Skip to main content

EU AI ActJuly 24, 2026 · Updated July 27, 2026 · 9 min

The deadline that moved was high-risk. Article 50 transparency lands on 2 August 2026 — here's what a deployer actually has to ship.

Article 50 transparency applies from 2 Aug 2026 — not deferred. Which AI triggers it, what a compliant disclosure looks like, marking, and a deployer checklist.

Key takeaways

  1. Article 50 transparency applies from 2 August 2026 and was NOT deferred by the Digital Omnibus. If your AI talks to people or generates content, you are in scope from that date — not in 2027.
  2. Four triggers: AI people interact with (chatbots, voice agents), synthetic content your systems generate (machine-readable marking), deepfakes shown to viewers, and emotion-recognition / biometric-categorisation notices.
  3. The machine-readable marking of generated content under Art. 50(2) has a short grace for systems already in service — it lands 2 December 2026. New systems mark from day one.
  4. Article 50 is not GDPR transparency. They overlap but don't substitute: an "I'm an AI" line is not a privacy notice, and emotion recognition drags in GDPR Article 9 and usually a DPIA.

The deadline everyone rescheduled was the high-risk one. Article 50 — the transparency layer — applies from 2 August 2026, and the Digital Omnibus did not touch it. If your AI talks to a customer, answers your phone, or generates content that reaches anyone, you are in scope on that date. The relief is that Article 50 is mostly a disclosure-and-labelling exercise, not an engineering programme. The catch is that “mostly” hides a few real implementation decisions — and the machine-readable-marking piece runs on its own clock.

For the full picture of what moved where, read The August 2 deadline just moved. This post is the implementation-level companion: everything Article 50 asks of a deployer, with the UI copy to match.

Which systems trigger Article 50

Article 50 has four triggers. The job is to map yours against them — most mid-market companies hit one or two and think they hit none.

  • AI people interact with — Art. 50(1). A chatbot, a voice agent, an AI phone line: the person on the other end must be able to tell they are dealing with a machine. If you run a support bot or an automated caller, this is you.
  • Synthetic content your systems generate — Art. 50(2). Text, images, audio and video your systems produce must be marked in a machine-readable format so downstream tools can detect it as AI-generated. This is the marking obligation with the separate December clock, below.
  • Deepfakes shown to a viewer — Art. 50(4). If you generate or manipulate image, audio or video that resembles real people, places or events, you must disclose to the viewer that it is artificially generated or manipulated. Also under 50(4): AI-generated text published to inform the public on matters of public interest must be disclosed — unless a human took editorial responsibility for it.
  • Emotion recognition & biometric categorisation — Art. 50(3). If you run a system that infers emotions or sorts people into categories from biometric data, you must inform the people exposed to it — and this one drags GDPR in behind it.

What a compliant disclosure actually looks like

The regulation says the information must be “clear and distinguishable,” provided “at the latest at the time of the first interaction or exposure,” and accessible. In product terms, that means specific copy in specific places. Here is what we actually ship.

A chatbot or web widget. The disclosure belongs in the first message and in a persistent label — not buried in a linked policy.

  • “Hi, I’m Anna! How can I help today?”
  • “You’re chatting with our AI assistant. It answers common questions and can pass you to a colleague anytime.” — with a small persistent “AI assistant” label on the header, so someone who scrolls back still knows.

A voice agent or AI phone line. Disclosure has to be audible and up front, because there is no UI to label.

  • ✓ Opening line: “Hi — this is an automated assistant from [company]. I can help with orders and appointments, or connect you to a person. This call may be recorded.” One sentence covers the Art. 50 disclosure; the recording clause is a separate GDPR duty riding along.

A deepfake or AI-generated image in marketing. 50(4) wants the viewer to know; 50(2) wants a machine to know. They are different obligations and you usually need both.

  • ✓ A visible label on or beside the asset — “AI-generated” — plus provenance metadata embedded in the file (a C2PA manifest or equivalent) so platforms and detection tools can read it even after the caption is stripped.

Emotion recognition — e.g. call-centre sentiment scoring.

  • “Calls may be analysed by automated systems to assess tone and sentiment for quality purposes.” — surfaced before or at the start of the interaction. This notice satisfies Art. 50(3); it does not satisfy GDPR, which is a separate stack (more below).

AI-generated text published to the public.

  • ✓ A byline or note: “Drafted with AI and reviewed by our team.” If a named human genuinely holds editorial responsibility for the piece, 50(4) doesn’t force the label on that text — but “a human skimmed it” is not editorial responsibility, and the honest, trust-building move is to disclose anyway.

Machine-readable marking, and the December grace

Art. 50(2) — marking generated content so a machine can detect it — is the one piece of Article 50 with real engineering behind it, and the one piece with extra time.

The obligation falls primarily on the provider of the generative system: outputs must be marked in a machine-readable format and detectable as artificially generated or manipulated, using solutions that are effective, interoperable and robust “as far as technically feasible.” In practice that means embedded provenance metadata (the C2PA standard is the emerging default) and, where it fits, watermarking. Pure standard editing that doesn’t substantially alter the input is carved out.

Two implementation consequences for a deployer:

  1. If you build on someone else’s model, this is a procurement question. You don’t implement 50(2) yourself — you confirm your vendor does, and that the marking survives your pipeline. A watermark your CMS strips on re-encode is not compliance.
  2. The visible label (50(4)) and the machine mark (50(2)) are not interchangeable. A caption satisfies the viewer; a C2PA manifest satisfies the detector. Public-facing deepfakes typically need both.

So the honest sequencing is: ship the disclosures now (they are due on 2 August), and use the short window to Dec 2026 to get provenance marking working on the generative systems you already run — not as a reason to defer the whole thing.

How Article 50 sits with GDPR

This is where deployers most often ship one notice and think it covers two laws. It doesn’t.

Article 50 answers “am I dealing with AI / synthetic content?” GDPR Articles 13–14 answer “what personal data are you processing, on what basis, for how long, and what are my rights?” Different questions, different notices, both required when personal data is in play. An “I’m an AI” line at the top of a chat does nothing for GDPR; a cookie-and-privacy notice does nothing for Article 50.

Where they collide hardest is emotion recognition and biometric categorisation. Inferring emotion or sorting people by biometric traits is special-category processing under GDPR Article 9 — so on top of the Art. 50(3) notice you generally need an Article 9 legal basis and a Data Protection Impact Assessment, and in an employment context the bar is higher still. The Art. 50 disclosure is the easy 10% of that obligation; the GDPR analysis is the other 90%.

The clean pattern is to layer the two: a short, plain AI-transparency line at the point of interaction, linking to the fuller privacy notice that carries the GDPR detail. One does not absorb the other.

The one-page checklist

There is a print-friendly version of this checklist — A4, black-and-white safe — if it is easier to hand to the people who own the bots and the marketing assets.

  1. 01

    Inventory every outward-facing AI

    List every AI system that interacts with a person or produces content that reaches one: support bots, voice agents, lead-reply automations, marketing-content generators, sentiment tools. Internal-only models that never face a customer, partner or the public are largely out of Article 50 — but be strict about what counts as "internal."

    ⏱ Half a day

  2. 02

    Add interaction disclosure to every bot and voice agent

    First message and a persistent label for chat; an audible opening line for voice. Plain language, at first interaction. Kill the "it's obvious" excuse for anything with a human name or persona.

    ⏱ Art. 50(1) — due 2 Aug 2026

  3. 03

    Label deepfakes and public-interest AI text to the viewer

    Visible "AI-generated" marking on synthetic image/audio/video that resembles real people or events, and on AI-written public-interest text unless a named human holds editorial responsibility.

    ⏱ Art. 50(4) — due 2 Aug 2026

  4. 04

    Notify for emotion recognition / biometric categorisation — then do the GDPR work

    Surface the Art. 50(3) notice before exposure. Separately, confirm a GDPR Article 9 basis and run a DPIA; in the workplace, check the use is even permitted before you build it.

    ⏱ Art. 50(3) + GDPR

  5. 05

    Confirm machine-readable marking with your generative vendors

    For any system that generates media, verify Art. 50(2) provenance marking (C2PA or equivalent) is produced and survives your pipeline. Legacy systems already running have until 2 December 2026; new ones, from day one.

    ⏱ Art. 50(2) — grace to 2 Dec 2026

  6. 06

    Layer, don't merge, the AI and GDPR notices

    A plain AI-transparency line at the point of interaction, linking to the full privacy notice. Neither notice substitutes for the other. Assign an owner to keep the inventory and the notices current as new tools arrive.

    ⏱ Ongoing

Where you actually stand

Most deployers we talk to are closer to compliant than they fear on disclosure and further than they think on marking and GDPR. The disclosures are an afternoon of copy and a few UI changes; the machine-readable marking is a vendor conversation; the emotion-recognition path is the one that quietly needs a DPIA. If you’re not sure which of the four triggers you hit, that is exactly the question the inventory answers.

Oleks builds the technical controls — provenance marking, logging, the plumbing that makes a disclosure real; I handle the classification and the GDPR overlay. Between us we cover both the sentence in the UI and the paperwork behind it.

What changed

  1. Corrected throughout from past to future tense: Article 50 applies from 2 August 2026. The first version described the deadline as already passed.

SOURCES

  1. Regulation (EU) 2024/1689 (AI Act), Article 50 — transparency obligations — European Commission, 2024
  2. Digital Omnibus — simplification of EU digital rules — European Commission, 2026
  3. AI Act Explorer — Article 50, topic-indexed reference — Future of Life Institute, 2024
  4. C2PA — technical standard for content provenance and authenticity — Coalition for Content Provenance and Authenticity, 2025

Frequently asked questions

  • What does Article 50 of the EU AI Act require?
    Transparency, in four parts: AI systems people interact with (chatbots, voice agents) must disclose they are AI; AI-generated synthetic content must be marked in a machine-readable way; deepfakes must be labelled to viewers; and emotion-recognition or biometric-categorisation systems must inform the people exposed to them. It applies from 2 August 2026 and was not deferred by the Digital Omnibus.
  • Does Article 50 have a grace period?
    The disclosure duties apply from 2 August 2026. Only the machine-readable marking of generated content under Article 50(2) has a short grace for systems already in service, landing 2 December 2026 — and new systems mark from day one. Nothing else in Article 50 was deferred.
  • Is an AI disclosure the same as a GDPR privacy notice?
    No. Article 50 tells a person they are dealing with AI or looking at synthetic content; GDPR Articles 13 and 14 tell them what personal data you process and why. You need both, layered — and an emotion-recognition system needs a GDPR Article 9 legal basis and usually a DPIA on top of the Article 50 notice.
  • Our chatbot uses a third-party model like ChatGPT — are we the provider or the deployer?
    Usually the deployer. If you take someone else's model and put it in front of your customers, you carry the deployer duties: the interaction disclosure, and the labelling of any deepfake or public-interest content it produces. The machine-readable marking of generated media under Article 50(2) is a provider duty — but you should confirm your vendor actually supports it rather than assume.

Was this helpful?

share

linkedin email

Want this in your inbox?

or write: hello@saloid.com · gräfelfing · de