EU AI Act Article 50 Chatbot and Deepfake Labels

EU AI Act Article 50 requires chatbot notices, deepfake disclosures, and other measures from August 2, 2026. Machine-readable labels and human-perceivable disclosures are separate requirements, and some obligations for existing systems are subject to a grace period.

Article 50 of the EU AI Act applies from August 2, 2026. Disclosures for chatbots and deepfakes are central. Machine-readable marking of generated content is also required. However, the responsible party and the exceptions and transition periods differ by obligation.

The dates and figures in this article are based on the Commission’s official guidance from July and August 2026.

What Does Article 50 Require?

Article 50 sets out transparency rules requiring disclosure of AI use. Not every obligation applies to every AI system. The applicable provision depends on the system’s function and the purpose of the content.

Applicable situation Primary responsible party Required action
AI that interacts directly with people Provider Design it to disclose that the person is interacting with AI
AI that generates audio, images, video, or text Provider Ensure machine-readable marking and detectability of outputs
Emotion recognition or biometric categorisation system Deployer Inform affected persons that the system is operating
Deepfake or public-interest text subject to disclosure Deployer Disclose that the content was generated or manipulated by AI

The Commission published interpretive guidelines on July 20, 2026. In an announcement on July 31 of the same year, it reaffirmed that the rules would apply from August 2. This date does not apply uniformly to every provision of the AI Act. Commission enforcement announcement

Comparing the Responsibilities of Providers and Deployers

Responsibility is divided according to the role actually performed, rather than the company’s industry. A provider is an entity that develops an AI system or has one developed. It places the system on the market or puts it into service under its own name or trademark. A deployer is an entity that uses an AI system under its authority.

Category Provider Deployer
Statutory term provider deployer
Typical role Provides an AI system under its own name Uses AI to produce content or perform work
Core obligation Design that enables disclosure and technical marking Disclosure appropriate to the context of use and exposure
Basis for determination Responsibility for development, market placement, or putting into service Authority over the use of the system

In this article, “deployer” means deployer. It is a different concept from a distributor involved in sales and distribution. A single organisation may act as both provider and deployer. The definitions are based on Article 3 of the AI Act.

Businesses outside the EU may also fall within its scope. This includes cases where an AI system is provided in the EU market. It also applies where the system’s output is used in the EU. Being based in South Korea does not, by itself, exclude a business.

Deployer obligations do not apply to purely personal, non-professional use. Business or professional activities are distinct from this exception. Article 50 is not exempted merely because a system is free or open source. Article 2 of the AI Act

When Must a Chatbot Disclose That It Is AI?

AI that directly engages in conversation must provide disclosure no later than the first interaction. This may include not only chatbots but also conversational AI agents and avatars. The disclosure must be clearly distinguishable on screen or through audio.

The Commission’s guidelines assess the following conditions together:

Machine-to-machine communication that no person sees is distinct from this disclosure obligation. Analytical functions operating in the background also do not constitute direct conversation. Whether the obligation applies is not determined merely by whether the system is a simple automated response tool.

A separate disclosure may not be required if it is obvious that the system is AI. The benchmark is a reasonably well-informed, observant, and circumspect ordinary user. The Commission explains that this exception should be interpreted narrowly. Official Article 50 FAQ

The Difference Between Machine-Readable Marking and On-Screen Labels

Machine-readable marking helps software detect whether content was generated or manipulated by AI. A human-readable on-screen label directly informs users of that fact. The two methods have different purposes and responsible parties.

Comparison Machine-readable marking Human-perceivable disclosure
Main provision Article 50(2) Article 50(4)
Primary responsible party Provider of a generative AI system Deployer using the relevant content
Scope Synthetic audio, images, video, and text Deepfakes and certain public-interest text
Core requirement Marking and detection must be technically possible The information must be perceivable without a separate tool
Substitutability Does not automatically replace human-facing disclosure Does not automatically replace technical marking

The provider’s technology must be robust and reliable to the extent technically feasible. Interoperability with other systems must also be considered. Limitations specific to the type of content and implementation costs are considered as well.

Merely saving something as a JSON file does not satisfy this obligation. A machine’s ability to read a file is different from its ability to detect AI provenance. This distinction follows from the purpose of marking under Article 50. Article 50 of the AI Act

Deepfake Labelling Criteria

A deepfake is AI-generated or manipulated content made to appear authentic. The relevant formats are images, audio, and video. It may involve not only people but also objects, places, entities, or events.

The key considerations are resemblance to the original subject and the possibility of misleading someone about authenticity. Accordingly, not every AI-generated image is automatically a deepfake. Conversely, content is not excluded merely because it does not involve face swapping. The definition is explained in the Commission’s transparency summary.

For deepfakes subject to disclosure, people must be able to recognise the use of AI when they first encounter the content. The method of disclosure may be adjusted for artistic, satirical, or fictional works. In such cases, disclosure may be provided in a way that does not hinder the enjoyment of the work. The disclosure obligation does not disappear entirely merely because the content is an artistic work.

The labelling icons provided by the EU are optional. Use of an icon does not, by itself, guarantee legal compliance. The disclosure must also satisfy accessibility requirements. EU labelling icon guidance

The information shall conform to the applicable accessibility requirements.

— EU AI Act Article 50(5)

This wording expressly states the accessibility requirements applicable to the provision of information. Whether a small icon alone conveys the meaning must be assessed separately. For audio content, consideration must also be given to how listeners perceive the disclosure.

Is Public-Interest Text Exempt If Reviewed by a Person?

An exception to disclosure may apply where there is substantive human review and editorial responsibility. It applies to text published to inform the public about matters of public interest. The deployer’s disclosure obligation does not apply to every AI-written document.

The exception requires the following elements together:

A spell check alone does not constitute substantive review. Human review is a process that assesses the validity of the content. Editorial control involves the authority to approve, revise, or reject the content.

This exception concerns disclosure of public-interest text. It does not also exempt the provider from the machine-readable marking obligation. Nor does the same exception automatically apply to a deepfake reviewed by a person. Official FAQ explanation of editorial review

Must Emotion Recognition and Biometric Categorisation Also Be Disclosed?

Deployers must inform affected persons that the relevant system is operating. This obligation is separate from chatbot disclosures or the marking of generated content. Applicable data protection rules also apply to the processing of personal data.

Merely providing disclosure does not make use of the system permissible. Other prohibitions or requirements for high-risk AI may apply separately. Article 50 does not eliminate other regulatory obligations. Commission guidance on scope

Summary by Condition

Exceptions must be assessed only within the scope of the relevant obligation. Even for the same content, the conclusions for providers and deployers may differ. The following table compares the official rules by situation.

Condition or example Key point in determining applicability
AI assisting with standard editing Consider the exception to the machine-readable marking obligation under paragraph 2
Processing that does not substantially alter input data or its semantics Consider the exception conditions under paragraph 2
Substantive review of public-interest text with editorial responsibility An exception to the deployer’s text disclosure obligation may apply
AI-generated public-interest text published without review Consider the deployer’s disclosure obligation
Deepfake included in an artistic or satirical work Disclosure may be provided in a way that does not hinder enjoyment of the work
Use for lawfully authorised crime-prevention or law-enforcement purposes Verify the purpose and safeguard requirements for each provision

Merely claiming that a system is used for crime-prevention or law-enforcement purposes does not establish an exception. The use must be legally authorised and satisfy the conditions of the relevant provision. Public-facing AI through which citizens report crimes requires particular caution. Paragraph 1 excludes this case from the law-enforcement exception. Exceptions by obligation under Article 50

Common Mistakes About the Application Date and Transition Period

The transition period until December 2026 is not a transition period for all of Article 50. It is limited to specified systems and obligations. The question of retroactive labelling for existing content must also be considered separately.

Category Application date or treatment
General application of Article 50 August 2, 2026
Paragraph 2 obligations for systems placed on the market before August 2, 2026 Compliance required from December 2, 2026
Chatbot disclosures and deployers’ deepfake disclosures The paragraph 2 transition period above does not automatically apply
Content generated before August 2, 2026 The Commission FAQ explains that there is no retroactive labelling obligation

The date a system was placed on the market and the date content was generated are different assessment criteria. New content is not entirely excluded merely because it was produced by an existing system. The schedule is based on the official FAQ explanation of application dates and transition periods.

Labels Disappearing During HTML, JSON, and RSS Republishing

When publishing in multiple formats, the label should be checked across each exposure path. Whether a label on a webpage remains in a downloaded file is a separate issue. This section is an operational analysis combining disclosure obligations with guidance on resharing.

Publication channel What to check
HTML page Is the disclosure perceptible when the content is first viewed?
TXT or Markdown Does the necessary disclosure remain when separated from the page?
RSS/XML Is the disclosure conveyed when the feed content is read independently?
JSON or JSON-LD Is the AI-related information conveyed to users during redisplay?
Image or video download Does the label remain after downloading and resharing?

This does not mean that the law specifies a particular JSON key name. Nor can it be assumed that a data structure alone satisfies the disclosure obligation. The key issue is how content subject to disclosure is presented to people.

The EU icon guidance addresses visibility during resharing and downloading. Verification by publication channel is therefore a useful operational check. This is distinct from an independent obligation to attach the same label to every data file. EU icon placement guidance

The Difference Between Guidelines and a Code of Practice

Guidelines explain the scope of application, while a code of practice helps with implementation methods. The legal basis for the obligations is the AI Act. Participation in a code of practice is voluntary.

Document Primary role Points to note
AI Act Legal basis for obligations and exceptions Check application dates and amendments
Article 50 guidelines Interpretation of concepts, scope, and exceptions Review against the factual circumstances of the service
Code of Practice on Transparency of AI-Generated Content Practical implementation of marking, detection, and disclosure After signing, the relevant measures must actually be implemented

Businesses that do not sign the code must still comply with their legal obligations. They may demonstrate that measures implemented through other methods are appropriate. This code of practice is distinct from the code of practice for GPAI models. The former mainly addresses the marking of outputs. Code of Practice on Transparency of AI-Generated Content

Enforcement Authorities and Official Reporting and Complaint Channels

The reporting channel depends on the authority supervising the system at issue. National competent authorities are responsible for general AI systems. The AI Office is responsible for systems within its statutory jurisdiction. The EDPS is involved with systems used by EU institutions.

Situation Official channel to check
System supervised by a Member State authority The relevant national market surveillance authority
Suspected violation involving a system under AI Office jurisdiction AI Act Complaint Tool
Information about a violation learned through a work-related relationship AI Act Whistleblower Tool
Related complaint by a provider integrating an external GPAI model GPAI complaint channel for downstream providers

Reporting channels can be distinguished in the following order:

  1. Determine whether the subject at issue is an AI system or a GPAI model.
  2. Check jurisdiction in the Commission’s guidance on the scope of supervision.
  3. Proceed to the complaint or reporting channel designated by the relevant authority.

Relevant corporate violations may result in substantial financial penalties. The Commission states that the maximum may be up to €15 million. Another benchmark is 3% of worldwide annual turnover in the preceding financial year. For ordinary companies, the higher of the two amounts is the maximum.

The actual penalty is determined according to factors including the nature, gravity, and duration of the infringement. Separate proportionality considerations apply to SMEs and others. Article 50 violations are not subject to a uniform fixed penalty. Enforcement framework and official reporting channels

Frequently Asked Questions

Does All AI-Generated Content Need a Visible Label?

The deployer’s disclosure obligation does not apply uniformly to all generated content. Deepfakes and certain public-interest text are the main categories covered. The provider’s machine-readable marking obligation must be assessed separately.

Must a Chatbot Repeat the Disclosure Every Time It Responds?

Under Article 50, disclosure must be provided no later than the first interaction. The rule does not require the same wording to be repeated in every sentence. However, a first-time user must be able to perceive it clearly.

Does an AI-Written Article Reviewed by a Person Need No Label?

The assessment does not end with substantive review or editorial control alone. There must also be an entity that holds editorial responsibility for the publication. It is difficult to apply this exception based on a spell check alone.

Is a Satirical Video Exempt from Deepfake Labelling?

Satire does not provide a complete exemption by itself. If the content qualifies as a deepfake, the method of disclosure may be adjusted. A method that does not hinder the display or enjoyment of the work is permitted.

Does Using an EU Icon Guarantee Compliance?

Use of an icon alone does not guarantee legal compliance. Its use is optional. The timing, perceptibility, and accessibility of the label must also be assessed.

Are All Obligations Deferred Until December 2026?

The transition period is limited to the Article 50(2) obligations for existing systems. Those systems must comply from December 2, 2026. It is not a blanket transition period for chatbot disclosures and deepfake disclosures.

Does an AI Label Mean the Content Is Factual?

An AI label provides information about whether content was generated or manipulated. It does not certify fact-checking or copyright permission. The accuracy and legality of the content must be assessed separately.

FAQ

When does Article 50 of the EU AI Act become applicable?

In principle, it applies from August 2, 2026. The labeling and detection obligations under paragraph 2 are an exception for systems released earlier. Those obligations must be complied with from December 2, 2026.

Can Korean companies also be subject to Article 50?

They may be subject to it if they provide AI systems in the EU market. It is also relevant if the systems' outputs are used in the EU. Being located in Korea alone does not exclude them from its application.

Are machine-readable markings and human-readable labels the same thing?

They are methods for fulfilling different obligations. Machine-readable markings facilitate the technical detection of whether content was AI-generated or manipulated. Disclosure to people enables users to recognize that fact.

Are all AI images deepfakes?

Not all AI images are deepfakes. Resemblance to a real subject and the potential to mislead people about authenticity are factors in the assessment. Content depicting objects, places, or events, as well as people, may also be relevant.

Does merely having a person check the spelling in an AI-generated article qualify for a disclosure exemption?

A spelling check alone does not constitute substantive review. Human review of the content or editorial control is required. There must also be an entity that assumes editorial responsibility for the publication.

Does including JSON-LD satisfy the machine-readable marking obligation?

The use of JSON-LD alone does not determine whether the obligation is satisfied. It must be possible to indicate and detect whether content was AI-generated or manipulated. The data format and the legal marking requirements must be distinguished.

Must deepfakes created for artistic or satirical purposes also be disclosed?

They are not fully exempt merely because they are intended for artistic or satirical purposes. Adjustments to the method of disclosure are permitted for such works. The disclosure may be made in an appropriate manner that does not interfere with the enjoyment of the work.

Is the EU disclosure icon mandatory?

Use of the EU icon is optional. The disclosure obligation itself is not optional. Merely displaying the icon does not guarantee compliance.

Is joining the Code of Practice on transparency of generated content mandatory?

Joining the Code of Practice is voluntary. Businesses that do not join must still comply with the obligations under the AI Act. They may demonstrate compliance by other appropriate means.

Should all suspected violations of Article 50 be reported to the AI Office?

The reporting channel varies depending on the system's supervisory authority. The AI Office complaint tool is the channel for systems under its jurisdiction. For other systems, the competent national authority of the Member State must be identified.

Sources

Images

Editor reviewing footage of a female presenter on a video editing monitor
Editor reviewing footage of a female presenter on a video editing monitor
Woman editing video on a monitor displaying AI and chatbot icons in a projection room
Woman editing video on a monitor displaying AI and chatbot icons in a projection room