The AI Act’s transparency chapter answers a simple question: when must people be told that AI is in the room? Article 50 sets four disclosure duties for systems that are not high-risk but still shape what people believe or reveal: chatbots, generative models, emotion recognition, and deepfakes. The duties apply from 2 August 2026, with fines up to EUR 15 million or 3% of global turnover.
| Regulation | AI Act (2024/1689), Article 50 |
|---|---|
| Applies from | 2 August 2026 |
| Max penalty | EUR 15M or 3% of global turnover (Art. 99(4)) |
| Enforcing authority | EU AI Office, national market surveillance authorities |
| Official text | EUR-Lex CELEX 32024R1689 |
The four disclosure duties
Chatbots and conversational AI. People interacting with an AI system must be informed of that fact, unless it is obvious from the circumstances. The safe implementation is an unambiguous statement at the start of the interaction; a bot name with a robot emoji is a design choice, not a legal disclosure.
Machine-readable marking of synthetic content. Providers of generative systems must ensure outputs are marked as artificially generated or manipulated in a machine-readable, detectable way, so far as technically feasible. This is the provision pushing watermarking and content-provenance standards such as C2PA into production; the statute asks for marking that is effective, interoperable, and reliable to the extent the state of the art allows.
Emotion recognition and biometric categorization. Where such systems are lawful at all (workplaces and schools are largely off-limits under Article 5), the people exposed to them must be informed, and the personal data processing must independently satisfy GDPR, which for these systems usually means Article 9 special category analysis.
Deepfakes and public-interest text. Deployers must disclose that deepfake content was artificially generated or manipulated. AI-generated text published to inform the public on matters of public interest must be disclosed as such, unless a human exercised editorial control and someone holds responsibility for the publication, which is the carve-out newsroom workflows rely on.
Implementing without waiting
The duties reward early adoption because they are product features, not paperwork. Add the interaction disclosure to conversational interfaces now; retrofit costs nothing. Choose generation vendors that already emit provenance metadata. Build the deepfake-labeling decision into content workflows rather than reviewing case by case. And where AI features process personal data, keep the GDPR notices current in parallel, since Article 50 supplements rather than replaces them.
For the wider regime these duties sit inside, see the AI Act and GDPR overview; for the decisions the transparency rules often accompany, the automated decision-making guide. If AI chat or personalization runs on your public site, a free scan shows what visitor data those components send and to whom.