AI Has to Say It's AI Now: EU AI Act Article 50, Explained


AI is now part of ordinary life. People chat with AI assistants, watch AI-generated video, read AI-written articles, and walk past systems that analyze faces, voices, and behavior.

The problem is that most people cannot tell when any of that is happening.

Article 50 of the EU AI Act is the rule written to fix that. It creates transparency requirements so people know when AI is involved.

Think of it as a nutrition label for AI. It does not ban AI-generated content. It requires organizations to disclose when AI has created, changed, or influenced what people see and hear.

The rules took effect on 2 August 2026. Organizations that fail to comply face fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.

If your company ships a chatbot, publishes anything written with AI help, or runs a system that reads faces or voices, this is now your problem.


Who Article 50 Applies To

One distinction is worth holding onto, because it decides which rules land on you.

The Act separates providers, who build AI systems and put them on the market, from deployers, who use those systems in their own operations. Article 50 hands each of them a different list.

  • Providers must make chatbots announce themselves, and must mark AI-generated output so machines can detect it.
  • Deployers must label deepfakes, disclose AI-written text on matters of public interest, and notify people subjected to emotion recognition or biometric categorization.

Most organizations are deployers. Some are both.


AI Must Identify Itself

The simplest rule in Article 50 is this: if people are interacting with AI, they should be told they are interacting with AI.

This applies to systems such as:

  • Customer service chatbots
  • Virtual assistants
  • AI-powered support agents
  • Other systems that communicate directly with people

For example.

A problem:

“Welcome back. How can I help you today?”

The user reasonably assumes a human may be answering.

Compliant:

“Hello. I am an AI assistant. How can I help you today?”

The disclosure has to happen at the latest during the first interaction, unless it is already obvious to a reasonable person that they are dealing with AI. Nobody needs to be told that a talking robot avatar is a machine.

The goal is narrow and worth stating plainly: people should not be tricked into believing they are talking to a human when they are not.


AI Output Has to Be Machine-Readable

This is the requirement that gets the least attention and carries the most engineering work.

Providers of generative AI must mark AI-generated or AI-manipulated output in a machine-readable format, so that other software can detect it as artificial. A visible label aimed at humans does not satisfy this on its own.

In practice that means watermarking, provenance metadata, or similar signals that travel with the file.

A few things are carved out: very short text fragments, source code, and machine-to-machine output that no person ever sees.

If you build anything that generates content, this is the line item that turns into real product work.


To demonstrate how this works: the section above was drafted by Claude. Anthropic announced this week that Claude's output now carries an invisible, machine-readable watermark, specifically to satisfy the new EU rule. These marks are fragile. Heavy rewriting, mixing with other copy, or a short passage can all defeat detection.


Deepfakes Must Be Clearly Labeled

Deepfakes are AI-generated or AI-altered images, audio, or video that imitate real people or events.

Article 50 requires deployers to disclose when content is a deepfake, clearly and at first exposure.

Examples:

  • An AI-generated video showing a politician saying something they never said
  • A fake audio recording imitating a company executive
  • A realistic AI-generated image presented as a real event

The label does not have to wreck the experience. For work that is evidently artistic, creative, satirical, or fictional, the disclosure only needs to be appropriate, and it should not hamper enjoyment of the work. A closing credit does the job:

“This film contains AI-generated visual effects.”

AI Text on Public-Interest Topics Requires Disclosure

Article 50 covers AI-generated text published to inform the public about matters of public interest, which includes politics, justice, and public health.

Examples:

  • AI-written election analysis
  • AI-generated news summaries
  • Public announcements drafted with AI assistance

There is an important exception. If the text goes through genuine human review or editorial control, and a person or organization takes editorial responsibility for it, the disclosure requirement does not apply.

The word doing the work there is genuine. Regulators describe this as substantive examination by someone who knows the subject and has authority to approve or reject. A quick skim before hitting publish does not count.

Human accountability is the point. AI can help produce the work, as long as a responsible human stays on the hook for it.


People Must Be Told About Emotion Recognition and Biometric Categorization

Article 50 also reaches certain biometric systems. Organizations running emotion recognition or biometric categorization systems must inform the people exposed to them that the technology is operating.

Examples:

  • A workplace system analyzing employee emotion
  • A security system sorting people by biometric characteristics

These systems remain subject to existing privacy and data protection law as well, so Article 50 sits on top of GDPR obligations rather than replacing them.


The Dates That Matter

  • 2 August 2026. Article 50 applies.
  • 2 December 2026. Extended deadline for the machine-readable marking requirement, for generative systems already on the market before August 2.
  • Content generated before the rules applied does not have to be labeled retroactively.

The Commission has also published guidelines on the transparency obligations, and a Code of Practice on Transparency of AI-Generated Content covering a standard EU label, the line between fully AI-generated and AI-assisted work, and technical standards for watermarking. Following the Code is voluntary. Organizations that do will be better positioned to demonstrate compliance.


What Article 50 Means for Security Teams

For security leaders, this is more than a compliance checkbox. It changes how organizations track and manage AI risk.

1. Inventory your AI systems

You need to know:

  • Which AI systems are customer-facing
  • Which systems generate content
  • Which systems process biometric information

You cannot label or secure systems you do not know exist. This is the step most organizations discover they have not done.

2. Add disclosure controls

Review your chatbot interfaces, AI-generated communications, and content publishing workflows.

The question to ask about each one:

“Would a reasonable person know AI was involved?”

If the answer is no, disclosure is likely required.

3. Prepare for synthetic content detection

If you produce AI-generated content, evaluate your metadata standards, provenance tracking, content authenticity tools, and internal review processes. This is where the December deadline lands.

4. Train your people

Anyone using generative AI should understand when disclosure is required, when human review changes the obligation, and how to handle AI-generated content they receive from outside.


Sources: Axios, Anthropic's text watermarks signal new front in AI detection · Fortune · SiliconANGLE · Euronews