Skip to content

Regulation

EU AI Act Article 50: AI transparency and disclosure explained

EU AI Act Article 50 requires companies to tell people when they are dealing with an AI system and to mark or label certain AI-generated content. It has applied since August 2, 2026 (opens in a new tab), with extra time until December 2, 2026 only for machine-readable marking by generative AI systems already on the market. This guide explains each paragraph in plain words and shows how to disclose AI in voice, chat and email agents.

By the KDS security engineering teamPublished 10 min read

Key takeaways

  • Article 50 has applied since August 2, 2026, including to AI systems already in use on that date.
  • Providers must design agents so people learn they are dealing with AI, at the latest at the first interaction.
  • Deployers must disclose deepfakes and AI-generated public-interest text, unless a person with editorial responsibility reviewed the text.
  • The Digital Omnibus kept the start date and gave existing generative AI systems until December 2, 2026 for marking.
  • Article 50 fines can reach EUR 15 million or 3% of worldwide annual turnover, whichever is higher.
On this page

What EU AI Act Article 50 covers

Article 50 of the AI Act (opens in a new tab), Regulation (EU) 2024/1689, sets transparency duties for AI systems that talk with people or create content. They apply in addition to any high-risk rules.

The article has seven paragraphs. Paragraphs 1 and 2 bind providers: companies that develop an AI system, or have it developed, and place it on the market or put it into service under their own name. Paragraphs 3 and 4 bind deployers: organizations that use an AI system in their professional activity. Paragraph 5 sets how and when people must be informed, paragraph 6 keeps other laws in place and paragraph 7 covers codes of practice.

The rules also reach companies outside the EU. According to the Commission's guidelines on Article 50 (opens in a new tab), a provider in a third country is covered when it places a system on the EU market or when the system's output is used in the EU. Our EU AI Act guide explains the roles and risk tiers of the whole regulation.

Who must do what under Article 50

Article 50 duties by paragraph
ParagraphWhoDutyMain exceptions
50(1) AI that interacts with peopleProvidersDesign the system so people are informed they are interacting with AIObvious from the context; law enforcement systems, unless the public uses them to report a crime
50(2) Synthetic contentProviders of generative AI, including general-purpose AI systemsMark outputs in a machine-readable format so they can be detected as AI-generatedAssistive editing that does not substantially change the input; law enforcement
50(3) Emotion recognition and biometric categorizationDeployersInform the people exposed and follow EU data protection lawUses permitted by law to fight crime
50(4) DeepfakesDeployersDisclose that image, audio or video content was AI-generated or manipulatedLaw enforcement; lighter disclosure for evidently artistic, satirical or fictional works
50(4) Public-interest textDeployersDisclose AI-generated text published to inform the public on matters of public interestHuman review or editorial control with editorial responsibility; law enforcement
50(5) Form and timingProviders and deployersInform clearly, distinguishably and accessibly, at the latest at the first interaction or exposureNone
Article 50 duties by paragraph

Paragraph 1: telling people they are talking to AI

If an AI system is intended to interact directly with people, the provider must design it so those people are informed they are dealing with AI. The guidelines list four conditions that must all be met: it is an AI system, it is intended to interact, the interaction is direct and the other side is a natural person.

This covers chat and voice agents in support, sales and booking. It also covers AI agents that call or write to people during a task. The guidelines expect such agents to disclose that they are AI and on whose behalf they act. Rule-based auto-replies, such as a classic out-of-office email, are not AI systems and fall outside the rule.

The guidelines treat a company that builds a chatbot in-house and runs it under its own name as the provider. A business that commissions an agent and runs it under its own brand is usually in the same position.

When staff use AI to draft a reply and send it as their own, the person is the main contact, so the message is not a direct AI interaction. The mere option for a person to step in does not remove the duty.

The obvious-from-context exception

No notice is needed when a reasonably well-informed, observant and careful person would find the AI obvious, given the context. The guidelines read this exception narrowly. It can fit a code assistant used only by developers or an internal assistant for trained staff, but not a help desk chatbot that customers may take for a human. A provider that relies on it must be able to show why.

Paragraph 2: machine-readable marking of AI content

Providers of systems that generate synthetic audio, images, video or text must mark the outputs in a machine-readable format so they can be detected as AI-generated. The technical solution must be effective, interoperable and reliable as far as technically feasible, given the type of content, the cost and the state of the art.

The duty does not apply to assistive editing or to outputs that leave the input or its meaning largely unchanged. If you run your own generative system under your name, the duty is yours. If you use another company's system, ask that provider how it marks outputs.

Paragraph 3: emotion recognition and biometrics

Deployers of emotion recognition or biometric categorization systems must inform the people exposed to them. They must also follow the GDPR (the EU General Data Protection Regulation) and related EU data protection laws. Uses permitted by law to detect, prevent or investigate crimes are exempt, with safeguards.

For agents, this matters if a voice agent analyzes a caller's voice to infer emotions. Review that feature separately before launch.

Paragraph 4: deepfakes and AI-generated public texts

Deployers must disclose deepfakes they create with AI. The AI Act defines a deepfake as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear authentic or truthful. For evidently artistic, creative, satirical or fictional works, the duty is limited to disclosing the AI content in a way that does not hamper the display or enjoyment of the work.

A second duty covers text. If you publish AI-generated or manipulated text to inform the public on matters of public interest, you must disclose it. The exception applies when the text went through human review or editorial control and a person or company holds editorial responsibility for the publication. The guidelines say a spelling or grammar check does not count as review.

Deepfakes generated before August 2, 2026 and texts published before that date do not need retroactive labels. Text generated earlier but published on or after that date does.

Paragraph 5: timing, clarity and accessibility

Information under paragraphs 1–4 must reach people in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure, and must meet the applicable accessibility requirements. The guidelines explain each element:

  • Clear means noticeable and easy to understand, including for people with disabilities.
  • Distinguishable means easy to identify as separate from the rest of the content or screen.
  • First interaction applies to every person and every new session, not only to the first user of the system.
  • Accessibility means following existing EU rules, such as the European Accessibility Act, where they apply. Article 50 adds no new ones.

The guidelines also name techniques that are not enough on their own. These include a notice only in terms and conditions or a manual, machine-readable marks that people cannot perceive and a general notice for a whole platform.

Paragraphs 6 and 7: other laws and codes of practice

Paragraph 6 states that Article 50 does not replace other transparency duties in EU or national law. Your GDPR privacy notices and consumer protection disclosures still apply next to the AI notice.

Paragraph 7 covers codes of practice for the detection, marking and labeling of AI-generated content. The Digital Omnibus reworded it: the Commission, after considering the AI Board's opinion, now assesses whether following such a code is adequate for compliance with paragraphs 2 and 4.

Guidelines and code of practice: status in 2026

Two Commission documents support Article 50. Neither is legally binding, but both show how regulators read it.

  • Guidelines on transparency obligations. Published on July 20, 2026 as document C(2026) 5054. They explain scope, exceptions and disclosure techniques with examples.
  • Code of Practice on Transparency of AI-generated Content. The final version (opens in a new tab) was published on June 10, 2026. On July 8, 2026 the Commission concluded (opens in a new tab) that it adequately covers paragraphs 2, 4 and 5. The AI Board also assessed it as adequate. Signing is voluntary.

Signatories can rely on the code to demonstrate compliance with marking and labeling. Others must show compliance by other means, for example a gap analysis against the code. For the paragraph 1 duty, which the code does not address, the guidelines are the main reference.

When Article 50 applies and what the Omnibus changed

Under Article 113 of the AI Act, Article 50 has applied since August 2, 2026, also to systems placed on the market earlier. The Digital Omnibus on AI (opens in a new tab), Regulation (EU) 2026/1744, in force since July 27, 2026, kept that date. It gave generative AI systems placed on the market before August 2, 2026 four more months for machine-readable marking and reworded paragraph 7. The transition does not cover paragraph 1: according to the guidelines, a system that is partly interactive and partly generative had to meet the disclosure duty from August 2, 2026. Our post on what still applies after the Digital Omnibus covers the other changes.

Key Article 50 dates
DateWhat happened
June 10, 2026Final Code of Practice on Transparency of AI-generated Content published
July 8, 2026Commission opinion finds the code adequate for paragraphs 2, 4 and 5
July 20, 2026Commission publishes its guidelines on Article 50
July 27, 2026Digital Omnibus on AI enters into force
August 2, 2026Article 50 applies
December 2, 2026Marking deadline for generative AI systems placed on the market before August 2, 2026
Key Article 50 dates

Penalties for breaking Article 50

Breaches of Article 50 can lead to fines of up to EUR 15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher, under Article 99(4) of the AI Act. For SMEs (small and medium-sized enterprises), including start-ups, the cap is whichever of the two is lower. National market surveillance authorities enforce the rules, and anyone can file a complaint with them.

How to disclose AI in voice, chat and email agents

The AI Act does not prescribe wording. The provider chooses the technique, as long as the result is clear, timely and accessible. These are the patterns we build into client agents.

Voice agents

  • State it in the first sentence of every call, before asking for any details: "Hello, you are speaking with the AI assistant for [company]."
  • On outbound calls, also say on whose behalf the agent is calling.
  • Repeat the notice in long calls, after a hold or when the agent's role changes. The guidelines say a tone or sound alone is not enough.
  • Answer truthfully each time a caller asks whether they are talking to a person, and offer a hand-off to your team.

Our AI receptionist follows this pattern: the disclosure is the first sentence of each call.

Chat widgets

  • Open with a first message that says the assistant is AI.
  • Keep a visible "AI assistant" label near the input field for the whole conversation.
  • Do not give the AI a human photo or a staff name. The guidelines note that this makes the AI nature less obvious.
  • When staff take over, show it. In mixed conversations, mark AI-generated replies unless a person reviewed and sent them.

Email agents

  • Put a short AI label at the top of each AI-written email, as in the guidelines' own example, not only in the footer.
  • Name the company or team the agent writes for, for example "AI assistant, [company] support".
  • When a person reviews and sends a draft, record who approved it.

What to log

Article 50 sets no specific logging duty for interactive systems, but records help you show an authority what people saw and when. We suggest keeping:

  • The disclosure text for each channel and language, with a version number and the date it changed.
  • A timestamp showing the disclosure was given at the start of each conversation or call.
  • Questions about the agent's AI nature and the answers given.
  • Hand-offs to a person and approvals of AI-drafted messages.
  • Your written assessment if you rely on the obvious-from-context exception.

These logs contain personal data, so apply the GDPR: keep only what you need and set a retention period. Before launch, our AI security testing includes attempts to make the agent claim it is human through prompt injection (tricking an AI with hidden instructions). Our AI transparency statement shows how we apply these rules to our own work, and the AI disclosure checklist turns this guide into 10 points.

Sources

  1. 1.Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), Articles 50, 99 and 113, EUR-Lex, Publications Office of the European Union, 2024-07-12 (opens in a new tab)
  2. 2.Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI), EUR-Lex, Publications Office of the European Union, 2026-07-24 (opens in a new tab)
  3. 3.Guidelines on transparency obligations for providers and deployers of AI systems, European Commission, 2026-07-20 (opens in a new tab)
  4. 4.Transparency obligations under Article 50 of the AI Act, European Commission, 2026-07-24 (opens in a new tab)
  5. 5.Code of Practice on Transparency of AI-generated Content, European Commission, 2026-07-31 (opens in a new tab)
  6. 6.Commission opinion on the assessment of the Code of Practice on Transparency of AI-generated Content, European Commission, 2026-07-09 (opens in a new tab)
  7. 7.Article 50: Transparency obligations for providers and deployers of certain AI systems, AI Act Service Desk, European Commission (opens in a new tab)
  8. 8.Timeline for the implementation of the EU AI Act, AI Act Service Desk, European Commission (opens in a new tab)

Get a free 30-minute assessment

Walk us through the AI tools and agents you use or plan to launch. We'll point out the biggest risks and the first fixes, in plain words.

Frequently asked questions

What is Article 50 of the EU AI Act?

Article 50 is the transparency article of the EU AI Act. It requires providers to design AI systems that interact with people so those people know they are dealing with AI, and to mark AI-generated content in a machine-readable way. Deployers must disclose deepfakes, certain AI-generated public texts and the use of emotion recognition or biometric categorization. It has applied since August 2, 2026.

Does Article 50 apply to companies outside the EU?

In many cases, yes. According to the Commission's guidelines, providers are covered when they place an AI system on the EU market or put it into service there, and also when the system's output is used in the EU. Deployers outside the EU are covered when they expect their AI output to be used in the EU. A U.S. company whose chat or voice agent serves EU customers should plan for Article 50.

Do we need an AI disclosure if a person reviews every message?

For agents, a message that a person reviews and sends as the main contact is not a direct AI interaction, according to the Commission's guidelines. The mere option for staff to step in is not enough. For AI-generated text published on matters of public interest, the exception needs real human review or editorial control and someone holding editorial responsibility. A spelling or grammar check does not count.

Did the Digital Omnibus delay Article 50?

No. The Digital Omnibus on AI, in force since July 27, 2026, kept August 2, 2026 as the start date for Article 50. It gave providers of generative AI systems placed on the market before that date until December 2, 2026 to add machine-readable marking to outputs. The duty to tell people they are dealing with AI received no extra time.

What are the fines for not disclosing AI under the AI Act?

Breaches of Article 50 can be fined up to EUR 15 million or 3% of total worldwide annual turnover for the previous financial year, whichever is higher. For small and medium-sized enterprises, including start-ups, the lower of the two amounts is the cap. National authorities decide each case, considering factors such as the nature, gravity and duration of the breach and the level of cooperation.

Services and use cases

  • Clinic reception desk in the evening with a phone lighting up as a call comes in

    Use case

    AI receptionist

    An AI receptionist that answers every call, books appointments 24/7 and transfers urgent callers to your staff. Built for clinics and service businesses.

    See how the AI receptionist works
  • Customer support lead calmly reviewing a short list of escalated tickets at her desk

    Use case

    AI customer support

    AI customer support agents that resolve order, return and account questions from start to finish and hand complex cases to your team with full history.

    See how the AI support agent works
  • Service

    AI security and red teaming

    AI security consulting for AI agents and LLM apps: red teaming, prompt injection testing, shadow AI discovery and EU AI Act and ISO/IEC 42001 readiness.

    Explore AI security consulting
  • Service

    AI agent development

    Custom AI agent development for support, sales, front desk and back-office work. Voice and chat agents built and attack-tested by a cybersecurity team.

    Explore AI agent development

Free 30-minute assessment

Find the one workflow worth automating first.

Tell us how your team works. We'll come back with two or three AI opportunities, the risks to watch and a rough payback estimate. No obligation.

  • A senior engineer replies within one business day
  • We can sign an NDA before you share details
  • No fixed packages, every quote tailored to you
What can we help with?
About your company

Company size

When would you like to start?

How can we reach you?

Encrypted in transit · read only by our team · never sold

Free 30-minute AI assessmentGet it →

Before you go

Find out where AI can save your team time

Book a free 30-minute assessment. A senior engineer reviews one workflow with you and sends back the opportunities, the risks and a rough payback estimate.