AI transparency rules take effect on August 2
Article 50 of the EU AI Act becomes applicable on 2 August 2026. "AI content will need labelling" is an oversimplification - it's actually five separate obligations landing on different actors in different situations. Here's what's actually changing, and who it affects.
The headline version making the rounds lately is: "AI content will need to be labelled." The reality is more nuanced - and more practical for businesses. Article 50 of the EU AI Act doesn't put a sticker on every AI output. It sets out five distinct obligations that apply to different roles (provider vs. deployer of an AI system) in different situations. For any company using AI internally or in customer-facing communication, the key question is which category its use case falls into.
Penalties: non-compliance can trigger fines of up to EUR 15 million or 3% of global annual turnover, whichever is higher.
The five obligations at a glance
Disclosing chatbots and voicebots
When a person interacts directly with an AI system, they must know they're talking to AI. This falls on the provider; an exception applies only where the AI nature of the interaction is genuinely obvious.
Technical marking of AI content
Providers must ensure AI-generated text, images, audio or video are machine-detectable as AI-generated. Systems placed on the market before 2 Aug 2026 get a grace period until 2 Dec 2026.
Emotion recognition and biometrics
Anyone deploying an emotion-recognition or biometric-categorisation system must inform the people exposed to it.
Labelling deepfakes
Realistic AI content that could pass as an authentic recording of a real person, place or event must be disclosed as artificially generated when published.
Text on matters of public interest
AI-generated or AI-edited text published to inform the public on matters of public interest (politics, public administration, health...) must be labelled - unless it went through editorial review with clear accountability.
Who's on the hook: provider vs. deployer
Article 50 hinges on two roles. A provider develops or commissions an AI system and places it on the market under its own name - typically the vendor of an AI tool. A deployer uses an AI system in a professional capacity - a company, public body, media outlet or agency deciding what the system is used for.
The first two obligations (chatbot disclosure, technical content marking) sit with providers. The remaining three (biometrics, deepfakes, public-interest text) fall on whoever actually deploys the AI system - often the company itself.
What it means in practice for companies
Most companies running AI chatbots on their website, AI-assisted customer support, or AI agents wired into internal systems will mainly be affected by obligation 1: if a customer or employee is talking directly to an AI system, that must be made clear from the first interaction - not buried in terms and conditions.
If a company doesn't use emotion recognition or biometric categorisation, and doesn't publish AI-generated content as news, the remaining three obligations typically won't apply directly. Still worth keeping on the radar - particularly for marketing content with AI-generated visuals, where the line into deepfake territory isn't always obvious.
The practical question isn't just "was this made with AI?" - it's who is using the AI system, in what role, what content results, and what risk of deception it could create for the audience.
Two documents worth knowing
Two supporting documents from the European Commission and the AI Office help with practical application: implementation guidelines for Article 50, which interpret the key terms and give concrete examples, and a voluntary code of practice for labelling AI content, which spells out the technical side of obligations 2, 4 and 5 (metadata, watermarking, the AI GENERATED / AI MODIFIED icon). Only the Court of Justice of the EU can give a legally binding interpretation, but these documents are what regulators will actually use to assess compliance in practice.
Key takeaways
- The rules apply from 2 August 2026, with a grace period until 2 December 2026 for technical content marking on older systems.
- This isn't a blanket "label everything" rule - relevance depends on role (provider/deployer) and use case.
- For most companies, obligation 1 matters most: transparency wherever AI talks directly to a person.
- Penalties are significant (up to EUR 15m / 3% of turnover) - worth mapping your own AI deployments against the right category.
Not sure where your AI deployment falls?
Let's walk through which obligations actually apply to your specific setup, and what to do about them.
Book a free consultation →