All guides

Aug 19, 2026 · 14 min read

Article 50 Transparency Obligations: Four Lanes, Two Roles (2026)

Article 50 Transparency Obligations: Four Lanes, Two Roles (2026)

Short answer: Article 50 of the EU AI Act imposes four separate transparency duties split between AI providers and deployers. Two duties bind the provider (interaction notices and machine-readable marking of synthetic content); two bind the deployer (notices for emotion recognition and biometric systems, and disclosures of deepfakes and AI-generated public-interest text). All four apply as of 2 August 2026; a limited marking transition to 2 December 2026 for eligible systems has been proposed by the European Commission but is not yet adopted law.

What Article 50 Is and Who It Binds

Article 50 transparency obligations are the four legally binding disclosure requirements in the EU AI Act that govern how AI systems must inform people when they encounter artificial intelligence. The obligations are not one rule but four separate duties, and they do not all land on the same company.

Two duties bind the provider — the company that designs and develops the AI system:

  • Paragraph 1: An interaction notice for any AI system intended to interact directly with natural persons, delivered before or at the first interaction.
  • Paragraph 2: Machine-readable marking of synthetic audio, image, video, or text, detectable as artificially generated or manipulated.

Two duties bind the deployer — the company that puts the system in front of people:

  • Paragraph 3: Notice to persons exposed to emotion recognition or biometric categorisation systems, plus lawful processing of their personal data.
  • Paragraph 4: Disclosure that deepfake images, audio, or video — and AI-generated text published to inform the public on matters of public interest — are artificially generated or manipulated.

The application date is 2 August 2026. A limited transition that may extend provider-side machine-readable marking to 2 December 2026 for eligible systems is envisaged in the Commission's November 2025 Digital Omnibus proposal; treat it as proposed, not adopted, until it appears in the Official Journal (European Commission, guidelines on transparency obligations).

This is operational guidance, not legal advice. Where the answer depends on facts specific to your system or your company's role in the AI value chain, those questions are flagged below and warrant counsel's input.

The Four Lanes: Routing Your Features

The wording of a disclosure notice is straightforward. What often goes wrong is routing: deciding which of the four lanes a feature sits in, and whether your company is the provider or the deployer for that specific feature. Get the routing wrong and you ship a carefully drafted notice that answers a duty you do not owe, while the one you do owe stays unshipped.

Run this table per feature, not per company. A single product with a chatbot, a blog, and a call-analytics add-on lands in three different lanes with two different roles.

Feature PatternLane to Check FirstRole You Are Likely ArguingFirst Thing to Ship
In-app support chatbot on a third-party model, your brand on the UI50(1)Provider of the system you put on the marketNotice rendered before the first user message
Outbound voice agent that calls customers50(1) and 50(2)ProviderSpoken notice in the opening turn, not the closing one
Internal HR helpdesk bot, employees only50(1)Provider and deployer of the same systemThe same notice — staff are natural persons
Reply suggestions a human agent edits and sends50(2), assistive-function questionProviderA written decision on whether the edit is substantial
Grammar and spelling correction50(2) exceptionProviderDocumented reasoning for why the exception applies
Blog posts drafted by a model, published under the company name50(2), plus 50(4) text limb if public-interestProvider and deployerMarking in the page source; named editorial sign-off
AI-generated product photography in a catalogue50(2) marking (owed by the generator's provider); check 50(4)Deployer of the generatorProvider's marking preserved on export, not stripped in your pipeline
Synthetic voiceover cloning a real presenter50(4)DeployerAudible or on-screen disclosure
Face-swap or likeness feature in a consumer app50(2) provider marking; 50(4) may bind business users as deployersProviderMarking, plus in-product notice that professional users may owe their own 50(4) disclosure
Support-ticket sentiment scoring, text onlyLikely outside 50(3)DeployerRecord why: no biometric input
Call-centre voice tone and emotion analysis50(3)DeployerNotice to callers, plus a data protection review — and if agents at work are analysed too, the Article 5 prohibition on workplace emotion recognition is the prior question
Age or gender inference from a webcam feed50(3)DeployerNotice at the point of capture
A model API you resell to other companies50(2)ProviderMarking plus documentation your customers can rely on
Vendor chatbot embedded under the vendor's brand50(1)Deployer of a third-party systemVerify the vendor's notice actually renders on your site

When Sentiment Scoring Falls Outside Article 50(3)

Text-only sentiment scoring sits outside lane 3 because that lane is scoped to emotion recognition and biometric categorisation systems, both defined in the Act by reference to biometric data. Add a webcam or a voice recording to the same pipeline and the answer changes. The distinction matters because it shifts whether you owe a notice to the exposed persons.

When You Are Reselling an API

The resold-API row matters because your marking decisions become your customers' evidence. If you do not tell them what marking your outputs carry, they cannot document their side of the compliance chain.

When Provider and Deployer Lines Are Contested

Where the provider/deployer line is genuinely contested — you fine-tuned a model, put your name on it, and materially changed what it does — that is a question about responsibilities along the AI value chain. It is worth an hour of counsel's time rather than a confident row in a spreadsheet. Our longer walkthrough of the chatbot case sits in Chatbot disclosure requirement under EU AI Act Article 50.

Where the Exceptions Get Read Too Generously

Obviousness Under Article 50(1)

The disclosure duty does not apply where the interaction is obvious from the point of view of a reasonably well-informed, observant and circumspect natural person, taking account of the circumstances and context of use (AI Act Service Desk, Article 50). That is a test about a stranger, not about your team.

A usable rule: if you cannot name the specific cue in the interface that tells a first-time user, on their first message, that they are talking to software, you have familiarity, not obviousness. "The widget is called AI Assistant" is a cue. "Everyone knows support chat is automated now" is not one.

Assistive Editing Under Article 50(2)

The marking duty is scoped away from assistive functions for standard editing and from systems that do not substantially alter the input data provided by the deployer or its semantics (Article 50 text with recitals). Spell-check is comfortably inside that carve-out. "Rewrite this paragraph in a warmer tone" is not spell-check, and a feature that started as autocorrect and grew a rewrite button has left the exception it was scoped under.

Artistic and Satirical Work Under Article 50(4)

This exception is not an off switch. The disclosure is scaled rather than removed: it is made in an appropriate manner that does not hamper the display or enjoyment of the work (Article 50 text with recitals). A caption in the credits can satisfy that where a modal over the artwork would not.

Separately, the text limb of 50(4) steps back where the AI-generated text has undergone human review and a natural or legal person holds editorial responsibility — which means a named accountable reviewer, with a record, not "someone read it before publishing".

What Article 50 Does Not Ask For

Not a Risk Classification

Article 50 is not a risk classification. Paragraph 6 is explicit that paragraphs 1 to 4 do not affect the requirements set out in Chapter III (AI Act Service Desk, Article 50). A system can owe an Article 50 notice and separately fall under the high-risk regime; shipping the notice tells you nothing about the second question.

Not a Consent Mechanism

Article 50 is not a consent mechanism. The same paragraph leaves other transparency obligations in Union or national law untouched, so the GDPR information duties run on their own track. A cookie-style consent banner that also mentions AI has answered neither properly.

Not Provenance or Cryptographic Proof

Machine-readable marking — HTML attributes, JSON-LD blocks, embedded metadata, response headers — is advisory metadata. It is not signed provenance and not a C2PA certification, and it does not survive a screenshot, a re-encode, or a copy-paste through a CMS that strips unknown fields. A metadata label tells a cooperative pipeline what happened; it proves nothing to anyone determined to remove it. The Act asks for marking that is machine-readable and detectable as artificially generated, taking account of technical feasibility and the state of the art — not for cryptographic proof.

Not a One-Time Project

Article 50 is not a one-time project. The marking duty attaches to output, so a model swap, a new export format, or a new generation surface re-opens the question you closed last quarter.

The Proposed Marking Transition: 105 Days to 2 December 2026

As of 19 August 2026, Article 50 has been in application for seventeen days and there are 105 calendar days until 2 December 2026. Two things need verifying before you plan around that date: whether the transition has actually been adopted (at the time of writing it is a Commission proposal), and whether a given system is eligible — check both against the Commission's guidance rather than assuming the later date applies to you. Where the transition applies, it concerns provider-side machine-readable marking; it does not move the 2 August date for the interaction notice or the deployer disclosures.

Milestone Timeline for the Transition Window

If you are using the remaining window, here is what those 105 days look like as milestones rather than intentions:

DateDayMilestoneDone When
2 Sep 202614Lane and role decided for every AI featureOne written determination per feature, with the decider's name
18 Sep 202630Notice copy and placement frozenCopy versioned, translated, accessibility-checked
18 Oct 202660Marking pipeline running in stagingMarking present on every output type, including exports
11 Nov 202684Verification against production, evidence log populatedA report you could hand over unedited
2 Dec 2026105Buffer consumed21 days spent on the things that broke in November

The buffer is the point. Teams that plan to the deadline instead of to day 84 discover in the last fortnight that the marking is stripped by their own image CDN, or that the notice renders on web but not in the mobile webview, and those are code changes, not copy changes.

Evidence That Survives a Change of Staff

Article 50 gives you no evidence format, which means the format is your problem. Ten fields per feature keep a determination reconstructable a year later, by someone who was not in the room:

1. Feature ID and every surface it renders on: Internal identifier and all deployment contexts (web, mobile, API, export). 2. Lane claimed: 50(1), (2), (3), (4) — or "out of scope" with the reason. 3. Role determination: The person who made it, the date, and the reasoning. 4. Notice text verbatim: With a version number and all translations. 5. Placement and trigger point: Which screen, which event, before or after first input. 6. Accessibility handling: Screen-reader announcement, contrast, a non-visual channel for voice. 7. Marking method and payload version: Per output type (e.g., HTML meta tag for images, JSON-LD for text). 8. Model or vendor version in force: At the time of the determination. 9. Dated verification that the notice actually rendered in production: Not a screenshot in Slack; a production report. 10. Change triggers that re-open the determination: Model swap, new output type, new market.

The common failure is not missing evidence. It is evidence that exists as a screenshot in a Slack thread plus a staging URL that no longer resolves, produced by an engineer who left in April. Field 9 is the one most often skipped and most often needed: a claim that a notice exists is weaker than a dated record that it rendered.

DiscloseKit does the mechanical part of this — a deterministic checker that maps features to the four lanes with no model in the compliance path, a disclosure widget, a verification run, and an append-only evidence log. What it does not do, and what no tool can do, is settle an ambiguous provider/deployer question for you or certify the outcome. If you are building the notice layer yourself, the implementation detail is in Article 50 Disclosure Widget Embed; the documentation side is in AI transparency statement template: what to document.

Three Questions Worth Paying a Lawyer For

Does Fine-Tuning and Rebranding Make You the Provider?

You have changed the system's behaviour and put your name on it. Where the answer flips the role, it flips which paragraphs you owe, and the reasoning depends on facts a checklist cannot see. This is a fact-specific determination that benefits from counsel's input before the feature ships.

Is Your Published Text "To Inform the Public on Matters of Public Interest"?

A security advisory, a health explainer, a comment on pending legislation — the line between marketing copy and public-interest information is exactly where the text limb of 50(4) bites, and it is not drawn by your content calendar. The distinction determines whether you owe a 50(4) disclosure on top of any 50(2) marking.

Does Your Employee-Facing Tool Trigger Article 50(1)?

Staff are natural persons. An internal assistant does not leave the interaction lane simply because it never faces a customer; the question is whether the deployment involves direct interaction, and works councils tend to ask it before regulators do. The answer has both compliance and employment-law dimensions.

None of the three is settled by a table, including the one above. All three get more expensive to answer the longer a feature ships without a written determination behind it.

Frequently Asked Questions

Which Article 50 duties bind the provider, and which bind the deployer?

Two duties sit with the provider: the interaction notice under paragraph 1 for systems intended to interact directly with natural persons, and machine-readable marking of synthetic audio, image, video or text under paragraph 2. Two sit with the deployer: the notice to persons exposed to emotion recognition or biometric categorisation under paragraph 3, and the disclosure of deepfakes and AI-generated public-interest text under paragraph 4. One company can hold both roles for different features of the same product, so the routing has to run per feature.

When do the Article 50 transparency obligations apply?

All four lanes apply as of 2 August 2026. A limited transition that may extend provider-side machine-readable marking to 2 December 2026 for eligible systems has been proposed by the European Commission but is not yet adopted law; verify its status and eligibility before planning around it, and note that even as proposed it does not move the 2 August date for the interaction notice or the deployer disclosures.

Is machine-readable marking proof of provenance?

No. HTML attributes, JSON-LD blocks, embedded metadata and response headers are advisory metadata. They are not signed provenance and not a C2PA certification, and they do not survive a screenshot, a re-encode or a copy-paste through a CMS that strips unknown fields. The Act asks for marking that is machine-readable and detectable as artificially generated, not for cryptographic proof.

Does an employee-only internal assistant fall outside Article 50(1)?

Not automatically. Staff are natural persons, so an internal assistant does not leave the interaction lane simply because it never faces a customer; the question is whether the deployment involves direct interaction with people. That determination has both compliance and employment-law dimensions and is worth a written decision, with counsel's input where it is close.

See exactly what applies to your product

Run the free check

Sources

This is compliance tooling, not legal advice. Consult counsel for your specific case.