AI POLICY

EU AI Act AI Labeling Rules: What Must Be Disclosed in 2026?

A practical decision guide to the EU AI Act’s Article 50 marking and disclosure duties for providers, deployers, publishers, and product teams.

From 2 August 2026, Article 50 of the EU AI Act requires disclosures in four main situations: direct interaction with certain AI systems, machine-readable marking of synthetic content by providers, notice when people are exposed to emotion recognition or biometric categorisation, and visible labels for deepfakes or certain AI-generated public-interest text. The exact duty depends on whether you provide the AI system or deploy it, what the output contains, and whether an exception applies.

Key takeaways

  • Article 50 duties apply from 2 August 2026, but different actors perform different disclosures
  • Providers generally build interaction notices and machine-readable synthetic-content marks into systems
  • Deployers generally notify exposed people and visibly label qualifying deepfakes or public-interest text
  • Human review can matter for public-interest text, but it is not a blanket exemption for every synthetic asset
  • The Commission’s guidelines explain scope while the voluntary code offers a recognised compliance route
  • Product teams should preserve provenance and disclosure decisions across the full content supply chain

Start by separating provider duties from deployer duties

Article 50 is not a single instruction to put an AI badge on content. It assigns different responsibilities to providers—the organizations that develop an AI system or have it developed and place it on the market under their name—and deployers, which use an AI system under their authority. One company can occupy both roles in a product chain, and vendors, customers, agencies, contractors, and publishers may divide the work in ways that are not obvious from a user interface.

The Commission groups the obligations into four situations. Providers must design covered interactive systems so people know they are interacting with AI, and providers of generative systems must make covered synthetic outputs machine-readable and detectable. Deployers must notify people exposed to emotion recognition or biometric categorisation, and must clearly disclose qualifying deepfakes and certain AI-generated or manipulated public-interest text.

Build a role-and-output matrix before choosing labels. For every system, name the provider, deployer, intended audience, content type, distribution channel, editorial owner, and technical handoffs. That matrix prevents a common failure: a deployer adds a visible caption while the upstream provider never supplies a durable machine-readable mark, or a provider supplies metadata that disappears before publication.

Interactive AI notices must appear when the interaction begins

A provider of an AI system designed for genuine, direct, two-way exchange with natural persons must make the AI nature clear unless it is obvious. The Commission’s Q&A says the notice should be clear and distinguishable, meet accessibility requirements, and appear from the start of the first interaction. A buried privacy policy or help-center paragraph is therefore a weak implementation for a customer-facing assistant.

The obligation is narrower than every automated event. Background processing, machine-to-machine exchange, systems that only collect data, and responses delivered through a human intermediary may fall outside this particular rule. The obviousness exception should be treated cautiously: branding a product as an assistant may help, but teams should test what an average reasonably informed and observant person would understand in the actual interface.

A practical design uses plain language beside the conversation entry point and retains the signal throughout voice, avatar, messaging, and embedded experiences. Accessibility testing should cover screen readers, contrast, spoken introductions, localization, and cases where a user enters halfway through a session. Keep evidence of the wording, placement, test results, and release version.

Machine-readable marking and visible labels solve different problems

For covered synthetic audio, image, video, or text, the provider duty is technical: outputs must be marked in a machine-readable format and detectable as artificially generated or manipulated. The Commission notes exclusions and qualifications, including source code, some machine-only outputs, standard editing, and outputs that do not substantially alter the supplied data or meaning. Narrow business-to-business or industrial treatment may also depend on conditions in the guidelines.

The deployer duty is perceptual. A person publishing a qualifying deepfake must disclose its artificial nature, while AI-generated or manipulated text intended to inform the public on matters of public interest requires a clear label when it lacks the relevant human review and editorial responsibility. The legal definition of a deepfake focuses on image, audio, or video that resembles an existing or plausibly existing subject and would falsely appear authentic or truthful.

Do not treat metadata and a visible disclosure as interchangeable. A machine-readable mark supports automated detection and provenance across systems; a visible label communicates directly to a person. A workflow may need both. Teams should test whether technical marks survive file conversion and whether visible language remains close enough to the content to be understood after syndication, quoting, embedding, or reposting.

Human review must be substantive and accountable

The public-interest text rule has generated an attractive shortcut: add a human reviewer and omit the label. That is too simplistic. The relevant exception refers to a process of human review or editorial control where a natural or legal person holds editorial responsibility. A person clicking approve without checking evidence, meaning, and presentation is not a persuasive control, especially when the workflow automatically publishes at scale.

Define what review covers. The editor should identify the sources, confirm consequential facts, inspect whether the model changed the claim, correct misleading framing, and own the decision to publish. Record the reviewed version and the responsible party. If content changes after review through personalization, translation, summarization, or automated optimization, decide whether that creates a new unreviewed publication.

Public-interest status also requires judgment. Government, elections, health, safety, the economy, and significant social issues are obvious candidates, but a commercial publisher should not invent a narrow definition. Create an escalation path for borderline topics and obtain qualified legal advice rather than allowing a content generator to classify its own output.

Build compliance into the content supply chain

The strongest program combines legal classification, product design, publishing operations, and evidence retention. Providers should specify the marking method, detection expectations, failure behavior, model and feature coverage, and downstream documentation. Deployers should define visible label templates, location, timing, accessibility, review rules, and handling for third-party assets. Contracts should allocate responsibility without assuming that a clause transfers the statutory role.

Run end-to-end tests with real formats: generate an asset, edit it, export it, compress it, place it in a content management system, publish it, and download it again. Check the machine-readable signal at each stage. For visible labels, test mobile cropping, audio-only playback, translated pages, social previews, captions, and reposts. Monitor loss rates and block publication when a required control is missing.

The Commission’s voluntary Code of Practice offers signatories a recognized way to demonstrate compliance with marking and labelling duties. It does not replace the regulation or guidelines, and choosing not to sign does not remove the obligation. Whichever route you use, maintain a decision record tied to specific system versions and revisit it when models, editing features, distribution channels, or official guidance change. This article summarizes official materials and is not legal advice.

Practical checklist

  • Inventory interactive AI, generative features, emotion recognition, biometric categorisation, and synthetic media uses
  • Identify the legal provider and deployer for each system and document who controls the relevant obligation
  • Classify each output as text, image, audio, video, deepfake, standard edit, or public-interest publication
  • Design machine-readable marking, visible labels, timing, placement, language, and accessibility together
  • Record any exception with the facts, responsible reviewer, editorial control, and supporting guidance
  • Test whether marks survive export, compression, editing, syndication, and platform handoffs
  • Update vendor contracts and publishing workflows so provenance data and compliance evidence travel downstream
  • Obtain legal advice for borderline or consequential cases before the rules apply

Warning signs

  • A team uses one generic AI badge for every Article 50 obligation without classifying actor or content
  • Visible labels are added manually but the provider has no machine-readable marking design
  • The business assumes a human glanced at content, yet nobody holds real editorial responsibility
  • Provenance metadata disappears when an asset is cropped, transcoded, downloaded, or uploaded to another platform
  • A chatbot disclosure appears only in terms of service instead of at the start of the interaction
  • The compliance plan relies on an exception without a written factual analysis

Frequently asked questions

When do the EU AI Act transparency rules apply?

The Article 50 transparency obligations discussed here apply from 2 August 2026. Transitional details and amendments can affect particular systems, so confirm the current rule for your product and release date.

Does every AI-generated image need a visible label?

Not necessarily. Providers face a machine-readable marking duty for covered synthetic outputs, while deployers have visible disclosure duties for qualifying deepfakes and certain public-interest text. Context, actor, content, and exceptions matter.

Must a chatbot say that it is AI?

A provider of an AI system designed for direct two-way interaction with people must make that clear unless it is obvious to a reasonably informed and observant person. The notice should appear from the start of the first interaction.

Does human review remove the need to label AI-generated text?

For certain text published to inform the public on matters of public interest, human review plus editorial responsibility can affect the deployer disclosure duty. It does not erase other applicable duties or automatically exempt images, audio, video, or deepfakes.

Is the EU transparency code mandatory?

The code is voluntary. Signatories may rely on its measures to demonstrate compliance; organizations using another route must be able to show that their measures are adequate.

Primary sources and further reading

Research before you rely.

AI products, prices, policies, and capabilities change. Verify consequential details with primary sources and test tools using representative work.