU. A US-only company with EU users or EU-distributed content is in scope.
Fines scale with turnover, with SME relief. The headline figure is up to €15 million or 3% of global annual turnover, whichever is higher. Lower caps apply for small and medium-sized enterprises, but "lower" is relative — for an early-stage startup, even reduced fines are existential.
Text is in scope, not just media. The marking and disclosure duties cover synthetic text as well as audio, image, and video. Products generating long-form AI text — content tools, document generators — need a marking strategy, not just the image and video shops.
Accessibility is part of the rule. Disclosures must conform to accessibility requirements, which ties this regime to the European Accessibility Act. A disclosure that screen-reader users cannot perceive is not compliant.
"Substantive human editorial review" is a real but narrow escape hatch. AI-generated text on matters of public interest is exempt from disclosure only where it has genuinely undergone substantive human editorial review with a named person assuming editorial responsibility. A quick skim does not count.
Takeaway#
Article 50 is the EU AI Act at its most democratic: unlike the high-risk regime, which sorts AI into risk tiers, the transparency rules apply to a vast population of everyday AI products. A startup's support bot, an agency's image generator, a retailer's in-store analytics camera — all of them have obligations under this chapter, and the final guidelines leave little ambiguity about what is expected.
The grace period for watermarking runs out on 2 December 2026, but the chatbot disclosure and deployer duties are live now. For any team shipping AI to European users, the audit cannot wait for a convenient quarter: map every conversational interface, every synthetic-output pipeline, and every biometric or emotion-sensing system you operate, and get the disclosures in place. The Commission has published the rulebook. Enforcement is the next chapter.