Skip to content
EU AI Stack

AI Act Article 50: what to label, where, and who signs off

Fryderyk Pryjma5 min read
Editorial infographic on a dark navy background listing the four Article 50 transparency duties: chatbot disclosure, synthetic media marking, deepfake label and emotion recognition notice

Article 50 asks for four things. Tell a person when they are talking to an AI system. Mark synthetic audio, image, video and text in a machine-readable format. Label deepfakes visibly where a human will see them. Inform people exposed to emotion recognition or biometric categorisation. The duty binds providers and deployers separately, and the part most teams miss is the last one: a named owner who signs off the labelling decision and keeps the record that proves when it was made.

What exactly has to carry a label?

Article 50 is a transparency chapter, not a risk chapter. It does not care how capable your model is. It cares whether a person can tell that a machine was involved. That reduces to four triggers, and if none of them fire, the article does not reach your product at all.

TriggerWho owes itWhat ships
Direct interaction with a personProvider of the systemA disclosure at the start of the interaction, unless it is obvious to a reasonably informed person
Synthetic audio, image, video or textProvider of the generating systemMachine-readable marking in the output, robust enough to survive normal handling
Deepfake contentDeployer who publishes itA visible disclosure that the content is artificially generated or manipulated
Emotion recognition or biometric categorisationDeployer operating the systemNotice to the exposed people, plus the GDPR legal basis behind the processing
The four Article 50 triggers, who carries the duty and what the label looks like in practice. Regulation (EU) 2024/1689, Article 50, applicable since 2 August 2026.

Where does the disclosure actually sit?

The regulation says the information must reach the person clearly and distinguishably, at the latest at the time of the first interaction. It does not prescribe a widget. In practice four placements hold up, and one does not.

  • Chat and voice: a line in the first system turn, plus a persistent marker in the interface header. A one-off greeting that scrolls away is weak evidence.
  • Generated media: marking in the file metadata and, where the format allows, a watermark carried in the content itself, so a screenshot does not strip the fact.
  • Published deepfakes: a caption or on-frame label in the same view as the content, not in a linked policy page.
  • Emotion recognition in a physical space: signage at the entry point, in the languages the site actually serves.
  • What does not hold up: burying the disclosure in terms of service, a cookie banner, or a footer link. None of those meet clearly and distinguishably.

The marking grace period ends this December

Two dates matter for this chapter. Article 50 became applicable on 2 August 2026. The Digital Omnibus, in force since 27 July 2026, left it untouched while moving the high-risk regime to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I products. What the Omnibus did add is breathing room on the technical marking standard, which means output labelling built after December 2026 will be judged against a settled expectation rather than a moving one. Ship the interface disclosure now, and treat the machine-readable marking as a December deliverable with code behind it.

Who signs off, and what does the record contain?

This is the part that separates a labelled product from a defensible one. Article 50 creates no documentation duty in the way the high-risk chapter does, so teams assume there is nothing to keep. Then a market surveillance authority or, far sooner, a buyer asks when the decision was made and on what basis, and there is nothing dated to hand over.

  1. One page per system: which triggers fire, which do not, and the reasoning for each exclusion.
  2. The placement decision, with a screenshot of the shipped disclosure and the release it went out in.
  3. The marking specification: format, fields, and a test showing the metadata survives export and re-encoding.
  4. A named owner, by role rather than by person, who approves changes to any of the above.
  5. A review date. Once a quarter is enough while the product is stable, and every release that touches output handling.

Enforcement gives the record its price. Breaches of Article 50 sit in the tier reaching 15 million EUR or 3 percent of worldwide annual turnover, whichever is higher. The realistic exposure for most vendors is not that number, it is a stalled deal: buyers now ask for the labelling pack in the same questionnaire as their NIS2 supplier evidence, and an undated answer reads as an absent one.

A label is a product decision. The record of who made it is the compliance artefact.

Frequently asked questions

Does Article 50 apply to our chatbot if it is obviously a bot?
The disclosure duty falls away only where it is obvious to a reasonably informed person that they are interacting with an AI system. That judgement is yours to document, and a named product bot with a clear interface usually qualifies. Write down the reasoning rather than relying on it silently.
Do we have to watermark generated text as well as images?
Yes. Article 50 covers synthetic audio, image, video and text alike, and asks for marking in a machine-readable format. For text this typically means provenance metadata attached at the API boundary rather than a visible mark in the words.
Who labels a deepfake, the model provider or the publisher?
Both, at different layers. The provider embeds the machine-readable marking in the output. The deployer who publishes the content owes the visible disclosure that it is artificially generated or manipulated.
What are the penalties for missing Article 50 labelling?
Non-compliance with the transparency obligations sits in the tier of up to 15 million EUR or 3 percent of worldwide annual turnover, whichever is higher. Commercially, the more frequent cost is a blocked security or procurement review.
ShareLinkedInXEmail

Related articles

Next step

Need this as an outcome, not an article? AI Act readiness.

Article 50 has applied since 2 August 2026. The high-risk obligations moved: Annex III to 2 December 2027, Annex I to 2 August 2028. Most readiness projects on the market are still priced against the old calendar. We scope yours against the current one.

Explore AI Act readiness