The AI Act's transparency rules, Article 50, have been enforceable since 2 August 2026. On 20 July the European Commission published the final guidelines that explain how to comply: 51 pages, replacing a May draft. Breaches can cost up to €15 million or 3% of worldwide turnover, whichever is higher.
If your business runs a website chatbot, publishes AI-generated images or video, or posts AI-written articles, this applies to you. Our earlier guide for small businesses covered the basics. This article covers what the final guidelines settled, what is still deferred, and where the GDPR adds its own test.
Four duties, and who carries them
Article 50 has four strands. Two fall mainly on providers, the companies that build AI systems, and two on deployers, the organisations that use them:
| Duty | Who | What it requires |
|---|---|---|
| Tell people they are dealing with AI (50(1)) | Provider | Design the system so people are informed, unless it is obvious to a reasonably well-informed, observant and circumspect person |
| Mark AI-generated content (50(2)) | Provider | Mark synthetic audio, images, video and text in a machine-readable format so it can be detected as AI-generated |
| Emotion recognition and biometric categorisation (50(3)) | Deployer | Inform the people exposed to the system, and process their data in line with the GDPR |
| Deepfakes and AI text on public-interest matters (50(4)) | Deployer | Disclose that content is AI-generated or manipulated; for text, unless a human has reviewed it and someone holds editorial responsibility |
Most small businesses are deployers: they use someone else's chatbot or image generator. Stibbe notes, though, that a “provider” includes anyone who puts a system into service under their own name, and that deployers stay responsible when a third party runs a system for them under their responsibility and control.
Chatbots: “obvious” is a narrow exit
The disclosure has to reach people clearly, at the latest at their first interaction (Article 50(5)). The only general exception is where it is obvious that they are dealing with AI. Legalithm reads the final guidelines as keeping that exception narrow: a fluent, human-sounding support bot does not qualify, and if visitors might plausibly believe they are talking to a person, disclosure is required.
- Say it in the first message. Not in a footer or on a terms page.
- Don't dress the bot as a person. A human first name and a stock-photo avatar work against the disclosure.
- Remember the GDPR. Whatever the bot does with the conversations still needs a lawful basis and a clear privacy notice. See why your AI chatbot isn't anonymising anything.
AI content: marking is the vendor's job, labelling is yours
Providers must mark AI-generated audio, images, video and text so that machines can detect them. The final guidelines do not mandate a single technology. Paul Weiss reports that they expect a layered approach, such as metadata plus watermarking, because no single technique currently meets the Act's standard. Legalithm's reading is content credentials (C2PA) for images, video and audio, watermarking as a complementary layer, and metadata for text.
For most businesses that is a question for your vendors: ask whether the tools you use mark their output. The deployer duties are yours:
- Deepfakes. The test is objective: content is a deepfake if it looks plausibly real, and intent to deceive is not needed (Paul Weiss). Clearly fantastical content, such as flying dragons, falls outside (Bird & Bird). Commercial or purely informative deepfakes cannot use the lighter labelling that applies to artistic works (Bird & Bird).
- Text on public-interest matters. Disclose the AI origin unless a person has genuinely reviewed it and holds editorial responsibility. Rubber-stamping does not count (Legalithm), and Paul Weiss advises keeping documented editorial workflows.
- What is exempt. Assistive tools such as grammar checkers fall outside. Faegre Drinker reports that AI-generated translations now count as standard editing. Content generated before 2 August 2026 needs no retroactive label: the generation date counts for images, audio and video, the publication date for text.
Faegre Drinker adds that the final version widens the territorial reach: deepfake labelling applies to content that is accessible globally and reaches EU audiences, wherever it was made.
What is deferred, and what is not
Only one duty got extra time. Under the AI Omnibus, providers of generative systems placed on the market before 2 August 2026 have until 2 December 2026 to add machine-readable marking (Article 50(2)). Gibson Dunn stresses that the rest of Article 50, including chatbot disclosure and the deployer labelling duties, proceeds as scheduled from 2 August.
Separately, signatories of the voluntary Code of Practice on transparency of AI-generated content, which the Commission and the AI Board have confirmed as adequate, must have watermark-detection interoperability in place by 2 February 2027. The Commission says adherence to the Code can demonstrate compliance and that equivalent alternatives are allowed. Legalithm cautions that it is evidence of good faith rather than immunity.
Where the GDPR adds its own test
Article 50 does not replace other transparency rules, and an early enforcement example came from a data protection authority. On 23 July 2026, Italy's Garante warned the broadcaster R.T.I. over AI-altered satirical clips of the journalist Enrico Mentana aired on Striscia la Notizia, announcing the decision on 7 August. It found that the on-screen notices about the artificial nature of the videos were not clear or prominent enough for every viewer, including people watching on social media, given how realistic the clips were. It cited Article 5 (lawfulness, fairness, transparency) and Article 25 (data protection by design), banned further use of his data in that way, and imposed no fine.
The lesson is that a label which exists but fails the viewer is not enough. Both regimes look at how the disclosure is presented, and Article 50(3) expressly requires GDPR-compliant processing for emotion recognition and biometric categorisation.
GDPRChat is an AI customer chat widget built with Article 7 consent gates and automatic data deletion — compliance built into the architecture, not bolted on after a regulator starts asking questions.
A checklist for this week
- Inventory every AI touchpoint. The website chatbot, AI images, video or voice in marketing, AI-drafted articles, and any emotion or biometric tool.
- Work out your role for each. Deployer if you use a vendor's tool, provider if you put a system into service under your own name. Check the vendor contract.
- Fix the chatbot's opening. Announce in the first message that it is AI, and avoid a human persona.
- Label realistic AI media clearly. Anything showing real-looking people, places or events needs a clear disclosure at first exposure. Ask vendors whether outputs carry machine-readable marks; the 2 December deferral covers only the provider's marking duty.
- Document human review of AI-written public-interest text, or label it. Keep a simple record of who reviewed it and who answers for it.
- Keep the evidence and align with the GDPR. Save screenshots and disclosure wording, update your privacy notice, and cover chatbot and emotion-recognition uses in your DPIA.
Enforcement is live: Ashurst notes that the AI Office and national authorities have been able to enforce the AI Act since 2 August, with a dedicated complaints mechanism and a whistleblower channel.
The bottom line
Article 50 is one of the few AI Act duties that already bites, and it is mostly about honest presentation: tell people when they are dealing with a machine, and make synthetic content recognisable. The final guidelines make the expectations concrete, and the Garante case shows that regulators will judge the presentation, not just the existence of a label.
Book a free consultation with GDPRGard → and we will help you map which of your AI tools trigger which duties.
Sources
- European Commission: Guidelines on transparency obligations for providers and deployers of certain AI systems
- EU Artificial Intelligence Act: Article 50, transparency obligations
- Paul Weiss: EU finalises transparency rules for AI-generated content
- Faegre Drinker: Commission confirms transparency Code of Practice as adequate and publishes final guidelines
- Stibbe: The AI Act's transparency obligations, rules, scope and timeline
- Gibson Dunn: EU AI Act Omnibus agreement, postponed high-risk deadlines and other key changes
- Legalithm: Article 50 final guidelines, what changes before 2 August
- Bird & Bird: European Commission adopts final guidelines on AI Act Article 50
- Garante per la protezione dei dati personali: press release on the R.T.I. deepfake decision (7 August 2026)
- Ashurst: Data Bytes 68, EMEA Data Privacy Update, September 2026
Also read:
- The AI Act delay doesn't cover your chatbot
- Your AI chatbot isn't anonymising anything
- The high-risk deadline moved to December 2027. The GDPR overlap didn't move at all.