EU AI Act Transparency Obligations: What Your Company Needs to Know
Summary
- Article 50 of the EU AI Act is now in force: Since 2 August 2026, Article 50 of the EU AI Act has imposed transparency obligations on providers and deployers of certain AI systems. The European Commission’s Guidelines, published shortly thereafter, provide the clearest indication to date of how these obligations should be understood, applied in practice, and enforced.
- The scope is broader than many companies may assume: The transparency obligations are relevant not only where users interact directly with AI, but also where AI systems generate or materially manipulate text, images, audio, or video, including deepfakes and multimodal outputs. Businesses should not assume that these rules are limited to consumer-facing chat interfaces.
- Required preparedness: Organizations should now review their AI features, outputs, and user journeys to assess whether Article 50 applies and whether their current disclosures, technical measures, governance processes, and vendor arrangements adequately support compliance. For many businesses, this should be treated as an immediate product, legal, and compliance review rather than a future implementation exercise.
Article 50 of the EU AI Act has applied since 2 August 2026 and imposes transparency obligations requiring organizations to make clear when individuals are interacting with AI or are being exposed to AI-generated or AI-manipulated content. It applies to providers and deployers of certain AI systems, including generative and interactive AI systems and deepfakes.
Against that backdrop, the European Commission published Guidelines intended to clarify how these Article 50 requirements should be understood, applied in practice, and enforced.
What to Watch
The Guidelines provide the Commission’s clearest indication to date of how it interprets Article 50, what compliance is expected to look like in practice, and where enforcement is likely to focus. That clarity is particularly important as generative and interactive AI tools become more widely embedded in products, services, and internal workflows, making it increasingly difficult to distinguish between human and AI interactions and between authentic and synthetic content.
We have created a practical guide for your teams to navigate these new transparency obligations and assess the steps they should now consider.
What do the AI Act transparency obligations mean for your company?
Which uses are in scope?
The AI Act transparency measures apply to different practices where the use of AI has the potential to mislead individuals. These include, amongst other uses:
- AI interacting with individuals directly – chatbots, voice assistant, social media bots, marketing and support bots, and more.
- AI generating or manipulating content – text, images, audio, or video that users, customers, or the public may see, hear, or otherwise consume.
- Deep fakes – AI system is used to generate or manipulate image, audio, or video content so that it appreciably resembles a real or realistic person, object, place, entity, or event, and the result would appear authentic or truthful to people.
We have a support chatbot, how should we prepare?
The new obligations cover chatbots as these are designed to interact with individuals. The AI Act requires you to tell people that they are not interacting with a human, but rather with AI. This is not required if it is evident from the circumstances that there is no human on the other side of the conversation.
This can be done by including language indicating AI use like “powered by AI”, or including a notice in the chat attributes (in the heading “company’s AI support”, or in the first message “Hi, I am company’s AI chatbot”).
What counts as “direct interaction”?
Usually, it means the user and the AI are actually exchanging information back and forth. A chatbot, voice assistant, or AI agent in the UI is the obvious example. If AI is just helping your human support team behind the scenes, and the customer is only interacting with the human, that is generally not direct interaction.
Shouldn’t the company providing the bot take care of this?
They should! But the AI Act places responsibility both on the provider (the company making and selling the tool) and the deployer (the company using the tool). So, if the supplier did not include such functionality, you have to make sure you do.
As part of the product, we allow users to generate content. What should we pay attention to?
Two things, and you need both:
- the output must be marked in a machine-readable way; and
- the output must be detectable as AI-generated or AI-manipulated.
Doing only one of these is not enough.
You also need to provide your users with a way to check content to verify whether it is AI generated or not.
Usually, where the system is only doing standard editing or making changes that do not substantially alter the input or its meaning, the obligations will not apply. EU guidelines give examples like grammar correction, spell check, format conversion, minor cropping, minor colour correction, and technical compression.
Content that is only machine-to-machine and never perceived by humans is also generally outside the scope.
What kinds of content and AI use are we talking about?
The obligations apply to AI-generated or AI-manipulated text, images, audio, and video. That includes multimodal outputs (outputs mixing different types). So if your product creates AI copy, AI images, AI voice, AI video, or materially edits those types of content, this applies to you.
Is a visible “AI-generated” label or watermark enough?
No, not on its own. The guidelines say the legal requirement is for machine-readable marking. A visible label or watermark can still be helpful, but it is treated as an extra measure, not a substitute.
Do we need to build our own detection tool?
Not necessarily. You can rely on a tool from the model provider, a third party, or a publicly available solution. But your company still remains responsible for ensuring that the solution works for your product and is compliant.
The information about the detection tool needs to be provided in a clear and distinguishable manner, no later than the user’s first interaction or first exposure to the content. That means buried legal text or something hidden behind several clicks is risky. In practice, the safer approach is to place it close to the chatbot, content, or user flow where it matters.
We only use AI internally. Are we out of scope?
No. There is no blanket exemption just because the tool is internal. If an internal AI assistant interacts directly with employees, the obligations still apply.
If an internal tool generates synthetic content that people inside the company use, review, or circulate, Article 50(2) can still matter too. The draft guidelines do discuss limited cases where highly technical internal outputs may fall outside the practical need for marking and detection, but that is not a general rule.
What should product teams do now?
A good practical starting point is to review each AI feature and ask:
- Is the user interacting directly with AI?
- Is the system generating or materially changing text, images, audio, or video?
- Who will see or hear the output?
Based on this, product teams should seek legal advice, to determine the applicability of these obligations.
We are not based in the EU. Can this still apply to us?
Yes. If your AI system’s output is used in the EU, the rules can still apply even if your company is based elsewhere.
What is the downside of getting this wrong?
The enforcement risk is real. Non-compliance with the transparency obligations can lead to fines of up to EUR 15 million or, for companies, up to 3% of worldwide annual turnover, whichever is higher.
In light of the Commission’s Guidelines and the entry into application of Article 50 of the EU AI Act, organizations should review whether their practices adequately address the new transparency obligations.
Our Privacy, AI, and Cyber Department would be pleased to advise on how these obligations apply in practice and what steps organizations should consider to support compliance.
***
Dr. Avishay Klein is a partner and head of the firm’s Privacy, Cyber and AI Department.
Adv. Masha Yudashkin is an associate in the firm’s Privacy, Cyber and AI Department.

