Article 50 transparency obligations under the EU AI Act have applied since 2 August 2026, and the European Commission has begun exercising its new enforcement powers. For businesses using chatbots, content generators or applications with AI integration, the question is no longer only whether the system works. They need to determine who provides it, who deploys it, what the user sees, how content is marked and where human control remains.
The regulation follows a risk-based approach, and obligations change with the role and use case. A store enabling a chatbot purchased from a supplier does not have exactly the same responsibilities as a company that develops and places that chatbot on the market. Nor does every AI system automatically become high risk. A real classification must come before a generic checklist.
The practical point: a sentence saying “we use AI” inside a long policy does not solve transparency. Notice must appear at the right moment in a clear form, and the internal process must be able to show which system produced an outcome and who reviewed it.
What began applying on 2 August 2026
The European Commission published its Article 50 transparency guidelines in July 2026. Depending on the situation, they apply to providers and professional deployers of certain AI systems. The Commission's relevant enforcement powers also began on 2 August.
The regulated situations include:
- systems interacting directly with people that must disclose the AI interaction when it is not already obvious;
- synthetic audio, image, video or text that providers must mark in a machine-readable format under the relevant conditions;
- deepfakes requiring visible disclosure of their artificial or manipulated nature;
- certain AI-generated or manipulated texts published to inform the public about matters of public interest;
- emotion-recognition or biometric-categorization systems where exposed persons must be informed in regulated situations.
Conditions and exceptions exist, including for content subject to genuine human review and editorial responsibility. A company should not turn a press summary into universal legal interpretation.
Provider or professional deployer: why the role changes the duty
| Role | Example | Main question |
|---|---|---|
| Provider | The company develops an AI system and offers it under its own name | How is the output designed, documented and marked? |
| Deployer | The company uses an AI system in its operations | How is it configured, disclosed and controlled? |
| Distributor or importer | The company places another entity's system on the market | Are the conditions and required documents in place? |
| Mixed role | The company substantially modifies or rebrands a product | Has it assumed obligations normally belonging to the provider? |
One internal application can involve several roles. A company buys a model, builds its own interface, adds data and rules, then provides the application to clients. The model vendor's contract does not automatically describe responsibility for the final product. A map of components, data, decisions and entities is needed.

Chatbots: notice should appear before confusion does
A user should not discover after several messages that they have been communicating with an automated system. As a rule, the AI identity should be disclosed at the beginning or first interaction in language that is easy to understand. The label needs to remain visible on desktop and mobile, including small widgets and messaging channels.
The notice should not obstruct the experience, but it should not be hidden in an inaccessible tooltip either. A concise message can say that answers are generated automatically, which questions the system can handle and how to reach an employee. Health, finance, recruitment, education and other sensitive contexts deserve much stricter escalation and limitation rules.
Generated content: technical marking and human disclosure
The AI Act separates two ideas that are often mixed together. The first is machine-readable marking of synthetic content, an obligation relevant to providers of covered systems. The second is visible disclosure to a person for certain uses, such as deepfakes or some public-interest texts.
A visible watermark does not always replace metadata, and hidden metadata does not always replace reader disclosure. A social platform may also strip metadata during compression. The process should follow a file from generation to publication and retain evidence of origin, the approved version and the reviewer responsible.
Checklist for a business using AI
- Inventory systems, not only contracts. Include chatbots, AI functions in CRM, call analysis, image generation, transcription, recommendations, automation and tools purchased individually by employees.
- Record the legal and operational role. For each case, identify the provider, deployer, affected people and country of use.
- Describe the data and output. What enters, what leaves, where it is retained, who has access and which action can the output trigger?
- Test disclosure in the interface. Check first interaction, mobile, accessibility, every language and the fallback when scripts or styles fail.
- Define human review. Who reviews, against which criteria, and what happens when an output is uncertain, harmful or challenged?
- Retain an auditable trail. Model version, relevant prompt, sources, output, approval and incidents should be documented in proportion to risk.
- Update contracts and procedures. Clarify instructions, incident notice, retention, subcontractors and model changes.
Four mistakes that create only apparent compliance
1. One label applied everywhere
“Made with AI” does not explain whether an image is entirely synthetic, a text was merely proofread or an editor assumed responsibility. Disclosure should match the use, not be attached mechanically.
2. Treating human approval as a button press
Review matters only when the person has time, competence, enough evidence and the authority to stop the process. Automatic approval disguised as oversight does not reduce risk.
3. Ignoring tools purchased by employees
A central inventory may look clean while teams send documents into dozens of AI services. Policy needs approved alternatives, training and reasonable technical controls.
4. Treating the AI Act as a GDPR substitute
The AI Act and data protection intersect but do not replace each other. Legal basis, minimization, notice, data-subject rights and security remain separate obligations.
How to design an application that can be audited
Compliance is easier when introduced into architecture from the beginning. For custom applications with AI integration, data separation, logging, roles and escalation can be product features. In business automation with AI integration, irreversible actions can be stopped before execution and sent for human confirmation.
A mature system does not rely on the model “knowing” a rule. Deterministic validation, access rights, cost limits, filters, prompt versioning and rollback procedures belong in software. The model may propose; the application decides what is permitted, and people retain control where consequences require it.
A four-week operating plan
| Week | Outcome | Evidence |
|---|---|---|
| 1 | Complete inventory and owner for every system | Register with role, purpose, data and users |
| 2 | Classification and gap analysis | Validated duties, exceptions and risks |
| 3 | Interface and procedure changes | Notices, escalation, logs and mobile tests |
| 4 | Incident and approval test | Simulation, findings and named owner |
Frequently asked questions
Does every chatbot need a warning?
Article 50 addresses interactions where a person must be told they are dealing with AI when that fact is not already obvious. The precise form depends on the system, context and applicable guidance; a concrete assessment is safer than copied wording.
Must every AI-generated image be visibly labeled?
There is no single rule for every image and use. The regulation distinguishes technical marking by the provider from visible duties for certain uses, including deepfakes. Platform policies and rights rules may add requirements.
Do the obligations disappear if an employee checks the text?
Human review and editorial responsibility can matter in certain situations, but they must be genuine and documented. They do not automatically remove other duties or risks.
Is this article legal advice?
No. It is an operational guide based on official sources. Classification, exceptions and contractual obligations need legal and technical review for the specific case.
What should remain after the audit
A sound audit does not end with a generic document. It leaves a product that is easier to understand and control. The user knows when AI is involved, the employee knows when to intervene, and the company can reconstruct how an outcome was obtained.
The AI Act turns transparency from a marketing statement into a design and operating requirement. Businesses that inventory systems now and build these controls at the source can avoid rushed changes, reduce incidents and create applications customers can trust more readily.
Verified official sources
- European Commission – guidelines on Article 50 transparency obligations
- European Commission – European regulatory framework for artificial intelligence
Checked on 31 August 2026. Guidance and enforcement practice can change; specific legal decisions and high-impact systems require case-by-case assessment.