EU Privacy Law EU/EEA

EU AI Act Transparency Rules: Disclosure Duties for Chatbots, Deepfakes, and AI Content

Article 50 of the EU AI Act explained: when users must be told they face an AI system, how AI-generated content must be marked, and the deadlines and fines.

Regulation

Regulation (EU) 2024/1689 (AI Act), Article 50

Max Penalty

EUR 15 million or 3% of global annual turnover for transparency violations

Enforcing Authority

EU AI Office and national market surveillance authorities

Official Source

eur-lex.europa.eu

Executive Summary

  • Article 50 of the AI Act creates four transparency duties: disclose chatbots, mark synthetic content machine-readably, inform people subject to emotion recognition or biometric categorization, and label deepfakes.
  • These duties apply to limited-risk systems generally from 2 August 2026, separate from the high-risk regime.
  • Providers of generative systems must ensure outputs are marked as artificially generated in a machine-readable way, driving adoption of watermarking and provenance standards such as C2PA.
  • Transparency violations are fined up to EUR 15 million or 3% of global turnover (Article 99(4)).
  • GDPR transparency duties run in parallel: if the chatbot or model processes personal data, Articles 13 and 14 notices are still owed.

The AI Act’s transparency chapter answers a simple question: when must people be told that AI is in the room? Article 50 sets four disclosure duties for systems that are not high-risk but still shape what people believe or reveal: chatbots, generative models, emotion recognition, and deepfakes. The duties apply from 2 August 2026, with fines up to EUR 15 million or 3% of global turnover.

RegulationAI Act (2024/1689), Article 50
Applies from2 August 2026
Max penaltyEUR 15M or 3% of global turnover (Art. 99(4))
Enforcing authorityEU AI Office, national market surveillance authorities
Official textEUR-Lex CELEX 32024R1689

The four disclosure duties

Chatbots and conversational AI. People interacting with an AI system must be informed of that fact, unless it is obvious from the circumstances. The safe implementation is an unambiguous statement at the start of the interaction; a bot name with a robot emoji is a design choice, not a legal disclosure.

Machine-readable marking of synthetic content. Providers of generative systems must ensure outputs are marked as artificially generated or manipulated in a machine-readable, detectable way, so far as technically feasible. This is the provision pushing watermarking and content-provenance standards such as C2PA into production; the statute asks for marking that is effective, interoperable, and reliable to the extent the state of the art allows.

Emotion recognition and biometric categorization. Where such systems are lawful at all (workplaces and schools are largely off-limits under Article 5), the people exposed to them must be informed, and the personal data processing must independently satisfy GDPR, which for these systems usually means Article 9 special category analysis.

Deepfakes and public-interest text. Deployers must disclose that deepfake content was artificially generated or manipulated. AI-generated text published to inform the public on matters of public interest must be disclosed as such, unless a human exercised editorial control and someone holds responsibility for the publication, which is the carve-out newsroom workflows rely on.

Implementing without waiting

The duties reward early adoption because they are product features, not paperwork. Add the interaction disclosure to conversational interfaces now; retrofit costs nothing. Choose generation vendors that already emit provenance metadata. Build the deepfake-labeling decision into content workflows rather than reviewing case by case. And where AI features process personal data, keep the GDPR notices current in parallel, since Article 50 supplements rather than replaces them.

For the wider regime these duties sit inside, see the AI Act and GDPR overview; for the decisions the transparency rules often accompany, the automated decision-making guide. If AI chat or personalization runs on your public site, a free scan shows what visitor data those components send and to whom.

Frequently Asked Questions

Do I have to tell users they are talking to a chatbot?

Yes. Article 50(1) requires that people interacting with an AI system be informed they are interacting with AI, unless it is obvious from context to a reasonably informed person. The disclosure must come at the latest at the first interaction.

Does AI-generated content have to be labeled?

Two layers. Providers must mark synthetic audio, image, video, and text outputs as artificially generated in machine-readable form (Article 50(2)). Deployers must additionally disclose deepfakes, and AI-generated text published to inform the public on matters of public interest, unless there was human editorial review with responsibility.

What counts as a deepfake under the AI Act?

AI-generated or manipulated image, audio, or video content that resembles existing persons, objects, places, or events and would falsely appear authentic or truthful (Article 3(60)). Artistic, satirical, and fictional works get lighter treatment: disclosure must not hamper the work's display or enjoyment.

When do the transparency rules start applying?

Article 50 applies from 2 August 2026, along with most of the regulation. The prohibitions took effect earlier, in February 2025, and general-purpose AI model duties in August 2025.

How do these duties interact with GDPR?

They add to it. If the AI system processes personal data, GDPR's own transparency articles still require notice about the processing, and Article 22 rights may apply to automated decisions. Article 50 is about disclosing the AI itself, not the data processing.

Regulatory Crosswalk

GDPR Articles 13/14 and 22DSAISO/IEC 42001

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.