Skip to main content
Industry Insights

The EU AI Act's transparency rules apply now. Start with the public surface.

EU AI Act Article 50 transparency duties now apply. Provider marking, deployer labelling, deepfakes, public-interest text, and optional icons are separate decisions.

Sean McLellan profile photo

Sean McLellan

Lead Architect & Founder

8 min read
A barista checks three espresso streams flowing into a ceramic cup, a glass measuring carafe, and an open takeaway cup.
IllustrationBaristaLabs illustration of one production system sending three outputs into distinct review paths. The image is not EU guidance, a legal classification, or evidence of compliance.

On 2 August 2026, the transparency obligations in Article 50 of the EU AI Act became applicable. This does not mean the entire AI Act suddenly started today. The law has a phased timetable, and high-risk AI systems follow a separate schedule. The immediate task for product, marketing, communications, and operations teams is to find the public interfaces and publications where Article 50 may require information, machine-readable marking, or a visible disclosure.

This article explains which public surfaces to inventory and why the actor matters. Providers have duties tied to system design and output marking. Deployers have duties tied to how certain content is presented to people. The European Commission's voluntary Code of Practice and optional icons can support this work, but the legal obligations come from Article 50. This is operational information, not legal advice, and it does not decide whether a specific business or use is in scope.

Article 50 became applicable within a law that already had a timetable

The official regulation entered into force in 2024 and set several application dates. Some provisions applied before 2 August 2026. Article 50 applies now, while parts of the high-risk regime apply later. The Commission's current AI Act overview keeps the transparency and high-risk timetables separate.

For customer-facing generative AI work, three public surfaces deserve immediate attention after the provider-marking review: systems that interact directly with people; deepfake image, audio, or video; and AI-generated or manipulated text published to inform the public on matters of public interest. Provider marking is a separate, cross-cutting review because Article 50(2) also covers synthetic text and media outside the deployer's visible-disclosure classes. Article 50 also includes a separate notification duty for deployers of emotion-recognition and biometric-categorisation systems. That duty needs its own review and is outside the content inventory discussed here.

Provider marking and deployer labelling solve different problems

The regulation uses “provider” and “deployer” for different actors. In Article 50, provider duties address how an AI system is designed and how synthetic output can be detected. Deployer duties address how certain output is disclosed when the deployer uses or publishes it. One organization can have different roles across different products, so a company-wide label such as “AI user” is too vague.

For an AI system intended to interact directly with natural persons, Article 50(1) puts the duty on the provider. The provider must design and develop the system so the people concerned are informed that they are interacting with AI, unless that fact is obvious to a reasonably well-informed, observant, and circumspect person in the circumstances and context of use. Article 50(5) requires clear and distinguishable information, applicable accessibility measures, and delivery no later than the first interaction or exposure.

Article 50(2) gives providers of systems that generate synthetic audio, image, video, or text another duty. Their outputs must be marked in a machine-readable format and detectable as artificially generated or manipulated. The technical solution must be effective, interoperable, robust, and reliable as far as technically feasible, with content limits, implementation cost, and the generally acknowledged state of the art taken into account.

Machine-readable marking and human-visible labelling are separate. Metadata, a watermark, or another detection method can help a system identify synthetic output, but it may not tell a person what they need to know when they encounter the content. An icon can inform a person, but it cannot satisfy the provider's technical marking duty by itself. Article 50(4) puts the visible disclosure duty on deployers for specified deepfake media and public-interest text.

Three public surfaces require separate classification decisions

Direct AI interaction starts with the provider's system design

List every system intended to interact directly with a person, such as a customer chat or AI voice interface. Record where the person receives the information and whether it is present at first interaction, clear, distinguishable, and accessible. Do not assume that a product name or interface style makes AI involvement obvious. Application of the regulation's “obvious” test depends on the circumstances and context, so the review needs the live interface state.

Deepfake media needs disclosure at the point of exposure

The AI Act defines a deepfake as AI-generated or manipulated image, audio, or video that resembles existing persons, objects, places, other entities, or events and would falsely appear authentic or truthful to a person. A deployer of an AI system that generates or manipulates image, audio, or video content constituting a deepfake must disclose that the content was artificially generated or manipulated.

Inventory each publication surface, not only the source file. The same media can appear on a web page, in an advertisement, inside an embedded player, in a social post, or as a download. A production note that never reaches the audience cannot perform the public disclosure job. Record where the disclosure appears for each use and who checks that it remains with the content. For an advertising-specific example, our analysis of Google's AI-ad disclosure follows origin information through the placement and viewer handoff.

Public-interest text depends on purpose and editorial responsibility

The text duty is narrower than a general rule for all AI-assisted writing. Article 50(4) places the duty on the deployer of the AI system when the system generates or manipulates text that is published with the purpose of informing the public on matters of public interest. Preserve the actor, system, output, and publication purpose during classification. Reducing all of them to “AI copy” hides the decision the regulation requires.

Publication context and purpose matter. Record why the team classified a publication inside or outside this content class. Send uncertain cases to a qualified legal or compliance owner instead of letting the writer, content management system, or model make the decision implicitly.

The limits and exceptions require evidence, not a shortcut

Article 50 qualifies several duties. The provider marking obligation does not apply to the extent that a system performs an assistive function for standard editing or does not substantially alter the deployer's input data or its semantics. The regulation also contains specific exceptions for uses authorised by law to detect, prevent, investigate, or prosecute criminal offences. These provisions do not create a general exemption for any use described as minor.

For deepfake content in an evidently artistic, creative, satirical, fictional, or analogous work or programme, disclosure is still required. The obligation is limited to an appropriate disclosure that does not hamper display or enjoyment of the work. The creative treatment changes how the disclosure can appear. It does not remove the disclosure.

For public-interest text, the disclosure obligation does not apply when both parts of the exception are present. The AI-generated content must have undergone human review or editorial control, and a natural or legal person must hold editorial responsibility for its publication. The regulation does not express the required review as a word count, approval click, or job title. Application is fact-specific, so preserve evidence of the review, control, and responsible person before relying on the exception.

A qualified legal or compliance owner should review material classifications and exceptions. Article 50 compliance also does not establish that the content or AI use is lawful under every other EU or national rule.

The code and icons support compliance, while Article 50 creates the duty

The Commission's Code of Practice on Transparency of AI-generated Content has two sections. The provider section covers marking and detection of generated or manipulated content. The deployer section covers labelling deepfakes and generated or manipulated text. The split follows the distinct roles in the regulation.

Adherence to the code is voluntary. Article 50's transparency requirements are legal obligations. The Commission and the AI Board have confirmed the code as an adequate voluntary tool for demonstrating compliance, but it does not replace the Act or the Commission's guidance. Signing the code is not independent proof that every relevant system or publication complies.

The Commission's EU icons for labelling AI-generated content are optional and freely available. The Commission states that using an icon does not establish legal compliance by itself. The disclosure still needs to be perceivable and distinguishable no later than first exposure. Placement, accompanying language, accessibility, and persistence when content is shared or downloaded remain implementation decisions.

A three-column diagram separates direct AI interaction, synthetic media, and public-interest text into distinct Article 50 review paths.
Constructed diagramBaristaLabs-constructed reading aid based on Article 50 and the Commission's transparency pages. It is not legal advice or a complete scope determination.

Inventory the public surface before choosing the disclosure method

Create one entry for each live interface or publication path. Record these facts in plain language:

  • Interface or publication: Name the customer chat, voice experience, page, media placement, report, or other public surface.
  • Provider or deployer role: Identify the organization with the relevant Article 50 role for that system or use. Mark uncertainty instead of guessing.
  • Content class: Record direct AI interaction; synthetic audio, image, video, or text subject to provider-marking review; deepfake media; public-interest text; or another class that needs separate review.
  • Disclosure owner: Name the person or role responsible for the system information, machine-readable marking, or public label.
  • Marking or label location: State where the technical marking exists and where a person sees the disclosure at first interaction or exposure.
  • Exception relied on: Cite the exact limitation or exception, or write “none.” An empty field must not silently mean no exception.
  • Retained evidence: Link to the system configuration, output test, publication preview, approval history, editorial-responsibility record, or other evidence that supports the decision.

Confirm the actor and content class before choosing an icon or writing label text. Check the live interface or publication instead of relying only on a policy page. Then assign unresolved classifications to counsel or a qualified compliance owner and store the decision where the product or publishing team can use it.

This review can expose gaps that a compliance slogan or logo cannot show. A provider may have machine-readable marking while the deployer has no public label. A publisher may show an icon while nobody can identify the exception it relies on. A chatbot may mention AI only in terms that the person never sees during the first interaction. The live state, named owner, and retained evidence make each gap visible. Teams that also need to control who can publish generated brand material can pair this inventory with the approval-layer guidance for brand assets.

BaristaLabs helps teams connect AI policy decisions to real interfaces and publishing workflows through AI consulting. To classify your public surfaces, assign disclosure owners, and identify the remaining implementation work, contact BaristaLabs about an Article 50 review.

Sources

AI transparency implementation

Turn the rule into a review of live public surfaces

BaristaLabs helps product, marketing, communications, and operations teams inventory AI interfaces and publications, assign implementation owners, and prepare unresolved legal classifications for qualified review.

Operational implementation support, not legal advice or a determination that a specific use is in scope.

Turn this idea into a pilot

Which workflow should go first?

Use the readiness check to compare impact, effort, risk, owner, and next step before booking a call.

  • 3-5 minutes
  • Deterministic score
  • No sensitive data
Check workflow readiness

Practical AI Workflow Notes

Want more practical AI operations ideas?

Get short notes on applying AI inside real small-business workflows — from document handling and customer follow-up to internal reporting, compliance, and automation guardrails.

A useful next step if you’re still exploring and not ready to book a 20-minute AI assessment.

Occasional emails. Practical workflow guidance only. Unsubscribe anytime.