
Notice
This article is based on Article 50 of the EU AI Act, the amendments introduced through the Digital Omnibus on AI, the European Commission’s Guidelines on Transparency Obligations for Providers and Deployers of AI Systems, and related official guidance publicly available as of August 3, 2026. It also includes DANA NOTES’ analysis.
What This Article Covers
The transparency obligations under Article 50 of the EU AI Act began to apply on August 2, 2026.
Companies that provide AI systems must design their products so that users can recognize when they are interacting directly with an AI system. Images, audio, video, and text produced by generative AI must, in principle, carry machine-readable markings that make it possible to detect that the content was generated or manipulated by AI.
Separate obligations also apply to companies that use AI systems in their actual operations and services. When they disclose deepfakes, publish certain AI-generated texts concerning matters of public interest, or use emotion recognition or biometric categorization systems, they must inform the people concerned.
However, not every obligation applies to every AI system in the same way from August 2, 2026.
For generative AI systems placed on the EU market or put into service before August 2, 2026, a transitional period applies, allowing providers to comply with the machine-readable marking obligation under Article 50(2) by December 2, 2026.
This does not mean that the marking obligation has been waived. It provides additional time to add marking capabilities to existing systems.
The remaining transparency obligations, including disclosure of AI interaction, disclosure of deepfakes, disclosure of certain AI-generated texts concerning matters of public interest, and notification concerning emotion recognition and biometric categorization systems, began to apply as scheduled on August 2, 2026.
The key point of this regulation is not to apply the same label to all AI content.
Responsibilities differ depending on whether a company provides an AI system directly or uses another company’s AI. Even within the same company, the necessary preparations differ depending on whether AI is used for internal work or for services and content provided to customers and the general public.
The regulation can be understood as distinguishing who is responsible at each stage of the process in which AI outputs are generated, reviewed, distributed, and exposed to people.
Term to Know First — Machine-Readable Marking
A machine-readable marking is not a notice that a person reads directly on a screen. It is a method of embedding information so that platforms and detection systems can identify whether content was generated by AI.
This may include recording generation information in the content’s metadata or applying technologies such as digital watermarks.
Article 50(2) of the EU AI Act requires providers of generative AI systems to mark AI-generated or AI-manipulated images, audio, video, and text in a machine-readable format and make their AI-generated nature detectable.
The technologies used for such markings must, to the extent technically feasible, be effective, interoperable, robust, and reliable. The characteristics and limitations of the content, implementation costs, and the current state of technology are also taken into account.
However, the marking obligation may not apply when AI merely assists with standard editing or does not substantially alter the meaning of data provided by the user.
Existing Generative AI Systems Have a Transitional Period
The general application date for the machine-readable marking obligation is August 2, 2026.
However, providers of generative AI systems placed on the EU market or put into service before August 2, 2026, may comply with the obligation by December 2, 2026.
Companies operating existing generative AI systems have therefore been given additional time to develop marking capabilities and incorporate them into their existing products.
By contrast, this transitional period does not apply to generative AI systems newly placed on the EU market or put into service after August 2, 2026.
This transitional period is limited to the machine-readable marking obligation under Article 50(2).
It does not mean that all obligations concerning AI interaction disclosure, deepfake disclosure, disclosure of AI-generated texts concerning matters of public interest, and notification concerning emotion recognition and biometric categorization systems have been postponed until December 2026.
Nor is there a requirement to retroactively mark content that had already been generated before August 2, 2026. However, the European Commission recommends voluntary marking where possible.
Machine-Readable Markings and Human-Visible Labels Are Different
Machine-readable markings and notices shown directly to users are separate obligations.
Even when an AI system provider embeds machine-readable information within content, a deployer that discloses a deepfake must inform people, in a manner they can recognize, that the content was generated or manipulated by AI.
For example, even when metadata is embedded in an AI-generated video file, ordinary users are unlikely to be able to inspect that information without a separate detection tool.
Accordingly, content such as deepfakes that could mislead people requires a separate human-recognizable indication, such as on-screen text, an icon, or an audio notice.
A machine-readable marking enables systems and platforms to detect that content was generated by AI, while a human-visible label enables actual users to recognize that AI was used.
What Is the Difference Between an AI Provider and an AI Deployer?
The EU AI Act distinguishes the roles of companies participating in the AI value chain by classifying them as providers and deployers.
AI Provider
An AI provider is an entity that develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark.
The company that originally develops an AI model is not the only entity that can be considered a provider.
When a company uses an external AI model to create a new AI system and offers it to customers under its own name, that company may also be regarded as the provider of the final AI system it offers.
Two main transparency obligations apply to AI providers.
- They must design the system so that people can recognize when they are interacting directly with an AI system.
- They must apply machine-readable markings to images, audio, video, and text generated by generative AI systems.
However, when it is obvious from the circumstances that the user is interacting with an AI system, a separate repeated notice may not be necessary.
AI Deployer
An AI deployer, referred to in this article as a company using AI, is a company, institution, or organization that uses an AI system under its own authority and responsibility in actual operations or services.
Advertising agencies, media companies, online platforms, financial institutions, hospitals, public authorities, and ordinary companies that subscribe to external generative AI services may all become AI deployers.
When an employee uses AI under the company’s instructions and supervision, the individual employee does not ordinarily become a separate deployer. The company itself generally occupies the position of deployer.
When the following systems or content meet the applicable conditions under Article 50, AI deployers must inform the people concerned.
- When using an emotion recognition system
- When using a biometric categorization system
- When disclosing deepfake images, audio, or video
- When publishing AI-generated or AI-manipulated text concerning matters of public interest without substantial human review or editorial control
The European Commission also distinguishes between the obligations imposed on providers—AI interaction disclosure and machine-readable marking—and the obligations imposed on deployers concerning emotion recognition, biometric categorization, deepfakes, and certain texts concerning matters of public interest.
The Same Company May Be Both a Provider and a Deployer
An AI provider and an AI deployer do not necessarily have to be different companies.
Suppose a company uses an external general-purpose AI model to build an AI customer service system for its own customer center.
If the company merely subscribes to the external model as a complete service and allows employees to use it internally, it is generally closer to being an AI deployer.
By contrast, if the company integrates the external model into its own systems and provides an AI customer service product to customers under its own name, it may assume the role of provider for the final AI system. At the same time, it is also the entity using that system for actual customer service.
In such a case, the company cannot transfer all responsibility to the original model developer merely because it used an external AI model.
Even when the external model includes machine-readable marking capabilities, the company that configures and operates the final service must separately verify whether users are properly informed that they are interacting with AI and whether generated content is appropriately managed.
When adopting AI, companies should distinguish among the following three situations.
- Is the company using an external AI service in its completed form?
- Is it connecting external AI to an existing business system?
- Is it offering a new product or service under its own name based on external AI?
The closer the arrangement is to the third situation, the greater the possibility that the company will be regarded not only as an AI deployer but also as an AI system provider.
When AI Is Used Inside a Company
Internal corporate use refers to employees or other members of an organization using AI to perform their work.
This includes drafting internal documents, summarizing meeting minutes, translation, preparing report drafts, internal search, coding, producing training materials, and operating internal AI chatbots.
Using AI internally does not mean that every output must carry an AI-generated label.
However, separate obligations may still apply when employees interact directly with AI, are exposed to deepfake content, or become subjects of emotion recognition or biometric categorization systems.
Internal AI Chatbots and Workplace AI Assistants
When a company adopts an external AI service as an employee chatbot or workplace assistant, the company is generally in the position of an AI deployer.
When employees interact directly with the AI, the AI provider must design the system so that employees can recognize that they are interacting with an AI system.
When the name and interface of the workplace service clearly indicate that it is an AI system, a separate repeated notice may not be necessary.
By contrast, when a system appears to be an ordinary internal messenger or a human support channel but actually provides direct AI-generated responses, employees may need to be informed so that they do not mistake the responses for those of a person.
Companies adopting AI must also check whether their suppliers provide the required disclosure functions.
If a company removes the supplier’s AI disclosure notice or modifies the service so that it appears to be operated by a person, separate regulatory risks may arise during operation.
Internal Reports and Business Documents
The fact that an employee used generative AI to draft an internal report or summarize a meeting does not mean that every internal document must carry an AI-generated label.
The disclosure obligation for AI-generated text concerning matters of public interest applies to text published for the purpose of informing the public about matters of public interest.
Reports used only within an organization, personal work notes, and internal meeting materials that are not disclosed to the public do not fall directly into the same category as this disclosure obligation.
However, the situation must be reassessed if an internal document is later released as a press release, website post, policy notice, investor information, news article, or external report.
The important criterion is not where the AI output was initially created, but to whom and for what purpose it is ultimately disclosed.
Internal Training Images, Audio, and Video
When a company creates a virtual instructor video or voice using AI for internal training, it must still examine the nature of the content.
AI-generated or manipulated images, audio, or video that resemble an existing person, object, place, institution, or event and may be mistaken by employees as authentic may constitute deepfakes.
For example, if a company synthesizes the face and voice of an actual executive for an internal training video, it may need to inform employees that the material is AI-generated rather than an actual recording.
By contrast, if it is clear from the outset that the content features a fictional character or illustration and there is little possibility of confusing it with a real person or event, it may be distinguished from an ordinary deepfake.
Employee Emotion Recognition and Biometric Categorization
Companies must exercise greater caution when using AI that analyzes employees’ facial expressions, voices, or biometric data.
An AI deployer must inform people subject to an emotion recognition or biometric categorization system that the system is operating.
However, emotion recognition AI in the workplace is not an area in which use becomes permissible merely by providing notice.
Except in limited circumstances such as medical or safety purposes, the EU AI Act classifies the use of AI systems to infer people’s emotions in workplaces and educational institutions as a prohibited AI practice.
Therefore, before reviewing the transparency obligations under Article 50, a company considering an internal emotion recognition system must first determine whether the use itself is prohibited.
When AI Is Used for Customers and External Users
External corporate use refers to situations in which customers, citizens, subscribers, platform users, or the general public encounter an AI system or AI-generated content.
This includes customer service chatbots, AI voice support, advertisements, social media posts, news articles, public notices, AI avatars, and generative AI content services.
In external use, AI is more likely to appear to be a real person or authentic content, and outputs may be distributed more widely. Transparency obligations therefore become direct product and content operations issues.
Customer Service Chatbots and AI Agents
When customers communicate directly with an AI chatbot, AI agent, or AI avatar, the AI system provider must design the system so that customers can recognize that they are interacting with AI.
A distinction must be made between cases in which AI merely assists a human agent and the human agent delivers the actual response, and cases in which AI responds directly to the customer.
When AI performs only background analysis or a person reviews the content before delivering it to the customer, the applicable structure may differ from a situation in which AI interacts directly with a person.
Companies adopting external AI customer service solutions should not rely solely on contracts and feature descriptions.
They should also examine when and how AI use is disclosed through the actual customer interface, call connection notice, voice message, and customer service process.
Advertising and Social Media Content
The fact that a company uses generative AI to create advertising copy or a social media post does not mean that every item must carry a conspicuous AI label.
The disclosure obligation for AI-generated text concerning matters of public interest applies to text published to inform the public about matters of public interest. Ordinary product advertising copy may not fall into this category, depending on its content and purpose.
However, when an AI-generated advertising image, audio clip, or video appears to depict a real person or event and constitutes a deepfake, a separate disclosure obligation may apply.
For example, an advertisement that synthesizes the face or voice of a real celebrity, or presents a nonexistent event as if it were genuine footage, is highly likely to require a notice informing users that it was generated or manipulated by AI.
Conversely, not every AI-generated image is a deepfake.
Abstract graphics, infographics, clearly identifiable illustrations, and featured images that do not reproduce real people or events are generally distinguished from deepfakes.
News and Content Concerning Matters of Public Interest
AI-generated or AI-manipulated text that provides the public with information relating to political affairs, government administration, the judiciary, public safety, public health, the environment, consumer safety, the economy, finance, science, or culture may be subject to a disclosure obligation.
However, the fact that AI was used to some extent does not mean that every news article, analysis, or blog post must carry an AI-generated label.
When the text has undergone substantial human review or editorial control, and an individual or legal entity bears editorial responsibility for the publication, it may qualify for an exception to the disclosure obligation for AI-generated text concerning matters of public interest.
Human review in this context does not mean a simple spelling check or formatting review.
The specific assessment may vary according to the content and editorial structure, but companies and media organizations should at least examine the following matters.
- Were the facts and figures reviewed?
- Was the reliability of the sources verified?
- Were the substance and logic of the text substantially reviewed?
- Did the responsible person have the authority to modify, delete, or reject the content?
- Is there an individual or entity that assumes editorial responsibility for the final publication?
A formal review limited to spelling and grammar is unlikely to qualify as substantial human review or editorial control. An individual or legal entity must bear legal editorial responsibility for the final publication.
When an AI-generated draft is published almost automatically with little review, or mass-published after only minor corrections to spelling and phrasing, it may be difficult to qualify for the human-review exception.
By contrast, when an operator or editor selects the topic, verifies the materials and facts, substantially revises the structure and substance, decides whether to publish the text, and assumes responsibility for the publication, the case may be distinguished from one in which a separate AI-generation disclosure is required.
Accordingly, media companies, corporate communications teams, public institutions, research companies, and informational blogs should not merely record whether AI was used. They should establish a structure capable of explaining what a person reviewed and who assumes final editorial responsibility.
Separately from legal obligations, a company or media outlet may voluntarily disclose its use of AI through an editorial policy or AI use policy on its website. However, this is different from repeating the same statement on every post.
Must Every AI-Generated Featured Image Be Labeled?
Not every AI-generated image must carry a human-visible AI label.
For images, audio, and video, the human-visible disclosure obligation for deployers that disclose content applies to deepfakes.
Abstract featured images, informational graphics, and icon-based technology images that do not reproduce an actual person, place, or event are unlikely to be mistaken for authentic records.
Therefore, abstract technology-themed featured images and infographics that do not reproduce real people or events are not necessarily required to carry a human-visible AI-generated label each time.
By contrast, labeling is likely to be required in the following cases.
- A synthetic image depicting an actual EU official as if the person were making an announcement
- A fabricated image that appears to show an actual protest, accident, or disaster scene
- Content that synthesizes the face or voice of a specific company CEO
- An image presenting a nonexistent event as if it were an authentic news photograph
The obligation under Article 50(2) to embed machine-readable markings primarily applies to providers of generative AI systems.
It does not mean that a company publishing content or a blog operator must personally develop digital watermarking technology for every image.
However, it will be necessary in practice to determine whether metadata embedded by the AI provider is removed during image compression, file conversion, WebP conversion, or platform uploads.
Emotion Recognition and Biometric Categorization for External Users
When a company uses emotion recognition or biometric categorization AI in a store, platform, customer service center, event venue, or online service, it must inform users that the system is operating.
For example, when a system analyzes customers’ voices or facial expressions to infer their emotional state, or categorizes people based on biometric data, users must be able to recognize that they are subject to such a system.
However, complying with the notification obligation does not mean that all other legal requirements concerning privacy and the processing of biometric data have been satisfied.
The AI Act’s transparency obligations and data protection rules such as the GDPR must be reviewed separately.
Final Exposure Determines Whether AI Use Is Internal or External
When distinguishing between internal and external corporate uses of AI, companies should focus less on where AI was first used and more on who ultimately encounters the output and for what purpose.
Even AI-generated text initially prepared as an internal report must be reassessed under the disclosure obligations for text concerning matters of public interest if it is later published on a website or distributed as a press release.
Internal training content is not automatically excluded from labeling obligations merely because it is used internally if it may be mistaken for a real person or event and constitutes a deepfake.
Companies therefore need to manage the following stages together, from the generation of AI content to its final exposure.
- Generation stage: Record which AI system was used and what content was created.
- Review stage: Determine whether a person substantially reviewed the content and sources.
- Approval stage: Designate the person responsible for final use and publication.
- Distribution stage: Distinguish between internal use and external disclosure.
- Exposure stage: Determine whether a human-visible label or notice is required.
- Retention stage: Verify whether machine-readable markings survive editing, conversion, and uploading.
Even when content was not subject to a disclosure obligation at the time it was generated, it must be reassessed if its purpose or scope of distribution changes.
Labeling Obligations Affect Products and Business Processes
AI labeling obligations are difficult to address simply by adding a statement after the content has been completed.
AI providers must design systems so that machine-readable information can be embedded from the generation stage.
Providers operating existing generative AI systems must complete the development, implementation, and testing of marking capabilities within the transitional period.
Companies using AI must also verify whether the relevant information remains intact during image editing, video encoding, file conversion, and platform uploading.
When a human-visible label is required, companies must also determine on which screen and at what point it should be displayed.
Product Development
- AI interaction disclosure screens
- Embedding content-generation information
- Preservation of machine-readable markings
- Testing whether marking capabilities operate properly
- Management of the transitional deadline for existing systems
- Reverification after product updates
Content Operations
- Classification of AI-generated content
- Determination of whether content constitutes a deepfake
- Determination of whether text concerns matters of public interest
- Human review and editorial approval procedures
- Management of the transition from internal content to external disclosure
- Recordkeeping and preservation of evidence concerning AI content
Supplier Management
- Verification of marking functions in external AI services
- Verification of marking formats and compatibility
- Allocation of responsibility between AI providers and deployers
- Notification of model and feature changes
- Securing materials required to respond to regulatory authorities
Organization and Responsibility
- Determining provider and deployer roles for each AI system
- Legal and compliance review
- Distinguishing the roles of content personnel and developers
- Designating the person with final editorial responsibility
- Training employees who use AI
Applying the Same Label to All AI Content Is Not the Answer
A company may choose to apply the same label to all AI-related content in an effort to simplify regulatory compliance.
However, this is not always the most appropriate approach.
Excessive labeling may make it difficult for users to distinguish important warnings from ordinary notices.
If content receives the same level of labeling as a deepfake even when AI merely performed auxiliary editing such as spelling correction, noise reduction, or background removal, the significance of the label may weaken.
Conversely, incorrectly classifying content that requires disclosure as a mere AI-assisted output may create regulatory compliance problems.
Rather than classifying AI use through a simple yes-or-no test, companies need a system that classifies content according to the following criteria.
- Did AI substantially alter the meaning of the original input?
- Could the content be mistaken for an actual person, event, or place?
- Does the content provide the public with information concerning matters of public interest?
- Is there substantial human review and editorial responsibility?
- Who encounters the content, and in what manner?
These criteria must be incorporated into product and content operations procedures so that the rules can be applied consistently.
A Voluntary Code of Practice Does Not Replace Legal Obligations
The European Union has established a Code of Practice on Transparency of AI-Generated Content to help companies comply with obligations concerning markings and labels for AI-generated content.
Participation in the Code of Practice is voluntary.
However, the transparency obligations under Article 50 of the AI Act are themselves legal obligations.
Companies participating in the Code of Practice can demonstrate compliance in a more predictable manner through the measures set out in the code.
Companies that do not participate may use other technologies and procedures, but they must separately demonstrate that their approach satisfies the applicable regulatory requirements.
The European Commission explains that companies not participating in the Code of Practice may receive additional requests for information because their method of compliance is relatively less transparent.
The choice for companies is not whether to comply with the regulation.
It is whether to reduce the compliance burden by using the common Code of Practice or to establish their own marking, labeling, and verification framework and demonstrate its adequacy.
What Penalties May Apply for Violating the Transparency Obligations?
The transparency obligations under Article 50 of the EU AI Act are legal requirements, not recommendations.
Administrative fines may be imposed when a company fails to properly disclose AI interaction, fails to apply required markings to AI-generated or manipulated content, or fails to appropriately disclose deepfakes and certain AI-generated texts concerning matters of public interest.
Under Article 99 of the EU AI Act, violations of obligations including Article 50 may be subject to administrative fines of up to the following limits.
- €15 million
- For companies, 3% of total worldwide annual turnover for the preceding financial year
For companies other than SMEs, the higher of the two amounts serves as the maximum fine.
For example, if a company’s worldwide annual turnover for the preceding financial year was €1 billion, 3% would equal €30 million.
In that case, €30 million, which is higher than the fixed amount of €15 million, could become the maximum fine.
However, a violation does not mean that the maximum fine will always be imposed.
The actual level of the fine is determined by considering factors such as the following.
- The nature, severity, and duration of the violation
- The number of affected people and the extent of the harm
- The size of the company and its worldwide turnover
- Whether the violation was intentional or negligent
- The economic benefit obtained through the violation and the measures taken to mitigate harm
- Cooperation with regulatory authorities and previous violations
Accordingly, a temporary technical failure in a marking function that a company immediately detects and corrects may not be assessed in the same way as a prolonged and intentional failure to comply with a known marking obligation.
Different Maximum Fine Calculations Apply to SMEs
For small and medium-sized enterprises, the higher of the two amounts is not applied in the same way as it is for larger companies.
For SMEs, the lower of the fixed monetary limit and the turnover-based percentage serves as the maximum fine.
For example, if an SME’s worldwide annual turnover for the preceding financial year was €10 million, 3% would equal €300,000.
Because this is lower than the fixed limit of €15 million for violations of Article 50 obligations, €300,000 could, in principle, become the maximum fine for that SME.
This mechanism takes the company’s size and ability to pay into account. However, the transparency obligations under Article 50 are not waived merely because a company is an SME.
Fines Are Not the Only Burden on Companies
The costs companies may face are not limited to administrative fines.
If a regulatory authority requires a company to correct a violation, the company may have to relabel products and content or modify its systems.
This may lead to additional costs such as the following.
- Urgent modification of products and AI marking functions
- Recall or republication of existing content and additional customer notices
- Reexamination of supplier contracts and internal procedures
- Legal and regulatory response costs and loss of trust in the company
In particular, when a labeling problem is discovered after AI-generated content has already been distributed widely across multiple platforms, the cost of modifying or recalling individual items may increase.
Companies should therefore focus not only on calculating the maximum possible fine but also on incorporating marking and review procedures at the product design stage to reduce the cost of later corrections.
DANA NOTES Commentary
The focus of AI regulation is expanding from managing how models are developed and trained to managing how AI-generated outputs are created, reviewed, and distributed, and who bears responsibility for them.
This change does not concern only generative AI companies.
Ordinary companies that subscribe to external AI services must also determine whether they are AI deployers. If they integrate an external model into their own product and provide it to customers, they may also assume the role of provider for the final AI system.
The questions companies must answer when adopting AI are also changing.
Previously, the main considerations were which AI model to use and what levels of generation quality and cost it offered. Going forward, companies must also determine who is the provider and who is the deployer, how far outputs will be distributed, and who will ultimately review them and assume responsibility.
In particular, capabilities that reliably identify AI-generated content, preserve marking information throughout editing and platform distribution, and help enterprise customers demonstrate regulatory compliance may become part of an AI product’s competitive strength.
AI transparency regulation is therefore not simply a regulation requiring the attachment of a label.
It is closer to a regulation requiring companies that use AI to reorganize their product design, content operations, supplier contracts, and internal approval systems.
Variables to Watch
First, companies must determine which existing generative AI systems qualify for the transitional period and whether they can implement marking functions by December 2, 2026.
Companies should examine not only the system’s development date or contract date, but also when it was actually placed on the EU market or put into service.
When an existing system is substantially updated or an external model is newly integrated into a company’s service, additional review may be required to determine whether it remains the same existing system or is regarded as the launch of a new system.
Second, companies must determine whether machine-readable marking technologies survive across different platforms and services.
Even when markings are properly embedded in the system that generated the content, their practical detection value may weaken if information is removed during image compression, video encoding, file conversion, or platform uploading.
Third, it will be necessary to observe how regulatory authorities distinguish substantial human review from formal review in actual cases.
For media companies, businesses, public institutions, and information platforms dealing with matters of public interest, the level of review required for editorial control will become an important operational standard.
Fourth, companies must examine how the boundary between provider and deployer is determined when external AI is connected to their own systems or offered under their own name.
The allocation of responsibility among model developers, system integrators, and final service operators may affect actual contracts and product structures.
Fifth, it will be necessary to determine how much documentation and additional information submission will be required when companies that do not participate in the Code of Practice attempt to demonstrate their own compliance methods.
Sixth, it will also be important to observe in which areas actual supervision and enforcement cases first emerge.
The priority of corporate responses may change depending on whether regulators first focus on customer service AI, deepfake advertising, automatically generated content concerning matters of public interest, or emotion recognition systems.

