Real or Rendered? Article 50 of the EU AI Act, Explained for Business
Since 2 August 2026, EU law requires AI chat and voice tools to say they are AI, generative tools to mark their outputs so software can detect them, and businesses to label deepfakes and some AI-written public-interest text. What Article 50 asks, who it applies to, what changed in July, and the one later deadline: 2 December 2026.
By Charl Dominic Coetzee, Founder, OCHOS.AI
Why this matters now
Article 50 of the EU AI Act (Regulation (EU) 2024/1689) has applied since 2 August 2026 (Art. 113). It is directly applicable in every Member State, Spain included, so the duties do not wait for national law, although fines are set by each Member State within the EU maximums (Art. 99(1)).
It reaches almost every business that uses AI in front of customers: the website chat, the voice assistant, the AI product video, the virtually furnished rental photographs, the AI-written blog update.
One later date matters. Providers of generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to mark their outputs (Art. 111(4), inserted by Regulation (EU) 2026/1744). That transition covers marking only. It does not delay the duty to tell people they are talking to AI.
The four duties in plain English
1. Tell people they are talking to AI (Art. 50(1)). Providers of AI systems intended to interact directly with people must design them so that people are informed they are dealing with AI, unless that is obvious to a reasonably well-informed, observant and circumspect person in context. Think website chat assistants, voice assistants and AI avatars. The Commission reads the "obvious" exception narrowly, and vulnerable groups need extra care (Rec. 132).
2. Mark AI-generated content so software can detect it (Art. 50(2)). Providers of systems that generate synthetic audio, images, video or text, including general-purpose AI systems, must mark outputs in a machine-readable format so they are detectable as artificially generated or manipulated. The solutions must be effective, interoperable, robust and reliable as far as technically feasible.
3. Disclose emotion recognition and biometric categorisation (Art. 50(3)). Deployers of a system that infers emotions or intentions from biometric data (Art. 3(39)), or sorts people into categories such as age group from biometric data (Art. 3(40)), must inform the people exposed and comply with the GDPR. Categorisation that is only ancillary to another commercial service and strictly necessary for objective technical reasons does not count (Art. 3(40)). First check the use is not banned: emotion recognition at work or in education is prohibited, except for medical or safety reasons (Art. 5(1)(f)), and so is categorisation inferring traits such as race, religion or sexual orientation, other than labelling or filtering lawfully acquired biometric datasets or categorising biometric data in law enforcement (Art. 5(1)(g)). Emotion recognition systems that are allowed are also high-risk under Annex III, with further duties once the high-risk rules apply.
4. Label deepfakes and certain AI-written text (Art. 50(4)). A deepfake is AI-generated or manipulated image, audio or video that resembles existing (or plausibly real) people, objects, places, entities or events and would falsely appear authentic or truthful (Art. 3(60)). Deployers must disclose that it is artificial. For evidently artistic, creative, satirical, fictional or analogous works, the deployer must still disclose the AI content, but in an appropriate way that does not hamper the display or enjoyment of the work. Deployers who publish AI-generated or manipulated text to inform the public on matters of public interest must also disclose it, unless it has undergone human review or editorial control and a natural or legal person holds editorial responsibility.
Provider or deployer?
The provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark, paid or free (Art. 3(3)). The deployer uses an AI system under its authority, other than for personal non-professional activity (Art. 3(4)). Duties 1 and 2 fall on providers, duties 3 and 4 on deployers. One business can be both.
- A Madrid software company selling a customer-service chat assistant under its own brand is a provider.
- A Formentera hotel that has a booking assistant built for it and runs it under the hotel's name is likely to be its provider, even if an outside developer wrote the code.
- A shop using an off-the-shelf chat widget as supplied is a deployer, unless it modifies or rebrands the widget as its own, which can make it the provider. While it stays a deployer, the disclosure duty sits with the widget's provider, but the shop should check the notice shows.
- A property agency that uses AI to furnish photographs of an empty flat is a deployer, and the result may be a deepfake needing a label. The Commission uses this very example.
The Act also reaches providers and deployers outside the EU when the output is used in the EU (Art. 2(1)(c)). An open-source licence gives no exemption from Article 50 (Art. 2(12)).
What falls outside
- Purely personal, non-professional use (Art. 2(10)). An influencer earning regularly from content acts professionally.
- Assistive standard editing, and outputs that do not substantially alter the input or its meaning, for the providers' marking duty only (Art. 50(2)). Grammar correction, AI translation and minor cropping count as standard editing; summaries, rewrites that change meaning or style, face swaps and voice cloning need marking. A deployer publishing AI-translated public-interest text still needs a label unless a person has reviewed it.
- Text not published to inform the public on a public-interest matter, such as ordinary product descriptions (without health, safety or sustainability claims) or private client advice.
- Systems authorised by law to detect, prevent, investigate or prosecute criminal offences (Art. 50(1), (2) and (4)), or permitted by law to detect, prevent or investigate them for emotion recognition and biometric categorisation (Art. 50(3)). The chat exception does not cover tools the public uses to report a crime.
- Content created before 2 August 2026, which needs no retroactive label, although AI text created earlier but published later does (Commission guidelines).
How and when to tell people
Article 50(5) sets three tests: the information must be clear and distinguishable, given at the latest at the first interaction or exposure, and meet the applicable accessibility rules. The Commission's guidelines add detail:
- A notice buried in terms and conditions, a vague "assistant" label, or "Services on this website use AI" is not enough.
- For a chat, one prominent notice at the start usually suffices. In riskier settings such as financial, health or legal assistance, periodic reminders are likely needed, and the system must say it is AI when asked.
- For deepfakes and public-interest text, the label must be visible or audible. An invisible watermark alone does not meet the deployer's duty.
Penalties and who enforces
The EU maximum for breaching Article 50 is EUR 15 million or 3% of worldwide annual turnover, whichever is higher (Art. 99(4)(g)). For SMEs and start-ups, and since 27 July 2026 for small mid-caps, the cap is whichever is lower (Art. 99(6) and (6a)). Authorities weigh gravity, cooperation and your safeguards (Art. 99(7)), and anyone with grounds may complain to the market surveillance authority (Art. 85).
Enforcement is mainly national. For Spain, the Commission lists the Agencia Española de Supervisión de Inteligencia Artificial (AESIA), based in A Coruña, as single point of contact, with the national designation still pending. The bill that would confirm it, the Proyecto de Ley Orgánica para el buen uso y la gobernanza de la inteligencia artificial, is still at the amendment stage in the Congreso (deadline extended several times since June). As drafted, it names AESIA as the authority for Article 50 systems and treats breaches as serious infringements, with fines of up to EUR 7.5 million or 1% of worldwide turnover, whichever is higher, below the EU maximum. It is a bill, not law, and how Article 50 breaches are fined in Spain until it passes is not yet settled.
What the Code and the guidelines add
The Code of Practice on Transparency of AI-generated Content (Art. 50(7)) was published on 10 June 2026. The Commission found it adequate on 8 July 2026 and the AI Board on 9 July. Signing is voluntary, but it gives a predictable way to show compliance with Art. 50(2), (4) and (5); non-signatories must prove equivalent measures and can expect more information requests. About 190 organisations had signed by the end of July, Iberdrola among them.
Section 1 (providers) expects at least two layers of marking for audio, images and video (digitally signed metadata and an imperceptible watermark), plus detection tools. Section 2 (deployers) sets a visible "AI" label (a free EU icon is available), placement rules so labels survive resharing, internal processes, staff awareness and, for text, a written review policy naming who holds editorial responsibility.
The Commission's guidelines on Article 50, published on 20 July 2026, are non-binding but give the clearest map of scope, with practical examples.
The Digital Omnibus on AI is adopted law, not a proposal: Regulation (EU) 2026/1744, published on 24 July 2026 and in force since 27 July. It moved the high-risk rules to 2 December 2027 and 2 August 2028 but left the Article 50 date untouched. For Article 50, it added the December marking transition, a rewritten Art. 50(7) and lower caps for small mid-caps. From 2 December 2026 it also bans AI systems designed for, or left without safeguards against, producing realistic intimate or sexual images, video or audio of an identifiable person without their explicit consent, and AI-generated child sexual abuse material (Art. 5(1)(ba), (bb) and (1a)).
A 10-point checklist for businesses in Spain and the EU
- 1List every AI tool that talks to people, creates content or reads faces, and its supplier.
- 2Decide, tool by tool, whether you are provider, deployer or both.
- 3Open every AI chat and voice line with a clear AI notice in your customers' language.
- 4If you build or sell generative tools, follow the Code's approach (signed metadata and a watermark) or document an equally effective one, and bring legacy systems into line by 2 December 2026.
- 5Ask vendors in writing how their outputs are marked and whether they signed the Code. Keep the answer.
- 6Label deepfakes visibly (or audibly, for audio) at first exposure, embedded so the label survives sharing.
- 7For public-interest text, label it or run a genuine review: a qualified person checks substance and facts, someone named takes editorial responsibility, and no AI edits follow sign-off.
- 8Before any emotion recognition or biometric categorisation, confirm it is not prohibited, check whether the high-risk rules will apply, then post a clear notice and complete your GDPR work.
- 9Put the rules in your AI policy, support AI literacy among the people who publish content (Art. 4), for example through training, and let the public report a missing label.
- 10Decide whether to sign Section 2 of the Code, and follow AESIA and the Spanish bill.
How OCHOS.AI helps
Our AI audits map your tools, your role under the Act and your gaps. Our AI policy frameworks set your labelling and review rules, and our training prepares the teams who apply them. The free Article 4 AI literacy check at ochos.ai is a quick first step. The OCHOS Hub, our CRM and operations platform for businesses in Spain and the EU, comes from the same team.
In a market flooded with synthetic content, saying what is real is no longer good manners. It is the law, and it is how trust is earned.
This article is general information, not legal advice.
Sources
- Regulation (EU) 2024/1689 (AI Act), Official Journal text
- AI Act, consolidated text of 27 July 2026
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- Commission guidelines on Article 50, C(2026) 5054, 20 July 2026
- Guidelines page
- Commission Q&A on Article 50
- Code of Practice on Transparency of AI-generated Content
- Code of Practice (PDF)
- Commission Opinion on the Code
- Code signatories
- EU icons for labelling AI-generated content
- Commission, enforcement and transparency rules from 2 August
- Market surveillance authorities under the AI Act
- Proyecto de Ley Orgánica para el buen uso y la gobernanza de la inteligencia artificial, BOCG A-97-1, 12 June 2026
- Congreso de los Diputados, status of bill 121/000096
- Real Decreto 729/2023, Statute of AESIA (BOE)