[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fZSjQT_eFHbaHWHeqSt6fbKBF3RTu6vMO_fg_CS5uuqI":3},{"tableOfContents":4,"markDownContent":5,"htmlContent":6,"metaTitle":7,"metaDescription":8,"wordCount":9,"readTime":10,"title":11,"nbDownloads":12,"excerpt":13,"lang":14,"url":15,"intro":16,"featured":17,"state":18,"author":19,"authorId":20,"datePublication":25,"dateCreation":26,"dateUpdate":27,"mainCategory":28,"categories":35,"metaDatas":38,"imageUrl":43,"imageThumbUrls":44,"id":52},false,"## Article 50 does not follow from your risk classification\n\n\nMost organisations came to the AI Act through Chapter III: is my system high-risk? Article 50 answers a different question, and it answers it independently. A perfectly ordinary system, outside Annex III, with no criticality at all, can trigger a transparency obligation simply because it talks to a person or because it produces text.\n\n\nThe regime rests on four triggers, which cumulate, and on two distinct duty-holders.\n\n\n| Paragraph | Trigger | Who carries the obligation |\n| --- | --- | --- |\n| Art. 50(1) | System intended to interact directly with natural persons | Provider |\n| Art. 50(2) | System generating synthetic content (text, image, audio, video) | Provider |\n| Art. 50(3) | Emotion recognition or biometric categorisation | Deployer |\n| Art. 50(4) | Deep fake, or text published to inform the public on matters of public interest | Deployer |\n\n\nOne system can fall under three paragraphs at once. One organisation can be both provider and deployer, on the same tool. That is why establishing the role is the first step, not an administrative detail: without it, no obligation can be assigned to anyone.\n\n\n## Step 1: establish your role, then your exemptions\n\n\nThree situations dominate in practice.\n\n\n→ **You develop or market the system under your own name.** You are a provider: Articles 50(1) and 50(2) apply to you.\n→ **You use a system under your own authority.** You are a deployer: Articles 50(3) and 50(4) apply to you.\n→ **You embed a third-party model in your product and ship it under your brand.** You are very probably both.\n\n\nAn undetermined role is the real blocker. This is not a comfortable grey area: it is the impossibility of identifying anyone responsible, and the first finding a supervisory authority will make.\n\n\nThere is a single cross-cutting exemption, for systems authorised by law for the detection, prevention, investigation or prosecution of criminal offences. It requires an identified legal basis and documented safeguards for the individuals concerned. If it does not apply to you, document that: the absence of an exemption is itself a piece of your compliance file.\n\n\n## Step 2: the four questions that trigger everything\n\n\n### Art. 50(1), does your system talk to anyone?\n\n\nThe test is the system's **intended purpose**, not an occasional use. Chatbots, virtual assistants, voice assistants, avatars, automated callers, but also interaction through other modalities: image, gesture, sensors.\n\n\nThe \"obviousness\" exception exists, but it has to be demonstrated. Assuming that \"everyone knows it's a bot\" is not an analysis: keep the evidence establishing that users naturally identify an AI.\n\n\n### Art. 50(2), does your system produce content?\n\n\nThis is the most underestimated trigger, because the functions concerned do not present themselves as generative. An automatic summary, a rewording, a text completion, speech synthesis, a generated illustration: all of it produces synthetic content within the meaning of Article 50(2).\n\n\nThe standard editing assistance exception covers spellchecking, noise reduction, contrast enhancement and cropping. It covers neither the creation of new content nor a change of meaning. And relied on without a formal analysis, it will be set aside.\n\n\n### Art. 50(3), are you inferring emotions or sorting people?\n\n\nWatch the dual regime here. Before you talk about transparency, check that the use does not amount to a practice **prohibited** by Article 5, notably emotion recognition in the workplace and in education. No transparency measure makes a prohibited practice lawful.\n\n\nWorth noting: sentiment analysis carried out on text alone falls outside Article 50(3), for want of biometric data.\n\n\n### Art. 50(4), do you publish deep fakes or public-interest text?\n\n\nTwo distinct obligations sit in the same paragraph.\n\n\nA deep fake is defined by its **potential to deceive**, irrespective of your intent. A synthetic voice, an avatar, a generative retouch on a photograph of a real event: the fact that the content came from an external agency does not release you.\n\n\nThe second obligation covers text published to inform the public: health, safety, environment, consumer matters, current affairs, public life. Do not conclude too quickly that you are not a media organisation. Corporate communication about a product recall, an environmental note, a public health prevention message all fall within that notion. The exception here is human editorial control, provided a person or organisation genuinely assumes editorial responsibility for the publication.\n\n\n## Step 3: the expected measures, and the ones that fall short\n\n\n**For Article 50(1).** Explicit notice before the first exchange, a persistent indication during the session, a voice announcement at the start of automated calls, a clear signal when handing over to a human, and information that is accessible and in plain language. A mention in the terms of use does not discharge the obligation.\n\n\n**For Article 50(2).** The marking must be **machine-readable**. Current state of the art: signed provenance metadata (C2PA / Content Credentials), an imperceptible digital watermark, a logged cryptographic fingerprint. Complete it with robustness tests against compression, cropping and format conversion, and ideally a verification tool for third parties. A user-facing visible notice is a useful complement, never a substitute.\n\n\n**For Article 50(3).** Prior information to individuals, signage at the place of use, a GDPR legal basis identified against Article 9, a DPIA completed, and where relevant a fundamental rights impact assessment under Article 27. Article 50(3) sits alongside the GDPR, it does not replace it.\n\n\n**For Article 50(4).** Disclosure embedded in the content or its carrier, preserved when reshared on third-party platforms, sign-off before publication, and a register of published content together with the disclosure evidence.\n\n\n## Step 4: transparency only counts if you can prove it\n\n\nArticle 50(5) sets the common terms: the information must be clear, readily identifiable, accessible, and given no later than the first interaction or exposure. Information that arrives late, is barely visible or is inaccessible is treated as information never given.\n\n\nArticle 50(6) confirms that these obligations sit on top of those in the AI Act, the GDPR and other applicable law.\n\n\nThen comes the question that decides everything over time: will your compliance survive the next release? The patterns are familiar: a generative feature added without re-qualification, a marking switched off during a technical optimisation, a notice removed in an interface redesign. Six governance habits to put in place:\n\n\n→ a register of transparency obligations per system, linked to its evidence;\n→ a named owner, with a deputy;\n→ transparency clauses in supplier contracts, with a right to audit;\n→ an \"Article 50\" gate in the product lifecycle milestones;\n→ monitoring of the European AI Office's guidelines and implementing acts;\n→ training for product, marketing and communications teams, not only legal.\n\n\n## The five most common mistakes\n\n\n1. **Treating Article 50 as an annex to high-risk.** The regime is self-standing.\n2. **Missing the quiet generative features.** Summarising, rewording and speech synthesis trigger Article 50(2).\n3. **Relying on an exception without writing it down.** An undocumented exception is a lost exception.\n4. **Confusing a visible notice with machine-readable marking.** Article 50(2) requires the latter.\n5. **Believing compliance is a state.** Authorities assess compliance that is continuous and demonstrable.\n\n\n## From checklist to register\n\n\nWe have turned this qualification tree into a **two-page checklist**, to tick off system by system, with the measures expected for each obligation and a reading scale for your level of readiness.\n\n\nTo go further, the \"AI transparency (Article 50)\" qualification questionnaire is available in Dastra: guided qualification with conditional display, a readiness score, tasks generated automatically and attached to your action plan, and evidence centralised alongside the rest of your privacy and AI compliance.\n\n\n**[Download the Article 50 checklist →]**\n\n\n*This content is provided for information and does not constitute legal advice.*","\u003Ch2 id=\"article-50-does-not-follow-from-your-risk-classification\">Article 50 does not follow from your risk classification\u003C/h2>\n\u003Cp>Most organisations came to the AI Act through Chapter III: is my system high-risk? Article 50 answers a different question, and it answers it independently. A perfectly ordinary system, outside Annex III, with no criticality at all, can trigger a transparency obligation simply because it talks to a person or because it produces text.\u003C/p>\n\u003Cp>The regime rests on four triggers, which cumulate, and on two distinct duty-holders.\u003C/p>\n\u003Ctable>\n\u003Cthead>\n\u003Ctr>\n\u003Cth>Paragraph\u003C/th>\n\u003Cth>Trigger\u003C/th>\n\u003Cth>Who carries the obligation\u003C/th>\n\u003C/tr>\n\u003C/thead>\n\u003Ctbody>\n\u003Ctr>\n\u003Ctd>Art. 50(1)\u003C/td>\n\u003Ctd>System intended to interact directly with natural persons\u003C/td>\n\u003Ctd>Provider\u003C/td>\n\u003C/tr>\n\u003Ctr>\n\u003Ctd>Art. 50(2)\u003C/td>\n\u003Ctd>System generating synthetic content (text, image, audio, video)\u003C/td>\n\u003Ctd>Provider\u003C/td>\n\u003C/tr>\n\u003Ctr>\n\u003Ctd>Art. 50(3)\u003C/td>\n\u003Ctd>Emotion recognition or biometric categorisation\u003C/td>\n\u003Ctd>Deployer\u003C/td>\n\u003C/tr>\n\u003Ctr>\n\u003Ctd>Art. 50(4)\u003C/td>\n\u003Ctd>Deep fake, or text published to inform the public on matters of public interest\u003C/td>\n\u003Ctd>Deployer\u003C/td>\n\u003C/tr>\n\u003C/tbody>\n\u003C/table>\n\u003Cp>One system can fall under three paragraphs at once. One organisation can be both provider and deployer, on the same tool. That is why establishing the role is the first step, not an administrative detail: without it, no obligation can be assigned to anyone.\u003C/p>\n\u003Ch2 id=\"step-1-establish-your-role-then-your-exemptions\">Step 1: establish your role, then your exemptions\u003C/h2>\n\u003Cp>Three situations dominate in practice.\u003C/p>\n\u003Cp>→ \u003Cstrong>You develop or market the system under your own name.\u003C/strong> You are a provider: Articles 50(1) and 50(2) apply to you.\n→ \u003Cstrong>You use a system under your own authority.\u003C/strong> You are a deployer: Articles 50(3) and 50(4) apply to you.\n→ \u003Cstrong>You embed a third-party model in your product and ship it under your brand.\u003C/strong> You are very probably both.\u003C/p>\n\u003Cp>An undetermined role is the real blocker. This is not a comfortable grey area: it is the impossibility of identifying anyone responsible, and the first finding a supervisory authority will make.\u003C/p>\n\u003Cp>There is a single cross-cutting exemption, for systems authorised by law for the detection, prevention, investigation or prosecution of criminal offences. It requires an identified legal basis and documented safeguards for the individuals concerned. If it does not apply to you, document that: the absence of an exemption is itself a piece of your compliance file.\u003C/p>\n\u003Ch2 id=\"step-2-the-four-questions-that-trigger-everything\">Step 2: the four questions that trigger everything\u003C/h2>\n\u003Ch3 id=\"art.501-does-your-system-talk-to-anyone\">Art. 50(1), does your system talk to anyone?\u003C/h3>\n\u003Cp>The test is the system's \u003Cstrong>intended purpose\u003C/strong>, not an occasional use. Chatbots, virtual assistants, voice assistants, avatars, automated callers, but also interaction through other modalities: image, gesture, sensors.\u003C/p>\n\u003Cp>The \"obviousness\" exception exists, but it has to be demonstrated. Assuming that \"everyone knows it's a bot\" is not an analysis: keep the evidence establishing that users naturally identify an AI.\u003C/p>\n\u003Ch3 id=\"art.502-does-your-system-produce-content\">Art. 50(2), does your system produce content?\u003C/h3>\n\u003Cp>This is the most underestimated trigger, because the functions concerned do not present themselves as generative. An automatic summary, a rewording, a text completion, speech synthesis, a generated illustration: all of it produces synthetic content within the meaning of Article 50(2).\u003C/p>\n\u003Cp>The standard editing assistance exception covers spellchecking, noise reduction, contrast enhancement and cropping. It covers neither the creation of new content nor a change of meaning. And relied on without a formal analysis, it will be set aside.\u003C/p>\n\u003Ch3 id=\"art.503-are-you-inferring-emotions-or-sorting-people\">Art. 50(3), are you inferring emotions or sorting people?\u003C/h3>\n\u003Cp>Watch the dual regime here. Before you talk about transparency, check that the use does not amount to a practice \u003Cstrong>prohibited\u003C/strong> by Article 5, notably emotion recognition in the workplace and in education. No transparency measure makes a prohibited practice lawful.\u003C/p>\n\u003Cp>Worth noting: sentiment analysis carried out on text alone falls outside Article 50(3), for want of biometric data.\u003C/p>\n\u003Ch3 id=\"art.504-do-you-publish-deep-fakes-or-public-interest-text\">Art. 50(4), do you publish deep fakes or public-interest text?\u003C/h3>\n\u003Cp>Two distinct obligations sit in the same paragraph.\u003C/p>\n\u003Cp>A deep fake is defined by its \u003Cstrong>potential to deceive\u003C/strong>, irrespective of your intent. A synthetic voice, an avatar, a generative retouch on a photograph of a real event: the fact that the content came from an external agency does not release you.\u003C/p>\n\u003Cp>The second obligation covers text published to inform the public: health, safety, environment, consumer matters, current affairs, public life. Do not conclude too quickly that you are not a media organisation. Corporate communication about a product recall, an environmental note, a public health prevention message all fall within that notion. The exception here is human editorial control, provided a person or organisation genuinely assumes editorial responsibility for the publication.\u003C/p>\n\u003Ch2 id=\"step-3-the-expected-measures-and-the-ones-that-fall-short\">Step 3: the expected measures, and the ones that fall short\u003C/h2>\n\u003Cp>\u003Cstrong>For Article 50(1).\u003C/strong> Explicit notice before the first exchange, a persistent indication during the session, a voice announcement at the start of automated calls, a clear signal when handing over to a human, and information that is accessible and in plain language. A mention in the terms of use does not discharge the obligation.\u003C/p>\n\u003Cp>\u003Cstrong>For Article 50(2).\u003C/strong> The marking must be \u003Cstrong>machine-readable\u003C/strong>. Current state of the art: signed provenance metadata (C2PA / Content Credentials), an imperceptible digital watermark, a logged cryptographic fingerprint. Complete it with robustness tests against compression, cropping and format conversion, and ideally a verification tool for third parties. A user-facing visible notice is a useful complement, never a substitute.\u003C/p>\n\u003Cp>\u003Cstrong>For Article 50(3).\u003C/strong> Prior information to individuals, signage at the place of use, a GDPR legal basis identified against Article 9, a DPIA completed, and where relevant a fundamental rights impact assessment under Article 27. Article 50(3) sits alongside the GDPR, it does not replace it.\u003C/p>\n\u003Cp>\u003Cstrong>For Article 50(4).\u003C/strong> Disclosure embedded in the content or its carrier, preserved when reshared on third-party platforms, sign-off before publication, and a register of published content together with the disclosure evidence.\u003C/p>\n\u003Ch2 id=\"step-4-transparency-only-counts-if-you-can-prove-it\">Step 4: transparency only counts if you can prove it\u003C/h2>\n\u003Cp>Article 50(5) sets the common terms: the information must be clear, readily identifiable, accessible, and given no later than the first interaction or exposure. Information that arrives late, is barely visible or is inaccessible is treated as information never given.\u003C/p>\n\u003Cp>Article 50(6) confirms that these obligations sit on top of those in the AI Act, the GDPR and other applicable law.\u003C/p>\n\u003Cp>Then comes the question that decides everything over time: will your compliance survive the next release? The patterns are familiar: a generative feature added without re-qualification, a marking switched off during a technical optimisation, a notice removed in an interface redesign. Six governance habits to put in place:\u003C/p>\n\u003Cp>→ a register of transparency obligations per system, linked to its evidence;\n→ a named owner, with a deputy;\n→ transparency clauses in supplier contracts, with a right to audit;\n→ an \"Article 50\" gate in the product lifecycle milestones;\n→ monitoring of the European AI Office's guidelines and implementing acts;\n→ training for product, marketing and communications teams, not only legal.\u003C/p>\n\u003Ch2 id=\"the-five-most-common-mistakes\">The five most common mistakes\u003C/h2>\n\u003Col>\n\u003Cli>\u003Cstrong>Treating Article 50 as an annex to high-risk.\u003C/strong> The regime is self-standing.\u003C/li>\n\u003Cli>\u003Cstrong>Missing the quiet generative features.\u003C/strong> Summarising, rewording and speech synthesis trigger Article 50(2).\u003C/li>\n\u003Cli>\u003Cstrong>Relying on an exception without writing it down.\u003C/strong> An undocumented exception is a lost exception.\u003C/li>\n\u003Cli>\u003Cstrong>Confusing a visible notice with machine-readable marking.\u003C/strong> Article 50(2) requires the latter.\u003C/li>\n\u003Cli>\u003Cstrong>Believing compliance is a state.\u003C/strong> Authorities assess compliance that is continuous and demonstrable.\u003C/li>\n\u003C/ol>\n\u003Ch2 id=\"from-checklist-to-register\">From checklist to register\u003C/h2>\n\u003Cp>We have turned this qualification tree into a \u003Cstrong>two-page checklist\u003C/strong>, to tick off system by system, with the measures expected for each obligation and a reading scale for your level of readiness.\u003C/p>\n\u003Cp>To go further, the \"AI transparency (Article 50)\" qualification questionnaire is available in Dastra: guided qualification with conditional display, a readiness score, tasks generated automatically and attached to your action plan, and evidence centralised alongside the rest of your privacy and AI compliance.\u003C/p>\n\u003Cp>\u003Cstrong>[Download the Article 50 checklist →]\u003C/strong>\u003C/p>\n\u003Cp>\u003Cem>This content is provided for information and does not constitute legal advice.\u003C/em>\u003C/p>\n","AI Act Article 50: are you caught? 2026 checklist","Chatbots, generated content, deep fakes, biometrics: work out which Article 50 AI Act transparency obligations apply to you, and download the checklist.",1265,7,"Checklist: are you caught by Article 50 of the AI Act?",0,"Since 2 August 2026, four transparency obligations have applied to AI systems that converse, generate, analyse or publish. Here is the qualification tree, in four questions, to work out which ones fall on you, plus a two-page checklist to download.","en","checklist-are-you-caught-by-article-50-of-the-ai-act","Article 50 of Regulation (EU) 2024/1689 has applied since 2 August 2026. It creates a self-standing transparency regime: it does not depend on high-risk classification, and it therefore catches systems that many organisations assumed were outside the scope of the AI Act. A support chatbot, an assistant that drafts replies, facial expression analysis, a synthetic voice in a campaign: four cumulative triggers, two different duty-holders depending on whether you are a provider or a deployer, and exceptions that must be documented before you rely on them. This article sets out the qualification method, the measures expected for each obligation, and the mistakes that are immediately visible in an inspection.",true,"Published",{"id":20,"displayName":21,"avatarUrl":22,"bio":23,"blogUrl":23,"color":23,"userId":20,"creationDate":24},38,"Paul-Emmanuel Bidault","https://static.dastra.eu/tenant-27/avatar/38/paul-emmanuel-bidault-150.jpg",null,"2019-12-03T19:09:28","2026-08-04T14:02:00","2026-08-04T14:02:04.2585465","2026-08-04T14:04:02.9233894",{"id":29,"name":30,"description":23,"url":31,"color":32,"parentId":23,"count":23,"imageUrl":23,"parent":23,"order":33,"translations":34},70,"Livre blanc","white-papers","#1795d3",3,[],[36],{"id":29,"name":30,"description":23,"url":31,"color":32,"parentId":23,"count":23,"imageUrl":23,"parent":23,"order":33,"translations":37},[],[39],{"typeMetaDataId":40,"value":41,"id":42},4,"https://static.dastra.eu/backofficefilescontainer/d7d53868-0d58-49e9-b495-6733827d73c9/AI Act are you concerned by article 50.pdf",117722,"https://static.dastra.eu/content/f617d6d1-1e9d-4476-bfd1-324e109bf2c4/visual-article-50-1600x900-en-original.png",[45,46,47,48,49,50,51],"https://static.dastra.eu/content/f617d6d1-1e9d-4476-bfd1-324e109bf2c4/visual-article-50-1600x900-en-1000.webp","https://static.dastra.eu/content/f617d6d1-1e9d-4476-bfd1-324e109bf2c4/visual-article-50-1600x900-en.webp","https://static.dastra.eu/content/f617d6d1-1e9d-4476-bfd1-324e109bf2c4/visual-article-50-1600x900-en-1500.webp","https://static.dastra.eu/content/f617d6d1-1e9d-4476-bfd1-324e109bf2c4/visual-article-50-1600x900-en-800.webp","https://static.dastra.eu/content/f617d6d1-1e9d-4476-bfd1-324e109bf2c4/visual-article-50-1600x900-en-600.webp","https://static.dastra.eu/content/f617d6d1-1e9d-4476-bfd1-324e109bf2c4/visual-article-50-1600x900-en-300.webp","https://static.dastra.eu/content/f617d6d1-1e9d-4476-bfd1-324e109bf2c4/visual-article-50-1600x900-en-100.webp",60252]