EU AI Act Transparency Obligations: What Your Company Needs to Know
Summary
- Article 50 of the EU AI Act is now in force: Since August 2, 2026, Article 50 of the EU AI Act has imposed transparency obligations on providers and deployers of certain AI systems. The European Commission’s guidelines, published shortly afterward, provide the clearest indication to date of how these obligations should be understood, applied in practice, and enforced.
- Broader scope than many companies may assume: The transparency obligations are relevant not only where users interact directly with AI, but also where AI systems generate or materially manipulate text, images, audio, or video, including deepfakes and multimodal outputs. Businesses should not assume that these rules are limited to consumer-facing chat interfaces.
- Required preparedness: Organizations should now review their AI features, outputs, and user journeys to assess whether Article 50 applies and whether their current disclosures, technical measures, governance processes, and vendor arrangements adequately support compliance. For many businesses, this should be treated as an immediate product, legal, and compliance review, rather than a future implementation exercise.
Article 50 of the EU AI Act has applied since August 2, 2026. It imposes transparency obligations requiring organizations to make clear when individuals are interacting with AI or are exposed to AI-generated or AI-manipulated content. It applies to providers and deployers of certain AI systems, including generative and interactive AI systems and deepfakes.
Against that backdrop, the European Commission published guidelines intended to clarify how the Article 50 requirements should be understood, applied in practice, and enforced.
What to Watch
The guidelines provide the European Commission’s clearest indication to date of how it interprets Article 50, what compliance is expected to look like in practice, and where enforcement is likely to focus. This clarity is particularly important as generative and interactive AI tools become more widely embedded in products, services, and internal workflows, making it increasingly difficult to distinguish between human and AI interactions and between authentic and synthetic content.
We have prepared a practical guide to help your teams navigate these new transparency obligations and assess the steps they should now consider.
What Do AI Act Transparency Obligations Mean for Your Company?
Which uses are in scope?
The AI Act’s transparency measures apply to practices involving AI that have the potential to mislead individuals. These include, among other uses:
- AI interacting directly with individuals, including chatbots, voice assistants, social media bots, and marketing and support bots.
- AI generating or manipulating content, including text, images, audio, or video that users, customers, or the public may see, hear, or otherwise consume.
- Deepfakes, where an AII system generates or manipulates image, audio, or video content so that it appreciably resembles a real or realistic person, object, place, entity, or event, and appears authentic or truthful to individuals.
We have a support chatbot. How should we prepare?
The new obligations cover chatbots because they are designed to interact with individuals. The AI Act requires you to tell people that they are interacting with AI rather than a human. This is not required where it is evident from the circumstances that there is no human on the other side of the conversation.
This can be done by including language indicating AI use, such as “powered by AI,” or by including a notice in the chat interface, for example in the heading, “Company’s AI Support,” or in the first message, “Hi, I am the company’s AI chatbot.”
What counts as “direct interaction”?
Generally, this means the user and the AI are actually exchanging information back and forth. A chatbot, voice assistant, or AI agent in the user interface is an obvious example. If AI is only assisting your human support team behind the scenes and the customer interacts solely with a human, this is generally not considered direct interaction.
Shouldn’t the company providing the bot take care of this?
They should. However, the AI Act places responsibility on both the provider—the company making and selling the tool—and the deployer—the company using the tool. Therefore, if the supplier has not included the required functionality, you must ensure that it is in place.
As part of the product, we allow users to generate content. What should we pay attention to?
There are two requirements, and both must be met:
- The output must be marked in a machine-readable manner.
- The output must be detectable as AI-generated or AI-manipulated.
Meeting only one requirement is not enough.
You must also provide users with a way to check whether the content is AI-generated.
Generally, the obligations will not apply where the system performs only standard editing or makes changes that do not substantially alter the input or its meaning. The EU guidelines give examples such as grammar correction, spell-checking, format conversion, minor cropping, minor color correction, and technical compression.
Content that is solely machine-to-machine and is never perceived by humans is also generally outside the scope.
What kinds of content and AI use are we talking about?
The obligations apply to AI-generated or AI-manipulated text, images, audio, and video, including multimodal outputs that combine different content types. If your product creates AI-generated copy, images, voice, or video, or materially edits those types of content, these obligations may apply.
Is a visible “AI-generated” label or watermark enough?
No, not on its own. The guidelines state that the legal requirement is machine-readable marking. A visible label or watermark can still be helpful, but it is an additional measure rather than a substitute.
Do we need to build our own detection tool?
Not necessarily. You can rely on a tool provided by the model provider, a third party, or a publicly available solution. However, your company remains responsible for ensuring that the solution works for your product and supports compliance.
Information about the detection tool must be provided in a clear and distinguishable manner, no later than the user’s first interaction with, or first exposure to, the content. Buried legal text or information hidden behind several clicks is therefore risky. In practice, the safer approach is to place this information close to the chatbot, content, or user flow where it is relevant.
We only use AI internally. Are we out of scope?
No. There is no blanket exemption merely because the tool is used internally. If an internal AI assistant interacts directly with employees, the obligations may still apply.
If an internal tool generates synthetic content that people within the company use, review, or circulate, Article 50(2) may also apply. The guidelines discuss limited cases in which highly technical internal outputs may fall outside the practical need for marking and detection, but this is not a general rule.
What should product teams do now?
A practical starting point is to review each AI feature and ask:
- Is the user interacting directly with AI?
- Is the system generating or materially changing text, images, audio, or video?
- Who will see or hear the output?
Based on this assessment, product teams should seek legal advice to determine whether these obligations apply.
We are not based in the EU. Can this still apply to us?
Yes. If your AI system’s output is used in the EU, the rules may still apply even if your company is based elsewhere.
What is the downside of getting this wrong?
The enforcement risk is real. Non-compliance with the transparency obligations may result in fines of up to EUR 15 million or, for companies, up to 3% of worldwide annual turnover, whichever is higher.
In light of the European Commission’s guidelines and Article 50’s entry into application, organizations should review whether their practices adequately address the new transparency obligations.
Our Privacy, Cyber and AI Department would be pleased to advise on how these obligations apply in practice and the steps organizations should consider to support compliance.
***
Dr. Avishay Klein is a partner and head of the firm’s Privacy, Cyber and AI Department.
Adv. Masha Yudashkin is an associate in the firm’s Privacy, Cyber and AI Department.

