EU AI Act Article 50: who must disclose what, to whom and when
The binding law separates provider duties from deployer duties and machine-readable marking from disclosures people can perceive. The Commission's guidance helps, but it is not the law itself.

What happened
Article 50 of the EU AI Act became applicable on 2 August 2026, supported by final Commission guidelines and a voluntary code for marking and labelling AI-generated content.
Why it matters
Product, HR and newsroom teams must identify their legal role and the relevant use case before choosing a notice, machine-readable marker, visible label or editorial-review control.
Article 50 of the EU AI Act is often shortened to a slogan: label AI content. That shorthand hides the rule's most important design choice. The binding regulation assigns different duties to providers and deployers, and it distinguishes technical marking from disclosures that a person can see, hear or otherwise perceive.
The rules became applicable on 2 August 2026. The European Commission published final implementation guidelines on 20 July and maintains a detailed Article 50 questions-and-answers page. Those documents are operationally important, but the guidelines explicitly state that they are non-binding; only the Court of Justice of the European Union can ultimately give an authoritative interpretation of the Act. The legal obligation comes from the regulation.
First classify the organisation's role
A provider develops an AI system, or has it developed, and places it on the EU market or puts it into service under its own name or trade mark. A deployer uses an AI system under its authority for a professional activity. An employee acting under a company's instructions is not normally a separate deployer; the legal person remains responsible. A contractor may also operate a system on that organisation's behalf.
This classification is use-case specific. A software vendor may be the provider and its customer the deployer. An organisation that commissions or white-labels a system under its own name may need to examine whether it has assumed provider responsibilities. Procurement labels such as “buyer”, “customer” or “platform partner” do not answer the legal question.
The four Article 50 cases
1. Direct interaction with people
Providers of AI systems intended to interact directly with natural persons must design them so that people are informed they are interacting with AI, unless that fact is obvious to a reasonably well-informed, observant and circumspect person in the circumstances. The Commission says the obviousness exception should be read restrictively.
The notice must be clear and distinguishable, meet applicable accessibility requirements and be given no later than the start of the first interaction. The guidance describes four cumulative elements: the product must be an AI system; it must support a genuine two-way exchange; the interaction must be direct rather than mediated by a person; and the other party must be a natural person. Background systems and machine-to-machine exchanges fall outside this particular duty.
For an HR product, a conversational career assistant or recruitment agent is the obvious example. The provider needs to design the disclosure into the experience. The employer using the product should still verify during procurement and configuration that the notice appears in the real candidate journey, in an accessible form, rather than assume a contract clause makes it happen.
2. Machine-readable marking of synthetic content
Providers of systems, including general-purpose AI systems, that generate synthetic audio, image, video or text must make the output detectable as artificially generated or manipulated. The mark must be machine-readable, and the technical solution must be effective, interoperable, robust and reliable as far as technically feasible. Content type, implementation cost and the generally acknowledged state of the art can be taken into account.
This is a provenance layer for machines, platforms and downstream tools. It is not necessarily a visible badge for an audience. The law contains boundaries: the duty does not apply to the extent that a system performs an assistive function for standard editing or does not substantially alter the input or its meaning. The Commission also identifies certain outputs outside scope, including source code, short sequences of symbols and some machine-only or closed-loop industrial outputs. These are bounded exceptions, not a general “business use” exemption.
A limited transition applies only here. Providers of relevant systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2). That does not delay all of Article 50.
3. Emotion recognition and biometric categorisation
Deployers of emotion-recognition or biometric-categorisation systems must inform the natural persons exposed to their operation. The Commission says this applies to real-time and later analysis. Article 50 itself does not require the notice to explain the purpose, but the processing must still comply with applicable data-protection law.
Disclosure is not permission. In a workplace or recruitment setting, a transparency notice does not override separate AI Act prohibitions or high-risk requirements, employment law, data-protection rules, equality duties or consultation requirements. A team should therefore ask two questions, not one: must people be informed, and is the use itself lawful?
4. Deepfakes and public-interest text
Deployers must disclose image, audio or video that constitutes a deepfake. The label must reach the person no later than first exposure and be understandable and perceivable without special technical tools. A deployer cannot satisfy this duty merely by pointing to a provider's hidden machine-readable marker. For evidently artistic, creative, satirical or fictional works, disclosure can be presented in a way that does not hamper enjoyment, but the provision does not become a blanket exemption.
Deployers must also disclose AI-generated or manipulated text published for the purpose of informing the public on matters of public interest. The Commission lists areas such as politics, public services, justice, fundamental rights, public health, consumer safety and economic, financial, scientific or cultural developments relevant to public debate. Not every internal memo, personalised candidate message or routine product description automatically falls into that category; purpose, audience and context matter.
Why substantive editorial review matters
Public-interest text need not carry the deployer disclosure when it has undergone human review or editorial control and a natural or legal person holds editorial responsibility for publication. The Commission's explanation sets a meaningful threshold. Human review is a deliberate examination of substance by people with relevant knowledge and professional judgement. Editorial control requires practical authority to approve, alter or reject the substance, including fact-checking and checking the trustworthiness of sources. Editorial responsibility means ultimate legal responsibility for publication.
Spell-checking, grammar correction, formatting or a purely procedural approval is not enough. Nor should a newsroom treat a named editor as a compliance ornament if that person cannot change or reject the copy. A defensible workflow would identify the responsible editor, preserve the sources and substantive changes reviewed, and record the approval decision. That evidence practice is an editorial recommendation, not an express Article 50 logging rule, and requires legal review before implementation.
Machine signal and human disclosure are different controls
The provider's machine-readable mark and the deployer's audience-facing disclosure serve related but different purposes. The first helps systems detect origin or manipulation. The second helps a person calibrate trust at the moment of exposure. Content can therefore require both. A visible newsroom label does not fix a missing provider-side provenance mechanism, and embedded metadata does not replace a visible or audible deepfake disclosure.
The Commission's Code of Practice on Transparency of AI-generated Content offers voluntary measures for marking and labelling under Article 50(2), (4) and (5). The Commission and AI Board have assessed it as an adequate way for signatories to demonstrate compliance. Signing is voluntary, while Article 50 remains mandatory. A non-signatory may use alternative adequate measures, but must be able to demonstrate them to the relevant authority. The code does not replace the Act or the guidelines and should not be described as immunity from enforcement.
A practical control map
Before changing product copy or adding a generic “made with AI” badge, an organisation should create a use-case inventory that records:
- the system, model and output types involved;
- which entity is provider, deployer or potentially both;
- whether people interact directly with the system;
- whether output is marked for machine detection;
- whether emotion recognition, biometric categorisation, deepfakes or public-interest publication are involved;
- the intended audience, context and time of first interaction or exposure;
- any claimed exception and the evidence supporting it;
- the visible, audible or otherwise accessible disclosure channel;
- the human reviewer, editorial authority and legal responsibility where the text-review exception is used; and
- contract terms covering marking, downstream transformations, metadata preservation and compliance evidence.
For HR technology teams, this map belongs in system inventory, procurement and candidate-experience testing. For newsrooms, it belongs beside sourcing, corrections and editorial approval rather than in a generic AI policy alone. In both settings, the organisation should test the real interface and publication flow, not just read the vendor's product description.
What remains uncertain
Terms such as “obvious”, “standard editing”, “substantially alter”, “matter of public interest” and adequate human review require contextual judgement. Technical expectations for reliable and interoperable marking will evolve with the state of the art. The guidelines can be updated, national market-surveillance authorities will enforce most cases, and courts retain the final interpretative role.
Non-compliance with Article 50 falls within the AI Act category carrying administrative fines of up to EUR 15 million or, for an undertaking, up to 3 per cent of total worldwide annual turnover for the preceding financial year, subject to the Act's proportionality and SME rules. Those are maximum statutory categories, not an automatic penalty for every error.
This explainer is an AI-assisted editorial draft, not legal advice. It has not been verified by a human editor or qualified EU legal reviewer. Organisations should assess the current consolidated law, their facts, applicable sectoral and national rules, and competent-authority guidance before acting.