Article 50 of the AI Act has applied since 2 August 2026. Providers of AI systems must tell people they are interacting with AI and mark AI output in a machine-readable way. Organisations that use AI must label deepfakes and AI-generated text that informs the public on matters of public interest. A transition period until 2 December 2026 applies to the marking, but only for systems placed on the market before 2 August 2026.
In short
- Article 50 of the EU AI Act is about recognisability: people must know when they are dealing with AI.
- Providers make sure a chatbot says it is AI, and that generated images, audio, video and text are marked in a machine-readable format.
- Deployers label deepfakes and AI-generated text they publish to inform the public on matters of public interest. If a human has reviewed that text and someone holds editorial responsibility, the duty falls away.
- The Digital Omnibus on AI gave providers of existing systems until 2 December 2026 for the marking. The other duties have applied since 2 August 2026.
- An infringement can lead to a fine of up to € 15 million or 3% of worldwide annual turnover.
What does Article 50 of the AI Act require?
Seven paragraphs, with different duties for different parties. The table summarises paragraphs 1 to 5; paragraphs 6 and 7 deal with other rules and codes of practice.
| Paragraph | For whom | What | Main exception |
|---|---|---|---|
| 1 | Provider | An AI system for direct interaction says it is AI | Where that is already obvious to a reasonably observant person |
| 2 | Provider | Mark generated audio, images, video and text in a machine-readable way and make it detectable | Assistive function for standard editing, or the input is not substantially altered |
| 3 | Deployer | Inform people about emotion recognition or biometric categorisation | Use permitted by law for criminal investigation |
| 4, first subparagraph | Deployer | Disclose that a deepfake is artificial | For evidently artistic, creative or satirical work, an appropriate mention suffices |
| 4, second subparagraph | Deployer | Disclose that text on matters of public interest was generated by AI | Human review plus editorial responsibility |
| 5 | Both | At the latest at the first interaction or exposure, clearly and accessibly | None |
A deepfake is image, audio or video content that looks real but was generated or manipulated by AI.
Are you a provider or a deployer of AI?
That determines your duties. The AI Act distinguishes a provider from a deployer.
A provider develops an AI system, or has it developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority. Personal, non-professional use does not count.
Most organisations are deployers: they use a vendor's tool. Put a chatbot on your website under your own name, and you may also be a provider, bound by paragraph 1.

Article 50 AI Act comparison. Provider (paragraphs 1 and 2): makes a chatbot say it is AI and marks AI output machine-readably. Deployer (paragraphs 3 and 4): labels deepfakes and AI text on matters of public interest.
Do you always have to label AI-generated text?
No. For deployers, the labelling duty for text applies only when you publish it to inform the public on matters of public interest, such as a news item.
Even then, the duty falls away if a human has reviewed or edited the text and a person or organisation holds editorial responsibility. A quote, an email to a client or an internal report does not fall under paragraph 4. Deepfakes, however, must always be disclosed.
Note that Article 50 leaves other rules untouched. Agreements with clients, professional rules and the GDPR may still require openness. For lawyers we set out what that means in our overview of NOvA guidance on AI use in Dutch law firms. In short: Article 50 does not require a court document to state that AI was used.
Which transition period applies to Article 50?
Only for the marking under paragraph 2, and only for existing systems. The Digital Omnibus on AI, Regulation (EU) 2026/1744, added a new Article 111(4) to the AI Act. Providers of systems that generate synthetic audio, images, video or text and were placed on the market before 2 August 2026 must comply with paragraph 2 by 2 December 2026.
That gives them four months. New systems get no transition period. And paragraphs 1, 3 and 4 have applied to everyone since 2 August 2026.

Article 50 AI Act timeline: 27 July 2026 Digital Omnibus in force, 2 August 2026 Article 50 applies, 2 December 2026 deadline for marking by existing systems.
What does Article 50 mean for your vendors?
Two core duties (paragraphs 1 and 2) sit with the provider, so usually with your vendor. Ask them:
- Does the chatbot or assistant tell users they are talking to AI?
- Does the tool mark generated images, audio, video and text in a machine-readable way? If not, from when, and does the system fall under the deadline of 2 December 2026?
- Has the vendor signed the EU Code of Practice on Transparency of AI-generated Content? Signing is voluntary, but signatories can rely on it to demonstrate compliance.
- Can you label a deepfake or a public text in the tool itself, for example with the icons the EU provides for this?
How Dutch cybersecurity law looks at the supply chain is explained in our overview of NIS2 in the Netherlands (Cyberbeveiligingswet).
How it works at Prudai
Article 50 is about making AI recognisable. A related question is whether users can see what a suggestion is based on. This is how we handle that; these are not Article 50 measures, which concern marking and labelling.
Suggestions only after approval. In IRMA's process editor, IRMA can suggest a risk or control for each process step. It does so with a fixed rule set without AI, or through the IRMA assistant if AI suggestions are switched on for your organisation; by default they are off. Every suggestion must include a rationale and at least one source reference. It only becomes a link once an employee approves it.
A visible label for an uncertain source. In LEO's chat, a gate checks every answer for ECLI numbers, the identifiers of Dutch judgments. If an ECLI did not come from a source, a tool or your own documents, and the model cannot retrieve the judgment, the answer is marked "unverified". For law firms, the page on the NOvA recommendations (in Dutch) explains how LEO helps with this.
AI governance next to information security. IRMA includes frameworks such as ISO/IEC 42001 (the management system for AI), ISO/IEC 27001 and the Dutch Cyberbeveiligingswet. Having a framework in the software does not make you compliant. It provides the structure in which you record your measures.
For the specialist
- Definitions. Article 3(3) (provider) and 3(4) (deployer) of Regulation (EU) 2024/1689.
- Other paragraphs. Paragraph 2 requires technical solutions that are effective, interoperable, robust and reliable as far as technically feasible. Paragraph 6: other transparency duties remain. Paragraph 7 was amended by Regulation (EU) 2026/1744: the Commission assesses whether codes of practice are adequate.
- Code of practice. The Code of Practice on Transparency of AI-generated Content has a section for providers (marking and detection) and one for deployers (labelling). According to the Commission, it and the AI Board have confirmed the code is an adequate voluntary tool. The Commission has also published guidelines on the scope of Article 50.
- Penalties. Article 99(4)(g): up to € 15 million or 3% of worldwide annual turnover, whichever is higher. For SMEs (paragraph 6) and, since Regulation (EU) 2026/1744, also for small mid-cap enterprises (paragraph 6a), the lower of the two applies. Member States lay down the rules on penalties (paragraph 1).
- Dates. Article 113: the regulation applies in the main from 2 August 2026. Regulation (EU) 2026/1744 is dated 8 July 2026, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026.
Frequently asked questions
Does Article 50 apply to text I write with ChatGPT?
Only if you publish that text to inform the public on matters of public interest and there was no human review for which someone holds editorial responsibility. Ordinary business text, such as an email or a quote, is not covered by the labelling duty in paragraph 4.
Do I have to tell a client that AI helped write an email?
Not under Article 50. Client agreements or professional rules may require it. When in doubt, be open in advance.
What is the fine for infringing Article 50?
Up to € 15 million or 3% of worldwide annual turnover, whichever is higher. For SMEs and small mid-caps the lower of the two applies. Member States set the detailed rules on penalties.
When must AI output be marked?
For new systems, since 2 August 2026. Providers of systems already on the market before that date have until 2 December 2026. That deadline comes from the Digital Omnibus on AI.
Sources
- AI Act, Regulation (EU) 2024/1689 (Articles 3, 50, 99 and 113)
- Digital Omnibus on AI, Regulation (EU) 2026/1744 (OJ 24 July 2026)
- European Commission, Code of Practice on Transparency of AI-generated Content (consulted 2 October 2026)
- Dutch Data Protection Authority, AI Act (in Dutch; consulted 2 October 2026)
- Dutch Authority for Digital Infrastructure, Artificial intelligence (in Dutch; consulted 2 October 2026)
Would you like to know how IRMA places ISO/IEC 42001 next to ISO 27001 and the Cyberbeveiligingswet in your ISMS? See IRMA (in Dutch) and the frameworks it includes.
Updated on 4 October 2026
