1. Introduction

Transparency Effective as of August 2, 2026

As of August 2, 2026, the transparency obligations under Article 50 of Regulation (EU) 2024/1689 (the AI Act) apply. These obligations apply to selected AI systems where it must be clear to the user or other affected person that they are interacting with artificial intelligence or that they are exposed to content or the operation of an AI system. Article 50 therefore covers, in particular, interactive AI systems, the generation of synthetic content, emotion recognition, biometric categorization, deepfakes, and certain texts published on matters of public interest.

Who May Be Subject to Obligations Under Article 50

Article 50 primarily divides obligations between providers and operators of AI systems. In both cases, the entity may be a natural person or legal entity, a public authority, an agency, or another entity. A single entity may assume different roles in different situations, and obligations under several paragraphs of Article 50 may apply simultaneously to the same system. Therefore, the first step in assessing transparency must always be to determine the specific role of the entity in question and the manner in which the AI system is developed, placed on the market, or used.

For providers, Article 50 primarily concerns systems intended for direct interaction with natural persons under paragraph 1 and systems that generate synthetic audio, image, video, or text content under paragraph 2. In practice, this may include, for example, customer chatbots, voice assistants, and AI agents communicating directly with customers, synthetic avatars, or systems that generate text, images, audio, or video. For interactive systems, the individuals concerned must generally be informed that they are communicating with AI, unless this is already apparent from the circumstances; for generative systems, the provider must ensure machine-readable labeling and the detectability of synthetic content.

Entities that create misleading content are subject, in particular, to the obligations set forth in paragraphs 3 and 4. Such entities must inform individuals exposed to emotion recognition systems or biometric categorization systems. Furthermore, under the conditions specified in paragraph 4, they must label deepfakes and AI-generated or manipulated text that is published for the purpose of informing the public about matters of public interest. The obligation does not apply to such text, among other cases, if the content has undergone appropriate human review or editorial oversight and a natural person or legal entity bears editorial responsibility for its publication.

These obligations may also apply to individuals, such as independent creators, influencers, consultants, or other persons engaged in independent professional activities, if they use an AI system under their own responsibility. Purely personal and non-professional use is, by definition, excluded from the scope of a misleading entity. Conversely, if the system is used under the responsibility of a legal entity, its employees or external contractors acting in accordance with its instructions and under its control are generally not considered separate misleading entities.

Commission Guidelines and Code

Of particular importance for the practical application of Article 50 are the European Commission’s final Guidelines on Transparency Obligations under Article 50, published on July 20, 2026, and the Code of Practice on Transparency for AI-Generated Content. The Guidelines explain the scope of the individual obligations and provide examples of their practical application; they represent the Commission’s interpretive guidance, not a binding source of law. The authoritative interpretation of EU law ultimately rests with the Court of Justice of the European Union.

The Code is voluntary and focuses on the obligations under Article 50(2), (4), and (5)—namely, the technical labeling of AI-generated or manipulated content and the labeling of deepfakes and certain text-based publications. The Commission and the European AI Board have assessed it as an adequate pan-European tool, whose measures can be used by signatories to demonstrate compliance. However, adherence to the Code alone does not constitute conclusive proof of compliance with legal obligations, and entities that do not use it may demonstrate compliance by other adequate means.

The Commission’s practical tools also include EU icons for labeling content created or modified using AI. Their use is voluntary and serves primarily to label content in accordance with Article 50(4) visually; they do not replace the machine-readable labeling required of providers under Article 50(2).

Transition Period Following the Amendment of the AI Act by the Digital Omnibus

Although Article 50 generally applies as of August 2, 2026, Regulation (EU) 2026/1744, known as the Digital Omnibus for Artificial Intelligence, established a limited transition period for certain providers. This applies to AI systems, including general AI systems, that generate synthetic audio, image, video, or text content and were placed on the market before August 2, 2026. Their providers must ensure compliance with the machine-readable labeling and traceability requirements under Article 50(2) no later than December 2, 2026.

This transitional rule applies exclusively to Article 50(2). Other obligations under Article 50 apply as of August 2, 2026. For a system that is both generative and designed for direct interaction with natural persons, the provider may thus make use of the transitional period for the technical labeling of generated content under paragraph 2, while the obligation to provide information to persons communicating with the system under paragraph 1 must be fulfilled as of August 2, 2026.

According to the Guidelines, it is not necessary to label, retroactively, synthetic content that was created or manipulated before August 2, 2026. The same principle applies to image, audio, or video content constituting a deepfake created before that date. However, for AI-generated or manipulated texts on matters of public interest, the decisive factor is the time of their publication: text created before August 2, 2026, but published on or after that date, is subject to the labeling requirement under Article 50(4), unless one of the statutory exceptions applies, in particular the exception based on human oversight or editorial supervision and editorial responsibility.

 

2. Article 50 at a Glance

Provisions

Applicability

Typical Situation

What Must Be Ensured

Article 50(1)

Provider

chatbot, voice assistant, AI agent

Notify the individual that they are communicating with an AI system

Article 50(2)

Provider

a system that generates or manipulates text, images, audio, or video

machine-readable labeling of outputs and their identifiability as artificially generated or manipulated

Article 50(3)

misleading entity

emotion recognition, biometric categorization

inform natural persons exposed to the system about its operation

Article 50(4)

misleading entity

deepfake

disclose that the content was artificially created or manipulated

Article 50(4)

misleading entity

certain published texts on matters of public interest

indicate artificial origin or manipulation, unless a statutory exception applies

Article 50(5)

provider / implementing entity

Common standard for paragraphs 1 through 4

Provide the information clearly and distinctly no later than the first interaction or exposure, and comply with accessibility requirements

 

Be aware of the two different levels of transparency!

Article 50(2) governs the technical, machine-readable labeling of outputs on the provider’s side. Article 50(4) requires the disclosure of information that is perceptible to humans in the case of deepfakes and certain texts. Therefore, the provider’s fulfillment of the technical obligation does not automatically cover the misleading entity’s obligation toward the public.

 

3. Determine Your Role

According to Article 3(3) of the AI Act, a provider is a natural person or legal entity, public authority, agency, or other entity that develops an AI system or a general AI model—or has it developed—and places it on the market or puts the AI system into service under its own name, trade name, or trademark. According to Article 3(4), a “deployer” is a person or other defined entity that uses an AI system within the scope of its authority, with the exception of personal, non-professional activities. Thus, the legal form or size of the addressee is not, in and of itself, decisive.

For natural persons, it is important to distinguish between professional use and purely personal, non-professional activities. The guidelines consider professional activities to include, among other things, activities from which a natural person regularly derives economic benefit, as well as entrepreneurial, commercial, professional, employment-related, or freelance activities. A self-employed individual, independent consultant, professional creator, or influencer may thus be a deploying entity just as a legal entity may be. The exception applies only to natural persons using an AI system in a purely personal and non-professional context and only to the obligations of the deploying entity; the obligations of the provider remain unaffected.

Czech terminology is also relevant for contracts, policies, and other documentation. The term “operator” has a broader definition in the AI Act and includes, among others, the provider, the product manufacturer, the deployer, the authorized representative, the importer, and the distributor. We therefore refer to the English term “deployer” as the “deploying entity” in this article.

The guidelines interpret the use of a system “within its scope of authority” in a functional manner. What matters is who decides on the purpose and manner of the system’s use and assumes responsibility for its use and outputs. Technical control over the model or software is not necessary. If the system is used by employees or external collaborators of a legal entity in accordance with its instructions and under its control, that legal entity generally remains the “implementing entity.” A self-employed individual may be the “implementing entity” themselves if they use the system in the course of their professional activities or if other persons use it within the scope of those activities under their authority.

A different situation may arise when the activity is outsourced to an external agency or another contractor. The guidelines provide the example of a company that commissions an advertisement and leaves it up to the agency to decide whether and how to use AI in its creation. The client does not become the implementing entity merely by placing the order and paying for the service. The same principle applies to a self-employed individual or an independent creator who commissions a finished product and does not decide whether or how the supplier will use AI. The decisive factor remains actual control over the use of the system.

The same entity may act as both the provider and the implementing entity for the same system. An example would be a legal entity or a sole proprietor who has developed—or commissioned the development of—a generative system marketed under their own name and simultaneously uses it to create their own marketing content. In such a case, they may address technical attribution as the provider while also handling the publication of deepfakes as the implementing entity.

Territorial Scope

Article 50 may also apply to providers and disseminators outside the EU, regardless of whether they are legal entities or natural persons. In addition to placing a system on the EU market or putting it into service, the AI Act applies under certain conditions even when the output of a system provided by a provider or disseminator from a third country is used within the EU. The guidelines for operators emphasize predictability and control over the distribution of output within the EU; incidental and unpredictable subsequent dissemination is treated differently. For global campaigns and publicly available content, it is therefore advisable to include, explicitly, territorial scope in the assessment.

Decision-Making Framework

Obligations are assessed concurrently. The practical procedure can be broken down according to your specific role in the given use case:

If you are a provider

If you are an implementing entity

1. Is the system intended for direct interaction with natural persons?
→ Assess Article 50(1).

2. Does the system generate or manipulate synthetic audio, image, video, or text content? → Assess Article 50(2).

3. If both conditions are met, the obligations apply simultaneously.

1. Is the system an emotion recognition or biometric categorization system? → Refer to Article 50(3).

2. Does the system generate or manipulate images, audio, or video constituting a “deepfake”? → Assess Article 50(4).

3. Does the system generate or manipulate text published for the purpose of informing the public about matters of public interest? → Assess Article 50(4) and its exceptions.

 

General rule:

Article 50(5) applies to all relevant disclosure requirements. The information must be provided in a clear and distinguishable manner no later than the time of the first interaction or exposure and in accordance with applicable accessibility requirements.

 

4. Chatbots, voice assistants, and AI agents – Article 50(1)

The provider of an AI system intended for direct interaction with natural persons must design and develop the system in such a way that the natural persons concerned are made aware that they are communicating with an AI system. An exception applies if the artificial nature of the interaction is apparent to a reasonably informed, observant, and circumspect natural person, taking into account the circumstances and context of use.

This group includes, in particular, customer chatbots, voice assistants, conversational agents, AI robots and avatars, or AI bots on social media, provided they actually communicate directly with a natural person. The guidelines also include AI agents capable of engaging in communication while performing tasks.

Direct interaction distinguishes Article 50(1) from internal support tools. If a customer support employee uses AI solely to draft a response and communicates with the customer personally, such a support tool may fall outside the scope of Article 50(1). The guidelines cite recommendation systems, spam filters, automatic translations and transcriptions, certain search tools, auto-complete features, and internal decision-support systems as additional examples that fall outside this scope. For hybrid solutions, it is necessary to assess whether a specific AI output is sent directly to the customer by the system, or whether a human—as the primary communication partner—reviews the content and sends it.

AI agents acting on behalf of another person or organization

The guidelines pay particular attention to agent systems that, for example, book services, manage correspondence, negotiate, conclude contracts, or make purchases. According to the Commission’s interpretation, an agent should be designed to disclose its artificial nature during direct interaction, as well as the identity of the person on whose behalf it is acting. For systems capable of operating in a variety of different environments, the notification mechanism should function at the agent’s architectural level and be activated whenever direct contact with a human is reasonably foreseeable.

Example of a disclosure:

“I am an AI assistant. I am communicating with you on behalf of [name of business or organization].” For a voice agent, this information can be conveyed verbally at the beginning of the call; for an email agent, it can be included directly in the body of the message.

 

When and How to Provide Information

The information should be part of the interaction itself and must reach the person concerned no later than at the time of first contact. A general mention of the use of AI in the terms of service, user guide, or on a separate web page usually does not fulfill this requirement. The notice may be provided as text, visually, audibly, or through a combination of methods, depending on the nature of the service.

According to the Guidelines, a single prominent notification prior to the first interaction will suffice in most cases. For long-term or sensitive interactions, repeated reminders may be appropriate. The Commission explicitly mentions, for example, financial and insurance advice, legal or medical assistance, complaint handling, AI companions, and situations involving children, seniors, people with disabilities, or people with lower digital literacy.

The Guidelines interpret the exception for the obvious nature of an interaction restrictively. General public awareness of the existence of chatbots or AI agents does not, in and of itself, mean that a specific individual will recognize the artificial nature of a particular interaction. The provider should be able to substantiate its conclusion regarding obviousness with regard to the target and reasonably foreseeable audience, the form of the interface, and the extent to which the system mimics human communication.

5. Machine-Readable Labeling of Generated Content – Article 50(2)

Article 50(2) applies to providers of AI systems, including general AI systems, that generate synthetic audio, image, video, or text content. The provider must ensure that the outputs are labeled in a machine-readable format and are identifiable as artificially generated or manipulated. Technical solutions should be effective, interoperable, robust, and reliable, to the extent technically feasible, taking into account the nature of different types of content, costs, and generally recognized state-of-the-art technology.

The obligation has two components: the output must bear a machine-readable label, and at the same time, there must be a mechanism that allows this label to be recognized and the result made available in a usable form. The guidelines anticipate, for example, publicly available standard detection solutions or—until such standards are established—the provider’s own or a shared detection solution provided by a third party.

The labeling need not occur exclusively at the model level. The guidelines explicitly permit implementation after content creation, at the system level, during the inference process, or at the model level. A provider may also use labeling implemented by the provider earlier in the value chain or by a specialized third party. The provider thereby retains responsibility for the compliance of its system.

Article 50 applies to AI systems. A standalone general AI model is not subject to Article 50(2) solely for this reason; however, model-based measures can significantly facilitate downstream providers’ compliance with their obligations, and the Code supports their use in many cases.

When the Technical Label Does Not Apply

The AI Act provides an exception to the extent that a system performs an assistive function for standard editing or does not substantially alter the input data provided by the deploying entity or its semantics. The assessment relates to the specific output and the manner in which the content is modified.

The guidelines list the following as examples of standard editing and non-substantial changes: spelling and grammar corrections, minor linguistic adjustments that do not alter the essence or message of the text, formatting, format conversions, technical compression, noise reduction, minor cropping, standard adjustments to color and contrast, transcription, and, under certain conditions, translations. Conversely, the guidelines cite summarizing a text, significant paraphrasing or rewriting, adding or removing a person or object from an image, replacing a face, synthesizing realistic speech with a specific voice, or creating a realistic event that did not occur as examples of more substantial changes.

Practical Distinction:

AI proofreading of a finished press release may still be considered standard editing. However, instructing the system to create a new press release from internal materials or to rewrite its content substantially generally falls under Article 50(2).

 

Narrowly Defined Industrial and B2B Situations

Beyond the scope of explicit statutory exceptions, the Guidelines derive from the principle of proportionality a limited group of industrial and B2B cases in which labeling and detection may not be required. This interpretation must be applied with caution, as it does not constitute a separate exception explicitly set forth in Article 50(2).

The Commission requires that three conditions be met cumulatively: the output is of a purely technical nature; it is intended solely for a limited, predefined group of natural persons acting in a professional capacity within the organization of the provider and the implementing entity; and it is not intended for sharing outside this closed organizational environment or for use by external parties, provided that appropriate technical measures are in place to prevent reasonably foreseeable misuse. The guidelines mention, for example, technical instructions, industrial manufacturing processes, predictive maintenance outputs, or internal documentation steps prior to the creation of the final external output. This interpretation by the Commission is primarily aimed at closed industrial and B2B environments; for a self-employed individual, its practical significance will generally be more limited.

Similarly, the guidelines address certain ephemeral content created in real time—such as in video games or virtual reality—provided that labeling is not technically feasible, the content is not recorded or further disseminated, and individuals exposed to the content are informed of its artificial origin by other appropriate means.

What the Code Adds

The Code specifies the technical standards of compliance for its signatories. Given the current state of the art for audio, image, and video content, as well as for text in a format that supports metadata, it generally provides for multi-layered labeling. The basic layers consist of digitally signed metadata and an imperceptible watermark. For plain text that does not carry metadata on its own, the Code employs a different approach. Fingerprinting and logging are supplementary, not generally mandatory, layers under the Code.

The Kodex acknowledges that the technical landscape will evolve. A signatory may demonstrate an equivalent or higher standard using a different technique, or even a single technique, provided it demonstrates at least comparable effectiveness, interoperability, robustness, and reliability. Compliance also includes testing, verification, ongoing monitoring, and documentation of the solution used.

What the provider should be able to demonstrate:

How and at what stage the machine-readable label is generated; how it is detected; how the label withstands common content transformations; how dependencies on the provider’s solution in the previous part of the value chain or on an external solution are addressed; how testing and updates are conducted; and what documentation is available to the supervisory authority.

 

6. Emotion Recognition and Biometric Categorization – Article 50(3)

Entities implementing an emotion recognition system or a biometric categorization system must inform natural persons exposed to the system about its operation. The Czech version of the AI Act specifically uses the terms “emotion recognition system” and “biometric categorization system.”

The guidelines confirm that the information obligation applies to both real-time operation and subsequent processing. The form of the notification depends on the environment and the group of individuals involved. The Commission cites, for example, a prominent warning before launching a video game that analyzes a player’s emotions or visible information at the entrance to an area where the system classifies visitors into age groups based on biometric data.

Before implementing an information mechanism, the permissibility of the use itself must be assessed separately. Article 5 of the AI Act prohibits certain practices, and some systems may fall under the category of high-risk systems. Transparency under Article 50(3) does not in itself legalize the use of the system. Nor does it replace the information and other obligations under the GDPR and other personal data protection regulations.

7. Deep fakes – Article 50(4)

The AI Act defines a “deepfake” as image, audio, or video content created or manipulated by artificial intelligence that resembles existing persons, objects, places, entities, or events and that could falsely appear authentic or true to the person viewing it. The operator of a system that creates or manipulates such content must disclose that the content was artificially created or manipulated.

The guidelines elaborate on the four elements of the definition: similarity; the existence or realistic existence of the imitated subject; the nature of the person, object, place, entity, or event; and the content’s ability to create a false impression of authenticity or truthfulness in a person. Realistic synthetic persons or situations may fall within the definition even if a specific model does not actually exist, provided that the subject could realistically exist and the content is capable of misleading others regarding its authenticity or truthfulness.

The intent of the misleading entity to deceive someone is not a requirement. The assessment is objective in nature and takes into account, among other things, the context of use and a reasonably foreseeable audience. For content intended for children, seniors, or individuals with lower digital literacy, their greater susceptibility to misperceiving authenticity may also be relevant.

Marketing, Content Creation, and Public Communication

The guidelines provide examples with direct relevance for entrepreneurs, creators, and organizations: a realistic synthetic video of a CEO, an AI-generated influencer in an advertising or promotional context, a cloned voice of a host, or an AI-generated image of a product that may influence the perception of its actual appearance, characteristics, or use. The same test applies when an individual entrepreneur or creator uses AI to generate a realistic representation of themselves, another real person, a product, or an event. In such cases, the publishing or marketing process should include a review to determine whether the output meets the definition of a deepfake and how it should be labeled.

Minor technical or cosmetic adjustments may fall outside the definition if they do not significantly alter the perception of the content’s authenticity or veracity. The guidelines mention, for example, lighting adjustments, noise reduction, color correction, certain background adjustments, compression, or cosmetic enhancements. The decisive factor is the impact of a specific change in the given context.

Artistic, Creative, Satirical, and Fictional Works

If a deepfake is part of a clearly artistic, creative, satirical, fictional, or similar work or program, Article 50(4) provides for a less stringent disclosure requirement. The existence of artificially created or manipulated content is still disclosed, but in an appropriate manner that does not prevent the display or use of the work. The Code permits, for example, the use of captions, accompanying information, a description of the work, or an adjacent user interface element, depending on the nature of the medium.

Important Convergence:

The designation “deepfake” does not address its legality under other regulations. Depending on the circumstances, it is necessary to assess separately the protection of personal data, rights to one’s likeness and voice, copyright and trademarks, advertising regulations, consumer protection, and any criminal law limitations.

 

8. Texts Published for the Purpose of Informing the Public on Matters of Public Interest

The second part of Article 50(4) applies to a misleading AI system operator that generates or manipulates text published for the purpose of informing the public about matters of public interest. The misleading operator must state that the text was generated or manipulated by an AI system, unless one of the statutory exceptions applies.

The guidelines break down the assessment into three questions: whether the text was published; whether the purpose of the publication is to inform the public; and whether the text concerns a matter of public interest.

What Does “Published” Mean?

The Commission considers a text to be published if it is available to an indeterminate and sufficiently large number of unrelated potential readers, even if access is paid or requires a subscription. Private professional correspondence or an organization’s internal communications—such as content on an internal intranet—generally do not meet this criterion under the Guidelines.

For professional services, a useful example is a consultant who uses AI to tailor regulatory advice sent to a specific client. The Guidelines do not consider such text to be a publication intended to inform the public. Conversely, a publicly accessible website of a businessperson, author, association, or company—or content behind a paywall—may constitute publication if it is intended for an unspecified, broader audience.

How Broad Is the Public Interest?

The guidelines interpret the concept of public interest broadly. They include politics and democratic processes, public administration and services, the administration of justice and law enforcement, fundamental rights, public safety and health, environmental protection, consumer safety, and economic, financial, scientific, or cultural issues that may be the subject of public debate.

In professional and corporate communications, this definition may apply, for example, to investor information, professional blogs, public commentary, or certain educational texts. The guidelines cite AI-generated corporate reports published on the website of a publicly traded company as one possible example of a text on a matter of public interest. For an independent author, consultant, or creator, the same question may arise, for example, regarding a publicly published text on public health, politics, security, the environment, or another matter of public interest. Ordinary advertising copy or product descriptions are generally outside the scope of this policy; however, a different outcome may apply to communications regarding health, consumer safety, sustainability, or other topics of broader public significance.

Exception: Human Review or Editorial Oversight and Editorial Responsibility

The labeling requirement does not apply if the AI-generated content has undergone a human review or editorial oversight process and a natural person or legal entity bears editorial responsibility for its publication. Both conditions must be met simultaneously.

According to the Guidelines, human review should consist of a substantive assessment of the content by a person with relevant knowledge and professional judgment. Verification of factual accuracy should be a minimum component of the review. Spelling or grammar checks, purely formal approvals, automated reviews, or superficial checks without substantive human involvement do not meet the required standard.

The order of steps is essential. If a person substantively approves a text and generative AI subsequently substantially supplements, rewrites, or reformulates it, the Guidelines consider the exemption for the modified version to be void. The publishing entity must ensure a new substantive review or label the text accordingly.

Editorial responsibility, as defined by the Guidelines, means the ultimate legal responsibility of a natural person or legal entity for publication, including the functioning of the review or editorial control process. The Commission recommends that the identity and contact information of the responsible person, legal entity, or responsible function be publicly available and easily accessible. The Code further requires signatories to have an internal policy that designates a responsible person or function and describes the organizational measures and resources for ensuring review; it does not, however, require a record of every single review of every publication.

Recommended publication process:

AI can prepare a draft → an expert conducts a substantive review, including fact-checking → the responsible person or position approves the text for publication → once approved, no substantial AI-generated changes may be made without a new review. With this process in place, the application of the exception under Article 50(4) may be considered.

 

9. How Information Should Be Provided – Article 50(5) and (6)

Article 50(5) establishes a common standard for the information referred to in paragraphs 1 through 4. The information must be provided to the natural persons concerned in a clear and distinguishable manner no later than at the time of the first interaction or exposure and must comply with applicable accessibility requirements.

In the case of deepfakes and relevant texts, the information must be perceivable without the need for a technical tool or a specific action by the user. A machine-readable label under Article 50(2) therefore cannot, on its own, fulfill the obligation of the entity creating the misleading content under paragraph 4. Similarly, information hidden solely in terms of service, a manual, or several levels deep within the user interface will generally not be considered adequate.

For visual content, the Code requires that the label be recognizable upon first exposure, not obscured by other elements, and remain visible for a sufficient period of time. For videos and long-form or live content, it anticipates repetition depending on the context, particularly after interruptions. For purely audio deepfakes, an audio warning is provided at the beginning, and for longer content, additional reminders may be provided as circumstances warrant.

Article 50(6) ensures consistency with other requirements of the AI Act and with transparency obligations under EU and national law. In a specific project, therefore, it may be necessary to address, in addition to Article 50, issues such as the GDPR, consumer protection, advertising, the Digital Services Act, intellectual property rules, personality rights, or information obligations for high-risk systems.

EU Icons for Labeling AI-Generated Content

The European Commission has published the following standardized set of icons that entities may use to label deepfakes and texts falling under Article 50(4). Only the obligation to label AI-generated content is legally binding; however, the use of these icons is voluntary (the obligation may also be fulfilled through other appropriate forms of labeling). The mere placement of an icon does not in itself indicate that the labeling requirement has been properly met, as requirements regarding timing, visibility, comprehensibility, and accessibility must also be met. Nevertheless, it is useful in terms of standardization.

 

 

When AI played a role in the creation of the relevant content, the icon is accompanied by a custom text label or other interactive information.

When the entire relevant deepfake or text is created entirely by AI without any human-generated content or editorial oversight, except for the input of instructions.

When previous human-created content has been partially altered using AI such that the resulting content constitutes a deepfake or relevant text.

The Commission notes that variants supplemented with the explicit text “GENERATED” or “MODIFIED” achieved better comprehensibility in user testing than the basic icon alone. All icons are freely usable without any obligation to credit the Commission or the AI Office as the author. Their use by an entity that has not signed the Code does not constitute adherence to the Code.

When placing the icon, consider the specific medium. The Commission recommends sufficient size and contrast, simple accompanying text, accessibility for assistive technologies (such as alternative text or an ARIA label), and sufficient display time. For digital content, the label should, if possible, remain intact even when downloaded or shared further. For purely audio content, the Code specifies an audio announcement; a common audio version of the icon is currently under development.

10. What is the significance of the Code?

The Code focuses on the obligations set forth in Article 50, paragraphs 2, 4, and 5. The first part addresses technical labeling and detection by providers of generative AI systems. The second part applies to entities that create misleading content and sets out practical rules for labeling deepfakes and relevant texts, including the placement of labels, internal processes, training, correction of erroneous labels, and procedures for human review and editorial responsibility.

Adherence to the Code is voluntary. In July 2026, the Commission and the European AI Board confirmed its adequacy for demonstrating compliance with Article 50(2), (4), and (5). For signatories, supervision will focus primarily on whether they are actually complying with the Code and have implemented its measures. At the same time, the Code explicitly states that adherence alone does not constitute conclusive evidence of compliance in every individual case.

An entity that does not sign the Code may fulfill its obligations in another adequate manner. However, the guidelines expect such an entity to be able to describe and document the measures chosen and their adequacy; they explicitly mention an analysis of the differences from the adequate Code as an appropriate approach. Non-signatories may face more detailed requests for information or access to technical and organizational measures during an audit.

The Need for a Choice:

For a provider or implementing entity that repeatedly provides a generative system or regularly creates deepfakes or public texts falling under Article 50(4), the Code can offer a uniform and predictable basis for implementation. This applies to both individuals and organizations. If a party chooses its own solution, it should consciously document any deviations from the Code and the reasons why its alternative meets the requirements of the AI Act.

 

11. How to Put the Requirements of Article 50 into Practice

Ensuring compliance with the requirements of Article 50 should be based on specific use cases. A mere list of purchased licenses for AI tools typically does not provide a sufficient picture. For each system, it is advisable to document its function, origin, the person or department deciding on its use, the type of outputs generated, the audience for those outputs, and the method of further distribution.

The next step is to determine one’s own role and identify the relevant paragraph of Article 50. For in-house solutions—whether developed independently or marketed under one’s own name or brand—it is necessary to verify the provider’s status. When using third-party tools professionally, the user will often act as the “introducing entity,” which is particularly relevant for deepfakes, public texts, and systems covered by Article 50(3).

The scope of practical measures may vary significantly depending on the size and nature of the business. For a self-employed individual, a brief checklist, proper configuration of the tools used, retention of documentation from the supplier, and records of decisions regarding the labeling of specific content may suffice. For larger organizations, it will typically be appropriate to divide responsibilities among the product, IT, marketing, legal, or compliance functions, and other relevant departments. However, the legal test under Article 50 is the same in both cases.

Publishing and Marketing Processes

When creating and publishing content, it is advisable to establish simple rules for synthetic images, audio, and video. Before publication, it is necessary to determine who will assess whether the content meets the definition of a deepfake, select the labeling method, and verify that the label is maintained throughout the distribution channel. For a sole proprietor or creator, this review can be conducted by the individual themselves; for an organization, it may be assigned to a specific person or department. For public texts, it is advisable to determine separately whether the matter is of public interest and whether the misleading entity will use labeling or an approval process based on human review and editorial responsibility.

Contracts with Providers and Agencies

Contractual documentation should reflect the actual division of roles. For providers of generative systems, the following may be particularly relevant: the method of machine-readable labeling, the availability of a detection mechanism, the preservation of metadata and watermarks during export, technical documentation, testing, and a commitment to respond to changes in technical standards. For marketing and content agencies, it is advisable to specify who decides on the use of AI, how outputs are transferred, whether embedded labels are preserved, and who performs the final labeling before publication.

Recommended compliance documentation for each major use case

Identification of the system and the supplier; one’s own role as a provider or implementing entity; the relevant paragraph of Article 50; the exemption applied and its justification; the technical or user-facing solution; the supplier’s documentation; the responsible person or function, if applicable; a sample notification or screenshot of the relevant interface; and a record of the procedure’s approval. The scope of the documentation can be tailored to the risk, size, and nature of the business—for a self-employed individual, it may be significantly simpler than for a large organization.

 

Typical Situations in Business and Professional Practice

Situation

What to Assess

Practical Step

A business owner’s or organization’s customer chatbot

Section 50(1); or Section 50(2), if it generates synthetic content

Ensure a disclosure is provided during the first interaction; verify the technical labeling of generated outputs if you are also the provider

Voice agent scheduling appointments

Article 50(1)

Disclose that it is AI and, in accordance with the Guidelines, also identify the person on whose behalf the agent is acting

Internal AI co-pilot for customer support

Determine whether there is direct interaction between the AI and the customer

Set up human review and clearly define who the primary communication partner is

Proprietary marketing image generator

Article 50(2)

Ensure machine-readable labeling, detection, testing, and documentation

AI proofreading of the final text

Exception for standard editing under Article 50(2)

Document that the change does not alter the substance, meaning, style, or message beyond the scope of standard editing

Synthetic video of a businessperson, creator, or CEO

“deepfake” pursuant to Article 50(4)

Choose a clear label upon first display; a machine-readable provider label alone is not sufficient

Realistic AI image of a product

Deep fakes and advertising/consumer protection rules

Assess the impact on the perception of the product’s actual appearance, characteristics, and use

Private professional advice to the client or internal memorandum

Disclosure pursuant to Article 50(4) is generally lacking

For paragraph 4, the designation of a public text generally does not apply; assess other relevant regulations separately

Annual or ESG report prepared using AI

text on matters of public interest and the exception for human review

Implement a substantive review, assign editorial responsibility, and prevent significant AI-driven edits after approval

Analysis of employee emotions

Article 50(3) + prohibition / other regimes under the AI Act + GDPR

First, verify the permissibility of the use itself; only then establish the disclosure obligation

Independent creator or influencer publishing realistic AI content

Professional use vs. personal, non-professional activity; potentially a “deepfake” under Article 50(4)

In the case of professional or monetized activity, do not rely on the exception for purely personal use; assess the obligation to label the content clearly

An independent consultant or author publishing AI-generated text on a matter of public interest

Article 50(4); human review and editorial responsibility

either label the text or conduct a substantive review and assume editorial responsibility; a natural person may be the editor-in-chief

 

Implementation Checklist

  1. Map out the systems and specific use cases of AI, including tools used in content creation, marketing, customer communications, HR, or by external vendors.
  2. For each use case, determine your own role as a provider, an implementing entity, or both.
  3. Identify the relevant paragraph of Article 50 and verify any statutory or interpretive exceptions.
  4. Review the user interface of interactive systems and the timing of notifications during the first interaction.
  5. For generative systems acting as providers, review labeling, detection, robustness, interoperability, testing, and documentation.
  6. Establish a process for deepfakes and publicly published AI-generated texts, including rules for the use of EU icons or equivalent labeling.
  7. Establish human review, editorial oversight, and editorial responsibility in cases where a misleading entity seeks to invoke the exception for texts under Article 50(4).
  8. Amend contractual terms with AI providers, integrators, and content or marketing agencies.
  9. Document key decisions and retain evidence of implementation, particularly vendor documentation, notification templates, and screenshots of relevant interfaces.
  10. Ensure that individuals involved in creating, editing, or publishing relevant content or configuring systems are familiar with the applicable rules. For self-employed individuals, this can be achieved through a brief self-assessment procedure; if employees or external collaborators are involved, it is advisable to provide them with appropriate training.

12. Penalties

A breach of the obligations under Article 50 falls under Article 99(4) of the AI Act. An administrative fine may amount to up to EUR 15 million or, if the breach is committed by a company, 3% of its total worldwide annual turnover for the preceding fiscal year, whichever is higher. The penalty regime is therefore not limited to commercial companies; the specific upper limit also depends on the status of the addressee in the given case. For small and medium-sized enterprises, including startups, the lower of the two limits applies. The Digital Omnibus on AI has also extended the same rule for fines under Article 99(4) and (5) to small enterprises with medium market capitalization.

When determining a fine, the circumstances of the specific case are assessed, including, among other things, the nature, gravity, and duration of the violation, its consequences, the degree of liability, cooperation with the supervisory authority, prior violations, and whether the conduct was intentional or negligent. A well-documented process can therefore be important not only for ongoing compliance management but also for any interactions with the supervisory authority.

13. Conclusion

Article 50 may apply to a wide range of entities—from individuals who run a business or create content professionally to large companies or public institutions. For self-employed individuals, the requirements will primarily manifest in the selection and configuration of tools, the method of communicating with the public, content labeling, and the individual’s own publishing process. For organizations, this is compounded by the allocation of internal responsibilities, product and technical processes, contracts with suppliers, and training for relevant personnel. The most practical approach in both cases is based on specific use cases and assigns to each a specific role, obligation, and evidence of compliance.

For generative content, it is particularly important to distinguish between technical labeling under Article 50(2) and human-perceivable information under Article 50(4). For public texts, a properly configured fact-checking process and editorial responsibility can significantly influence the labeling obligation; editorial responsibility may even be borne by a natural person. For interactive systems, a significant part of ensuring compliance takes place directly within the interface and at the moment of the first interaction. Individuals can incorporate these rules into their own work and publication procedures, while organizations can integrate them into their existing product, marketing, and approval processes, so that Article 50 is not addressed only at the time of publication or system launch.

In practice, the answers to many questions under Article 50 will depend on the specific circumstances of each case. Decisive factors may include not only the role of the entity and the AI system used, but also the manner of its deployment, the nature of the specific output, the audience, or the configuration of related technical and organizational processes. Individual use cases must therefore be assessed on a case-by-case basis, and transparency rules must be directly incorporated into the processes in which AI is actually used.

At Peterka & Partners, our AI Task Force is continuously addressing these issues and is available for consultation on specific cases.