Short answer: Article 50 of the EU AI Act imposes four separate transparency duties split between AI providers and deployers. Two duties bind the provider (interaction notices and machine-readable marking of synthetic content); two bind the deployer (notices for emotion recognition and biometric systems, and disclosures of deepfakes and AI-generated public-interest text). All four apply as of 2 August 2026; a limited marking transition to 2 December 2026 for eligible systems has been proposed by the European Commission but is not yet adopted law.
What Article 50 Is and Who It Binds
Article 50 transparency obligations are the four legally binding disclosure requirements in the EU AI Act that govern how AI systems must inform people when they encounter artificial intelligence. The obligations are not one rule but four separate duties, and they do not all land on the same company.
Two duties bind the provider — the company that designs and develops the AI system:
- Paragraph 1: An interaction notice for any AI system intended to interact directly with natural persons, delivered before or at the first interaction.
- Paragraph 2: Machine-readable marking of synthetic audio, image, video, or text, detectable as artificially generated or manipulated.
Two duties bind the deployer — the company that puts the system in front of people:
- Paragraph 3: Notice to persons exposed to emotion recognition or biometric categorisation systems, plus lawful processing of their personal data.
- Paragraph 4: Disclosure that deepfake images, audio, or video — and AI-generated text published to inform the public on matters of public interest — are artificially generated or manipulated.
The application date is 2 August 2026. A limited transition that may extend provider-side machine-readable marking to 2 December 2026 for eligible systems is envisaged in the Commission's November 2025 Digital Omnibus proposal; treat it as proposed, not adopted, until it appears in the Official Journal (European Commission, guidelines on transparency obligations).
This is operational guidance, not legal advice. Where the answer depends on facts specific to your system or your company's role in the AI value chain, those questions are flagged below and warrant counsel's input.
The Four Lanes: Routing Your Features
The wording of a disclosure notice is straightforward. What often goes wrong is routing: deciding which of the four lanes a feature sits in, and whether your company is the provider or the deployer for that specific feature. Get the routing wrong and you ship a carefully drafted notice that answers a duty you do not owe, while the one you do owe stays unshipped.
Run this table per feature, not per company. A single product with a chatbot, a blog, and a call-analytics add-on lands in three different lanes with two different roles.
| Feature Pattern | Lane to Check First | Role You Are Likely Arguing | First Thing to Ship |
|---|---|---|---|
| In-app support chatbot on a third-party model, your brand on the UI | 50(1) | Provider of the system you put on the market | Notice rendered before the first user message |
| Outbound voice agent that calls customers | 50(1) and 50(2) | Provider | Spoken notice in the opening turn, not the closing one |
| Internal HR helpdesk bot, employees only | 50(1) | Provider and deployer of the same system | The same notice — staff are natural persons |
| Reply suggestions a human agent edits and sends | 50(2), assistive-function question | Provider | A written decision on whether the edit is substantial |
| Grammar and spelling correction | 50(2) exception | Provider | Documented reasoning for why the exception applies |
| Blog posts drafted by a model, published under the company name | 50(2), plus 50(4) text limb if public-interest | Provider and deployer | Marking in the page source; named editorial sign-off |
| AI-generated product photography in a catalogue | 50(2) marking (owed by the generator's provider); check 50(4) | Deployer of the generator | Provider's marking preserved on export, not stripped in your pipeline |
| Synthetic voiceover cloning a real presenter | 50(4) | Deployer | Audible or on-screen disclosure |
| Face-swap or likeness feature in a consumer app | 50(2) provider marking; 50(4) may bind business users as deployers | Provider | Marking, plus in-product notice that professional users may owe their own 50(4) disclosure |
| Support-ticket sentiment scoring, text only | Likely outside 50(3) | Deployer | Record why: no biometric input |
| Call-centre voice tone and emotion analysis | 50(3) | Deployer | Notice to callers, plus a data protection review — and if agents at work are analysed too, the Article 5 prohibition on workplace emotion recognition is the prior question |
| Age or gender inference from a webcam feed | 50(3) | Deployer | Notice at the point of capture |
| A model API you resell to other companies | 50(2) | Provider | Marking plus documentation your customers can rely on |
| Vendor chatbot embedded under the vendor's brand | 50(1) | Deployer of a third-party system | Verify the vendor's notice actually renders on your site |
When Sentiment Scoring Falls Outside Article 50(3)
Text-only sentiment scoring sits outside lane 3 because that lane is scoped to emotion recognition and biometric categorisation systems, both defined in the Act by reference to biometric data. Add a webcam or a voice recording to the same pipeline and the answer changes. The distinction matters because it shifts whether you owe a notice to the exposed persons.
When You Are Reselling an API
The resold-API row matters because your marking decisions become your customers' evidence. If you do not tell them what marking your outputs carry, they cannot document their side of the compliance chain.
When Provider and Deployer Lines Are Contested
Where the provider/deployer line is genuinely contested — you fine-tuned a model, put your name on it, and materially changed what it does — that is a question about responsibilities along the AI value chain. It is worth an hour of counsel's time rather than a confident row in a spreadsheet. Our longer walkthrough of the chatbot case sits in Chatbot disclosure requirement under EU AI Act Article 50.
Where the Exceptions Get Read Too Generously
Obviousness Under Article 50(1)
The disclosure duty does not apply where the interaction is obvious from the point of view of a reasonably well-informed, observant and circumspect natural person, taking account of the circumstances and context of use (AI Act Service Desk, Article 50). That is a test about a stranger, not about your team.
A usable rule: if you cannot name the specific cue in the interface that tells a first-time user, on their first message, that they are talking to software, you have familiarity, not obviousness. "The widget is called AI Assistant" is a cue. "Everyone knows support chat is automated now" is not one.
Assistive Editing Under Article 50(2)
The marking duty is scoped away from assistive functions for standard editing and from systems that do not substantially alter the input data provided by the deployer or its semantics (Article 50 text with recitals). Spell-check is comfortably inside that carve-out. "Rewrite this paragraph in a warmer tone" is not spell-check, and a feature that started as autocorrect and grew a rewrite button has left the exception it was scoped under.
Artistic and Satirical Work Under Article 50(4)
This exception is not an off switch. The disclosure is scaled rather than removed: it is made in an appropriate manner that does not hamper the display or enjoyment of the work (Article 50 text with recitals). A caption in the credits can satisfy that where a modal over the artwork would not.
Separately, the text limb of 50(4) steps back where the AI-generated text has undergone human review and a natural or legal person holds editorial responsibility — which means a named accountable reviewer, with a record, not "someone read it before publishing".
What Article 50 Does Not Ask For
Not a Risk Classification
Article 50 is not a risk classification. Paragraph 6 is explicit that paragraphs 1 to 4 do not affect the requirements set out in Chapter III (AI Act Service Desk, Article 50). A system can owe an Article 50 notice and separately fall under the high-risk regime; shipping the notice tells you nothing about the second question.
Not a Consent Mechanism
Article 50 is not a consent mechanism. The same paragraph leaves other transparency obligations in Union or national law untouched, so the GDPR information duties run on their own track. A cookie-style consent banner that also mentions AI has answered neither properly.
Not Provenance or Cryptographic Proof
Machine-readable marking — HTML attributes, JSON-LD blocks, embedded metadata, response headers — is advisory metadata. It is not signed provenance and not a C2PA certification, and it does not survive a screenshot, a re-encode, or a copy-paste through a CMS that strips unknown fields. A metadata label tells a cooperative pipeline what happened; it proves nothing to anyone determined to remove it. The Act asks for marking that is machine-readable and detectable as artificially generated, taking account of technical feasibility and the state of the art — not for cryptographic proof.
Not a One-Time Project
Article 50 is not a one-time project. The marking duty attaches to output, so a model swap, a new export format, or a new generation surface re-opens the question you closed last quarter.
The Proposed Marking Transition: 105 Days to 2 December 2026
As of 19 August 2026, Article 50 has been in application for seventeen days and there are 105 calendar days until 2 December 2026. Two things need verifying before you plan around that date: whether the transition has actually been adopted (at the time of writing it is a Commission proposal), and whether a given system is eligible — check both against the Commission's guidance rather than assuming the later date applies to you. Where the transition applies, it concerns provider-side machine-readable marking; it does not move the 2 August date for the interaction notice or the deployer disclosures.
Milestone Timeline for the Transition Window
If you are using the remaining window, here is what those 105 days look like as milestones rather than intentions:
| Date | Day | Milestone | Done When |
|---|---|---|---|
| 2 Sep 2026 | 14 | Lane and role decided for every AI feature | One written determination per feature, with the decider's name |
| 18 Sep 2026 | 30 | Notice copy and placement frozen | Copy versioned, translated, accessibility-checked |
| 18 Oct 2026 | 60 | Marking pipeline running in staging | Marking present on every output type, including exports |
| 11 Nov 2026 | 84 | Verification against production, evidence log populated | A report you could hand over unedited |
| 2 Dec 2026 | 105 | Buffer consumed | 21 days spent on the things that broke in November |
The buffer is the point. Teams that plan to the deadline instead of to day 84 discover in the last fortnight that the marking is stripped by their own image CDN, or that the notice renders on web but not in the mobile webview, and those are code changes, not copy changes.
Evidence That Survives a Change of Staff
Article 50 gives you no evidence format, which means the format is your problem. Ten fields per feature keep a determination reconstructable a year later, by someone who was not in the room:
1. Feature ID and every surface it renders on: Internal identifier and all deployment contexts (web, mobile, API, export). 2. Lane claimed: 50(1), (2), (3), (4) — or "out of scope" with the reason. 3. Role determination: The person who made it, the date, and the reasoning. 4. Notice text verbatim: With a version number and all translations. 5. Placement and trigger point: Which screen, which event, before or after first input. 6. Accessibility handling: Screen-reader announcement, contrast, a non-visual channel for voice. 7. Marking method and payload version: Per output type (e.g., HTML meta tag for images, JSON-LD for text). 8. Model or vendor version in force: At the time of the determination. 9. Dated verification that the notice actually rendered in production: Not a screenshot in Slack; a production report. 10. Change triggers that re-open the determination: Model swap, new output type, new market.
The common failure is not missing evidence. It is evidence that exists as a screenshot in a Slack thread plus a staging URL that no longer resolves, produced by an engineer who left in April. Field 9 is the one most often skipped and most often needed: a claim that a notice exists is weaker than a dated record that it rendered.
DiscloseKit does the mechanical part of this — a deterministic checker that maps features to the four lanes with no model in the compliance path, a disclosure widget, a verification run, and an append-only evidence log. What it does not do, and what no tool can do, is settle an ambiguous provider/deployer question for you or certify the outcome. If you are building the notice layer yourself, the implementation detail is in Article 50 Disclosure Widget Embed; the documentation side is in AI transparency statement template: what to document.
Three Questions Worth Paying a Lawyer For
Does Fine-Tuning and Rebranding Make You the Provider?
You have changed the system's behaviour and put your name on it. Where the answer flips the role, it flips which paragraphs you owe, and the reasoning depends on facts a checklist cannot see. This is a fact-specific determination that benefits from counsel's input before the feature ships.
Is Your Published Text "To Inform the Public on Matters of Public Interest"?
A security advisory, a health explainer, a comment on pending legislation — the line between marketing copy and public-interest information is exactly where the text limb of 50(4) bites, and it is not drawn by your content calendar. The distinction determines whether you owe a 50(4) disclosure on top of any 50(2) marking.
Does Your Employee-Facing Tool Trigger Article 50(1)?
Staff are natural persons. An internal assistant does not leave the interaction lane simply because it never faces a customer; the question is whether the deployment involves direct interaction, and works councils tend to ask it before regulators do. The answer has both compliance and employment-law dimensions.
None of the three is settled by a table, including the one above. All three get more expensive to answer the longer a feature ships without a written determination behind it.
Frequently Asked Questions
Which Article 50 duties bind the provider, and which bind the deployer?
Two duties sit with the provider: the interaction notice under paragraph 1 for systems intended to interact directly with natural persons, and machine-readable marking of synthetic audio, image, video or text under paragraph 2. Two sit with the deployer: the notice to persons exposed to emotion recognition or biometric categorisation under paragraph 3, and the disclosure of deepfakes and AI-generated public-interest text under paragraph 4. One company can hold both roles for different features of the same product, so the routing has to run per feature.
When do the Article 50 transparency obligations apply?
All four lanes apply as of 2 August 2026. A limited transition that may extend provider-side machine-readable marking to 2 December 2026 for eligible systems has been proposed by the European Commission but is not yet adopted law; verify its status and eligibility before planning around it, and note that even as proposed it does not move the 2 August date for the interaction notice or the deployer disclosures.
Is machine-readable marking proof of provenance?
No. HTML attributes, JSON-LD blocks, embedded metadata and response headers are advisory metadata. They are not signed provenance and not a C2PA certification, and they do not survive a screenshot, a re-encode or a copy-paste through a CMS that strips unknown fields. The Act asks for marking that is machine-readable and detectable as artificially generated, not for cryptographic proof.
Does an employee-only internal assistant fall outside Article 50(1)?
Not automatically. Staff are natural persons, so an internal assistant does not leave the interaction lane simply because it never faces a customer; the question is whether the deployment involves direct interaction with people. That determination has both compliance and employment-law dimensions and is worth a written decision, with counsel's input where it is close.
