What Article 50 actually requires
Article 50 of the EU Artificial Intelligence Act targets the transparency gap that generative AI exploded into public consciousness. The logic is simple: citizens should know when they are interacting with a machine, not a human, and they should be able to tell when content has been synthetically generated or manipulated. The European Commission's newly published guidelines, developed with input from Member States, the EU AI Board, and industry stakeholders, split obligations between providers (the ones building AI systems) and deployers (the ones putting them in front of people).
What providers must do
If you build an AI system that interacts directly with people — customer support chatbots, virtual assistants, automated phone handlers — users must be explicitly notified at first contact that they are talking to an AI. No fine print buried on page seven of terms. No "maybe it's a human" ambiguity. The notification must be clear and immediate.
For systems that generate synthetic audio, images, video, or text, providers must integrate machine-readable markings and provenance signals. This means digital watermarks, cryptographic metadata, and standards like C2PA Content Credentials. The goal: detection tools should be able to programmatically identify AI-generated outputs without relying on human judgment. This is the same approach Adobe, Microsoft, and Google have been pushing through the C2PA standard — embedding tamper-evident provenance metadata directly into media files.
What deployers must do
If you use emotion recognition or biometric categorisation systems, you must explicitly inform people before data processing begins. This applies whether you're running sentiment analysis on call centre audio or deploying facial analysis in a retail environment.
Anyone deploying AI to generate or manipulate synthetic media depicting realistic people, places, or historical events — what the Act calls deepfakes — must attach clear, human-perceivable labels. A watermark in the corner, a disclosure in the caption, something a person can actually see.
Media outlets and digital publishers distributing AI-generated text on matters of public interest — election coverage, public health advisories, economic reports — must clearly disclose its artificial origin. There are exemptions for routine digital workflows, but the line is drawn at content that could shape public opinion or individual decision-making.
The compliance path: voluntary code or go it alone
Companies have two routes to compliance. The first is the voluntary Code of Practice on Transparency of AI-generated Content, which the Commission has endorsed as a recognised benchmark. Align with the Code, and your legal risk drops significantly. The second route: build your own proprietary marking and labelling solution and prove to regulators that it meets equivalent standards of effectiveness, robustness, and interoperability. That second path is more work, more legal uncertainty, and more documentation — but it exists for organisations with specific technical requirements that the Code doesn't cover.
For direct human-AI interaction notices, the Commission grants flexibility: companies can implement tailored disclosures that fit their specific user interfaces, rather than a one-size-fits-all banner. The key requirement is that the notice is unmissable at first contact.
What this means in practice
As of August 2, any company serving European consumers needs to audit its content workflows. If you run a customer service chatbot, the greeting needs to state it's AI. If your video pipeline generates synthetic avatars, those outputs need provenance metadata. If you publish AI-written news summaries, the byline or header should disclose the fact.
The big technology companies have been preparing for this. Microsoft, Adobe, Google, and OpenAI all participate in C2PA and have been building Content Credentials into their products for over a year. Smaller AI startups and European companies using off-the-shelf models will have more work to do — especially those whose AI pipelines were assembled from open-source components without provenance tracking built in.
From our own operational perspective at ai-jarvis.eu: we run several AI pipelines for article generation, translation, and content processing. Article 50 means any AI-generated images we publish need embedded C2PA metadata, and any use of automated content tools that produce public-facing text about matters of public interest requires disclosure. We have been tracking these requirements — they are not impractical for a small team, but they require deliberate integration choices, not afterthoughts.
What's still ahead
Article 50 is not the final chapter. The EU AI Act is a phased rollout, and August 2 marks only the transparency layer. The high-risk AI system obligations — the ones that carry the heaviest compliance burden, including risk management systems, technical documentation, and human oversight requirements — come later. The general-purpose AI model rules, including the GPAI Code of Practice, are also on their own timeline.
But transparency is the front door. Before the EU regulates what AI can do, it is first mandating that people know when AI is doing it. That principle is harder to argue against than any specific prohibition, and it is the one that takes effect on Saturday.
Does Article 50 apply to companies outside the EU?
Yes — if your AI system's output is used in the EU market, the obligations apply regardless of where your company is incorporated. A US-based chatbot serving EU customers must comply. A non-European image generator whose outputs reach EU users must embed provenance markings. The AI Act has extraterritorial reach similar to GDPR.
What are the penalties for non-compliance?
Under the EU AI Act, fines for most infringements can reach up to €15 million or 3% of global annual turnover, whichever is higher. The exact penalty framework for Article 50 violations falls under the Act's general enforcement provisions, with national market surveillance authorities in each member state responsible for enforcement starting August 2.
Is C2PA Content Credentials mandatory or just recommended?
C2PA is not explicitly mandated by the Act — the text requires "machine-readable markings" without naming a specific standard. However, the Commission's guidelines reference C2PA as the leading implementation, and the voluntary Code of Practice effectively standardises on it. Companies that adopt C2PA have a strong compliance presumption; those choosing alternative methods must document and justify equivalence.