Prefer to listen? Click play for AI narration

The AI Act's transparency rules, Article 50, have been enforceable since 2 August 2026. On 20 July the European Commission published the final guidelines that explain how to comply: 51 pages, replacing a May draft. Breaches can cost up to €15 million or 3% of worldwide turnover, whichever is higher.

If your business runs a website chatbot, publishes AI-generated images or video, or posts AI-written articles, this applies to you. Our earlier guide for small businesses covered the basics. This article covers what the final guidelines settled, what is still deferred, and where the GDPR adds its own test.

Four duties, and who carries them

Article 50 has four strands. Two fall mainly on providers, the companies that build AI systems, and two on deployers, the organisations that use them:

DutyWhoWhat it requires
Tell people they are dealing with AI (50(1))ProviderDesign the system so people are informed, unless it is obvious to a reasonably well-informed, observant and circumspect person
Mark AI-generated content (50(2))ProviderMark synthetic audio, images, video and text in a machine-readable format so it can be detected as AI-generated
Emotion recognition and biometric categorisation (50(3))DeployerInform the people exposed to the system, and process their data in line with the GDPR
Deepfakes and AI text on public-interest matters (50(4))DeployerDisclose that content is AI-generated or manipulated; for text, unless a human has reviewed it and someone holds editorial responsibility

Most small businesses are deployers: they use someone else's chatbot or image generator. Stibbe notes, though, that a “provider” includes anyone who puts a system into service under their own name, and that deployers stay responsible when a third party runs a system for them under their responsibility and control.

2 Aug 2026
Article 50 applies
2 Dec 2026
Marking deferral for generative systems already on the market
2 Feb 2027
Watermark-detection interoperability for Code signatories
€15M / 3%
Maximum fine, whichever is higher

Chatbots: “obvious” is a narrow exit

The disclosure has to reach people clearly, at the latest at their first interaction (Article 50(5)). The only general exception is where it is obvious that they are dealing with AI. Legalithm reads the final guidelines as keeping that exception narrow: a fluent, human-sounding support bot does not qualify, and if visitors might plausibly believe they are talking to a person, disclosure is required.

AI content: marking is the vendor's job, labelling is yours

Providers must mark AI-generated audio, images, video and text so that machines can detect them. The final guidelines do not mandate a single technology. Paul Weiss reports that they expect a layered approach, such as metadata plus watermarking, because no single technique currently meets the Act's standard. Legalithm's reading is content credentials (C2PA) for images, video and audio, watermarking as a complementary layer, and metadata for text.

For most businesses that is a question for your vendors: ask whether the tools you use mark their output. The deployer duties are yours:

Faegre Drinker adds that the final version widens the territorial reach: deepfake labelling applies to content that is accessible globally and reaches EU audiences, wherever it was made.

What is deferred, and what is not

Only one duty got extra time. Under the AI Omnibus, providers of generative systems placed on the market before 2 August 2026 have until 2 December 2026 to add machine-readable marking (Article 50(2)). Gibson Dunn stresses that the rest of Article 50, including chatbot disclosure and the deployer labelling duties, proceeds as scheduled from 2 August.

Separately, signatories of the voluntary Code of Practice on transparency of AI-generated content, which the Commission and the AI Board have confirmed as adequate, must have watermark-detection interoperability in place by 2 February 2027. The Commission says adherence to the Code can demonstrate compliance and that equivalent alternatives are allowed. Legalithm cautions that it is evidence of good faith rather than immunity.

Where the GDPR adds its own test

Article 50 does not replace other transparency rules, and an early enforcement example came from a data protection authority. On 23 July 2026, Italy's Garante warned the broadcaster R.T.I. over AI-altered satirical clips of the journalist Enrico Mentana aired on Striscia la Notizia, announcing the decision on 7 August. It found that the on-screen notices about the artificial nature of the videos were not clear or prominent enough for every viewer, including people watching on social media, given how realistic the clips were. It cited Article 5 (lawfulness, fairness, transparency) and Article 25 (data protection by design), banned further use of his data in that way, and imposed no fine.

The lesson is that a label which exists but fails the viewer is not enough. Both regimes look at how the disclosure is presented, and Article 50(3) expressly requires GDPR-compliant processing for emotion recognition and biometric categorisation.

💬
GDPRGard Product
Deploying a website chatbot? Build the disclosure in from day one

GDPRChat is an AI customer chat widget built with Article 7 consent gates and automatic data deletion — compliance built into the architecture, not bolted on after a regulator starts asking questions.

See GDPRChat →

A checklist for this week

  1. Inventory every AI touchpoint. The website chatbot, AI images, video or voice in marketing, AI-drafted articles, and any emotion or biometric tool.
  2. Work out your role for each. Deployer if you use a vendor's tool, provider if you put a system into service under your own name. Check the vendor contract.
  3. Fix the chatbot's opening. Announce in the first message that it is AI, and avoid a human persona.
  4. Label realistic AI media clearly. Anything showing real-looking people, places or events needs a clear disclosure at first exposure. Ask vendors whether outputs carry machine-readable marks; the 2 December deferral covers only the provider's marking duty.
  5. Document human review of AI-written public-interest text, or label it. Keep a simple record of who reviewed it and who answers for it.
  6. Keep the evidence and align with the GDPR. Save screenshots and disclosure wording, update your privacy notice, and cover chatbot and emotion-recognition uses in your DPIA.

Enforcement is live: Ashurst notes that the AI Office and national authorities have been able to enforce the AI Act since 2 August, with a dedicated complaints mechanism and a whistleblower channel.

The bottom line

Article 50 is one of the few AI Act duties that already bites, and it is mostly about honest presentation: tell people when they are dealing with a machine, and make synthetic content recognisable. The final guidelines make the expectations concrete, and the Garante case shows that regulators will judge the presentation, not just the existence of a label.

Book a free consultation with GDPRGard → and we will help you map which of your AI tools trigger which duties.

Sources

Share this article

Also read:

⚠️ This article is for informational purposes only and does not constitute legal advice. For complex compliance situations, consult a qualified data protection professional. GDPR and EU AI Act requirements are subject to ongoing regulatory guidance — verify current obligations with your legal adviser.