The European Commission has published final guidance on one of the most visible obligations introduced by the EU AI Act: people must be able to recognise when they are interacting with an AI system or encountering certain forms of AI-generated content.
The guidance was published on 20 July 2026, less than two weeks before the transparency requirements under Article 50 begin to apply on 2 August. The development was also reported by Digi24, while the European Commission’s final Article 50 guidelines provide the authoritative interpretation of the legal scope, exemptions and implementation expectations.
The rules apply to interactive AI systems, generative tools, deepfakes, emotion-recognition applications and biometric-categorisation systems. They also cover certain AI-generated or manipulated text published to inform the public about matters of public interest.
For companies, Article 50 requires coordinated changes across product design, customer communication, content production, supplier management and compliance. A notice placed in a privacy policy will rarely solve the entire problem. Organisations need to determine where AI interacts with people, what content it produces, who reviews that content and which party is responsible for each disclosure.
What changes on 2 August 2026
Under the official text of Article 50 of the EU AI Act, providers must design AI systems intended to interact directly with natural persons so that individuals are informed that they are communicating with AI.
The notice should be presented clearly and at an appropriate point in the interaction. It should also meet applicable accessibility requirements. The obligation may not apply where the artificial nature of the interaction is obvious to a reasonably informed and observant person, taking account of the context.
The European Commission’s Article 50 questions and answers provide additional guidance on how providers and deployers should interpret the rules. In practice, organisations should apply the “obvious interaction” exception carefully. Modern interfaces may use natural language, synthetic voices, realistic avatars and personalised responses, making it difficult for users to determine whether a human is involved.
Customer-service chatbots, recruitment assistants, AI sales representatives, healthcare support tools and public-service interfaces may therefore require a direct notice such as: “You are interacting with an AI system.” Expressions such as “digital assistant” or “automated support” may be too vague where they do not clearly communicate the nature of the system.
The position of the notice matters. Users should receive the information when the interaction begins, rather than discovering it later in the terms of service or privacy documentation.
Synthetic content, deepfakes and public-interest information
Providers of systems capable of generating synthetic audio, images, video or text must support the detection of that content as artificially generated or manipulated. Article 50 requires machine-readable marking that is effective, interoperable, robust and reliable, as far as technically feasible.
The appropriate technical method may vary according to the content and the system. Metadata, content credentials, provenance records, watermarks and other detection mechanisms may form part of the implementation. The Code of Practice on Transparency of AI-Generated Content provides a voluntary implementation framework for these marking and labelling duties. The Commission and the AI Board have confirmed that the Code is an adequate instrument for supporting compliance, although signing it does not create conclusive evidence that every legal requirement has been satisfied.
Deployers also carry direct responsibilities. Professional users of AI systems must disclose deepfakes when the material is presented to natural persons. The disclosure should be visible or audible to the audience. A technical marker hidden inside metadata does not replace a public-facing notice where the deployer is required to inform viewers or listeners.
This obligation has direct consequences for broadcasters, advertising agencies, political organisations, marketing teams, film producers, social-media publishers and companies using synthetic presenters or cloned voices.
Creative, artistic, satirical and fictional works receive more flexible treatment. The disclosure may be adapted to avoid unnecessarily disrupting the work, but the audience must still be informed that generated or manipulated material is present.
Article 50 also addresses AI-generated or manipulated text published to inform the public about matters of public interest. This may include content relating to politics, public administration, justice, public health, financial markets, consumer protection, science, environmental policy and other subjects that contribute to public debate.
The disclosure obligation does not apply where the text has undergone human review or editorial control and a natural or legal person accepts editorial responsibility for the publication.
For media organisations, consultancies and corporate communications teams, this exemption depends on the quality of the review. A grammar check or superficial approval provides limited evidence of editorial control. A credible process should allow a qualified reviewer to verify sources, challenge unsupported claims, amend the material and reject publication.
Organisations using AI during drafting should retain evidence showing who reviewed the content, what checks were completed and who approved the final version.
Emotion recognition and biometric categorisation
Deployers of emotion-recognition and biometric-categorisation systems must inform the individuals exposed to those systems.
Potential applications include workplace analytics, audience measurement, retail monitoring, education, security screening and customer research. The transparency requirement applies alongside the General Data Protection Regulation, employment law, equality rules and any sector-specific requirements.
Providing a notice does not establish that the underlying use is lawful. Certain applications may be restricted or prohibited under the AI Act or other legislation. Organisations should therefore assess the purpose, necessity, proportionality, data sources, retention arrangements, access controls and potential consequences of an incorrect categorisation.
Provider and deployer responsibilities
The Commission’s guidance distinguishes between providers and deployers.
A provider develops an AI system, has one developed or places it on the European market under its own name or trademark. The AI Act may also apply to providers established outside the EU where the output of their systems is used within the Union.
A deployer uses an AI system under its authority in a professional context. The same organisation may perform both roles. A company that substantially modifies a third-party system or markets it under its own brand may acquire provider responsibilities alongside its deployer obligations.
Providers are generally responsible for the design of direct-interaction notices and the implementation of machine-readable marking. Deployers are responsible for disclosures relating to deepfakes, public-interest text, emotion recognition and biometric categorisation within their operational context.
Contracts between model providers, software vendors, integrators, agencies and customers should allocate implementation responsibilities clearly. They should address marking functionality, disclosure controls, system updates, evidence retention, incident support and cooperation with competent authorities.
Contractual allocation can reduce operational ambiguity, but it cannot remove statutory responsibility.
The deadline and the limited transition period
The Article 50 transparency obligations apply from 2 August 2026.
The Commission’s official implementation Q&A confirms a limited transition period for systems placed on the market before 2 August 2026. This accommodation applies only to the machine-readable marking and detection obligation for AI-generated content. Providers of those existing systems have until 2 December 2026 to implement the relevant measures.
The transition period does not represent a general postponement of Article 50. Direct-interaction notices, deepfake disclosures, public-interest content requirements and the other applicable transparency duties begin to apply on 2 August.
Content generated before that date does not have to be labelled retrospectively, although the Commission encourages voluntary labelling where feasible.
The implementation risk lies in fragmented ownership. Product teams may expect legal departments to supply the required language. Communications teams may assume that vendors already provide compliant markings. Procurement teams may lack information about content-provenance capabilities. Compliance functions may not know which AI systems are already active in customer-facing channels.
What organisations should do now
The first step is to identify every AI system that communicates directly with customers, employees, applicants, patients, citizens or other individuals. The inventory should also cover tools that generate or manipulate text, audio, images and video.
For each system, the organisation should establish its role as provider, deployer or both. It should identify the applicable Article 50 obligation, the responsible business owner, the technical control, the required disclosure and the evidence that must be retained.
Customer-facing notices should be tested across websites, mobile applications, messaging platforms, telephone systems and embedded third-party tools. Multilingual and accessibility requirements should form part of this assessment.
Content-production workflows require equivalent scrutiny. Organisations should determine whether generative tools preserve machine-readable markings after editing, compression, export or publication. They should also define visible disclosure standards for deepfakes, synthetic voices, avatars and manipulated video.
Public-interest content should follow a documented editorial process. Reviewers must have sufficient knowledge and authority to verify the substance, correct the material and reject publication. Approval records should identify the reviewer and the person or entity accepting editorial responsibility.
Supplier due diligence should examine marking functionality, data processing, subcontractors, product updates, interoperability, technical limitations and support for regulatory enquiries. Contracts should specify which party maintains each transparency control and what happens when the provider changes the system.
Useful compliance evidence includes system inventories, screenshots of interaction notices, technical test results, supplier documentation, editorial approvals, policy decisions and written assessments explaining why an exemption was considered applicable.
Enforcement and financial exposure
National market-surveillance authorities will carry most of the responsibility for enforcing Article 50. The AI Office has a more limited role in relation to certain systems built on general-purpose AI models, while the European Data Protection Supervisor will supervise systems used by EU institutions and bodies.
According to the Commission’s Article 50 enforcement guidance, non-compliance may result in administrative fines of up to €15 million or 3% of total worldwide annual turnover for the preceding financial year. Proportionality considerations apply to smaller organisations.
The financial penalty represents one part of the exposure. Undisclosed synthetic content and unclear AI interactions may also generate consumer-law disputes, reputational damage, misinformation risks, contractual claims and scrutiny under data-protection or sector-specific rules.
The ISAD.ai perspective
Article 50 converts transparency into an operating capability.
A compliant organisation needs an accurate system inventory, reliable use-case classification, clear provider and deployer responsibilities, technical marking, visible disclosures, accountable editorial review and evidence that can withstand regulatory examination.
A practical control model can be organised around four stages:
AI inventory → use-case classification → transparency control → evidence and monitoring
The inventory establishes which systems exist and who owns them. Classification determines which obligations may apply. The control layer introduces notices, technical markings, editorial review or public disclosure. Monitoring confirms that these controls remain effective after product updates, supplier changes and new deployment scenarios.
This structure should form part of a broader AI governance framework covering risk assessment, data governance, third-party oversight, incident management, human accountability and employee training.
How ISAD.ai can support organisations
ISAD.ai can support providers and deployers through an AI Transparency Readiness Assessment covering system inventories, provider and deployer classification, Article 50 applicability, chatbot notices, synthetic-content marking, deepfake disclosures, public-interest editorial controls, supplier arrangements, evidence requirements and implementation planning.
The assessment can be integrated with wider AI Act readiness, AI inventory development, AI risk assessment, third-party governance and AI literacy programmes.
Conclusion
The Commission’s July 2026 guidance gives organisations a clearer basis for implementing the transparency requirements under Article 50. It also confirms that compliance extends across product architecture, content workflows, supplier governance and executive accountability.
The 2 August 2026 deadline requires immediate action. Organisations should identify relevant systems and content, introduce the appropriate notices and markings, formalise editorial review and retain evidence supporting their compliance decisions.
Transparency will increasingly influence customer trust, regulatory exposure and the credibility of digital communications. Companies that establish disciplined controls now will be better positioned as AI becomes more deeply integrated into customer service, marketing, media and operational processes.
Does your organisation know where AI interacts with people or shapes public-facing content?
Request an AI Transparency Readiness Assessment from ISAD.ai to identify Article 50 obligations, close implementation gaps and establish an auditable compliance framework.


