Who has to label AI content, and when.
A question arrives in almost every room now, and it is a practical one: do I have to put a label on this, and if so, what kind? Since 2 August 2026 the EU AI Act answers it — more specifically than “be transparent about AI”, and more narrowly than most organisations fear. Four duties, two roles, five exceptions. The work is knowing which of them are yours.
Regulation (EU) 2024/1689, Article 50 · current as at 04-08-2026 · read with the Commission’s implementation Guidelines, C(2026) 5054 final of 20-07-2026
The transparency obligations became applicable, and they were not deferred.
Much of the AI Act moved. The principal high-risk obligations were pushed out to 02-12-2027 and 02-08-2028 by the Digital Omnibus on AI — Regulation (EU) 2026/1744, in force since 27-07-2026. Article 50 did not move. It became applicable on 02-08-2026 and it is now the provision of the Act that reaches the largest number of organisations — and the one whose duties land furthest from the technology team: on marketing, communications, HR, investor relations and public affairs.
It is also narrower than the anxiety around it suggests. Article 50 is four distinct duties, split between two roles, with five exceptions. Most organisations owe one or two of them. Almost none owe all four. This guide walks the four questions you need to answer about any system or any piece of content you hold — and it is the operational companion to the EU AI Act, explained and the timeline.
The obligation is more specific than “be transparent about AI”, and narrower than most organisations fear.
The four duties, at a glance.
Two of the four fall on whoever built and released the system. Two fall on whoever uses it. That split is the whole architecture, and almost every misunderstanding in practice is a failure to see it.
| What triggers it | Provision | Whose duty | What is owed |
|---|---|---|---|
| The system interacts directly with people | Art. 50(1) | Provider | Design it so the person is told they are dealing with an AI system. |
| The system generates or manipulates synthetic audio, image, video or text | Art. 50(2) | Provider | Mark the output machine-readably, so software can detect that it is artificial. |
| The system performs emotion recognition or biometric categorisation | Art. 50(3) | Deployer | Inform the people exposed to it that the system is operating. |
| The output is a deep fake, or text published to inform the public on matters of public interest | Art. 50(4) | Deployer | Disclose visibly that the content is artificially generated or manipulated. |
Four gates, in the order a reader meets them.
Take any one system, or any one piece of content, and walk it down. If it stops at any gate, you are finished with it.
- Gate 1Provider · Deployer · both at once
Which role are you in, for this system?
The question is per system, not per company. Both answers can be true of the same organisation on the same day.
- Gate 2One of four triggers — or none
Does anything you hold actually engage Article 50?
Most organisations engage one or two. Almost none engage all four. Nothing engaged means nothing to disclose.
- Gate 3Five exceptions, four of them narrow
Does an exception apply?
An exception either reduces the disclosure or removes it. Read them restrictively; they are drafted narrowly.
- Gate 4Clear · distinguishable · at first exposure · accessible
What must the disclosure actually look like?
This is where most compliance fails — not by omitting the disclosure, but by placing it where nobody sees it.
Which role are you in, for this system?
Not “is my company a provider or a deployer”. The question is asked per system, and both answers can be true at once.
You released it under your own name
You develop an AI system, or have one developed, and place it on the market or put it into service under your own name or trademark — whether paid for or free. It includes the organisation that builds a chatbot in-house and puts it into service for its own use. It also includes a company that takes an existing generative system and modifies it, with new training data for instance: it becomes the provider of the new system.
You use it under your authority
You use an AI system under your authority, in a professional capacity. Authority means responsibility for the decision to deploy and for how the system is used. It does not require technical control — you need never have seen the model to be its deployer.
The common case, and the one that doubles the work
Build a generative system in-house and use it to make a deep fake, and you owe the Article 50(2) marking duty and the Article 50(4) labelling duty. Two roles, two duties, one organisation — and each duty has to be discharged separately, because discharging one does nothing for the other.
Who is not a deployer. This list matters, because organisations routinely assume they are caught when they are not.
- Your own employees and contractors. The legal person remains the deployer. Digital animators, web designers, content creators and journalists acting under its instructions are not separate deployers.
- A company that commissions an advertising agency without taking decisions or exercising control over whether and how the agency uses AI. Control, not commissioning, is the test.
- Hosting services, online platforms and broadcasters whose role is limited to disseminating or transmitting third-party content. They are strongly encouraged to preserve marks and labels, but they are not responsible for them under the AI Act.
The reach extends beyond the Union. Providers established outside the EU are caught where the output of their system is used in the Union. Third-country deployers are caught where they foresee dissemination and use of the output in the Union — expressly including by posting deep fakes to the open internet — but not where content arrives through channels that are unforeseeable and outside their control.
Where you sit on the provider–deployer line, and how ordinary configuration decisions can move you across it, is the subject of its own guide: deployer or provider?
Does anything you hold actually engage Article 50?
Four triggers. The value is in the Commission’s own lists of what is in and what is out — they settle arguments that would otherwise run for weeks.
Direct interaction with people Art. 50(1) · provider
Four cumulative elements: an AI system · intended to interact · directly · with natural persons. Interaction means a genuine two-way exchange with a conversational or responsive character. It need not be started by a human, and a single turn is enough.
- Voice assistants
- Chatbots in customer support, complaints, e-commerce, finance, healthcare, education and public service
- AI hotlines for incident or fraud reporting
- Robots, including collaborative robots (“cobots”) designed to work in a shared space alongside people
- AI companions and robotic companion pets
- Avatars in virtual environments
- Social-media bots
- Coding agents and other agents capable of direct interaction, including inside multi-agent architectures
- Industrial robots in closed settings
- Recommender systems
- Spam filters
- Automated translation and transcription
- AI-enabled search and retrieval that neither generates nor modifies content
- Text and code auto-completion
- Authentication and biometric recognition
- Backend decision support, where the user sees only an output
- Predictive maintenance
- Virtual try-on and product rendering
- Single-turn route planning
An agent must disclose two things: that it is artificial, and the person on whose behalf it is acting. Where the provider cannot know in advance whether the agent will meet a person, the agent must be designed at architecture level to disclose whenever that is reasonably likely — including where the person on the other side represents a company rather than themselves.
Agents must also disclose to the people instructing them at key steps — authorisation, reporting, validation — and at every new interaction. This is the most forward-looking part of Article 50, and it lands squarely on anyone deploying the patterns set out in agentic AI design patterns and briefed with the method in delegate the goal, not the task.
Synthetic audio, image, video or text Art. 50(2) · provider
It applies across text, image, audio and video, including multimodal content, 3-D, virtual and augmented reality, and digital twins. Content that mixes human and AI work still counts. What follows is what falls outside — and it removes a great deal of anxiety.
| Outside the duty | Why |
|---|---|
| Rendered frames and simple data processing | No generative step — the system is displaying, not creating. |
| Reproduction, presentation or arrangement of existing content | Playlists and recommender output rearrange; they do not generate. |
| Observation and recording from sensors | Smart meters, GPS traces and instrument logs record the world; they do not synthesise it. |
| Short sequences of numbers, symbols or letters | Single words, image captions, alt-text and interface labels. |
| Source code | Including SDKs, SQL, infrastructure-as-code, YAML, JSON, schemas, APIs — and the natural-language comments inside code. |
| Machine-to-machine output never perceived by a person | If no human ever sees it, there is nobody to inform. |
| Closed-loop industrial and production workflows | Only the final output must be marked, not each intermediate artefact. |
Emotion recognition and biometric categorisation Art. 50(3) · deployer
A deployer duty, and it applies both in real time and after the fact. Two points deserve emphasis, because both are routinely missed. All emotion recognition systems are also high-risk unless they are prohibited outright — which they are, under Article 5(1)(f), in the workplace and in education. And Article 50(3) catches any biometric categorisation system, age or gender classification from biometric data included, whether or not it is high-risk.
Deep fakes, and text published on matters of public interest Art. 50(4) · deployer
The trigger most organisations actually meet, and the one most often misjudged. It has its own section below, because a deep fake is a narrower and stranger category than the word suggests.
Does an exception apply?
Five. It is worth being candid that four of them are narrower than organisations hope — and that an exception more often reduces the disclosure than removes it.
Obviousness — Article 50(1) only
The test is whether the artificial nature is obvious to a reasonably well-informed, observant and circumspect member of the intended and reasonably foreseeable audience. Two steps: identify the audience, then calibrate to it. Vulnerable audiences — children, elderly people, people with disabilities or lower AI literacy — lower the standard you may assume; a professional, specialised audience raises it.
Read it restrictively. The exception is limited to cases where there is almost no doubt left about the nature of the interaction, and the Commission is explicit that general awareness that chatbots exist does not mean people recognise them in an interaction.
- Developer-only code assistants
- Internal assistants for trained, AI-literate staff in HR, legal, procurement, compliance or IT
- Clinician-only diagnostic support
- Ambient AI confined to operating a home appliance
- Non-player characters in a single-player game
- Realistic robotic companion pets
- Immersive avatars and human-sounding voices
- Ordinary helpdesk and platform chatbots
And it does not travel. Consumer-law information duties apply irrespective of whether the interaction is considered obvious. Where a service is AI-driven, that functionality may be an essential characteristic requiring pre-contractual disclosure under the Consumer Rights Directive.
Standard editing and non-substantial alteration — Article 50(2)
- Grammar and spellchecking; minor stylistic polish
- AI translation; transcription
- Formatting, format conversion, compression, noise reduction
- Minor cropping, colour adjustment, lightening, sharpening
- Dust-spot and red-eye removal; blurring or pixelating faces
- Rescaling and limited stabilisation
- Medical image reconstruction
- Assistive communication technologies, including custom neural voices
- AI-generated summaries
- Paraphrasing that changes style, structure or meaning
- Removal, replacement or insertion of objects or people
- Face replacement or substantial facial modification
- Realistic speech synthesis in a specific person’s voice
- Realistic video of events that did not occur
- Altering body shape or skin colour
- Composite images that modify the representation of persons, objects, events or facts
The right-hand column is the one to circulate. It is where ordinary marketing and communications work crosses the line without anyone intending it to.
Human review and editorial responsibility — Article 50(4), text only
Two cumulative conditions, both demanding.
- Substantive human review or editorial control. A deliberate examination of the substance, by people with relevant knowledge and professional judgement, with fact-checking as a minimum — or control by a responsible editorial entity able to approve, alter or reject on substantive grounds. Expressly insufficient: superficial, formal or procedural checks; spell-checking; the mere existence of an editorial policy; automated review; cursory approval.
- A person or body holding editorial responsibility, whose identity and contact details are publicly available in an easily findable location — website legal information, or a colophon.
The rule that voids it. Any substantive AI intervention after editorial sign-off — reformulating, supplementing, generating the summary or the headline — makes the content AI-generated again for Article 50(4) purposes.
Purely personal, non-professional use — deployers only
Any activity from which a natural person gains economic benefit on a regular basis, or which is professional, business, trade, occupational or freelance, is professional use. The provider’s duty survives it: the provider of a system used to make a deep fake for a personal Christmas card still owes the Article 50(2) marking duty.
Law enforcement
Available where a system is authorised by Union or national law to detect, prevent, investigate or prosecute criminal offences, subject to safeguards. One limit is worth knowing: it does not apply where the system is publicly available and offers a functionality to report criminal offences. Police chatbots on official websites, fraud-reporting portals and witness-statement assistants all remain subject to Article 50(1).
One further line, on research. AI systems developed and put into service for the sole purpose of scientific research fall outside the Act altogether, as does pre-market research, testing and development — except testing in real-world conditions, which remains in scope.
What must the disclosure actually look like?
Article 50(5) sets four requirements: the disclosure must be clear, distinguishable, given at the latest at the first interaction or exposure, and conform to applicable accessibility requirements.
Clear means noticeable, easy to understand and accessible. Distinguishable means easy to identify as separate from the surrounding information and environment. A disclosure fails if it can be easily overlooked or missed under normal conditions — buried in a manual, hidden under menu layers, or placed in terms of use that are often not read.
First exposure means each person’s first exposure, not the first person’s. For generated content the duty attaches to each output, with respect to any person exposed to it. Disclosure only at the start of a video is not enough where people foreseeably join partway through.
- Disclosure only in terms and conditions, at a URL, or in documentation.
- A machine-readable mark or watermark the person cannot perceive at the point of interaction.
- Ambiguous signals — a generic “assistant” — or human-like presentation that misleads.
- A blanket statement such as “services on this website use AI”.
- A technology description such as “this system uses LLMs”, which explains the technology rather than the function or its implications.
What works. Textual: a plain-language banner or first-turn greeting — “You are interacting with an AI system” — placed near the input field, optionally with a persistent badge. Auditory: an explicit spoken statement at the start — “This is an AI-powered assistant” — with periodic reminders in longer interactions; tones alone are not sufficient. Visual: persistent icons, watermarks or recognisable “AI” symbols complementing the text. Best practice is a combination across modes.
When once is not enough. A single prominent notification before the first interaction will usually suffice. Periodic, context-aware reminders are likely to be necessary where the audience includes vulnerable persons; in sustained, sensitive or immersive interactions, including where users may experience emotional distress or addiction-like behaviour; where there is a heightened risk of being misled — financial advice, insurance, legal assistance, health advice and complaints handling; with AI companions; and where an agent is taking actions. In every case, the system must disclose its nature when asked.
The EU icon. The voluntary Code of Practice on Transparency of AI-generated Content carries a freely usable EU icon whose main visual element is the capitalised acronym “AI” — in English, or in the national language where national language law requires it — with equal letter heights and proportions preserved on resize. Signatories are encouraged to add an interactive second layer stating whether the content was generated or modified, and what was modified. It should be immediately recognisable without any action by the user; for video, at the start and at intervals and after interruptions, so that it survives clipping and screenshots; for published text, above or near the headline, or in the colophon. Where visual disclosure is impossible, a short audible disclaimer in plain language at the beginning.
What a deep fake actually is.
Article 3(60) defines it as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events, and would falsely appear to a person to be authentic or truthful. Note what is absent: text is not in the deep-fake limb. Text has its own regime, set out further down.
Four criteria, all of which must be met.
- Appreciable resemblance. A high level of similarity in characteristic or distinctive features. Not identity — resemblance is enough.
- Existing. Or plausibly existing, or plausibly having existed. Content that defies nature or physics is unrealistic, and outside.
- A person, object, place, entity or event. Persons include digital replicas, realistic avatars and personas — and personal characteristics such as image, voice, behaviour and performance.
- Would falsely appear authentic or truthful. Judged as a whole, against the intended and reasonably foreseeable audience and the deployment context.
You do not need to have meant to mislead anyone. The assessment is objective and does not require any intention on the deployer’s part to deceive. A cheerful corporate video made in complete good faith is a deep fake if the four criteria are met.
Photorealism alone does not decide it, and neither does the absence of a real person. A wholly synthetic influencer who never existed is still a deep fake where they resemble someone who plausibly could. A real car in front of an AI-generated landscape is not.
| Is a deep fake | Is not |
|---|---|
| Two real footballers placed by AI in front of a stadium-like building | A sphinx flying over the Eiffel Tower |
| Cloned voices of a podcast’s regular presenters discussing the news | Mice arguing in human language about cheese, in a cheese advertisement |
| A video of someone resembling a politician giving a speech | AI voice replication for fictional characters in audiobooks or games, where nobody is deceived about the narrator |
| A synthetic depiction of a celebrity influencer in an advertisement | An AI-generated cartoon of an existing photograph of a historical event |
| A realistic synthetic avatar of a company chief executive congratulating employees on the year’s results | Audio normalisation and noise reduction that leave the words and the delivery intact |
| A product image that misleads about the product’s real appearance, characteristics or use | A real car shown against an AI-generated background, where the advertisement does not mislead about the car |
What is permitted, and on what condition.
“Permitted” carries two different meanings here, and conflating them is the most common error in the room.
Permitted with a lighter disclosure — the artistic route
Where a deep fake forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, the duty is reduced: disclosure in an appropriate manner that does not hamper the display or enjoyment of the work — in accompanying notes, in credits, adjacent to the frame, or at the point of entry or sale. Reduced, never removed.
The categories are read strictly, precisely because the lighter regime exists to protect freedom of expression and of the arts. Content whose nature is potentially unclear or ambiguous to the audience is excluded. And for mixed content the rule is decisive: where a deep fake combines several characters — say informative and creative — the informative character prevails, and full labelling applies.
- Films and trailers using de-aged actors or digital replicas of deceased performers
- AI-generated music resembling an existing artist’s style
- A satirical image placing a politician in a scene that clearly criticises a policy through humour
- Gaming imagery simulating real people
- A teleshopping-style video where synthetic people demonstrate a product to persuade viewers to buy
- AI images implying celebrities did things they never did, with no satirical or fictional purpose
- A synthetic influencer testing a sponsored product
- Realistic AI-generated Holocaust scenes on public social media
Not permitted at all — and a label does not change that
Applying a label does not affect the potential illegality of the content under other frameworks. Child sexual abuse material and non-consensual intimate images remain criminal, and from 02-12-2026 the AI Act itself carries new Article 5 prohibitions covering them. Trademark and copyright infringement, misleading advertising, and personality rights over image and voice are all unaffected by a label. And where a living person is depicted, the deployer is a controller under data protection law and needs a legal basis.
The label answers one question: was this made by a machine? It does not answer whether you were allowed to make it, allowed to publish it, or allowed to use the material you made it from.
Published text on matters of public interest.
Three elements, all of which must be present. Published — accessible to an indeterminate, fairly large number of unrelated readers, whether paid for or free. Private professional correspondence and organisation-internal communications, including intranet publications, are not published. Informing the public — communicating knowledge, opinions or facts. On matters of public interest — relevant to society at large and meriting public debate or scrutiny: politics and democratic processes, public administration and services, justice and law enforcement, fundamental rights, public security, public health, the environment, consumer safety, and economic, financial, political, scientific or cultural developments.
| Caught | Not caught |
|---|---|
| An AI-generated summary of an article about a town-council decision | AI-generated fantasy novels |
| AI-manipulated parts of an article on the effects of diets on a disease | AI-manipulated advertising and product descriptions, absent health, safety or sustainability claims |
| AI-manipulated corporate reports carrying investor information on a listed company’s website | A chatbot news summary visible only to the person who prompted it |
| An AI-generated storm warning on a meteorological institute’s social media | AI-manipulated text by a consultant advising a client on regulatory compliance |
That last exclusion deserves to be said plainly rather than left for professional readers to infer: text a consultant writes to advise a client on regulatory compliance is not caught. It is not published to the public. The corporate report on a listed company’s website, on the other hand, is.
These guides are AI-assisted text, published to inform the public on matters of public interest — precisely the shape of content Article 50(4) reaches. They fall outside the labelling duty because each one undergoes substantive human review, with editorial responsibility held by a named person whose contact details are published. Kramer Consulting discloses the AI assistance anyway, at the foot of every guide. The exception is available; using it is not a reason to say less.
Marking is not labelling.
The provider marks the output machine-readably, so that software can detect it. The deployer labels it, so that a person can see it. They serve different audiences, and neither discharges the other.
Machine-readable mark
Placed by the provider
Read by software — detection tools, platforms, downstream systems
Visible label
Placed by the deployer
Read by a person — the viewer, the reader, the audience
Two disclosures · two audiences · neither substitutes for the other
The Commission is explicit on the point: deployers cannot rely on the machine-readable marking embedded in the content by the provider under Article 50(2), because those markings are not immediately clear and distinguishable.
This is the misunderstanding most likely to produce an actual breach, because the intuition runs the other way — we used a compliant tool, so we are compliant. The tool’s provider discharged the tool’s provider’s duty. The visible label on the published video is yours. It is the same structural error examined in running your own AI isn’t compliance: a technical property of the system is mistaken for a legal answer about its use.
The obligation lands on a desk, not on a system.
Articles 50(3) and 50(4) bind the deployer — which, in practice, means whoever decided to make and publish the content. That is marketing, communications, HR, investor relations and public affairs. It is almost never the engineering team that selected the model, and it is rarely the person who reads the compliance memo.
So Article 50 is not primarily a legal-drafting problem. It is a workflow and literacy problem: someone in the content chain has to recognise, at the moment of making, that what they are making is a deep fake — and that the badge is their job. No policy document catches that. Only a person who knows what they are looking at does.
That is the Ownership competency in operational form, one of the four in the AI-era skills taxonomy: full professional responsibility for AI-assisted work, held by the person who made it. It is also why capability and governance multiply rather than add, the argument set out in the AI Value Equation — and why the controls only work when they are lodged in the people doing the work, the subject of AI governance, explained.
Article 50 is not a legal-drafting problem. It is a question of whether the person making the content recognises what they are making.
The compact version.
All four duties. The date was not deferred: the Digital Omnibus moved the principal high-risk obligations to 02-12-2027 and 02-08-2028, and left Article 50 where it was.
A four-month window, inserted by Regulation (EU) 2026/1744, for systems already on the market. It covers the Article 50(2) marking duty only.
Covering non-consensual intimate images and child sexual abuse material. The same date as the transition, and entirely unrelated to it.
Three points on the transition, because they are widely misstated. The window sits in Article 111(4), as inserted by Regulation (EU) 2026/1744 — not in Article 50 — and it runs for four months, not three. It covers the marking duty under Article 50(2) and nothing else: a system that is partly interactive and partly generative benefits from it only as regards marking, and the Article 50(1) interaction disclosure was due on 02-08-2026. Most commercial chat products are exactly that shape, so the window is not a general reprieve. And the new Article 5 prohibitions falling on the same day are a separate matter entirely.
The obligations are not retroactive. They attach to content generated or systems placed on the market from the applicable date, not to an archive.
Consequences. Breaches of Article 50 sit in the middle tier of the Act’s penalty regime: up to 3% of total worldwide annual turnover. Each ceiling has two limbs — a share of turnover and a fixed sum — and the higher of the two applies; for SMEs and start-ups it is the lower that applies instead. Beyond penalties, any person may lodge a complaint with the national market surveillance authority, and the label does nothing to cure illegality under other frameworks. The evidence that these regimes are in fact enforced is set out in hiding your AI system isn’t hiding the risk.
The voluntary Code. The Code of Practice on Transparency of AI-generated Content was published on 10-06-2026, received a Commission adequacy opinion on 08-07-2026 and was endorsed by the AI Board on 09-07-2026. Signing is not required, and not signing is not a breach — but adherence is the most direct way to demonstrate compliance to a supervisory authority. As at 31-07-2026 it had roughly 190 signatories.
One honest note, on what the Guidelines are worth. The Commission’s Guidelines of 20-07-2026 are formally non-binding, and they say so themselves. In practice they carry more weight than that label suggests. By publishing how it reads Article 50, the Commission limits its own discretion: under settled case law of the Court of Justice, an institution that adopts and announces rules for its own administrative practice cannot then depart from them in an individual case without breaching the general principles of equal treatment and the protection of legitimate expectations. In that sense the Guidelines bind their author. They do not bind national authorities or national courts — but most supervisory authorities can be expected to align their enforcement practice with the Commission’s stated position, and a national court must take that position into consideration. Authoritative interpretation of the Regulation itself remains with the Court of Justice.
Going to the sources. The Commission maintains a short public summary of these rules — Quick facts: transparency rules for AI systems — alongside the Guidelines and the Code of Practice themselves.
Does the person making the content know it needs a label?
Thirty minutes to walk your own systems and content down the four gates, and see which duties are actually yours. No pitch.
Related guides
The EU AI Act, explained
Heard of it, hazy on the detail? Grasp it through two laws you may already know — GDPR and product-safety regulation.
Read the guide Provider or deployerDeployer or provider?
Most companies using AI are “deployers”, with manageable duties. But configure, rebrand or repurpose that AI and the Act can treat you as its “provider” — with a manufacturer’s full obligations. The line, and how not to cross it by accident.
Read the guide AI Act timelineThe EU AI Act timeline
From a 2021 proposal to a law that lands in waves. The full chronology — adoption, entry into force and every date of application — what each wave switches on, who it binds, and the one high-risk deadline that has moved.
Read the guide