Article 50 Transparency Toolkit
While the high-risk regime waits for December 2027, these are the duties that bind today — and they are the easiest for a regulator to verify from the outside: anyone can open your chatbot and check. Below: what each trigger requires, when the notice must appear, paste-ready texts following the Code of Practice two-layer pattern, and the evidence worth keeping. Content marking for systems already on the market before 2 August 2026 has a hard date of 2 December 2026 — systems launched after that must mark from day one.
Texts are counsel-review starting points, not legal advice. Run the free assessment to find out which of these triggers actually apply to your systems.
Chatbots & voice agents — people interact with the AI
Art. 50(1) · duty of the provider · applies since 2 August 2026People must be informed that they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person in the circumstances and context of use (narrow law-enforcement exceptions exist). The Commission's Code of Practice (June 2026) recommends a two-layer disclosure: a persistent visual indicator plus an explicit first-interaction notice.
When: At the latest at the time of first interaction — in practice: before or in the first message, and visible for the whole session.
AI assistant
You're chatting with an AI assistant. It can make mistakes — for anything important, please verify with our team. Ask to be connected to a human at any time.
Hi, this is an automated AI assistant for [Company]. This call may be handled entirely by AI — say “human” at any point to be transferred to a person.
Automated AI chat — answers may contain errors.
Evidence worth keeping (4)
- Screenshot of the badge and the first-message notice, dated
- The notice text in every UI language you ship
- Ticket/commit reference of the implementation
- Named owner responsible for keeping the disclosure in place
Generated audio, image, video or text — machine-readable marking
Art. 50(2) · duty of the provider · applies since 2 August 2026Outputs must be marked as artificially generated or manipulated in a machine-readable format (e.g. metadata/watermarking) — effective, interoperable, robust and reliable as far as technically feasible. Timing split under the Omnibus: systems placed on the market ON OR AFTER 2 August 2026 must mark from day one; only systems already on the market before that date get a grace period, until 2 December 2026.
When: At generation time, embedded in the output itself — a disclaimer on the website does not satisfy the machine-readable requirement.
This content was generated with AI.
All media returned by this API carries provenance metadata (C2PA) identifying it as AI-generated. Preserve it when re-encoding: it is how the marking requirement of Article 50(2) EU AI Act is met for this content, and your own disclosure duties (e.g. deepfake labelling under Article 50(4)) may depend on it.
Evidence worth keeping (4)
- Sample output file whose metadata shows the AI-generated marking
- Description of the marking technique (C2PA / watermark / metadata) and where it is applied in the pipeline
- Robustness note: what survives re-encoding, cropping, screenshots
- For systems on the market before 2 August 2026: the plan dated before 2 December 2026
Deepfakes — visible disclosure of manipulated content
Art. 50(4) · duty of the deployer · applies since 2 August 2026Deployers of systems that generate or manipulate image, audio or video constituting a deepfake must disclose that the content has been artificially generated or manipulated; for artistic, satirical or fictional works the duty narrows to a disclosure that does not hamper the display. Separately, AI-generated text published to inform the public on matters of public interest must be disclosed — exempt only where the text has undergone human review or editorial control AND a natural or legal person holds editorial responsibility for the publication. Both limbs are required for the exemption.
When: Visible when the content is first shown — not in a linked policy page.
Digitally generated/altered — this is not a real recording.
This article was generated by AI and has not undergone human editorial review.
Evidence worth keeping (3)
- Screenshot of the label as actually displayed with the content
- If you rely on the text exemption: the editorial-review process AND the named person/entity holding editorial responsibility — both are required
- Dated record of when labelling went live
Emotion recognition & biometric categorisation — informing the exposed
Art. 50(3) · duty of the deployer · applies since 2 August 2026Where a permitted emotion-recognition or biometric-categorisation system is used, the natural persons exposed to it must be informed of its operation, and personal data must be processed in line with GDPR. Remember the boundary: emotion recognition in workplaces and education is prohibited outright (Art. 5(1)(f), save narrow medical and safety exceptions), not merely disclosable.
When: Before or at the moment the person is exposed to the system's operation.
This area/service uses an AI system that analyses [voice/facial expressions] to infer [emotional state / category]. Details on the data processed and your rights: [link to privacy notice].
Evidence worth keeping (3)
- The notice as displayed at the point of exposure, dated
- The GDPR record of processing covering this system (lawful basis, DPIA if required)
- Written analysis of why the use does not fall under the Art. 5 workplace/education prohibition
Not sure which triggers apply to your systems?
The free 10-minute assessment maps every system to its Article 50 triggers — and everything else — with article references. In your browser only.
Run the free assessment →