EU AI Act Article 50 enters force: new transparency obligations bite
The EU AI Act’s Article 50 has officially entered into force, bringing with it a fresh set of transparency obligations for AI providers and deployers across the bloc. If your organisation runs generative AI tools, you’re now on the hook.
The rule targets a simple problem: people increasingly can’t tell whether they’re talking to a machine or a human. AI-generated images are getting harder to distinguish from real photos. Emotion recognition and biometric categorisation tools are being deployed without anyone knowing. The European Commission ties all of this to manipulation at scale, fraud, impersonation, and consumer deception.
Article 50 is the EU’s answer. It forces transparency into the AI value chain, and it applies right now.
What providers must build into their systems
Providers have a clear duty under Article 50: design systems so that anyone interacting directly with an AI knows it’s an AI. There’s a sensible carve-out for cases where a reasonably well-informed, observant person would already know from the context. Law enforcement systems used to detect, prevent, investigate, or prosecute crimes also sit outside the rule, provided safeguards protect third-party rights — unless the public can use the system to report a crime.
Providers of systems that generate synthetic audio, image, video, or text face a separate duty. The mechanism is marking. Output must carry a machine-readable mark that identifies it as artificially generated or manipulated.
Marking must be effective and interoperable
The Act asks for marking that’s effective and interoperable “as far as this is technically feasible,” weighing implementation cost against the state of the art. Assistive editing that leaves deployer-supplied input essentially untouched falls outside the requirement. A routine photo touch-up doesn’t trigger it; a wholesale AI-generated replacement does.
What deployers must tell people
Deployers running emotion recognition or biometric categorisation systems must inform the people exposed to them. Personal data gathered through such systems still falls under existing data protection law: the GDPR governs the general case, the EU institutions data protection regulation applies where an EU body runs the system, and the Law Enforcement Directive covers policing contexts.
Deepfakes get their own disclosure duty. Image, audio, or video content that’s artificially generated or manipulated has to carry a disclosure saying so. Artistic, satirical, or fictional work gets a lighter touch: the disclosure only needs to flag the content’s existence, worded so it doesn’t get in the way of enjoying the work.
Public interest text has its own rule
Text published to inform the public on matters of public interest carries a distinct obligation. Deployers must disclose AI generation or manipulation of that text unless a human has reviewed it and someone holds editorial responsibility for the publication. Standard newsroom review clears the bar. Unedited AI output published straight to a public interest story does not.
All disclosures need to land no later than the first interaction or exposure, in a manner that’s plain, distinguishable, and accessible under existing accessibility rules. There’s no grace period for informing someone after the fact.
How the EU will enforce Article 50
Three bodies split enforcement. National market surveillance authorities handle most cases. The AI Office takes systems that fall under its own supervision. The European Data Protection Supervisor steps in when an EU institution itself acts as provider or deployer.
The guidelines set out how providers and deployers can show they’ve met the marking obligation in Article 50. Signing on to the Code of Practice on Transparency of AI-generated Content is one path. Organisations that skip the Code have to demonstrate compliance through alternative means the Commission considers adequate. What those alternatives look like in practice isn’t spelled out in detail; that judgement falls to the market surveillance authorities doing the enforcing.
The other transparency duties don’t have an equivalent code. No code, no shortcut. Telling people they’re talking to an AI is one duty. Disclosing deepfakes and flagging AI-generated public interest text round out the rest, and providers and deployers work out their own adequate measures, with the guidelines serving as a reference point rather than a checklist.
Definitions and the provider-deployer distinction
Much of the document is definitional. It sets out what counts as a directly interactive AI system, what qualifies as synthetic content, and where the line sits between a deepfake and ordinary edited media. Standard editing sits outside scope by name, alongside assistive functions that leave deployer-supplied input intact.
The guidance also works through the value chain question of who counts as a provider and who counts as a deployer, and what happens when both roles sit with the same organisation. Which of the four Article 50 obligations apply, and to whom, comes down to that provider-deployer distinction.
Organisations weighing up the Code of Practice against building their own labelling approach now have somewhere to start. The guidelines give them a Commission-endorsed reference point that goes beyond the bare text of the regulation.
For a deeper look at how AI regulation is shaping the enterprise landscape, see our piece on OpenAI aligning safety practices with the EU AI Act. And if you’re tracking the broader compliance picture, you might also want to read about GDPR compliance for AI systems.
Want to learn more about AI and big data from industry leaders? Check out the AI & Big Data Expo taking place in Amsterdam, California, and London. The comprehensive event is part of TechEx and is co-located with other leading technology events including the Cyber Security & Cloud Expo. For more details, visit the event page.