← Back to overview

EU AI Act Article 50: Transparency Obligations for AI Systems – What Businesses Need to Know Now

Dr. Maik Bunzel
Dr. Maik Bunzel
16.08.2026 · 7 min read
EU AI Act Article 50: Transparency Obligations for AI Systems – What Businesses Need to Know Now

The Silent Deadline: Why Article 50 Catches Many Companies Off Guard

While many companies breathed a sigh of relief in the first half of 2026 upon hearing that significant parts of the EU AI Act had been postponed, another clock was quietly ticking away. On 2 August 2026, the transparency obligations under Article 50 of the EU AI Act (Regulation (EU) 2024/1689) came into force – on schedule, without delay, without any transitional period. Those who had hoped the Digital Omnibus package would push back these provisions too were mistaken.

The consequence: companies that deploy chatbots, produce synthetic media, use emotion recognition, or publish deepfake content are now subject to concrete statutory disclosure obligations. And the fines for non-compliance are substantial: up to 15 million euros or 3 percent of global annual turnover – whichever is higher.

What Article 50 Specifically Requires

Article 50 of the EU AI Act defines four distinct transparency obligations, targeting different groups of providers and operators:

  • Providers of conversational AI systems (chatbots, voice assistants): They must ensure that users can recognise they are interacting with an AI – unless this is already obvious. Disclosure must take place no later than at the first interaction.
  • Providers of systems for synthetic content generation (image, audio, video, and text generators): Outputs must be marked in a machine-readable format that identifies them as AI-generated or AI-edited. The technical solution must be effective, interoperable, robust, and reliable – "insofar as this is technically feasible".
  • Operators of emotion recognition or biometric categorisation systems: Affected individuals must be informed about the use of the system, in accordance with applicable data protection law.
  • Operators of deepfake or AI-generated content on matters of public interest: Such content must be labelled as artificially created or altered – with exceptions for clearly artistic, satirical, or fictional works, as well as for human-edited texts with clearly assigned editorial responsibility.

Crucially, these obligations are not tied to a risk classification under Annex III. They apply functionally – that is, whenever an AI system is conversational, generative, emotion-recognising, or deepfake-producing. This effectively encompasses the full breadth of modern enterprise AI deployments: from OpenAI's ChatGPT and Anthropic's Claude to internal AI assistants.

The Digital Omnibus Misunderstanding

The EU Digital Omnibus package, politically agreed in May 2026 and adopted by the Council at the end of June 2026, pushed back the compliance deadlines for standalone high-risk AI systems under Annex III to 2 December 2027 – and for product-integrated systems under Annex I even until August 2028. The background: harmonised technical standards from CEN-CENELEC were not available by the original deadline.

Article 50, however, was explicitly excluded from these negotiations. The transparency obligations are structurally different from the high-risk requirements – they do not follow a risk typology but a functional logic. The Digital Omnibus package left this category untouched. The sole exception: a separate four-month transition period for the machine-readable watermarking obligation, running until 2 December 2026.

Dr. Maik Bunzel, founder and managing director of mabucon.eu, observes in his consulting practice that many mid-sized companies have placed too much weight on the delay announcements: "The broad communication surrounding the Omnibus package has created a misconception. Many organisations assume they can sit out the EU AI Act topic until the end of 2027 – yet the transparency obligations for chatbots and generative AI are already in force today."

The technical gap: when law outpaces technology

Particularly critical is the discrepancy between legal requirements and technical reality when it comes to the watermarking obligation for synthetic content. Independent security research shows that current watermarking methods are vulnerable:

  • Researchers at ETH Zurich's SRI Lab demonstrated that an attacker can crack a watermarking scheme with a success rate of over 80 percent through simple API queries – both to remove the watermark from AI-generated texts and to impose it on human-authored text. The cost: under 50 US dollars.
  • A further attack, known as the Self-Information Rewrite Attack, specifically targets the high-entropy tokens in which the signal is typically embedded – and removes the watermark without altering the semantic content of the text.
  • For image watermarks, a publicly available tool already exists that circumvents Google's own SynthID detection system on images currently generated with Gemini.

The legislative text itself accounts for this uncertainty: the criterion "insofar as technically feasible" builds a degree of flexibility into the standard. Authorities will therefore likely assess compliance not against a fixed technical benchmark, but against the state of the art at any given point in time. On the one hand, this provides some relief; on the other, it represents an ongoing obligation: companies must continuously review and adapt their technical measures.

"Watermarking technology is not a solved problem. Anyone who introduces a solution today and considers it permanently compliant is acting negligently. Compliance in the area of synthetic content is an iterative process."

The burden of proof lies with the company

An often overlooked detail of the regulation concerns the burden of proof. Unlike in some other regulatory areas, under Article 50 it is not for the authority to demonstrate a violation – but for the company to provide evidence of proper and timely disclosure. This has direct implications for documentation obligations: companies should keep verifiable records of when which disclosure texts were implemented, what technical measures were taken, and how internal review was conducted.

National market surveillance authorities have been empowered to initiate corresponding enforcement measures since 2 August 2026. The European Commission has published a voluntary icon set for labelling AI-generated content, though its use is optional. The underlying disclosure obligation itself remains binding.

Which systems are specifically affected

The scope of Article 50 is considerably broader than widely assumed. Not only specialised deepfake applications fall within its remit – but the entire mainstream of generative AI in enterprise use:

  • Internal and external chatbots based on language models such as GPT-4 or Claude
  • AI-assisted text creation tools in marketing, customer service, or HR
  • Image generators in design and communications
  • Voice and video synthesis tools for training or customer communication
  • Systems for sentiment analysis or emotion recognition in customer experience contexts

B2B deployments are not exempt either: if a company operates a chatbot for its customers, it bears responsibility as a deployer – regardless of whether the underlying model provider meets its own obligations.

Recommendations for companies

Dr. Maik Bunzel, founder and managing director of mabucon.eu, recommends that companies treat Article 50 compliance not as a one-off project, but integrate it as an ongoing operational task into their AI governance: "Transparency obligations are not bureaucracy to be ticked off once. They must be built into every deployment process for AI systems – from conception through to operation."

Specifically, the following steps are recommended:

  • Inventory of all AI systems that may fall under Article 50 – in particular conversational and generative applications
  • Implementation of clear disclosure notices at first user interaction, accessible and in plain language
  • Technical review of the watermarking solution for synthetic content, including regular reassessment in light of rapid developments in adversarial research
  • Documentation of compliance measures with timestamps and responsible persons, in order to bear the burden of proof in the event of an investigation
  • Clarification of deployer responsibility in contracts with AI providers, particularly where external models are used

Outlook: Article 50 as a blueprint for AI transparency

In its design, Article 50 is a precursor to a more comprehensive AI transparency policy that is likely to set a precedent beyond the EU. The core idea – functional obligations that apply independently of risk classifications – could serve as a model for future regulatory frameworks. At the same time, the debate around the limits of technical enforceability (watermarks, detection systems) shows that regulatory intent and technical feasibility do not always align.

For companies, this means: the use of generative AI is no longer a regulatory grey area. Anyone who uses AI systems productively already bears active disclosure obligations today – and should build the technical and organisational infrastructure for this now, before enforcement authorities take action.

Contact

Which of your workflows should become smarter first?

Briefly describe the process you would like to support or replace with AI. We will get back to you with a first, concrete assessment — no obligation and confidential.