Regulation
EU AI Act Article 50: AI transparency and disclosure explained
EU AI Act Article 50 requires companies to tell people when they are dealing with an AI system and to mark or label certain AI-generated content. It has applied since August 2, 2026 (opens in a new tab), with extra time until December 2, 2026 only for machine-readable marking by generative AI systems already on the market. This guide explains each paragraph in plain words and shows how to disclose AI in voice, chat and email agents.
By the KDS security engineering teamPublished 10 min read
Key takeaways
- Article 50 has applied since August 2, 2026, including to AI systems already in use on that date.
- Providers must design agents so people learn they are dealing with AI, at the latest at the first interaction.
- Deployers must disclose deepfakes and AI-generated public-interest text, unless a person with editorial responsibility reviewed the text.
- The Digital Omnibus kept the start date and gave existing generative AI systems until December 2, 2026 for marking.
- Article 50 fines can reach EUR 15 million or 3% of worldwide annual turnover, whichever is higher.
On this page
What EU AI Act Article 50 covers
Article 50 of the AI Act (opens in a new tab), Regulation (EU) 2024/1689, sets transparency duties for AI systems that talk with people or create content. They apply in addition to any high-risk rules.
The article has seven paragraphs. Paragraphs 1 and 2 bind providers: companies that develop an AI system, or have it developed, and place it on the market or put it into service under their own name. Paragraphs 3 and 4 bind deployers: organizations that use an AI system in their professional activity. Paragraph 5 sets how and when people must be informed, paragraph 6 keeps other laws in place and paragraph 7 covers codes of practice.
The rules also reach companies outside the EU. According to the Commission's guidelines on Article 50 (opens in a new tab), a provider in a third country is covered when it places a system on the EU market or when the system's output is used in the EU. Our EU AI Act guide explains the roles and risk tiers of the whole regulation.
Who must do what under Article 50
| Paragraph | Who | Duty | Main exceptions |
|---|---|---|---|
| 50(1) AI that interacts with people | Providers | Design the system so people are informed they are interacting with AI | Obvious from the context; law enforcement systems, unless the public uses them to report a crime |
| 50(2) Synthetic content | Providers of generative AI, including general-purpose AI systems | Mark outputs in a machine-readable format so they can be detected as AI-generated | Assistive editing that does not substantially change the input; law enforcement |
| 50(3) Emotion recognition and biometric categorization | Deployers | Inform the people exposed and follow EU data protection law | Uses permitted by law to fight crime |
| 50(4) Deepfakes | Deployers | Disclose that image, audio or video content was AI-generated or manipulated | Law enforcement; lighter disclosure for evidently artistic, satirical or fictional works |
| 50(4) Public-interest text | Deployers | Disclose AI-generated text published to inform the public on matters of public interest | Human review or editorial control with editorial responsibility; law enforcement |
| 50(5) Form and timing | Providers and deployers | Inform clearly, distinguishably and accessibly, at the latest at the first interaction or exposure | None |
Paragraph 1: telling people they are talking to AI
If an AI system is intended to interact directly with people, the provider must design it so those people are informed they are dealing with AI. The guidelines list four conditions that must all be met: it is an AI system, it is intended to interact, the interaction is direct and the other side is a natural person.
This covers chat and voice agents in support, sales and booking. It also covers AI agents that call or write to people during a task. The guidelines expect such agents to disclose that they are AI and on whose behalf they act. Rule-based auto-replies, such as a classic out-of-office email, are not AI systems and fall outside the rule.
The guidelines treat a company that builds a chatbot in-house and runs it under its own name as the provider. A business that commissions an agent and runs it under its own brand is usually in the same position.
When staff use AI to draft a reply and send it as their own, the person is the main contact, so the message is not a direct AI interaction. The mere option for a person to step in does not remove the duty.
The obvious-from-context exception
No notice is needed when a reasonably well-informed, observant and careful person would find the AI obvious, given the context. The guidelines read this exception narrowly. It can fit a code assistant used only by developers or an internal assistant for trained staff, but not a help desk chatbot that customers may take for a human. A provider that relies on it must be able to show why.
Paragraph 2: machine-readable marking of AI content
Providers of systems that generate synthetic audio, images, video or text must mark the outputs in a machine-readable format so they can be detected as AI-generated. The technical solution must be effective, interoperable and reliable as far as technically feasible, given the type of content, the cost and the state of the art.
The duty does not apply to assistive editing or to outputs that leave the input or its meaning largely unchanged. If you run your own generative system under your name, the duty is yours. If you use another company's system, ask that provider how it marks outputs.
Paragraph 3: emotion recognition and biometrics
Deployers of emotion recognition or biometric categorization systems must inform the people exposed to them. They must also follow the GDPR (the EU General Data Protection Regulation) and related EU data protection laws. Uses permitted by law to detect, prevent or investigate crimes are exempt, with safeguards.
For agents, this matters if a voice agent analyzes a caller's voice to infer emotions. Review that feature separately before launch.
Paragraph 4: deepfakes and AI-generated public texts
Deployers must disclose deepfakes they create with AI. The AI Act defines a deepfake as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic or truthful. For evidently artistic, creative, satirical or fictional works, the duty is limited to disclosing the AI content in a way that does not hamper the display or enjoyment of the work.
A second duty covers text. If you publish AI-generated or manipulated text to inform the public on matters of public interest, you must disclose it. The exception applies when the text went through human review or editorial control and a person or company holds editorial responsibility for the publication. The guidelines say a spelling or grammar check does not count as review.
Deepfakes generated before August 2, 2026 and texts published before that date do not need retroactive labels. Text generated earlier but published on or after that date does.
Paragraph 5: timing, clarity and accessibility
Information under paragraphs 1–4 must reach people in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure, and must meet the applicable accessibility requirements. The guidelines explain each element:
- Clear means noticeable and easy to understand, including for people with disabilities.
- Distinguishable means easy to identify as separate from the rest of the content or screen.
- First interaction applies to every person and every new session, not only to the first user of the system.
- Accessibility means following existing EU rules, such as the European Accessibility Act, where they apply. Article 50 adds no new ones.
The guidelines also name techniques that are not enough on their own. These include a notice only in terms and conditions or a manual, machine-readable marks that people cannot perceive and a general notice for a whole platform.
Paragraphs 6 and 7: other laws and codes of practice
Paragraph 6 states that Article 50 does not replace other transparency duties in EU or national law. Your GDPR privacy notices and consumer protection disclosures still apply next to the AI notice.
Paragraph 7 covers codes of practice for the detection, marking and labeling of AI-generated content. The Digital Omnibus reworded it: the Commission, after considering the AI Board's opinion, now assesses whether following such a code is adequate for compliance with paragraphs 2 and 4.
Guidelines and code of practice: status in 2026
Two Commission documents support Article 50. Neither is legally binding, but both show how regulators read it.
- Guidelines on transparency obligations. Published on July 20, 2026 as document C(2026) 5054. They explain scope, exceptions and disclosure techniques with examples.
- Code of Practice on Transparency of AI-generated Content. The final version (opens in a new tab) was published on June 10, 2026. On July 8, 2026 the Commission concluded (opens in a new tab) that it adequately covers paragraphs 2, 4 and 5. The AI Board also assessed it as adequate. Signing is voluntary.
Signatories can rely on the code to demonstrate compliance with marking and labeling. Others must show compliance by other means, for example a gap analysis against the code. For the paragraph 1 duty, which the code does not address, the guidelines are the main reference.
When Article 50 applies and what the Omnibus changed
Under Article 113 of the AI Act, Article 50 has applied since August 2, 2026, also to systems placed on the market earlier. The Digital Omnibus on AI (opens in a new tab), Regulation (EU) 2026/1744, in force since July 27, 2026, kept that date. It gave generative AI systems placed on the market before August 2, 2026 four more months for machine-readable marking and reworded paragraph 7. The transition does not cover paragraph 1: according to the guidelines, a system that is partly interactive and partly generative had to meet the disclosure duty from August 2, 2026. Our post on what still applies after the Digital Omnibus covers the other changes.
| Date | What happened |
|---|---|
| June 10, 2026 | Final Code of Practice on Transparency of AI-generated Content published |
| July 8, 2026 | Commission opinion finds the code adequate for paragraphs 2, 4 and 5 |
| July 20, 2026 | Commission publishes its guidelines on Article 50 |
| July 27, 2026 | Digital Omnibus on AI enters into force |
| August 2, 2026 | Article 50 applies |
| December 2, 2026 | Marking deadline for generative AI systems placed on the market before August 2, 2026 |
Penalties for breaking Article 50
Breaches of Article 50 can lead to fines of up to EUR 15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher, under Article 99(4) of the AI Act. For SMEs (small and medium-sized enterprises), including start-ups, the cap is whichever of the two is lower. National market surveillance authorities enforce the rules, and anyone can file a complaint with them.
How to disclose AI in voice, chat and email agents
The AI Act does not prescribe wording. The provider chooses the technique, as long as the result is clear, timely and accessible. These are the patterns we build into client agents.
Voice agents
- State it in the first sentence of every call, before asking for any details: "Hello, you are speaking with the AI assistant for [company]."
- On outbound calls, also say on whose behalf the agent is calling.
- Repeat the notice in long calls, after a hold or when the agent's role changes. The guidelines say a tone or sound alone is not enough.
- Answer truthfully each time a caller asks whether they are talking to a person, and offer a hand-off to your team.
Our AI receptionist follows this pattern: the disclosure is the first sentence of each call.
Chat widgets
- Open with a first message that says the assistant is AI.
- Keep a visible "AI assistant" label near the input field for the whole conversation.
- Do not give the AI a human photo or a staff name. The guidelines note that this makes the AI nature less obvious.
- When staff take over, show it. In mixed conversations, mark AI-generated replies unless a person reviewed and sent them.
Email agents
- Put a short AI label at the top of each AI-written email, as in the guidelines' own example, not only in the footer.
- Name the company or team the agent writes for, for example "AI assistant, [company] support".
- When a person reviews and sends a draft, record who approved it.
What to log
Article 50 sets no specific logging duty for interactive systems, but records help you show an authority what people saw and when. We suggest keeping:
- The disclosure text for each channel and language, with a version number and the date it changed.
- A timestamp showing the disclosure was given at the start of each conversation or call.
- Questions about the agent's AI nature and the answers given.
- Hand-offs to a person and approvals of AI-drafted messages.
- Your written assessment if you rely on the obvious-from-context exception.
These logs contain personal data, so apply the GDPR: keep only what you need and set a retention period. Before launch, our AI security testing includes attempts to make the agent claim it is human through prompt injection (tricking an AI with hidden instructions). Our AI transparency statement shows how we apply these rules to our own work, and the AI disclosure checklist turns this guide into 10 points.
Sources
- 1.Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), Articles 50, 99 and 113, EUR-Lex, Publications Office of the European Union, 2024-07-12 (opens in a new tab)
- 2.Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), EUR-Lex, Publications Office of the European Union, 2026-07-24 (opens in a new tab)
- 3.Guidelines on transparency obligations for providers and deployers of AI systems, European Commission, 2026-07-20 (opens in a new tab)
- 4.Transparency obligations under Article 50 of the AI Act, European Commission, 2026-07-24 (opens in a new tab)
- 5.Code of Practice on Transparency of AI-generated Content, European Commission, 2026-07-31 (opens in a new tab)
- 6.Commission opinion on the assessment of the Code of Practice on Transparency of AI-generated Content, European Commission, 2026-07-09 (opens in a new tab)
- 7.Article 50: Transparency obligations for providers and deployers of certain AI systems, AI Act Service Desk, European Commission (opens in a new tab)
- 8.Timeline for the implementation of the EU AI Act, AI Act Service Desk, European Commission (opens in a new tab)

