EU AI Act transparency rules take effect for chatbots, deepfakes and AI content
Providers and deployers face separate disclosure, marking and labeling duties under Article 50, with specific requirements for systems used by children and fines of up to €15 million or 3% of worldwide annual turnover
Article 50 of the EU AI Act introduces transparency requirements for interactive systems, generated content, deepfakes and certain biometric AI uses
The European Union’s transparency rules for certain AI systems took effect on August 2, requiring providers and deployers to identify AI interactions and content across the Union.
Article 50 of the EU AI Act divides responsibility between the organizations that provide AI systems and those that deploy them. Its four obligations cover interactive systems such as chatbots and AI agents, machine-readable marking of generated content, notices for emotion recognition and biometric categorization systems, and visible labels for deepfakes and some public-interest text.
The scope includes AI chatbots and conversational agents that interact directly with students, teachers or other users. Notifications must account for children and people with disabilities, while the Commission’s guidance makes clear that placing a reference in terms and conditions will not be enough.
The obligations apply to providers established outside the EU when they place systems on the Union market or their systems’ outputs are used in the Union. However, incidental, unforeseeable or unauthorized downstream use does not automatically bring an overseas provider within scope.
The European Commission published 51 pages of implementation guidance on July 20. The document is non-binding, and only the Court of Justice of the European Union can provide an authoritative interpretation of the legislation.
Who must disclose an AI interaction
Providers are the people, companies, public authorities and other organizations that develop an AI system, or have one developed, and place it on the market or put it into service under their own name or trademark. Their duties sit primarily under the first two parts of Article 50.
Deployers are the organizations or public bodies using an AI system under their authority and deciding how it operates. They carry the duties relating to emotion recognition, biometric categorization, deepfakes and public-interest text. One organization can occupy both roles, including when it develops an interactive AI system in-house and puts it into service under its own name.
Providers of systems that interact directly with people must design them to disclose their artificial nature. The rule covers written, visual, auditory and physical interactions, including voice assistants, conversational agents, social media bots, coding agents and AI agents acting on someone’s behalf.
For agents, the requirement goes further than telling the person instructing the system that it is AI. Where an agent communicates with another person while completing a booking, managing correspondence, making a purchase or carrying out another task, it must also identify its artificial nature and the person on whose behalf it is acting.
Disclosure is not required when the AI interaction is obvious to a reasonably well-informed, observant and circumspect person. But the Commission applies a restrictive reading to that exception. The guidance says it should be confined to situations where there is “almost no doubt left” about the artificial nature of the interaction.
That assessment must account for the intended and foreseeable audience. A professional coding assistant available only to developers may qualify for the exception, while a public-facing chatbot that could be used by children, older people or people with lower AI literacy is less likely to do so.
The notification must appear no later than the first interaction. A chatbot could identify itself in its opening message, while a voice assistant could provide a spoken disclosure at the beginning of a session. Persistent badges, visual symbols and reminders during longer or higher-risk interactions can supplement the initial notice.
A statement buried in terms and conditions, documentation or a separate URL is insufficient on its own. Nor can providers rely solely on labels such as “assistant,” technical references to large language models or machine-readable markings that users cannot see.
Where children may interact with the system, disclosures must be child-friendly, age-appropriate and easy to understand. They must also be accessible to children with disabilities or additional accessibility needs. The guidance recommends simplified wording near the point of interaction and says information can be presented gradually to support retention.
Not every AI-enabled education product falls within this part of Article 50. Systems that provide automated translation, transcription, recommendations, spam filtering or information retrieval without generating or modifying content are among the examples outside the direct-interaction rule. Back-end decision-support systems are also excluded where users see an output but cannot interact with the AI itself.
Students using AI to write homework are treated as acting in a purely personal, non-professional capacity and are excluded from deployer obligations. That exception does not remove the separate responsibilities of the provider supplying the AI system.
Machine-readable marks and visible labels are separate duties
Providers of systems that generate or substantially manipulate text, images, audio or video must ensure that the output is marked in a machine-readable format and detectable as artificially generated or altered.
A machine-readable mark is structured so software can identify and extract it without human intervention. The guidance lists watermarks, metadata, cryptographic techniques, fingerprints and logging methods among the possible approaches.
Marking alone is not sufficient. Providers must also make a corresponding detection method available so people and other organizations can establish whether content came from the system. The result of that detection must be human-readable.
Technical solutions must be effective, interoperable, robust and reliable to the extent that this is technically feasible. Providers can use technology supplied by an upstream model provider or specialist service, but responsibility for meeting the requirement remains with the AI system provider.
The rule does not cover every use of AI in an editing workflow. Grammar correction, spellchecking, minor stylistic polishing, formatting, technical compression, noise reduction and minor image adjustments can qualify as standard editing when they do not change the substance, meaning, style or message.
AI-generated summaries, substantive paraphrasing and rewriting fall on the other side of that line. So do the removal, replacement or insertion of people or objects where this changes the meaning of an image or video, cloned speech in a specific person’s voice and realistic video depicting events that did not happen.
Some outputs fall outside the marking requirement entirely. These include short sequences of numbers, symbols or letters, source code, machine-to-machine communications that are not exposed to people, and intermediate material produced inside closed development workflows. Only the final output from those workflows may need to be marked.
Deployers have an additional, human-facing responsibility when generated or manipulated images, audio or video constitute deepfakes. The AI origin must be disclosed through a visible or audible label that people can understand without using a detection tool. A hidden machine-readable mark added by the provider does not satisfy this deployer obligation.
The guidance defines a deepfake as AI-generated or manipulated content that resembles an existing or realistically plausible person, object, place, entity or event and could falsely appear authentic or truthful. An intention to deceive is not required.
Artistic, creative, satirical and fictional works remain subject to disclosure, although the label can be presented in a way that does not disrupt the display or enjoyment of the work. The lighter approach only applies when the nature of the content is evident to the audience. Where material combines informative and creative elements, the Commission says its informative character should take priority.
Publicly available AI-generated or manipulated text about matters of public interest must also carry a clear label. The scope can include politics, public services, health, consumer safety, science, culture and economic or financial developments. Examples in the guidance include an AI-generated summary of an article about a town council decision, a health-related lifestyle article and a weather warning published on social media.
There is an important editorial exception. A label is not required when the text has undergone substantive human review or editorial control and a person or organization holds editorial responsibility for its publication.
Fact-checking is the minimum expected component of that review. A superficial grammar check, an automated review or cursory approval does not qualify. If AI makes substantive changes after editorial sign-off, the exception no longer applies. The identity or contact details of the person, editorial function or organization holding responsibility should also be publicly accessible.
Emotion recognition, enforcement and the transition period
Deployers of emotion recognition and biometric categorization systems must inform everyone exposed to their operation, including children. The notice must be clear, distinguishable and accessible, and provided no later than the first exposure.
The required notice identifies that the system is operating. Article 50 does not itself require deployers to explain why it is being used, although separate data protection rules may impose further requirements.
Providing a notice does not make the underlying use lawful. The Commission states that Article 50 compliance does not legitimize intrusive or discriminatory systems prohibited under other parts of the AI Act or other EU law. Its guidance specifically points to emotion recognition in workplaces and educational institutions as a practice that may fall under Article 5 prohibitions.
Member State market surveillance authorities, the EU AI Office and the European Data Protection Supervisor will enforce Article 50 within their respective areas of responsibility. Authorities can act on their own initiative or following a complaint.
Non-compliance can result in fines of up to €15 million or, for an undertaking, 3% of its total worldwide annual turnover in the preceding financial year, whichever is higher. For small and medium-sized enterprises, including startups, the lower of the percentage or fixed maximum applies. EU institutions, bodies and agencies can face administrative fines of up to €750,000.
Most Article 50 duties apply to systems placed on the market or put into service in the EU regardless of when they were introduced. Content produced before August 2 does not have to be marked or labeled retrospectively. However, public-interest text generated or manipulated before that date must be labeled if it is published on or after August 2.
A targeted transition applies to machine-readable marking and detection for generative AI systems already on the market before August 2. According to the Commission guidance, providers of those systems have until December 2, 2026, to bring them into conformity. Interactive disclosure duties have applied since August 2.