Which AI-Generated Content Must Be Disclosed Under the EU AI Act?
7 min read
Article 50 of the EU AI Act creates four separate disclosure duties, not one labelling rule: AI systems people interact with, synthetic audio, image, video and text output, emotion recognition and biometric categorisation, and deepfakes and public-interest text. Two of the four fall on the provider rather than on whoever publishes the content.

“The AI Act’s labelling rule” does not describe anything in the Regulation. Article 50 is a list of four obligations that share a chapter heading and not much else. They catch different content, they bind different parties, and three of the four have exceptions that swallow a large share of ordinary use.
Article 50 contains four obligations, not one
Chapter IV of Regulation (EU) 2024/1689 runs to a single article. Inside it are four duties:
| Provision | Who carries it | What triggers it |
|---|---|---|
| Article 50(1) | Provider | An AI system intended to interact directly with people |
| Article 50(2) | Provider | An AI system generating synthetic audio, image, video or text |
| Article 50(3) | Deployer | An emotion recognition or biometric categorisation system |
| Article 50(4) | Deployer | A deepfake, or text published to inform the public on matters of public interest |
Two of the four bind the provider, meaning whoever develops the system and places it on the market under their own name or trademark. Two bind the deployer, meaning whoever uses it under their own authority in a professional capacity. Working out which one you are is the question that decides everything else, and it is worked through in Provider or Deployer? Which Article 50 Obligation Applies to You.
Article 50(5) then sets one standard across all four: the information goes to the people concerned in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure, and it has to conform with the applicable accessibility requirements.
Article 50(1): systems that interact with people
This is the chatbot rule, and it is a design obligation rather than a labelling one. The provider has to build the system so that a person can tell they are talking to software.
The Commission’s guidelines, adopted on 20 July 2026, read the trigger as four conditions that all have to hold:
Article 50(1) then removes the duty where the AI involvement is obvious “from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use”. That standard is objective rather than about what your particular visitor happened to know. Recital 132 adds that where a system is intended to interact with people who are vulnerable because of age or disability, their characteristics have to be taken into account.
Article 50(2): marking synthetic audio, image, video and text
This is the widest of the four in terms of content, and the narrowest in terms of who it binds.
Providers of AI systems, including general-purpose AI systems, generating synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated.
Three things follow that people routinely get wrong.
It covers all four media, including text. There is no deepfake test here and no public-interest test. Any synthetic output from a generative system is in scope.
It is satisfied invisibly. Recital 133 lists the accepted techniques: watermarks, metadata identifications, cryptographic methods for proving provenance and authenticity, logging methods and fingerprints. None of those is something a reader sees. The difference between this and a visible label is the subject of Visible Label or Machine-Readable Marking?.
It is the tool vendor’s duty, not yours. If you generate images with a commercial model, Article 50(2) is a question about that model’s provider. It does not transfer to you by using the output.
The provision carves itself back in two places: it does not apply “to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof”. The Commission’s FAQ adds further output types it treats as outside the marking duty, including short sequences of numbers, symbols or letters, source code, machine-to-machine output, and closed-loop industrial output that is not the final output.
One date attaches only to this paragraph. Systems placed on the EU market before 2 August 2026 have until 2 December 2026 to meet the marking obligation. Anything placed on the market on or after 2 August 2026 is in scope immediately. That transitional period came in with the Digital Omnibus on AI, which delayed several high-risk deadlines and left the rest of Article 50 alone.
Article 50(3): emotion recognition and biometric categorisation
A deployer running an emotion recognition system or a biometric categorisation system has to inform the people exposed to it, and process their personal data in line with the GDPR, Regulation (EU) 2018/1725 and Directive (EU) 2016/680 as applicable.
Recital 132 gives a sense of how wide biometric categorisation reaches. The categories it names include sex, age, hair colour, eye colour, tattoos, personal traits, ethnic origin, and personal preferences and interests.
Most organisations publishing AI imagery never touch this paragraph. It is here because it is one of the four, and because a reader auditing their AI use should check it off rather than discover it later.
Article 50(4): deepfakes, and text on matters of public interest
Article 50(4) contains two separate duties in two subparagraphs, and they are frequently read as one.
The first subparagraph covers image, audio or video content constituting a deepfake. Article 3(60) defines that as content resembling existing persons, objects, places, entities or events that would falsely appear to a person to be authentic or truthful. The Commission treats the elements as cumulative. That test, and the exceptions attached to it, are worked through in When Does an AI-Generated Image Need a Visible Label Under Article 50?.
The second subparagraph covers text, and almost nothing written about Article 50 covers it properly. It applies only where all three limbs hold:
Then comes the exemption that decides most real cases. The duty does not apply where the AI-generated content “has undergone a process of human review or editorial control and where a natural or legal person holds editorial responsibility for the publication of the content”.
The Commission sets a substantive bar for that. Human review means a deliberate examination of the substance by people with relevant knowledge and professional judgement. Editorial control means a responsible editor with authority to approve, alter or reject the substance on substantive grounds. Checks that are superficial, purely formal or procedural, such as running a spell-checker, do not qualify.
What Article 50 does not reach
Four things sit outside all four paragraphs, and knowing that prevents over-labelling, which carries its own costs.
- Purely personal, non-professional use. Article 3(4) excludes it from the definition of a deployer, so the Article 50(3) and 50(4) duties do not attach. The Commission reads professional activity broadly, including activity that provides an economic benefit.
- Content that meets no trigger. An abstract illustration, a plainly stylised graphic, or an internal document nobody publishes fails the deepfake test and the text test alike.
- Any duty to name the model. Article 50 asks you to disclose that content is artificially generated or manipulated. It does not ask which system produced it.
- A ban on AI content. Nothing in Article 50 restricts generating or publishing synthetic content. It regulates what you say about it.
Article 50 is not the only transparency rule you are under
Article 50(6) is a single sentence and it is easy to miss:
Paragraphs 1 to 4 shall not affect the requirements and obligations set out in Chapter III, and shall be without prejudice to other transparency obligations laid down in Union or national law for deployers of AI systems.
Reading Article 50 as the whole of your disclosure position is therefore a mistake even where you have read it correctly. Consumer protection law on misleading commercial practices, platform and marketplace policies, national media rules and data protection law where a real person’s likeness is involved all continue to apply on their own terms. Working out that they do is outside what this page can tell you, and it is worth putting to someone who advises on your sector.
Penalties for breaching Article 50 sit in Article 99(4): up to €15 million or 3% of total worldwide annual turnover, whichever is higher, with lower ceilings for SMEs. Enforcement practice this early is thin, so treat that figure as the statutory maximum rather than as a prediction.
Frequently asked questions
Does Article 50 of the EU AI Act apply to AI-generated text?
In two ways, on two different parties. Article 50(2) requires the provider of a generative AI system to mark synthetic text in a machine-readable format, alongside audio, image and video. Article 50(4) additionally requires a deployer to disclose AI-generated or manipulated text that is published to inform the public on matters of public interest, unless the text went through human review or editorial control and a natural or legal person holds editorial responsibility for it.
Is a chatbot covered by the EU AI Act transparency rules?
Article 50(1) applies to AI systems intended to interact directly with natural persons, which covers a customer-service chatbot or a voice assistant. It is the provider of the system that must design it so a person is informed they are interacting with AI. The duty falls away where that is obvious to a reasonably well-informed, observant and circumspect person given the circumstances and the context of use.
Does Article 50(2) apply to AI used for retouching photos?
Article 50(2) states that the marking obligation does not apply to the extent an AI system performs an assistive function for standard editing or does not substantially alter the input data or its semantics. Recital 133 gives the same carve-out. Where a generative edit changes what the image depicts rather than adjusting how it looks, the carve-out is harder to rely on, and the separate deployer duty in Article 50(4) may apply on its own terms.
Who carries each of the four Article 50 obligations?
Article 50(1) and Article 50(2) fall on the provider of the AI system: informing people they are interacting with AI, and marking synthetic output in a machine-readable format. Article 50(3) and Article 50(4) fall on the deployer: informing people exposed to emotion recognition or biometric categorisation, and disclosing deepfakes and public-interest text. A single organisation can hold both roles at once for different systems.
Sources
- Regulation (EU) 2024/1689 (AI Act), Articles 3 and 50(opens in a new tab)Official Journal of the European Union
- Regulation (EU) 2024/1689, Recitals 132 to 134(opens in a new tab)Official Journal of the European Union
- Transparency obligations under Article 50 of the AI Act (FAQ)(opens in a new tab)European Commission
- Guidelines on transparency obligations for providers and deployers of certain AI systems(opens in a new tab)European Commission



