AI Has to Say It's AI Now: EU AI Act Article 50, Explained
|
AI is now part of ordinary life. People chat with AI assistants, watch AI-generated video, read AI-written articles, and walk past systems that analyze faces, voices, and behavior. The problem is that most people cannot tell when any of that is happening. Article 50 of the EU AI Act is the rule written to fix that. It creates transparency requirements so people know when AI is involved. Think of it as a nutrition label for AI. It does not ban AI-generated content. It requires organizations to disclose when AI has created, changed, or influenced what people see and hear. The rules took effect on 2 August 2026. Organizations that fail to comply face fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher. If your company ships a chatbot, publishes anything written with AI help, or runs a system that reads faces or voices, this is now your problem. Who Article 50 Applies ToOne distinction is worth holding onto, because it decides which rules land on you. The Act separates providers, who build AI systems and put them on the market, from deployers, who use those systems in their own operations. Article 50 hands each of them a different list.
Most organizations are deployers. Some are both. AI Must Identify ItselfThe simplest rule in Article 50 is this: if people are interacting with AI, they should be told they are interacting with AI. This applies to systems such as:
For example. A problem: “Welcome back. How can I help you today?” The user reasonably assumes a human may be answering. Compliant: “Hello. I am an AI assistant. How can I help you today?” The disclosure has to happen at the latest during the first interaction, unless it is already obvious to a reasonable person that they are dealing with AI. Nobody needs to be told that a talking robot avatar is a machine. The goal is narrow and worth stating plainly: people should not be tricked into believing they are talking to a human when they are not. AI Output Has to Be Machine-ReadableThis is the requirement that gets the least attention and carries the most engineering work. Providers of generative AI must mark AI-generated or AI-manipulated output in a machine-readable format, so that other software can detect it as artificial. A visible label aimed at humans does not satisfy this on its own. In practice that means watermarking, provenance metadata, or similar signals that travel with the file. A few things are carved out: very short text fragments, source code, and machine-to-machine output that no person ever sees. If you build anything that generates content, this is the line item that turns into real product work. To demonstrate how this works: the section above was drafted by Claude. Anthropic announced this week that Claude's output now carries an invisible, machine-readable watermark, specifically to satisfy the new EU rule. These marks are fragile. Heavy rewriting, mixing with other copy, or a short passage can all defeat detection. Deepfakes Must Be Clearly LabeledDeepfakes are AI-generated or AI-altered images, audio, or video that imitate real people or events. Article 50 requires deployers to disclose when content is a deepfake, clearly and at first exposure. Examples:
The label does not have to wreck the experience. For work that is evidently artistic, creative, satirical, or fictional, the disclosure only needs to be appropriate, and it should not hamper enjoyment of the work. A closing credit does the job: “This film contains AI-generated visual effects.” AI Text on Public-Interest Topics Requires DisclosureArticle 50 covers AI-generated text published to inform the public about matters of public interest, which includes politics, justice, and public health. Examples:
There is an important exception. If the text goes through genuine human review or editorial control, and a person or organization takes editorial responsibility for it, the disclosure requirement does not apply. The word doing the work there is genuine. Regulators describe this as substantive examination by someone who knows the subject and has authority to approve or reject. A quick skim before hitting publish does not count. Human accountability is the point. AI can help produce the work, as long as a responsible human stays on the hook for it. People Must Be Told About Emotion Recognition and Biometric CategorizationArticle 50 also reaches certain biometric systems. Organizations running emotion recognition or biometric categorization systems must inform the people exposed to them that the technology is operating. Examples:
These systems remain subject to existing privacy and data protection law as well, so Article 50 sits on top of GDPR obligations rather than replacing them. The Dates That Matter
The Commission has also published guidelines on the transparency obligations, and a Code of Practice on Transparency of AI-Generated Content covering a standard EU label, the line between fully AI-generated and AI-assisted work, and technical standards for watermarking. Following the Code is voluntary. Organizations that do will be better positioned to demonstrate compliance. What Article 50 Means for Security TeamsFor security leaders, this is more than a compliance checkbox. It changes how organizations track and manage AI risk. 1. Inventory your AI systemsYou need to know:
You cannot label or secure systems you do not know exist. This is the step most organizations discover they have not done. 2. Add disclosure controlsReview your chatbot interfaces, AI-generated communications, and content publishing workflows. The question to ask about each one: “Would a reasonable person know AI was involved?” If the answer is no, disclosure is likely required. 3. Prepare for synthetic content detectionIf you produce AI-generated content, evaluate your metadata standards, provenance tracking, content authenticity tools, and internal review processes. This is where the December deadline lands. 4. Train your peopleAnyone using generative AI should understand when disclosure is required, when human review changes the obligation, and how to handle AI-generated content they receive from outside. Sources: Axios, Anthropic's text watermarks signal new front in AI detection · Fortune · SiliconANGLE · Euronews |