Article 50 Does Not Require Labelling Everything from August: It Is Split into Four Duties
TL;DR
- A simplified and false version has been circulating: that from 2 August 2026 you must label "all content" generated with AI. Article 50 of Regulation (EU) 2024/1689 does not say that in any of its paragraphs.
- Article 50 comprises four distinct obligations with two distinct roles. Paragraphs 1 and 2 bind the provider. Paragraphs 3 and 4 bind the deployer.
- Paragraph 2 does not require a visible label, but marking "in a machine-readable format": metadata, watermarks, cryptographic provenance. It is implemented by whoever builds the system, not whoever uses it.
- A company that publishes on its corporate blog a text written with AI assistance does not fall under paragraph 4: that paragraph covers text published "for the purpose of informing the public on matters of public interest", and it falls away if there is human review and editorial responsibility.
- Regulation (EU) 2026/1744 (the Digital AI Omnibus) replaced paragraph 7 and inserted a new Article 111.4: generative systems already on the market before 2 August 2026 have until 2 December 2026 to comply with paragraph 2.
- Chapter IV, where Article 50 lives, is not among what the Omnibus deferred to 2027 and 2028.
- Fine: up to €15,000,000 or 3% of worldwide business volume, whichever is higher. For SMEs, the lower (Art. 99, paragraphs 4 and 6).
Where does the myth of "label all content" come from?
From conflating three things the regulation keeps separate: the obligation to mark, the obligation to disclose, and who bears each obligation.
Article 50 is titled "Obligations of transparency of providers and deployers of certain AI systems". That word certain is not decorative. Neither is the plural: these are two roles with their own definitions in Article 3. Provider (point 3) is whoever "develops an AI system" or for whom it is developed, and "places it on the market or puts it into service the AI system under its own name or trademark, whether for payment or free of charge". Deployer (point 4) is whoever "uses an AI system under its own authority, except where its use falls under a personal non-professional activity".
A consultancy that uses an AI tool to draft documents is a deployer; the company that built and sells that tool is the provider. Article 50 distributes obligations between them surgically, so start by knowing which side you are on: I have set it up as a role decision tree under the AI Act.
Who is obliged to do what, paragraph by paragraph?
This is the complete breakdown of Article 50 as currently in force after the Omnibus.
| Paragraph | What it requires | Who is bound | From when |
|---|---|---|---|
| 50.1 | That the person knows they are interacting with an AI | Provider | 2 Aug 2026 |
| 50.2 | Mark the output in a machine-readable format | Provider (including GPAI providers) | 2 Aug 2026, or 2 Dec 2026 if the system was already on the market |
| 50.3 | Inform persons exposed to the system of how it works | Deployer | 2 Aug 2026 |
| 50.4 | Make public that the content is artificial | Deployer | 2 Aug 2026 |
| 50.5 | Form: clear, distinguishable, accessible, at the latest on first interaction | Both | 2 Aug 2026 |
| 50.6 | Compatibility with Chapter III and other obligations | Both | 2 Aug 2026 |
| 50.7 | Codes of good practice | The Commission | Since 27 Jul 2026 |
None of the cells in that table say "label all AI-generated content".
Who has to warn that someone is talking to a machine?
Paragraph 1 requires providers to ensure "that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system".
There is an exception: there is no obligation "where this is evident from the point of view of a reasonably informed, attentive and discerning natural person, taking into account the circumstances and context of use". If the widget is called "Virtual Assistant" and appears with a robot icon, that notice is already given.
And the duty is on the provider, at the design and development phase. An SME that embeds a third party's chatbot in its website, under that third party's brand, is not a provider of that system. This is where many agencies get the side wrong: if you build a chatbot on a third-party model and deliver it to your client under your own name or brand, you fit the Article 3 definition of provider. Point 68 also defines the "downstream provider" as "a provider of an AI system, including a general-purpose AI system, that integrates an AI model".
What exactly does "marked in a machine-readable format" mean?
This is the heart of the misunderstanding. Paragraph 2 states:
"Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text content, shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated."
Three consequences.
First: the recipient of the marking is a machine, not a reader. Recital 133 lists the techniques: "watermarks, metadata identification, cryptographic methods for proving the provenance and authenticity of content, logging methods, fingerprints or other techniques". None of that is a visible notice at the foot of an article.
Second: it binds the system provider, not the end user. The same recital clarifies that the solutions "may be implemented at the level of the AI system or at the level of the AI model, including general-purpose AI models generating content, thus facilitating compliance with this obligation by the downstream AI system provider". The marking flows up the value chain: if you integrate a model that already marks its output, you inherit much of the compliance.
Third: there are two express exceptions. The obligation "shall not apply to the extent that AI systems perform a standard editing function or do not materially alter the input data provided by the deployer or their semantics". The spell-checker that fixes your circular does not trigger paragraph 2. The second exception covers systems authorised by law to detect, prevent, investigate or prosecute crime.
The paragraph also modulates the requirement: the solutions must be effective, interoperable, robust and reliable "to the extent that this is technically feasible".
What if the system reads emotions or classifies by biometrics?
That is paragraph 3, and here the obliged party changes sides. Deployers of an emotion recognition or biometric categorisation system "shall inform natural persons exposed to it of its operation, and shall process personal data in accordance with Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680, as applicable".
If your company installs such a system, the obligation is yours, not that of whoever sold it to you. And watch the layering: inferring emotions from persons in the workplace or in educational settings is prohibited by Article 5.1(f). Before asking how to inform people, check whether you can use it at all.
When do you have to disclose that a video or text is artificial?
Paragraph 4 has two sub-paragraphs, and they must not be conflated.
First sub-paragraph: deepfakes. Deployers of a system that generates or manipulates "images or audio or video content constituting a deep fake shall make public that the content or images have been generated or manipulated artificially". The definition is in Article 3, point 60: image, audio or video content generated or manipulated by AI "that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful".
Notice what it does not cover: text. This sub-paragraph deals with image, audio and video. Nor does it reach a manifestly synthetic illustration that nobody would mistake for a real photograph.
Where the content "forms part of an evidently artistic, creative, satirical or fictional work or programme", the obligation is limited to making public the existence of that content "in an appropriate manner that does not hinder the display or enjoyment of the work".
Second sub-paragraph: text of public interest. This is the most widely misquoted one. It requires disclosure that the text has been artificially generated or manipulated when it is published "for the purpose of informing the public on matters of public interest". This falls away in two cases: where the use is authorised by law for the purpose of ensuring compliance with law, and "where the AI-generated content has been subject to a human review or editorial process and where a natural or legal person bears editorial responsibility for the publication".
Translated into a communications agency or a corporate blog: if someone made of flesh and blood reviews the piece and the company assumes editorial responsibility, the disclosure obligation in this sub-paragraph does not trigger. And a product data sheet or a commercial note is not, as a starting point, information to the public on matters of public interest.
What did the Omnibus change in Article 50?
Two things, and one of them is a real deadline.
Point 20 of the Digital AI Omnibus replaces paragraph 7. Previously the AI Office led it; now it is the Commission that "shall encourage and facilitate the development of codes of good practice at Union level to contribute to the effective application of the obligations relating to the detection, marking and labelling of artificially generated or manipulated content". It will assess whether observing them is sufficient to comply with paragraphs 2 and 4, and if it finds them inadequate it may adopt an implementing act with common rules. Recital 41 explains the adjustment: these codes "have limited legal effect and, in particular, do not confer a presumption of conformity".
Point 39 adds a new Article 111.4, which is the one giving industry some breathing room:
"4. Providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video or text content and have been placed on the market before 2 August 2026 shall take the necessary measures to comply with the provisions of Article 50, paragraph 2, by 2 December 2026 at the latest."
Recital 38 describes this as "a transitional period of four months". If your product is already on the market and generates synthetic content, that is your deadline. If you launch it after 2 August 2026, it is born with the obligation.
What did not change: Chapter IV does not appear among the deferred provisions. Point 40 rewrites paragraph 3 of Article 113 and moves to December 2027 and August 2028 Chapter III, Sections 1, 2 and 3 — the high-risk regime. The Article 50 transparency obligations stay where they were: the full map of what did move is in the analysis of Regulation (EU) 2026/1744.
What belongs to my company and what to my software vendor?
Four typical scenarios.
| Situation | Your role | Your obligation under Art. 50 |
|---|---|---|
| You embed a third party's chatbot, under the third party's brand | Deployer | None under 50.1: that is the provider's. Verify the notice exists |
| Your agency delivers a bespoke assistant to the client, built on a third-party model | Provider (and downstream provider, Art. 3.68) | 50.1 and, if it generates synthetic content, 50.2 |
| You use a generative tool to draft texts that you review and sign off | Deployer | 50.2 is the provider's. 50.4, second sub-paragraph, falls away with human review and editorial responsibility |
| You publish a video with the face or voice of a real person recreated by AI | Deployer | 50.4, first sub-paragraph. Attenuated if it is a manifestly creative, satirical or fictional work |
In all cases paragraph 5 applies: the information is provided "in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure". A notice buried in the privacy policy does not comply.
How much does non-compliance cost?
Article 99, paragraph 4, point (g), includes "the transparency obligations of providers and deployers pursuant to Article 50" among infringements penalised by fines of up to €15,000,000 or, if the infringer is a company, up to 3% of its total worldwide annual turnover "if this amount is higher". For SMEs and start-ups, paragraph 6 inverts the comparison: the percentage or amount is applied "whichever of them is lower".
What to do before 2 August
- Determine your role for each system, not per company. The same organisation can be a provider for one product and a deployer for five others: run each one through the role decision tree.
- Ask your generative software vendors in writing whether their output is marked in a machine-readable format in accordance with Article 50.2, and whether they invoke the Article 111.4 transitional period. Keep the reply.
- Review published chatbots: the Article 50.1 notice must be visible on first interaction.
- Set a written editorial rule: who reviews and who bears editorial responsibility. That is what activates the Article 50.4, second sub-paragraph, exception — and without written evidence it cannot be demonstrated.
- Keep a separate inventory of deepfakes: any piece featuring real people, places or events recreated by AI falls under Article 50.4, first sub-paragraph.
Frequently asked questions
Do I have to put "generated with AI" on my corporate blog texts?
Article 50 does not generally require it. Paragraph 2 requires the system provider to apply machine-readable marking, not the user to add a label. Paragraph 4, second sub-paragraph, only reaches text published "for the purpose of informing the public on matters of public interest", and it falls away with human review and editorial responsibility.
Does the 2 December 2026 deadline apply to me as a user?
No. Article 111.4 is a transitional rule for providers of generative systems already on the market before 2 August 2026, and only in respect of Article 50.2. Paragraphs 3 and 4, which apply to the deployer, have no such deferral.
Is Article 50 deferred to 2027 like the rest of the AI Act?
No. The Omnibus deferred Chapter III, Sections 1, 2 and 3 (the high-risk regime) to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I systems. Article 50 is in Chapter IV and remains at 2 August 2026.
If my chatbot makes it clear it is a bot through its very design, am I still obliged?
Paragraph 1 excepts cases that are evident "from the point of view of a reasonably informed, attentive and discerning natural person". An assistant identified as such fits. Even so, document why you consider it evident: the burden of justifying it is yours.
Does marking content exempt me from high-risk obligations?
No. Paragraph 6 says this expressly: paragraphs 1 to 4 "shall not affect the requirements and obligations set out in Chapter III". They are independent layers, and Recital 137 adds that complying with transparency does not make the use of the system lawful.
Who sanctions this in Spain?
The national sanctioning regime is still being drafted and is not yet law. The Draft Organic Law on the sound use and governance of artificial intelligence was published in the BOCG on 12 June 2026, pre-dates the Omnibus, and is subject to amendments.
Sources
- Regulation (EU) 2024/1689 (AI Regulation). Articles 3 (points 3, 4, 60 and 68), 5, 50, 99 and 113; Recitals 132–137. data.europa.eu
- Regulation (EU) 2026/1744 (Digital AI Omnibus). OJEU Series L, 2026/1744, 24 July 2026. Points 20, 39 and 40; Recitals 38, 40 and 41. data.europa.eu
- Regulation (EU) 2016/679 (GDPR), to which Article 50.3 refers. data.europa.eu
- Draft Organic Law on the sound use and governance of artificial intelligence. BOCG, Congress, Series A, No. 97-1, 12 June 2026. congreso.es