Article 50 of the EU AI Act is a transparency norm. It does not aim to prohibit the normal use of artificial intelligence; its central function is to reduce information asymmetries and make it perceptible when a person is interacting with AI or receiving certain AI-generated or AI-manipulated content. In practice, compliance combines legal, product, design, engineering, accessibility, security, content, and governance measures.
Important notice: this material is for educational and governance support purposes. It does not replace specific legal advice or the reading of the official versions of Regulation (EU) 2024/1689, the European Commission's guidelines, and applicable national legislation. In case of divergence, the official texts and decisions of the competent authorities prevail.
This e-book was written to answer three operational questions: (1) when Article 50 applies; (2) who must comply with each obligation; and (3) how to transform the legal rule into verifiable controls.
What you will find
- Annotated reading of paragraphs 1 through 7 of Article 50.
- Difference between the provider and the deployer.
- Rules for chatbots, agents, avatars, and conversational interfaces.
- Machine-readable marking of synthetic text, image, audio, and video.
- Rules for deepfakes, emotion recognition, and biometric categorization.
- Treatment of public-interest texts and the exception for human review/editorial control.
- Extraterritorial scope, including for companies based outside the European Union.
- Sanctions, governance, technical architecture, implementation roadmap, and checklists.
The AI Act and the place of Article 50
Regulation (EU) 2024/1689, known as the EU AI Act, creates harmonized rules for artificial intelligence in the European market. The approach is risk-based: some practices are prohibited; certain systems are treated as high-risk; general-purpose AI models receive specific obligations; and certain systems, even without being "high-risk," must comply with transparency rules.
Article 50 is part of Chapter IV of the regulation and focuses on situations in which the user or the public may confuse an artificial interaction or content with something human, authentic, or unmanipulated. That is why chatbots, agents, synthetic content, deepfakes, emotion recognition, and certain published texts appear in the same article.
Essential timeline
The regulation's general rule establishes application starting on August 2, 2026, with different dates for specific blocks. For Article 50, the European Commission confirmed application starting on August 2, 2026, and published final guidelines on July 20, 2026.
- Jun 13, 2024 — Adoption of the AI Act.
- Feb 2, 2025 — First rules take effect.
- Aug 2, 2025 — New parts of the Regulation applicable.
- Jul 20, 2026 — Final guidelines on Article 50.
- Aug 2, 2026 — Article 50 applicable.
Point of attention: for AI systems placed on the market before August 2, 2026, the Commission provides for a limited tolerance until December 2, 2026, specifically for the marking and detection obligation of Article 50(2). Content created before August 2, 2026, does not need to be labeled retroactively, although the Commission encourages voluntary adoption when possible.
Why does Article 50 exist?
- Reduce the risk of deception, fraud, impersonation, and manipulation.
- Allow people to calibrate their trust when interacting with automated systems.
- Preserve the integrity of the information ecosystem.
- Create technical provenance signals and perceptible signals for people.
- Support the enforcement of other European norms, without replacing them.
Essential legal concepts
Before evaluating a case, it is essential to classify the organization's role. The same product may involve multiple actors in the chain: the model developer, the system provider, the integrator, the company operating the system, and the platform publishing the content.
| Term | Operational meaning | Why it matters |
|---|---|---|
| AI system | Machine-based system that infers, from inputs, how to generate predictions, content, recommendations, or decisions. | Article 50 only applies when there is an AI system within the meaning of the regulation. |
| Provider | Person or entity that develops or has developed a system and places it on the market or puts it into service under its own name or trademark, whether paid or free. | Primarily responsible for the duties of Art. 50(1), 50(2), and the form requirements of 50(5). |
| Deployer | Person or entity that uses the system under its authority in a professional activity. Purely personal, non-professional use falls outside this obligation. | Primarily responsible for the duties of Art. 50(3), 50(4), and the form requirements of 50(5). |
| Deepfake | AI-generated/manipulated image, audio, or video that resembles an existing person, object, place, entity, or event and may falsely appear authentic or truthful. | Triggers a specific disclosure obligation when the criteria are met. |
| Emotion recognition | System that identifies or infers emotions or intentions based on biometric data. | The deployer must inform exposed persons, without prejudice to prohibitions and data protection rules. |
| Biometric categorization | System that assigns individuals to specific categories based on biometric data. | Also triggers the duty to inform exposed persons when permitted. |
The definitions of "provider," "deployer," emotion recognition systems, biometric categorization, and deepfake are found in Article 3. The regulation also excludes, from deployer obligations, natural persons who use AI in a purely personal, non-professional activity.
Practical rule: ask first: "Are we placing the system on the market under our own brand, or are we merely using a third party's system in our operation?" The answer changes the set of obligations and the evidence that must be kept.
Article 50 on one page
Quick map of the obligations.
| Paragraph | Who | Core obligation |
|---|---|---|
| 50(1) | Provider | Inform people when they interact directly with AI, unless this is obvious from the context. |
| 50(2) | Provider | Mark synthetic text, image, audio, and video outputs in a machine-readable and detectable format. |
| 50(3) | Deployer | Inform persons exposed to emotion recognition or biometric categorization. |
| 50(4) | Deployer | Disclose deepfakes and certain public-interest texts generated/manipulated by AI. |
| 50(5) | Both, depending on the obligation | Provide the information in a clear, distinguishable, and accessible manner, at the latest at the time of the first interaction or exposure. |
| 50(6) | Both | The rules do not displace other EU or national transparency obligations. |
| 50(7) | Regulatory ecosystem | Allows codes of practice and, if necessary, common implementation rules. |
Two layers of transparency: Article 50 combines transparency for machines (marking/origin detection) and transparency for people (notices, labels, and perceptible disclosure). One does not automatically replace the other.
Article 50(1): direct interaction with AI
Chatbots, agents, avatars, voice, and conversational interfaces. Article 50(1) requires providers to design and develop systems intended to interact directly with individuals in such a way that those individuals are informed that they are interacting with an AI system. The exception is when this is obvious to a person who is reasonably well-informed, observant, and circumspect, taking into account the context.
Four cumulative criteria from the 2026 guidelines
- The product must qualify as an AI system.
- There must be a genuine two-way exchange with people; mere data collection or simple automated response may not be sufficient.
- The interaction must be direct: the AI itself communicates with the person, without a human intermediary.
- The interaction must be with a natural person, whether consumer, professional, or other user.
Systems that operate only in the background, machine-to-machine communication, or those without direct contact with people fall outside this specific obligation.
When to inform?
The information must be provided from the start of the first interaction, in a clear and distinguishable manner and in compliance with applicable accessibility requirements. The Commission recommends interpreting the "obviousness" exception restrictively, because the exception reduces the transparency available to the person.
Recommended implementation standards
| Channel | Strong implementation | Avoid |
|---|---|---|
| Web/app chat | Persistent "AI Assistant" badge + short initial message. | Notice hidden only in the Terms of Use. |
| Voice/phone | Audible notice before or at the start of the dialogue: "You are talking to an AI assistant." | Notice given only after several turns. |
| Avatar | Text label next to the avatar and repetition during onboarding. | Human appearance with no indication whatsoever. |
| Agent within a workflow | Identify when the agent speaks directly to the person; separate human and automated messages. | Mixing AI and human messages without clear origin. |
| Kiosk/robot | On-screen signage and, when necessary, audio notice. | Assuming the hardware "looks robotic" and skipping the entire contextual assessment. |
Example notice: "You are chatting with an artificial intelligence assistant. Responses are generated automatically and may be reviewed by our team when applicable."
Article 50(2): marking of synthetic content
The technical obligation to make AI-generated or AI-manipulated content detectable. Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video, or text must ensure that the outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated. The solutions must be effective, interoperable, robust, and reliable to the extent technically feasible, considering limitations per content type, implementation costs, and the state of the art.
What does "machine-readable" mean in practice?
The regulation is technologically neutral: it does not mandate a single technology. Recital 133 mentions, as possible families of techniques, watermarks, metadata identification, cryptographic methods for provenance and authenticity, logging methods, and fingerprints, among others. The choice must be testable and proportional to the content type.
| Mechanism | Function | Risk to control |
|---|---|---|
| Provenance metadata | Carry information about origin and manipulations within the file/content. | Removal during reprocessing, screenshots, or platforms that discard metadata. |
| Watermarking | Insert a perceptible or imperceptible signal associated with the synthetic origin. | Compression, cropping, transcoding, and removal attacks. |
| Cryptographic signature | Enable verification of integrity, issuer, or provenance chain. | Key management, trust, and chain preservation. |
| Fingerprinting | Generate a representation used to identify or compare content. | Strong content alterations can reduce matching accuracy. |
| Logs and generation trail | Record the generation event, model, version, and identifiers. | Does not travel with the file if there is no proper linkage. |
Exclusions and limits highlighted by the Commission
- Short sequences of numbers, symbols, or letters.
- Source code.
- Outputs intended exclusively for machine-to-machine communication, automatically processed without exposure to people.
- Outputs used only in industrial environments or closed-loop product development, unless they become the final output.
- Standard assistive editing functions or situations in which the system does not substantially alter the input data or its semantics.
- A narrow exception may exist in certain B2B/industrial contexts, provided the requirements of the guidelines are met.
These exclusions must be documented. "We did not mark it because it was editing" needs to be supported by internal criteria and evidence that the function did not produce a substantial alteration.
Do not confuse: a visible "made with AI" seal may be useful, but by itself it is not equivalent to the technical machine-readable marking obligation under Art. 50(2). Likewise, the technical marking under 50(2) does not replace the perceptible disclosure required from the deployer for deepfakes under 50(4).
Article 50(3): emotion and biometrics
Transparency for people exposed to sensitive systems. Deployers of emotion recognition or biometric categorization systems must inform exposed natural persons about the system's operation. The processing of personal data remains subject to the GDPR, Regulation (EU) 2018/1725, and Directive (EU) 2016/680, as applicable.
The guidelines clarify that the duty to inform applies both to real-time exposure and to subsequent (ex-post) operation. To comply with Article 50(3), the notice does not necessarily need to explain every detail or the complete purpose of the system, although other data protection norms may require additional information.
Attention to the AI Act's own prohibitions
The fact that Article 50(3) provides for transparency does not mean that every use of emotion recognition or biometric categorization is permitted. Article 5 contains specific prohibitions, such as certain emotion inferences in workplaces and educational institutions, except for medical or safety exceptions, and certain biometric categorizations that infer sensitive characteristics.
Transparency does not legalize the use: a correct notice does not make lawful a processing operation that is prohibited by the AI Act, incompatible with the GDPR, or contrary to another applicable norm.
Deployment checklist
- Identify the legal basis and purpose before using the system.
- Map which persons may be exposed, including visitors and third parties.
- Provide the notice before or at the appropriate moment of exposure.
- Ensure accessibility and appropriate language.
- Document the vendor, version, processed data, and retention.
- Assess whether there is a prohibited practice or an additional high-risk obligation.
Article 50(4): deepfakes
When content must be clearly disclosed as artificial. The deployer that uses AI to generate or manipulate an image, audio, or video constituting a deepfake must disclose that the content was artificially generated or manipulated.
Three cumulative criteria highlighted by the Commission
- Resemblance: a relevant level of similarity with the simulated subject.
- Existence: the person, object, place, entity, or event must exist, plausibly could exist, or have existed.
- False appearance of authenticity or truthfulness: the content has the capacity to deceive or mislead as to its authenticity or truth.
In analyzing the third criterion, the level of similarity, the substantive message, foreseeable contexts of use, and audience expectations may be considered. Special effects in a work that the audience does not expect to be "real" may not meet the same deception assessment.
What should the label look like?
At the latest by the first exposure, in a clear and distinguishable format, understandable and perceptible without special technical tools. It may be a visual label or an audible notice, depending on the medium. The Commission is explicit: the deployer cannot rely solely on the technical marking inserted by the provider under Art. 50(2).
| Scenario | Likely assessment | Action |
|---|---|---|
| Video of a real executive with synthetic voice and speech appearing authentic | Strong candidate for a deepfake. | Clear label before or at first exposure. |
| Obvious political satire featuring a public figure | May benefit from treatment as a satirical work, but still requires appropriate disclosure. | Disclosure that does not hamper enjoyment of the work. |
| Fiction film with set effects and audience aware it is a fictional work | May not falsely appear authentic in context. | Document the assessment; apply appropriate disclosure when there is a deepfake. |
| Fully fictional avatar, clearly stylized | May not qualify as a deepfake if it does not imitate an existing person/entity and does not appear authentic. | Still assess other obligations, such as direct interaction under Art. 50(1). |
Label template: "Content generated or manipulated by artificial intelligence." For sensitive video/audio, add a specific indication, for example: "The voice and image in this scene were synthesized by AI."
AI-generated text and public interest
When articles, news, and publications must be labeled. The second block of Article 50(4) addresses AI-generated or AI-manipulated text published for the purpose of informing the public on matters of public interest. To fall within scope, the Commission summarizes three criteria: the text must be published, intended to inform the public, and address a matter of public interest.
Examples of matters of public interest
- Politics and democratic processes.
- Public administration and services.
- Administration of justice and law enforcement.
- Fundamental rights and public safety.
- Public health and environmental protection.
- Consumer safety.
- Economic, financial, political, scientific, or cultural developments relevant to public debate.
The most important exception: human review and editorial responsibility
The text does not need to be labeled under this specific obligation when it has undergone human review or editorial control and a natural or legal person assumes editorial responsibility for the publication. The Commission explains that human review requires deliberate examination of the content by a person with relevant knowledge and judgment. Editorial control involves real authority to approve, alter, or reject the substance of the text, including fact-checking and reliability of the sources.
Superficial review is not enough: merely correcting spelling, grammar, punctuation, or formatting is not considered sufficient human review or editorial control for this exception.
| Editorial workflow | Labeling under Art. 50(4)? | Comment |
|---|---|---|
| AI writes; automatically publishes a news item of public interest | In principle, yes. | There is no human review/editorial control before publication. |
| AI generates a draft; journalist verifies sources, rewrites, and editor approves; company assumes responsibility | May fall under the exception. | There must be substantial review and documentable editorial responsibility. |
| AI writes; a human only corrects language and publishes | In principle, yes. | Superficial correction does not satisfy the exception, according to the Commission. |
| AI assists commercial text with no matter of public interest | Not under this part of 50(4). | Other obligations or laws may still apply. |
Article 50(5) to (7): form, accessibility, and codes
The detail that turns the rule into a real experience.
Article 50(5): clear, distinguishable, and accessible
The information required under paragraphs 1 to 4 must be provided to individuals in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure, and must comply with applicable accessibility requirements.
- Use direct language, without unnecessary legal jargon.
- Do not hide the notice in deep menus, terms, or lengthy policies.
- Adapt the channel: text for a visual interface, audio for interaction that is exclusively auditory, accessible alternatives when necessary.
- Avoid manipulative design that reduces contrast or minimizes the notice.
- Test perception of the notice with real users and assistive technologies.
Article 50(6): other laws remain in force
Compliance with Article 50 does not replace transparency obligations under the GDPR, DSA, consumer law, sector-specific rules, or national norms. In terms of governance, treat Article 50 as an additional layer on the regulatory map.
Article 50(7): codes of practice
The AI Office should encourage codes of practice to facilitate the implementation of detection and labeling. In 2026, this mechanism materialized in the Code of Practice on Transparency of AI-generated Content, subsequently deemed adequate by the Commission and the AI Board as a voluntary instrument to demonstrate compliance.
Companies outside the EU and extraterritorial effect
Why a Brazilian company may fall within scope. Article 2 of the AI Act reaches providers who place systems or models on the Union market even if established in a third country. It also reaches providers and deployers established outside the EU when the output produced by the AI system is used in the Union.
Typical exposure situations for Brazilian companies
- AI SaaS commercially available to customers or users in the European Union.
- Content-generation API integrated into a product whose output is used in the EU.
- Agent or chatbot platform operated for European companies.
- Marketplace distributing AI systems, workflows, or tools under certain conditions.
- Campaigns, content, or deepfakes produced professionally and targeted at the European market.
Looking only at the headquarters is not enough: the absence of a physical establishment in the EU does not automatically eliminate application of the AI Act. The place where the output is used and the placement of the system on the European market are relevant criteria.
Recommended contractual controls
- Define in the contract who is the provider and who is the deployer for each service.
- Require preservation of technical marking when the vendor makes it available.
- Define responsibilities for visible labels, editorial review, and accessibility.
- Provide for cooperation in audits, incidents, and authority requests.
- Avoid a generic clause transferring all responsibility without reflecting the real role of each party.
Fines, enforcement, and regulatory risk
The potential cost of non-compliance. Article 99 expressly includes the transparency obligations of Article 50 among the infringements subject to administrative fines of up to €15 million or, for companies, up to 3% of total worldwide annual turnover for the previous financial year, whichever is higher. For SMEs, including startups, the lower of the percentage or the fixed amount applies.
Maximum exposure: up to €15,000,000 or 3% of the company's total worldwide annual turnover in the preceding financial year, per the rules of Art. 99(4). For SMEs/startups, the cap follows the rule of the lower of the percentage and the fixed amount.
What influences the sizing of the fine
- Nature, gravity, and duration of the infringement.
- Number of persons affected and harm suffered.
- Size, turnover, and market share.
- Benefit obtained or loss avoided.
- Degree of cooperation with authorities.
- Technical and organizational measures implemented.
- Intentional or negligent nature.
- Mitigation actions and history of related sanctions.
Who enforces it?
Enforcement is primarily the responsibility of the competent national market surveillance authorities. The AI Office has specific competencies, especially when systems are based on general-purpose AI models in certain configurations. The European Data Protection Supervisor acts with respect to systems used by EU institutions, bodies, and agencies.
2026 Code of Practice on Transparency
The main voluntary route to demonstrate compliance. The Code of Practice on Transparency of AI-generated Content was published on June 10, 2026. It has two sections: the first addresses providers' obligations for marking and detection; the second addresses deployers' obligations for labeling deepfakes and certain texts.
In July 2026, the Commission and the AI Board considered the code an adequate means of facilitating and demonstrating compliance with Articles 50(2), 50(4), and 50(5). Adherence is voluntary and does not constitute conclusive proof of compliance, but it provides regulatory predictability and a recognized reference point across the EU.
| Option | Advantage | Point of attention |
|---|---|---|
| Adhere to the Code | Recognized framework, common language, and greater predictability in demonstrating compliance. | Real controls still need to be implemented; adherence does not immunize against enforcement. |
| Not adhere | Freedom to use an equivalent proprietary architecture. | The organization must demonstrate adequacy through alternative means and may face more evidence requests. |
Governance: even for non-signatories, the Code of Practice is an excellent operational benchmark: it shows how the Commission expects organizations to translate the abstract duties of marking and labeling into verifiable measures.
Technical compliance architecture
Turning Article 50 into product and engineering controls.
Layer 1 — Governance and inventory
- Inventory of AI systems and models used.
- Role classification: provider, deployer, or both.
- Mapping of territories and target audience.
- Legal, technical, and product owner per system.
- Record of exceptions with justification and evidence.
Layer 2 — Experience and disclosure
- Reusable "AI disclosure" component for chat, voice, avatar, and content.
- Control to ensure display at the first interaction/exposure.
- Versioning of notice text and language.
- Accessibility and contrast testing.
- Consent logs when required by another legal basis — without confusing transparency with consent.
Layer 3 — Provenance and marking
- Generation pipeline that applies marking before the output is delivered.
- Testing of marking survivability after compression, resizing, cropping, transcoding, and re-upload.
- Internal verifier for presence/validity of the marking.
- Generation identifier linked to an audit log.
- Monitoring of changes in the state of the art and applicable standards.
Layer 4 — Content and editorial review
- Human workflow for public-interest publications.
- Substantive review and fact-checking criteria.
- Approval by a person with editorial authority.
- Record of who reviewed, when, and which sources were verified.
- Clear policy for deepfake, satire, fiction, and advertising.
Layer 5 — Evidence and audit
- Generation and publication logs.
- Model, system, and policy version applied.
- Marking/detection test results.
- Evidence of label display.
- Periodic assessments, team training, and remediation plan.
30/60/90-day implementation plan
A pragmatic roadmap to bring the organization into compliance condition.
0-30 days — Discover and classify
- Create an AI inventory by product and process.
- Classify provider/deployer roles and countries of use.
- Identify chatbots, agents, avatars, synthetic generation, biometrics, and editorial content.
- Map vendors and review contracts.
- Conduct a gap assessment against each paragraph of Article 50.
- Prioritize risks of wide reach, deepfake, and public content.
31-60 days — Implement controls
- Add interaction notices and accessible UI components.
- Integrate a machine-readable marking mechanism into applicable outputs.
- Create visible/audible labels for deepfakes.
- Formalize an editorial review workflow for public-interest texts.
- Create an exceptions policy for standard editing and out-of-scope cases.
- Train Product, Engineering, Marketing, Legal, Support, and Content teams.
61-90 days — Prove and sustain
- Run marking robustness tests.
- Collect evidence of first interaction/exposure.
- Audit accessibility and languages.
- Simulate an incident and an authority request.
- Define compliance KPIs and quarterly review.
- Evaluate adherence to the Code of Practice and document the decision.
| Suggested KPI | Initial target |
|---|---|
| % of systems with classified provider/deployer role | 100% |
| % of interaction flows with tested notice | 100% of applicable flows |
| % of eligible synthetic outputs with detectable marking | >= 99% in controlled tests; adjust to architecture and risk |
| % of public content with evidence of editorial review | 100% of flows relying on the exception |
| Time to fix a disclosure failure | Define an SLA proportional to reach and risk |
Practical cases by sector
How the same rule changes depending on the context.
| Sector / case | Likely obligations | Key control |
|---|---|---|
| SaaS with customer support chatbot | 50(1); possibly 50(2) if it generates synthetic content. | Notice at first interaction + marking when applicable. |
| Sales agent talking to leads by voice | 50(1); assess 50(2) for synthetic audio. | Audible notice at the start and trail of the audio's origin. |
| Marketing agency creating a video with a synthesized real person | 50(2) on the system provider; 50(4) on the deployer if it is a deepfake. | Technical marking + visible/audible label. |
| News portal using AI for drafting | 50(4) for public-interest text, unless the editorial exception applies. | Substantive review, sources, responsible editor. |
| Retail using biometric emotion analysis | 50(3), GDPR, and possible permissibility assessment. | Notice, legal basis, assessment of prohibitions, and DPIA when applicable. |
| Film/series with generative AI | 50(2) and possibly 50(4) depending on deepfake status and context. | Provenance in the pipeline + appropriate disclosure without harming the work. |
| Internal code tool | Source code may be outside the 50(2) marking obligation per the guidelines. | Document the classification; assess other product obligations. |
| Closed B2B system generating an artifact for machine-to-machine use only | May fall outside certain markings, depending on conditions. | Prove absence of human exposure and monitor when the output becomes final. |
Checklists and decision tree
Ready-made tools for evaluating systems and content.
Transparency decision tree
Does the content/experience use AI? From there, three paths open up: direct interaction with a person (Art. 50(1) — inform that it is AI, unless obvious), synthetic content in text/image/audio/video (Art. 50(2) — machine-readable marking, and then assess whether it is a deepfake or public-interest text for Art. 50(4)), or emotion recognition/biometric categorization (Art. 50(3) — inform exposed persons).
Provider checklist
- Does the system interact directly with people?
- Is the AI notice provided at the first interaction and is it accessible?
- Has the "obviousness" exception been documented and validated restrictively?
- Does the system generate synthetic text, image, audio, or video?
- Do applicable outputs receive machine-readable marking?
- Is the marking tested for effectiveness, interoperability, robustness, and reliability?
- Are exclusions (standard editing, M2M, etc.) documented?
- Does the contract with downstream providers preserve responsibilities and necessary information?
Deployer checklist
- Is there emotion recognition or biometric categorization?
- Do exposed persons receive a clear and accessible notice?
- Does the content constitute a deepfake?
- Does the deepfake label appear at the latest at first exposure?
- Is the text published to inform the public about a matter of public interest?
- If there is an editorial exception, is there substantial human review?
- Is there a natural or legal person with editorial responsibility?
- Is evidence of publication, review, and labeling preserved?
Evidence audit checklist
- Interface capture demonstrating the disclosure.
- Log of the notice text version.
- Marking and detection test result.
- Record of the model and system version.
- Provider/deployer classification document.
- Record of exceptions and justifications.
- Evidence of editorial review and fact-checking.
- Accessibility report.
- Approved training and internal policy.
- Action plan for non-conformities.
Notice and internal policy templates
Base texts that must be adapted to the real context.
Chatbot notice (PT-BR): "You are conversing with an artificial intelligence assistant. Responses are generated automatically. For matters requiring human validation, use our team's service option."
Chatbot notice (English): "You are interacting with an artificial intelligence assistant. Responses are generated automatically. For matters requiring human validation, please use the option to contact our team."
Deepfake / audiovisual content label: "Content generated or manipulated by artificial intelligence. Synthetic image and/or audio were used in this publication."
Internal editorial statement: "AI-assisted content intended to inform the public about matters of public interest may only be published without the specific label required by Art. 50(4) when there has been substantive human review or editorial control and editorial responsibility has been formally assigned. The review must cover content, sources, context, and reliability; merely linguistic corrections are not sufficient."
Clauses that the vendor contract should address
- Description of generation and manipulation capabilities.
- Marking/detection mechanisms offered.
- Restrictions and circumstances under which marking may be removed.
- Documentation and support for audits.
- Notification of relevant changes to the system.
- Cooperation for investigating transparency failures.
- Responsibilities for interface, publication, and end-user labels.
Important: the templates above are starting points. The final wording must consider the channel, the audience, the language, accessibility requirements, national legislation, and the organization's legal role.
Frequently asked questions
Does every text made with ChatGPT need to say "generated by AI"?
No. The deployer's specific duty under Art. 50(4) addresses text published to inform the public about matters of public interest. In addition, there is an exception when there is human review/editorial control and editorial responsibility. The system's provider, in turn, may have a technical obligation to mark the output under 50(2).
Is it enough to put "made with AI" in the footer?
It depends on the obligation. For a deepfake, the label must be clear, distinguishable, and perceptible at the latest by the first exposure. For the synthetic content provider, the obligation under 50(2) is technical and machine-readable; a visible footer does not replace this layer.
If the user already knows they are using a chatbot, do I need to give notice?
The regulation contains an exception when the interaction with AI is obvious to a reasonably well-informed and observant person, taking the context into account. The Commission advises that this exception be interpreted restrictively.
Is a Brazilian startup affected?
It may be. The AI Act reaches, under certain conditions, providers from third countries that place systems on the EU market or when the system's output is used in the Union.
Is artistic content with a deepfake exempt?
It is not a total exemption. For a work that is evidently artistic, creative, satirical, fictional, or analogous, the obligation is limited to an appropriate disclosure that does not hamper the display or enjoyment of the work.
Is metadata sufficient for a deepfake?
Not for the deployer's duty under Art. 50(4). The Commission clarifies that the person must be able to perceive the disclosure without a special technical tool; the provider's technical marking alone is not enough.
Does source code need marking under 50(2)?
The Commission's guidelines indicate that source code is among the outputs outside the scope of this specific marking obligation.
Does spelling review count as human review?
No. The Commission distinguishes substantive review/editorial control from superficial, merely formal or procedural checks.
Is the Code of Practice mandatory?
No. Adherence is voluntary, but Article 50 is mandatory. Those who do not adhere need to demonstrate compliance through adequate alternative means.
Does complying with Article 50 resolve GDPR and DSA obligations?
No. Article 50(6) itself preserves other transparency obligations provided for under European or national norms.
Conclusion and next steps
Transparency as a product requirement, not just a legal notice. Article 50 turns transparency into a property of the system and of the publication process. Mature companies do not treat the topic as generic text in the Terms of Use: they embed disclosure in the interface, provenance in the pipeline, editorial review in workflows, evidence in logs, and governance in contracts.
Effective implementation starts with a correct classification of the organization's role and continues with proportional controls. When the company is a provider, the system's engineering and output marking become central. When it is a deployer, the manner of use, publication, exposure of individuals, and editorial review become determinative.
Final principle: if a reasonable person could be led to believe they are talking to a human or watching authentic content when, in reality, there is AI in a situation covered by Article 50, the organization must treat transparency as a functional and auditable requirement.
Five actions to start today
- Inventory AI systems and content.
- Classify provider/deployer by use case.
- Implement disclosures and marking where applicable.
- Formalize editorial review and a deepfake policy.
- Collect evidence and test continuously.
Glossary
| Term | Definition |
|---|---|
| AI Act | Regulation (EU) 2024/1689, the European horizontal framework for artificial intelligence. |
| AI Office | Function of the European Commission responsible for implementation, monitoring, and supervision tasks within the AI Act ecosystem. |
| Provider | Entity that develops or has developed and places the system on the market or into service under its own name/trademark. |
| Deployer | Entity that uses the system under its authority in a professional context. |
| Synthetic content | Text, image, audio, or video artificially generated or manipulated by an AI system. |
| Deepfake | AI-generated/manipulated image, audio, or video content that simulates something existing and may falsely appear authentic or truthful. |
| Machine-readable | Format that can be automatically processed by computer systems to enable detection or verification. |
| Provenance | Information about the origin, history, and transformations of a piece of content. |
| Watermarking | Technique for inserting a mark or signal into content, visible or not, for identification/detection. |
| Editorial responsibility | Final legal responsibility for the publication of the content and for the review/editorial control process. |
Sources
- Regulation (EU) 2024/1689 — Artificial Intelligence Act. EUR-Lex. Official text and consolidated version. Articles 2, 3, 50, 99, and 113; recitals 132-137.
- Guidelines on transparency obligations for providers and deployers of AI systems. European Commission, published July 20, 2026; updated July 31, 2026.
- Transparency obligations under Article 50 of the AI Act — Questions & Answers. European Commission, 2026 FAQ with examples and interpretation of the final guidelines.
- Code of Practice on Transparency of AI-generated Content. European Commission / AI Office, final code published June 10, 2026.
- Commission opinion on the assessment of the Code of Practice on Transparency of AI-generated Content. European Commission, July 9, 2026; adequacy confirmed jointly with the AI Board.
- Quick Facts: Transparency rules for AI systems. European Commission, reference material updated in 2026.
Cutoff date: content verified against official sources available as of August 22, 2026. Since the AI Act has evolving implementing acts, guidelines, and standards, organizations should periodically review the regulatory and technical status.