The short answer first: Article 50 generally applies from 2 August 2026. It contains different obligations for providers and deployers. Providers must make certain systems and their generated outputs technically transparent. Deployers must, among other things, disclose the use of emotion recognition and label deepfakes and certain texts on matters of public interest[1]. Which obligation applies to a business must therefore be assessed separately for each use case.
What applies from 2 August 2026?
The EU AI Act has been in force since August 2024 and takes effect in stages[2]. While the strictest high-risk obligations have been postponed to December 2027 by the Omnibus reform, the transparency obligations under Article 50 remain on the original schedule: they are binding from 2 August 2026[3]. Article 50 covers four categories of cases[1]:
A limited transitional rule applies to systems placed on the market before 2 August 2026. For the machine-readable marking and detectability of generated content under Article 50(2), the providers of such systems only have to meet the requirements from 2 December 2026. Content generated before 2 August does not have to be labelled retrospectively.
Interaction with AI systems
Anyone operating a chatbot, voicebot or AI assistant must inform users that they are interacting with an AI. Exception: this is obvious from the circumstances.
Synthetic content
AI systems that generate audio, images, video or text must mark their outputs as artificially generated in a machine-readable format. This obligation falls primarily on the providers of the systems.
Deepfakes and texts informing the public
Anyone publishing AI-generated or manipulated image, audio or video content that appears real must disclose this. The same applies to AI-generated texts intended to inform the public, unless a person holds editorial responsibility for them.
Emotion recognition and biometric categorisation
Where such systems are used, the people affected must be informed. For the typical SME, this is the rarest category, but it can quickly become relevant in an HR context.
Labelling must be clear, understandable and timely, at the latest at the first interaction or exposure. Notices hidden in the terms and conditions are not sufficient[4].
Who exactly is subject to the labelling obligations?
Article 50 distinguishes between providers, which develop AI systems or place them on the market under their own name, and deployers, which use systems under their own authority in a professional context[5]. An SME can be the deployer of a purchased system and at the same time a provider if it makes its own system available under its own name. Company size does not determine these roles[6].
Three scenarios are particularly relevant for SMEs in practice: the customer service chatbot, which will in future have to identify itself clearly as AI; AI-generated images and videos in marketing that show realistic-looking people or scenes and may therefore fall under the deepfake disclosure requirement; and AI-generated texts informing the public, such as automatically generated news or guidance content. For the latter, the disclosure obligation does not apply if a person assumes editorial responsibility and reviews the content[1]. This very exception shows the direction of the regulation: human control over AI outputs is rewarded.
How do you label AI-generated content correctly?
For a long time, it was unclear what machine-readable marking should look like technically. Since 10 June 2026, there has been an official answer: the European Commission has published the Code of Practice on Transparency of AI-Generated Content[8]. It specifies labelling as an approach with at least two layers: digitally signed metadata based on C2PA-like standards plus an imperceptible watermark firmly embedded in the content[9].
The code of practice is voluntary. Signatories can rely on the measures it describes to document their implementation in a more traceable and predictable way[10]. However, this does not amount to a blanket guarantee of conformity. Businesses that choose other suitable measures must be able to demonstrate their suitability. Deployers should also check which visible disclosure obligations apply to them[11].
A further obligation: AI literacy under Article 4
Article 4 continues to require providers and deployers to support the development of AI literacy among employees and other persons working with AI systems on their behalf[12]. Following the amendment by the Digital Omnibus, no specific or “sufficient” level of literacy is guaranteed. Measures should be based on prior knowledge, the context of use and the risks of the systems used[13].
Article 4 does not prescribe a specific training course or a guaranteed level of literacy for individuals. Depending on the system and context of use, appropriate measures may include internal rules, briefings, documented approvals, role descriptions or training. Independently of this, data protection, employment law, contractual obligations and general duties of care may give rise to further requirements. These must be assessed on a case-by-case basis[13].
Who enforces this? Market surveillance and sector-specific supervision
The Federal Network Agency (Bundesnetzagentur) is taking on central coordination and market surveillance tasks. Existing specialist authorities may also remain responsible for individual product areas and regulated sectors[7]. Businesses should therefore not only ask about general AI supervision, but also check whether data protection, product or sector-specific supervisory authorities are relevant to their area of use.
In practice, this means that from 2 August 2026 there are not only obligations, but also an authority to enforce them. The Bundesnetzagentur can request documents, inspect systems and require deficiencies to be remedied[19]. Legal expectations and operational implementation therefore overlap in time: anyone who only starts after the deadline will be working under supervision rather than ahead of it[20].
What does an infringement cost?
Penalties are governed by Article 99 of the EU AI Act. Infringements of the transparency obligations under Article 50 can be punished with fines of up to €15 million or 3 per cent of worldwide annual turnover, whichever is higher[16]. For prohibited AI practices, fines of up to €35 million or 7 per cent apply; for supplying incorrect information to authorities, up to €7.5 million or 1 per cent. Important for SMEs: for SMEs and start-ups, the lower of the two caps applies in each case, and penalties must be proportionate to the size of the business[16].
“Transparency does not begin with a sticker, but with clarifying the roles correctly: who provides the system, who deploys it and which output is used in what way?”
Why your own local AI systems simplify compliance
At this point, it is worth changing perspective. Many businesses experience the new obligations as a loss of control: they use generative AI through cloud services but know neither exactly how their outputs are marked nor where their inputs end up. The way out of this dilemma is not less AI, but more control over it, and this is exactly where your own local AI systems play to their strengths.
A local architecture can simplify data flows and technical control if the system is operated professionally and completely separated from the internet and external services[21]. That does not automatically make its use legally compliant. The legal basis, access protection, deletion policy, any data protection impact assessment and data subject rights still need to be assessed[23].
The same applies to the labelling obligations: anyone operating their own AI, whether a local language model, a self-hosted AI agent for internal processes or their own data pipeline, decides for themselves how outputs are marked, documented and reviewed. Instead of relying on a US provider's compliance commitments, you get a system that your own team understands and maintains. We describe in detail how to get started with your own infrastructure in our article on local IT infrastructure; what matters when choosing external support is explained in our guide to AI consulting for SMEs.
Checklist: implementation in seven steps
Take an AI inventory
Record all AI systems in use: chatbots, image and text generators, AI features in existing software. Without a complete list, there is no complete compliance.
Assign the categories
For each system, clarify: does it interact with people? Does it generate synthetic content? Could its outputs act as deepfakes? This determines the specific labelling obligation.
Check your providers
For cloud AI, ask for proof that machine-readable marking has been implemented in line with the Code of Practice. If there is no proof, that is a warning sign, including for data protection.
Add visible notices
A chatbot notice, labels on AI images and videos, disclosure for AI-generated texts without editorial review. Clear, understandable, at the first point of contact.
Document editorial responsibility
Where people review AI-generated texts and take responsibility for them, the disclosure obligation does not apply. Record this review process in writing; it is also the best quality assurance tool.
Promote AI literacy and document the measures
Article 4 requires appropriate measures to promote AI literacy. Which rules, briefings or training are appropriate depends on the system, prior knowledge and context of use.
Consider running your own system
For recurring AI tasks, calculate whether your own local system is the better solution: full control over labelling and data, no subscription costs, no dependence on third-party compliance commitments.
Frequently asked questions about AI labelling obligations
When do the AI labelling obligations apply?
From 2 August 2026. On that date, the transparency obligations under Article 50 of the EU AI Act become applicable, and market surveillance in Germany by the Federal Network Agency (Bundesnetzagentur) begins at the same time[3].
Do I have to label every AI-generated image?
Machine-readable marking is the responsibility of the AI provider. As a deployer, you must visibly disclose content that appears real and could deceive people, particularly deepfakes. Exceptions apply to purely artistic or evidently fictional content[1].
Does this also apply to internal AI use?
The labelling obligations under Article 50 target interaction with natural persons and published content. Purely internal analyses are generally not covered. However, Article 4 requires appropriate measures to promote AI literacy for internal use as well. Data protection requirements may also apply[12].
Does Article 4 apply even if we only use ChatGPT?
Article 4 covers providers and deployers of AI systems. Businesses whose employees use generative AI on the company's behalf should therefore define appropriate measures to promote AI literacy. The regulation prescribes neither a specific course nor a guaranteed level of literacy for individuals[13].
Is a notice in our terms and conditions enough?
No. The information must be clear, understandable and provided at the latest at the first interaction. A clause buried in the terms and conditions does not meet this requirement[4].
Conclusion
The AI labelling obligations are a transparency rule with a clear deadline: 2 August 2026. The European Commission has published current guidelines and a voluntary Code of Practice on the subject. Businesses should take an inventory of their AI systems, assign roles and categories, review visible and technical labelling and document appropriate AI literacy measures. Your own or local systems can create more technical control, but they are not automatically legally compliant.