Most of the EU AI Act’s transparency obligations began to apply on 2 August 2026, and they did so after a turbulent few months. The European Commission published its final Guidelines on Article 50 – explaining how providers and deployers should approach their respective obligations relating to AI interactions, deep fakes and other AI-generated or manipulated content – on 20 July 2026, less than a fortnight before the obligations took effect. The AI Office’s Code of Practice on Transparency of AI-Generated Content had been finalised only six weeks before that. The Digital Omnibus on AI then moved the goalposts again, giving providers of generative AI systems already on the market before 2 August 2026 until 2 December 2026 to meet the machine-readable marking requirement in Article 50(2).

Everything else in Article 50 applies now and, unlike much of the AI Act, it applies well beyond high-risk AI systems. What the Guidelines don't do is answer the questions that matter most in practice… keep reading to find out more.

A quick reminder of the rules

Article 50 of the EU AI Act broadly sets the following requirements:

  • Providers of AI systems designed to interact directly with people must ensure that people are informed that they are interacting with AI, unless this is obvious from the circumstances.
  • Providers of AI systems that generate synthetic audio, image, video or text content must ensure that their outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. This obligation is subject to technical feasibility and does not apply where the system merely performs an assistive function for standard editing or does not substantially alter the input or its meaning. Providers of systems already on the market before 2 August 2026 have until 2 December 2026 to comply.
  • Deployers of emotion recognition and biometric categorisation systems must inform the people exposed to those systems.
  • Deployers must disclose when image, audio or video content constitutes a deep fake.
  • Deployers must disclose when AI-generated or manipulated text is published for the purpose of informing the public about matters of public interest. This does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for its publication – although the Guidelines set the bar for “human review” at a deliberate examination of the substance of the content by a person with relevant knowledge and professional judgement, which is not the same as a quick once-over.
  • Where a disclosure is required, it must be clear and distinguishable, provided no later than the first interaction or exposure and comply with applicable accessibility requirements.

Providers have been preparing for these requirements for some time. Many deployers, sensibly, waited for the final Guidelines before settling on their approach, particularly given the breadth of the “deep fake” concept as it appeared in earlier drafts.

The stakes are reasonably high. Breach of Article 50 attracts fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher, with enforcement sitting with national market surveillance authorities in each Member State and with the AI Office for systems under its supervision. A missing or misleading AI disclosure could amount to a misleading omission under EU consumer protection and advertising law, particularly in advertising and influencer marketing, and the same content can engage the Digital Services Act, the GDPR and national likeness and criminal rules in parallel. In our experience, scrutiny of synthetic content currently comes mainly from consumer and data protection authorities, and a clearer delineation of responsibilities will be needed once market surveillance authorities begin enforcing Article 50.

Now that the dust has settled, the harder questions are surfacing, and most of them cannot be answered by reading Article 50. Set out below are the issues we are being asked about most often, together with those we think are still being missed.

The disclosure obligation may sit with the deployer, but providers will be expected to help

Article 50(4) places the obligation to disclose deep fakes (and certain AI-generated public-interest content) on the deployer of the relevant AI system. The Guidelines recognise that deployers often operate within complex content production and distribution chains, and confirm that deployers are expected to take proportionate steps to ensure that any required disclosure reaches the end user, including through contractual arrangements with distribution partners and appropriate user interface settings. The Commission has also confirmed that a deployer cannot discharge its Article 50(4) duty by pointing to the machine-readable marking embedded by the provider under Article 50(2). The disclosure must be perceivable by a person, without specialist tools or any dedicated step on their part.

This is fast becoming a standard issue in procurement and vendor due diligence. We are already seeing detailed questions about provenance tooling, disclosure functionality, auditability, metadata preservation and the contractual allocation of responsibility.

In practice, the legal duty is the deployer’s, but the commercial expectation is that the provider supplies the tools, the information and, increasingly, the indemnity that make compliance workable. Providers who can evidence all three are likely to find it an advantage on enterprise deals.

AI agents and hybrid services need attention

Article 50(1) requires people to be informed when they are interacting directly with an AI system, unless this is obvious from the point of view of a reasonably well-informed, observant and circumspect person. The Guidelines take a relatively strict view of that exception, and the working assumption should be that general-purpose chatbots and help-desk assistants will not qualify. Nor does the fact that a human may review or contribute to an AI agent’s output remove the disclosure requirement by itself. Generic wording that AI “may” be used somewhere within a service is unlikely to be enough, as the disclosure must relate clearly to the interaction actually taking place.

The Guidelines further state that an AI agent should disclose that it is artificial and identify the person or organisation on whose behalf it is acting, and that it may need to identify itself again at key stages of the interaction. This creates a familiar tension between legal compliance and user experience. Sound familiar? See GDPR.

Businesses will need to comply without causing unnecessary repetition or frustration for their customers. The text of Article 50 does not make the extent of these expectations obvious, and much of the detail is found only in the Guidelines. Legal, product and design teams will therefore need to decide how to make disclosures clear enough without letting them dominate the interaction or erode the efficiencies the AI agent was introduced to deliver.

“Deep fake” is much broader than its everyday meaning

For many businesses, the most surprising aspect of the Commission’s approach is the breadth of its interpretation of “deep fake". There had been some hope across the tech industry that the concept would be narrowed from earlier drafts of the Guidelines, but it has not been. The regulatory concept is considerably wider than the way most businesses and consumers use the term.

In everyday usage, a deep fake tends to suggest impersonation, deception or malicious intent. The AI Act’s definition instead focuses on whether AI-generated or manipulated images, audio or video content resembles existing people, objects, places, entities or events and would falsely appear authentic or truthful to a person. There is no separate requirement for an intention to deceive or mislead.

The Guidelines indicate that AI-assisted background scenes, special effects and standard technical pre- and post-production processes will generally fall outside the definition, on the basis that the audience does not expect that material to be authentic in the first place. By contrast, fully AI-generated actors, synthetic voices, de-ageing, digital resurrection and simulated performances are more likely to fall within it. 

This is particularly important for synthetic voice providers and their enterprise customers, who may not instinctively associate their products with deep fakes at all, and for whom realistic synthetic voiceover may require disclosure even where it has been created with the full authority of the people involved and without any intention to deceive.

None of this means that the content is deceptive, harmful or unlawful. It means only that the professional deployer may need to disclose its artificial origin. Consent, rights clearance, identity verification and contractual controls all remain essential, but they have no bearing on whether content is a deep fake for Article 50 purposes. 

Synthetic voice businesses face this in a compressed form, because a single product can engage Article 50(1) where the voice is conversational, Article 50(2) in respect of marking the audio output and Article 50(4) where the voice resembles a real person – alongside the GDPR, both as to training data and as to any use of voice to identify a speaker.

The so-called artistic exemption

The AI Act recognises that an intrusive label may undermine the experience of a film, programme, game, advertisement or other creative work. Where a deep fake forms part of an evidently artistic, creative, satirical, fictional or analogous work or programme, an Article 50(4) disclosure can therefore be made in a manner that does not hamper the display or enjoyment of the work.

That does not mean Article 50 falls away, but instead means that there is some flexibility about how the disclosure is made. Depending on the circumstances, an ‘entry-point’ notice, accompanying information or end credits may be more appropriate than a label displayed throughout the work. Advertising is unlikely ever to qualify, and we would treat branded content, advertiser-funded programming and in-game commercial placements with caution before relying on this flexibility.

Know your audience

One of the more pragmatic aspects of the Guidelines concerns downstream distribution. When assessing whether content may appear authentic or truthful, and therefore constitute a deep fake, deployers should consider the audiences and distribution channels that are reasonably foreseeable. They are not expected to account for every hypothetical person who might encounter the content following unauthorised or unforeseeable redistribution.

For example, content intended for a controlled subscriber-only environment can generally be assessed by reference to the audience reasonably contemplated for that channel, rather than every person who might conceivably gain access to it. This should help businesses distributing synthetic content in restricted environments or to audiences with relatively high levels of AI awareness.

The position becomes more difficult where content is designed to be copied, shared or republished across multiple channels. In those circumstances, the range of reasonably foreseeable audiences will be much wider. This also has an important territorial dimension. A non-EU business publishing content for a global audience may find it difficult to argue that use in the EU was unforeseeable. By contrast, content reaching the EU through unauthorised channels outside the organisation’s control may be treated differently.

Businesses should document both their intended audience and the distribution channels through which they expect the content to travel.

The line between AI content and AI interaction is blurring

The Guidelines address AI interactions and AI-generated content as distinct categories. In practice, they are likely to overlap significantly. For example:

  • A voice-based AI agent may generate synthetic audio while interacting directly with a user.
  • A customer service tool may move between automated responses and human intervention.
  • An AI assistant may act on behalf of a business while generating content that is then shared with third parties.

In these scenarios, Article 50(1) may require disclosure of the AI interaction, while Article 50(4) may also require disclosure that the resulting content is a deep fake. The Guidelines do not fully explain how these obligations should work together, including whether one disclosure can satisfy both requirements and how prominent or frequent the disclosure(s) should be.

This will matter most to businesses operating at the intersection of synthetic voice, conversational AI, publishing and AI agents, and further guidance may well be needed as those technologies converge.

To sign or not to sign the Code of Practice

The Code of Practice on Transparency of AI-Generated Content, finalised in June 2026, is voluntary. The Commission and the AI Board concluded in July 2026 that it adequately covers the obligations in Article 50(2), (4) and (5), making it the EU-wide recognised route to demonstrating compliance regardless of where a business is established or which authority supervises it. Around 190 organisations had signed by the end of July 2026, and the Commission publishes and updates the list. The Code has two sections – one for providers and one for deployers – which can be signed independently, and Section 1 is also open to providers of AI models and of marking and detection tooling who are not themselves caught by Article 50(2).

Many businesses remain hesitant, given the Code’s expectations around multilayered marking, testing and monitoring, documentation of robustness and limitations, contractual prohibitions on the removal of labels and the provision of detection tooling – several of which go well beyond what Article 50 says on its face. Against that is the ability to tell customers that you are a publicly listed signatory, which is already surfacing in enterprise procurement. Signing and then under-delivering is a worse position than not signing at all, so the decision should be taken by reference to all of the Code’s commitments and to what the business can realistically deliver against them.

What should businesses do now?

For organisations still working through implementation, immediate priorities should include:

  • Identifying user-facing AI systems and synthetic-content workflows.
  • Distinguishing provider obligations from deployer obligations, and determining which role the organisation takes for each use case.
  • Considering whether modifying, white-labelling or rebranding a third-party AI system could cause the organisation to become a provider in its own right.
  • Identifying realistic synthetic voices, people, performances, objects, places and events.
  • Determining whether relevant content is evidently artistic, creative, satirical, fictional or analogous, and documenting why any lighter-touch disclosure is appropriate.
  • Checking whether disclosures appear at the right point in the user journey.
  • Reviewing how disclosures will be maintained when content is distributed through third parties.
  • Assessing whether AI agents also generate content that may constitute a deep fake.
  • Reviewing contracts with AI providers, agencies and distribution partners.
  • Preserving machine-readable markings and provenance information supplied by providers.
  • Documenting intended audiences and reasonably foreseeable distribution channels.

The deadline has passed, but the practical interpretation of these rules and the market approach to compliance will continue to develop – through supervisory practice, through the Code of Practice and, in time, through the courts. Article 50 compliance cannot be left to legal teams alone – it will take coordination across product, engineering, design, marketing, content and commercial functions to implement the rules without spoiling the user experience.

For many, the hardest task will not be deciding whether a disclosure is required. It will be ensuring that the disclosure continues to reach the right people as AI-generated content moves through ever more complex products, platforms and distribution chains – and being able to show why each judgement call was made, should a regulator come knocking.