The EU AI Act's transparency rules now apply. That does not mean every sentence, image or spreadsheet touched by AI needs a warning label. It does mean that organisations need to know which AI systems they provide, which they deploy, what those systems do, and who encounters their outputs.
That distinction is where practical compliance starts. Article 50 assigns different duties to providers and deployers, covers several specific situations, and includes exceptions that depend on context. A generic "AI was used" footer cannot repair a missing system inventory or an incorrect role assessment.
For most businesses, the sensible order is inventory first, labels second.
What changed on 2 August 2026
Regulation (EU) 2024/1689 entered into force in August 2024 and applies in stages. Article 50 sits in Chapter IV and its transparency obligations apply from 2 August 2026. The Commission now describes the rules as enforceable by the AI Office and national authorities, according to their respective remits.
Article 50 addresses four situations:
- AI systems intended to interact directly with people;
- AI systems that generate or manipulate synthetic audio, images, video or text;
- emotion recognition and biometric categorisation systems; and
- deployer use of AI to create deepfakes or certain text published to inform the public on matters of public interest.
These categories overlap, but they are not interchangeable. A customer-service chatbot raises the direct-interaction rule. A provider of an image generator may have a machine-readable marking duty. A marketing team publishing a synthetic video that depicts a real person may have a separate deepfake disclosure duty as deployer. One workflow can trigger more than one obligation.
Start by identifying your role
The Act defines a provider as the person or organisation that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer is the person or organisation using an AI system under its authority, except for purely personal, non-professional activity.
In plain business terms, buying access to a third-party model usually puts you in the deployer column. Building an AI assistant and offering it under your brand may put you in the provider column. Developing an internal system and then using it can put you in both columns.
The Commission's guidelines make the same point: roles can be cumulative. They also distinguish a deployer from an actor that merely hosts or transmits third-party content without authority over the AI system used to create it. Contracts and vendor names do not settle the question. Control, branding, purpose and actual use do.
Before choosing a label, record at least:
- the system, owner, vendor and version;
- where it is offered or used, and whether its output is used in the EU;
- intended users and people exposed to it;
- input and output modalities;
- whether the organisation is provider, deployer or both;
- whether the system interacts directly with people;
- whether it generates or substantially manipulates synthetic content;
- whether outputs can constitute deepfakes or public-interest text;
- the disclosure, marking and accessibility controls already present; and
- the exception relied on, its evidence, owner and review date.
This inventory is not paperwork for its own sake. It exposes the awkward cases that a publishing policy misses: a voice bot in customer support, an avatar in onboarding, an AI agent emailing suppliers, image editing inside a design suite, or a communications agency producing content on the company's instructions.
Interactive AI: tell people when they are dealing with a system
Providers of systems intended to interact directly with natural persons must design them so that people are informed they are interacting with AI. The information must be clear and distinguishable, accessible, and provided no later than the first interaction or exposure.
The rule has an "obviousness" exception. Disclosure is not required when the AI nature of the interaction would be obvious to a reasonably well-informed, observant and circumspect person, taking the circumstances and context into account. That is a contextual test, not permission to assume that everyone recognises a polished voice, avatar or agent as artificial.
A clear notice at the start of a chat or call is usually easier to defend than an ambiguous bot name or a statement buried in terms and conditions. The notice should reach the person who interacts with the system, not merely the procurement team that bought it.
The law-enforcement exception is narrow and subject to safeguards. It does not remove the information duty for systems made available to the public to report a criminal offence. Most commercial teams should not build their compliance position around it.
Synthetic output: machine-readable marking is a provider duty
Article 50(2) applies to providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text. They must ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated.
The technical solution must be effective, interoperable, robust and reliable as far as technically feasible. The Act expressly allows consideration of content-specific limitations, implementation cost and the generally acknowledged state of the art. The Commission's voluntary Code of Practice offers a recognised route for demonstrating compliance with the marking and detection duties, but the legal obligation comes from Article 50, not from signing the code.
This requirement is not the same as placing a visible badge on every output. Machine-readable provenance and human-facing disclosure solve related but different problems. Metadata, embedded signals or other technical measures may support detection downstream; a visible notice tells the person in front of the content what they need to know.
Nor does Article 50(2) cover every edit. The provision excludes systems to the extent that they perform an assistive function for standard editing or do not substantially alter the deployer's input data or its semantics. It also contains the specified law-enforcement exception. Spell-checking, formatting or a minor technical correction should not be casually equated with generating a synthetic article or replacing a speaker in a video. Teams still need to document why an edit is non-substantial rather than treating the exception as a blanket exemption for familiar software.
Deepfakes: the deployer has a visible disclosure job
A deepfake has a narrower legal meaning than "AI-made media." The Act defines it as AI-generated or manipulated image, audio or video that resembles existing people, objects, places, entities or events and would falsely appear authentic or truthful.
When a deployer uses an AI system to generate or manipulate content that meets that definition, it must disclose that the content was artificially generated or manipulated. This is why an inventory needs to follow the production workflow, not stop at the model vendor. The provider may be responsible for a machine-readable mark; the organisation publishing the deepfake may separately owe a clear disclosure.
There is a special regime for content that forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme. Disclosure is still required, but it can be made in an appropriate way that does not hamper display or enjoyment. "Creative" is not a magic word that cancels transparency. It changes how the disclosure may be delivered.
The practical test is specific. Does the media resemble something existing? Could it falsely appear authentic or truthful? Who controlled the use of the AI system? Where will people first encounter the result? A stock-style illustration generated from scratch may be synthetic content without being a deepfake. A cloned executive voice delivering words the executive never said may be both.
Public-interest text: do not turn a targeted rule into a universal label
Article 50(4) also covers deployers that generate or manipulate text published for the purpose of informing the public on matters of public interest. In that case, the deployer must disclose that the text was artificially generated or manipulated.
The wording matters. It does not say that all AI-assisted text needs a label. Internal notes, product descriptions, private correspondence and many routine commercial texts will require their own scope analysis, but they are not automatically public-interest publications under this paragraph.
The provision also contains an important exception where the AI-generated content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for publication. A token glance is a weak basis for that exception. A stronger process names the editor, records the review, checks material claims and confirms who accepts responsibility for publication.
This is one reason an editorial control log can matter more than a decorative label. If the organisation relies on the exception, it should be able to show what was reviewed, by whom, under which standard and before which publication decision. Other disclosure duties or sector rules may still apply; Article 50 does not erase them.
Do not forget emotion recognition and biometric categorisation
Article 50 is often discussed as a content-labelling rule, but paragraph 3 addresses deployers of emotion recognition and biometric categorisation systems. They must inform exposed people that the system is operating and process personal data in line with the applicable EU data-protection framework.
That matters for workplace tools, audience analytics, access systems and customer research. Some AI uses may also fall under prohibited-practice or high-risk rules elsewhere in the Act. Article 50 compliance does not make the rest of the AI Act disappear.
A 30-day implementation plan
Days 1-7: map systems and owners
Ask procurement, IT, product, marketing, HR, legal and security for the AI tools they build or use. Include features embedded in larger platforms. Record purpose, modalities, geography, users, exposed people and accountable owner.
Days 8-14: classify roles and outputs
For each use case, decide whether the organisation is provider, deployer or both. Test direct interaction, synthetic generation, substantial manipulation, emotion or biometric use, deepfake characteristics, and public-interest publication. Record which Article 50 paragraph is relevant.
Days 15-21: verify controls and vendor evidence
Check the first-interaction notice, accessible presentation, machine-readable marking capability, retention of provenance through export, visible disclosure placement and editorial review evidence. Do not accept "AI compliant" as a vendor answer. Ask which output formats carry marks, what removes them, how detection works and what documentation supports the claim.
Days 22-30: fix gaps and set review triggers
Implement missing notices and disclosures, update publishing and approval procedures, and assign an owner for exceptions. Add review triggers for model changes, new output modalities, rebranding, new channels, material changes to editing functions, and expansion into the EU.
The useful compliance question
The poor question is, "Where should we put an AI label?" The useful question is, "Which system, role, output and audience put us within which part of Article 50?"
Once that answer is documented, labels and technical marks become implementation decisions rather than guesswork. Enclave Guard's AI and automation work can help teams map systems and technical controls, while our virtual CISO service can support governance ownership and evidence. Teams reviewing the security of AI-enabled services may also find our Security Bench assessment useful before contacting Enclave Guard about a scoped review.
This article is for general informational purposes only and does not constitute legal advice. The application of the EU AI Act depends on the facts, roles, system design, jurisdiction and use context. Obtain qualified legal advice for your organisation's circumstances.
Primary sources and further reading
- EUR-Lex, Regulation (EU) 2024/1689 (Artificial Intelligence Act)
- European Commission AI Act Service Desk, Article 50: Transparency obligations for providers and deployers of certain AI systems
- European Commission AI Act Service Desk, Article 3: Definitions
- European Commission, Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act
- European Commission, Guidelines on transparency obligations for providers and deployers of certain AI systems
- European Commission, AI Act regulatory framework
- European Commission, Code of Practice on Transparency of AI-generated Content
- European Commission, Commission starts enforcing AI Act rules and new transparency requirements on 2 August



