EU AI Act Article 50: Product Changes to Make
Article 113 of the EU Artificial Intelligence Act (Regulation (EU) 2024/1689, the “AI Act”) provides that, unless otherwise specified, the AI Act applies from 2 August 2026, following a transition period of about two years. Article 50 is not among the provisions listed in Article 113 as applying earlier or later. Its transparency obligations therefore also apply from 2 August 2026. Article 50 establishes several transparency obligations. Different product functions have different responsible parties, recipients of the information and implementation methods: some information must be shown directly when a person first interacts with AI; some markings must be embedded in generated content and be machine-detectable; other disclosures must be addressed directly to content viewers or persons exposed to the system.
One point requires attention. For AI systems placed on the market before 2 August 2026, the Article 50(2) obligation to mark and ensure the detectability of AI-generated content applies from 2 December 2026. This transitional arrangement does not apply to the other transparency obligations in Article 50.
On 20 July 2026, the European Commission published its Guidelines on the transparency obligations under Article 50 of the AI Act (the “Guidelines”). They further explain how providers and deployers of AI systems should meet obligations relating to human-AI interaction notices, machine-readable markings for synthetic content, notices for emotion recognition and biometric categorisation, deepfake disclosures, and disclosures for text on matters of public interest. Businesses offering AI assistants, customer-service tools, AI image generation, voice generation, image editing, digital humans, emotion analysis, biometric categorisation or AI-powered content publishing services in the EU should now identify the responsible party, disclosure recipient and transparency measure for each product function. A single, generic “AI-generated” notice cannot cover every compliance scenario.
This article draws on the text of Article 50, the Guidelines and the European Commission’s accompanying Q&A to analyse five categories of AI product transparency requirements, the allocation of responsibilities between providers and deployers, the application of different transparency measures, and the product improvements businesses should consider.
1. Three ways of implementing transparency obligations
From a product-implementation perspective, Article 50 involves three types of transparency measures:
| Transparency measure | Primary audience | Common implementation methods |
|---|---|---|
| Interaction notice | Natural persons interacting with, or exposed to, an AI system | Chat-window notice, welcome message, in-product notification |
| Machine-readable marking | Platforms, detection tools and other machine systems | Metadata, content credentials, digital watermarks or other detectable mechanisms |
| Explicit disclosure | Viewers or readers of deepfakes or specified public-interest text | Visible label, audible notice or disclosure directly associated with the content |
These measures cannot substitute for one another. Displaying “AI-generated” on a product page does not mean an exported image, audio file, video or text already carries a machine-readable marking. Adding an invisible watermark to a file also does not replace a deployer’s clear disclosure to content viewers. A general statement in a privacy policy or terms of service will usually not replace a notice at the first interaction or exposure.
The same content may trigger more than one obligation. For example, the provider of an AI face-swap tool may need to ensure that its output carries a machine-readable marking. A business that uses the tool to make and publicly publish a deepfake video may also have an explicit disclosure obligation as a deployer.
2. Specific requirements for different product scenarios
Drawing on Article 50 and the Guidelines, Kaamel groups the relevant transparency requirements into the following five product-focused check items:
| Product scenario | Responsible party | Product issue to address | Check item |
|---|---|---|---|
| AI assistants, customer-service tools and voice assistants | Provider | Whether users can identify the AI nature of the interaction at first contact | Check item (1) |
| AI image generation, writing, voice generation and image editing | Provider | Whether a machine-readable marking accompanies the generated content and remains detectable | Check item (2) |
| Emotion recognition and biometric categorisation | Deployer | Whether persons being recognised or categorised receive an effective notice | Check item (3) |
| Deepfakes such as face swaps, voice clones and digital humans | Deployer | Whether content recipients can promptly identify that content was generated or manipulated by AI | Check item (4) |
| AI-generated public news, notices and other text on matters of public interest | Deployer | Whether human review genuinely participates in the publication decision | Check item (5) |
(1) Notices for human-AI interaction
For AI assistants, customer-service tools and voice assistants, Article 50 focuses on whether a user can understand at the start of an interaction that they are engaging with AI. Product names, welcome messages, chat-window notices and voice announcements may all serve this notice function. A statement placed only in a privacy policy or terms of service will usually not demonstrate that users received the information during the actual interaction.
This obligation may appear to require only one additional notice, but it must be assessed across the full interaction journey. For example, a product may be called an “AI assistant” on its homepage, while a user who lands directly on an individual chat page from a search result may no longer see that name. A text chat may contain an identity notice, but the user may later switch to voice and hear a highly realistic human voice. A business may have provided a notice on its own platform, while the same service offered through a third-party platform, plug-in or API uses a different design. Each of these situations can affect whether the notice works in practice.
Anthropomorphic design also affects the assessment. The closer a real name, human portrait, natural voice, simulated typing indicator or emotional expression comes to a human interaction, the greater the risk of confusion. A business relying on the view that users obviously know they are interacting with AI should assess the interface design, access path and intended users together, and ensure that the notice covers web, mobile, voice and third-party access channels.
(2) Machine-readable markings for synthetic content
For AI systems that generate or modify audio, images, video and text, Article 50 requires providers to mark relevant output in a machine-readable format so it can be detected as artificially generated or manipulated. An “AI-generated” notice on a page mainly serves the current user. A machine-readable marking needs to be embedded in the output itself or remain stably associated with it.
The key product work is therefore in the output chain. Businesses should confirm that markings are applied across all output channels, including web downloads, mobile saves, API responses, batch generation and third-party plug-ins. Where a product supports several file formats, each format should be covered. For example, an image may carry provenance information when exported as PNG but lose it after conversion to JPEG. A video may carry content credentials in its original file but become unreadable after a platform compresses or transcodes it. A marking kept only in a company database may also be insufficient once content leaves the platform.
The marking mechanism itself also needs testing. Businesses should understand whether a marking is retained after compression, cropping, screenshots, transcoding and common editing operations, and document the technology’s scope and known limitations. Article 50 requires effectiveness, interoperability, robustness and reliability to the extent technically feasible. Merely integrating a watermark function shows that a measure has been taken; whether the marking performs reliably still depends on testing results.
Standard editing assistance and functions that do not substantially alter the input or its semantics may qualify for an exception. The assessment should focus on the function’s actual effect. Automated noise reduction, brightness adjustment, background replacement, subject redrawing and outpainting may all be described as editing tools, but they alter original content to materially different degrees. A product name alone cannot determine whether an exception applies.
(3) Notices for emotion recognition and biometric categorisation
Transparency design for emotion recognition and biometric categorisation systems begins with identifying the natural persons actually recognised or categorised. The system purchaser, back-office operator and analysed individual may be three different groups. Showing functional information only to administrators does not reach people being analysed in front of a camera or device, or through their data.
These systems are often embedded in other business processes. A recruitment platform may analyse a candidate’s video performance; a retail camera may analyse customer attributes; an online meeting tool may analyse participants’ states; and an education product may analyse student attention. Analysed persons may not actively open a specific AI feature and may not be able to tell from the interface that analysis is taking place in the background. Businesses should therefore design on-site notices, interface notices or other methods that reach the relevant persons in the actual context, taking into account when and where recognition occurs.
This check item also needs to be considered separately from the legality of the AI use itself. Article 50 addresses the notice. Article 5’s prohibitions, the GDPR and other data-protection rules determine whether the function may be used and what data may be processed. After giving notice, a business must still assess restrictions on emotion recognition in workplaces and educational institutions, and the legal basis for processing biometric data.
(4) Disclosures for deepfake content
Deepfake scenarios usually involve two product chains: a tool creates content, then a business or user publishes it. The provider of a generation tool needs to consider machine-readable marking; a deployer using the content needs to disclose its AI-generated or manipulated nature to viewers.
The two measures serve different audiences. Machine-readable markings are primarily for platforms and detection tools, and ordinary viewers may not see them. When a deployer publishes face-swap videos, voice-cloned content, digital-human videos or other highly realistic synthetic content, it must still design an explicit disclosure for natural persons.
Product teams need to decide who adds the disclosure, where it appears and how it remains associated with the content. Video platforms may provide a label in the player, title area or video itself. Audio content may require an audible notice or written information stably associated with the player. For content that can be forwarded or separated from its original page, teams should also consider whether the disclosure travels with the content. A statement only in the publishing back office, internal asset name or generation-tool introduction will usually not directly reach viewers.
Artistic, creative, satirical and fictional works can use disclosure methods that have less impact on the presentation of the work. Businesses still need to ensure that audiences can understand that the content was generated or manipulated by AI, taking account of the distribution context, realism of the content and audience expectations. Platforms offering generation, hosting and distribution services should also define the transparency measures assigned to each product module, so that no gap appears in the disclosure chain.
(5) Disclosures for text on matters of public interest
Article 50 also covers AI-generated or manipulated text published to inform the public about matters of public interest. For businesses, the key product-design issue is usually whether human review can amount to effective editorial control.
The presence of a person in a review flow does not necessarily mean that the text has received substantive review. Reviewers must be able to see the full content and its main basis, have authority to amend, return or reject it, and a natural or legal person must bear final editorial responsibility for publication. Spell-checking, formatting changes or clicking approval are unlikely to demonstrate substantive judgement about the accuracy of content and the decision to publish.
This obligation can directly affect permissions and workflow design in a content-management system. Businesses should identify which text must enter human review, what actions reviewers may take, how key facts and information sources are verified, whether amendments and returns are logged, and who gives final approval. If a system permits AI text to be published directly without review, the disclosure obligation needs to be reassessed even where sampling mechanisms exist.
Whether a text concerns a matter of public interest cannot be determined by content category alone. The same AI writing tool may generate marketing copy, product information, public-safety notices and financial news. The purpose and subject of each text can differ. Businesses should identify text that may trigger this requirement through content classification or publication workflows, rather than drawing one broad conclusion for an entire writing tool.
3. Four distinctions when applying transparency obligations
(1) Providers and deployers
Under Article 50, providers mainly bear the human-AI interaction notice and synthetic-content marking obligations. Deployers mainly bear the notice for emotion recognition and biometric categorisation, and disclosure obligations for deepfakes and public-interest text. The same business may have different roles across different parts of its operations because it develops a system, commissions development, calls a third-party model, provides functionality to customers or publishes content itself.
Businesses should therefore not classify the company as a whole as either provider or deployer. The role should be assessed separately for each product function and business chain.
(2) Machine-readable marking and explicit disclosure
Machine-readable markings primarily support automated detection and content provenance. Explicit disclosure primarily helps natural persons understand whether content was generated or manipulated by AI. The same content may require both measures, and neither replaces the other.
(3) General information and notices at interaction
Privacy policies and terms of service are general information. Several Article 50 obligations emphasise clear information at first interaction or first exposure. The main remediation points are therefore often chat windows, players, content pages, exported files and publication flows. Relying only on a general statement in a privacy policy will usually not meet the relevant requirements.
(4) Transparency and the lawfulness of AI use
Informing users that they are interacting with AI does not by itself make the system function or related data processing lawful. Disclosing a deepfake does not mean that its creation and distribution are free of other legal restrictions. Notifying people of emotion recognition does not displace the Article 5 prohibitions. Transparency is one part of AI compliance; it cannot replace an assessment of prohibited practices, data protection, consumer protection, intellectual property and other applicable requirements.
4. Preparing to meet transparency obligations
As the relevant Article 50 transparency obligations are about to apply, Kaamel recommends that businesses conduct product and compliance work across the following six areas.
First, establish an AI functionality inventory. Identify scenarios involving direct interaction, content generation and editing, emotion recognition, biometric categorisation and external publication of AI content, and record model sources, inputs and outputs, intended users and EU market touchpoints.
Second, determine roles by function and business chain. Confirm whether the business is a provider, deployer or both in each scenario, and clarify the responsibilities of product, engineering, legal, content operations and customers.
Third, map each product function to check items (1) through (5). Identify the recipient, timing, implementation method, exceptions and other applicable legal requirements for each function.
Fourth, establish product acceptance criteria. Review chat-window notices, machine-readable markings, deepfake disclosures and public-interest text review workflows, and test whether machine-readable markings remain after export, transcoding and common distribution chains.
Fifth, document conclusions on exceptions. For conclusions such as “users obviously know they are interacting with AI,” “the function is only standard editing” or “effective human review has occurred,” businesses should record the factual basis and review process rather than rely only on a product name or internal statement.
Sixth, retain compliance evidence. Businesses should keep interface screenshots, marking test results, review records, product-requirements documents, version records, role assessments and exception assessments so that they can verify that relevant controls remain effective.
Implementing Article 50 requires businesses to assess each AI function separately, including the responsible party, transparency measure, exceptions and evidence required. A single generic “AI-generated” notice cannot cover this work. The five check items outlined here can serve as a reference framework for businesses to organise product functions and discuss improvement options. The specific conclusion in each case still depends on the product design, use scenario and business chain.
Sources
European Commission Guidelines on Article 50; European Commission Q&A on Article 50 transparency obligations; European Commission quick facts on AI system transparency rules; European Commission Code of Practice on transparency of AI-generated content; Regulation (EU) 2024/1689.

