logo
|
Blog
    INSIGHT

    EU AI Act Article 50 Explained

    The transparency obligations for AI systems and AI-generated content, article by article — and who actually has to comply.
    muse blossom's avatar
    muse blossom
    Jul 28, 2026
    EU AI Act Article 50 Explained
    Contents
    Who has to comply50(1) — AI systems that talk to people50(2) — Marking AI-generated content50(3) — Emotion recognition and biometric categorization50(4) — Deepfakes and AI-generated public-interest text50(5)–(7) — How and when this actually gets appliedWhen it takes effectPenaltiesWhere this is going

    💡

    Article 50 of the EU AI Act (Regulation (EU) 2024/1689) is the part of the law that most companies working with generative or interactive AI will run into first. It sits in Chapter IV, titled "Transparency obligations for providers and deployers of certain AI systems," and it covers four separate situations rather than one single rule. Here's what each part actually requires.

    Who has to comply

    Article 50 applies to providers and deployers of AI systems whose output reaches people in the EU — not to companies that happen to be headquartered in the EU. A company based in Korea, the US, or anywhere else is in scope the moment its AI system interacts with, or generates content for, people in the EU. Where the company sits doesn't change that.

    50(1) — AI systems that talk to people

    If an AI system is designed to interact directly with people (a chatbot, a voice assistant), the provider has to make sure people know they're talking to an AI — unless that's already obvious given the context. There's a carve-out for AI systems that law enforcement is authorized to use for detecting or investigating crime.

    50(2) — Marking AI-generated content

    This is the provision most companies in the content and media space actually need to build for, so it's worth going through in more detail.

    Providers of AI systems — including general-purpose AI systems — that generate synthetic audio, image, video, or text have to ensure the output is marked so it can be detected as AI-generated or manipulated. The regulation itself is specific about the bar this has to clear. It requires that outputs be

    "marked in a machine-readable format and detectable as artificially generated or manipulated" (Article 50(2))

    — which rules out a visible caption or an "AI-generated" label as a complete solution on its own. A human-readable tag doesn't help a detection system verify anything. The law also requires the technical solution to be effective, interoperable, robust, and reliable "as far as this is technically feasible," accounting for the type of content, the cost of implementation, and the current state of the art.

    There are two exceptions: content where the AI performs only an assistive editing function without substantially altering the input, and systems authorized by law for criminal detection or investigation.

    In practice, this is why watermarking-only approaches and C2PA-only approaches are both incomplete on their own. A visible or invisible watermark can be a machine-readable signal, but it needs to survive re-encoding, screenshotting, and format conversion to stay detectable — and C2PA's Content Credentials give it something a raw watermark doesn't: a verifiable, structured provenance record embedded in the file's metadata. Most compliant implementations combine the two rather than picking one.

    50(3) — Emotion recognition and biometric categorization

    Deployers using an emotion recognition or biometric categorization system have to inform the people exposed to it, and handle their personal data under GDPR and the other applicable EU data protection rules. The same law-enforcement carve-out applies here.

    50(4) — Deepfakes and AI-generated public-interest text

    Deployers of a system that generates or manipulates image, audio, or video content amounting to a deepfake have to disclose that it's artificially generated or manipulated. If the content is clearly artistic, creative, satirical, or fictional, the disclosure requirement is lighter — it just needs to be visible in a way that doesn't get in the way of experiencing the work.

    Separately, if an AI system generates or manipulates text that's published specifically to inform the public on a matter of public interest, that has to be disclosed too — unless the content has gone through human review and a named person or organization holds editorial responsibility for it.

    50(5)–(7) — How and when this actually gets applied

    • The disclosures required under 50(1)–(4) have to be clear, distinguishable, and given no later than the first interaction or exposure, and they have to meet EU accessibility standards.

    • None of this replaces the separate obligations that apply to high-risk AI systems, or any other transparency rules already set elsewhere in EU or national law.

    • The EU AI Office is tasked with encouraging a Code of Practice to standardize how the detection and labelling obligations get implemented in practice — which is where the technical specifics that aren't spelled out in the law itself are meant to get filled in.

    When it takes effect

    Article 50 applies from August 2, 2026. There's one adjustment worth knowing about: in May 2026, EU negotiators agreed to delay the machine-readable marking requirement under 50(2) until December 2, 2026, but only for generative AI systems that were already on the market before August 2. Anything launched on or after August 2 has to meet the marking requirement immediately, with no grace period. The disclosure and deepfake-labeling obligations under 50(1), 50(3), and 50(4) aren't affected by this delay — they apply from August 2 regardless of when the underlying system launched.

    Penalties

    Non-compliance with Article 50 carries fines of up to €15 million or 3% of global annual turnover, whichever is higher, with proportional caps for SMEs. Enforcement runs through national market surveillance authorities, with the AI Office handling systems under its direct oversight.

    Where this is going

    The exact technical bar for "machine-readable marking" is still being filled in through the Commission's Code of Practice, so the specifics will keep tightening between now and December. MuseBlossom's ContentsDefence pairs C2PA content credentials with imperceptible watermarking specifically to meet the 50(2) marking requirement across image, audio, video, and document content — the combination the law's own language points toward, rather than either technique alone.

    ※ Article text and dates cited in this article are drawn directly from Regulation (EU) 2024/1689 (the EU AI Act), the European Commission's July 2026 guidelines and Code of Practice on Article 50, and the May 2026 EU AI Omnibus provisional agreement between the European Parliament and Council. Forward-looking interpretation and commentary are MuseBlossom's own, based on these public sources.

    ✉️

    "Start preparing for AI content watermarking now. MuseBlossom's ContentsDefence protects image content through a single API — audio, video, and document support are in active development."

    Explore Contents Defence

    Contact : contact@museblossom.com

    Share article
    Contents
    Who has to comply50(1) — AI systems that talk to people50(2) — Marking AI-generated content50(3) — Emotion recognition and biometric categorization50(4) — Deepfakes and AI-generated public-interest text50(5)–(7) — How and when this actually gets appliedWhen it takes effectPenaltiesWhere this is going

    MUSEBLOSSOM

    RSS·Powered by Inblog