Article 50 applied on 2 August 2026 and attaches to how a system interacts with people, not to its risk tier. Two duties sit with providers, two with deployers. Here's which is which, and a checklist you can run this week.
Article 50 is the part of the EU AI Act most likely to apply to an organisation that has concluded the Act does not apply to it. It does not depend on a high-risk classification. It attaches to four specific interactions, and it applied on 2 August 2026, unaffected by the Digital Omnibus deferral that moved the high-risk deadlines to December 2027.
The four duties, and who carries each
The split between provider and deployer matters more here than almost anywhere else in the Act, because two of the four duties are yours only if you are the provider.
50(1) - Telling people they are dealing with AI (provider)
Providers must design interactive systems so that people are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person given the circumstances. A support assistant on a pricing page needs the disclosure. There is a carve-out for systems authorised by law to detect, prevent or investigate criminal offences, subject to safeguards.
50(2) - Marking synthetic content (provider)
Providers of systems that generate synthetic audio, image, video or text must mark the output as artificially generated or manipulated in a machine-readable format. Article 50(2) sets the standard for that marking in its own words: 'effective, interoperable, robust and reliable as far as this is technically feasible'. Assistive editing tools that do not substantially alter the input data sit outside this.
Systems already on the market before 2 August 2026 have until December 2026 to meet the 50(2) machine-readable marking requirement. Anything placed on the market from 2 August 2026 had to comply on day one. Treat the December date as month-precision until you have checked the day against the Official Journal text.
50(3) - Emotion recognition and biometric categorisation (deployer)
Deployers of an emotion recognition system or a biometric categorisation system must inform the people exposed to it, and process any personal data in line with data protection law. This one reaches further than teams expect. Sentiment scoring over recorded support calls, engagement or attention scoring in a video platform, and biometric categorisation in access control all sit here, and none of them feel like 'deploying an AI system' when they arrive as a feature of something you already own.
50(4) - Deepfakes (deployer)
Deployers who generate or manipulate image, audio or video content that appreciably resembles real people, objects, places or events must disclose that it is artificially generated or manipulated. A marketing team using an AI-generated presenter or a cloned voice is a deployer for this purpose. Narrower carve-outs apply to evidently artistic, creative or satirical work, and to AI-generated text published to inform the public where a person holds editorial responsibility.
How the disclosure has to be made
Article 50(5) sets the standard for all four: the information must be provided clearly and distinguishably, at the latest at the time of the first interaction or exposure, and it must meet applicable accessibility requirements. A disclosure that only appears in a terms page does not meet 'at the time of the first interaction'.
A checklist you can run this week
- 1List every system, feature and integration that talks to people, generates content, or scores people from audio, video or biometric input. Include features switched on inside tools you already pay for.
- 2For each one, decide whether you are the provider or the deployer, and write the reason down. Article 25 is what settles it where you have rebranded or modified something.
- 3For assistants and chatbots, confirm the AI disclosure appears at first interaction, not further down the conversation and not only in the footer.
- 4For anything doing sentiment, emotion or biometric categorisation, confirm the people exposed to it are informed. This is your duty as deployer and no vendor can discharge it for you.
- 5For marketing and comms output, identify any synthetic presenter, cloned voice, or photorealistic image of a real-looking person or place, and add the disclosure.
- 6For generative systems you provide, check the machine-readable marking, and check the December 2026 transitional date if the system predates 2 August 2026.
- 7Record the decision, the disclosure wording, and the date for each system, so the position is evidenced rather than remembered.
Where this usually goes wrong
- Assuming Article 50 followed the high-risk deferral. It didn't, and the two dates are ten months apart.
- Assuming the vendor's disclosure covers you. 50(3) and 50(4) are deployer duties and sit with you regardless of what the provider does.
- Reading 'obvious' generously. The test is what a reasonably well-informed person would take from the circumstances, not what your team knows about the system.
- Missing sentiment and emotion scoring, which usually arrives as a feature of a support or meeting tool rather than as a purchase anyone recorded.
- Publishing synthetic imagery of real-looking people in campaign work without a disclosure, on the basis that it is clearly an advert.
This is a description of the obligations, not legal advice. The carve-outs in Article 50 are narrower than the summaries above can convey, and several of them turn on facts specific to your deployment.
Sources & references
- Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (AI Act) - EUR-Lex
- Regulation (EU) 2026/1744 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 (Digital Omnibus on AI) - EUR-Lex
- Regulation (EU) 2024/1689 - consolidated text as at 27 July 2026 - EUR-Lex
- AI Act - regulatory framework for artificial intelligence - European Commission


