The European Union’s AI transparency rules are no longer a future concern. Since 2 August 2026, Article 50 of the EU AI Act has required certain providers and professional users of AI systems to inform people when they are interacting with AI, to make synthetic outputs detectable, and to clearly disclose specific types of AI-generated or manipulated content.
For businesses, however, the practical question is not simply, “Was AI used?” The correct questions are: What kind of AI system is involved? Is the company the provider or the deployer? What type of content was produced? Is the content a deepfake or a publication on a matter of public interest? Was there meaningful human review and editorial responsibility?
This distinction matters because the EU AI Act does not create a universal rule requiring every AI-assisted email, product description, advertisement, or blog post to carry the same label. It establishes targeted duties for defined actors and use cases. A company that treats every use of AI as legally identical may create unnecessary friction. A company that assumes no disclosure is required may face regulatory, contractual, and reputational risk.
This guide explains the content-labeling rules that matter to businesses in 2026, the most important exceptions, the penalties for non-compliance, and the operational steps needed to build a defensible AI transparency process.
Key takeaway: Article 50 is now applicable. Providers generally carry the technical marking duties, while deployers carry visible disclosure duties for deepfakes, certain public-interest text, emotion recognition, and biometric categorisation. Voluntary transparency can go further than the legal minimum, but it should never be confused with a formal guarantee of compliance.
The EU AI Act entered into force on 1 August 2024 and has applied in stages. Article 50’s transparency obligations became applicable on 2 August 2026. On that date, the European Commission’s AI Office and national authorities also began exercising enforcement powers over the relevant provisions.
The transparency regime addresses a basic problem of the generative AI era: people increasingly encounter chatbots, synthetic voices, altered images, generated video, and machine-written publications without being able to tell whether they are dealing with a person or authentic media. Article 50 responds with four main categories of transparency obligation:
The Commission published final Article 50 guidelines in July 2026 and approved a voluntary Code of Practice on Transparency of AI-generated Content. The guidelines explain the scope of the law. The Code offers a recognised route for demonstrating compliance with the marking and labelling obligations, but signing it is voluntary. Article 50 itself is not voluntary.
Many compliance mistakes begin with the assumption that every company using AI has the same duties. The AI Act separates responsibilities across the value chain.
A provider is a person or organisation that develops an AI system, or has one developed, and places it on the EU market or puts it into service under its own name or trademark. A provider can be established inside or outside the EU. The rules may also apply to a provider outside the Union when the output of its system is used in the EU.
For content transparency, providers have the central technical responsibilities. They must design directly interactive systems so that users are informed they are interacting with AI. Providers of generative systems must also implement machine-readable ways to identify synthetic or manipulated outputs.
A software company selling a white-label AI chatbot under its own brand may therefore be a provider. A business that substantially modifies and rebrands a third-party system may also need to assess whether it has moved beyond being a customer and assumed provider responsibilities.
A deployer is a person or organisation using an AI system under its authority in a professional context. The law excludes purely personal, non-professional activity. An individual who regularly uses AI for economic gain, trade, freelance work, or another professional activity may nevertheless qualify as a deployer.
For a company, the legal entity is generally the deployer when employees use AI under its instructions and control. Individual designers, marketers, or journalists are not usually separate deployers in that situation. Contractors and freelancers operating on behalf of the company do not automatically remove the company’s responsibility.
Most agencies, online retailers, publishers, professional creators, and ordinary businesses using third-party generative AI tools will begin their analysis as deployers. Their visible labelling duties are narrower than the provider’s technical marking duty, but they are still significant.
Consider an AI image generator. The company offering the generator is responsible for designing the system so that qualifying outputs carry appropriate machine-readable marking. An agency using that generator for a campaign is responsible for deciding whether the published image constitutes a deepfake requiring a clear label. The client publishing the final asset may also have deployer responsibilities depending on who controls the use.
One content item can therefore involve several organisations and several duties. Contracts should identify who selects the tool, who reviews the output, who publishes it, who applies the visible label, and who keeps the evidence.
Providers of systems designed for genuine, direct, two-way interaction with natural persons must ensure that users are told they are interacting with AI. Common examples include customer-service chatbots, AI agents, conversational avatars, and voice assistants.
The notice should appear from the start of the first interaction, in a clear and distinguishable way, and it must respect accessibility requirements. A disclosure hidden at the bottom of a privacy policy is unlikely to serve the same purpose as a notice placed inside the interface before or as the conversation begins.
The duty does not apply when it is obvious to a reasonably well-informed and observant person that the interaction is with AI. The Commission advises interpreting this exception restrictively. A robot illustration or a product name containing the letters “AI” may not be enough if the overall experience is designed to resemble a human agent.
A practical notice can be concise: “You are chatting with an AI assistant. Responses may be generated automatically.” The disclosure can link to more information about limitations, human escalation, and data use, but the first-layer message should remain understandable.
Providers of AI systems that generate synthetic text, audio, images, or video must design their systems so that qualifying output is marked in a machine-readable format and can be detected as artificially generated or manipulated. The technical approach must be effective, interoperable, robust, and reliable as far as technically feasible, taking account of the type of content, implementation cost, and the state of the art.
This is not the same as placing the words “AI-generated” under a picture. Machine-readable marking is designed for tools and platforms to detect the origin or manipulation of content. Visible labelling is designed for people. In some workflows, both layers may be required.
The guidelines exclude or limit some outputs. Examples include source code, short sequences of numbers or symbols, machine-to-machine outputs with no human exposure, and intermediate material used in closed-loop industrial or production environments. There is also an exception when AI performs only an assistive function for standard editing or does not substantially alter the input data or its meaning.
Standard editing should be interpreted carefully. Routine correction, formatting, enhancement, or similar assistance may remain outside the marking duty when it does not materially change the semantics of the input. Generating a new scene, replacing a person’s face, rewriting an argument, or inventing factual material is different from correcting spelling or adjusting basic presentation.
Following the 2026 amendment, systems placed on the market before 2 August 2026 receive a limited grace period for the Article 50(2) marking and detection obligation until 2 December 2026. That grace period does not postpone all Article 50 duties. Businesses should record the placement date and version of each generative system on which they rely rather than assuming every established tool benefits from the exception.
Deployers of emotion-recognition and biometric-categorisation systems must inform the natural persons exposed to those systems. The obligation can apply whether analysis occurs in real time or later.
This rule can affect retailers measuring apparent audience reactions, event organisers analysing attendees, employers using behavioural analytics, or digital platforms categorising people through biometric data. Other AI Act restrictions, data-protection rules, and employment laws may also apply. A transparency notice alone does not make an otherwise prohibited or unlawful use permissible.
Businesses should identify these systems during procurement. Product descriptions sometimes use softer terms such as “sentiment detection,” “engagement intelligence,” or “audience analytics.” The compliance team should examine what the system actually infers and from which data, rather than relying only on marketing language.
Deployers have the most visible content-labelling duties in two areas: deepfakes and certain AI-generated or manipulated text on matters of public interest.
A deepfake is AI-generated or manipulated image, audio, or video content that resembles an existing or plausibly existing person, object, place, entity, or event and would falsely appear authentic or truthful. The assessment depends on resemblance, message, context, audience, and the likelihood that viewers or listeners will take the content as real.
The disclosure must reach a person no later than their first exposure. It must be clear, distinguishable, understandable, and perceivable without requiring a special technical tool. Relying only on metadata or an invisible watermark is not enough to satisfy this deployer duty.
Artistic, creative, satirical, fictional, or analogous works receive a more flexible treatment: the disclosure may be made in an appropriate way that does not hamper display or enjoyment. Context remains crucial. A clearly fictional visual effect in a fantasy film is different from a realistic video of a chief executive announcing a fabricated acquisition.
The second category covers AI-generated or manipulated text that is published with the purpose of informing the public on a matter of public interest. Relevant topics may include politics, democratic processes, public administration, justice, law enforcement, fundamental rights, security, public health, environmental protection, consumer safety, finance, science, culture, or other developments that are legitimately part of public debate.
Three elements must be present: the text is published, it informs the public, and it concerns a matter of public interest. An internal draft that never leaves the company is not “published.” A routine product description is not automatically a public-interest publication. A public article about the safety of a consumer product, an election, a disease outbreak, or environmental contamination is much more likely to qualify.
No. The EU AI Act does not impose one blanket visible-label rule on every piece of business content created with some AI assistance.
For text on matters of public interest, a deployer does not have to apply the Article 50(4) label when the publication has undergone meaningful human review or editorial control and a natural or legal person holds editorial responsibility for publication. This is an important exemption for professional publishing workflows.
Meaningful review is more than running a spell-checker, approving a layout, or glancing at the finished copy. The Commission describes human review as a deliberate examination of substance by people with relevant knowledge and professional judgement. Editorial control means that a responsible person or entity can approve, change, or reject the substance, fact-check information, and assess source reliability. Editorial responsibility means assuming ultimate legal responsibility for publication, including the review process.
The exemption therefore rewards a real governance process, not a checkbox. A business relying on it should be able to identify the reviewer, show what was checked, retain the source record, document material corrections, and identify the person or entity responsible for publication.
Even where a legal label is not mandatory, voluntary disclosure may still be commercially valuable. Readers, clients, marketplaces, professional bodies, and procurement teams may expect greater transparency than the statutory minimum. A clear “AI-assisted, human-reviewed” statement can communicate human accountability without incorrectly describing the work as fully AI-generated.
An online store offers a conversational assistant that answers product questions and closely imitates a human service agent. The provider must design the system so users are informed that they are interacting with AI, unless this is obvious. The store should confirm where and how the disclosure appears and should not remove it during implementation.
An agency generates a fictional living-room scene for a furniture advertisement. The system provider may have a machine-readable marking duty. Whether the agency or brand must apply a visible deepfake label depends on whether the image resembles an existing or plausibly existing subject or event and would falsely appear authentic. Even if Article 50 does not compel a visible label, voluntary disclosure may support consumer trust.
A company uses a synthetic clone of its chief executive’s voice in a public investor video. Because the audio resembles an existing person and may appear authentic, it is likely to fall within the deepfake definition. A clear disclosure should be perceptible at first exposure; hidden metadata alone is insufficient. Consent, personality rights, financial-market rules, and advertising law may create additional requirements.
A health platform publishes an AI-generated article about vaccine safety without substantive review. The text is published to inform the public on a matter of public interest and should be clearly labelled. If qualified medical and editorial reviewers examine the substance, check evidence, make necessary changes, and the publisher assumes editorial responsibility, the Article 50 text-labelling exemption may apply. The organisation should preserve evidence of that process.
A retailer uses AI to improve wording for a standard product page, after which a merchandiser checks accuracy and approves the copy. The text is not necessarily a publication on a matter of public interest, so the deployer’s Article 50(4) visible-label duty may not apply. The provider’s technical obligations are a separate question, and consumer law still prohibits misleading claims.
A professional writer uses AI to correct spelling, standardise headings, or adjust formatting without materially changing meaning. This may qualify as standard editing rather than generation or substantial manipulation. Businesses should still define the boundary in their own policy, because a tool can move from correction to substantive rewriting in a single prompt.
Article 50(5) requires information to be provided in a clear and distinguishable manner, at the latest at first interaction or exposure, and in a way that meets accessibility requirements. The best implementation depends on the medium.
For a chatbot, place the disclosure in the conversation interface before or beside the first automated response. For an image, use a visible adjacent label or overlay that survives normal sharing. For audio, use an audible disclosure at the beginning and consider a visible label wherever the file is presented. For video, use an on-screen notice early enough to reach the viewer before deception can occur. For public-interest text, place a concise notice near the title, byline, or opening text rather than hiding it in a footer.
Useful label language is direct and neutral:
The final example may be voluntary rather than legally required, depending on the circumstances. It is valuable because it separates AI assistance from AI authorship and identifies human accountability.
Avoid vague phrases such as “enhanced with technology,” “digitally optimised,” or “created with innovative tools.” If an average person cannot understand that AI was involved, the notice is not achieving meaningful transparency.
List every AI system used across marketing, design, customer support, HR, operations, research, product development, and publishing. Record the vendor, system version, launch date, purpose, media type, users, and markets. Include AI features embedded in larger platforms; many organisations miss them because they were activated through an update rather than purchased as a separate tool.
For each system and output, identify the provider, deployer, publisher, reviewer, and responsible legal entity. Analyse whether custom development, white labelling, or substantial modification could turn the organisation into a provider. Put responsibility for disclosure, marking, preservation of metadata, and evidence into vendor and agency contracts.
Create a decision tree for text, image, audio, and video. Ask whether an output is synthetic or materially manipulated, whether it is a deepfake, whether text informs the public on a public-interest matter, whether standard-editing exceptions may apply, and whether humans will encounter the output.
Confirm what marking the provider embeds and whether your production pipeline preserves it through export, resizing, transcoding, editing, content-management systems, social publishing, and distribution. Then independently assess whether a clear human-facing label is required. Never assume that one layer automatically replaces the other.
If relying on the public-interest text exemption, document substantive human review. The record should identify the reviewer, expertise, sources checked, factual changes made, approval date, and responsible publisher. A generic “human checked” field without supporting evidence is weak.
Prepare approved wording and placement rules for each medium and channel. Test colour contrast, screen-reader compatibility, captions, audio notices, mobile layouts, and reposted content. A label that disappears when a video is clipped or an image is downloaded may not remain effective throughout the intended workflow.
Revise the AI use policy, editorial policy, brand guidelines, freelancer agreements, statements of work, platform terms, and procurement questionnaires. Require vendors to explain how machine-readable marking works, what exceptions they rely on, and how updates affect compliance.
Legal teams cannot review every asset. Train marketers, designers, editors, social-media managers, and customer-support owners to recognise deepfakes, public-interest content, standard editing, and meaningful human review. Provide an escalation route for borderline cases.
Keep system records, prompts where appropriate, source files, marking information, review notes, approvals, label versions, screenshots, and publication dates. The purpose is not to retain every keystroke indefinitely, but to demonstrate a reasonable, consistent process.
Periodically check whether labels still appear, metadata remains intact, links work, and downstream platforms have altered the content. Review complaints and near misses. Update the process when the Commission’s guidance, standards, or technology changes.
Article 50 compliance is primarily enforced by national market-surveillance authorities. The AI Office has responsibility for specified systems under its supervision, and the European Data Protection Supervisor oversees systems used by EU institutions.
For companies, violations can lead to fines of up to €15 million or up to 3% of total worldwide annual turnover for the preceding financial year. The rules include proportionality considerations for small and medium-sized enterprises and small mid-cap companies. The precise penalty depends on the circumstances, including the nature, seriousness, and duration of the infringement.
Regulatory fines are only one part of the exposure. Undisclosed synthetic content can trigger consumer-protection claims, advertising complaints, platform enforcement, contractual disputes, intellectual-property problems, privacy investigations, and reputational damage. A technically non-mandatory disclosure can still be the prudent business choice when the audience could otherwise be misled.
Content produced before 2 August 2026 does not have to be labelled retroactively under Article 50, although the Commission encourages voluntary labelling where possible. Organisations should not use that point as a reason to ignore legacy content. High-impact synthetic media may remain risky under other laws and can still undermine trust.
VHC Global distinguishes human-created, AI-generated, and AI-assisted digital work.
Legal compliance answers whether a specific statutory obligation applies. Trust communication answers a broader question: can a visitor quickly understand how digital work was created and who stands behind it?
VHC Global is designed around three creation-method categories:
These categories can help a business communicate distinctions that the law does not always require it to publish. For example, an AI-assisted article that received substantive human review may qualify for the Article 50 public-interest text exemption, yet the publisher may still choose an AI Assisted badge to show its process honestly. A human-created portfolio may use a Human-Created badge to make human effort visible in a market crowded with synthetic work.
A voluntary trust badge should complement, not replace, a legal assessment. It does not remove a provider’s duty to embed machine-readable marking, a deployer’s duty to label a deepfake, or a publisher’s obligation to make required notices clear and accessible. The strongest approach combines legal compliance, technical provenance, documented human review, and simple public communication.
Inventory systems, vendors, media types, teams, and publication channels. Prioritise customer-facing AI interactions, synthetic voice or video, public-interest publishing, and any emotion or biometric tools. Identify content created before and after 2 August 2026.
Map provider and deployer roles, define the deepfake assessment, establish the public-interest text test, and set the standard-editing boundary. Create a review form and nominate editorially responsible people. Ask vendors for documentation on machine-readable marking and preservation.
Deploy chatbot notices, image and video label templates, audio disclosures, and text notices. Update content-management workflows so the correct label is selected before publication. Prevent employees from removing provenance information without a documented reason.
Test across desktop, mobile, social sharing, downloads, and assistive technologies. Train relevant teams with real examples. Sample published content and record defects. Present management with unresolved risks, responsible owners, and target dates.
The Article 50 transparency obligations became applicable on 2 August 2026. A limited grace period until 2 December 2026 applies to the machine-readable marking obligation for certain generative AI systems placed on the market before 2 August 2026. It is not a general delay for all transparency duties.
No. Duties depend on the business’s role and the content. Providers face technical marking and interaction-disclosure obligations. Deployers must disclose emotion recognition, biometric categorisation, deepfakes, and qualifying public-interest text. Other AI content may fall outside Article 50’s visible-label duty, although voluntary disclosure or other laws may still be relevant.
Not automatically. Standard editing and non-substantial assistance may fall outside the provider marking obligation. For public-interest text, substantive human review, editorial control, and editorial responsibility can create an exemption from the deployer’s visible-label duty. Businesses should document the actual workflow rather than rely on a broad “AI-assisted” description.
Not always. Providers may need machine-readable marking that enables detection. Deployers of deepfakes and qualifying public-interest text need a clear human-facing disclosure. Depending on the workflow, both technical marking and visible labelling may be necessary.
Article 50 does not require retroactive labelling of content generated before 2 August 2026, although the Commission encourages voluntary labelling where possible. Other legal and reputational risks can still make disclosure advisable.
No single badge can guarantee compliance across every system and use case. A badge can provide a public trust signal and help communicate the declared creation method, but legal duties may also require technical marking, specific placement, accessibility, documentation, and governance measures.
The EU AI Act changes content transparency from an informal brand preference into an operational responsibility for defined AI systems and use cases. In 2026, businesses need more than a generic AI policy. They need role mapping, content classification, technical provenance, visible-label rules, substantive human review, accessible implementation, and evidence.
The organisations that handle this well will not label everything indiscriminately. They will understand why a disclosure is required, apply it where people need it, and communicate the difference between human-created, AI-generated, and AI-assisted work with precision.
That precision is valuable beyond compliance. As synthetic content becomes easier to create and harder to recognise, clear origin information can become a competitive trust signal. Businesses that can explain who created their work, how AI was involved, and who remains accountable will be better positioned to earn confidence from customers, clients, employees, and partners.
Ready to make your creation process visible? Explore VHC Global’s Verified Human-Created, Verified AI-Generated, and Verified AI Assisted badges at https://vhc.global.
This article provides general information and is not legal advice. Businesses should obtain advice based on their systems, role, markets, and use cases.
Helping real businesses prove they are authentic, transparent, and human-responsible in the age of AI.
Copyright© 2026 Verified Human Created, All rights reserved.