Of the whole EU AI Act, Article 50 is the one most companies breach without realising. Not through negligence: because it isn’t labelled “high risk” and almost everyone assumed the regulation was about something else.
What it requires
Article 50 places transparency duties on AI systems that interact with people or generate content. In practice, four things:
| Situation | What you must do |
|---|---|
| An AI system interacts with a person | Tell them they are interacting with an AI, unless it is obvious |
| You generate synthetic audio, image, video or text | Mark the output as artificially generated, in machine-readable form |
| You detect emotions or perform biometric categorisation | Inform the people exposed to it |
| You generate deepfakes | Disclose that the content has been generated or manipulated |
The nuance most often missed is the machine-readable marking. A visual notice to the user is not sufficient on its own when the requirement is that the output be technically identifiable.
The dates
General application of the Regulation landed on 2 August 2026, and Article 50 with it.
There is one exception with its own deadline: systems generating synthetic content that were already on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2).
If you deployed a chatbot or content generator in 2024 or 2025 and haven’t touched it since, that is your deadline. Weeks, not quarters.
What usually goes wrong
In the reviews we run, the failures repeat:
The notice exists, in the wrong place. A line in the privacy policy informs nobody. The duty is that the person knows while interacting, not that they could find out if they investigated.
The chatbot has a human name and a human sign-off. “Hi, I’m Laura from the support team” is precisely what the rule exists to prevent. You can give an assistant personality without pretending it is a person.
Generated content ships unmarked. Product descriptions, email drafts, catalogue images. If they are published as synthetic content, they are in scope.
Nobody maintains the inventory. You complied on deployment day and six months later there are three new integrations nobody reviewed.
What compliance costs
Very little, and that is the best news in the whole Regulation. For a typical mid-sized company:
- A line of notice when the chat opens and in the assistant’s first message.
- Provenance metadata on generated content you publish.
- A sheet listing your AI systems, their purpose and their owner.
- A quarterly review of that sheet.
That is days of work, not months. The risk is not in the difficulty, it is in never having realised it applied.
A recommendation that goes beyond the rule
Disclosing that an AI is behind the conversation does not hurt conversion: it helps. Users are reasonably good at detecting when something isn’t human, and finding out on their own breeds far more distrust than being told up front.
Complying here is one of the few regulatory duties that pays for itself.