Article 50 transparency obligations under the EU AI Act have applied since 2 August 2026, and the European Commission has begun exercising its new enforcement powers. For businesses using chatbots, content generators or applications with AI integration, the question is no longer only whether the system works. They need to determine who provides it, who deploys it, what the user sees, how content is marked and where human control remains.

The regulation follows a risk-based approach, and obligations change with the role and use case. A store enabling a chatbot purchased from a supplier does not have exactly the same responsibilities as a company that develops and places that chatbot on the market. Nor does every AI system automatically become high risk. A real classification must come before a generic checklist.

The practical point: a sentence saying “we use AI” inside a long policy does not solve transparency. Notice must appear at the right moment in a clear form, and the internal process must be able to show which system produced an outcome and who reviewed it.

What began applying on 2 August 2026

The European Commission published its Article 50 transparency guidelines in July 2026. Depending on the situation, they apply to providers and professional deployers of certain AI systems. The Commission's relevant enforcement powers also began on 2 August.

The regulated situations include:

  • systems interacting directly with people that must disclose the AI interaction when it is not already obvious;
  • synthetic audio, image, video or text that providers must mark in a machine-readable format under the relevant conditions;
  • deepfakes requiring visible disclosure of their artificial or manipulated nature;
  • certain AI-generated or manipulated texts published to inform the public about matters of public interest;
  • emotion-recognition or biometric-categorization systems where exposed persons must be informed in regulated situations.

Conditions and exceptions exist, including for content subject to genuine human review and editorial responsibility. A company should not turn a press summary into universal legal interpretation.

Provider or professional deployer: why the role changes the duty

RoleExampleMain question
ProviderThe company develops an AI system and offers it under its own nameHow is the output designed, documented and marked?
DeployerThe company uses an AI system in its operationsHow is it configured, disclosed and controlled?
Distributor or importerThe company places another entity's system on the marketAre the conditions and required documents in place?
Mixed roleThe company substantially modifies or rebrands a productHas it assumed obligations normally belonging to the provider?

One internal application can involve several roles. A company buys a model, builds its own interface, adds data and rules, then provides the application to clients. The model vendor's contract does not automatically describe responsibility for the final product. A map of components, data, decisions and entities is needed.

Team inventorying chatbots and AI-integrated applications for EU AI Act compliance
A useful inventory is not a subscription list. It maps where AI enters a process, which data it receives, what it produces and who can intervene.

Chatbots: notice should appear before confusion does

A user should not discover after several messages that they have been communicating with an automated system. As a rule, the AI identity should be disclosed at the beginning or first interaction in language that is easy to understand. The label needs to remain visible on desktop and mobile, including small widgets and messaging channels.

The notice should not obstruct the experience, but it should not be hidden in an inaccessible tooltip either. A concise message can say that answers are generated automatically, which questions the system can handle and how to reach an employee. Health, finance, recruitment, education and other sensitive contexts deserve much stricter escalation and limitation rules.

Generated content: technical marking and human disclosure

The AI Act separates two ideas that are often mixed together. The first is machine-readable marking of synthetic content, an obligation relevant to providers of covered systems. The second is visible disclosure to a person for certain uses, such as deepfakes or some public-interest texts.

A visible watermark does not always replace metadata, and hidden metadata does not always replace reader disclosure. A social platform may also strip metadata during compression. The process should follow a file from generation to publication and retain evidence of origin, the approved version and the reviewer responsible.

Checklist for a business using AI

  1. Inventory systems, not only contracts. Include chatbots, AI functions in CRM, call analysis, image generation, transcription, recommendations, automation and tools purchased individually by employees.
  2. Record the legal and operational role. For each case, identify the provider, deployer, affected people and country of use.
  3. Describe the data and output. What enters, what leaves, where it is retained, who has access and which action can the output trigger?
  4. Test disclosure in the interface. Check first interaction, mobile, accessibility, every language and the fallback when scripts or styles fail.
  5. Define human review. Who reviews, against which criteria, and what happens when an output is uncertain, harmful or challenged?
  6. Retain an auditable trail. Model version, relevant prompt, sources, output, approval and incidents should be documented in proportion to risk.
  7. Update contracts and procedures. Clarify instructions, incident notice, retention, subcontractors and model changes.

Four mistakes that create only apparent compliance

1. One label applied everywhere

“Made with AI” does not explain whether an image is entirely synthetic, a text was merely proofread or an editor assumed responsibility. Disclosure should match the use, not be attached mechanically.

2. Treating human approval as a button press

Review matters only when the person has time, competence, enough evidence and the authority to stop the process. Automatic approval disguised as oversight does not reduce risk.

3. Ignoring tools purchased by employees

A central inventory may look clean while teams send documents into dozens of AI services. Policy needs approved alternatives, training and reasonable technical controls.

4. Treating the AI Act as a GDPR substitute

The AI Act and data protection intersect but do not replace each other. Legal basis, minimization, notice, data-subject rights and security remain separate obligations.

How to design an application that can be audited

Compliance is easier when introduced into architecture from the beginning. For custom applications with AI integration, data separation, logging, roles and escalation can be product features. In business automation with AI integration, irreversible actions can be stopped before execution and sent for human confirmation.

A mature system does not rely on the model “knowing” a rule. Deterministic validation, access rights, cost limits, filters, prompt versioning and rollback procedures belong in software. The model may propose; the application decides what is permitted, and people retain control where consequences require it.

A four-week operating plan

WeekOutcomeEvidence
1Complete inventory and owner for every systemRegister with role, purpose, data and users
2Classification and gap analysisValidated duties, exceptions and risks
3Interface and procedure changesNotices, escalation, logs and mobile tests
4Incident and approval testSimulation, findings and named owner

Frequently asked questions

Does every chatbot need a warning?

Article 50 addresses interactions where a person must be told they are dealing with AI when that fact is not already obvious. The precise form depends on the system, context and applicable guidance; a concrete assessment is safer than copied wording.

Must every AI-generated image be visibly labeled?

There is no single rule for every image and use. The regulation distinguishes technical marking by the provider from visible duties for certain uses, including deepfakes. Platform policies and rights rules may add requirements.

Do the obligations disappear if an employee checks the text?

Human review and editorial responsibility can matter in certain situations, but they must be genuine and documented. They do not automatically remove other duties or risks.

Is this article legal advice?

No. It is an operational guide based on official sources. Classification, exceptions and contractual obligations need legal and technical review for the specific case.

What should remain after the audit

A sound audit does not end with a generic document. It leaves a product that is easier to understand and control. The user knows when AI is involved, the employee knows when to intervene, and the company can reconstruct how an outcome was obtained.

The AI Act turns transparency from a marketing statement into a design and operating requirement. Businesses that inventory systems now and build these controls at the source can avoid rushed changes, reduce incidents and create applications customers can trust more readily.

Verified official sources

Checked on 31 August 2026. Guidance and enforcement practice can change; specific legal decisions and high-impact systems require case-by-case assessment.