AI Compliance · 2026-07-30 · 10 min read

EU AI Act Article 50: Transparency Obligations From 2 Aug 2026

Article 50 of the EU AI Act applies from 2 August 2026 — and the Digital Omnibus did not move it. Here is who owes each of the four transparency duties, what a compliant chat disclosure looks like, and how to verify yours before penalties attach.

Article 50 of the EU AI Act sets four transparency obligations that apply from 2 August 2026: disclosing when people interact with an AI system, marking AI-generated or manipulated content in machine-readable form, labeling deep fakes, and disclosing emotion-recognition use. Providers and deployers each own specific duties, backed by the general penalty regime of up to €15 million or 3% of worldwide turnover, in force since 2 August 2025.

The rest of this guide unpacks each duty, who owes it, and what a compliant disclosure looks like in a live product — because from 2 August 2026 this is an enforceable legal requirement, not a design preference.

What is Article 50 of the EU AI Act?

Article 50 is the EU AI Act's transparency chapter for AI that touches people directly. It does not care whether your system is "high-risk" — it applies to everyday AI features: chatbots, support assistants, image and voice generators, content tools. The article bundles four distinct duties:

  1. AI interaction disclosure. People must be informed that they are interacting with an AI system.
  2. Marking of AI-generated or manipulated content. Synthetic audio, image, video, and text output must be marked as artificially generated or manipulated in a machine-readable format — in practice, watermarking plus provenance metadata.
  3. Deep-fake disclosure. AI content that convincingly depicts real people, places, or events must be disclosed as artificially generated or manipulated.
  4. Emotion-recognition disclosure. People exposed to emotion-recognition or biometric-categorization systems must be told the system is in operation.

Article 50 sits alongside duties already in force since 2 February 2025: the Article 4 AI-literacy duty (providers and deployers alike) and the Article 5 prohibited practices, which carry penalties up to €35 million or 7% of worldwide turnover. If those are also open items, work through the full EU AI Act compliance checklist for 2026.

When do the Article 50 transparency obligations apply?

DateWhat it means
2 August 2026Article 50 transparency duties apply. GPAI model-provider fines under Article 101 begin on that same date; the general penalty regime (up to €15 million or 3% of worldwide turnover) has applied since 2 August 2025.
2 December 2026End of the watermarking grandfather: systems placed on the market before 2 August 2026 must have machine-readable content marking in place by this date.
2 December 2027Annex III standalone high-risk systems come into scope (deferred by the Digital Omnibus).
2 August 2028Annex I embedded high-risk systems come into scope.

The watermarking grandfather is narrow: it covers only the content-marking duty, only for systems placed on the market before 2 August 2026, and it runs out on 2 December 2026. The other three duties get no window at all.

Didn't the Digital Omnibus delay the EU AI Act?

Only partly — and not the part most companies hit first. The Digital Omnibus, adopted in June 2026, deferred the high-risk conformity regime: Annex III standalone systems now apply from 2 December 2027, and Annex I embedded systems from 2 August 2028. It did not defer Article 4 (AI literacy), Article 5 (prohibited practices), Article 50 (transparency), GPAI obligations, or the penalty regime.

"The EU delayed the AI Act" is dangerously imprecise. Only the high-risk conformity machinery moved. The transparency duties — the ones that reach ordinary chatbots and content generators — kept their date, and so did the fines. If you are unsure which parts of the Act reach you at all, start with Does the EU AI Act apply to my company?

Who owes each Article 50 obligation: provider vs. deployer

The EU AI Act splits Article 50 between the provider (the party that develops the system or places it on the market under its own name) and the deployer (the party that uses the system in a professional context). Each of the four duties lands on one side of that line:

ObligationWho owes itWhat compliance means
AI interaction disclosureProviderDesign and build the system so the people using it are informed they are interacting with AI.
Machine-readable marking of synthetic contentProviderEnsure audio, image, video, and text outputs carry machine-readable marking identifying them as artificially generated or manipulated.
Deep-fake disclosureDeployerDisclose that the content has been artificially generated or manipulated when publishing or using deep-fake material.
Emotion-recognition / biometric-categorization disclosureDeployerInform the people exposed to the system that it is in operation.

Two traps catch companies here:

  • Building on a model API does not make you a mere deployer. If your product is built on a model API such as OpenAI's or Anthropic's, you are typically the provider of your downstream feature. The interaction-disclosure and content-marking duties land on you; the model vendor holds the GPAI duties for the underlying model.
  • One company can hold both roles at once. Ship an AI chat feature to customers and you owe provider duties for it. Run other vendors' AI tools on your own staff or visitors — an emotion-recognition tool in recruiting, for example — and you owe deployer duties for those.

Role classification is the single highest-leverage step, because it determines everything downstream. Shieldra's free EU AI Act checker gives you a risk tier and role-scoped obligation list, with citations, in about three minutes — no signup.

What does "clear and conspicuous" disclosure look like in a chat widget?

A disclosure buried in your terms of service fails the purpose of the duty — the person chatting has to actually be informed. A defensible chat-widget implementation looks like this:

  1. Disclose before the first user message. The label appears when the widget opens — "You're chatting with an AI assistant" — not three messages in, and not only after the user asks.
  2. Keep the label persistent. A one-time toast that disappears is weaker than a fixed header or pinned system message that stays visible for the whole session.
  3. Use plain words. "AI assistant" or "virtual agent — not a human." Skip euphemisms like "smart helper" or a cute bot name with no explanation, which inform nobody.
  4. Don't undermine the label with design. A human first name, a photorealistic avatar, and simulated "typing…" indicators all pull against the disclosure. Regulators read the whole experience, not just the label.
  5. Make it accessible. The disclosure should be announced by screen readers, survive small mobile viewports, and not depend on hover states.
  6. Disclose the handoff in both directions. When the conversation escalates to a human, say so — and if it returns to AI, say that too. Ambiguous mid-conversation switches defeat the disclosure.

The same principles carry to voice: an AI voice agent should identify itself as AI at the start of the call, before the substance of the conversation begins.

What are the penalties for violating Article 50?

From 2 August 2026, Article 50 violations sit under the EU AI Act's general penalty regime: fines up to €15 million or 3% of worldwide annual turnover. Two things make this sharper than it sounds:

  • Duties and penalties arrive on the same day. There is no enforcement grace period after the obligations apply. The only transition relief is the content-marking grandfather, which covers pre-2 August 2026 systems and expires 2 December 2026.
  • This is the second-highest tier in the Act. Only Article 5 prohibited practices carry more (up to €35 million or 7% of worldwide turnover, in force since 2 February 2025). Transparency was deliberately not treated as a paperwork offense.

Article 50 is not the only disclosure law with an August 2026 date

If you sell into the US, a second deadline pulls the same engineering work: California's SB 942/AB 853 AI Transparency Act applies covered-provider duties — generative AI systems with more than 1,000,000 monthly users producing image, audio, or video — from 2 August 2026, the same day. Chatbot disclosure is already live elsewhere: Maine's chatbot law (10 M.R.S. §1500-DD) has been in force since 16 September 2025, and California's BOT Act (BPC §17940) has barred bots that mislead people to influence purchases or votes since 2019.

The practical takeaway: build one disclosure and provenance capability, then map it across jurisdictions. See the complete map of US state AI laws for 2026 and the California AI laws guide for the state-side details.

How to verify your Article 50 disclosures before 2 August 2026

  1. Inventory every customer-facing AI feature. Include the embedded ones — the AI widget your support vendor turned on counts. If you don't trust your inventory, run a shadow AI discovery pass first; Shieldra's discovery matches usage against 284 known AI tools.
  2. Classify your role for each feature. Provider or deployer, feature by feature. The free EU AI Act checker does this with citations in about three minutes.
  3. Map each feature to the four duties. A text-only support chatbot pulls interaction disclosure; an image generator pulls machine-readable marking; a marketing team publishing synthetic video of real people pulls deep-fake disclosure.
  4. Test disclosures in the live product, not the spec. Open the actual widget as a new user on mobile and desktop. Is the AI label visible before the first message? Does generated media carry its marking after your CDN and compression pipeline touch it?
  5. Fix gaps and document the evidence. Screenshots, marking-pipeline test outputs, and dated change logs are what you will want on file if a regulator asks.

This is exactly what Shieldra's disclosure verifier automates: it checks the disclosures your users actually see against the Article 50 duty set for your role, and every finding traces to a statutory citation — a deterministic rules engine, not an LLM guess. Article 50 coverage ships in every plan alongside eight other AI frameworks; see what's included.

FAQ

When does Article 50 of the EU AI Act take effect?

Article 50 applies from 2 August 2026. The general penalty regime behind it — up to €15 million or 3% of worldwide turnover. The only transition relief is for machine-readable content marking: systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with that one duty.

Do chatbots have to tell users they are AI under the EU AI Act?

Yes. From 2 August 2026, Article 50 requires that people be informed when they are interacting with an AI system, and that duty falls on the provider — the disclosure must be designed into the product. A note in your terms of service is not a substitute for a clear label in the conversation itself.

Who is responsible for labeling deep fakes — the provider or the deployer?

Both, in different ways. The provider must ensure AI-generated or manipulated content carries machine-readable marking; the deployer who publishes or uses deep-fake content must disclose to its audience that the content was artificially generated or manipulated. If you both build and publish, you owe both duties.

Did the Digital Omnibus delay the Article 50 transparency rules?

No. The Digital Omnibus, adopted in June 2026, deferred only the high-risk regime — Annex III standalone systems to 2 December 2027 and Annex I embedded systems to 2 August 2028. Article 4, Article 5, Article 50, GPAI obligations, and penalties were not deferred and apply on their original dates.

Does Article 50 apply to my product if it is built on OpenAI or Anthropic models?

Typically yes. Building your product on a model API usually makes you the provider of your downstream feature, so the interaction-disclosure and content-marking duties are yours; the model vendor holds the GPAI duties for the underlying model. You can confirm your role and obligation set in about three minutes with the free EU AI Act checker.