AI made it? Say so. What the Commission’s new AI Act transparency Guidelines require

AI Act transparency Guidelines

AI made it? Say so. What the Commission’s new AI Act transparency Guidelines require

The European Commission’s Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act (20 July 2026), and the accompanying Code of Practice on Transparency of AI-generated Content – what they mean in practice, and when AI-generated content must be marked and labeled.

Summary

  • Four duties, two owners. Providers must design interactive systems to disclose themselves (Article 50(1)) and embed an invisible, machine-readable mark in synthetic output (Article 50(2)); deployers must notify people exposed to emotion-recognition and biometric categorization systems (Article 50(3)) and add a visible label on deep fakes and on public-interest text (Article 50(4)). The duties are cumulative, none discharges another, and the same organization frequently owes several.
  • Not every AI output has to be marked. Standard editing and minor alterations, AI translation, formatting, source code, single words and captions, machine-to-machine data, and genuine closed-loop internal B2B material all fall outside the scope of duty. That is where most of the practical relief lies.
  • AI-generated or manipulated public-interest text deserves particular attention. AI-touched investor and sustainability reports on a company website need a visible label unless genuine human review and editorial responsibility are both documented – and that exception collapses the moment AI edits the text after editorial sign-off.
  • Article 50 does not stop at the EU border. A provider or deployer established outside the EU owes the same duties where the output of its system is foreseeably used in the Union – so a third-country group entity generating content targeted at EU audiences is in scope.
  • A label is not a license. Marking and labeling answer the question “is this AI?”, not “is this allowed?”. A properly labeled deep fake can still be unlawful on other grounds, and a 50(3) notice does not legitimize a deployment prohibited under Article 5 or unlawful under data protection law.
  • One deadline has passed, one is coming – and the fines are real. Chatbot and voice-assistant disclosure under Article 50(1) has been required since 2 August 2026, with no grandfathering; providers of generative systems already on the market have until 2 December 2026 to bring Article 50(2) marking into conformity. Non-compliance amounts to EUR 15 000 000 or 3% of the total worldwide annual turnover, whichever is higher, with RRT supervising in Lithuania.

Since 2 August 2026, a new layer of Regulation (EU) 2024/1689 (the “AI Act”) applies to almost every business that lets customers talk to a chatbot, generates images or text with artificial intelligence (AI), or edits media with AI tools.

Article 50 of the AI Act imposes a set of transparency obligations: people must be told when they are dealing with AI, and AI-generated or manipulated content must be marked and, in defined cases, visibly labeled. On 20 July 2026, the European Commission (the “Commission”) adopted detailed Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of the AI Act (the “Guidelines”), complemented by the Code of Practice on Transparency of AI-generated Content (the “Code of Practice”).

The Guidelines are non-binding – only the Court of Justice can give an authoritative interpretation of the AI Act – but they are the clearest practical map of what is in scope, what is out of scope, and who has to do what.

This article walks through the four obligations, with the emphasis on the question clients actually ask: what has to be marked or labeled as AI, and by whom? It pays particular attention to the financial market and its participants – banks, payment and electronic money institutions, investment firms, crypto-asset service providers, insurers and listed issuers – for whom AI-touched investor communications, corporate and sustainability reports, client-facing chatbots, marketing content and biometric onboarding tools sit squarely inside Article 50, on top of the disclosure and conduct duties they already owe under financial services regulation.

The four obligations at a glance

Article 50 contains four distinct transparency duties, each attaching to a different type of AI system or output, and each falling on either the provider (the entity that develops the system and places it on the market under its own name) or the deployer (the entity that uses the system under its own authority, unless the use is purely personal and non-professional). The distinction matters because the same organization can be both at once – for example, a firm that builds an in-house generative tool and then uses it to produce deep fakes wears both hats. The deployer side reaches wider than most clients assume: businesses, public-sector bodies, media outlets, advertising and marketing agencies, and any other legal or natural person using AI content in a professional or economic activity – including influencers monetizing social media. Purely personal, non-professional use is outside Article 50 altogether.

  • Article 50(1) – interactive AI. The provider must design the system so that a person is informed that they are interacting with an AI. Think chatbots, voice assistants, and AI agents.
  • Article 50(2) – marking of synthetic content. The provider must ensure that AI-generated or manipulated audio, images, videos, or text are marked in a machine-readable format and detectable as artificial.
  • Article 50(3) – emotion recognition and biometric categorization. The deployer must inform people exposed to such a system that it is operating.
  • Article 50(4) – deepfakes and certain text. The deployer must clearly and visibly label deepfakes and AI-generated or manipulated text published to inform the public on matters of public interest.

A single system can trigger several of these at once. An image generator embedded in a chatbot engages 50(1) and 50(2) for the provider; if the deployer uses it to create a deep fake, 50(4) applies on top. The obligations are cumulative, not alternative.

Article 50 does not stop at the EU border. A provider or deployer established outside the EU is caught where the output of its AI system is used in the Union – so a third-country group entity generating content that is disseminated to, or targeted at, EU audiences owes the same duties as an EU actor. The trigger is foreseeable use of the output in the Union: a deployer who directs or authorizes EU distribution, including by posting deep fakes on the open internet, is in scope, whereas purely incidental or unforeseeable downstream use that reaches the Union through channels outside the actor’s control is not.

Two kinds of “marking” – and why the difference matters

The word “marking” serves two very different functions in Article 50, and conflating them is the most common source of confusion. It is worth pinning down the distinction before going further.

Machine-readable marking (Article 50(2)) is invisible plumbing. It is a technical signal – a watermark, metadata, a cryptographic provenance tag, a fingerprint – embedded in the content so that software can later identify it as AI-generated. It is the provider’s job, and it applies to essentially all synthetic audio, image, video and text output of the system.

Visible labeling (Article 50(4)) is a disclosure a person can see or hear – a caption, a banner, a spoken statement – telling the audience that a deep fake or a public-interest text is artificial. It is the deployer’s job, and it applies to a much narrower set of content.

The Guidelines are explicit that these do not substitute for one another. A deployer cannot discharge the 50(4) labeling duty by pointing to the provider’s machine-readable mark, because that mark is not perceptible to the ordinary viewer without special tools. Conversely, a visible label does not relieve the provider of the duty to provide a machine-readable marking under 50(2).

What must be marked under Article 50(2)

This is the obligation with the widest reach, and the one clients most often ask about. It applies where all of the following are true: the system is an AI system; it generates or manipulates synthetic content; the content is audio, image, video or text (an exhaustive list, but one that includes multimodal, 3-D, and virtual and augmented reality (VR/AR) output); and none of the exceptions applies.

Crucially, content does not have to be wholly AI-generated to count. Content mixed with human-created material still qualifies as synthetic if the AI-generated or manipulated part falls within one of the four modalities. “Generation” means creating new material (an AI-drawn image, a synthesized song); “manipulation” means altering existing content beyond standard editing (a face swap, a voice clone).

Marking is only half of it. Article 50(2) imposes two cumulative duties: the provider must mark the output in a machine-readable format and ensure a means of detection is available to the people exposed to it, one that returns a human-readable result indicating whether the content is AI-generated or manipulated. A mark that no one can read back is not compliance. Where the provider relies on another actor for detection, it remains responsible for ensuring that the solution works and that the result is clearly shown at first exposure.

In scope – must be marked

  • AI-generated summaries of text, or paraphrasing/rewriting that changes style, structure or meaning.
  • Removal, replacement or insertion of objects or persons in images and videos that change the substance; face replacement or substantial facial modification.
  • Synthesis of a specific person’s voice, or a realistic video of events that did not occur; altering a person’s body shape or skin color.
  • Composite images or clips that modify the depiction of persons, objects, events or facts.
  • AI agent output that is perceptible to a person as audio, image, video or text.

Out of scope – no marking required

The Guidelines carve out a long list of things that do not have to be marked, which is just as useful to know:

  • Standard editing and minor alterations – grammar and spell-checking, minor stylistic polishing, AI-generated translations, formatting and format conversion, noise reduction, minor cropping or color correction, red-eye removal, background blurring, video stabilization, and converting black-and-white to color.
  • Non-substantial changes – anything that does not significantly alter the input data or its meaning, style or intent.
  • Source code – code in any programming, scripting, markup, query or configuration language (including SDKs, SQL, YAML, JSON, APIs), and integral comments.
  • Very short outputs – single words, image captions, alt-text, UI labels, icon-scale graphics.
  • Machine-to-machine output processed automatically and never perceived by a person; internal analytical extraction and structuring of data; mere reproduction, ranking or arrangement of existing content (playlists, recommender systems).
  • Closed-loop and industrial output – strictly technical, business-to-business (B2B) output, perceived only by a limited pre-defined set of professionals inside the organization, not shared externally, with appropriate safeguards. Real-time ephemeral content (e.g. in games or VR) consumed immediately and not stored may also be exempt where marking is not technically feasible, and an in-experience notice is provided.
  • Law enforcement use authorized by law to detect, prevent, investigate or prosecute criminal offences.

The technical solution must be effective, interoperable, robust and reliable, as far as technically feasible and in line with the state of the art. Providers may rely on an adequate Code of Practice to demonstrate compliance; those who do not adhere to one must provide equivalent alternative measures and should expect closer scrutiny and more information requests.

What must be labeled under Article 50(4)

This obligation sits on deployers and concerns visible, perceivable disclosure. It has two limbs.

Deepfakes

A “deepfake” is AI-generated or manipulated image, audio or video content that (i) appreciably resembles (ii) an existing (iii) person, object, place, entity or event, and (iv) would falsely appear to a person to be authentic or truthful. “Existing” is read broadly: something that exists, plausibly could exist, or could have plausibly existed. Content that defies physics or biology – a dragon, an elephant driving a car – is not a deepfake, because it cannot mislead.

Minor or cosmetic AI manipulation of existing content does not make it a deepfake in the first place, where the change has too little effect on how a viewer perceives the content’s authenticity or truthfulness – for example, editing out a background passer-by, adjusting lighting or color, noise reduction, re-scaling or file compression. This is a threshold question, not an exemption: such content is simply not a deep fake, so no labelling duty arises. Whether a given edit stays on this side of the line is context-dependent: the Guidelines contrast these cosmetic operations with substantial AI editing of journalistic images, where the expectation of authenticity is high enough that a similar change may affect perceived authenticity and cross into deep fake territory.

The fourth criterion is assessed objectively and in context; the deployer’s intention to deceive is not required. Where the foreseeable audience does not expect the content to be authentic – for instance, standard special effects in a movie – the content may not “falsely appear” authentic and so falls outside the definition. But fully AI-generated actors, digital replicas of real or deceased actors, de-aging, or non-authentic depictions in documentaries generally will be deepfakes.

Deepfakes must be clearly and distinctly labeled. A lighter regime applies to content that is evidently artistic, creative, satirical, fictional or analogous: the disclosure need only be made in a manner that does not hamper enjoyment of the work, but disclosure is still required, and the “evidently” threshold is read strictly. Two limits keep this regime narrow. Where content mixes an informative and a creative character, the informative character prevails labeling, and full labeling applies; and the lighter regime is, in any event, subject to appropriate safeguards for third-party rights, so it is no justification for disregarding data-protection or intellectual-property obligations.

Public-interest text

AI-generated or manipulated text published to inform the public on matters of public interest must also be labeled. “Published” means accessible to an indeterminate, fairly large group; “public interest” covers politics, public administration, justice, fundamental rights, public health and safety, the environment, consumer safety, and economic, financial, scientific or cultural developments meriting public debate.

There is an important exception: text that has undergone genuine human review or editorial control and for which a natural or legal person holds editorial responsibility need not be labeled. Both conditions are cumulative. A superficial spell-check, an automated review, or a mere editorial policy will not do – the review must engage with the substance, and fact-checking is the minimum. If AI makes any substantive change after editorial sign-off, the exception falls away.

For a regulated financial entity, note the concrete examples the Guidelines give as in scope: AI-manipulated corporate reports containing investor information on a listed company’s website, and AI-generated sustainability reports – both of which need labeling unless the human-review/editorial-responsibility exception is satisfied. Conversely, an AI-manipulated advice text prepared by a consultant for a single client on regulatory compliance is not “published” and falls outside 50(4).

How to label in practice

Article 50 does not dictate wording. The Code of Practice does the practical work: the AI Office has published three EU icons – AI involved, fully AI-generated, and human content modified by AI – free to use, and testing showed that an icon on its own is not enough. The icon plus a few plain words are what people actually understand. “AI” is the only abbreviation to use.

What that looks like in practice. An icon and “Image created with AI” in the caption of a social media post – not in the small print. A spoken line in the first seconds of a podcast produced with a synthetic voice. A badge at the top of an AI-drafted news summary, not in the website footer. A mark that stays in the corner of the screen while an AI presenter is speaking. Give the icon alt text so a screen reader conveys it, leave a temporary label up long enough to be read, and use the same icon and the same words everywhere.

A label is not a license. The Guidelines are emphatic that complying with Article 50 does not make the content or its use lawful. A properly labeled deep fake can still be unlawful on other grounds – child sexual abuse material, non-consensual intimate imagery, trademark or copyright infringement, misleading advertising – and a 50(3) notice does not legitimize an emotion-recognition deployment that is prohibited under Article 5 or unlawful under data protection law.

Marking and labeling answer the question “is this AI?”, not “is this allowed?” The two assessments are separate.

The other two obligations, briefly

When must a chatbot tell users that they are interacting with AI?

Providers of systems that interact directly with people – chatbots, voice assistants, AI companions, AI agents – must design them so the person is told they are dealing with AI, at the latest at the first interaction. The disclosure must be clear and in context: a first-turn message, a spoken statement, a persistent badge. Burying it in terms and conditions, or relying on a vague reference to an “assistant” or “this system uses LLMs”, is not enough.

There is an obviousness exception – no disclosure is needed where it would be obvious to a reasonably well-informed, observant and circumspect person that they are dealing with AI. But the Guidelines read this narrowly: general awareness that chatbots exist does not mean people recognize them in a given interaction, and the exception is unavailable where vulnerable groups (children, the elderly, the less digitally literate) may be exposed. A professional-only internal helpdesk assistant may qualify; a public-facing helpdesk chatbot generally will not.

AI agents carry an extra layer. An agent must disclose not only its artificial nature but also the person on whose behalf it acts, reflecting the need for transparency regarding both its origin and delegated authority. Where the provider cannot know in advance whether an agent will meet a natural person, it must be designed to disclose itself in every situation where interaction with a person is reasonably likely, including in multi-agent chains where another agent is the one facing the person. Agents should also re-disclose to the person instructing them at key steps such as authorization, reporting and validation, and at every new interaction.

Emotion recognition and biometric categorization – Article 50(3)

Deployers of these systems must inform the people exposed to them that the system is operating – for example, a notice at the entrance to a space where facial images are captured to infer age, or a pop-up before a game that reads the player’s emotions. This applies whether the system runs in real time or after the fact, and to any biometric categorization system (unless outright prohibited under Article 5).

Timing, accessibility and penalties

Whatever the obligation, Article 50(5) requires the information to be given clearly and distinguishably, at the latest at the first interaction or exposure, and in an accessible format. “First exposure” means the start of a video featuring a deepfake, the start of a public-interest text, or the moment a person scrolling through social media encounters the content. Where children are foreseeably in the audience, the disclosure must be child-friendly and age-appropriate.

Non-compliance is not trivial. Fines can reach EUR 15 000 000 or 3% of total worldwide annual turnover, whichever is higher (EU institutions face up to EUR 750 000; small and medium-sized enterprises (SMEs) and start-ups face the lower of the two figures). Enforcement sits with national market surveillance authorities, the AI Office for systems based on general-purpose AI (GPAI) models, and the European Data Protection Supervisor (EDPS) for EU institutions.

In Lithuania, the Communications Regulatory Authority (RRT) has already issued public guidance of its own on when AI-generated content must be marked and when it need not be – an early signal that the national supervisor intends to engage with these obligations actively rather than wait for complaints.

On timing of application: Article 50 has applied since 2 August 2026 to all in-scope systems on the market on that date, regardless of when they were placed. A targeted grandfathering rule under the AI Omnibus gives providers of existing generative systems until 2 December 2026 to bring the 50(2) marking into conformity – but the 50(1) interaction disclosure had to be in place by 2 August 2026. Content generated before 2 August 2026 need not be marked or labeled retroactively, but pre-existing text published on or after that date does need labeling.

What should businesses pay attention to?

Four practical points to act on:

  • Separate the two “markings”. Providers owe invisible, machine-readable markings on synthetic output (50(2)); deployers owe visible labels on deepfakes and public-interest text (50(4)). One does not cover the other.
  • Get the label right – and know what needs none. The EU icon, plus a short, plain-language line (“AI” is the only abbreviation to use), placed where the content is consumed, with alt text and an audio disclaimer when there is nothing to see. Standard editing, translation, formatting, source code, short labels and genuine internal B2B output fall outside the marking duty entirely – that is where much of the practical relief lies.
  • Watch the text limb closely. AI-touched investor and sustainability reports on a company website count as text published on matters of public interest, so they are squarely in scope unless the human-review and editorial-responsibility exception is properly documented – and that exception collapses if AI edits the text after sign-off.
  • Consider the Code of Practice. Adhering to the adequate Code of Practice is the most predictable way to demonstrate compliance with the 50(2) and 50(4) content obligations; non-signatories should run a gap analysis against it and keep evidence of equivalent measures.

Businesses introducing AI systems should assess Article 50 alongside their wider AI governance, data protection and intellectual property obligations. ECOVIS ProventusLaw can assist with this assessment and the implementation of appropriate compliance measures.

This article reflects ECOVIS ProventusLaw’s interpretation of the Commission’s non-binding Guidelines and Code of Practice and is provided for general information purposes only. It does not constitute legal advice; specific advice should be obtained before acting on any part of it.

Related news

Knowledge without experience is of little use. Therefore we are proud of having our own valuable experience to share with you.

Contact person

+370 5 212 40 84

[email protected]

Inga Karulaitytė

Lawyer, Attorney at law, Partner, Head of Banking and Finance & FinTech, CAMS

Contact person

+370 5 212 40 84

[email protected]

    Newsletter SubscriptionGet in touch