Skip to content
EU AI ActArticle 50transparencychatbotsdeep fakespublic sector

Transparency Duties Under Article 50

Art. 50 disclosure duties for chatbots, emotion recognition, biometric categorisation, deep fakes and AI-generated public text, and how to evidence them.

Landfall ยท Published 5 September 2026

Most of the AI Act's weight sits on high-risk systems. Article 50 is different: it attaches to features, not to a risk classification, and it reaches the ordinary chatbot on a municipal website as easily as a scoring model in a benefits office. This article sets out the five duties in Art. 50, who owes each, the exceptions that matter, and the question a supervisory authority will actually ask: how do you evidence that the disclosure was made?

The numbering, first

The transparency article was Art. 52 in the Commission proposal and in most commentary written before 2024. In the final text of Regulation (EU) 2024/1689 it is Art. 50. Deep fake is defined in Art. 3(60). If a policy document in your organisation still cites Art. 52, update it; the content moved as well as the number.

The five duties

Art. 50(1), direct interaction. Providers must design systems intended to interact directly with natural persons so that those persons are informed they are interacting with an AI system, unless that is obvious to a reasonably well-informed, observant and circumspect person in the circumstances. A deployer that buys a chatbot inherits the practical job of not hiding that notice behind a persona.

Art. 50(2), machine-readable marking. Providers of systems that generate synthetic audio, image, video or text must mark the output in a machine-readable format so that it is detectable as artificially generated, as far as technically feasible. This is a provider duty; a deployer should ask its supplier how the marking works.

Art. 50(3), emotion recognition and biometric categorisation. Deployers of an emotion recognition or biometric categorisation system must inform the natural persons exposed to it of its operation, and must process the personal data in accordance with the GDPR and, where relevant, the law enforcement directive. Emotion inference in the workplace and in education is prohibited outright by Art. 5(1)(f), so Art. 50(3) governs what remains.

Art. 50(4), first subparagraph, deep fakes. Deployers of a system that generates or manipulates image, audio or video constituting a deep fake must disclose that the content has been artificially generated or manipulated. For evidently artistic, satirical or fictional work the duty is limited to disclosing the existence of the generated content in a way that does not hamper the work.

Art. 50(4), second subparagraph, public-interest text. Deployers of a system that generates or manipulates text published to inform the public on matters of public interest must disclose that the text was artificially generated or manipulated, unless it has undergone human review or editorial control and a natural or legal person holds editorial responsibility for it.

Art. 50(5) adds that the information must be provided in a clear and distinguishable manner at the latest at the time of the first interaction or exposure, and must meet accessibility requirements. Art. 50(6) confirms these duties are without prejudice to Chapter III. Law enforcement uses authorised by law are carved out in several paragraphs.

Where the exceptions actually bite

The "obvious" exception in Art. 50(1) is narrower than it looks. It asks what a reasonably observant person would understand in context, and a chat widget with a first name and an avatar does not make anything obvious. Saying "I am a virtual assistant" in the first message does.

The editorial-responsibility exception in Art. 50(4) is broad for public bodies, because most published text goes through a communications team. The condition is that a person actually reviews it and someone holds responsibility, not that a workflow exists on paper. Text pushed straight from a model to a website, such as auto-generated summaries of council decisions, does not qualify.

How to evidence disclosure

The duty is to inform. The evidence is that the person was informed, at the right time, in a form they could perceive. Four artefacts cover most cases:

  1. The notice itself, captured as a screenshot or a stored template with a version number, showing the wording and where it appears.
  2. A coverage record that maps every interaction channel or content type to its notice: web chat, telephone assistant, letters, images on social media, published summaries.
  3. A timing check showing the notice is shown before or at the first interaction or exposure, not in a privacy policy linked from the footer.
  4. For text, the editorial record: who reviewed the piece and who holds responsibility, so that the Art. 50(4) exception can be shown rather than asserted.

Where the same interaction also triggers GDPR Art. 13 or 14 information duties, one notice can serve both, if it is drafted to. Where a high-risk system is involved, Art. 26(11) adds a separate duty to inform people that they are subject to it; that notice is cumulative with Art. 50, not a substitute.

A worked example

The fictional municipality of Duinvoort deploys three things in one quarter: a chatbot for waste-collection questions, a tool that drafts the weekly "what the council decided" page, and a video explainer with a synthetic presenter.

The chatbot owes Art. 50(1). The team adds "You are chatting with an automated assistant. A colleague can take over on request" as the first message, and stores the template with its version. The drafting tool owes Art. 50(4), second subparagraph, unless the exception applies. The communications officer edits and signs off every page, so the municipality records that editorial responsibility and keeps the review log; no label is needed, but the log is the evidence. The video is a deep fake under Art. 3(60) in the sense that the presenter appears to be a real person. Art. 50(4), first subparagraph, applies, and the caption "This presenter is AI-generated" runs for the first five seconds and in the description. The coverage record lists all three with the artefact for each.

How Landfall helps

Landfall asks which Art. 50 features a system has, and the codebase scan proposes emotion recognition where it finds such code, as a suggestion a person confirms. Each selected feature attaches the matching Art. 50 duty, with its own work item and evidence checklist: the notice, the coverage record, the timing check and, for text, the editorial record. A system with no Annex III area but at least one feature is classified as carrying transparency duties, and the CI decision check warns, or fails in strict mode, while an Art. 50 mapping is unapproved.

Explore the underlying obligations

This article is grounded in the obligations Landfall maps from source legal text. Browse them yourself:

Questions this article answers

Is transparency Art. 50 or Art. 52?
Art. 50 in the final text of Regulation (EU) 2024/1689. Earlier drafts numbered it Art. 52, and many summaries still use that number. Cite Art. 50.
Do Art. 50 duties depend on the risk tier?
No. They attach to a feature: direct interaction with people, emotion recognition, biometric categorisation, deep fakes, or AI-generated public-interest text. A system with no Annex III area can owe several, and a high-risk system owes them in addition to Chapter III.
When does a chatbot need no disclosure?
Art. 50(1) waives the duty where it is obvious from the point of view of a reasonably well-informed, observant and circumspect person that they are interacting with an AI system. That is a narrow exception; a chat window on a public website with a human-sounding name is not obvious.
Does AI-drafted text on a government website need a label?
Art. 50(4), second subparagraph, requires disclosure for AI-generated or manipulated text published to inform the public on matters of public interest, unless the text has undergone human review or editorial control and a natural or legal person holds editorial responsibility. A reviewed and signed-off page normally falls in that exception.
From when does Art. 50 apply?
From 2 August 2026, under the general application date in Art. 113. The Digital Omnibus proposal may adjust related transitional rules, so check the adopted position.

Sources

For informational purposes only. This guide is summary-level, informational writing โ€” not legal advice, not a risk score, and not regulatory approval. It does not create an attorney-client relationship. Always consult qualified legal counsel for compliance decisions about your specific product.

What Landfall Is NOT

Critical Boundaries

Understanding these boundaries is essential before using this product. Misuse of this tool for purposes outside its scope may create legal, regulatory, or commercial risk for your organization.

NOT Legal Advice

This product does not provide legal advice and does not create an attorney-client relationship.

Interpretations are informational analysis, not legal counsel. Always consult qualified legal professionals for compliance decisions.

NOT a Risk Score

We do not quantify, calculate, or certify your compliance risk level.

No numerical risk rating, compliance percentage, or safety score. Risk assessment requires human judgment about your specific context.

NOT Runtime Enforcement

This is a planning and mapping tool, not a runtime enforcement system.

Does not integrate with your production systems. Does not block, filter, or enforce compliance in real-time. Implementation is your responsibility.

NOT Regulatory Approval

Using this tool does not mean you are compliant with any regulation.

No certification, seal of approval, or compliance guarantee. Regulators will evaluate your actual implementation, not your use of this tool.

NOT Authoritative Interpretation

Our interpretations are not binding and may differ from regulatory guidance.

Only regulators and courts provide authoritative interpretation. Our analysis reflects our reading of requirements, which may be incomplete or incorrect.

NOT a Safe Harbor

This tool does not shield you from enforcement actions or liability.

Documentation of your process is valuable, but does not constitute a legal defense. Compliance is ultimately your organization's responsibility.

NOT an AI Compliance Agent

AI features assist analysis but do not make compliance decisions for you.

AI-generated interpretations require human review and approval. Automated suggestions are starting points, not final answers.

NOT Complete Coverage

We do not cover all regulations, all obligations, or all jurisdictions.

Regulatory landscape is vast and evolving. Gaps in our coverage do not mean those requirements don't apply to you.

What This Tool IS:

  • A structured workflow for mapping regulatory requirements to implementation tasks
  • A documentation system for compliance decisions (audit trail)
  • A collaboration platform for compliance, legal, and engineering teams
  • An informational resource for understanding regulatory obligations