Reguly
All articles
EU regulation

Art. 50 AI Act: transparency obligations from 2026

Ben Koenigs, Co-Founder & CPO, Reguly
Ben Koenigs
Co-Founder & CPO, Reguly
8 min read Updated July 2026
A person at an editing desk with two monitors working on images — representing the labelling of generated and manipulated content under Art. 50

On 2 August 2026 Art. 50 of the AI Act takes effect — the article that hits most companies first. Not because it governs high-risk systems, but because it attaches to ordinary use: the chatbot on the website, the generated product shot, the text in the newsroom. It contains four obligations, and they are spread across two different roles. Confuse the roles and you satisfy the wrong obligation.

Legal basis
Art. 50 Regulation (EU) 2024/1689
Applicable from
2 August 2026
Obligations
4, split between providers and deployers
Fine range
up to €15m or 3% of turnover

Provider or deployer — the question before all others

Art. 50 addresses two roles with different obligations. A provider is anyone who develops an AI system and places it on the market under their own name. A deployer is anyone using such a system under their own authority. Most companies are deployers: they buy in a model and use it. Anyone substantially modifying a third-party system, or offering it under their own name, can however become a provider themselves — and then owes the provider obligations on top.

This distinction is not a formality, because the obligations differ technically. The provider obligation under paragraph 2 is a marking in machine format — something that sits in the file and can be read out automatically. The deployer obligation under paragraph 4 is a disclosure to people — something a reader sees. A machine-readable watermark satisfies no disclosure obligation, and a visible note satisfies no marking obligation.

The four obligations at a glance

  • Para. 1 — interaction with AI (provider): people have to be able to tell that they are talking to an AI system. Exception: it is obvious from the perspective of a reasonably well-informed person.
  • Para. 2 — marking synthetic content (provider): systems generating audio, image, video or text have to mark their output in machine-readable form as artificially generated or manipulated.
  • Para. 3 — emotion recognition and biometric categorisation (deployer): the people affected have to be informed of the use; data protection requirements apply alongside, untouched.
  • Para. 4 — deepfakes and text on matters of public interest (deployer): anyone publishing such content has to disclose that it is artificially generated or manipulated.

Two rules on top of that are easily missed. Under paragraph 5 the information has to be provided at the latest at the first interaction or exposure, has to be clearly distinguishable and has to meet the accessibility requirements — a note in the legal notice therefore does not suffice. And under paragraph 6 Art. 50 does not take the place of other obligations: the requirements for high-risk systems in Chapter III and requirements from other Union or national law continue to apply alongside it.

Transparency is not a risk class

Art. 50 does not hang on the risk classification of a system. A minimal-risk chatbot can trigger the obligation under paragraph 1, an image generator the one under paragraph 2 — regardless of whether anything says “high risk” anywhere. The risk class decides the heavy obligations; the transparency obligations run alongside.

Which exemptions the regulation names

The exemptions are narrow and expressly named — they are not a general clause for “it is different with us”. Across all four paragraphs an exemption applies for legally authorised law enforcement purposes. For the marking of synthetic content under paragraph 2 two technical exemptions are added: systems performing an assistive function for standard editing, and systems that do not substantially alter the input data provided by the user or its semantics. Denoising a photo does not create synthetic content; turning it into a different scene does.

For deepfakes under paragraph 4 there is a softened variant for evidently artistic, creative, satirical or fictional works: there it suffices to disclose the existence of the artificial generation in an appropriate manner without hindering the display or enjoyment of the work. For text on matters of public interest the obligation falls away where the content underwent human review or editorial control and a natural or legal person holds editorial responsibility.

Code of Practice and guidelines: what is settled

Paragraph 7 provides that the AI Office encourages codes of practice on the detection and labelling of artificially generated content; the Commission may approve codes by implementing act or lay down its own common rules. On that basis the Code of Practice on Transparency of AI-Generated Content was produced, published on 10 June 2026. It consists of two sections — one for providers on marking and detection, one for deployers on labelling deepfakes and text on matters of public interest — and is expressly voluntary: signing happens via a form submitted to the AI Office. Annex I provides an optional EU symbol in three variants.

The Commission guidelines are now final

Following the draft that went to consultation in spring 2026, the Commission published the final guidelines on implementing the transparency obligations under Art. 50 on 20 July 2026. They are not legally binding, but market surveillance authorities will orient themselves by them. Anyone citing guidelines in compliance documentation should still check the version and reference themselves rather than adopting a third party’s summary.

What breaches risk

The fine structure of the AI Act has three tiers. Breaches of the prohibitions in Art. 5 sit at the top with up to €35m or 7% of worldwide annual turnover, whichever is higher. Breaches of obligations of operators — expressly including the transparency obligations in Art. 50 — sit at up to €15m or 3% of worldwide annual turnover. Incorrect, incomplete or misleading information to notified bodies or authorities sits at up to €7.5m or 1%. For SMEs including start-ups the lower of the two figures applies in each case, not the higher.

What this means in practice

The obligation attaches to the individual system and to your own role with it. That means: without a list of the AI systems in use, Art. 50 cannot be satisfied, because nobody can say which paragraph applies to which system. Three steps are enough to start.

  • Record the systems: name, provider, area of use, responsible person — one entry per tool, including the subscription the marketing department booked on the side.
  • Clarify the role per system: deployer or provider, and whether a substantial modification exists. That determines which paragraph applies.
  • Check the output: where does generated content leave the building? That is exactly where the marking or disclosure obligation arises — not at the model but at the publication route.

Reguly keeps exactly this list as an AI inventory: per system the classification together with the trigger that caused it, plus the obligations with article references and the evidence of AI literacy under Art. 4. The judgement of whether a piece of content falls under paragraph 4 remains a legal decision — Reguly makes it documentable, not unnecessary.

Talk to us

Which AI systems are running in your organisation?

We go through which tools are in use, which role you occupy with each and which transparency obligation follows from that.

Arrange a call