On 2 August 2026, the transparency obligations in Article 50 of the EU AI Act begin to apply. Much of the discussion has centred on labels, but the operational problem begins earlier: an organisation must determine which obligation applies, whether it is acting as a provider or deployer and what facts support the answer.
A disclosure can be written in minutes once those questions have been resolved. Reaching the same conclusion consistently across a chatbot, marketing asset, internal drafting tool and AI-assisted publishing workflow requires marketing, product, legal and compliance teams to work from shared evidence.
This is a narrower question than the broader governance challenge explored in The EU AI Act is moving into company workflows. Article 50 shows how that challenge appears inside an individual review: the applicable requirement depends on the organisation’s role, the system, the output and the circumstances in which it will be used.
Article 50 is several obligations, not one label
Article 50 covers four broad situations. Providers of systems intended to interact directly with people must ensure those people are informed that they are interacting with AI, unless this is already obvious to a reasonably informed, observant and circumspect person in the circumstances.
Providers of systems that generate synthetic audio, image, video or text content must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The duty is qualified by technical feasibility and takes account of factors including implementation costs and the state of the art.
Different duties fall on deployers. Organisations using emotion recognition or biometric categorisation systems must inform the people exposed to them, while deployers of systems that generate or manipulate deepfakes must disclose that the content has been artificially generated or manipulated.
A further deployer obligation covers AI-generated or manipulated text published to inform the public on matters of public interest. It includes an exception where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for publication.
These duties cannot be reduced to an instruction to label everything made with AI. A blanket rule may appear cautious, but it conceals the legal basis for a decision and can leave the organisation unprepared for use cases where disclosure alone does not answer the relevant provider duty.
The guidance clarifies scope without changing the law
The European Commission published its final Article 50 guidelines on 20 July 2026. They explain the Commission’s interpretation of the provision and provide practical examples for providers, deployers and competent authorities, but they do not amend Article 50.
That distinction matters because examples can make an obligation easier to apply without becoming a substitute for the Regulation. Teams still need to identify the relevant paragraph, establish their role and test the facts of the use case against its conditions and exceptions.
The Commission has also published a Code of Practice on Transparency of AI-Generated Content. Adherence is voluntary and can support organisations in demonstrating compliance with the relevant generated-content duties, but it is not a universal safe harbour or conclusive evidence of compliance.
Taken together, the law, guidelines and voluntary code provide several layers of information. The governance task is to keep those layers connected so a reviewer can distinguish a legal requirement from an interpretative example, internal policy choice or technical implementation route.
Transparency decisions belong in the review workflow
Most regulated organisations already review communications before publication. Article 50 becomes manageable when its questions enter that process at the point where teams still know how the content was produced, who will publish it and which system features are involved.
Marketing may know whether AI generated the published asset or merely assisted a draft. Product can explain how a customer-facing feature behaves, legal can interpret the applicable provision and compliance can determine whether the proposed control and evidence meet the organisation’s standard. Separating those perspectives into independent checklists makes it easier for a critical assumption to disappear between them.
The review record should identify the system and output, the organisation’s role, the relevant Article 50 duty, any condition or exception relied on, the disclosure or technical control selected and the person accountable for the decision. It should also record what would trigger reassessment, such as a new model, market, audience, publishing route or level of human review.
This does not require every organisation to build a new compliance platform. It requires the route from facts to conclusion to remain visible, whether the record sits in an existing content workflow, product governance process or structured register.
That evidence matters because similar-looking communications can produce different answers. An internal drafting assistant and a system publishing public-interest text may use the same underlying model, yet their roles, outputs and publication controls are not the same. Reusing a previous conclusion without its factual basis turns precedent into guesswork.
Machine-readable marking makes transparency an information problem
Article 50’s machine-readable marking requirement is directed at providers of systems that generate synthetic content, rather than every organisation that happens to use a generative tool. The distinction is important because a visible notice aimed at a person and a technical mark intended to support detection perform different jobs.
The provision also recognises that technical methods have limits. Providers must make their techniques effective, interoperable, robust and reliable as far as technically feasible, taking account of content characteristics, costs and the generally acknowledged state of the art.
For deployers and downstream content teams, this creates a practical dependency on system information that may sit with a vendor or product owner. Procurement, technical documentation and content review therefore need to connect: a reviewer cannot assess what marking is present, retained or altered if the organisation cannot retrieve reliable information about the system and workflow.
The larger lesson is that transparency information must survive movement between tools and teams. A disclosure added at publication is useful, but it cannot compensate for a process that has lost the system identity, production history, editorial intervention or reasoning that determined the obligation.
Article 50 does not require organisations to maintain a library of previous decisions. Repeated use cases nevertheless make organisational memory valuable, because a well-preserved decision can show which facts mattered without being treated as a permanent answer.
Preparedness will therefore be visible less in the length of an AI policy than in the quality of individual records. An organisation should be able to explain what it decided, which obligation it considered, what evidence supported the decision and when the reasoning must be revisited.
What teams need to know
What changes on 2 August 2026?
Article 50’s transparency obligations begin to apply. They cover specified direct interactions with AI, machine-readable marking of certain synthetic outputs, the use of emotion recognition and biometric categorisation systems, and disclosures for certain deepfakes and public-interest text.
Does every piece of AI-generated content need a visible label?
No. Article 50 creates distinct obligations for particular providers, deployers, systems and outputs, with conditions and exceptions. The relevant duty depends on the organisation’s role, the content and the way the system is used.
What is the difference between a provider and a deployer?
A provider develops an AI system or has one developed and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its authority, except for personal, non-professional activity. An organisation may perform different roles in different use cases.
Did the Commission’s guidelines change Article 50?
No. The guidelines explain the Commission’s interpretation of Article 50 and give practical examples, but they do not amend the Regulation. Organisations should begin with the legal text and use the guidance to support application.
Do smaller organisations need a dedicated Article 50 platform?
Article 50 does not prescribe a particular governance platform. An organisation still needs a proportionate way to identify relevant systems and outputs, assign its provider or deployer role, reach the required decision and retain enough evidence to explain it.