AI Act Transparency Rules: What Chatbots and AI-Generated Content Must Disclose
Article 50 is not a universal “AI-generated” badge. It assigns different duties to system providers and deployers: disclosure at the start of a chatbot conversation, machine-readable provenance in synthetic output, and visible labels for deepfakes and some public-interest text.
- AI Act
- Article 50
- Chatbots
- AI Labeling
- Deepfakes
- Generative AI
Article 50 of the EU AI Act has applied since August 2, 2026. Its arrival has prompted a deceptively simple compliance question: where should an “AI-generated” label appear? The answer depends on whether a company is providing an interactive system, generating synthetic output, or deploying that output where people can see or hear it. Those are not interchangeable roles. A notice in a chat window cannot do the job of machine-readable provenance in an exported file, and embedded metadata alone does not give a viewer the visible disclosure required for a deepfake. Treating all three as one labeling task leaves gaps even when the words “created with AI” appear somewhere.
One article, three points of disclosure
For an AI system designed to interact directly with people, the provider must ensure that users are told they are interacting with AI. The notice belongs at the start of the first interaction, must be clear and distinguishable, and must meet applicable accessibility requirements. The exception for an interaction that is already obvious is assessed from the perspective of a reasonably well-informed and observant person; the Commission’s guidance says it should be read narrowly.
This obligation covers genuine two-way communication with tools such as chatbots, voice assistants, avatars, and interactive agents. It does not automatically reach background analytics or machine-to-machine exchanges that never communicate directly with a person. The provider role also deserves attention: a business that has a system developed and puts it into service under its own name or trademark may itself be the provider, even when a third-party model runs underneath.
Provenance has to travel with the output
A separate provider obligation applies to systems that generate synthetic text, audio, images, or video. Their output must be marked in a machine-readable format and be detectable as artificially generated or manipulated. The technical method must be effective, interoperable, robust, and reliable as far as technically feasible, taking account of the content type, implementation cost, and state of the art. This is an output-pipeline requirement, not merely a user-interface choice. If a file passes through export, transcoding, a content-management system, or a distribution platform, the organization needs to know whether the mark survives. A visible caption may add useful context for a reader, but it does not by itself satisfy the provider’s machine-readable marking duty.
Article 50 does not pull every assisted edit into the same rule. Standard editing that does not substantially alter the input or its meaning can fall outside the marking requirement. The Commission guidance also discusses narrow exclusions for machine-only output and certain closed industrial or business-to-business workflows. These depend on the actual use and exposure of the output, not on a product’s marketing category.
There is one targeted timing exception. Regulation (EU) 2026/1744 gives providers of relevant systems placed on the market before August 2, 2026 until December 2, 2026 to meet the machine-readable marking duty in Article 50(2). It is not a four-month delay for chatbot disclosure, deepfake labeling, or the other Article 50 obligations.
A deepfake needs a human-visible disclosure
Responsibility shifts to the deployer when an AI system generates or manipulates image, audio, or video that qualifies as a deepfake. The disclosure must be understandable and perceivable no later than a person’s first exposure to the content. The Commission expressly distinguishes this from the provider’s embedded marking: people should not need a specialized tool or a separate technical action to discover that what they are seeing or hearing is artificial. The definition is narrower than “any synthetic image.” It turns on content that resembles an existing—or plausibly existing—person, object, place, entity, or event and falsely appears authentic or truthful. Evidently artistic, creative, satirical, or fictional works remain subject to disclosure, although the form may be adapted so that it does not interfere with the experience of the work.
Public-interest text turns on editorial responsibility
Deployers must also disclose AI-generated or manipulated text published to inform the public about matters of public interest. Commission guidance places subjects such as politics, public administration, safety, health, the environment, and economic or scientific developments within that concept. A company article or automated briefing therefore cannot be classified by format alone; purpose and subject matter matter.
The regulation provides a specific exception when the text has undergone human review or editorial control and a natural or legal person holds editorial responsibility for publication. That review must address substance. A spell-check, grammar pass, or procedural sign-off is not the professional assessment described by the guidance; the reviewer needs relevant judgment and practical authority to change or reject claims. That exception concerns the deployer’s visible disclosure for published text. It does not automatically remove the provider’s separate obligation to make a generative system’s output machine-readable. The EU Code of Practice and the Commission’s downloadable labeling icons can help organizations implement parts of the framework, but both are voluntary tools. The legal duties in Article 50 remain binding.
Map the handoffs, not just the tools
A workable implementation starts with the route content takes: model, application, export, editing, approval, publication, download, and redistribution. Each handoff can strip provenance, obscure a visible notice, or change an internal draft into material intended for the public. A software inventory that stops at vendor and model names will not reveal those changes in responsibility. Controls can then be attached to the correct boundary. The first direct interaction needs a clear interface notice; synthetic files need durable machine-readable marking; deepfakes and covered public-interest text may need a visible disclosure; and the editorial exception needs evidence of substantive human review and named publication responsibility. Testing should include conversion, content-management processing, downloads, and reposting rather than only the original output.
In Germany, the Federal Network Agency’s AI Service Desk publishes implementation material, while the national AI Market Surveillance and Innovation Promotion Act establishes the oversight and coordination structure. Each deployment still requires a case-specific assessment of the organization’s role, the content, its audience, and any claimed exception.
Note: This assessment is not a substitute for a review of the specific case.
More articles
More articles from the UTOVER Journal.