EUROPEAN UNION / REGULATION (EU) 2024/1689

EU AI Act Article 50: transparency requirements

Understand who must disclose AI use, mark generated content and label deepfakes — and where an evidence record can help.

SUMMARY CHECKED 07 SEP 2026 · SOURCES ↓

On this page

01 / THE REQUIREMENTS

Who owes what

Providers and deployers have different duties. Start with your role, then check the content type and applicable exceptions.

WHO / PARAGRAPHWHAT THE DUTY REQUIRES
ProviderArticle 50(1)Tell people when they are interacting with an AI system, unless this is obvious in the circumstances.
ProviderArticle 50(2)Make synthetic audio, image, video and text detectable as AI-generated in a machine-readable format.
DeployerArticle 50(3)Inform people exposed to emotion recognition or biometric categorisation systems.
DeployerArticle 50(4)Disclose deepfakes and certain AI-generated text published to inform the public on matters of public interest.
BothArticle 50(5)Make the information clear and distinguishable, no later than the first interaction or exposure.

An organisation can be both a provider and a deployer. Map the duties to each system and use case.

Read the provider and deployer qualifications

Three consequences follow that are easy to miss. An organisation that builds a generative tool and also publishes with it is both, and the obligations apply cumulatively — map them per system per use case, not per company. Light fine-tuning does not make you a provider; putting your own name on the system, substantially modifying it, or changing its intended purpose does. And a platform that merely distributes third-party AI content is not a deployer — it exercises no authority over the generating system, and applying a label does not make it one. It is encouraged to preserve upstream marks, not obliged to.

02 / DATES & TRANSITION

Dates and transition

General application
General application of the transparency duties.
Limited marking transition
Limited transition for Article 50(2) marking by qualifying systems already on the market before 2 August.

03 / THE DUTIES

Read the duty with its exceptions

The requirement is only the starting point. Read the qualifications alongside the duty, rather than treating a label as the whole answer.

50(1) / PROVIDER

Tell people they are interacting with AI

The obviousness exception depends on the audience and context. General awareness that chatbots exist does not mean someone recognises an AI system in front of them.

Read the provision and qualifications

Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed so that those persons are informed they are interacting with an AI system — unless this is obvious to a reasonably well-informed, observant and circumspect person, taking into account the circumstances and context of use.

Regulation (EU) 2024/1689, Art. 50(1)

The obviousness exception is to be read restrictively: the Commission's guidance is explicit that general public awareness that chatbots exist does not mean people recognise one in front of them. The benchmark flexes with the audience — children, older users and people with disabilities lower the expected level of circumspection; a specialist professional audience raises it.

50(2) / PROVIDER

Mark generated output, including text

Marking must be effective, interoperable, robust and reliable as far as technically feasible. Content format and the applicable exceptions matter.

Read the provision and qualifications

Providers of AI systems generating synthetic audio, image, video or text content shall ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. Technical solutions shall be effective, interoperable, robust and reliable as far as technically feasible, taking into account the specificities of content types, implementation costs and the generally acknowledged state of the art.

Regulation (EU) 2024/1689, Art. 50(2)

Text is on the face of the provision. Summaries claiming Article 50(2) omits text are simply wrong. Exceptions are narrow: systems performing an assistive function for standard editing, systems that do not substantially alter the input data or its semantics, and law enforcement.

And read "technically feasible" carefully, because it does not mean what defendants would like. The Commission's guidance states that technical feasibility is an objective notion that is not dependent on the specific resources and capabilities of individual providers. Cost may inform proportionality. Being small is not an exemption.

50(4) / DEPLOYER

Disclose deepfakes in context

For deepfakes, creative or satirical use changes how disclosure is presented; it does not remove the disclosure duty.

Read the provision and qualifications

Deployers of a system generating or manipulating image, audio or video constituting a deep fake shall disclose that the content has been artificially generated or manipulated. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work, the obligation is limited to disclosing its existence in a manner that does not hamper the display or enjoyment of the work.

Regulation (EU) 2024/1689, Art. 50(4), first subparagraph

The artistic carve-out is an attenuation, not an exemption — the guidance is explicit that such works are not excluded from the duty; only the manner of disclosure softens. "Evidently" is the gate, judged on format, context of presentation and audience expectation. Where content mixes categories, the informative character prevails. Every advertising example in the Commission's guidance is classified as requiring ordinary labelling, however avant-garde its styling.

Note also that intent to deceive is irrelevant to deep-fake status, and photorealism makes it more likely without being decisive.

50(4) / PUBLIC-INTEREST TEXT

Understand the editorial exception

The public-interest text exception combines human review or editorial control with editorial responsibility for publication.

Read the provision and qualifications

The duty to disclose AI-generated text published to inform the public on matters of public interest does not apply where the content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for its publication.

Regulation (EU) 2024/1689, Art. 50(4), second subparagraph

Both conditions are cumulative, and the review must be substantive — cursory sign-off without real engagement does not qualify. The identity and contact details of whoever holds editorial responsibility should be publicly available in an easily findable place.

Here is the trap, and it is the reason this duty belongs in an evidence discussion at all: any substantive AI intervention that happens after editorial sign-off voids the exception. Whether you are inside the carve-out therefore depends on the order and timing of two events — the editorial act, and any later machine edit. A sealed record can help compare a reviewed content hash with a later version. It does not independently observe every edit or establish the quality of the review.

One more thing clients get backwards: this carve-out disapplies 50(4) only. It does not switch off the provider's 50(2) marking duty. The same article can be machine-marked by its provider and carry no visible label from its publisher.

“Effective, interoperable, robust and reliable”

Article 50(2) / marking solutions

04 / MARKING & THE CODE

Start with the content format

Assess the overall marking and detection solution against the applicable requirements. A named technology alone does not establish compliance.

Read the marking requirements

"Machine-readable" means marks structured so software can identify, recognise and extract them without human intervention. The Act names no technology; a recital lists watermarks, metadata identifications, cryptographic methods for proving provenance, logging methods and fingerprints as candidates.

The reviewed Article 50 instruments do not establish a harmonised-standard route to a presumption of conformity. The standardisation request given to the European standards bodies covers the high-risk chapter only; Article 50 sits outside it entirely. The Commission's 51-page guidance on this article does not contain the phrase "harmonised standard" even once. So there is no presumption of conformity available here — a fact worth internalising before budgeting for one.

The final Code and Guidelines reviewed for this page do not name C2PA. A named technology alone does not establish compliance. Evaluate the marking and detection solution against the applicable requirements, content format and qualifications.

Marking is also not the whole duty. Outputs must be detectable, which means the means of detection must be available to the people exposed to the content and must produce human-readable results. Providers may implement marking anywhere in the value chain and may rely on an upstream model provider or a third-party solution — without displacing their own responsibility to demonstrate compliance.

The guidance does not oblige providers to keep a full provenance chain of a content item’s origin and modifications. The marking and detection duties are distinct from any additional evidence process you choose to maintain.

The Code of Practice

The voluntary Code uses a layered approach with specific exceptions for free-form text and controlled physical products. Keep these qualifications beside the implementation decision.

Read the Code commitments and qualifications

The Code of Practice on Transparency of AI-generated Content was finalised on 10 June 2026, found adequate by Commission opinion on 8 July, and had roughly 190 signatories announced on 31 July — 83 to the provider section, 152 to the deployer section.

Be precise about what signing does. The Commission's opinion states that adherence to the code does not constitute conclusive evidence of compliance, and the amending regulation's recitals confirm that such codes do not grant a presumption of conformity. What signing buys is supervisory posture: for signatories, the Commission and market surveillance authorities will focus their activity on assessing whether the signatory has actually adhered to the code. Non-signatories are expected to demonstrate compliance by other adequate means, to run a gap analysis against the code, and may face more requests for information and access.

Planisphere can support a chosen evidence process. The Code's editorial-review commitment does not require documenting each individual review. A per-publication record is an optional way to bind a reviewed version to the evidence you retain; it does not establish that the review was adequate.

The Code describes a layered marking approach, with qualifications for content format and technical feasibility. The following layers must be read with its exceptions for free-form text and controlled physical-product environments.

  • Digitally signed metadata — mandatory. Recorded information must be digitally signed and time-stamped in a secure and tamper-evident manner, with controls over signing certificates and private keys.
  • Imperceptible watermarking — mandatory.
  • Fingerprinting or logging — optional, and expressly insufficient on its own.
  • Richer provenance information — explicitly optional.

Signatories also commit not to strip existing metadata markings from content they take as input, and to prohibit intentional removal in their acceptable-use terms. Single-layer marking is accepted for closed physical-product environments and for free-form text, which cannot carry metadata.

Where C2PA fits

The final Code and Guidelines reviewed for this page do not name C2PA. Evaluate the solution, content format and applicable qualifications together.

Read the primary sources

05 / TIMELINE & ENFORCEMENT

How the dates fit together

Keep the general application date separate from the limited marking transition.

  1. AI Act enters into force
  2. Date of the consolidated text
  3. General Article 50 application
  4. Limited marking transition ends
Read the full timeline and source context

Start here, because the single most common error about this article right now is that it moved. It did not. The Digital Omnibus deferred the high-risk obligations and left Article 50 alone — while quietly rewriting one of its paragraphs and adding a transitional nobody expected.

  1. The AI Act enters into force

    Regulation (EU) 2024/1689, published in the Official Journal on 12 July 2024, with duties phased across four years.

  2. The Digital Omnibus on AI enters into force

    Regulation (EU) 2026/1744 moves the Annex III high-risk obligations to 2 December 2027 and the Annex I ones to 2 August 2028. Article 50 appears nowhere in the deferral. It does replace Article 50(7) in full and insert a new transitional.

  3. Article 50 begins to apply

    All four transparency duties, for systems placed on the market from this date. California's SB 942 becomes operative the same day — the alignment was deliberate.

  4. The transitional closes

    Providers of systems generating synthetic audio, image, video or text that were already on the market before 2 August 2026 have until this date to comply with the Article 50(2) marking duty. The other duties bite on 2 August regardless.

  5. Detection interoperability deadline

    Under the Code of Practice, signatories must by this date route detection through a publicly available interoperable method, or signal in the content which detection solution to use.

Source status checked 9 September 2026: EUR-Lex now provides a consolidated text dated 27 July 2026. It is a reading aid; the original regulation and amending regulation published in the Official Journal remain the authoritative texts.

Who enforces the duties?

Enforcement depends on the system and the responsible authority. The detailed guide covers the AI Office, national authorities and the applicable penalty tier.

Read the authorities and penalty provisions

This is the part of the Omnibus that got the least coverage and may matter most. The amending regulation replaced Article 75(1) in full, and the change is structural.

The AI Office is now exclusively competent for supervision and enforcement in relation to AI systems built on general-purpose AI models where the model and system come from the same provider or undertaking, and AI systems that constitute or are integrated into a designated very large online platform or search engine.

Regulation (EU) 2024/1689, Art. 75(1), as replaced by Regulation (EU) 2026/1744

In plain terms: for the major frontier-lab assistants and image generators, and for AI built into the largest platforms, Article 50 is enforced centrally by the AI Office rather than by national market surveillance authorities. New provisions give it investigatory powers, a binding commitments procedure, and the ability to impose fines directly — including periodic penalty payments of up to 5% of average daily worldwide turnover, per day, to compel cooperation with an investigation or a corrective measure. The Court of Justice has unlimited jurisdiction to cancel, reduce or increase those fines.

For everyone else, enforcement runs through national market surveillance authorities, with the European Data Protection Supervisor covering EU institutions. Authorities may act on their own initiative or on a complaint — and any affected person, or anyone with grounds to consider there has been an infringement, may lodge one.

On penalties: an Article 50 breach sits in the tier at up to €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. That is not the Act's ceiling — prohibited practices reach €35,000,000 or 7% — and pages describing the 3% tier as the maximum are understating the Act elsewhere while overstating it here. For SMEs and small mid-caps the same figures apply, but whichever is lower. Where an authority sets a fine it weighs, among other things, the duration of the infringement and the degree of cooperation — and adherence to an adequate code of practice can be taken into account as mitigation.

06 / EVIDENCE & ITS LIMITS

Make the evidence inspectable

A record can connect a reviewed content version to the evidence you retain. It helps make that evidence inspectable.

01

Retain the version

Keep the reviewed text locally and compute its content hash.

02

Record the event

Record the chosen event and its metadata, bound to that hash.

03

Compare the content

Compare later content with the retained version when you need to check whether the bytes differ.

OPTIONAL EVIDENCE / CLEAR LIMITS

A record is not a legal conclusion

A per-publication record is optional. It does not establish review quality, identify who made an edit, or certify compliance.

Read what Planisphere does and does not do

Stated plainly, because a vendor who is vague here will be vague in front of a regulator. Planisphere is an evidence layer. It sits beside your systems, never inside the act.

  • It does not mark or watermark outputs, write metadata, or provide a detection solution. Those are the duty itself, and they are yours.
  • It does not render disclosures to your users or apply labels to deep fakes.
  • It does not decide whether a work is evidently artistic, whether an interaction is obvious, or whether your editorial process is substantive enough to hold the carve-out. It records the ground you relied on and when — it does not endorse it.
  • It is not a notified body, does not issue CE conformity marking, and confers no presumption of conformity — which, for Article 50, does not exist for anyone.
  • It does not certify compliance or make a legal determination. No vendor can. A record is evidence a third party can check; it is not a finding that you complied.
  • It seals the submitted record at the server’s recording time. The caller’s claimed event time is a separate field; a record does not independently observe the underlying act.
Inspect an evidence report
Match a chosen record to its event type

The record vocabulary describes the evidence you choose to submit. It does not impose a requirement to record each act, or establish that the underlying duty was met.

ActEvent typeRequest fields and commitment
Declaring what is in scope system_declared role output_classes marking_techniques counter_binding effective_from · commits scope_sha256
Output marked, 50(2) output_marked marking_techniques marking_payload_ids model model_version detection_check_result · commits content_sha256
Disclosure shown, 50(1) and 50(5) disclosure_rendered exposure_ref disclosed_at channel disclosure_version · commits disclosure_text_sha256
Deep fake or public-interest label, 50(4) label_published label_form label_placement · commits content_sha256
An optional record of the editorial review editorial_review reviewer_ref and reviewed_at are required inputs; content_sha256 commits the reviewed content. Only reviewed_at is retained from this event’s metadata.
An exemption relied on exemption_relied exemption_ground decided_at · commits rationale_sha256

exemption_relied can commit a hash of the rationale you retained. A rationale record does not endorse the exception or independently prove when the underlying decision was made.

07 / INTEGRATION EXAMPLE

An editorial review recorded

A synthetic editorial-review request shows the intended structure. Keep the content local; send its digest and the required metadata.

POST /v1/record

SYNTHETIC REQUEST BODY

{
  "pack": "eu-ai-act",
  "event_type": "editorial_review",
  "occurred_at": "2026-09-09T12:00:00Z",
  "system_id": "synthetic-newsroom-example",
  "source_payload": {
    "content_sha256": "cc5be4893a7eeff7fd4ac604c209a5451fee04d723ce2004bf24cf9f5fe2cb21"
  },
  "metadata": {
    "reviewer_ref": "synthetic-editor-01",
    "reviewed_at": "2026-09-09T11:59:50Z"
  }
}

The example uses a full SHA-256 digest and a synthetic review reference. Replace the sample values in a test workspace.

occurred_at is the caller’s claimed event time. recorded_at in the response is the server’s sealing time.

The hash is the SHA-256 digest of the UTF-8 text Synthetic Article 50 editorial review example. with no trailing newline. Keep that text locally; send its digest. reviewer_ref is a required request input; this event retains reviewed_at from the metadata, not the raw review reference.

Send the request from a test workspace

Save the JSON as article50-review.json, replace the sample values, and use a test workspace key. This example creates a record when you submit it; reading or copying it does not send a request.

curl --request POST https://api.planisphere.ooo/v1/record \
  --header "Authorization: Bearer $PLANISPHERE_API_KEY" \
  --header "Content-Type: application/json" \
  --data-binary @article50-review.json

Compare the retained reviewed text and the later text by computing their hashes. A mismatch shows that the bytes differ; the record does not itself identify who edited them. Other record events follow their own required fields. The API reference covers authentication, idempotency, batching and rate limits; see pricing for the current allowance.

Full API reference

08 / QUESTIONS

The questions that come next

What does Article 50 of the EU AI Act require?
Providers must address notices when people interact with AI and machine-readable marking of generated content. Deployers must address notices for emotion recognition and biometric categorisation, deepfake disclosures, and disclosures for certain public-interest text. The duties have specific exceptions; the provider and deployer table identifies each paragraph.
When does Article 50 apply?
Article 50 applies from 2 August 2026. For qualifying systems placed on the market before that date, the Article 50(2) marking obligation applies from 2 December 2026. That extension does not cover the other transparency duties.
Is C2PA enough?
C2PA alone does not establish compliance. Assess the overall marking and detection solution, the content format, and the applicable qualifications. The final Code and Guidelines reviewed for this page do not name C2PA.
Does Planisphere certify compliance?
No. A record can support an evidence process; it is not a legal finding or a certification.
More Article 50 questions
Our system launched last year. Do we have until December?
For the marking duty only. The new transitional gives providers of synthetic-content systems placed on the market before 2 August 2026 until 2 December 2026 to comply with Article 50(2). Everything else — the interaction disclosure, the deployer duties, the manner-and-timing rule — applies from 2 August. A system that is partly interactive and partly generative gets the extension for its marking and not for its disclosure.
Do we have to go back and mark everything we generated before?
No. There is no retroactive marking duty for outputs generated before 2 August 2026. But note one asymmetry in the guidance: text generated before that date and published on or after it does need to be labelled.
We signed the Code. Are we covered?
You are in a much better supervisory position and you have a mitigating factor available at the fining stage. You do not have a presumption of conformity, because none exists for this article, and the Commission has said adherence is not conclusive evidence of compliance. What signing does is change the question from "is your marking adequate?" to "did you adhere?" — which is a question about what you can show over a period.
Does Article 50 apply to us from outside the EU?
It reaches providers and deployers whose output is used in the Union. The guidance narrows this at the edges — incidental, unforeseeable or unauthorised downstream use should not on its own trigger the obligations — but publishing to the open internet does not obviously fall on the safe side of that line.
How does this compare with California, which starts the same day?
Different shape entirely. California binds one class of duty holder, prescribes four data elements in the disclosure, requires a public detection tool, and runs a 96-hour licence revocation clock. Article 50 splits duties between provider and deployer, prescribes no data elements, and has no detection-tool duty. California SB 942 disclosure and detection requirements

09 / PRIMARY SOURCES

Go back to the source

Read the primary text alongside the relevant guidance. Each source has a defined role in this explanation.

  • Consolidated textEU AI Act — Article 50Consolidated text dated 27 July 2026. The original and amending regulations in the Official Journal remain authoritative.

The summary and two introductory answers were checked against Commission guidance on 7 September 2026. The scoped accuracy corrections were reviewed on 9 September 2026. This layout revision does not imply a new review of every source.

ARTICLE 50 / WHERE PLANISPHERE FITS

Your team takes action.
The evidence travels with it.

Keep your content. Share verifiable records.

ILLUSTRATIVE WORKFLOW / NOT A LIVE RECORD
YOUR WORKSPACE

An AI-assisted draft

Human review
01

Your team

Reviews the content and retains the version it reviewed.

02

Planisphere

Seals the event your team submits, bound to a content hash.

PLANISPHERE / EVIDENCE

Signed record

Editorial review

Content version
Bound by its hash
Event time
Supplied by your team
Record time
Added when sealed
SIGNATURE
Independently verifiable
03

Your evidence

Inspect the event. Compare content hashes. Verify the signature.

WHEN SOMEONE ASKS WHAT HAPPENEDConnect the submitted review event to the version your team retained.

An optional evidence layer. Your team performs the review, notice or labeling; a record does not establish that an Article 50 duty was satisfied.