Share This Article
The AI Act transparency obligations finally have their rulebook: on 20 July 2026, the European Commission published the final guidelines on the implementation of Article 50 of the AI Act. Thirteen days before 2 August 2026 when the relevant provisions of the EU AI Act become applicable.
The timing tells you everything about how this file has been managed in Brussels. But it also removes the last excuse for waiting.
After months of projects on this topic, my impression is that the AI Act transparency obligations under Article 50 are the ones destined to touch the highest number of companies — far more than currently realise it. This is not a rule for those who build high-risk AI systems. It is a rule for anyone who puts artificial intelligence in front of people, through a chatbot, an image, an audio file, a video or a published text.
The guidelines are non-binding, and only the Court of Justice can give an authoritative interpretation of the AI Act. In practice, though, they will be the primary reference used by market surveillance authorities across all 27 Member States when they assess Article 50 compliance. That makes them the closest thing to a rulebook that businesses will have on 2 August 2026.
Below are the ten questions I am asked most often, answered in the light of the new guidelines, the Code of Practice on Transparency of AI-Generated Content, the Digital Omnibus and the Italian implementing decrees under Law No. 132/2025.
What the Guidelines Add to the AI Act Transparency Obligations
Three documents now sit on the same table, and they do different jobs.
The guidelines define the scope: who is caught, what counts as an interaction, what counts as a deep fake, when an exception genuinely applies. The Code of Practice on Transparency of AI-Generated Content, published on 10 June 2026 and confirmed by the Commission and the AI Board as an adequate voluntary tool, provides the practical framework for marking and labelling. The EU set of icons gives deployers a ready-made visual label.
The Code is voluntary. The obligations are not. And that distinction is where most of the compliance strategy now sits, as I explain at question 9.
1. Which AI Systems Are Actually Caught — and Who Is About to Find Out
Article 50 builds four distinct obligations, and they are worth keeping separate because they fall on different actors:
- Systems interacting directly with people (Article 50(1)): chatbots, voice assistants, automated customer service. The provider must design the system so that users know they are talking to a machine.
- Generative AI systems (Article 50(2)): whoever produces synthetic text, images, audio or video must mark the outputs in a machine-readable format and ensure they are detectable as artificial.
- Emotion recognition and biometric categorisation (Article 50(3)): the deployer must inform the people exposed to the system.
- Deep fakes and text on matters of public interest (Article 50(4)): the deployer must disclose the artificial nature of the content.
The point I always flag is this: the addressees are not “AI producers”, but the far broader category of businesses using AI in their daily operations. The e-commerce with a support chatbot. The communication agency generating visuals and copy. The company publishing press releases or editorial content built with AI. The retailer testing customer analytics. These are organisations that often do not perceive themselves as “AI Act subjects” at all — and that are squarely within scope.
The guidelines also confirm something many had hoped to avoid. AI agents are covered, and they must disclose both their artificial nature and the person on whose behalf they are acting. Where a provider cannot determine in advance whether an agent will interact with a human, the agent must be designed to disclose itself in every situation where such interaction is reasonably likely.
In my experience, the most frequent surprise concerns SMEs that adopted off-the-shelf generative tools without asking what obligations followed, on the assumption that everyone is doing it, so it will be fine.
It will not be fine.
2. Provider or Deployer? The Qualification Is Not Carved in Stone
In the vast majority of cases, a company that integrates a third-party chatbot into its website is a deployer: it uses the system under its own authority, but did not build it.
Be careful, though, because the qualification can shift. If a business substantially modifies the system, places it on the market under its own name or trademark, or changes its intended purpose, it can slide into the provider position and inherit far heavier obligations. The guidelines are explicit on this point, and it happens more often than people think.
The split of duties works as follows:
- The provider must design the system so that the disclosure of its artificial nature is technically possible and effective (Article 50(1)), and must mark generative outputs (Article 50(2)).
- The deployer must ensure that the disclosure actually reaches the user in the concrete context of use, and carries the labelling obligation for deep fakes and public-interest texts (Article 50(4)).
Two clarifications in the guidelines deserve attention. First, “authority” over an AI system does not require technical control — it is about deciding whether and how the system is used. Second, individual employees acting under the instructions of a company are not separate deployers: the legal person is.
The correct reading is a chain. The supplier provides the technical capability; the company using it activates and displays it. If either link breaks, the obligation is not met — which is exactly why the contract with the supplier becomes decisive, as I cover at question 8.
3. What a Compliant AI Disclosure Looks Like — and What Is Not Enough
Here the guidelines are genuinely useful, above all in telling us what does not work. The following are expressly listed as insufficient when used alone:
- disclosures contained only in terms and conditions, URLs or documentation;
- machine-readable markings, such as metadata or watermarks, that the user cannot perceive at the point of interaction;
- unclear or ambiguous signals, such as a generic reference to an “assistant”, or human-like representations that may mislead;
- generalised statements such as “services on this website use AI”;
- purely technical descriptions such as “this system uses LLMs”, without explaining what that means for the user.
The Wording That Works
What is required instead is a notice that is clear, in plain language, and placed at the moment the user comes into contact with the system. In practice I suggest a direct formulation — along the lines of “You are interacting with a virtual assistant based on artificial intelligence” — visible before or at the start of the conversation, not hidden behind a click. The guidelines reward a combination of formats: a plain textual message accompanied, where useful, by persistent visual elements.
The guiding test I keep in mind is simple. A reasonable user, at the point of contact, must understand immediately and without effort that there is no person on the other side.
When the Interaction Is Genuinely “Obvious”
And the “obvious interaction” exception is narrower than most people assume. The guidelines state that it should be limited to cases where there is almost no doubt left about the nature of the interaction. Code assistants used only by professional developers, internal employee-facing tools for trained staff, or diagnostic support tools used only by health professionals can qualify. A customer-facing helpdesk chatbot on a public website does not.
One more practical point: in riskier contexts — AI companions, financial or health advice, complaints handling, or interactions with children and elderly users — a single notice at the start may not be enough. Periodic reminders are likely to be necessary.
4. What Counts as a Deep Fake, and Why Your Intentions Are Irrelevant
The Commission has adopted a deliberately broad interpretation, and this is a point on which I invite clients not to deceive themselves.
The definition captures AI-generated or manipulated image, audio or video content that appreciably resembles existing persons, objects, places, entities or events, and that would falsely appear to a person to be authentic or truthful. It does not require a real person to be depicted, and it does not require a sophisticated manipulation.
And here the answer is blunt: yes, the obligation applies even in the complete absence of any intention to deceive. The guidelines confirm that the assessment is objective. Transparency is not a function of your good faith.
That is the most widespread error I see: thinking “it is obviously fake, I am not trying to fool anyone” and concluding that no label is needed.
The Audience You Must Have in Mind
Two further points from the guidelines are worth internalising. Unlike the Article 50(1) test, the deep fake assessment is not based on a hypothetical average person: it must take into account the diverse composition of the reasonably foreseeable audience, including children, the elderly and people with lower digital literacy. Content that would mislead that part of the audience qualifies.
Conversely, content that defies the laws of nature — dragons, flying humans, elephants driving cars — falls outside the scope, because it has no potential to mislead.
Commercially, the most relevant example is advertising. An AI-generated image of a product that makes it appear more appealing, of better quality or different from the real thing is a deep fake. A real car photographed against an AI-generated background, where the ad does not mislead about the product itself, is not.
There is a lighter regime for content that is evidently artistic, creative, satirical or fictional: there, disclosure must simply be appropriate and must not hamper the enjoyment of the work. But a full exemption does not exist. And where content mixes an informative and a creative character, the guidelines say the informative character always prevails.
5. AI-Generated Text on Matters of Public Interest: Who Labels It, and How
The obligation falls on the deployer, meaning the party publishing or disseminating AI-generated or manipulated text on matters of public interest. Think of an AI-generated summary of an article on a newspaper website, AI-manipulated corporate reports containing investor information, or a weather warning published by a public institute.
There is, however, a significant exception: where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility, no label is required. Both conditions must be met.
The guidelines close several doors here that were left ajar in the draft:
- superficial or purely formal checks — spell-checking, grammar correction, the mere existence of an editorial policy, cursory sign-off — do not qualify;
- fact-checking the accuracy of the content is described as a minimum requirement of the review;
- if AI is used to modify or reformulate the content after editorial sign-off, the exception becomes void;
- the identity and contact details of the person or function holding editorial responsibility should be publicly available in an easily findable location.
On the “how”, the EU has now published a set of icons with three variants: a basic icon, a Fully AI-Generated icon, and a Partially AI-Modified icon. They are free to use, and user testing showed that performance improves when the icon is accompanied by a short text label. Their use is optional; the labelling obligation is not.
The operational advice I give to communication and marketing teams is to define an internal editorial policy now: when AI is used, who verifies, who takes responsibility, and when the label must be applied. A clear process beats case-by-case decisions every time.
6. Machine-Readable Marking and the 2 December 2026 Window
This extension comes from the Digital Omnibus package, and it needs to be read precisely, because it is narrower than it is often described.
The rule is that generative AI systems placed on the market or put into service before 2 August 2026 benefit from a transitional period and must comply with the Article 50(2) marking obligation by 2 December 2026. Systems placed on the market from 2 August 2026 onwards get no tolerance at all: they must mark their outputs from day one.
The decisive criterion is therefore the date of placing on the market or putting into service of each individual system. Which is precisely where this intertwines with mapping: without an inventory recording, system by system, when each was adopted, you cannot even establish which deadline applies to you.
Three warnings I repeat constantly:
- The extension covers only Article 50(2). Every other Article 50 obligation — chatbot disclosure, deep fake labelling, public-interest text labelling — applies from 2 August 2026.
- Systems that are partly interactive and partly generative benefit only in relation to the marking obligation. The interaction disclosure is due on 2 August.
- This is not permission to slow down. It is a handful of extra weeks to finish a technical implementation.
The Quality Requirements Behind the Marking
A caveat on timing. The amending regulation had been adopted by the EU legislature but was still awaiting publication in the Official Journal when the guidelines were issued, and it enters into force on the third day following publication. Until then, the December date operates as a planning horizon rather than as applicable law. I would build the plan around it, but not bet the compliance programme on it.
On the substance, the technical solutions must be effective, interoperable, robust and reliable, in line with the generally acknowledged state of the art. And the guidelines make an important point: technical feasibility is an objective notion, not dependent on the resources of the individual provider. You cannot argue that marking was unfeasible for you because your team is small.
There are limited carve-outs — genuinely industrial or business-to-business applications meeting three cumulative conditions, generative outputs confined within closed physical products, and real-time ephemeral content that is not stored or disseminated. They are narrow, and they are not a general escape route.
7. Emotion Recognition and Biometric Categorisation: Check the Prohibition First
Here I have to reverse the question, because this is where I see the most confusion.
Before transparency comes the prohibition. Emotion recognition in the workplace and in educational institutions is banned under Article 5 of the AI Act, save for narrow medical or safety exceptions. So in a recruitment scenario, the issue is not “how do I inform the candidate”: it is that, as a rule, that system cannot be used at all. That is a distinction to clarify with HR teams immediately, because the exposure is not an information gap but a prohibited practice, carrying the highest penalty tier in the entire Regulation.
Where use is permitted — certain retail applications, for instance — Article 50(3) applies and the deployer must inform the people exposed to the system’s operation. The guidelines confirm that this applies whether the system runs in real time or ex post, and that the information must reach everyone exposed, including children. Practical examples given include a pop-up before a game is launched, or a visible notice at each entrance to a room where visitors’ facial images are captured.
On top of that sits the entire GDPR framework, because we are talking about biometric data and potentially special categories: legal basis, impact assessment, minimisation.
One technical point that matters enormously in practice. Many tools marketed as “sentiment analysis” simply analyse keywords in a conversation to understand its tone, without any biometric processing that would trigger the prohibition. That distinction was at the heart of the Italian Data Protection Authority’s warning in the Myndoor case, which I analysed in this article on AI sentiment analysis in the workplace. Before reasoning about the notice, verify how the technology actually works — and whether it is lawful at all.
8. The Five Mistakes I See Most — and the Clauses to Renegotiate Now
The recurring errors, in my experience, are five:
- burying the disclosure in the terms and conditions or the privacy policy, instead of placing it at the point of contact;
- relying on the technical watermark alone, forgetting the notice the user can actually see;
- using generic or euphemistic wording — “assistant”, “smart service” — that never declares the artificial nature;
- failing to map the systems, and therefore not knowing which obligations genuinely apply;
- treating compliance as a one-off project, with no ongoing ownership.
On the contractual side, I invite clients to renegotiate — or at least review — the following with their AI suppliers now:
- a clear allocation of the provider/deployer roles and of the related responsibilities;
- warranties that outputs are marked and detectable as artificial in line with Article 50(2);
- a commitment to make the disclosure functionalities and the necessary technical documentation available;
- indemnities for non-compliance attributable to the supplier;
- an obligation to cooperate in the event of an authority inspection;
- the flow-down of the obligations along the supply chain.
These clauses are frequently missing altogether from vendors’ standard terms. That is not a drafting oversight you want to discover during an inspection.
9. Who Enforces, With What Powers, and What the Fines Look Like
In Italy, the picture was settled by the implementing decrees under Law No. 132/2025, which I covered in detail in this article on Italy’s AI Act implementation. The pivot of operational supervision — including inspections and sanctions — is ACN, the National Cybersecurity Agency, while AgID is the notifying authority. The competences of sectoral regulators (Banca d’Italia, CONSOB, IVASS) and of the Garante remain intact within their respective areas.
On concrete powers, Article 50 plugs into the European market surveillance system. In practice that means requests for documentation and information, on-site inspections, the power to order corrective measures and, in the most serious cases, the power to require withdrawal or recall of a non-compliant system.
Penalties reach EUR 15 million or 3% of total worldwide annual turnover, whichever is higher. For SMEs and start-ups, the lower of the two applies. There is no exemption based on size: an individual professional or a micro-enterprise publishing AI-generated content without the required disclosures is fully within the perimeter.
The Italian decree adopts a graduated and proportionate approach, calibrating penalties to the degree of responsibility along the supply chain. That is a proportionality criterion, not a safe conduct.
Signing the Code, or Proving It Yourself
And here is the point I consider most strategically relevant in the guidelines. Signatories of the Code of Practice will see supervisory activity focused on whether they have implemented the measures it contains. Non-signatories are expected to demonstrate compliance by other adequate means, to explain how their measures achieve compliance, and — in the Commission’s own words — to carry out a gap analysis comparing what they have implemented against the Code. They should also expect a larger number of requests for information and requests for access.
In other words, not signing is a legitimate choice. It is also a choice to demonstrate compliance with the AI Act transparency obligations the hard way, carrying a heavier evidentiary burden. The deadline to be included in the first published list of signatories fell on 22 July 2026, although joining later remains possible.
One final observation from enforcement practice: as we have seen repeatedly in the Garante’s decisions, adopting corrective measures after the fact is generally not considered sufficient to avoid a sanction. Prepare the documentation before the inspection, not after.
10. The Three Priorities to Complete Before 2 August 2026
If a company had to fix three absolute priorities today, these would be mine, in order of urgency.
First, map the AI systems in use — including those hidden inside third-party software — and classify them by role and by Article 50 category. Without this, everything else is blind. The mapping exercise is less technical and more investigative than people expect: start from the business functions rather than from IT, because marketing, communication, HR, customer care and sales are the ones who introduced generative tools autonomously. Then go through procurement and software licences, and ask suppliers explicitly whether their product embeds AI components, whether it generates content, and whether it interacts with users. Record, for each system, the date of placing on the market or putting into service.
Second, implement the disclosures that bite on 2 August: the AI interaction notice in chatbots (Article 50(1)) and the labelling of deep fakes and public-interest texts (Article 50(4)). These are the obligations that arrive without any transitional period, and they are also the most externally visible.
Governance: Deciding Who Does What
Third, review supplier contracts and set up internal governance. Compliance with the AI Act transparency obligations is not a matter for a single function. Legal and the DPO interpret the obligations and handle the contractual review and the GDPR overlap; IT and the CISO implement the disclosures, the marking and the logs; compliance builds the register and the monitoring; the business owners in each function are responsible for the actual display of the notices; procurement guards the supplier clauses; and senior management provides the mandate, without which governance stays on paper. A small AI governance committee with a responsibility matrix — who does what, for each system — is the model I recommend.
Machine-readable marking under Article 50(2), which can rely on the window to 2 December 2026 for systems already in use, comes immediately after. Important, but with a few extra weeks of breathing room.
Accountability Is the Real Test
The principle I keep repeating to clients is accountability. It is not enough to be compliant; you must be able to prove it, quickly.
In concrete terms, I suggest building a compliance file for each system, containing:
| Item | What it should include |
|---|---|
| AI systems register | Role (provider/deployer), applicable Article 50 category, supplier, date of placing on the market or putting into service |
| Transparency evidence | Screenshots of notices, disclosure wording, label configurations |
| Technical documentation | Marking and detection solutions, supplier documentation |
| Logs | Operating logs where required |
| Internal assessments | FRIA where mandatory, DPIA under the GDPR where relevant, system classification analyses |
| Contracts | Supplier agreements and evidence of the allocation of obligations |
That file is the difference between answering an authority’s request in a day or in a matter of weeks.
Frequently Asked Questions
Do the AI Act transparency obligations apply to small businesses and individual professionals?
Yes. There is no exemption based on size. A professional or a micro-enterprise publishing AI-generated content without the required disclosures is fully within scope. For SMEs and start-ups, the penalty is calculated on the lower of the fixed ceiling and the turnover percentage, but that is a proportionality mechanism, not an exemption.
Do I have to label content generated before 2 August 2026?
No. Content generated or manipulated before that date does not need to be marked or labelled retroactively. However, texts on matters of public interest that were generated before 2 August but are published on or after that date do need to be labelled. Deployers holding pre-existing unlabelled deep fakes are encouraged to label them, without being expected to undertake disproportionate efforts such as auditing entire content databases.
Are public bodies covered by Article 50?
Yes, and almost always as deployers. A municipality with a chatbot on its portal, a health authority using AI support tools, a school using AI-based educational solutions all need to map their systems, ensure the disclosures, run the FRIA where required, guarantee genuine human oversight, and invest in AI literacy for their staff. Law No. 132/2025 is explicit on the anthropocentric principle: the final decision must remain with a natural person.
Does participating in a regulatory sandbox protect me?
Partially. Participants acting in good faith and respecting the agreed plan are shielded from administrative fines for infringements committed within the perimeter of the experimentation. They are not shielded from civil liability towards third parties for damage caused by the tested system. The Digital Omnibus, meanwhile, moved to 2 August 2027 the deadline for Member States to establish at least one operational national sandbox.
Is the Code of Practice on Transparency of AI-Generated Content mandatory?
No. Adherence is voluntary. The Article 50 obligations are not. Signing gives you a predictable, EU-wide recognised route to demonstrating compliance; not signing means demonstrating adequacy through other means, and expecting more detailed scrutiny from market surveillance authorities.
Do Not Let 2 August Find You Unprepared
The AI Act transparency obligations are, in my view, the provisions with the widest practical reach and the lowest level of awareness among the businesses they will actually hit. The Commission’s guidelines have removed most of the ambiguity that companies were relying on to postpone decisions. What remains is execution.
If you want to assess where your organisation stands, map the AI systems you are actually running, review your supplier contracts or set up the governance to hold it all together, feel free to reach out to me at giulio.coraggio@dlapiper.com or to connect with me on LinkedIn. At DLA Piper we support clients across the full AI Act compliance journey, from mapping and gap analysis to contractual remediation and interaction with the authorities.
On a similar topic, you can read the article “EU Reaches Deal on AI Act Changes: What the New Compromise Really Means” and, for the basics, “Is Your Software an Artificial Intelligence System Under the EU AI Act?“.
For more updates on the EU AI Act, AI governance and technology regulation, visit the AI section of GamingTechLaw.com and listen to the “Diritto al Digitale” podcast.

