Article 50 duty map: which sub-article binds the provider, which binds the deployer
Article 50 of Regulation (EU) 2024/1689 applies from 2 August 2026 and does not care what risk tier your system sits in. A customer-support chatbot that clears every Annex III use case still owes Art 50(1). An image generator nowhere near the high-risk regime still owes Art 50(2). Open-sourcing does not rescue you either: the Article 2(12) exclusion for free and open-source AI systems falls away for anything subject to Article 50.
The common failure is not missing a duty. It is owing the wrong one. Article 50 splits by role, cleanly. 50(1) and 50(2) are provider duties, discharged in how the system is designed and how its outputs are produced. 50(3) and 50(4) are deployer duties, discharged at the point of use, by whoever puts the system in front of real people. Buying a compliant product does not discharge a deployer duty. Shipping a compliant product does not discharge a duty that attaches to what your customer does with it.
| Sub-article | Duty | Binds | Trigger | Main exception | Applies from |
|---|---|---|---|---|---|
| 50(1) | Design the system so the person is informed they are interacting with an AI | Provider | System intended to interact directly with natural persons | AI nature obvious to a reasonably well-informed, observant and circumspect person; law enforcement | 2 Aug 2026 |
| 50(2) | Mark output in a machine-readable format, detectable as artificially generated or manipulated | Provider | System generates synthetic audio, image, video or text | Assistive function for standard editing, or no substantial alteration of input data or its semantics; law enforcement | At placement from 2 Aug 2026; 2 Dec 2026 for systems already on the market before that date |
| 50(3) | Inform the exposed persons of the operation of the system, and process personal data in line with GDPR | Deployer | Emotion recognition or biometric categorisation system | Law enforcement | 2 Aug 2026 |
| 50(4), first limb | Disclose that image, audio or video content has been artificially generated or manipulated | Deployer | The content constitutes a deepfake | Evidently artistic, creative, satirical or fictional work: disclosure limited to a form that does not hamper enjoyment | 2 Aug 2026 |
| 50(4), second limb | Disclose that published text was artificially generated or manipulated | Deployer | Text published to inform the public on matters of public interest | Human review or editorial control, with a natural or legal person holding editorial responsibility | 2 Aug 2026 |
| 50(5) and 50(6) | Make the disclosure clear, distinguishable and accessible, at the latest at first interaction or exposure | Both | Any duty above | None. Duties apply cumulatively and without prejudice to Chapter III and other transparency law | 2 Aug 2026 |
Picture a marketing team that generates a synthetic spokesperson video with a third-party tool. The vendor owes the 50(2) machine-readable marking on the output. The marketing team owes the 50(4) deepfake disclosure to the viewer. Neither substitutes for the other, and under 50(5) and 50(6) they stack. Before you settle on which side of that line you are on, confirm your role: putting your name on a system, or changing its intended purpose, can make you its provider, and the Article 25 flip in particular turns on the system being or becoming high-risk. See how the Article 25 role flip works.
Article 50(1): the AI chatbot disclosure requirement is a design duty, not a banner
Systems intended to interact directly with natural persons must be designed and developed so that the persons concerned are informed they are interacting with an AI system. Read the verb: designed. The obligation attaches to the provider at build time, not to whoever bolts a notice on at the end. If you licence a white-label conversational agent and place it on the market under your own name or trademark, you may already be the provider on the Article 3(3) definition rather than a deployer, and the 50(1) design duty comes with that. Note that the Article 25 name-or-trademark flip is a separate mechanism and applies only to high-risk systems, so for an ordinary chatbot the question turns on who places the system on the market under whose name.
The obviousness exception is narrower than it reads
The duty falls away where the AI nature is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use. That is a contextual test, not a general excuse. A widget explicitly presented as an AI assistant inside a product console is a plausible case. A synthetic voice that answers an inbound phone line and introduces itself with a human name is not, and the conservative reading is that anything voice-based or anything reaching consumers who did not choose to open an AI tool should carry the disclosure. There is also a narrow exception for AI systems authorised by law to detect, prevent, investigate or prosecute criminal offences.
Timing comes from Art 50(5): the information must be given at the latest at the time of the first interaction. A disclosure buried in terms of service, or surfaced only after the user has typed three messages, does not meet that.
Article 50(2): machine-readable marking of synthetic content, and where AI watermarking fits
Providers of AI systems that generate synthetic audio, image, video or text must ensure the outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The technical solutions have to be effective, interoperable, robust and reliable, as far as that is technically feasible given the specificities and limitations of the content type, the cost of implementation and the generally acknowledged state of the art. Those four adjectives are the whole compliance test.
This is a provider duty and it reaches general-purpose models used as generative systems, so if you fine-tune or host a model and expose it to users you should read it alongside the Article 53 and Article 55 duties on GPAI model providers. Two exceptions matter commercially. The first is where the system performs an assistive function for standard editing. The second is where the system does not substantially alter the input data or its semantics. Auto-levels on a photograph, noise reduction on an audio take, a grammar correction that leaves the meaning intact: these are the intended targets. Regenerating a background, replacing a face, or rewriting a paragraph into new claims is not standard editing, and the exception does not stretch to cover it. A law-enforcement exception also applies.
The 2 December 2026 date is the single most misread thing on this page. It is a transitional accommodation for generative systems already on the market before 2 August 2026. Anything you place on the market from 2 August 2026 onwards has to carry compliant marking from placement, with no grace at all. If you read the headline as extra build time for an unreleased product, you have read it backwards. See what actually applies on 2 August 2026.
Article 50(3): emotion recognition and biometric categorisation notice is a deployer duty
Deployers of an emotion recognition system or a biometric categorisation system must inform the natural persons exposed to it of the operation of the system, and must process personal data in accordance with the GDPR and related instruments. The duty sits with whoever runs the system in a real setting, which in practice means the employer, the retailer, the venue or the call centre rather than the software vendor. A law-enforcement exception applies.
Before you design the notice, check whether the use case is permitted at all. Article 5 prohibits emotion recognition in the workplace and in education outright, subject to medical and safety exceptions, and prohibits biometric categorisation that infers sensitive traits. If your candidate use case is sentiment scoring of employees on calls, the question is not what the notice should say - it is whether the practice is banned and therefore sitting in the €35,000,000 or 7% tier. Run it through the free seven-stage triage before you build the disclosure.
Article 50(4): deepfake disclosure in the EU and AI-generated text on matters of public interest
Deepfakes: image, audio and video
Deployers of an AI system that generates or manipulates image, audio or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated. This is the duty that reaches marketing teams, agencies, political campaigns and anyone publishing a synthetic likeness. It is aimed at the human audience, which is why it is separate from the machine-readable marking under 50(2), and why complying with one tells you nothing about the other.
Where the content is evidently artistic, creative, satirical or fictional, or part of an analogous work or programme, the obligation is limited to disclosing in an appropriate manner that does not hamper the display or enjoyment of the work. Note what that is: a limit on the form of the disclosure, not an exemption from it. A satirical short film still has to say so somewhere; it just does not have to stamp a label across the frame.
Text published to inform the public
The second limb of 50(4) is narrower than people assume and catches a specific pattern: deployers who publish AI-generated or manipulated text for the purpose of informing the public on matters of public interest must disclose that it was artificially generated or manipulated. Ordinary commercial copy, product descriptions and internal drafting are outside it.
The exception has two limbs and you need both. The obligation does not apply where the AI-generated content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication. A newsroom that runs an AI first draft past a named editor who owns the copy is covered. A pipeline that publishes model output straight to a public-affairs blog with nobody accountable for it is not, and a rubber-stamp check with no identifiable owner of editorial responsibility fails the second limb even if it passes the first.
Article 50(5) and 50(6): how the disclosure has to land, and what it does not displace
Article 50(5) sets the quality bar for every duty above. The information must be provided to the persons concerned in a clear and distinguishable manner at the latest at the time of the first interaction or exposure, and it must conform with the applicable accessibility requirements. Three practical consequences follow. Disclosure has to be perceivable, so a visual-only label on an audio deepfake is not enough. It has to be up front, so post-hoc notices fail. And it has to be distinguishable from ordinary interface chrome, so a grey footnote in the same weight as boilerplate is weak.
Article 50(6) confirms the duties are without prejudice to the requirements and obligations set out in Chapter III and other Union or national transparency law. A high-risk system does not escape Articles 9 to 15 because it complied with Article 50, and Article 50 compliance does not answer GDPR transparency. Where several sub-articles apply to the same product, they apply cumulatively: a deployed emotion recognition kiosk that also talks to people owes both the 50(3) notice and, from its provider, the 50(1) design duty.
The Code of Practice on transparency of AI-generated content: multi-layered marking and the 200-token line
The final version of the Code of Practice on transparency of AI-generated content was published on 10 June 2026, after draft Article 50 guidelines on 8 May 2026 and a consultation that closed on 3 June 2026. It is voluntary. It is also, realistically, the compliance route you will be measured against, because Article 50(2) gives you four adjectives and the Code gives you a method.
The two-layer rule
The Code requires multi-layered marking: at least two layers where a single technique cannot meet all four criteria of effective, interoperable, robust and reliable. The logic is failure tolerance: a perceptual watermark that does not survive re-encoding is not robust on its own, and provenance metadata that any transcode strips is not robust either. If you assert that a single technique satisfies all four criteria, expect to have to evidence that, and document the assessment the same way you would any other conformity decision.
Where the marking expectation stops
Two exceptions are carved out of the Code: generative systems embedded in closed physical products, and free-form text. The text carve-out is thresholded rather than absolute. Watermarking applies to free-form text longer than 200 tokens; very short outputs below that threshold are exempt, because there is not enough signal to carry a reliable mark. Do not read the threshold as a licence to chunk long outputs into short ones.
| Case | What the Code expects | Where it stops |
|---|---|---|
| Synthetic image, audio, video | Multi-layered marking: at least two layers where one technique cannot meet all four criteria | Single layer only where it demonstrably meets effective, interoperable, robust and reliable |
| Free-form text | Watermarking for outputs longer than 200 tokens | Outputs of 200 tokens or fewer are exempt |
| Generative system in a closed physical product | Outside the marking expectation of the Code | The exception is the product form, not the content type |
| Detection interoperability | Marks must be detectable across the ecosystem, not only by your own tooling | Bites from 2 February 2027, after both marking start points (at placement from 2 Aug 2026, or 2 Dec 2026 for the pre-existing installed base) |
That last row is the one to put in the plan now. The detection interoperability obligation under the Code applies from 2 February 2027. A proprietary mark that only your own detector can read may satisfy the bare 50(2) wording at first, whether your marking duty starts at placement from 2 August 2026 or on 2 December 2026 for the pre-existing installed base, and then fails once interoperability bites on 2 February 2027, so build for a published, checkable format the first time rather than retrofitting.
Your Article 50 checklist before 2 August 2026, and what a breach costs
Work the duties in role order. First, list every system you provide and test each against 50(1) and 50(2). Second, list every system you deploy and test each against 50(3) and 50(4), including tools your teams adopted without procurement. Third, for each duty you owe, record the trigger, the exception you are relying on and the evidence for it, because an exception you cannot evidence is an exception you do not have. Fourth, check the 50(5) quality bar on every disclosure you already ship.
A breach of Article 50 sits in the middle Article 99 tier: €15,000,000 or 3% of total worldwide annual turnover, whichever is higher for a company, and whichever is lower for SMEs and start-ups under Article 99(6). Penalties have been enforceable since 2 August 2025, so the machinery is already live when the duties start. The full breakdown of the three Article 99 tiers sets out which breach lands where. Primary text is on EUR-Lex and the Commission maintains its AI regulatory framework pages, including the transparency work.