Article 50 explained: when do you have to disclose that it's AI?
Article 50 of the EU AI Act does not require businesses to disclose every use of AI. The transparency obligation applies specifically to chatbots, AI-generated content, deepfakes and emotion recognition. A practical overview for SMEs — not legal advice.
Article 50 of the European AI Act does not require businesses to disclose every use of AI. The transparency obligation applies in specific situations: when people interact directly with an AI system, when certain AI-generated or manipulated content is published, and in applications such as deepfakes, emotion recognition and biometric categorisation.
For an SME, this means, for example, that a customer service chatbot will generally have to make clear that the customer is interacting with AI. By contrast, an employee who uses AI to improve an ordinary business email does not automatically have to add "written with AI" to the message. Nor does every blog article created with AI assistance need an AI label. Article 50 looks at the type of system, how its output is used and who is legally responsible for the application. The obligations have applied since 2 August 2026 — for the broader picture of what else already applies, see our overview The EU AI Act for SMEs.
Situation 1: someone interacts directly with an AI system
Article 50(1) concerns AI systems intended to interact directly with natural persons. The provider must ensure that people are informed that they are interacting with an AI system, unless this is already obvious to a reasonably well-informed, observant and circumspect person.
Examples include:
- a chatbot on a company website;
- an AI customer service agent;
- a virtual assistant;
- a voice bot handling telephone calls;
- an interactive AI avatar.
The European Commission clarifies that there must be genuine direct interaction. An AI system that merely analyses data in the background does not fall under this specific disclosure obligation. Machine-to-machine communication is also outside its scope.
The disclosure must be clear and recognisable no later than the beginning of the first interaction. A message such as "You are chatting with our AI assistant" is therefore much clearer than information buried somewhere in general terms and conditions.
There is an exception where it is obvious that the person is interacting with AI. The Commission has indicated, however, that this exception should be interpreted narrowly. For businesses that want to avoid uncertainty, a short and explicit disclosure will usually be the simplest solution.
An employee using AI is different
Not every communication in which AI is involved somewhere in the process becomes a direct AI interaction. Suppose an employee uses a language model to draft a response to a customer email, checks the output and then sends the message personally. The customer is interacting with the employee, not directly with the AI system. Article 50(1) does not automatically require the company to disclose that AI was used in drafting the message. This distinction matters for many SME workflows: AI used as an internal tool is legally different from an AI agent that operates independently in direct contact with a customer.
Situation 2: providers must technically mark generated content
Article 50(2) contains a different transparency obligation. Providers of systems that generate synthetic text, images, audio or video must ensure that the output is marked in a machine-readable format and can be detected as artificially generated or manipulated. This obligation also applies to providers of general-purpose AI systems.
That is different from a visible label aimed at the end user. A machine-readable marker can, for example, be embedded in metadata or another technical provenance mechanism. Its purpose is to allow systems to identify content as AI-generated or manipulated.
For an SME that simply uses an existing generative AI service, this technical obligation will generally fall on the provider of the AI system, rather than on every employee who generates an image or text. The Commission also identifies exceptions, including for certain standard editing functions, source code, very limited output and some machine-to-machine or industrial applications.
Situation 3: deepfakes must be disclosed
A visible AI disclosure becomes particularly important when a company uses AI to create a deepfake. The AI Act essentially defines a deepfake as AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and could falsely appear to be authentic or truthful.
A photorealistic video in which a real company director appears to say words they never actually said is a clear example. A completely fictional illustration, on the other hand, is not automatically a deepfake. The relevant question is not merely whether AI was used, but also whether the material imitates something that exists and could therefore wrongly be perceived as real.
Anyone using such a deepfake in a professional context must clearly disclose this no later than the first exposure. Relying solely on hidden metadata or a technical AI watermark is not enough: the disclosure must be perceptible to people. For obviously artistic, satirical, creative or fictional works, the AI Act allows a less intrusive form of disclosure so that the label does not unnecessarily interfere with the work itself.
Situation 4: AI-generated text about matters of public interest
Article 50 also contains a rule that can be directly relevant to websites, publishers and content teams. When a deployer uses AI to generate or manipulate text and publishes that text for the purpose of informing the public about matters of public interest, it must be disclosed that the text has been artificially generated or manipulated.
The Commission refers here to subjects such as politics, public administration, the judiciary, fundamental rights, public safety, public health, environmental protection and economic, financial, scientific or cultural developments that may form part of public debate. That does not mean every AI-assisted company blog automatically requires an AI label. There is an important exception.
Human editorial control can remove the labelling requirement
According to Article 50, AI-generated text about a matter of public interest does not have to be labelled as such where the text has undergone human review or editorial control and a person or organisation holds editorial responsibility for its publication.
That review must be substantive. Simply checking spelling, changing a few sentences or automatically passing the text through a grammar tool is not sufficient human review, according to the Commission. Genuine editorial control requires someone with appropriate knowledge to be able to assess, correct or reject the content and, where relevant, verify facts and sources.
This is an important practical distinction for SMEs: a company can use AI for research, structuring or drafting an article without necessarily having to label every published piece as AI-generated, provided there is genuine human substantive review and editorial responsibility where the publication falls within this category.
What should an AI disclosure look like?
Article 50 does not prescribe one mandatory sentence, icon or standard label. The information must, however, be clear and distinguishable and must be provided no later than the first interaction or exposure. The disclosure must also comply with applicable accessibility requirements.
For a chatbot, this means that a visitor should be able to understand immediately, when opening the conversation, that they are interacting with an AI system. Wording such as "You are chatting with our AI assistant" is clearer than displaying only a robot icon or mentioning AI somewhere in the privacy policy.
For deepfakes, the disclosure must likewise be perceptible to people. The European Commission gives examples such as a visible or audible label. Hidden metadata or a technical AI marker alone is not enough for this purpose — machine-readable marking serves a different purpose and falls under the obligations for providers in Article 50(2).
The practical rule of thumb is therefore: the person interacting with AI or being shown AI-generated content should be able to perceive the disclosure without having to inspect settings, metadata or technical information.
Who has to take action: the provider or the deployer?
Article 50 does not place every obligation on the same party. This distinction is particularly important when an SME uses AI software supplied by an external vendor.
The provider of the AI system is responsible under Article 50 for, among other things, obligations relating to systems that interact directly with people. Providers of generative AI must also ensure that synthetic text, audio, images and video can be technically marked in a machine-readable format and detected as artificially generated or manipulated.
The deployer is the organisation that uses an AI system under its authority. Article 50 places obligations on deployers in areas including emotion recognition, biometric categorisation, deepfakes and certain AI-generated texts concerning matters of public interest.
An SME that places an external AI chatbot on its website is therefore not automatically the provider of the underlying model. Conversely, using software supplied by an external vendor does not mean that all responsibility rests with that vendor.
For each AI application, it is therefore sensible to record at least:
- who is legally the provider of the AI system;
- who actually deploys the system;
- whether natural persons interact directly with the system;
- whether generated content is published externally;
- which Article 50 transparency obligation is therefore relevant.
This avoids the overly simple conclusion: "Our supplier complies with the AI Act, so we do not need to do anything." Article 50 deliberately distributes obligations across different roles in the AI value chain.
Emotion recognition and biometric categorisation also fall under Article 50
Article 50 is not limited to generative AI. A company using an emotion recognition system or a biometric categorisation system must inform the people exposed to that system about its operation. This applies both when the system is used in real time and when processing takes place afterwards.
This may be relevant, for example, to certain camera, analytics or employee-management systems. Separate or stricter requirements under other parts of the AI Act and the GDPR may also apply.
When does an SME not need to use an AI label?
Article 50 does not establish a general rule requiring every use of AI to be disclosed. For many everyday applications, there is therefore no specific obligation to tell customers that AI has been used.
Examples include AI used internally for:
- summarising documents;
- improving spelling and writing style;
- drafting emails that an employee reviews and sends;
- coding assistance;
- internal brainstorming;
- analysing business data without direct interaction with the people concerned.
A normal marketing text or product description also does not automatically require a visible "AI-generated" label merely because AI was involved in writing it. Other rules may still apply, however, including consumer protection law, copyright law, privacy legislation and rules against misleading practices.
A practical Article 50 check
For an SME, an initial assessment can usually be made by asking five questions:
- Is a customer or other person interacting directly with the AI system? If so, you should generally make clear that it is AI.
- Are you publishing AI-generated images, audio or video that could appear real when they are not? Check whether the content must be disclosed as a deepfake.
- Are you publishing AI-generated text to inform the public about a matter of public interest? Check the transparency obligation in Article 50(4).
- Has that text been substantively reviewed by a competent person and is it subject to genuine editorial responsibility? If so, the exception to the labelling obligation may apply.
- Do you provide a generative AI system yourself? If so, the technical obligations relating to machine-readable marking of output are also relevant.
Conclusion
"AI was used" does not automatically mean "an AI label is required" under the AI Act. Article 50 focuses on situations in which people need to be able to recognise that they are interacting with AI or that content has been artificially generated or manipulated.
For most SMEs, three situations are particularly relevant: customer-facing AI agents and chatbots, deepfakes, and AI-generated publications concerning matters of public interest. For the latter category, human editorial control is crucial: text that has been genuinely reviewed and published under editorial responsibility does not automatically have to carry an AI label.
The safest approach is therefore not to put "made with AI" on everything by default, but to document for each use case who is using the AI, who is interacting with it, what is being published and how much meaningful human review takes place before publication.
Neuralex does not provide legal advice. The application of the AI Act depends on the specific facts, roles and circumstances of each organisation, so you should have the requirements for your own situation reviewed by a qualified lawyer.