EU AI Act · Article 50 · Transparency obligations

EU AI Act Article 50: what companies must do by August 2026.

From August 2, 2026, the transparency obligations of the EU AI Act take effect. Article 50 requires providers and deployers of certain AI systems to apply labeling — toward users and within the technical infrastructure. This page explains who is affected by Art. 50, what specifically needs to be implemented, and what technical infrastructure requirements arise from it.

This page is for technical orientation. Not legal advice. Assessing regulatory obligations in individual cases is the responsibility of qualified legal and compliance advisors.

August 2, 2026

Why August 2026 is the decisive date

The EU AI Act entered into force on August 1, 2024. Most obligations apply on a staggered basis — the transparency obligations under Art. 50 apply, after a two-year implementation period, from August 2, 2026. The comprehensive high-risk obligations under Annex III, by contrast, were postponed via the AI Omnibus (Council, June 29, 2026) to December 2, 2027 (Annex I to August 2, 2028) — Art. 50 remained at its original date.

For companies that use chatbots, publish AI-generated content, or process synthetic media, this means: anyone who has not implemented technical and organizational measures under Art. 50 by August 2026 risks fines of up to EUR 15 million or 3% of global annual turnover.

The four transparency obligations

What Article 50 specifically requires

Art. 50 para. 1

Chatbot disclosure obligation

Providers of AI systems intended for direct interaction with natural persons (chatbots, virtual assistants) must ensure that users know they are interacting with an AI system — unless this is clearly evident from the context.

Technical infrastructure relevance: The disclosure obligation is not merely a UI requirement. It is reflected in the domain's machine-readable governance declaration — particularly in the AI Policy URL, the AI discovery layer and the agent-card.json. SOVP checks these signals as part of the AI Governance Hard Gate.

Art. 50 para. 2

AI labeling for synthetic content

Providers of AI systems that generate image, audio, video or text content must mark the outputs as AI-generated in a machine-readable way. This applies regardless of whether the content is realistic or recognizably artificial. Exceptions exist for purely assistive functions (e.g. autocorrect) and for professional creative tools.

Technical infrastructure relevance: Machine-readable marking requires technical standards for content provenance (e.g. C2PA). Companies operating such systems must maintain the corresponding infrastructure declarations on their domain.

Art. 50 para. 3

Emotion recognition and biometric categorization

Deployers who use a system for emotion recognition or biometric categorization must inform the natural persons affected by it about the operation of the system. This obligation does not concern deepfakes — para. 4 applies to those.

Technical infrastructure relevance: Relevant mainly for deployers in HR, security and retail contexts who use such systems. On purely website/content infrastructures without emotion recognition, this parameter typically does not apply.

Art. 50 para. 4

Deepfakes and AI-generated text on public-interest matters

Deployers who generate or manipulate deepfakes (synthetic image, audio or video representations of real existing persons) must disclose the content as artificially generated. The same obligation applies to deployers who publish AI-generated text on matters of public interest (e.g. elections, political topics, health) — unless it is under human editorial responsibility and review. Both fall under the same paragraph and are a deployer-only obligation, not a provider obligation.

Technical infrastructure relevance: Deepfake disclaimers and the machine-readable labeling of published AI text are externally verifiable governance signals. SOVP checks their presence and consistency as part of the technical infrastructure assessment. Publishers, media companies and platform operators are particularly affected here.

Classification

Article 50 vs. Annex III: what applies to whom?

The EU AI Act distinguishes between high-risk obligations (Annex III) and transparency obligations (Art. 50). Art. 50 applies from August 2, 2026; the high-risk obligations were postponed via the AI Omnibus to December 2027 (Annex III) and August 2028 (Annex I) respectively — and they affect different companies.

Annex III — high risk

Comprehensive obligations: technical documentation, risk management, quality management, Conformity Assessment Dossier, human oversight, accuracy and robustness. Applies to AI in biometrics, finance, HR, healthcare, critical infrastructure and more.

Annex III fully explained →

Article 50 — limited risk

Targeted transparency obligations: chatbot disclosure, machine-readable marking of AI-generated content, deepfake declaration. Applies to providers and deployers — regardless of the system's risk classification under Annex III.

Quick test: which obligations apply to me? →

Important: Art. 50 and Annex III obligations are not mutually exclusive. A company that operates a high-risk AI system under Annex III and uses a chatbot must satisfy both requirement frameworks.

Technical implementation

Checklist: what the infrastructure must deliver by August 2026

Art. 50 is not a purely UI-level requirement. Several obligations require a technically anchored, externally verifiable declaration at the infrastructure level.

AI Policy URL present and reachable

A machine-readable AI Policy declares how the company uses AI, which systems are active, and how requests can be directed to an AI contact point. Without a public AI Policy URL, the chatbot disclosure obligation is difficult to demonstrate.

AI discovery layer (ai.txt / llms.txt / ai.json)

Machine-readable governance files at the domain's root level allow AI agents and supervisory authorities to automatically check how the company handles AI training data, opt-out directives and content provenance.

Deepfake disclaimer in governance declaration

Companies that use deepfake technologies or publish synthetic representations must anchor an explicit disclaimer in their governance documentation — externally verifiable, not merely hidden in terms of use.

Robots.txt: consistent crawler directives for AI bots

The robots.txt configuration regarding AI training crawlers must be consistent with the AI Policy declaration. Contradictory directives (AI crawler allowed in robots.txt, prohibited in the AI Policy) count as an infrastructure deficiency in the SOVP scan.

Check your domain's Art. 50 readiness now

Free · No login · Result in 90 seconds

Frequently asked questions

Questions about EU AI Act Article 50

What does EU AI Act Article 50 regulate?

Article 50 EU AI Act regulates four transparency obligations for AI systems with limited risk: chatbots must be labeled as AI (para. 1, provider), AI-generated images, audio, video and text must be machine-readably marked (para. 2, provider), the use of emotion recognition and biometric categorization must be disclosed (para. 3, deployer), and deepfakes as well as AI-generated text on matters of public interest must be labeled accordingly (para. 4, deployer). The obligations apply from August 2, 2026. Full mapping in the glossary →

When does EU AI Act Article 50 take effect?

The transparency obligations under Art. 50 apply from August 2, 2026 — two years after the regulation entered into force on August 1, 2024. This is the first major deadline of the EU AI Act; national market surveillance in Germany is still being set up via the KI-MIG (draft bill: BNetzA as the central authority).

What is the difference between Article 50 and Annex III?

Annex III concerns high-risk AI systems with comprehensive obligations (Art. 9–15, including conformity assessment). Article 50 concerns AI systems with limited risk and focuses on transparency toward users. Both obligations apply from August 2026 but can apply to the same company at the same time.

What does the AI labeling obligation mean specifically?

The AI labeling obligation under Art. 50 comprises four separate obligations: 1) Providers must disclose, for chatbots, that users are interacting with an AI system (para. 1). 2) Providers must technically (machine-readably) mark AI-generated images, audio, video and text content as AI-generated (para. 2). 3) Deployers of emotion recognition or biometric categorization systems must inform affected individuals (para. 3). 4) Deployers must declare deepfakes as well as AI-generated text on matters of public interest as such (para. 4). Technical implementation requires adjustments in the infrastructure and in the domain's machine-readable governance declaration. SOVP checks exactly these signals.

Does Article 50 also apply to B2B companies?

Yes. Art. 50 distinguishes between providers (who develop systems) and deployers (who use systems). B2B companies that provide chatbots or AI-generated content to business customers also fall under the transparency obligations — unless it is purely internal use.

Be prepared by August 2026

Check now how your infrastructure stands.

The free CERTavia scan checks your domain's AI governance signals: AI Policy URL, deepfake disclaimer, crawler consistency and more — in 90 seconds, no login required.

Check your domain now – free Quick test: am I affected by Annex III?

CERTavia analyzes technical infrastructure signals. The result is a machine-readable finding, not a legal opinion and not a certification within the meaning of the EU AI Act conformity assessment under Article 43. For legally binding compliance assessments, contact an accredited conformity assessment body.