EU AI Act Transparency Rules (Article 50)
If your business puts AI in front of people, the transparency rules already apply to you. Here’s what they require and how to comply.
The EU AI Act’s transparency rules (Article 50) require you to be open when people are dealing with AI. Chatbots must identify themselves as machines, AI-generated content must be marked as artificial, and deepfakes and AI-written material on matters of public interest must be labelled. They apply to almost any business using everyday generative AI, not just high-risk systems.
Why it matters
For most organisations, Article 50 is the first real EU AI Act obligation they actually hit, because it attaches to ordinary tools: customer chatbots, AI image and copy generators, synthetic voice. It is one of the most common triggers of all, second only to AI literacy. It sits outside the high-risk structure entirely, so the Digital Omnibus that pushed high-risk deadlines to December 2027 did not touch it. The rules took effect on 2 August 2026 and are live now. Many businesses spent early 2026 believing enforcement had been postponed. For transparency, it wasn’t. Breaches carry penalties of up to €15 million or 3% of worldwide annual turnover.
Who it applies to
Both providers (those who build or supply the AI system) and deployers (those who use it in a professional capacity) have duties, depending on the situation. It reaches you wherever you’re based: a UK company serving EU users is in scope. The one clear exclusion is purely personal, non-professional use, for example an individual making a deepfake for their own social media.
The four transparency duties
1. Tell people when they’re talking to AI. If you provide a system that interacts directly with people, such as a chatbot, virtual assistant or AI voice agent, it must make clear the person is dealing with a machine. The exception is narrow: only where it would already be obvious to a reasonably informed person.
2. Mark AI-generated content so machines can detect it. Providers of generative AI must ensure outputs (image, audio, video, text) are marked in a machine-readable format that flags them as artificially generated or manipulated.
3. Disclose emotion recognition and biometric categorisation. If you deploy a system that infers emotions or sorts people by biometric characteristics, you must inform the people exposed to it.
4. Label deepfakes and AI-written public-interest content. Deployers must disclose when image, audio or video content is an AI-generated deepfake, and when AI-generated text is published to inform the public on matters of public interest. The deepfake duty applies even where there was no intent to deceive. Limited exceptions exist, for example for evidently artistic or creative work, where disclosure is handled so it doesn’t spoil the work, and for text that has had genuine human editorial review.
Key dates
● 2 August 2026: the transparency rules apply. Live now.
● 2 December 2026: the only extension, and a narrow one. It covers just the machine-marking duty for generative systems already on the market before 2 August 2026. Content generated before that date does not need to be labelled retroactively.
What good compliance looks like
Find every place AI meets an audience: chatbots, generated marketing content, synthetic media, published AI-assisted text. Decide how you disclose in each case, build it into the design and the workflow rather than bolting it on, and keep a record of your decisions. The Commission published draft guidelines on Article 50 on 8 May 2026, and a Code of Practice on marking AI-generated content is being developed, so the detail is firming up. If you’re not sure which of the four duties bite for you, that’s exactly what a readiness review answers.
Frequently asked questions
Do the transparency rules apply if I only use a third-party AI tool like ChatGPT?
Often, yes. As a deployer you can still carry duties, for example labelling a deepfake you generate or disclosing AI-written public-interest content you publish. Some marking duties fall on the tool’s provider, but that does not remove your own deployer obligations.
We’re a UK business. Are we really in scope?
If the output of your AI is used in the EU, yes. Article 50 applies regardless of where you’re established. There is no UK equivalent statute, but the ICO, Ofcom and the FCA apply existing duties to similar conduct, so it’s rarely a reason to relax.
Does mentioning AI in our terms and conditions count as disclosure?
No. The Commission’s draft guidelines are explicit that burying a reference in terms and conditions does not meet the standard. Disclosure has to be clear and noticeable to the person at the point they encounter the AI.
Do we have to label marketing copy or images our team makes with AI?
It depends on the content. Deepfake-style imagery that resembles real people or events needs disclosure. Ordinary AI-assisted marketing text generally does not, unless it’s publishing information to the public on a matter of public interest. The line isn’t always obvious, which is where mapping your use cases pays off.
What about our customer service chatbot?
It must make clear to users that they’re interacting with AI, unless that’s already obvious. A short, visible statement at the start of the interaction is the usual approach.
When did this take effect, and is there any grace period?
The rules have applied since 2 August 2026. The only extension runs to 2 December 2026 and covers only the machine-marking of content for generative systems already on the market before August 2026.
Let’s talk
Not sure which of the four duties apply to how you use AI? That’s the first thing we map. Start with a free, no-obligation intro call.
→ Schedule a call: Free Consultation - veritas_fox or email laura@veritasfox.com
AI compliance made easy.




Comments