From the journal

Part V AI Act transparency for content and interactions

The EU AI Act requires notices about certain AI interactions and disclosures identifying certain artificially generated or manipulated content.

Illia ProkopievCo-Founder and CEO17 min read

This fifth part continues Part IV on AI Act risk assessment and governance documents. That part addressed the records supporting compliance decisions. The question now concerns what people must be told, which operator must provide the information, and when it must appear. The analysis concerns professional uses and communications within Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744. The earlier parts explain how to determine the operator's role and the Act's applicability.

Summary

  • Providers must design covered interactive systems to inform people that they are interacting with AI. The exception depends on what a reasonably well-informed, observant and circumspect person would find obvious in the circumstances. A human name or conversational voice does not itself establish the exception. (AI Act, Article 50(1), (5).)
  • Providers of covered generative systems must mark synthetic outputs in a machine-readable format and make them detectable as artificially generated or manipulated. That technical duty differs from the deployer's duty to disclose deepfakes and certain public-interest text. One system or publication can engage several obligations. (Article 50(1)–(5).)
  • Professional deepfake disclosure is not confined to public-interest publications. Evidently artistic or fictional works receive an adjusted disclosure rule, which still requires disclosure. The human-review exception concerns the separate text-publication duty. (Articles 3(60), 50(4)–(5).)
  • The text exception requires human review or editorial control, together with a natural or legal person holding editorial responsibility. An organisation's name on a publication cannot replace the required review or control. (Article 50(4), second subparagraph.)
  • Required information must be clear, distinguishable and accessible under the applicable requirements, by first interaction or exposure. A notice available only after opening unrelated terms cannot satisfy that timing when the person has already encountered the relevant interaction or content. (Article 50(5).)
  • Article 50 generally applies from 2 August 2026. A specific transition gives providers of qualifying systems placed on the market before that date until 2 December 2026 to meet Article 50(2). It does not postpone the other Article 50 duties. (Articles 111(4), 113; Regulation (EU) 2026/1744, Article 1(39)(b).)

Separate duties for the interaction and the content

Article 50 assigns duties by function and actor. Providers address direct interaction under paragraph 1 and synthetic-output marking under paragraph 2. Deployers address emotion recognition and biometric categorisation under paragraph 3. Paragraph 4 concerns their use of systems producing deepfakes or specified published text. Paragraph 5 governs how the required information reaches people. An assessment should match each function to its paragraph before selecting a notice.

A hypothetical company supplies a conversational video service and uses it to publish a synthetic statement attributed to its chief executive. The interactive service can require an AI interaction notice and technical output marking. The company's professional publication can separately require deepfake disclosure if it meets Article 3(60). Compliance with one paragraph leaves the other applicable paragraphs to be satisfied. (Article 50(1)–(5).)

Article 50(2) expressly includes general-purpose AI systems. The model documentation and training-content summary considered in Part IV address different obligations under Chapter V. Supplying that documentation does not establish that a particular output carries the marking or disclosure required by Article 50. (Articles 3(66), 50(2), 53(1).)

Article 50 generally applies from 2 August 2026 under Article 113. Article 111(4) provides a specific transition for the marking duty. It concerns generative systems placed on the market before 2 August 2026 and requires compliance with Article 50(2) by 2 December 2026. The statutory wording does not add systems merely put into service before that date. (Articles 111(4), 113; Regulation (EU) 2026/1744, Article 1(39)–(40).)

Notices for direct interaction with AI

The provider must design and develop a covered interactive system so that the person concerned is informed of the AI interaction. Article 50(1) concerns systems intended to interact directly with natural persons.

Assume a hypothetical retailer offers an AI chat assistant under an ordinary personal name. The chat window should identify its AI character by the first interaction, unless the statutory obviousness exception applies. A proposed notice is: "This chat is operated by an AI assistant." That wording illustrates an implementation choice; Article 50 does not prescribe this sentence. The provider must still assess its presentation and the actual audience. (Article 50(1), (5).)

The exception uses the viewpoint of a reasonably well-informed, observant and circumspect natural person. The assessment must account for the circumstances and context of use. Familiarity among the provider's engineers does not, by itself, establish what a person meeting that standard would understand. The relevant evidence concerns what the person encounters: the system's description, presentation and interaction. (Article 50(1).)

For a hypothetical telephone service, a proposed opening is: "This is an AI voice assistant." A visual notice on a separate website would leave a caller uninformed if the caller never encounters it. The implementation must meet the first-interaction requirement in the channel actually used. (Article 50(1), (5).)

The provider should test the entry routes that people can use. A compliant notice on the main landing page may be absent when someone enters through an embedded chat window. An interface change can also remove the information on which an obviousness assessment depended. Testing those routes is a recommended method of checking the statutory result, rather than a prescribed universal testing procedure. (Article 50(1), (5).)

Machine-readable marking and detection

Article 50(2) requires providers of covered generative systems to mark synthetic audio, images, video and text in a machine-readable format. The outputs must also be detectable as artificially generated or manipulated. The duty is not limited to outputs constituting deepfakes or publications concerning public interests. Those conditions belong to the separate deployer rules in paragraph 4.

A visible caption can inform a viewer while leaving the provider's technical marking duty unanswered. Conversely, embedded machine-readable information does not necessarily inform the person viewing a deepfake. The operator must establish the technical result required by paragraph 2 and, where applicable, the disclosure required by paragraph 4. Neither provision makes the other form of information universally sufficient. (Article 50(2), (4)–(5).)

The technical solutions must be effective, interoperable, robust and reliable as far as technically feasible. Article 50(2) requires consideration of the content type's specificities and limitations, implementation costs and the generally acknowledged state of the art. These qualifications require an assessment of the selected solution. They do not create a general exemption whenever implementation has a cost or detection is imperfect.

The final Code of Practice on Transparency of AI-Generated Content provides one voluntary implementation route. Its provider section combines marking techniques with detection mechanisms and testing. The Commission assessed the Code as adequate in Opinion C(2026) 4839 final, paragraph 52. The Code's technical measures must be described as commitments under that route, rather than words enacted in Article 50(2). (Code, Section 1, Commitments 1–4.)

For content formats supporting metadata, the Code specifies digitally signed metadata and imperceptible watermarking under its stated conditions. It provides qualified alternatives where a single layer is sufficient or another technique achieves the required performance. A provider relying on that route must apply the relevant conditions to its content format. Article 50(2) itself does not name a mandatory technology vendor or file-format standard. (Code, Section 1, Measure 1.1 and Sub-measures 1.1.1–1.1.2.)

Detection needs an operational means of checking the marking. Under the Code, signatories provide a detection solution through a specification, software or an accessible service. The Code contains audience and access conditions, including qualifications for free-form text. A generic detector's unsupported prediction does not establish that the provider implemented the required marking and detection solution. (Article 50(2); Code, Section 1, Measure 2.1 and Sub-measures 2.1.1–2.1.2.)

The Code also requires signatories to present detection results clearly to people checking the content's origin. Applicable accessibility requirements must be satisfied. Where technically feasible, the results identify whether detection used metadata, watermarks, forensic methods or other techniques. These commitments implement the information duty within the provider's detection route. (Article 50(5); Code, Section 1, Commitment 2 and Measure 2.3.)

Reliance on an upstream model or a third-party marking supplier leaves the system provider responsible for its own outputs. Under the Code, the provider can use those technical solutions but must establish that its resulting system satisfies the relevant requirements. The provider should check the files produced by the final export path, including any transformation within its service. This is an implementation recommendation grounded in Article 50(2) and the Code, Section 1, Measure 1.1.

Standard editing and combined functions

Article 50(2) excludes the duty to the extent systems perform an assistive function for standard editing or do not substantially alter the input data supplied by the deployer or its semantics. An editing feature within a generative product cannot establish an exemption for every output that the product can create.

Assume a hypothetical writing tool corrects punctuation in a supplied paragraph without changing its message. That operation supports reliance on the standard-editing exception. If the same tool invents a new factual account, the provider must assess that generation separately. Calling the whole product an editor does not establish the conditions for the second operation. (Article 50(2).)

Human review of a later publication is a different exception under Article 50(4). A publisher's editorial process does not, by itself, exempt the provider's generated output from paragraph 2. The company should assess each exception against the actor, operation and conditions specified in the relevant paragraph. This remains necessary where one company performs both roles.

Emotion recognition and biometric categorisation

Deployers must inform people exposed to an emotion recognition system or biometric categorisation system of its operation. The notice must identify the relevant AI use, rather than merely announce the presence of a camera or microphone. Article 50(3) concerns the operation of the specified system; a notice describing only image collection can leave that operation undisclosed. (Article 50(3), (5).)

Assume a hypothetical commercial exhibition display uses facial features to infer visitors' emotional states. The deployer should explain that operation before visitors are exposed to it. A proposed notice is: "This display uses AI to infer emotional states from facial features." Its adequacy depends on the actual function and placement. The example assumes a lawful, in-scope use and does not establish that any particular emotion-recognition deployment is permitted. (Article 50(3), (5).)

Article 50(3) also requires personal-data processing to comply with the applicable EU data-protection legislation. Disclosure of the system's operation does not itself supply consent or another lawful basis. The prohibitions and classification questions remain those established under the earlier parts; an informative sign cannot authorise a prohibited practice. (Articles 2(7), 5 and 50(3), (6).)

Deepfakes and professional dissemination

The deployer must disclose artificially generated or manipulated image, audio or video content constituting a deepfake. Article 3(60) requires resemblance to existing persons, objects, places, entities or events and a false appearance of authenticity or truthfulness. The definition therefore requires examination of the content and how it appears, rather than the mere presence of AI somewhere in production. (Article 50(4), first subparagraph.)

Assume a hypothetical company generates a realistic recording in which an existing executive appears to make a statement never recorded by that executive. Its presentation would make viewers believe it was an authentic recording of an actual speech. On those facts, the content meets the relevant resemblance and false-authenticity conditions. The company must disclose the artificial generation when the professional use falls within Article 50(4). Permission from the depicted executive does not appear among that provision's disclosure exceptions. (Articles 3(60), 50(4).)

The deepfake duty does not contain the text-publication rule's public-interest condition. It can apply to a professional training video shown only to employees. The Code expressly addresses closed internal professional uses and permits suitable contextual disclosure under its conditions. A company should therefore distinguish an internal deepfake presentation from a text that never meets the separate publication trigger. (Article 50(4); Code, Section 2, Sub-measure 1.2.2(c).)

Content which does not falsely appear authentic or truthful does not meet Article 3(60) on that basis. A plainly illustrated fantasy scene can therefore require a different assessment from a realistic fabricated recording. The provider's paragraph 2 marking duty remains separately relevant to synthetic content, whether or not the deployer's output satisfies the deepfake definition. (Articles 3(60), 50(2), (4).)

Artistic works and satire

Article 50(4) adjusts disclosure where a deepfake forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme. The deployer must disclose the existence of generated or manipulated content in an appropriate manner that does not hamper display or enjoyment. The exception changes the manner of disclosure while preserving that obligation.

A proposed notice for a qualifying film is: "This film contains AI-generated or manipulated scenes." Placement must account for Article 50(5)'s first-exposure requirement. A description visible before playback can serve a different function from credits encountered only after the relevant scenes. A claim that the work is fictional does not resolve whether the audience received the required information in time. (Article 50(4)–(5).)

The Code permits contextual disclosure around qualifying creative works, including adjacent interface information and introductory material. Its Commitment 3 expressly retains clear, distinguishable and accessible disclosure by first exposure. The references to credits in its examples cannot be read as unconditional permission to delay every notice until the end. (Code, Section 2, Commitment 3(b) and following paragraphs.)

Public-interest text and editorial responsibility

The text rule applies where a deployer uses AI to generate or manipulate text published for the purpose of informing the public on matters of public interest. Article 50(4) does not require a deployer label merely because AI contributed to any written message. The publisher must examine the text's purpose and dissemination, alongside the AI operation.

Assume a hypothetical company uses AI to prepare a public bulletin explaining a new statutory safety requirement. That publication has the stated purpose of informing the public on a matter of public interest. The deployer must disclose the artificial generation or manipulation unless a relevant exception applies. A private draft which is never published does not satisfy that publication condition. (Article 50(4), second subparagraph.)

The editorial exception has two cumulative requirements. The content must have undergone human review or editorial control. A natural or legal person must also hold editorial responsibility for its publication. The alternatives concern the review process; they do not turn editorial responsibility into an optional substitute for that process. (Article 50(4), second subparagraph.)

An organisation cannot establish the exception solely by identifying a person who nominally approves publications. It must also establish the required review or control over the content. Conversely, a person's review does not establish who holds editorial responsibility. The company should identify the responsible person and the process actually applied before relying on the exception. These conclusions follow from the provision's cumulative conditions.

For signatories relying on the text exception, other than the specified media-service providers, the Code requires appropriate review or control policies. They must identify editorial responsibility and allocate people and resources to the process. The Code expressly does not require documentation of every individual review instance. Those signatories also commit to publish contact details for the responsible function, natural person or legal person where these are not already public. A recommendation to retain evidence must therefore avoid inventing a mandatory signed review form for each article. (Code, Section 2, Commitment 4, pages 35–36.)

The exception concerns the text-publication obligation. A reviewed article containing a realistic fabricated video still requires a separate assessment of that video's deepfake disclosure. The provider's output-marking duty also requires its own assessment. Editorial sign-off cannot transfer an exception between paragraphs with different conditions. (Article 50(2), (4).)

The wording and placement of disclosures

Article 50(5) requires clear and distinguishable information by the first interaction or exposure, with applicable accessibility requirements satisfied. The notice must communicate the fact required by the relevant paragraph. A proposed label for a wholly synthetic qualifying image is "AI-generated image." For qualifying manipulated footage, "Video manipulated using AI" describes a different production fact. These are illustrative wordings, not prescribed legal formulae.

A deployer should select wording that accurately describes the actual content. A vague statement that a service may use AI can leave the viewer unable to identify whether a particular deepfake was artificially produced. If the required fact remains undisclosed, merely displaying some reference to AI does not establish compliance. This is an application of Article 50(4)–(5) to the stated notice design.

The Code's deployer section provides design and placement specifications for icons or equivalent labels. It addresses video openings, appropriate repetition, text headings and disclosures for audio-only content. Those specifications implement the first-exposure duty for signatories; Article 50 does not itself prescribe one universal icon, font size or duration. (Code, Section 2, Measures 1.1–1.2.)

For an audio-only deepfake, the Code specifies an audible disclosure at the beginning, subject to its qualified alternative for other audible signals. A written label attached to a webpage may not reach someone receiving an extracted audio file. The deployer should assess the actual distribution format and provide information that reaches the exposed person. (Article 50(4)–(5); Code, Section 2, Measure 1.1 and Sub-measure 1.2.3.)

Accessibility requires attention to the relevant audience and applicable law. A visual label embedded only as an image can be unavailable to someone using a screen reader. The Code addresses assistive-technology detection and alternative cues. The operator should test the notice in the relevant accessible presentation, rather than infer accessibility from its presence on a designer's screen. (Article 50(5); Code, Section 2, Measure 1.1.)

The status and limits of the compliance measures

The Code is a voluntary means of demonstrating compliance with the relevant marking, labelling and disclosure obligations. The Commission's adequacy assessment is not conclusive evidence that a particular provider or deployer complies. Article 50(7) requires an adequacy assessment and permits common implementing rules if the Code is deemed inadequate. Adherence does not create the statutory presumption of conformity described for certain harmonised standards elsewhere in the Act. (Regulation (EU) 2026/1744, Article 1(20), recital 41; Commission Opinion C(2026) 4839 final, paragraph 52.)

Operators choosing another method must meet Article 50's applicable requirements through that method. Optional measures in the Code must also remain distinguishable from commitments used to demonstrate compliance. The provider section expressly identifies richer provenance information and perceptible-marking functionality as optional measures. Their inclusion cannot establish a statutory duty to publish a prompt, reveal model internals or visibly label every generated output. (Article 50(2); Code, Section 1, Measures 1.3–1.4.)

The statutory law-enforcement exceptions require the specified legal authorisation or permission. Paragraphs 1 and 2 concern detecting, preventing, investigating or prosecuting criminal offences. Paragraph 1 also requires appropriate safeguards for third-party rights and freedoms and preserves notices for public crime-reporting systems. Paragraph 3 has a different formulation: detection, prevention or investigation, with appropriate third-party safeguards and compliance with Union law. An ordinary commercial fraud-prevention purpose cannot establish an exception without the required legal basis and conditions. (Article 50(1)–(4).)

Article 50(6) preserves other applicable transparency obligations. An AI interaction notice does not replace separate information required about personal-data processing. The high-risk notice under Article 26(11) must also be given once its application dates and transitional conditions are met. A label does not establish the legality or factual accuracy of the content itself. Operators must assess those questions under the rules applicable to the underlying conduct. (Articles 2(7), 26(11), 50(3), (6), 111 and 113.)

The final publication check should examine the information people actually receive. A platform preview, clipped video or exported audio file may present the content separately from its original page. The deployer should verify that its chosen disclosure remains clear and timely in the distribution it controls. This is a recommended implementation check under Article 50(4)–(5), supported by the Code, Section 2, Measure 1.2. A notice visible only in an unpublished editor cannot satisfy a duty owed to the people exposed to the published content.

Illia Prokopiev

Written by

Illia Prokopiev

Co-Founder and CEO

Illia is the Managing Partner and founder of Licentium. With over 11 years of practice, he has guided innovators through cross-border M&A deals and the disputes that follow, combining transactional skill with courtroom resolve. Admitted to the bar in 2017, he pivoted early to Web3, serving as legal advisor to prominent crypto projects and carrying AML/MLRO duties that anchored complex token, DAO, and compliance questions on solid regulatory ground. Certified in money laundering prevention and an active crypto investor, Illia blends market intuition with a global network of specialists, enabling Licentium to untangle licensing knots for crypto and AI ventures anywhere in the world.