Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

EU AI Act transparency obligations explained

EU AI Act Transparency Obligations: A Clear Article 50 Guide

The EU AI Act transparency obligations in Article 50 have applied since 2 August 2026, and unlike the high-risk rules they were not postponed by the July 2026 Digital Omnibus. They reach far more organizations than the high-risk chapter does: anyone whose chatbot talks to people, anyone whose product generates text, images, audio or video, anyone who publishes a deepfake, and anyone who publishes AI-written text on matters of public interest. Breach is a tier-2 offence under Article 99 — up to €15 million or 3% of worldwide turnover.

This guide sets out the four obligations, who carries each, the exemptions, the 2 December 2026 grace period for older generative systems, the Code of Practice and EU labelling icons published in June 2026, and what a compliant implementation looks like.

EU AI Act transparency obligations: the four duties in Article 50 and who carries them
Two duties on providers, two on deployers, one deadline already passed.

The four EU AI Act transparency obligations in Article 50

Paragraph Who Obligation Main exemptions
50(1) Providers AI systems intended to interact directly with natural persons must be designed and developed so those persons are informed they are interacting with an AI system — unless obvious to a reasonably well-informed, observant and circumspect person Systems authorised by law for detecting, preventing, investigating or prosecuting crime, subject to safeguards, unless available to the public to report offences
50(2) Providers, including of general-purpose AI systems Outputs of systems generating synthetic audio, image, video or text must be marked in a machine-readable format and detectable as artificially generated or manipulated; solutions must be effective, interoperable, robust and reliable as far as technically feasible Assistive editing functions; systems that do not substantially alter the input data or its meaning; law-enforcement use authorised by law
50(3) Deployers Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them, and process personal data under GDPR, Regulation 2018/1725 and Directive 2016/680 Systems permitted by law for criminal-offence detection, subject to safeguards
50(4) Deployers Deployers must disclose that deepfake image, audio or video content has been artificially generated or manipulated; and must disclose AI-generated or manipulated text published to inform the public on matters of public interest Law-enforcement use; for evidently artistic, creative, satirical or fictional work, disclosure limited to an appropriate manner that does not hamper the work; for text, where it has undergone human review or editorial control and a person holds editorial responsibility

Article 50(5) sets the manner of the EU AI Act transparency obligations: the information must be provided in a clear and distinguishable way at the latest at the time of the first interaction or exposure, and must conform to applicable accessibility requirements. Article 50(6) confirms the obligations are without prejudice to the high-risk requirements in Chapter III and to any other transparency duty in Union or national law — a high-risk chatbot carries both.

Who the EU AI Act transparency obligations reach

The two provider duties attach at design time. If you build or substantially modify a system that converses with people or generates content, 50(1) and 50(2) are yours, wherever you are established, if the system is placed on the EU market or its output is used in the EU. The two deployer duties attach at use: a marketing team publishing a synthetic video, a newsroom publishing AI-drafted copy without editorial sign-off, an HR function running emotion recognition in interviews.

Most organizations are deployers of someone else’s system for 50(3) and 50(4) and providers of nothing — but a company that fine-tunes a model and offers it to customers has become a provider. Our guide to who the EU AI Act applies to sets out the roles.

EU AI Act transparency obligations dates: in force now, with one grace period

Date What it means for Article 50
2 August 2026 All four transparency obligations apply, under Article 113. The Digital Omnibus on AI (Regulation (EU) 2026/1744) did not move this date
2 December 2026 Article 111(4), inserted by the Omnibus: providers of generative AI systems placed on the market or put into service before 2 August 2026 have until this date to bring them into compliance with the machine-readable marking duty in 50(2)
2 December 2027 / 2 August 2028 Annex III and Annex I high-risk obligations — separate from, and in addition to, Article 50 for systems that are both

The grace period in the EU AI Act transparency obligations is narrow. It covers legacy systems and the marking duty only; a legacy chatbot still had to disclose itself from 2 August 2026, and every deployer duty applied from that date regardless of when the system was built. The full Article 113 schedule is in our EU AI Act deadlines guide.

The Code of Practice and EU icons for the EU AI Act transparency obligations

Article 50(7), as amended by the Omnibus, tasks the Commission with encouraging and facilitating codes of practice for the detection and labelling of artificially generated or manipulated content, with implementing acts held in reserve if the codes prove inadequate. The Commission published a first draft of the Code of Practice on marking and labelling AI-generated content on 17 December 2025, a second on 3 March 2026, and the final Code on 10 June 2026.

It has two sections: Section 1 for providers, on marking and detection under 50(2); Section 2 for deployers, on labelling deepfakes and AI-generated text under 50(4). Alongside it the Commission released a set of EU icons that deployers may use to label AI-generated content, and draft guidelines on the scope of Article 50 (8 May 2026) to complement the Code.

Adherence to the Code is voluntary; the EU AI Act transparency obligations are not. The practical value of signing up is a Commission-endorsed reading of what “effective, interoperable, robust and reliable” marking means and what an “appropriate” label looks like — the two phrases in Article 50 that would otherwise be argued system by system with 27 national authorities.

Implementing the four EU AI Act transparency obligations

50(1) — disclosure of AI interaction

  • Put the disclosure at the first interaction — a persistent label on the chat interface, a spoken line at the start of a voice call — not in terms and conditions.
  • Do not rely on the “obvious from context” carve-out for anything customer-facing; the test is a reasonably well-informed, observant and circumspect person, and it is applied by a regulator after a complaint.
  • Meet accessibility requirements: screen-reader text, not an icon alone.

50(2) — machine-readable marking of synthetic content

  • Mark at generation, in a machine-readable form — content provenance metadata and, where the Code recommends it, watermarking — and keep the marking through the export formats you support.
  • Document the technical solution, its limits and the feasibility judgement behind them; “as far as technically feasible” is a defence only if the feasibility analysis exists.
  • Check whether your product falls in the assistive-editing exemption before claiming it: a tool that rewrites a paragraph substantially alters the input.

50(3) — emotion recognition and biometric categorisation

  • Inform the people exposed, before exposure, in plain terms.
  • Check Article 5 first: emotion recognition in workplaces and education is prohibited outright, with narrow medical and safety exceptions, so most 50(3) questions are really Article 5 questions. See our guide to prohibited AI practices.

50(4) — deepfakes and public-interest text

  • Label deepfakes visibly, using the EU icons or an equivalent label, at first exposure.
  • For AI-drafted public-interest text, either label it or route it through documented human review with a named person holding editorial responsibility — the exemption is conditional on both.
  • Keep a record of what was labelled, when and how; the burden of showing compliance falls on the deployer.

EU AI Act transparency obligations: penalties and the paper trail

Article 99(4) lists the EU AI Act transparency obligations among those carrying the tier-2 fine: up to €15 million or 3% of worldwide annual turnover, whichever is higher, or whichever is lower for SMEs and small mid-caps. Article 99(7) requires authorities to weigh the technical and organizational measures in place and whether the operator self-reported — so a transparency policy, a marking design record and a labelling log are mitigation as well as compliance. Our guide to EU AI Act penalties covers the tiers.

Frequently asked questions

When did the EU AI Act transparency obligations start to apply?
2 August 2026, under Article 113. The Digital Omnibus on AI moved the high-risk dates but not this one.

Does every chatbot have to say it is an AI?
Every AI system intended to interact directly with natural persons must be designed so people are informed, unless it is obvious to a reasonably well-informed, observant and circumspect person. Customer-facing chatbots should disclose.

Is watermarking mandatory?
Article 50(2) requires machine-readable marking that is effective, interoperable, robust and reliable as far as technically feasible; it does not name a technique. The June 2026 Code of Practice sets out the expected methods for providers who sign up.

Do the obligations apply to systems built before August 2026?
Yes for interaction disclosure and every deployer duty. For the machine-readable marking duty, generative systems on the market before 2 August 2026 have until 2 December 2026 under Article 111(4).

Is signing the Code of Practice compulsory?
No. The Code is voluntary; Article 50 is law. Signing gives a recognised way of demonstrating compliance with the Article’s open-textured terms.

Where this leaves you

Treat the EU AI Act transparency obligations as the part of the Regulation that already applies to you: inventory every system that talks to people or generates content, decide for each whether you are provider or deployer, put disclosure at first interaction, mark synthetic output at generation, label deepfakes and unreviewed public-interest text, and keep the records. Use the June 2026 Code of Practice and the EU icons as the reference implementation, and clear the 2 December 2026 marking deadline for any legacy generative system now.

References

More on AI governance

An AI transparency policy, the Article 50 procedure, a disclosure notice template and a deepfake and synthetic content labelling procedure are in the EU AI Act Toolkit (60 templates), or start with the free templates.

When a standard changes, know first

One email a month: edition changes, new deadlines, and what they mean for documentation you already have. No sales sequence.

We don’t spam! Read our privacy policy for more info.