(5 min read)
From 2 August 2026, Article 50 of the AI Act requires businesses to disclose AI use across four scenarios: chatbots and other AI systems interacting with people, AI-generated images, audio, video or text marked in machine-readable form, emotion recognition or biometric categorisation tools, and, most relevant for marketing teams: deep fakes and AI-generated public-interest text, which must be clearly labelled as AI generated, unless meaningfully edited by a human. Importantly, not every AI-edited image falls under a deep fake definition: routine touch-ups are exempt, but altering a product to look better than it is likely is not. Businesses should audit marketing, HR and customer-facing content now, and decide who is the deployer. For a step-by-step compliance checklist, see our AI Act Article 50 guide.
From 2 August 2026, the transparency obligations under Article 50 of the Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on Artificial Intelligence (AI Act) will apply. Depending on the type of AI system and the role of the organisation involved, these rules require individuals to be informed when they are interacting with AI or are exposed to emotion recognition or biometric categorisation systems. They also require AI-generated or AI-manipulated content to be identifiable through technical measures, and certain deepfakes and AI-generated or AI-manipulated text on matters of public interest to be clearly disclosed.
Businesses using AI should therefore assess whether their specific use cases trigger any transparency requirements. The use of generative AI does not, by itself, automatically give rise to a disclosure obligation. This article summarises the key requirements and the practical steps businesses should take ahead of 2 August 2026.
Against this background, on 20 July 2026, the European Commission (Commission) published Guidelines on the transparency obligations for providers and deployers of AI systems (Guidelines) (1). Guidelines offer a detailed interpretation of how the obligations should be applied in practice.
A separate but complementary instrument is the Code of Practice on Transparency of AI-Generated Content (Code), published on 10 June 2026. The Code was developed by independent experts, facilitated by the European AI Office. Unlike the Guidelines, the Code is more narrowly focused on the marking and labelling of AI-generated or manipulated content.
Why this matters
Article 50 of the AI Act is relevant not only to businesses that develop or offer AI systems, but also to organisations that use them. In practice, the transparency obligations apply to marketing content, social media posts, websites, advertising, product descriptions, HR communications and audiovisual content wherever generative AI has been used to produce or alter them. Organisations that have never developed an AI system, but simply use tools such as gen-AI powered image generators or drafting assistants, may fall within scope.
(1) See: Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act, published by European Commission on 20 July 2026
The four obligations
Article 50 of the AI Act introduces four distinct transparency obligations, which apply either to providers or to deployers of AI systems, depending on the role an organisation performs in relation to a particular use case. The same organisation may perform both roles in different circumstances.
1 Disclosure of AI-human interactions – Article 50(1)
Providers of AI systems intended to interact directly with natural persons must ensure that individuals are informed that they are interacting with an AI system. This obligation does not apply where it is obvious to a reasonably well-informed, observant and circumspect person in the relevant context (for example, where it is evident that a chatbot is AI-powered), or to certain AI systems used for law enforcement purposes.
2 Machine-readable marking of AI-generated content – Article 50(2)
Providers of AI systems, including general-purpose AI models, that generate synthetic text, images, audio or video must ensure that AI-generated outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated. The AI Act requires these technical measures to be effective, interoperable, robust and reliable, while recognising technical feasibility. The obligation does not apply where AI is used solely for standard editing functions or does not substantially alter the original input or its meaning.
3 Transparency for emotion recognition and biometric categorisation systems – Article 50(3)
Deployers using emotion recognition or biometric categorisation systems must inform individuals exposed to those systems about their operation, no later than at the time of their first exposure. The obligation applies whether the system operates in real time or analyses data at a later stage. Where the processing involves personal data, deployers must also ensure compliance with the applicable data protection frameworks, including the Regulation on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (General Data Protection Regulation). Limited exemptions apply for certain law enforcement uses.
4 Disclosure of AI-generated or manipulated content (deep fakes and certain AI-generated text) – Article 50(4)
Deployers using AI systems to generate or manipulate image, audio or video content constituting a deep fake must clearly disclose that the content has been artificially generated or manipulated. A similar obligation applies to AI-generated or manipulated text published for the purpose of informing the public on matters of public interest, unless the content has undergone meaningful human review or editorial control and a natural or legal person assumes editorial responsibility.
The AI Act also provides limited exemptions for specified law enforcement activities. Deep fakes forming part of evidently artistic, creative, satirical or fictional works remain subject to disclosure, but the information may be presented in a way that does not interfere with the display or enjoyment of the work.
Key clarifications from the Guidelines
Although not legally binding, the Guidelines set out the European Commission's interpretation of the transparency obligations and provide valuable insight into how they are expected to be applied in practice. As such, they are likely to serve as an important benchmark for organisations seeking to comply with the AI Act and for supervisory authorities responsible for its enforcement..
- AI-generated text: the obligation to disclose AI-generated or manipulated text is narrower than may first appear. It applies only to text published for the purpose of informing the public on matters of public interest. As a result, ordinary commercial advertising, product descriptions and most marketing copy will generally fall outside its scope. However, the Guidelines indicate that AI-generated or manipulated content relating to health, consumer safety or sustainability claims may constitute information on matters of public interest. Where such content has not undergone substantive human review or editorial control, the disclosure obligation may still apply.
- Example triggering disclosure of AI use: AI-generated or manipulated sections of a lifestyle-website article comparing the effects of various diets on a particular disease in middle-aged women.
- Example NOT triggering disclosure of AI use: AI-generated or manipulated text that is part of a company’s advertisement or product descriptions (provided it does not include claims relating to matters of public interest, such as health, consumer safety or sustainability).
- Minor AI edits versus deep fakes: not every use of AI to edit or manipulate visual content constitutes a deep fake. The Guidelines explain that routine editing functions, such as cropping, colour correction, compression or replacing a background do not, by themselves, trigger the disclosure obligation. By contrast, where AI materially alters an image, for example by making a product appear more attractive or of higher quality than it is in reality, the resulting content is likely to constitute a deep fake requiring disclosure.
- Example triggering disclosure of AI use: Removal, replacement or insertion of objects or persons in existing images and videos that changes meaning and substance of the content; face replacement or substantial facial modification.
- Example NOT triggering disclosure of AI use: Removal of dust spots caused by a dirty lens or sensor, removal of red-eye caused by flash photography; deleting and obscuring backgrounds that are visible in the original file, pixelation or blurring of faces.
- Artistic and fictional works: a lighter disclosure regime applies to artistic, creative, satirical and fictional works. Commercial advertising will rarely benefit from this exemption, and content combining artistic and promotional purposes will generally remain subject to the standard transparency obligations. Where the lighter regime does apply, the obligation is not removed but may be fulfilled in a less intrusive way: disclosure may be provided in a manner that does not interfere with the viewing experience, such as in credits, a description panel or a settings menu, provided it is clear and available no later than the first exposure. The Guidelines also clarify that this lighter regime does not apply where AI-generated or AI-manipulated depictions of real persons are used in promotional content to suggest endorsement or association.
- Example triggering disclosure of AI use: AI-generated gaming imagery involving deep fake simulations of real, existing persons.
- Example NOT triggering disclosure of AI use: Movies where real existing actors (not manipulated by AI) are playing against an AI-generated background (e.g. depicting a fictitious stretch of prairie, historical buildings of ancient cities etc).
- Deployer status: whether an organisation qualifies as a deployer depends on the level of authority and control it exercises over the use of an AI system. The Guidelines make clear that simply engaging an advertising agency to produce content does not automatically make the company a deployer. However, where the company decides whether AI will be used, determines how it will be used, or exercises control over the AI-generated output, it is likely to qualify as the deployer for the purposes of Article 50. This distinction is particularly important where responsibilities are shared between brands and creative agencies. Although contracts can allocate day-to-day compliance responsibilities, they cannot determine which party qualifies as the provider or deployer under the AI Act.
- Example of a deployer: A media outlet established in the EU, whose editors use an AI system to support their written coverage of current events with AI-generated text publications on matters of public interests posted on a globally accessible website, is a deployer falling within the scope of the AI Act.
- Example of a provider: A provider offering a chatbot, image generator or AI agent on the EU market under its own name or trademark for direct use by consumers, professional users or other organisations is not a deployer for the purposes of that AI system.
The Code as a practical route to compliance
The Code is not an additional layer of mandatory regulation. It is a voluntary compliance framework envisaged by the AI Act to support the effective implementation of the obligations concerning the detection and labelling of AI-generated or AI-manipulated content.
Its scope is narrower than that of the Guidelines. It focuses on the obligations concerning AI-generated and manipulated content under Article 50(2) and Article 50(4), together with the requirements in Article 50(5) governing how and when the relevant information must be provided. It therefore does not cover the disclosure of direct interactions with AI systems under Article 50(1), or the use of emotion recognition and biometric categorisation systems under Article 50(3).
The Code is divided into two sections reflecting the different responsibilities of providers and deployers. Signatories may rely on the measures set out in the Code as an EU-wide framework for demonstrating compliance with the relevant transparency requirements. Adherence does not, however, constitute conclusive evidence of compliance. Organisations remain responsible for implementing the commitments in practice and ensuring that the outcome meets the requirements of the AI Act.
Organisations are not required to sign the Code and may adopt alternative compliance measures. Those choosing that route should nevertheless be prepared to demonstrate that their approach is equally adequate. In practice, this may require them to justify their chosen technical marking methods, labelling formats, approval processes and allocation of responsibilities to the relevant market surveillance authority. By contrast, following the Code may provide greater predictability across Member States and reduce the need to develop and defend an entirely separate compliance framework.
For businesses, signing the Code should therefore be treated as a substantive governance decision rather than a simple statement of support. Before signing, an organisation should identify which section of the Code applies to it, assess whether its existing systems and content workflows meet the relevant commitments, assign responsibility for implementation and establish a record of the measures taken. Even where an organisation decides not to become a signatory, the Code is likely to serve as an important practical benchmark when designing policies for the creation, review, publication and labelling of AI-generated content.
Penalties
Breaches of Article 50 of the AI Act can attract administrative fines of up to EUR 15 million or 3% of its total worldwide annual turnover for the preceding financial year, whichever is higher, applied proportionately by the relevant national authority. For SMEs, including start-ups, the lower of these two maximum amounts applies.
The level of any fine will be determined by the relevant authority taking account of the circumstances of the infringement and the principle of proportionality.
Practical considerations ahead of 2 August 2026
While the appropriate approach will depend on the nature of an organisation's AI use, businesses may wish to consider the following steps in preparation for the application of Article 50 of the AI Act:
- map the AI systems and use cases across the organisation, particularly in marketing, communications, HR and customer-facing functions;
- assess whether any AI-generated content is likely to fall within the transparency obligations, such as deep fakes, public-interest text or interactive AI systems;
- clarify internal roles and responsibilities for assessing whether Article 50 applies and, where necessary, implementing appropriate disclosures;
- review arrangements with external agencies and technology providers to ensure responsibilities for compliance are appropriately allocated; and
- consider developing consistent approaches to AI disclosures and labelling where transparency obligations are likely to arise.
Conclusion
Article 50 is one of the first AI Act obligations to reach beyond product development and into routine business operations. Unlike the high-risk AI regime, it does not depend on the sector an organisation operates in and will likely be relevant for most businesses.
Businesses using off-the-shelf AI tools may therefore be affected even if they do not develop AI systems themselves. However, not every use of AI automatically triggers a transparency or labelling obligation. The assessment depends on the organisation’s role, the type of AI system, the way it is used and the nature and purpose of the resulting content.
Many organisations that have concluded the AI Act "does not really apply to them" will need to revisit that assessment once transparency, rather than risk classification, is the trigger.