Article 50 does not follow from your risk classification
Most organisations came to the AI Act through Chapter III: is my system high-risk? Article 50 answers a different question, and it answers it independently. A perfectly ordinary system, outside Annex III, with no criticality at all, can trigger a transparency obligation simply because it talks to a person or because it produces text.
The regime rests on four triggers, which cumulate, and on two distinct duty-holders.
| Paragraph |
Trigger |
Who carries the obligation |
| Art. 50(1) |
System intended to interact directly with natural persons |
Provider |
| Art. 50(2) |
System generating synthetic content (text, image, audio, video) |
Provider |
| Art. 50(3) |
Emotion recognition or biometric categorisation |
Deployer |
| Art. 50(4) |
Deep fake, or text published to inform the public on matters of public interest |
Deployer |
One system can fall under three paragraphs at once. One organisation can be both provider and deployer, on the same tool. That is why establishing the role is the first step, not an administrative detail: without it, no obligation can be assigned to anyone.
Step 1: establish your role, then your exemptions
Three situations dominate in practice.
→ You develop or market the system under your own name. You are a provider: Articles 50(1) and 50(2) apply to you.
→ You use a system under your own authority. You are a deployer: Articles 50(3) and 50(4) apply to you.
→ You embed a third-party model in your product and ship it under your brand. You are very probably both.
An undetermined role is the real blocker. This is not a comfortable grey area: it is the impossibility of identifying anyone responsible, and the first finding a supervisory authority will make.
There is a single cross-cutting exemption, for systems authorised by law for the detection, prevention, investigation or prosecution of criminal offences. It requires an identified legal basis and documented safeguards for the individuals concerned. If it does not apply to you, document that: the absence of an exemption is itself a piece of your compliance file.
Step 2: the four questions that trigger everything
Art. 50(1), does your system talk to anyone?
The test is the system's intended purpose, not an occasional use. Chatbots, virtual assistants, voice assistants, avatars, automated callers, but also interaction through other modalities: image, gesture, sensors.
The "obviousness" exception exists, but it has to be demonstrated. Assuming that "everyone knows it's a bot" is not an analysis: keep the evidence establishing that users naturally identify an AI.
Art. 50(2), does your system produce content?
This is the most underestimated trigger, because the functions concerned do not present themselves as generative. An automatic summary, a rewording, a text completion, speech synthesis, a generated illustration: all of it produces synthetic content within the meaning of Article 50(2).
The standard editing assistance exception covers spellchecking, noise reduction, contrast enhancement and cropping. It covers neither the creation of new content nor a change of meaning. And relied on without a formal analysis, it will be set aside.
Art. 50(3), are you inferring emotions or sorting people?
Watch the dual regime here. Before you talk about transparency, check that the use does not amount to a practice prohibited by Article 5, notably emotion recognition in the workplace and in education. No transparency measure makes a prohibited practice lawful.
Worth noting: sentiment analysis carried out on text alone falls outside Article 50(3), for want of biometric data.
Art. 50(4), do you publish deep fakes or public-interest text?
Two distinct obligations sit in the same paragraph.
A deep fake is defined by its potential to deceive, irrespective of your intent. A synthetic voice, an avatar, a generative retouch on a photograph of a real event: the fact that the content came from an external agency does not release you.
The second obligation covers text published to inform the public: health, safety, environment, consumer matters, current affairs, public life. Do not conclude too quickly that you are not a media organisation. Corporate communication about a product recall, an environmental note, a public health prevention message all fall within that notion. The exception here is human editorial control, provided a person or organisation genuinely assumes editorial responsibility for the publication.
Step 3: the expected measures, and the ones that fall short
For Article 50(1). Explicit notice before the first exchange, a persistent indication during the session, a voice announcement at the start of automated calls, a clear signal when handing over to a human, and information that is accessible and in plain language. A mention in the terms of use does not discharge the obligation.
For Article 50(2). The marking must be machine-readable. Current state of the art: signed provenance metadata (C2PA / Content Credentials), an imperceptible digital watermark, a logged cryptographic fingerprint. Complete it with robustness tests against compression, cropping and format conversion, and ideally a verification tool for third parties. A user-facing visible notice is a useful complement, never a substitute.
For Article 50(3). Prior information to individuals, signage at the place of use, a GDPR legal basis identified against Article 9, a DPIA completed, and where relevant a fundamental rights impact assessment under Article 27. Article 50(3) sits alongside the GDPR, it does not replace it.
For Article 50(4). Disclosure embedded in the content or its carrier, preserved when reshared on third-party platforms, sign-off before publication, and a register of published content together with the disclosure evidence.
Step 4: transparency only counts if you can prove it
Article 50(5) sets the common terms: the information must be clear, readily identifiable, accessible, and given no later than the first interaction or exposure. Information that arrives late, is barely visible or is inaccessible is treated as information never given.
Article 50(6) confirms that these obligations sit on top of those in the AI Act, the GDPR and other applicable law.
Then comes the question that decides everything over time: will your compliance survive the next release? The patterns are familiar: a generative feature added without re-qualification, a marking switched off during a technical optimisation, a notice removed in an interface redesign. Six governance habits to put in place:
→ a register of transparency obligations per system, linked to its evidence;
→ a named owner, with a deputy;
→ transparency clauses in supplier contracts, with a right to audit;
→ an "Article 50" gate in the product lifecycle milestones;
→ monitoring of the European AI Office's guidelines and implementing acts;
→ training for product, marketing and communications teams, not only legal.
The five most common mistakes
- Treating Article 50 as an annex to high-risk. The regime is self-standing.
- Missing the quiet generative features. Summarising, rewording and speech synthesis trigger Article 50(2).
- Relying on an exception without writing it down. An undocumented exception is a lost exception.
- Confusing a visible notice with machine-readable marking. Article 50(2) requires the latter.
- Believing compliance is a state. Authorities assess compliance that is continuous and demonstrable.
From checklist to register
We have turned this qualification tree into a two-page checklist, to tick off system by system, with the measures expected for each obligation and a reading scale for your level of readiness.
To go further, the "AI transparency (Article 50)" qualification questionnaire is available in Dastra: guided qualification with conditional display, a readiness score, tasks generated automatically and attached to your action plan, and evidence centralised alongside the rest of your privacy and AI compliance.
[Download the Article 50 checklist →]
This content is provided for information and does not constitute legal advice.