AI Act Disclosure Kit

← All guides

Article 50 by product type: what chatbots, content generators and deep-fake tools each must do

Last updated 2 August 2026

Article 50 of Regulation (EU) 2024/1689 applies since 2 August 2026, but it does not hit every AI product the same way. A customer-support chatbot, an image generator and a face-swap app each trigger a different mix of paragraphs — and the split between provider duties (design-time) and deployerduties (use-time) is where most teams get confused. This guide sorts it by product type, using the Commission's FAQ and Guidelines on Transparency of AI-Generated Content (July 2026). Want the answer for your product without reading it all? Run the free 3-minute check.

First, know your role: provider vs deployer

  • Provider — you develop the AI system (or have it developed) and place it on the EU market under your own name or trademark, wherever you are established. Duties: Article 50(1), (2) and (5), before the system goes to market.
  • Deployer— you use an AI system under your authority in a professional context. Duties: Article 50(3) and (4). Purely personal, non-professional use is outside the AI Act — but regular economic benefit makes it professional, per the Commission's FAQ.
  • Many SaaS companies are both — provider of the feature they ship, deployer of the third-party AI they run internally. Classify each system separately; the applicability guide covers edge cases.

Product type 1: chatbots, AI agents and avatars

Core duty: Article 50(1) disclosure, by design. Systems that interact directly with natural persons must be designed and developed so that people are informed they are interacting with AI — unless it is obvious to a reasonably well-informed, observant and circumspect person. The guidelines make this concrete with four cumulative criteria:

  1. the system qualifies as an AI system;
  2. it is designed for a genuine two-way exchange — not mere data collection or fixed automated responses;
  3. the interaction is direct: the AI itself communicates with the person, not through a human intermediary;
  4. the counterpart is a natural person.

The notice must come at the start of the first interaction, clearly and distinguishably, and meet accessibility requirements. Background systems and machine-to-machine communication are out of scope. Implementation patterns, wording and screenshots: chatbot disclosure examples and is my chatbot covered? Voice agents add a timing wrinkle — disclose before the conversation gets going.

If your chatbot also generates content (it almost certainly does — text, images), the Article 50(2) marking duty below applies to those outputs too.

Product type 2: content generators (text, image, audio, video)

Core duty: Article 50(2) machine-readable marking, by the provider. Outputs must be marked in a machine-readable format and detectable as artificially generated or manipulated, with marks that are effective, reliable, robust and interoperable as far as technically feasible. In practice that means C2PA Content Credentials, invisible watermarks, or both — the implementation checklist compares the techniques per content type. You can try C2PA signing in the free playground right now.

Key scoping points from the Commission's guidance:

  • Assistive / standard editing is exempt — AI that helps with routine edits does not trigger marking; the guidelines give practical examples of where standard editing ends.
  • Machine-to-machine outputs without human exposure, short sequences of numbers/symbols/letters and source code are not covered.
  • Closed-loop industrial and product-development uses are exempt unless they are the final output, and a narrow B2B / industrial-context exemption exists under the guidelines' conditions.
  • Timing: systems placed on the market before 2 August 2026 must comply with 50(2) from 2 December 2026 countdown and who qualifies. Everything else applied on 2 August 2026.

If you build on someone else's model: you may still be the provider of your system. Establish what marking your model supplier already applies and close the gap at your boundary — the vendor due-diligence questions cover exactly this.

Product type 3: deep-fake and synthetic-media tools

Deep fakes are defined in Article 3(60): AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful. The guidelines set three cumulative criteria — resemblance, an existing (or plausibly existing) subject, and the capacity to deceive about authenticity — assessed in context: the substantive message, the deployment context, and what the foreseeable audience expects. Standard movie special effects, for example, are unlikely to falsely appear authentic to their audience.

  • Provider of the generating tool: Article 50(2) machine-readable marking of the outputs, as above — no deep-fake carve-out.
  • Deployer publishing the content: Article 50(4) requires visible disclosure that the content has been artificially generated or manipulated, upon first exposure. For evidently artistic, creative, satirical or fictional works, disclosure is limited to an appropriate manner that does not hamper enjoyment of the work.
  • AI-generated text on matters of public interest published without human review or editorial control must also be labelled by the deployer (Article 50(4)) — how to label AI content correctly.
  • Personal use is out of scope— but the Commission's FAQ is explicit that regularly monetised or business-related use makes a natural person a deployer.

One table to take away

  • Chatbot / AI agent: 50(1) disclosure by design (provider) + 50(2) marking of generated outputs (provider).
  • Content generator: 50(2) machine-readable marking (provider); exemptions for standard editing, M2M, code, closed-loop industrial.
  • Deep-fake tool: 50(2) marking (provider) + 50(4) visible labelling on publication (deployer); artistic-work light-touch regime.
  • Emotion recognition / biometric categorisation: 50(3) — deployers must inform exposed persons; not covered further here, see Article 50 clause by clause.

What happens if you get it wrong

Article 50 breaches carry fines up to EUR 15,000,000 or 3% of total worldwide annual turnover (Article 99(4)(g)), enforced by national market surveillance authorities since 2 August 2026 — who enforces in each country. The practical defence is dated evidence of what you disclosed, marked and labelled, and when. Run the free check to get a dated obligations report for your product, use the policy and disclosure templates to close gaps, and see plans for continuous evidence packs.

This tool and its content are provided for general information only and do not constitute legal advice. Consult a qualified lawyer for advice on your specific situation. Primary source: Regulation (EU) 2024/1689 (EU AI Act), Official Journal of 13 June 2024 — EUR-Lex.

Not sure which obligations apply to you?

Run the free 3-minute Article 50 check