Knowledge · As of 2026-10-01
AI labelling duty: what Article 50 of the EU AI Act requires
The four cases of Article 50
Article 50 is not one obligation but a bundle of four, each with a different addressee. The most common mistake in practice is to treat them as one and then label either too much or the wrong thing.
| Case | Who is liable | What to do |
|---|---|---|
| Direct interaction with people (Art. 50(1)) - chatbots, voice assistants, AI telephony | Provider of the system | Design the system so the person learns they are talking to an AI - waived only where this is obvious from the context |
| Generation of synthetic content (Art. 50(2)) - audio, image, video, text | Provider of the generating system | Mark outputs as artificially generated in a machine-readable format (watermark, metadata), as far as technically feasible |
| Emotion recognition and biometric categorisation (Art. 50(3)) | Deployer, i.e. the company using it | Inform the people exposed to it; the GDPR applies in full on top |
| Deepfakes (Art. 50(4)) | Deployer, i.e. the company publishing it | Disclose that the image, audio or video was artificially generated or manipulated |
Provider or deployer - your role decides
For a typical mid-sized company this is the most important distinction in the whole article. Anyone running an off-the-shelf chatbot is its deployer, not its provider: the duty under paragraph 1 to make the system recognisable sits with the manufacturer. That does not leave you with nothing to do - you have to check that the notice actually exists in the product you bought and is visible, and demand it or add it yourself if it is not.
Deepfakes and emotion recognition work the other way round: there the duty expressly falls on the deployer. Whoever has an AI-generated video of a real person produced for a campaign has to disclose it themselves, no matter which tool was used.
Anyone who does not merely use an AI but offers it under their own name moves into the provider role. That applies, for instance, to a bot you make available to your customers as your own product.
What "labelling" actually means
The regulation prescribes no wording, but it does prescribe timing and quality: the information must be available at the latest at the first interaction or exposure, and must be clear and accessible (Art. 50(5)). One sentence in the chat window usually suffices - a notice that only appears in the imprint or the terms of use does not, because it misses the moment.
For synthetic content, paragraph 2 additionally requires a machine-readable marking, meaning watermarks or metadata, not only a visible note for humans. That duty sits with the provider of the generating system, not with you as the user of the tool.
The "obvious" exemption is routinely overestimated. The yardstick is a reasonably well-informed, observant and circumspect person in the given context. A window merely labelled "Chat" does not clear that bar - what is recognisable is what is explicitly named an assistant, a bot or an AI.
The special case of AI-written text
The question mid-sized companies ask most: do we have to label AI-written text on our website, blog and newsletters? For the large majority of cases the answer is no. The deployer duty under Article 50(4) only bites for text published in order to inform the public on matters of public interest - and even there it falls away if the text was reviewed by a human and a natural or legal person holds editorial responsibility.
A product description, a proposal or a professional article with a named author and a responsible party therefore regularly falls outside the disclosure duty. The machine-readable marking under paragraph 2 is untouched by this, but sits with the provider of the tool.
Fines and enforcement
Breaches of the transparency obligations in Article 50 fall under Article 99(4) of the regulation: up to €15 million or 3% of worldwide annual turnover, whichever is higher. For small and medium-sized enterprises including start-ups, Article 99(6) applies the lower of the two figures.
Enforcement runs through the national market surveillance authorities. In Germany the arrangements were not settled in every respect as of 10/2026; the Bundesnetzagentur is designated as the central body and already runs a service desk for questions on the AI Act.
Four steps you can take this week
First, list every AI system running in the company or visible to the outside - chatbots, phone assistants, image generators, recruiting tools. Second, assign each entry a role, provider or deployer. Third, wherever direct interaction with people happens, check that the notice is visible at first contact. Fourth, document the result, with a date.
That last point is the one most often missing and the least work. An authority does not ask whether you got everything right, it asks whether you demonstrably dealt with it.
Frequently asked questions
Which AI systems does the labelling duty cover?
Four groups: systems that interact directly with people (chatbots, voice assistants), systems that generate synthetic audio, image, video or text, emotion recognition and biometric categorisation, and deepfakes. Article 50 does not apply to other AI systems, such as internal analytics with no outside contact.
Since when does the AI labelling duty apply?
Since 02 Aug 2026. The regulation entered into force on 01 Aug 2024 and its obligations phase in; Article 50 belongs to the general applicability from August 2026. Deadlines may still shift through ongoing EU legislation.
Do we have to label our website chatbot?
Yes, unless it is obvious from the context that this is an AI. One sentence when the chat window opens usually suffices. The duty formally falls on the provider of the system, but as the deployer you should check that the notice actually appears.
Is a note in the imprint or the privacy policy enough?
No. Article 50(5) requires the information at the latest at the moment of first interaction, clearly recognisable. A notice you have to go looking for does not meet that requirement.
Do we have to label AI-written text?
Usually not. The disclosure duty for text only applies to publications informing the public on matters of public interest, and even there it falls away if the text was reviewed by a human and someone holds editorial responsibility.
Does the labelling duty apply if we only use ChatGPT?
Not for internal use - Article 50 starts at contact with third parties. As soon as you operate an AI system towards the outside or publish AI-generated content covered by paragraph 4, the duty applies. Independently of that, the AI literacy duty under Article 4 applies to every use of AI, and has done since 02 Feb 2025.
What does a breach of Article 50 cost?
Up to €15 million or 3% of worldwide annual turnover, whichever is higher. For SMEs and start-ups the lower of the two figures applies.
Read next
EU AI Act: obligations for SMEs →AI COMPLIANCE: risk classes and governance →Proving AI literacy under Article 4 →
Factual summary, as of 10/2026 - not legal advice. Deadlines and interpretation may change through ongoing EU legislation and national implementing rules.

