EU AI Act · Article 50 in force · marking deadline 2 December 2026
EU AI Act · Article 50 · in force since 2 Aug 2026

EU AI Act Article 50, explained

The AI transparency rulesIn force since 2 Aug 2026Fines up to €15M / 3% turnoverLast reviewed July 2026

Article 50 is the EU AI Act's transparency rulebook. While the Act's high-risk regime made the headlines (and had its deadlines moved), Article 50 is the part most websites will meet first: it decides when you must tell people they're dealing with AI (a chatbot, an AI-generated image, an AI-written article), and it has applied since 2 August 2026, with enforcement powers active from the same day.

This guide covers what the article requires, who it binds, what changed (and didn't) with the Digital Omnibus, the penalties, and how to check a live site the way a regulator would.

On this page The four disclosure duties Who Article 50 binds: providers, deployers, and non-EU companies The timeline: 2 August 2026, and the one carve-out What the Digital Omnibus delayed, and what it didn't Penalties and enforcement The EU labels and the Code of Practice How to check your own site Common questions Sources and further reading

The four disclosure duties

Article 50(1): chatbots must say they're AI

Any AI system that interacts directly with people (a support chatbot, a voice assistant) must make that clear no later than the first interaction, in a clear and distinguishable way. A line in your terms of service doesn't satisfy it, and neither does a robot icon on a human-sounding bot. There is a narrow exception where it's already obvious to a reasonably well-informed person, but a natural-language customer-service bot doesn't qualify just because it's named "Assistant."

This is a duty you most likely meet through configuration: most major chat widgets already support an AI disclosure, and the gap is usually that it's switched off, worded too weakly, or hidden until someone clicks. Our per-vendor guides show where the setting lives in Intercom, Zendesk, HubSpot, and 17 other widgets.

Article 50(2): synthetic media needs machine-readable marking

AI-generated or AI-edited audio, image, video, and text must be marked in a machine-readable format so it's detectable as artificially generated, via C2PA Content Credentials or IPTC provenance metadata embedded in the file itself. This is a provider-side duty on the generative system, but it fails quietly in practice: image pipelines and CDNs routinely strip metadata on optimization, so content that left the generator marked can arrive on your site unmarked.

Article 50(3): emotion recognition and biometric categorisation need notice

People exposed to emotion-recognition or biometric-categorisation systems must be informed the system is in operation. This one usually isn't visible on a website at all (it's an operational disclosure), which is why it can't be verified by an external crawl and needs an internal record instead.

Article 50(4): deepfakes and AI-written public-interest text need labels

Deepfakes must be visibly disclosed as artificially generated or manipulated. AI-generated text published to inform the public on matters of public interest (news-style content) must be disclosed too, with a carve-out where a human exercised editorial control and someone holds editorial responsibility. If you publish with AI in the loop, this is your duty as the deployer.

Who Article 50 binds: providers, deployers, and non-EU companies

The Act splits duties between providers (who build the AI system) and deployers (who put it in front of users). Running a third-party chat widget on your site makes the vendor the provider, but how the widget is configured and presented on your site, under your brand, is your deployment. "The vendor handles it" is worth confirming rather than assuming.

Geography doesn't exempt you either: Article 50 follows your users, not your headquarters. The Act expressly covers providers and deployers outside the EU whenever the system's output is used in the Union: a US or UK company with EU traffic is in scope. There is also no general small-business exemption: SMEs get lighter supporting measures and a lower fine cap, not a pass on transparency.

The timeline: 2 August 2026, and the one carve-out

What the Digital Omnibus delayed, and what it didn't

The Digital Omnibus, the EU's simplification package for the AI Act, pushed the high-risk regime's deadlines out to 2027–2028, and a lot of headlines compressed that into "the AI Act is delayed." Article 50 stayed in place. The transparency duties still apply from 2 August 2026, with the single Art. 50(2) carve-out described above. If your compliance plan is waiting on the delay, it's waiting on the wrong article.

Penalties and enforcement

Non-compliance with Article 50's operator obligations carries fines up to €15 million or 3% of worldwide annual turnover, whichever is higher (for SMEs and start-ups, whichever is lower). Enforcement sits with national market-surveillance authorities.

What makes Article 50 unusual is how easy it is to check: a regulator (or a competitor drafting a complaint) doesn't need your code or your paperwork. They open your site, start a chat, look at your published content. And the burden of showing the disclosure was there sits with you: authorities expect documented evidence (screenshots, configurations, timestamps), not verbal assurance. That asymmetry is why keeping dated evidence matters as much as the disclosure itself.

The EU labels and the Code of Practice

On 10 June 2026 the European Commission published the final Code of Practice on Transparency of AI-Generated Content, which includes a uniform set of EU icons and text labels for marking AI content and deepfakes (see the official icons, explained and free to download). Draft Commission guidelines on Article 50 were published in May 2026. Using the official label set isn't the only way to disclose, but it's the clearest signal of good faith available, and it's what our scanner looks for on article-like pages, alongside other visible disclosure patterns.

How to check your own site

The manual version takes a few minutes per page and is worth doing once. Grab the printable one-page checklist if you'd rather work from paper:

The automated version is what DisclosureProof does: it loads your homepage in a real browser (desktop and mobile), opens your chat widget the way a visitor would, samples your media for machine-readable marking, checks article-like pages for labels, and seals what it saw into a timestamped, hash-verified evidence record. The homepage scan is free, with no signup.

One thing to expect from any honest checker: a scan reports what was detected, not detected, or couldn't be verified. It can't declare you compliant, because parts of Article 50 (like whether an image is genuinely AI-generated, or Art. 50(3) systems) aren't externally observable. Anyone promising a green "compliant" badge from a crawl alone is overclaiming.

Common questions

Is Article 50 part of the EU AI Act's high-risk rules?

No. Article 50 sits in the transparency chapter, which is separate from the high-risk regime. That distinction matters for timing: the Digital Omnibus pushed several high-risk deadlines to 2027 and 2028, but it left the Article 50 transparency duties on 2 August 2026. It also means there is no conformity-assessment paperwork here. The duty is to disclose, and to be able to show that you did.

Does Article 50 apply to internal AI tools, or only public-facing ones?

The transparency duties attach to systems that interact with people or produce content those people see. A purely internal tool used only by trained staff who already know they are working with AI is a weaker case for public disclosure than a customer-facing chatbot or published AI content. Where an AI system's output reaches the public, or reaches EU users at all, the duties are far more likely to apply. When in doubt, treat anything a customer can see or talk to as in scope.

What counts as machine-readable marking under Article 50(2)?

A marking a detector can read from the file itself, rather than a visible caption. In practice that means provenance metadata such as C2PA Content Credentials or IPTC fields embedded in the image, audio, or video. The common failure is not the generator but the pipeline: optimisation steps and CDNs often strip metadata, so a file that left the tool marked can arrive on your page unmarked. That is why checking the published asset, not the export, is what counts.

Do I have to use the official EU AI-content icons?

The icons and labels in the June 2026 Code of Practice are not the only lawful way to disclose, but they are the clearest signal of good faith, and a supervisory authority will recognise them on sight. You can read what each one means on our guide to the official EU AI icons. Our scanner looks for the official label set on article-like pages, alongside other visible disclosure patterns.

Does Article 50(1) cover voice assistants and phone bots, not just chat?

Yes. The duty applies to AI systems that interact with people, whatever the channel. A voice assistant, an AI phone line, or an in-app agent all have to make the AI nature clear no later than the first interaction, in a form the person can perceive in that medium. A visual 'AI' badge does nothing on a phone call, so the disclosure has to fit the channel it runs on.

Is Article 50 in force now?

Yes. The EU AI Act entered into force on 1 August 2024 and applies in stages; the Article 50 transparency duties have applied since 2 August 2026. One narrow deferral remains: machine-readable marking under Article 50(2) for generative systems already on the market before that date, which runs until 2 December 2026. Since 2 August, an undisclosed chatbot or an unlabelled deepfake is not a future risk but a present breach.

Is the EU AI Act a regulation or a directive?

A regulation — Regulation (EU) 2024/1689. Unlike a directive, it needed no national transposition: the Article 50 duties read the same in every member state and bind companies directly. What does vary by country is supervision — each member state designates its own market-surveillance authorities and handles penalties nationally — which is why enforcement posture differs even though the duties do not. Our country guides track those differences.

What records should I keep to show I complied?

Keep dated evidence of what your site displayed: screenshots of the chat disclosure at first interaction on desktop and mobile, the widget configuration, and the labels on published AI content. Because the burden of showing the notice was there sits with you, contemporaneous timestamped records are worth more than a later reconstruction. A DisclosureProof scan captures and seals exactly this, but the point holds however you record it.

Sources and further reading

This page summarises the rules for orientation. It is not legal advice, and the statute text linked above is the authority. Where your situation is non-obvious, involve qualified counsel.

Check your own site. One free scan returns your Article 50 findings (chat-widget disclosure at first interaction, media marking, and labels), with a sealed evidence record either way. Run the free scan →