EU AI Act transparency requirements in force now
Article 50 has applied since 2 August 2026, including duties for chatbots and synthetic content.
The EU AI Act's transparency obligations have been in force since 2 August 2026 (Article 50). For a UK organisation within the Act's scope, this is a present-tense issue. It should not be grouped with the Annex III and Annex I high-risk obligations deferred to December 2027 and August 2028 under Regulation (EU) 2026/1744.
Article 50 addresses four situations in the facts sheet: people interacting with an AI system, systems generating synthetic content, people exposed to emotion recognition or biometric categorisation, and deepfakes. The responsible party and the required form of transparency differ, so a general statement that an organisation uses AI will not answer every duty.
When must people be told they are talking to AI?
People must be informed when they interact with an AI system unless that fact is obvious from the context (Article 50). A customer-facing chatbot is the clearest ordinary example. The obligation concerns the interaction itself, so the notice needs to reach the person who is engaging with the system rather than sitting only in a general policy elsewhere.
As a practical response, a UK company with an in-scope chatbot can identify every place where a customer enters an AI-led conversation and make the nature of that interaction clear at the point of use. This is an operating approach to the duty to inform people, including its obvious-context exception (Article 50).
What must happen to synthetic content?
Providers of systems that generate synthetic audio, images, video or text must ensure that outputs are marked in a machine-readable form as artificially generated (Article 50). This is a provider duty directed at the output of the generating system. It is distinct from a visible statement written for a human reader.
An organisation operating an AI content pipeline should first establish whether it is acting as a provider or using a system supplied by someone else, because the Act defines provider and deployer as different roles and a company can hold more than one role (Article 3). It can then trace generated assets through the pipeline and check whether the machine-readable marking survives the steps through which the content is produced, stored and published. That process is practical governance advice, not an additional requirement stated in the Act.
What applies to emotion recognition and biometric categorisation?
Deployers of emotion recognition or biometric categorisation systems must inform the people exposed to them (Article 50). The duty belongs to the deployer, meaning the organisation using the system under its authority (Article 3). A supplier statement does not remove the need to consider what the deploying organisation tells the people affected by its own use.
There is a separate Article 5 issue to keep in view. Emotion inference in the workplace or education is a prohibited practice, subject to narrow medical or safety exceptions, and biometric categorisation used to infer sensitive attributes is also among the prohibited practices described in the facts sheet (Article 5). A transparency notice does not turn a prohibited practice into a permitted one, so the use case needs to be screened before the team designs the notice.
How must deepfakes be disclosed?
Deepfakes must be disclosed as artificially generated or manipulated (Article 50). This duty focuses on the nature of the material presented to people. It sits alongside, but is not the same as, the provider duty to apply machine-readable marking to synthetic outputs.
For a content team, a useful operating approach is to separate these questions in its publishing process: whether the source system applied a machine-readable mark, whether the material is a deepfake, and whether the audience-facing disclosure is present. Keeping those checks distinct makes it less likely that one technical or editorial action will be assumed to satisfy every Article 50 duty.
What should a UK company do first?
Start with scope. The Act applies to providers placing systems on the EU market or putting them into service there, deployers established or located in the EU, and cases where an AI system's output is used in the EU (Article 2). A UK-only organisation with no EU customers, users or outputs used in the EU is not bound by the Act today; the UK scope guide explains that boundary.
If the organisation is exposed, make an inventory of the relevant interactions and content flows, assign the provider or deployer role for each system, and connect each use to the correct Article 50 duty. That review can examine the interaction notice for a chatbot, machine-readable marking and deepfake disclosure for a synthetic-content pipeline, and both the notice duty and prohibited-practices screen for emotion or biometric systems (Articles 5 and 50).
The timetable matters because these actions belong in the current work queue. Our EU AI Act timeline separates Article 50 from the deferred high-risk dates, and the AI literacy guide covers the other broad organisational duty already in force.
Checked against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Last reviewed 11 August 2026.