Since 2 August 2026, if your software talks to people, you have to tell them it is software. That is the short version of Article 50 of the EU AI Act — the transparency chapter — and on 20 July 2026 the European Commission adopted its final guidelines explaining what actually satisfies the duty.
A note on terms before we go further. The EU AI Act is the European Union’s regulation on artificial intelligence. A provider is the party that develops an AI system and puts it on the market under its own name; a deployer is the organisation using that system in its own operations. Most of what follows turns on which of those two you are, so it is worth holding both definitions in mind.
Why almost everyone read 2026 as a quiet year
The Digital Omnibus on AI — Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July — pushed the Act’s high-risk obligations back: stand-alone high-risk systems to 2 December 2027, high-risk systems embedded in regulated products to 2 August 2028. Those dates are settled law, not a proposal. That was widely reported, and reported accurately.
What travelled less well is that the deferral applied to the high-risk chapter and nothing else. Two things still landed on 2 August 2026: the Article 50 transparency obligations, and the Commission’s enforcement powers over general-purpose AI models. We wrote about the revised timeline in EU AI Act readiness: what actually changed in 2026, and the wider regulatory picture in the 2026 obligation stack. This article is about the piece that reaches ordinary business software.
The four triggers
Article 50 attaches to four situations. None of them is limited to high-risk systems, and a single product can hit more than one.
- AI systems intended to interact directly with people — chatbots, virtual assistants, conversational agents. The people using them must be informed they are interacting with an AI, at or before the first interaction.
- Synthetic content generation — systems that produce text, images, audio or video must mark their outputs in a machine-readable format and make them detectable as artificially generated or manipulated.
- Emotion recognition and biometric categorisation — the people exposed to the system must be informed of its operation.
- Deepfakes, and AI-generated text published to inform the public on matters of public interest — both must be disclosed as artificially generated.
The exceptions matter as much as the triggers, and they are frequently paraphrased into something broader than the text supports:
- The interaction disclosure is not required where it is “obvious from the point of view of a reasonably well-informed, observant and circumspect natural person” that they are dealing with an AI. There is also a law-enforcement carve-out.
- The marking duty does not bite where a system performs only an assistive function for standard editing — grammar correction is the canonical example — or does not substantially alter the input data or its semantics.
- For public-interest text there is no duty where there has been substantive human review and someone holds editorial responsibility.
- For deepfakes, disclosure is reduced for evidently artistic, creative, satirical or fictional work, and must be made in a manner that does not hamper the display or enjoyment of the work.
Who owes what
This is where most teams get stuck, and the guidelines are unusually clear about it.
| Duty | Carried by |
|---|---|
| Interaction disclosure — “you are talking to an AI” | Provider |
| Machine-readable marking of generated content | Provider |
| Deepfake disclosure | Deployer |
| Labelling AI-generated public-interest text | Deployer |
| Emotion recognition / biometric categorisation notice | Deployer |
The split is tidy on paper and awkward in practice, because it was written with a mental model of a vendor operating a service and a customer consuming it.
Self-hosting complicates that model rather than resolving it. When an organisation installs software on its own infrastructure, configures it, points it at a language model it selected, and publishes the resulting assistant to its own users, the question of who “puts the system into service under their own name” stops being obvious. Depending on how it is set up, the deploying organisation may take on provider-like responsibilities. That is not a gap in the Act so much as an interaction between the Act’s definitions and a deployment shape that is now very common.
We are not going to pretend the answer is settled, and you should be sceptical of any vendor who tells you it is for your case. The factors that actually bear on it are worth naming, because they are what your counsel will ask about: who determines the intended purpose, whose name the deployed system carries, who controls the interface the end user sees, and whether the deploying organisation has substantially modified the system.
Three disclosures that fail
The most useful part of the guidelines is what they rule out. On the interaction duty, the Commission is explicit that the information must be perceivable in the interaction itself.
Patterns the guidelines say do not satisfy Article 50(1)
- Buried in terms and conditions. A disclosure nobody encounters in the course of using the system is not a disclosure.
- A machine-readable watermark on its own. Marking generated content is a different obligation; it does not discharge the duty to tell a person they are talking to a machine.
- A vague reference to an ‘assistant.’ The word does not tell anyone the thing is artificial intelligence.
Two design consequences follow, and they are cheap to implement if you decide early: the notice belongs at or before the first exchange, not in a footer or a settings panel; and it has to survive the ways people actually reach the system — embedded widgets, deep links into a conversation, and screen readers included.
The Code of Practice does not cover the chatbot duty
This is the point most coverage has missed, and it is worth stating plainly.
The voluntary Code of Practice on transparency of AI-generated content is aimed at the marking and labelling duties — machine-readable marking of synthetic content, and the labelling of deepfakes and public-interest text. It does not address the Article 50(1) interaction disclosure at all. If your exposure is primarily the chatbot duty, the Code was never the instrument for it, no matter how much attention its signing window attracted.
Three further facts about the Code, since it generated more noise than it deserved. The window for inclusion in the initial-signatories list closed on 22 July 2026 at 18:00 CEST. Signing remains possible at any time afterwards. And the Commission states plainly that signing is voluntary and not signing does not constitute non-compliance — non-signatories simply document and explain the alternative measures they rely on, and may attract more requests for information from market-surveillance authorities.
Interpretation is not statute
In practice, keep the two apart in your own documentation. “Clear and distinguishable” is the statutory standard. “A line in the footer does not count” is the Commission’s illustration of that standard. When you write your assessment, cite the first as law and the second as guidance, and you will be in a much better position if the reading later shifts.
Four questions to answer internally this week
None of these needs a lawyer to start, and all of them will make the eventual legal conversation shorter.
- Which of our systems interact directly with people? The list is almost always longer than expected once you include embedded widgets, internal helpdesk bots and anything with a chat interface bolted on.
- For each one, are we the provider, the deployer, or arguably both? Write down the reasoning, not just the conclusion.
- Would a first-time user notice the disclosure? Not “is it present” — would they notice it. Ask someone who has never seen the product.
- Does anything we ship generate content that ends up published? If so, the marking duty is a separate workstream from the interaction duty, with a separate owner.
If it helps to work through the classification questions in a structured way, our free EU AI Act risk classifier walks the decision tree for a system you describe. It stores nothing and requires no sign-up. It is a starting point for a conversation with your counsel, not a substitute for one.
Not legal advice.
Frequently asked questions
What exactly applied on 2 August 2026?
Two separate tracks. First, the Article 50 transparency obligations for providers and deployers of certain AI systems — systems that interact directly with people, systems that generate synthetic content, emotion recognition and biometric categorisation, and deepfakes or AI-generated text published to inform the public. Second, the Commission's enforcement powers over general-purpose AI models activated. The high-risk obligations are a different matter and now fall on 2 December 2027 and 2 August 2028.
Does Article 50 apply to a chatbot on a company website?
Article 50(1) reaches AI systems intended to interact directly with natural persons, and the Commission's guidelines define that category in a way that includes chatbots. The duty is to design the system so that people are informed they are interacting with an AI, at or before the first interaction, in a way that is clear and distinguishable. There is a statutory exception where it is obvious to a reasonably well-informed, observant and circumspect person — but that is a narrow carve-out, not a general excuse. Whether it applies to any particular deployment is a question for your own counsel.
Who owes the disclosure — the software vendor or the company running it?
The guidelines split the duties. The provider carries the Article 50(1) interaction disclosure and the Article 50(2) machine-readable marking of generated content. The deployer carries the deepfake disclosure, the labelling of AI-generated public-interest text, and the emotion-recognition notice. Where that line falls in a self-hosted deployment — where the customer installs the software on their own infrastructure and points it at a model of their choosing — is genuinely contested, and worth putting to counsel rather than assuming.
Are open-source AI systems exempt?
No. The AI Act does carve out free and open-source AI in several places, but that carve-out does not extend to the Article 50 transparency obligations. Publishing your system under a permissive licence changes nothing about the disclosure duty.
Does content published before 2 August 2026 have to be marked retroactively?
No. Outputs generated before that date do not need retroactive marking, though the Commission has encouraged relevant deployers to do so where it is feasible. A separate transitional arrangement for generative systems already on the market is envisaged in the AI Omnibus and would apply only if adopted — treat it as conditional, not settled.
What are the penalties?
Infringements of the transparency obligations sit in the tier of the Act's penalty regime that reaches up to €15 million or 3% of worldwide annual turnover, whichever is higher. Member States set the enforcement machinery; the market-surveillance authority in each country is the first port of call.
Sources & further reading
- European Commission — Guidelines on transparency obligations for providers and deployers of AI systems (adopted 20 July 2026) — the final guidelines; non-binding but the practical rulebook
- EU AI Act — Article 50 (text) — the statutory language, including the exceptions
- European Commission — Signing the Code of Practice on transparency of AI-generated content (FAQ) — scope, the 22 July 2026 initial-signatory deadline, and that not signing is not non-compliance
- Bird & Bird — Commission adopts final Guidelines on AI Act Article 50: first impressions — practitioner reading of the adopted text