The European Union’s new AI-transparency rules started applying on August 2, 2026, but the practical requirement is not “put an AI label on everything made with AI.”
Article 50 of the EU AI Act creates different duties for different actors. AI-system providers must build disclosure and machine-readable marking into certain systems. Businesses, publishers and other professional users—called deployers—must visibly disclose specific uses such as deepfakes and unreviewed AI-written text about matters of public interest.
A normal AI-assisted email, edited product description or stylised illustration is not automatically subject to a visible public label. The important questions are what the system does, how realistic or informative the output is, who publishes it, and whether a qualified human substantively reviewed it.
Rule check: August 4, 2026. Article 50 applies from August 2, 2026. The European Commission published final implementation guidelines on July 20 and an official quick-facts page updated July 29. The EU’s Code of Practice and labelling icons are voluntary tools; the underlying legal duties are not. This article is an operational explainer, not legal advice.
The quick answer
Visible disclosure is most clearly required in these cases:
- a person is interacting directly with an AI system and that fact is not already obvious;
- an organisation uses emotion-recognition or biometric-categorisation technology on people;
- AI creates or materially manipulates realistic image, audio or video content that could falsely appear authentic—a deepfake;
- AI-generated or manipulated text is published to inform the public about a matter of public interest without substantive human review or editorial control.
Separately, providers of systems that generate synthetic text, audio, images or video generally need to make outputs machine-readable and detectable as AI-generated or manipulated, where technically feasible.
The visible label and the machine-readable mark are related but different duties.
First separate the provider from the deployer
Many confusing summaries collapse two roles into one.
| Role | Typical example | Main Article 50 responsibility |
|---|---|---|
| Provider | A company develops and offers an AI chatbot, image generator or content system under its own name | Build interaction notices and machine-readable output marking into the system |
| Deployer | A retailer, publisher, agency, school or other organisation uses an AI system professionally | Inform people about emotion/biometric systems and visibly disclose covered deepfakes or unreviewed public-interest text |
A company can hold both roles. For example, an agency that develops its own branded customer chatbot and deploys it on client websites may have provider duties for the system and deployer duties for its use.
Hiring a freelancer or contractor does not necessarily move responsibility away from the organisation when the system is still operated on its behalf and under its control.
What providers need to build into AI systems
1. Tell people when they are interacting with AI
A provider of an AI system designed for direct two-way interaction must ensure people are informed that they are dealing with AI, unless that is obvious to a reasonably informed and observant person in the circumstances.
A clearly branded “AI assistant” usually presents less ambiguity than a support widget using a human name, portrait and conversational design without disclosure.
The information must be clear and distinguishable and provided no later than the first interaction. Accessibility requirements also apply.
2. Add machine-readable marks to generated content
Providers of systems generating synthetic text, audio, images or video must generally make outputs detectable as artificially generated or manipulated. The technical measure must be effective, interoperable, robust and reliable as far as technically feasible.
This is closer to provenance metadata, watermarking or another detection mechanism than to a large visible badge placed over every output.
The provider-side marking duty has important limits. It does not apply when the AI merely assists with standard editing or does not substantially alter the supplied input or its meaning. A basic crop, spelling correction or light adjustment is therefore different from generating a new scene, replacing a face or materially rewriting a factual publication.
What professional users need to disclose visibly
Deepfakes
Article 50 defines the covered category around realistic deception rather than around every generated picture.
A deepfake is AI-generated or manipulated image, audio or video content that appreciably resembles an existing person, object, place, organisation or event and could falsely appear authentic or truthful.
Likely covered examples include:
- cloning a real executive’s voice for a promotional recording;
- placing a public figure into footage of an event that did not happen;
- furnishing an authentic photograph of an empty property with realistic AI-generated interiors without making the alteration clear;
- materially modifying real news footage so viewers could mistake it for an authentic record.
A visible disclosure must be clear and distinguishable at the latest when the person first sees or hears the content.
Evidently artistic, fictional, satirical or creative works are not simply excluded. Instead, the disclosure can be made in an appropriate way that does not spoil the normal display or enjoyment of the work.
AI-written text on matters of public interest
The text rule is narrower than “all AI copy must be labelled.” Three elements matter:
- the text is published;
- its purpose is to inform the public;
- it concerns a matter of public interest.
The Commission’s guidance includes areas such as politics, public administration, justice, fundamental rights, public safety, health, environmental protection, consumer safety, and economic, financial, scientific or cultural developments relevant to public debate.
Examples that may fall within scope include an automatically generated public-health article, a political explainer, a financial-policy report or a news summary published without substantive editorial review.
Routine private correspondence, internal notes and ordinary commercial copy are not automatically public-interest publications merely because AI helped write them.
Human review can remove the text-labelling duty—but not any review will do
AI-generated public-interest text does not require the Article 50 disclosure when it has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication.
The Commission describes meaningful human review as deliberate examination of the substance by someone with relevant knowledge and professional judgement. Editorial control means having genuine authority to approve, alter or reject the content for substantive reasons, including fact-checking and assessing source reliability.
These are unlikely to be enough by themselves:
- running a spelling or grammar checker;
- accepting an AI draft after a quick skim;
- checking formatting but not factual claims;
- assigning a person nominal responsibility without giving them authority to change or reject the text.
A useful internal test is:
Could the reviewer explain the important claims, identify the sources, reject the draft, and accept responsibility for the published result?
When the answer is no, the organisation should not rely casually on the human-review exemption.
The four-case decision table
| Use case | Visible disclosure? | Other likely action |
|---|---|---|
| Website chatbot that could be mistaken for a person | Usually yes, unless interaction with AI is obvious | Provider designs the first-interaction notice |
| Fully synthetic decorative illustration that does not pretend to document reality | Not automatically under the deepfake rule | Provider may still need machine-readable marking |
| Real photograph materially altered to show a believable event or condition that did not exist | Usually yes | Keep the disclosure with downloaded or reshared versions where practicable |
| AI-drafted article about public health, economics or politics with no substantive editor | Yes | Label clearly at first exposure |
| AI-drafted public-interest article fact-checked and approved by a responsible editor | Article 50 text label may not be required | Preserve evidence of the review and editorial responsibility |
| Private AI-assisted email or internal summary | Generally outside the public-interest publication rule | Other privacy, employment or sector rules may still apply |
| Emotion-recognition tool assessing people in a workplace or service | Yes, inform exposed people | Data-protection and other AI Act requirements may also apply |
This table is a screening tool, not a substitute for analysing the actual system and context.
Do the rules affect organisations outside the EU?
Potentially, yes.
The Commission says the AI Act applies to public and private actors inside and outside the EU when they place an AI system or general-purpose model on the EU market, put an AI system into service in the EU, use it in the EU, or its use affects people located in the EU.
A non-EU software provider offering a generative product to EU customers should not assume that its incorporation address keeps it outside scope. A non-EU publisher or business should assess the rule when its AI system is used in the EU or produces output used there.
The exact territorial analysis can become complicated, especially for global websites, outsourced workflows and systems operating across several entities. That is a sensible point to obtain specialist advice rather than relying on a generic footer.
The optional EU icons are not the law itself
The European Commission has published free icons for:
- a general AI-involvement indication;
- AI GENERATED;
- AI MODIFIED.
Their use is optional. A business can use another clear disclosure method, provided it meets the legal requirement. Conversely, placing the official icon somewhere obscure does not automatically establish compliance.
The Commission recommends that disclosures be visible at first exposure, avoid overlays that hide them, remain available when content is reshared or downloaded where feasible, and use accessible plain language. Its own user testing found better recognition when the icon was accompanied by text.
For many organisations, “AI-generated reconstruction” or “Voice generated using AI” will communicate more clearly than an unexplained symbol alone.
The limited transition rule
Article 50 began applying on August 2, 2026. Outputs already generated and made available before that date do not need to be labelled retroactively under the new rule, although voluntary disclosure may still be useful.
The Commission also describes a limited transition until December 2, 2026 for the provider-side machine-readable marking obligation for certain generative systems already placed on the market before August 2. That transition does not create a broad four-month holiday for every chatbot notice or every new deepfake publication.
Organisations should document which system version and output date they are relying on rather than treating “existing AI” as a universal exemption.
A 30-minute compliance triage
1. Inventory public-facing AI uses
List chatbots, voice systems, image tools, automated publishing, synthetic presenters, product visualisation and any emotion or biometric analysis. Include systems operated by agencies and contractors.
2. Assign the role
For each use, record whether the organisation is the provider, deployer or both. Name the entity that controls the system and the entity that publishes the output.
3. Classify the exposure
Ask whether people are:
- directly interacting with AI;
- exposed to emotion recognition or biometric categorisation;
- seeing realistic manipulated media;
- reading AI-generated public-interest text.
4. Record the review gate
For public-interest text, identify the person with subject knowledge and real authority to approve, modify or reject the substance. Record the sources checked and the final approval.
5. Check the label and provenance path
Confirm that visible disclosures appear at first exposure and survive the normal download or sharing flow where required. Ask the system provider what machine-readable marking it adds and whether later editing strips it.
6. Keep evidence
Store the system version, publication date, disclosure wording, placement decision, review record and person responsible. The voluntary Code of Practice can provide a useful benchmark even for organisations that do not sign it.
Common mistakes
Labelling every AI-assisted sentence
Over-labelling can obscure the rule’s purpose and train readers to ignore warnings. Focus first on the covered interaction, deepfake, public-interest and biometric cases.
Treating a footer as sufficient for everything
Article 50 requires information at first interaction or exposure. A generic policy page that users never see may not provide a clear and distinguishable disclosure in context.
Assuming a human name equals human review
Naming an editor is not the same as substantive review, authority and responsibility. Preserve a real editorial process.
Relying only on visible labels
Providers also have a separate machine-readable marking duty. A caption can inform a viewer while failing to preserve provenance for platforms and detection tools.
Assuming an AI vendor handles every obligation
The vendor may handle system-level marking, while the deployer remains responsible for how a deepfake or public-interest publication is presented to people.
Enforcement and penalties
The Commission’s current quick-facts guidance says Article 50 enforcement can involve national market-surveillance authorities, the AI Office for systems under its supervision, and the European Data Protection Supervisor for EU institutions.
It lists maximum fines of €15 million or 3% of total worldwide annual turnover for companies, with proportionality considerations for smaller businesses. The maximum is not an automatic penalty for every imperfect label; enforcement must consider the circumstances and applicable legal framework.
The practical lesson is not to panic-label every use. It is to make a documented, defensible decision about the uses most clearly covered.
What to watch next
- National authorities will develop enforcement practice, which should clarify what disclosure placement works in real products.
- Technical standards for robust and interoperable machine-readable marking will continue evolving.
- The December transition for certain existing provider systems will end.
- Platforms may introduce stricter contractual labelling rules than Article 50 itself.
- Courts and regulators will eventually test the boundaries of “deepfake,” “public interest,” meaningful human review and territorial scope.
Conclusion
The EU’s new rule is not a universal sticker requirement for anything touched by AI.
It is a layered transparency system: tell people when they are interacting with AI, preserve machine-readable provenance for generated outputs, disclose realistic deceptive media, label unreviewed AI text that informs the public on important matters, and inform people exposed to emotion or biometric analysis.
The most useful next step is a short inventory and decision record. Identify the role, the audience exposure, the realism or public-interest purpose, the human-review gate and the disclosure method. That produces a more reliable compliance process than adding “made with AI” to everything—or to nothing.
Sources
- European Commission — Guidelines on transparency obligations under Article 50
- European Commission — Quick Facts: Transparency rules for AI systems
- European Commission — Article 50 questions and answers
- European Commission — EU icons for labelling AI-generated content
- European Commission — Code of Practice on Transparency of AI-Generated Content
- European Commission — Signing the transparency Code of Practice
- EUR-Lex — Regulation (EU) 2024/1689, including Article 50
