Skip to content

Commission guidance on Article 50 transparency obligations

The Commission's interpretive guidance on the EU AI Act's Article 50 transparency obligations is the Commission Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689. The Commission approved the content of the draft Guidelines on 20 July 2026 (Communication C(2026) 5054); they will be formally adopted under Article 96(1)(d) AI Act once all language versions are available. This page paraphrases the Commission's reading of the four transparency duties, the horizontal Article 50(5) rule, the scope exclusions, and the enforcement regime.

Status

Commission interpretive guidance, not binding law. The EU AI Act text and any Court of Justice of the European Union (CJEU) interpretation prevail in case of conflict; the Commission states this at paragraph (5).

The Commission has approved the content of these Guidelines; formal adoption follows once all language versions are available, and the Guidelines become applicable as guidance only from that formal adoption. The underlying Article 50 obligations apply from 2 August 2026 regardless of the guidance timeline.

Quick decision

  • You provide a chatbot, voice assistant, or any AI system that interacts directly with people → Article 50(1) — a provider-side design duty. The "obvious" exception is narrow.
  • You provide an AI system that generates or manipulates audio, image, video, or text → Article 50(2) — provider-side machine-readable marking and available detection. Source code, short labels, and standard editing are out of scope.
  • You deploy an emotion-recognition or biometric-categorization system → Article 50(3) — deployer-side notification. Check the Article 5(1)(f)/(g) prohibitions first.
  • You deploy an AI system that generates deepfakes, or publishes AI-generated text on matters of public interest → Article 50(4) — deployer-side labeling, with an attenuated regime for evidently artistic content and an editorial-responsibility exception for text.
  • You want the underlying Regulation text, not the Commission's reading → Prohibited practices and transparency.

TL;DR

  • Article 50 has four transparency duties plus a horizontal timing, clarity and accessibility rule (Article 50(5)). The same AI system can trigger several duties at once, engaging providers and deployers at different points in the value chain (paragraph 8).
  • Provider-side: interactive-AI disclosure (50(1)) and synthetic-content marking and detection (50(2)). Deployer-side: emotion/biometric notification (50(3)) and deepfake / public-interest-text labeling (50(4)).
  • Transparency under Article 50 does not make a use lawful — a system in scope may still be prohibited under Article 5 or classified high-risk under Article 6 (paragraph 25), and data-protection, consumer, IP and DSA obligations apply in parallel (Sections 3.3, 4.4, 5.3, 6.1.5).
  • Scope carve-outs the guidance clarifies: purely personal non-professional deployer use, scientific research and development, and free and open-source systems (which stay in scope where Article 50 applies).
  • Compliance can be demonstrated by adhering to a code of practice assessed as adequate under Article 50(7); the Code of Practice on Transparency of AI-Generated Content was published on 10 June 2026 and has been confirmed adequate by the Commission and the AI Board.
  • Penalties reach EUR 15 000 000 or 3% of worldwide annual turnover, whichever is higher (for SMEs and start-ups, whichever is lower); Article 50 applies from 2 August 2026. The Digital Omnibus on AI (Regulation (EU) 2026/1744) grandfathers only the 50(2) obligations for pre-existing systems to 2 December 2026.

Who is responsible, and what is out of scope

Providers (Article 3(3)) carry the Article 50(1) and (2) duties and must embed transparency into the system's design so it is met at the latest when the system is placed on the market or put into service, throughout its lifecycle and irrespective of who the downstream deployers are (paragraph 11). A company that substantially modifies an existing generative system (for example by retraining it) and places it on the market or puts it into service under its own name or trademark becomes the provider of the new system (Section 2.3).

Deployers (Article 3(4)) carry the Article 50(3) and (4) duties where they use the system under their authority for a professional purpose. The guidance draws several lines:

  • Employees and contractors are not separate deployers. Where a legal person deploys the system, the individual staff, freelancers or contractors acting under its authority (animators, journalists, web designers) are not deployers in their own right (paragraph 14).
  • Hosting services and broadcasters are not deployers merely by disseminating third-party AI content, though they are strongly encouraged to preserve marks and labels and may face duties under the DSA or other law (paragraphs 16–17).
  • Third-country reach. Providers are in scope where their system is placed on the market or its output is used in the Union; deployers are in scope where established in the Union or where they foresee dissemination of the output in the Union. Purely incidental, unforeseeable downstream reach does not, on its own, trigger the obligations (paragraphs 10, 13).
  • Dual roles. A company that builds a generative system in-house and uses it to produce deepfakes is both a provider (50(2)) and a deployer (50(4)) (paragraph 15).

Three scope exclusions matter for Article 50 (Section 2.4):

  • Purely personal, non-professional use (Article 2(10)) exempts the deployer's obligations only. The system stays in scope for the provider, who must still mark synthetic outputs under 50(2) (paragraphs 19–20).
  • Scientific research and development (Article 2(6) and (8)) is excluded, but the obligations revive once the system is put into service or its outputs are used for other purposes (paragraphs 21–22).
  • Free and open-source systems (Article 2(12)) stay within scope where Article 50 applies; standalone open-source components that are not themselves AI systems do not carry the duties (paragraphs 23–24).

Article 50 also interlocks with the rest of the Regulation: compliance with it neither replaces the Article 5 prohibitions, nor the high-risk requirements under Article 6, nor the AI-literacy duty under Article 4 (paragraph 25). Article 50 applies to general-purpose AI systems; it does not directly bind GPAI models, though model-level transparency measures are encouraged and help downstream providers comply (paragraphs 26–27).

Article 50(1) — transparency for interactive AI systems

What the Commission says (Section 3):

  • Four scope elements (paragraph 30): the system must be (i) an AI system within Article 3(1) — excluding simple non-AI automation such as rule-based out-of-office replies; (ii) intended to interact, meaning a genuine bidirectional exchange, not passive data collection or one-off feedback; (iii) directly, typically in real or near-real time, excluding cases where a human is the main interlocutor reviewing and sending the output; and (iv) with natural persons, excluding closed machine-to-machine or industrial settings.
  • AI agents must be designed to disclose both their artificial nature and the person on whose behalf they act, at key steps and at every new interaction. Where the provider cannot know in advance whether an agent will meet a natural person, it must be built to disclose in every situation where interaction is reasonably likely (paragraph 31).
  • The disclosure is a design duty on the provider, delivered at the latest at the first interaction, in a format the provider chooses (textual, auditory, visual, multimodal), adapted for vulnerable audiences including children where they are reasonably likely to be in the audience (paragraphs 32–37).
  • Techniques that are insufficient on their own (paragraph 38): disclosures buried in terms and conditions or documentation; machine-readable marks not perceivable at the point of interaction; vague signals such as "assistant"; generic site-wide notices ("services on this website use AI"); and technology descriptions ("this system uses LLMs") that do not explain the artificial origin.

The "obvious" exception (Section 3.2.1) is read restrictively. It turns on a reasonably well-informed, observant and circumspect member of the intended and reasonably foreseeable audience, borrowing the consumer-law "average consumer" standard. General public awareness that AI exists does not mean a person recognizes a specific interaction as AI; the exception is limited to cases where almost no doubt remains (paragraphs 42–45).

  • Obvious — a code-review assistant available only to professional developers; an internal AI tool for trained, AI-literate staff; AI-enabled non-playable characters in a single-player game.
  • Not obvious — a lifelike robotic companion pet; realistic avatars in immersive VR that children or older users may not distinguish; helpdesk chatbots whose replies a user may read as human.

The law-enforcement exception (Section 3.2.2) covers systems authorized by law to detect, prevent, investigate or prosecute criminal offenses, subject to safeguards. It does not apply where the system is available to the public to report a criminal offense — police reporting chatbots, fraud-reporting hotlines and witness-statement assistants remain subject to 50(1) (paragraphs 46–49).

Article 50(2) — marking and detection of AI-generated content

What the Commission says (Section 4):

  • Two linked obligations (paragraphs 69–70): providers must ensure outputs are marked in a machine-readable format and that means of detection are available to people exposed to the content. Meeting only one does not satisfy the provision.
  • Modalities in scope (paragraphs 60–63): audio, image, video, text, and multimodal combinations, including 3-D image/video/audio, virtual/augmented/mixed reality (treated as video), and digital twins. AI-agent outputs are covered where the action produces content perceptible by people; intermediate reasoning and machine-only actions are not.
  • Out of scope (paragraphs 64–68): content from simple data processing (a rendered frame); pure reproduction, selection or arrangement of existing content (playlists, recommenders); observations and recordings not AI-generated (sensor and telemetry data); very short strings (single words, captions, alt-text, UI labels); source code and machine-readable configuration (SDKs, SQL, IaC, YAML, JSON, APIs); machine-to-machine outputs not perceived by people; and intermediate outputs used only in closed industrial or product-development workflows (the final published output remains covered and must be marked and detectable).
  • Technique-neutral marking (paragraphs 71–74): watermarks, metadata, cryptographic provenance, fingerprints, logging, or a combination. A full provenance chain is encouraged but not required. Providers may rely on an upstream model provider's or a third party's compliant solution, without shedding their own responsibility.
  • Detection (paragraphs 75–78): must be available to exposed persons, produce human-readable results, and, for interoperability, rely on publicly available industry-standard, ideally locally executable solutions where they exist; a provider's own or shared solution is a time-limited fallback until standards emerge.
  • Quality bar (paragraphs 79–83): the combined solution must be effective, interoperable, robust and reliable to the degree that is technically feasible, judged against the state of the art and the cost of implementation. Technical feasibility is objective, not a function of an individual provider's resources; providers must keep pace as the state of the art evolves.
  • Narrow relief (paragraphs 86–88): less-robust metadata marking may suffice for closed, instructive embedded products (an in-car navigation voice); no marking is required for strictly technical industrial or business-to-business outputs consumed by a defined internal professional audience; and real-time ephemeral content that is not stored or disseminated may be exempt where marking is not feasible and users are told the content is AI-generated.

The three exceptions (Section 4.3):

  • Standard editing — preparing existing content for publication without generating new content (grammar and spelling correction, formatting, noise reduction, minor cropping, translation) (paragraph 90).
  • No substantial alteration — the system does not significantly change the input data or its semantics; a case-specific assessment of format, type, style and meaning (paragraphs 91–92). Summarizing, paraphrasing that changes meaning, object or face replacement, voice cloning and realistic event fabrication all require marking.
  • Law enforcement — authorized by law to detect, prevent, investigate or prosecute criminal offenses (paragraph 93).

Article 50(3) — emotion recognition and biometric categorization

What the Commission says (Section 5):

  • Deployers must inform the natural persons exposed that an emotion-recognition or biometric-categorization system is operating, whether the system runs in real time or ex post (paragraphs 99–100).
  • Relationship to other regimes (paragraphs 101–104): all emotion-recognition systems are also high-risk unless prohibited in the workplace or education under Article 5(1)(f) (a prohibition that itself excepts medical and safety uses); biometric-categorization systems are covered by 50(3) regardless of high-risk status, unless prohibited as sensitive-attribute inference under Article 5(1)(g) (a prohibition that does not cover labeling or filtering of lawfully acquired biometric datasets in the law-enforcement area). The high-risk-classification guidance definitions carry over.
  • What must be said (paragraphs 105–108): that the person is exposed to the operating system. The Regulation does not require stating the reasons; other purposes and processing details are governed by data-protection law. The information reaches all exposed persons, including children, at the latest at first exposure, by writing, standardized icons, orally, or a combination.
  • Law-enforcement exception (paragraph 109): weaker than the other Article 50 exceptions — it applies where use is permitted by the legal rules governing law-enforcement powers, without requiring a law that explicitly authorizes non-transparent use, subject to safeguards.

Article 50(3) notification does not make an otherwise unlawful or prohibited use lawful, and applies in addition to data-protection information duties, though the two notices can be combined (paragraph 110).

Article 50(4) — deepfakes and public-interest text

Article 50(4) sets two separate deployer duties: labeling deepfakes (image, audio, video), and labeling AI-generated text published to inform the public on matters of public interest. Both are additional to the provider's 50(2) marking (paragraph 111).

Deepfakes (Section 6.1)

  • Four cumulative criteria define a deep fake under Article 3(60) (paragraph 113): AI-generated or manipulated image, audio or video that (i) appreciably resembles (ii) an existing (iii) person, object, place, entity or event, and (iv) would falsely appear to a person to be authentic or truthful. Content that could plausibly exist counts; content that defies nature or physics and has no potential to mislead (a sphinx over the Eiffel Tower, mice debating cheese) falls outside the definition.
  • The false-appearance test is objective and does not require intent to deceive; it is assessed as a whole against the reasonably foreseeable audience, including where children or lower-literacy groups are foreseeably exposed (paragraphs 114–115). Photorealism makes deepfake status more likely but is not determinative.
  • Minor, non-substantive manipulation (background clean-up, color correction, compression, aesthetic adjustment) generally does not create a deepfake; substantial manipulation (such as heavy editing of journalistic images beyond standard editorial practice) can constitute one where the four Article 3(60) criteria are met (paragraph 116).
  • Disclosure must be perceivable by people without special tools (a visible or audible label). Deployers cannot rely on the provider's machine-readable 50(2) mark to meet this duty (paragraph 117).
  • Attenuated regime for evidently artistic content (Section 6.1.3): where a deepfake is evidently part of an artistic, creative, satirical, fictional or analogous work or programme, disclosure is limited to a form that does not hamper enjoyment of the work — but it is not eliminated. "Evidently" is read strictly; purely informative or commercial content is excluded, and where a work mixes informative and creative character the informative character prevails (paragraphs 119–123). The attenuated regime does not excuse infringing third-party data-protection or IP rights (paragraph 124).

Public-interest text (Section 6.2)

  • Scope (paragraph 131): the text must be published (accessible to an indeterminate, sizeable audience, not private or organization-internal), aim to inform the public, and concern matters of public interest (politics, public administration, justice, health, the environment, consumer safety, and economic, scientific or cultural matters open to public debate).
  • The editorial exception (Section 6.2.3): disclosure is not required where two cumulative conditions hold — the text underwent genuine human review or editorial control (a deliberate substantive examination, with fact-checking as a minimum; not spell-checking, an editorial policy on paper, an automated review, or a cursory sign-off) and a natural or legal person holds editorial responsibility for the publication (the Guidelines recommend making that person's identity and contact details publicly and easily findable). Any substantive AI intervention after editorial sign-off voids the exception (paragraphs 133–138). Media service providers may rely on existing editorial standards; the concept aligns with editorial responsibility under the European Media Freedom Act (paragraph 140).
  • Law enforcement authorized by law is exempt (paragraph 139).

Article 50(5) — clarity, timing and accessibility

Article 50(5) is the horizontal rule anchoring all four duties (Section 7):

  • Clear and distinguishable (paragraph 142): noticeable, easy to understand, and easy to identify as separate from the surrounding content, not buried in a manual, a menu, or terms of use.
  • First interaction or exposure (paragraph 143): the information reaches every natural person's first interaction or exposure, not only the first person overall. For interactive systems, at least once at the start of a session; for content, per output and per exposed person, with additional disclosure where people may not perceive content from its start.
  • Accessibility (paragraph 144): where Directive (EU) 2016/2102 or Directive (EU) 2019/882 applies, the information must meet those accessibility requirements. Article 50 imposes no distinct or additional accessibility requirements of its own.

Enforcement (Section 8)

  • Code of practice (paragraphs 146–150): providers and deployers can demonstrate compliance with the 50(2) and 50(4) content duties by adhering to a code of practice assessed as adequate under Article 50(7) — the Code of Practice on Transparency of AI-Generated Content was published on 10 June 2026 and has been confirmed adequate by the Commission and the AI Board. Non-signatories must show compliance by other adequate means, and can expect more detailed information requests; a gap analysis against an adequate code is advisable. If no code is deemed adequate, the Commission may set common rules by implementing act.
  • Authorities (paragraph 151): Member State market surveillance authorities, the AI Office (for systems built on a GPAI model from the same provider), and the European Data Protection Supervisor (for EU institutions) supervise Article 50 within the Regulation (EU) 2019/1020 system. Any affected person can lodge a complaint.
  • Penalties (paragraph 152): up to EUR 15 000 000 or 3% of total worldwide annual turnover, whichever is higher; up to EUR 750 000 for EU institutions, bodies and agencies. For SMEs and start-ups the applicable ceiling is whichever of the percentage or fixed amount is lower, with small-mid-cap proportionality.
  • Entry into application (paragraphs 153–154): Article 50 applies from 2 August 2026 to all in-scope systems regardless of when they were placed on the market. The Digital Omnibus on AI (Regulation (EU) 2026/1744, in force from 27 July 2026) grandfathers only the Article 50(2) obligations for generative systems placed on the market before that date, giving them until 2 December 2026; systems that are partly interactive and partly generative benefit from the transition only for the marking obligation, and interactive-disclosure duties under 50(1) are not extended. Content generated before 2 August 2026 need not be marked or labeled retroactively, but pre-existing text re-published on or after that date must be labeled.

How to operationalize Article 50 transparency in Modulos

The four duties map to per-AI-system requirements on the MFF-1 framework template:

ArticleCommission guidance sectionModulos requirementCode
Article 50(1) interactive-AI disclosureSection 3Transparent Interaction with Natural PersonsMRF-44
Article 50(2) synthetic-content marking and detectionSection 4Computer-Generated Works MarkingMRF-45
Article 50(3) biometric-categorization notificationSection 5Transparency of Biometric CategorisationMRF-58
Article 50(3) emotion-recognition notificationSection 5Transparency of Emotion RecognitionMRF-59
Article 50(4) deepfake labeling (image / audio / video)Section 6.1Transparency of DeepfakesMRF-60
Article 50(4) public-interest-text labelingSection 6.2Transparency of Computer-Generated ReportingMRF-61

Operating rules:

  • Provider-side duties (MRF-44, MRF-45) are evidenced by system-design artifacts: the disclosure mechanism for 50(1), and the marking-and-detection technical solution for 50(2). Deployer-side duties (MRF-58, MRF-59, MRF-60, MRF-61) are evidenced by deployer policy and the transparency notice itself.
  • The Article 50(5) clarity, timing and accessibility rule is a horizontal overlay on all four — evidence of when and how the information is provided sits on the relevant requirement.
  • The transparency notice is stored as control-level evidence on the requirement. Modulos does not provide a dedicated transparency-notice UI surface.

For the full template rollout see Operationalizing the EU AI Act in Modulos.

Cross-framework mapping (preview)

Article 50 dutyAdjacent reading
50(1) interactive-AI disclosureUCPD (Directive 2005/29/EC) misleading practices; Consumer Rights Directive (2011/83/EU) pre-contractual information; DSA recommender-system transparency.
50(2) synthetic-content markingDSA Articles 34–35 systemic-risk mitigation for VLOPs/VLOSEs; voluntary C2PA content-credentials standard; GDPR data-minimization for marking metadata.
50(3) emotion / biometric notificationGDPR Articles 13–14 information duty; GDPR Article 9 special-category processing; Article 5(1)(f)/(g) prohibitions.
50(4) deepfake / public-interest textDSA Article 35(1)(k) prominent-marking measure; European Media Freedom Act (2024/1083) editorial responsibility; Union IP and personality-rights law.

Source attribution

Commission Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689 (AI Act) — draft Guidelines whose content was approved on 20 July 2026 by Communication C(2026) 5054, to be formally adopted under Article 96(1)(d) AI Act once all language versions are available. © European Union. Landing page: Guidelines on transparency obligations for providers and deployers of AI systems. Section references on this page (e.g. "Section 4.2.3") are to the numbered sections of the Guidelines; paragraph references in the form (N) are to the Commission's paragraph numbering. The Guidelines will be formally adopted once all language versions are available. The underlying Regulation (EU) 2024/1689 is published in the OJ L of 12 July 2024 under CELEX 32024R1689.

Disclaimer

This page is for general informational purposes and does not constitute legal advice.