EU AI Act Article 50: what product builders have to do now

By Göran Sandahl -

Article 50 of the EU AI Act applies from 2 August 2026. It covers two things: telling people when they are dealing with AI, and marking content that AI generated.

Most of the coverage pointed it at the large model labs. But these duties fall on the companies that build products on top of models, and on the companies that deploy them. If you ship a chatbot, a drafting feature or an image generator, this is yours.

Article 50 has nothing to do with risk tiers. It is not limited to high-risk systems, so being outside the high-risk categories tells you nothing about whether these duties apply to you. An ordinary support chatbot is not high-risk and is still fully in scope.

Find what you ship in the table below, then read the section for it.

The one-minute version

What you shipWhat you must doBy when
A chatbot or assistant that talks to peopleTell them they are dealing with AINow
Generated images, audio or videoMark it so a machine can detect itNow, or 2 Dec 2026 if it was live before 2 Aug
Generated textMark it, as far as is technically feasibleNow, or 2 Dec 2026 if it was live before 2 Aug
A feature that only edits or assistsUsually nothingNot applicable
Synthetic media of real peopleDisclose that it is artificialNow
AI-written text published on public-interest topicsDisclose it, unless a human reviewed itNow
Emotion recognition or biometric categorisationInform the people exposed to itNow

What it costs to get these wrong: up to €15 million or 3% of your worldwide annual turnover, whichever is higher, under Article 99. Your national market surveillance authority enforces it, not the Commission, so the answer you give has to satisfy each country you operate in.

Those rows do not all land on the same party, so settle your role first.

First, which role are you in?

Every duty attaches to either the provider or the deployer.

Provider: you develop an AI system, or have one developed, and put it on the market or into service under your own name or trademark. Paid or free makes no difference.

Deployer: you use an AI system under your own authority, in a professional capacity.

The short test is whose name is on it.

  • You build a support assistant on a third-party model and ship it as your feature. You are the provider. You trained nothing, and that changes nothing.
  • Your team uses an off-the-shelf AI notetaker. You are its deployer. The notetaker company is its provider.
  • You take someone else's system, put your brand on it, or change it substantially. You become the provider and you inherit the provider's duties. This one catches people.

Most companies are both, in different parts of the business.

Provider duties are the first two rows of the table: disclosure of AI interaction, and marking of generated content. The rest are deployer duties.

Where you are based does not decide this. The obligations follow the output. If what your system produces is used in the EU, Article 50 applies regardless of where your company sits. A US company with European users is in scope, and so is a UK one.

If your product talks to people

Article 50(1). Anyone interacting directly with your system has to know it is a system.

There is an exception where it is obvious, but read the test before relying on it. The Act asks what a reasonably well-informed, observant and circumspect person would understand, given the circumstances and the context of use. That is a higher bar than "our users are technical". If a support widget answers in fluent prose, assume it is not obvious.

Article 50(5) then tells you when the notice has to appear and what it has to look like:

  • The information has to reach the person at the first interaction or exposure at the latest. Buried in your terms of service does not count.
  • It has to be clear and distinguishable from the rest of the interface.
  • It has to meet accessibility requirements, which means screen readers, not only a line of grey text.

In practice that means a line in the chat header or the opening message, in the language of the conversation, that survives being embedded in someone else's page. Voice systems need it spoken, not written in a widget nobody reads.

If your product generates images, audio or video

Article 50(2). Output has to carry a marker that a machine can read and that identifies the content as artificially generated or manipulated.

Two techniques, usually stacked.

Content Credentials. The C2PA standard, now an ISO standard with several thousand organisations behind it including Adobe, Microsoft, Google and the BBC. It is a cryptographically signed record that travels with the file and describes what made it and how it was edited. Straightforward to attach, and easy to lose. A screenshot, a format conversion, or an upload to a platform that strips metadata removes it.

Watermarks. Patterns embedded in the pixels or the audio samples themselves. Google's SynthID is the best known. These survive compression, cropping and re-encoding far better than metadata does.

Three things to check in your own stack:

  1. What your model providers emit. They differ, and it is rarely on the pricing page.
  2. Whether your own pipeline destroys it. Re-encoding an image usually strips Content Credentials. Generating a thumbnail almost always does.
  3. Whether anything downstream re-encodes: your CDN, your image optimiser, your CMS.

If your generative feature was already live before 2 August 2026, the Digital Omnibus gives you until 2 December 2026 for this obligation, and only this one. Anything shipped after 2 August gets no extension at all.

If your product generates text

Same obligation, much weaker technology. Know this before you promise anyone detection.

Text watermarking degrades badly under ordinary use:

  • SynthID's detection rate for text falls from around 99.8% on untouched output to roughly 50% under moderate paraphrasing.
  • Published work in 2026 found that a single pass through any LLM, asking it to rewrite the text, pushed every method tested below 30% detection.
  • One attack reports near-total success at under a dollar per million tokens.

The law accounts for this. Article 50(2) asks for solutions that are effective, interoperable, robust and reliable as far as is technically feasible, taking into account the state of the art. It does not ask you to solve an unsolved problem.

What that means in practice: apply what your provider offers, document what you applied, and keep your reasoning about what you considered and rejected. The obligation is a genuine attempt at the current state of the art, not a guarantee of detection. Any vendor telling you they have solved text watermarking is overselling.

If your product only edits or assists

Marking does not apply where the system performs an assistive function for standard editing, or where it does not substantially alter the input data or its meaning.

This carve-out will save you the most work, so check carefully which side of the line you are on.

Comfortably outside: spellcheck, grammar correction, autocompleting the next few words, reformatting, transcription cleanup, colour correction.

Comfortably inside: "write me a post about X", generating an image from a prompt, producing a synthetic voice.

Genuinely arguable: "rewrite this paragraph to be more formal", summarising a long document, expanding bullets into prose. The question the Act poses is whether the output substantially alters the input data or its semantics. A tone change applied to the user's own sentence sits closer to editing. A summary that produces new sentences sits closer to generation.

If you are in the arguable middle, write your reasoning down now rather than reconstruct it under questioning later.

If you publish AI text, or synthetic media of real people

These are deployer duties, under Article 50(4).

Synthetic media of real people. If you publish content that convincingly depicts real people, places or events, and it was artificially generated or manipulated, you disclose that. Where the content forms part of an evidently artistic, creative, satirical or fictional work, the duty is limited: you disclose in a manner that does not hamper the display or enjoyment of the work. A credit at the end of a film, not a watermark across every frame.

Published AI text on public-interest matters. If you publish AI-generated text to inform the public on matters of public interest, you disclose it. The exemption is where you get relief: it does not apply where the content went through human review or editorial control and a person or organisation holds editorial responsibility for it.

For most companies that means a product marketing blog falls outside the public-interest test, while an automated news or research feed falls inside it unless a named human signs off.

If you do emotion recognition or biometric categorisation

Article 50(3) is short, and easy to miss if you do not think of these as generative features. Deployers must inform the people exposed to the system that it is operating. This covers sentiment analysis on customer calls, attention tracking, and categorising people by biometric data.

GDPR applies alongside this, not instead of it. The duty to inform does not replace your lawful basis for processing.

How to show you complied

Saying you comply is not the same as being able to demonstrate it. Two instruments do that work.

The Code of Practice on Transparency of AI-generated Content. Finalised on 10 June 2026 after three drafting rounds and a multi-stakeholder process, with roughly 190 signatories by late July. The Commission and the AI Board have assessed it as an adequate voluntary tool for demonstrating compliance. It has a provider section covering machine-readable marking and detectability, and a deployer section covering synthetic media and published AI text.

The practical argument for signing is jurisdictional. Signatories get predictability across every member state. Non-signatories have to demonstrate adequate alternative measures to each national authority separately, and those authorities are at very different stages of maturity.

The Commission's guidelines. Adopted on 20 July 2026, two weeks before the rules applied. They carry the definitions, the exemptions and worked examples, and they are what to consult when your case sits near a line.

Whichever route you take, keep four things: an inventory of every generative surface with its go-live date, a record of what marking you applied and what your providers emit, your reasoning on any exemption you rely on, and the wording and placement of each disclosure.

Who enforces this, and what it costs

Article 50 is enforced by national market surveillance authorities, not by the Commission. The Commission enforces the separate regime covering providers of general-purpose models, where its powers to request information, access models, require corrective measures and force market withdrawal went live on the same date.

Penalties for breaching Article 50 fall under Article 99 and reach €15 million or 3% of worldwide annual turnover, whichever is higher.

The obligation is uniform across the EU. Enforcement will not be, because member states are at very different stages of designating and resourcing their authorities. That is an argument for being able to demonstrate compliance, not an argument for waiting.

A 30-minute audit

  1. List every surface that generates content or talks to a person. Support widgets, drafting features, summarisation, generated images on the marketing site, voice. Teams routinely miss two or three.
  2. Date each one against 2 August 2026. Earlier means the December window applies, and only to marking. Later means it is already in scope.
  3. Fix conversational disclosure first. No grace period, cheapest to fix, most visible if you get it wrong.
  4. Ask each model provider what they emit, then test whether your pipeline keeps it. Generate something, download it, inspect the file.
  5. Decide on the Code of Practice. It is the difference between one compliance story and twenty-seven.
  6. Make sure you can answer "what produced this" for anything you have shipped: which model, when, from what prompt.

One thing not to spend time on: high-risk classification. That moved to December 2027 and is a separate exercise.

The Opper perspective

We build an AI gateway, so the honest disclosure is which half of this we can help with.

We cannot mark your content. Nobody sitting between you and the model can, because the marker has to be applied while the content is being generated. Any vendor claiming to solve Article 50(2) for you is selling something it does not have.

What a gateway holds is the trace: which model produced which output, when, and from what prompt. That answers step 6 of the audit, and it helps with step 1, because calls running through one place give you the inventory instead of making you reconstruct it.

What is actually kept depends on how you run. On Gateway it is metadata only: the model, token counts, latency and cost. On the Control Plane every call is traced, so the prompt and the response are held alongside the model that produced them, the time, and the function. Retention is configurable per project, down to zero. That setting is the decision you are making: full traces give you something to produce later, zero retention gives you nothing.

None of that is compliance with Article 50(2). A trace describes content; it does not mark content.

This is a guide, not legal advice. Where your case sits near a line, read the guidelines and ask someone qualified.