Guide · EU AI Act
How to comply with Article 50 of the AI Act
The Digital Omnibus pushed the high-risk regime back to December 2027. It did not push back Article 50. If your company publishes anything made with artificial intelligence, the duty to say so is already in force — since 2 August 2026. This guide is what we do in an afternoon: the inventory, the verdict piece by piece, the label wording and the record. No panic, nothing to buy.
Has the AI Act been delayed? Not for you
The confusion is recent and it has a date. The Digital Omnibus —Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since the 27th— moved deadlines in the Artificial Intelligence Act. Headlines said “the EU delays the AI Act” and a lot of companies breathed out.
What moved is the high-risk regime: stand-alone systems go to 2 December 2027, and those embedded as a safety component in products already covered by sectoral law, to 2 August 2028. If your company neither builds nor sells AI systems, that did not apply to you before and does not apply now.
Article 50 —the transparency duties— was left untouched. It still applies from 2 August 2026. The one remaining grace period is narrow and it is not yours: systems already placed on the market before that date have until 2 December 2026 to meet the Article 50(2) marking, and that marking belongs to whoever develops the system, not to whoever publishes with it.
Put briefly: the deadline that mattered to you has already passed.
It is not one duty: it is four
Article 50 gets quoted as if it were a single rule. It is four separate duties, aimed at different parties, and pulling them apart is what turns a vague problem into an afternoon of work.
- 50(1) — Say that they are talking to a machine. If you run a chat, an assistant or an automated voice that deals with people, you have to say so. Unless it is obvious to anyone in that context.
- 50(2) — Machine-readable marking. Synthetic content has to carry a technical mark that makes its origin detectable. This one belongs to the provider: whoever develops and markets the system. It is not your job.
- 50(4) — Disclose to the public. Deep fakes and, in certain cases, published informational text. This is where almost all the work sits for an ordinary company.
- 50(3) — Emotion recognition and biometric categorisation. If you use systems that read emotions or sort people by biometric traits, the people exposed to them have to be told. Few companies use this, but some who do have not noticed.
If you publish content and deal with customers, 50(1) and 50(4) are yours. The other two, in all likelihood, are not.
The afternoon inventory
Start with what is already published, not with what you are going to make. The duty looks at what is on view today. Open the website, the social accounts, the catalogue and the live campaigns, and sort them.
The deep fake test is two conditions at once: the piece imitates a person, a place or an event that exists, and it could look authentic to whoever sees it. If either one is missing, it is not a deep fake. This is the table we use:
| What you publish | Label? | Why |
|---|---|---|
| Chat or assistant on the website | Yes | Article 50(1). Before the first message, not in the legal notice. |
| Product photo retouched with AI (light, background, clean-up) | No | Editing, not impersonation. The product exists and is what it is. |
| Synthetic photograph of a product or venue that exists | Yes | It imitates something real and passes as authentic. Both conditions. |
| Render or plainly stylised illustration | No | Nobody mistakes it for a photograph. |
| Synthetic voice-over that imitates no one | No | It impersonates no particular person. 50(1) does apply if it answers calls. |
| Cloned voice of a real person | Yes | Direct impersonation. And mind image rights, which is a different law. |
| Video using the face or voice of staff, a client or a public figure | Yes | A textbook deep fake, however kind the intent. |
| Generated stock footage with no recognisable people | Depends | On whether the place or the event exists and is recognisable. |
| Blog or product copy written with AI | Depends | It is caught if it informs the public on matters of public interest. Human review plus editorial responsibility takes it out. Commercial copy is normally outside. |
| Machine translation of your own website | No | It generates no new content and imitates nothing. |
| Internal summaries, minutes and drafts | No | Not published. Article 50 is about what reaches the public. |
The middle column is not a legal opinion: it is the technical criterion we work to. There is little genuine doubt, and it tends to sit in the two rows marked “depends”.
What exactly to write
The disclosure has to be clear, perceptible and at first contact with the piece. Buried in the legal notice or three screens in does not count. This is what we put, and where:
Chat or assistant
“You are talking to an automated assistant. If you need a person, type human.”
Visible before the user’s first message, inside the chat window.
Image
“Image generated with artificial intelligence.”
In the caption, in the alt text and —if the piece travels on its own through social media— burnt onto the image itself. A caption that falls away when shared does not comply.
Video
“This video contains imagery and voice generated with artificial intelligence.”
In the opening seconds, on screen, and repeated in the post description.
Audio and voice-over
“Voice generated with artificial intelligence.”
Spoken at the start of the piece, not only written in the description. People listening to audio are not reading.
Three things that always go wrong: putting the label on the page but not on the piece that gets shared; writing it in a language other than the piece’s; and trusting the tool’s automatic watermark, which is the provider’s Article 50(2) and does not stand in for what you have to say.
The two cases almost everyone gets wrong
Artistic work. In evidently artistic, creative, satirical or fictional content the disclosure still exists. What changes is the form: it is allowed in a way that does not spoil the work. In the credits or the caption, that is, not stamped across the shot. Many people read the exception as an exemption, and it is not.
Text on matters of public interest. Text published to inform the public on matters of public interest falls within the duty. The way out is specific: there has to have been human review, and someone has to take editorial responsibility. Both, and written down somewhere. A company with a news blog needs this; a product catalogue does not.
An honest note: we are not a law firm. What is here is technical and documentary judgement, meant to hold up a conversation with yours, not to replace it.
The sheet that saves you the trouble
What gets asked for, when it gets asked for, is not the label: it is the record that you thought about it. And a decision dated after the question is worth nothing. Four columns in a spreadsheet will do:
- The piece and where it lives. A URL or a filename.
- What made it. Tool and, if you know it, version.
- The verdict and the reason. “Needs a label — imitates a real venue.” One line.
- Date and who decided. The part people forget, and the only one that gives the rest its value.
A twenty-row sheet made today is worth more than a hundred-page report made the day you are asked. And the inventory keeps itself if you update it as you publish, rather than in an annual review.
Who asks, and under what
The law is Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. It is an EU regulation: it applies directly, with no need for transposition.
In Spain the market surveillance authority is AESIA —the Spanish Agency for the Supervision of Artificial Intelligence—, created by Royal Decree 729/2023 and based in A Coruña. The penalty regime is in Article 99 of the Regulation: breaching Article 50 reaches 15 million euros or 3% of worldwide turnover, whichever is higher. The Spanish Organic Law bill that implements it, approved by the Council of Ministers on 26 May 2026, names AESIA as the lead authority. The AEPD keeps its role over biometrics and personal data.
For a small or medium company the realistic risk is not the maximum fine: it is the request. Someone asks, and you have to answer with paperwork. The Digital Omnibus did introduce some scaling of penalties for smaller companies — but the duty to answer does not scale.
When there is nothing to do
It happens often. A company that uses AI to write product copy, translate its website, retouch catalogue photos and summarise meetings has nothing to label. Add a chat on the site and it owes one line of text, and that is that.
If your inventory comes out at zero, the work was not wasted: you now have it written down and dated why it is zero. That is exactly what is being asked for.
And the other way round: an audit that concludes “label everything” is not an audit, it is a fear policy. The value is in knowing where the line runs.
And if you would rather we did it
AI transparency audit. The inventory, the verdict piece by piece and a dated, filable document. What this guide describes, done and signed.
Can AI find you? A different question altogether: whether ChatGPT, Gemini or Perplexity name your company when someone asks about your sector. The checker is free.
Frequently asked questions
Did the Digital Omnibus delay Article 50?
No. Regulation (EU) 2026/1744, in force since 27 July 2026, pushed the high-risk regime to 2 December 2027 and 2 August 2028, but left Article 50 untouched. The transparency duties have applied since 2 August 2026.
What about the 2 December 2026 deadline?
That is the grace period for the machine-readable marking under Article 50(2), and only for systems already placed on the market before 2 August 2026. That duty belongs to the system provider. If you publish using a third party’s tool, it is not your deadline: you are already bound.
Do I have to label text I write with AI?
Usually not. The duty reaches text published to inform the public on matters of public interest, and human review with editorial responsibility takes it out. A product page, a service page or a sales email fall outside.
What about product photos retouched with AI?
Retouching light, background or blemishes is editing: no label. Generating from scratch a photograph that looks real of a product or venue that exists, yes. The line is whether it imitates something real and could pass as authentic.
Where exactly does the label go?
At first contact with the piece and perceptibly: in the opening seconds of a video, at the start of an audio, in the caption and on the image itself if it travels alone, and before the first message in a chat. The legal notice does not count.
Does the tool’s watermark cover me?
For Article 50(2), which is the provider’s, yes. For your duty to disclose to the public, no: they are two different things. Metadata in the file does not mean the user has been told.
What do I have to keep, and for how long?
Piece, tool, verdict with its reason, date and who decided. For as long as the piece stays published, at least. The value is in the date being earlier than the question.
Does this reach content I published before August 2026?
If it is still published, yes. The duty looks at what is on view today, not at when it was made. That is why the inventory starts with what is already online.
Last reviewed: 2026-10-02 · This guide covers a law that is still moving. We review it monthly.

