The EU AI Act's Article 50 disclosure rule: what agencies building AI features for EU clients need to know
The short answer
If you've shipped, or are about to ship, an AI chatbot, an AI-generated content feature, or an emotion-detection tool for a client, and either that client operates in the EU or the tool's outputs reach EU users, Article 50 of the EU AI Act already applies to you. It isn't a future deadline. It took effect on 2 August 2026, the European Commission published its implementing guidelines on 20 July 2026, and non-compliance can trigger fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.
The short answer: If you've shipped, or are about to ship, an AI chatbot, an AI-generated content feature, or an emotion-detection tool for a client, and either that client operates in the EU or the tool's outputs reach EU users, Article 50 of the EU AI Act already applies to you. It isn't a future deadline. It took effect on 2 August 2026, the European Commission published its implementing guidelines on 20 July 2026, and non-compliance can trigger fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher.
This isn't legal advice, and the line between "provider" and "deployer" responsibilities has enough nuance that you should confirm your specific situation with counsel before publishing a disclosure statement. What follows is the plain-English version of what the regulation actually asks for, so you know what questions to bring to that conversation.
What Article 50 actually requires
Four separate obligations, and most agencies only need to worry about two or three of them depending on what they've built:
| Obligation | Who it applies to | What you actually have to do |
|---|---|---|
| AI-disclosure for direct interaction | Whoever builds or deploys a chatbot, voice agent, or similar system that talks to end users | Make sure the person knows they're talking to an AI, unless it's already obvious from context |
| Machine-readable marking of synthetic content | Providers of systems generating synthetic audio, image, video, or text | Mark outputs so they're detectable as AI-generated, in a machine-readable format |
| Emotion recognition / biometric categorisation disclosure | Deployers of systems that infer emotion or biometric category | Tell the person being analyzed that the system is running, before or during use |
| Deepfake and public-interest text disclosure | Deployers who generate or manipulate image, audio, video (deepfakes), or text published on matters of public interest | Disclose that the content is artificially generated or manipulated, unless a human has done substantive editorial review and taken responsibility for what's published |
Two carve-outs worth knowing. Content that's evidently artistic, satirical, or fictional gets a lighter version of the requirement: just note that AI was involved, without disrupting the work. And if a human editor has genuinely reviewed AI-assisted text and takes responsibility for it before publication, the text-disclosure obligation doesn't apply. That's a real, meaningful distinction between "AI drafted this and a person then edited and approved it" and "AI generated this and it went straight out."
Why "provider" vs. "deployer" matters more than it looks like it should
This is where most agencies get tripped up on a first read. If your team builds a chatbot for a client and that client runs it under their own brand, your agency may be acting as the provider (the party that built and placed the system) while your client is the deployer, the party actually running it in front of end users. The two roles carry different specific obligations. If you're white-labeling someone else's AI system rather than building it from scratch, the split can look different again.
This distinction changes who's actually responsible for the machine-readable marking versus who's responsible for the "you're talking to an AI" disclosure in the product itself, and it's exactly the kind of thing worth a short conversation with a lawyer before launch, not something to guess at from a blog post.
What we actually check for on AI feature builds
When we scope an AI feature for a client (a support chatbot, a content-generation tool, anything that talks to or writes for an end user), Article 50 is part of the build conversation from the start, not a bolt-on after launch: where the disclosure needs to live in the interface, whether outputs need machine-readable marking, and which party in the relationship is the one actually holding the obligation. That's part of what AI Features & Agents covers on our end.
A quick self-check before your next AI feature ships
- Does the AI system talk directly to end users? You likely need a "you're interacting with AI" disclosure, unless it's obviously an AI from context.
- Does it generate audio, image, video, or text that gets published or shared? Check whether machine-readable marking or a visible disclosure applies.
- Does it read emotion or categorize people biometrically? The person needs to be told, before or during use.
- Is AI-generated text going out on a matter of public interest without a human editor taking responsibility for it? That needs disclosure too.
If two or more of these apply and you haven't had a compliance conversation yet, that's worth doing before the next release, not after a complaint lands.
Sources: European Commission, Digital Strategy: Transparency obligations under Article 50 of the AI Act; official AI Act text via artificialintelligenceact.eu, Article 50.
Want a second set of eyes on whether your current AI feature already handles this, or need it built in from the start? Book a 20-minute fit call and we'll walk through it.