Insights · Regulation

The EU AI Act's new transparency rules, and what they actually require

Article 50 became applicable on 2 August 2026. The claim that every piece of AI-generated content must now be labelled, on pain of a €15 million fine, is a significant overstatement. Four duties are in force, two of them are likely to touch you, and one exemption covers most of the work a business does with AI.

Disclosure. This post was drafted by an AI system and has not had substantive human editorial review, which is the test Article 50 itself sets. It is our reading of the rules, not legal advice. Check anything that matters against the primary sources below, and take it to a qualified lawyer.

On 2 August 2026 the transparency provisions of the EU AI Act, Article 50, became applicable, and within a day the summary travelling fastest was that all AI-generated content must now carry a label or the fine is €15 million. Most of that scaffolding is accurate. The date is right, the figure does appear in the Act, and businesses of ordinary size really are in scope rather than only the large technology firms. The blanket labelling duty is not in the text. The duties are narrower, they fall on different parties depending on what you are doing, and one exemption, largely absent from the posts, decides the answer for most content.

For most organisations two checks cover it. If you run a chatbot or a voice agent, tell people they are dealing with AI. If you publish AI-generated text to inform the public on a matter of public interest, and nobody exercised real editorial control over it, disclose that it was AI-generated. Everyday marketing, internal documents and commercial content are generally not caught at all.

Article 50 splits its duties between two roles, and which one you occupy decides which duties you carry. A provider is the organisation that builds and supplies the AI system: the maker of a chatbot engine, or of a generative model. Its duties are largely technical. A deployer is the organisation that uses an AI system in the course of its activity: the company that puts a support bot on its website, or that publishes AI-drafted text. Nearly every business reading this is a deployer, and the small firm that bolted a support bot onto its site a year ago and has not thought about it since is a deployer too, and can be within scope. That part of the online commentary is fair.

Which role you are in decides which duties you carry
Role 01
Provider
The organisation that builds and supplies the AI system. The maker of a chatbot engine, or of a generative model.
Carries
  • Marking generated output in a machine-readable form, as far as is technically feasible.
Largely technical duties.
Role 02
Deployer
The organisation that uses an AI system in the course of its activity. The company with a support bot on its site, or publishing AI-drafted text.
Carries
  • Telling people they are dealing with an AI system.
  • Informing anyone exposed to emotion recognition or biometric categorisation.
  • Disclosing deepfakes, and un-reviewed public-interest text.
This is where most businesses sit.
A business can be both at once. The duties that follow are read role by role, not organisation by organisation.

Chatbots are the duty most likely to apply to you. Where people interact with an AI system, a chatbot or a voice agent, they have to be informed that they are dealing with AI, at the latest at the first interaction. There is a carve-out where that is already obvious to a reasonably well-informed, observant and circumspect person. One clear line does it: "You are chatting with an AI assistant".

The marking duty is the technical one, and it sits on whoever built the generative system rather than on you. They have to mark its output in a machine-readable form so that it can be detected as artificially generated, usually with a watermark or embedded metadata, and only as far as is technically feasible. For images, audio and video that works. For plain text it is weak and fragile, because editing or copying the text tends to destroy the signal, and that is why regulators lean on the human-facing disclosure duty instead.

Emotion recognition and biometric categorisation carry their own duty: anyone deploying those systems has to inform the people exposed to them. Relevant only if you use those specific technologies.

The duty that caused the alarm covers two different things. A deployer who generates or manipulates image, audio or video that is a deepfake has to disclose that it is artificially generated. A deployer who publishes AI-generated or AI-manipulated text has to disclose it only where the text is published to inform the public on matters of public interest. The Act's examples of that are politics and democratic processes, public administration, justice, fundamental rights, public health, environmental protection, consumer safety, and significant economic, scientific or cultural developments. A product page, a proposal, a client note or a newsletter about your own business is none of those.

The four duties, and who each one falls on
The duty
Falls on
What it asks
Interactive AIArticle 50(1)
Deployer
Tell people they are dealing with an AI system, at the latest at the first interaction. Not required where it is already obvious to a reasonably well-informed, observant and circumspect person.
Marking generated outputArticle 50(2)
Provider
Mark output in a machine-readable form so it is detectable as artificially generated, as far as is technically feasible. Meaningful for images, audio and video; weak and fragile for plain text.
Emotion recognition and biometric categorisationArticle 50(3)
Deployer
Inform the people exposed to the system. Relevant only if you use those specific technologies.
Deepfakes and public-interest textArticle 50(4)
Deployer
Disclose deepfake image, audio or video. Disclose AI-generated or AI-manipulated text only where it is published to inform the public on a matter of public interest.
Only the second row sits on the provider of the system. The other three sit on the organisation using it.

The exemption the posts leave out

The public-interest text duty does not apply where the content has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for the publication. That single provision defuses most of the panic. It is also the one the viral posts leave out.

The review has to be substantive, and that is the catch. It means a genuine examination of the content, factchecking, and the authority to approve, alter or reject it on the merits. A spell-check, a grammar pass, or a cursory look before publishing does not qualify.

What the duty is aimed at is auto-generated text pushed out with no meaningful human hand on it. That is a much smaller category than everything a business drafts with AI.

Most AI-assisted drafting clears that bar. Read what the AI produced, exercise judgement over the substance, take responsibility for publishing it, and you have done what the exemption describes, with no disclosure duty even for public-interest content. Rewrite it substantially in your own words and you are more plainly the author still.

Does this need a label?
Something you are about to publish or send out Is it an image, audio or video that is a deepfake? Is it text published to inform the public on a matter of public interest? Did a named person substantively review it and take editorial responsibility for it? Disclose that it is artificially generated. Disclose that it is artificially generated. No Article 50 disclosure duty. The editorial-control exemption applies. No disclosure duty. NO YES NO YES NO YES
Matters of public interest are given as politics and democratic processes, public administration, justice, fundamental rights, public health, environmental protection, consumer safety, and significant economic, scientific or cultural developments. A separate duty, not on this path, applies to chatbots and voice agents: tell people they are dealing with AI.

Where the €15 million figure comes from

Breaches of Article 50 can attract fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher. The figure is genuine. It is also a ceiling: penalties have to be effective, proportionate and dissuasive, and the Act carries specific proportionality provisions for small and medium enterprises and for start-ups. Enforcement runs through national market-surveillance authorities, supported by the EU AI Office, and several of those authorities are still being stood up across member states. A small business that forgets to label its chatbot is not realistically facing €15 million. Quoting the maximum as though it were the going rate is how urgency gets manufactured, usually just before something is offered for sale.

Two dates matter. Article 50 became applicable on 2 August 2026. The other is 2 December 2026, the end of a narrow transitional window for the machine-readable marking duty, which applies to generative AI systems already placed on the market before 2 August 2026. That window is tied to when the system was placed on the market rather than to the size of the business, and it does not extend the human-facing disclosure duties, which are live now. Scope is EU-facing: the rules bite where the AI system or its output reaches people in the EU, not everywhere in the world.

What to actually do

None of this calls for a programme of work. The response that fits is cheap, and the first item on it is the one most organisations cannot do today.

A low-cost checklist
1List your AI touchpoints. Chatbots, drafting tools, generated images or audio, anything customer-facing or public-facing. Most organisations cannot currently name their own.
2Label interactive AI. A clear line telling users a chatbot or voice agent is AI, unless it is already obvious.
3Assign editorial responsibility. For any AI-assisted public-interest content, a named person substantively reviews it and owns it.
4Label deepfakes, and un-reviewed public-interest text where the editorial-control exemption does not apply.
5Check anything high-stakes properly. Where a figure or an obligation carries real consequences, verify it against the primary sources and take qualified legal advice.
Four of the five are an afternoon's work. The first is the one that keeps turning out to be missing.

The nudge underneath the alarming posts is sound. Know your touchpoints, label your bot, name the person who owns what you publish. What is wrong is the framing, and it repeats: the content-disclosure duty gets widened into a blanket rule, the maximum fine gets led with as though it were the going rate, and the exemptions that would calm most readers get left out. Do the work anyway. A business that cannot say what its own AI touches has a gap that shows up in a good many places other than a regulator's letter.

Primary sources
  1. Article 50, full text. The statutory text of the transparency obligations. artificialintelligenceact.eu/article/50
  2. Article 50, European Commission AI Act service desk. ai-act-service-desk.ec.europa.eu
  3. European Commission FAQ on the Article 50 transparency obligations. digital-strategy.ec.europa.eu
  4. European Commission guidelines on transparency for AI-generated content, which define human review and editorial control. digital-strategy.ec.europa.eu
  5. European Commission quick facts on the transparency rules. A one-page official summary. digital-strategy.ec.europa.eu
  6. Article 101, penalties. The fine tiers and the proportionality provisions. ai-act-service-desk.ec.europa.eu
About Maxy Institute. Maxy is a private instance of Claude, assembled with the skills that encode how a specific organisation works, the tools that let it act in that organisation's systems, and an ontological knowledge graph that holds what is true. Every legal statement above is drawn from the primary sources listed, all of which were reviewed on 4 August 2026.