IT

EN

Artificial Intelligence

Article 50 of the AI Act: transparency obligations from 2 August 2026

From 2 August 2026, Article 50 of the AI Act brings into force new transparency obligations for chatbots, AI-generated content, deepfakes, emotion recognition systems and texts intended to inform the public. It is a cross-cutting regime that requires businesses, publishers and public administrations to turn disclosure into a verifiable governance process.

Much of the AI Act is built on a logic of risk classification: the more potentially dangerous an artificial intelligence system is to health, safety or fundamental rights, the stricter the obligations on those who produce it and those who use it. Article 50 breaks with this pattern. It does not look at the system’s level of risk, but at a specific capacity to affect how people perceive things: the possibility that content or an interaction appears human when in reality it is not. This is why the provision applies horizontally, regardless of whether the AI system involved is classified as high-risk, limited-risk or posing no significant risk.

The result is a regime that potentially concerns anyone using artificial intelligence to interact with the public, generate content or analyse people: companies with a chatbot on their website, communications departments producing images with generative tools, public administrations offering virtual assistants to citizens, newsrooms using AI for drafts or translations. The obligation became fully effective on 2 August 2026, while the requirements for general-purpose AI models had already applied since 2 August 2025.

Bliss Faculty · Criminal law

Artificial intelligence and criminal law: what’s new in Law 132/2025

→

The four obligations set out in the provision

Article 50 sets out four separate cases, each addressed to different parties and situations, sharing the same purpose: to enable anyone who comes into contact with an AI-generated output or behaviour to understand its nature.

The first obligation concerns systems designed to interact directly with natural persons: chatbots, voice assistants, avatars and AI agents, including multi-agent systems. The provider must design them so that users know they are dealing with an artificial system, unless this is already obvious to a reasonably well-informed, observant and circumspect person. This obviousness clause must be interpreted narrowly: if the potential audience includes minors, elderly people or vulnerable persons, the exception can hardly be invoked. The obligation also covers agents that act on a user’s behalf by carrying out concrete actions (bookings, payments, administrative requests), which must disclose not only their artificial nature but also on whose behalf they are operating.

The second obligation is addressed to providers of systems, including general-purpose ones, that generate synthetic audio, image, video or text content. Such outputs must be marked in a machine-readable format and made detectable as artificially generated or manipulated, using technical solutions that are effective, interoperable, robust and reliable, as far as technically feasible. The obligation does not cover standard editing, non-substantial changes to the input (grammar corrections, translations, noise reduction) or specific situations such as machine-to-machine communications or technical outputs intended for a small, predefined group of industrial professionals.

The third obligation applies to those who use emotion recognition or biometric categorisation systems: they must inform the people exposed to the system’s operation, in real time or even afterwards, without prejudice to compliance with data protection law, which this transparency obligation in no way replaces.

The fourth obligation applies to those who generate or manipulate deepfakes (images, audio or video that realistically recreate people, objects, places or events, making them appear authentic), as well as AI-generated or manipulated texts published to inform the public on matters of public interest. For evidently artistic, creative, satirical or fictional works, disclosure is lighter and need only avoid hampering the enjoyment of the work. For informative texts, by contrast, the obligation to declare the artificial origin lapses only where the content has undergone genuine human review or substantial editorial control, under the responsibility of an identifiable person: a condition that requires demonstrable procedures, not a mere formal statement.

The four obligations at a glance

Transparency obligations under Article 50

Who is responsible for what, and when the obligation does not apply

Provider obligations Deployer obligations
ObligationResponsible partyWhat it requiresMain exclusions
Paragraph 1Interactive systems Provider Inform users that they are interacting with an AI Artificial nature evident; law enforcement, except public crime reporting
Paragraph 2Marking of synthetic content Provider Machine-readable marking and detectability of output Standard editing, non-substantial changes, narrow technical B2B use
Paragraph 3Emotion recognition and biometrics Deployer Inform people exposed to the system Public order and security purposes authorised by law
Paragraph 4Deepfakes and texts of public interest Deployer Declare the artificial or manipulated origin Artistic and satirical works, with lighter disclosure; substantial editorial review for texts

The first two paragraphs apply to those who build the system, the other two to those who use it. The exclusions column is a summary, not the legal text: for practical application, the Article must be read in full.

 

The Commission’s guidelines and the Code of Conduct

To accompany the entry into application of the provision, on 20 July 2026 the European Commission adopted non-binding interpretative Guidelines, which offer a systematic reading of the four operative paragraphs of Article 50 and numerous practical examples to distinguish cases that fall within the obligation from those that remain outside it. Among other things, the Guidelines clarify that “deployer” status rests on actual responsibility for the decision to use the system and for how it is used, rather than on direct technical control: a company may therefore take on this role even without physically managing the technological infrastructure. The Guidelines expressly exclude personal non-professional activities and scientific research from the obligations, and specify that the obligations under Article 50 are in addition to, not in place of, those already laid down by the GDPR, the Digital Services Act and consumer protection law.

This instrument is complemented by the Code of Practice on Transparency of AI-Generated Content, published on 10 June 2026 and deemed adequate by the Commission and the AI Board as the preferred route (while remaining voluntary) for demonstrating compliance with the marking and labelling obligations under paragraphs 2, 4 and 5. Adherence to the Code is not, however, conclusive proof of compliance: an independent assessment of one’s own practices is still required.

The Digital Omnibus and the transitional regime

The regulatory framework should be read together with Regulation (EU) 2026/1744, the so-called Digital Omnibus on AI, which entered into force on 27 July 2026. The measure did not postpone the application of Article 50 across the board: the date remained 2 August 2026 for all its requirements. It did, however, introduce a limited transitional regime: for generative systems already placed on the market before that date, only the marking and detectability obligation under paragraph 2 may be brought into line by 2 December 2026. All other requirements (information on interaction, disclosure on emotions and biometrics, declaration of deepfakes) remain fully effective from the original date.

Why a label is not enough: from disclosure to governance

A common mistake is to consider the transparency obligation met by adding a generic statement such as “content generated with artificial intelligence”. Article 50(5), by contrast, requires the information to be clear and distinguishable, provided at the latest at the time of the first interaction or exposure, and compliant with digital accessibility requirements. Information buried in terms and conditions is therefore not sufficient, nor are machine-readable markings with no signal perceptible to the user, ambiguous cues or purely technical descriptions that convey nothing concrete to the reader or listener.

Machine-readable marking, in particular, adds a further layer beyond simply informing users: synthetic content must also be recognisable by automated systems, distribution platforms, moderation tools and search engines. Relying solely on watermarking or metadata, however, would be illusory: detection techniques are inherently probabilistic, can degrade through compression or reuse of content, and remain vulnerable to circumvention strategies. That is why compliance with Article 50 must be built as a genuine organisational framework (mapping AI uses, classifying the roles the organisation assumes, controlling outputs, human review, logging generations, incident management), of which the label is only the visible part.

A broader regulatory mosaic

Article 50 does not operate in isolation, but sits within a network of European legislation that shares the goal of making the digital environment more trustworthy. The GDPR remains central whenever the generation or manipulation of content involves personal data, images, voice or biometric data: disclosure of AI use does not replace the privacy notice, nor does it legitimise processing that lacks a legal basis. The Digital Services Act strengthens the obligations on large platforms to assess and mitigate systemic risks, including the risk of disinformation. Copyright law affects the training pipeline of generative models. The Cyber Resilience Act and the NIS2 Directive safeguard the technical reliability of the chain that produces, marks and distributes content, while the Data Act and the Data Governance Act address the quality and availability of the data used to train and test AI systems.

For more content by Professor Tupponi

Artificial intelligence in court: the efficiency of predictive models and judges’ objections

→

Penalties and operational implications

Breaches of the transparency obligations are punishable by fines of up to €15 million or, for companies, up to 3% of total worldwide annual turnover if higher, with a more lenient regime for small and medium-sized enterprises, to which the more favourable of the two thresholds applies.

In operational terms, the implications are cross-cutting and require a preliminary review. Businesses must first map the roles they take on in relation to their AI systems (provider, deployer, publisher, data controller), bearing in mind that a single organisation may hold more than one, each with different obligations: without this mapping, any claim of compliance has no foundation. Public administrations must integrate disclosure into the general principles of administrative transparency and accessibility, making clear to users that AI-generated outputs are not binding and always keeping an alternative human channel available. Publishers and newsrooms must adopt internal policies that clearly distinguish editorial assistance (drafts, translations, summaries) from the substantive production of content, and that support any exemption from disclosure with genuinely documentable human review procedures, not with merely nominal editorial responsibility.

The contractual side also deserves attention: in dealings with technology providers and external agencies, it is advisable to set out expressly the marking of outputs, the technical standards adopted, the retention of metadata, updates over time and liability for shortcomings in disclosure, providing for cooperation mechanisms to respond to any challenges or requests from supervisory authorities.

Transparency to be built, not declared

Article 50 marks a step change in European digital transparency: it is no longer a matter of a generic notice, but of the need to make the artificial origin of interactions, content and decisions that affect the daily lives of citizens, customers and users of public services recognisable, in a systematic and verifiable way. From 2 August 2026, businesses, public administrations and publishers will be required to demonstrate not so much that they have applied a label as that they have built the processes that make that label accurate, timely, accessible and reliable over time. This work calls for a joint reading of the legislation, the Commission’s Guidelines and the Code of Practice, but above all for a concrete, case-by-case assessment of one’s own systems and content: the only way to turn a regulatory obligation into a genuine source of public trust.

Domande frequenti

When did Article 50 of the AI Act become applicable?

The transparency obligations under Article 50 apply from 2 August 2026. They cover, among others, systems that interact directly with people, synthetic content, deepfakes, emotion recognition systems and certain text publications generated or manipulated by AI.

Must a text written with artificial intelligence always be disclosed?

No. For text generated or manipulated by AI and published to inform the public on matters of public interest, Article 50 provides an exception where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for it.

What changes for chatbots and AI assistants?

Systems designed to interact directly with natural persons must be built so that users know they are interacting with an artificial intelligence system, except where the artificial nature is already evident in the specific circumstances.

What are the penalties for breaching Article 50?

Breaches of the transparency obligations under Article 50 are among those that may incur fines of up to €15 million or, for companies, up to 3% of total worldwide annual turnover for the preceding financial year, if higher, under the conditions set out in the AI Act.

How can Bliss work with a business to address the obligations of Article 50?

The first step is to map uses of artificial intelligence and establish what role the organisation plays in each process: provider, deployer, publisher, data controller, or several roles at once. From there, Bliss can work across Advisory, Governance and Operations to translate the requirements into responsibilities, procedures, controls, workflows and operational infrastructure. The aim is to make compliance part of the system through which the company governs AI, rather than confining it to the presence of a disclosure.

Fonti e riferimenti
  1. Parlamento europeo e Consiglio dell’Unione europea, Regolamento (UE) 2016/679 – GDPR
  2. Parlamento europeo e Consiglio dell’Unione europea, Direttiva (UE) 2022/2555 – NIS2
  3. Parlamento europeo e Consiglio dell’Unione europea, Regolamento (UE) 2022/2065 – Digital Services Act
  4. Parlamento europeo e Consiglio dell’Unione europea, Regolamento (UE) 2023/2854 – Data Act
  5. Parlamento europeo e Consiglio dell’Unione europea, Regolamento (UE) 2024/1689 – Artificial Intelligence Act, articolo 50
  6. Parlamento europeo e Consiglio dell’Unione europea, Cyber Resilience Act
  7. Commissione europea, Code of Practice on Transparency of AI-generated Content
  8. Commissione europea, How to sign the Code of Practice on Transparency of AI-generated Content, 10 giugno 2026
  9. Parlamento europeo e Consiglio dell’Unione europea, Regolamento (UE) 2026/1744 – Digital Omnibus on AI
  10. Commissione europea, Guidelines on transparency obligations for providers and deployers of AI systems, 20 luglio 2026
BLISS®© 2026. ALL RIGHTS RESERVED
Scritto il · Aggiornato il

Brand Advisory

Brand Positioning
Brand Architecture
Archetypal Models
Identity Systems

Audit

Consulting
Advisory
Growth
Applying strategy across markets
Brand control system
Global activation framework
Strategic validation of initiatives

Corallo.Ai

Operations

Photography
Video Production
Campaign Shooting
Cinematic Content
Visual Identity
Graphic Systems
3D Design
Motion Assets
UI/UX Design
Web Development
E-Commerce
Platform Maintenance
Google Ads
Meta Ads
SEO Optimization
AI Optimization
AI Visibility
Semantic Authority
Generative Citability
LLM Digital PR