← Back to blog
Business & Legal

EU AI Act Article 50: The Rules, the Exemptions, and What Nobody Can Prove

By James A Snell·26 September 2026

The EU AI Act's transparency rules took effect on 2 August 2026 — reports that the Act had been delayed were about different obligations entirely. Several of Article 50's central tests turn on facts nobody has a way to prove.

What Article 50 Requires

Most coverage of the Act in 2025 focused on the high-risk regime in Chapter III. Article 50 sits in its own chapter, applies more broadly, and reached its compliance date first.

Article 50 of Regulation (EU) 2024/1689, the EU AI Act, sets four separate transparency duties, and they land on different people depending on the AI system involved. Providers of AI systems meant to interact directly with people, such as chatbots and virtual assistants, must design them so a person knows they are dealing with AI, unless that is obvious from context. Providers of systems that generate synthetic audio, image, video or text must mark the output in a machine-readable format and make it detectable as artificially generated, as far as this is technically feasible.

Deployers running emotion recognition or biometric categorisation systems must inform anyone exposed to the system. Deployers using AI to create a deepfake, or to generate text published on a matter of public interest, must disclose that the content was artificially generated or manipulated.

Two carve-outs inside that fourth duty matter more than they first appear. A deepfake that forms part of an evidently artistic, creative, satirical, fictional or analogous work only needs to disclose that manipulated content exists, in a manner that does not hamper the display or enjoyment of the work, not a full label. AI-generated text needs no disclosure at all where it has undergone a process of human review or editorial control and a named person or organisation holds editorial responsibility for the publication. Both carve-outs depend on facts that exist, if they exist, outside the text of the law itself.

Who This Reaches

The obligations in Article 50 do not only bind large AI developers. A deployer under the Act is whoever uses an AI system under its own authority, other than for a purely personal, non-professional activity, and a provider is whoever places that system on the market or puts it into service. That reaches a company running an AI customer-service chatbot for EU customers, a publisher whose journalists use an AI drafting tool on articles a human later reviews and publishes, a platform hosting user-generated AI images or video visible to people in the EU, and a UK marketing agency producing AI-generated content for an EU-based client.

None of those examples is a frontier AI lab. They are ordinary businesses using AI tools that already exist, for purposes that already existed before the Act, and the transparency duties attach to that use regardless of how small the operation is or how incidental the AI component feels. The Regulation makes no size exception in Article 50 itself; the exceptions that do exist for smaller organisations sit elsewhere, in the high-risk regime the Digital Omnibus deferred, not in the transparency duties that took effect on schedule.

The one line that does matter is professional use. The Act exempts an AI system used under a natural person's own authority for a purely personal, non-professional activity, which is why an individual generating an image for their own amusement sits outside Article 50 in a way a business publishing the same image to customers does not. Once content moves from private use to anything published, sold, or put in front of another person in a professional capacity, that exemption is gone.

The Deadline That Moved, and the One That Didn't

Coverage of the EU AI Act's delay in 2026 was accurate about one part of the Act and misleading about the rest. Regulation (EU) 2026/1744, the Digital Omnibus, was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, pushing back the high-risk AI obligations in Chapter III. Stand-alone high-risk systems under Annex III, covering recruitment tools, credit scoring and biometric identification among others, now have until 2 December 2027, a sixteen-month extension from the original 2 August 2026 date. High-risk AI embedded in regulated products under Annex I moved from 2 August 2027 to 2 August 2028.

Article 50 was not part of that deferral. The transparency duties described above applied from 2 August 2026, as originally scheduled, and continue regardless of what happened to the high-risk timeline. The one exception sits inside Article 50(2) itself: the machine-readable marking duty does not apply to generative AI systems already placed on the EU market before 2 August 2026, until 2 December 2026. That four-month window covers legacy systems only. Content generated by a system placed on the market after 2 August 2026 gets no grace period.

Why Being Outside the EU Doesn't Escape Article 50

The UK has no equivalent of Article 50. A House of Commons Library briefing published on 20 January 2026 acknowledged the case for AI content labelling and noted the technical challenges involved, but no UK legislation requires it, and none is currently before Parliament. Oversight instead runs through existing sector regulators, including the ICO, Ofcom and the FCA, applying their existing powers to AI-related conduct rather than a single horizontal labelling duty.

That gap does not place a UK-based business outside Article 50's reach. The Regulation applies wherever an AI system is placed on the EU market, wherever its output is used in the EU, or wherever it affects people located in the EU, regardless of where the provider or deployer is established. A UK studio licensing AI-generated content to an EU publisher, or a UK platform with EU users encountering AI-manipulated content, sits inside the Article 50 duties for that content even though no UK statute requires anything of the kind.

The Cost of Getting It Wrong

Article 99(4) of the AI Act sets the penalty for a breach of Article 50 at up to €15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. That figure is regularly confused with the Act's headline number: the €35 million or 7% tier under Article 99(3) applies only to the prohibited practices listed in Article 5, not to a transparency shortfall. Applying the higher figure to an Article 50 breach is, by a wide margin, the most common error in commentary on the Act.

Article 99(6) allows small and medium enterprises, including start-ups, the lower of the fixed amount or the turnover percentage, rather than the higher figure applied to large undertakings. That distinction rewards documentation as much as it rewards scale.

The mitigating factors in Article 99(7), including cooperation and whether compliance steps were already documented, apply on top of whichever cap is relevant. A smaller organisation with a clear dated record of its decisions is still better placed than a larger one with no record at all.

The Code of Practice Is a Shortcut, Not a Substitute

Article 50(7) has the Commission encourage codes of practice to help implement the marking and labelling duties, and assess whether following one adequately satisfies the obligations in paragraphs 2 and 4. The Commission and the AI Board assessed the resulting Code of Practice on Transparency of AI-Generated Content as adequate in July 2026. Signing up is voluntary, and it gives providers and deployers a documented, EU-recognised route to demonstrate compliance rather than working out an approach alone.

The Code also supplies three EU icons, developed by the AI Office, for marking partially or fully AI-generated content. Using them is optional, and the Commission is explicit that the icons do not themselves establish legal compliance; the underlying labelling requirement in Article 50 applies regardless of the marking method chosen. A business that adopts the Code still needs to show, for a specific piece of content, that the marking and disclosure steps it describes were followed at the time that content was published, not asserted afterwards.

None of that reaches the harder problem. A code of practice, like the Article itself, describes what a compliant process looks like in general. It does not, and cannot, generate a record that a specific piece of content went through that process on a specific date. That record either exists because someone built it into the workflow, or it does not exist at all by the time anyone asks.

The Exemptions Nobody Has a Way to Prove

Two of the widest gaps in Article 50 sit inside its own exemptions, not its obligations.

The marking duty in Article 50(2) does not apply to the extent an AI system performs an assistive function for standard editing, or does not substantially alter the input data provided by the deployer or the semantics of that data. That is a real distinction; a spelling correction is not the same as a generated paragraph.

But the Act draws the line at a judgment made in the moment, about a specific piece of input and a specific output, without asking anyone to record what that input was, what the tool changed, or when the call was made. If a regulator or a complainant asks eighteen months later whether a given edit crossed that line, the honest answer depends on evidence that most workflows never captured in the first place.

The deepfake carve-out in Article 50(4) turns on whether a work is evidently artistic, creative, satirical, fictional or analogous. Evidently is carrying the entire exemption. A piece that reads as obvious satire to its creator and as a convincing fake to someone who encounters it stripped of context is exactly the dispute the word invites, and the Act sets out no method for establishing, after the fact, what the work's context or intent was at the point it was made public.

A Claim of Review Is Not a Record of Review

The second text-specific exemption in Article 50(4) is narrower, and harder to satisfy in practice, than it reads. AI-generated text published on a matter of public interest needs no disclosure where the content has undergone a process of human review or editorial control, and a natural or legal person holds editorial responsibility for the publication. Both conditions have to be true, not merely claimed.

Nothing in the Act specifies how a publisher demonstrates, months after publication, that a specific piece went through that process rather than being generated and posted directly. A statement that editors review everything is a policy, not evidence about one article on one date. Where the exemption is later disputed, by a regulator, a competitor, or a reader who suspects otherwise, the burden sits with whoever relied on it, and a policy is not a record of what happened to that specific piece of text before it went live.

The three carve-outs covered here, standard editing, evident satire, and genuine editorial review, are not edge cases invoked once a year. They describe the ordinary route most content-heavy AI use takes: a tool assisting rather than replacing a person, work that leans on exaggeration or parody, a draft a human edits before anything goes out. Built on a real, dated record, an exemption removes a disclosure duty. Built on an unrecorded assumption, it removes nothing, and simply postpones the dispute to the first time anyone asks.

None of this is resolved by reading the Article more closely. Article 50 sets out what has to be true: a genuine edit rather than generation, a genuine satirical work, a genuine editorial review, without saying how any of those states get proven once they are challenged. That gap sits between the law and whoever has to answer for it, and closing it is a separate problem from complying with the text in the first place.

This post provides general information about the EU AI Act's transparency obligations and does not constitute legal advice. Anyone with a specific compliance question should consult a qualified lawyer in the relevant jurisdiction.

Related Reading

Article 50 of the EU AI Act, artificialintelligenceact.eu

European Commission Code of Practice on Transparency of AI-Generated Content, digital-strategy.ec.europa.eu

AI content labelling, House of Commons Library

How AI training data provenance disputes get decided, provlyn.com/blog/ai-training-data-provenance

Watermarking as a content-marking mechanism, provlyn.com/watermarking

James Snell is the founder of Provlyn, a platform providing cryptographic prior proof of IP ownership. provlyn.com

EU AI Act Article 50 Explained | Provlyn