EU AI Act Article 50 Is Live: What Agent Builders Must Disclose Now

EU AI Act Article 50 took effect August 2, 2026. What agent builders must disclose, how to mark AI content, who is in scope, and a practical checklist.

EU AI Act Article 50 transparency obligations in force August 2, 2026: AI disclosure and synthetic content marking
Three duties, one date: interaction disclosure, content marking, and deployer disclosures, applicable since August 2, 2026.

On August 2, 2026, EU AI Act Article 50 became applicable. If your software talks to people in the EU, generates content that reaches them, or publishes AI-drafted material, you now have disclosure and marking duties — enforceable ones, as Cooley’s client alert laid out the week it happened.

Here is the part the panicked summaries skip: Article 50 is a transparency rule, not a licensing regime. Nobody needs permission to ship a chatbot. Nobody is auditing your model weights. The obligation is honesty — tell people when they’re dealing with AI, and make AI-generated content identifiable. For most agent teams, full compliance is a sprint, not a program.

This is the builder’s guide: what Article 50 actually requires, who is in scope (your internal coding agent almost certainly is not the problem; your customer-facing bot is), the compliance patterns that hold up, what the law does not demand, and a checklist you can run this week. It reads the law the way engineers should — from the primary text and the official guidance around it, not from screenshots of screenshots. Regulation arriving here was always the likely next chapter of the agentic software wave; this is what chapter one says. One thing stated plainly, once: this article is not legal advice — for decisions with real stakes, talk to a lawyer who works on EU tech regulation.

What Article 50 of the EU AI Act actually requires

Article 50 of the EU AI Act sets transparency duties for AI systems that interact with people or generate content: providers must ensure users know they’re dealing with AI and that synthetic output carries machine-readable marks, while deployers must disclose deepfakes, certain AI-written text, and emotion-recognition use. It became applicable on August 2, 2026.

The article — full text in the AI Act Explorer, plain-language walkthrough on the same site’s transparency-rules page — breaks into four duties plus a delivery rule. In builder’s terms:

1. Tell people they’re talking to AI — Article 50(1), a provider duty. AI systems intended to interact directly with natural persons must be designed so those persons are informed they’re dealing with AI — unless that is already obvious to a person who is “reasonably well-informed, observant and circumspect,” given the circumstances and context of use. The obviousness carve-out is real and matters enormously for scoping, as we’ll see. There are narrow law-enforcement exceptions you almost certainly don’t have.

2. Mark synthetic content — Article 50(2), a provider duty. Systems that generate synthetic audio, image, video, or text — general-purpose models included — must ensure outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. The law tempers itself: technical solutions must be effective, interoperable, robust, and reliable “as far as this is technically feasible,” accounting for state of the art, cost, and the content type. Exceptions cover assistive functions and standard editing that doesn’t substantially alter the input — your grammar checker is fine.

3. Disclose emotion recognition and biometric categorisation — Article 50(3), a deployer duty. If you operate such systems, the people exposed to them must be informed. Most agent builders can read this line and move on; if it does describe your product, you have larger scoping questions than this article.

4. Label deepfakes and certain AI-written text — Article 50(4), a deployer duty. Deployers of systems generating or manipulating deepfake image, audio, or video content must disclose the content was artificially generated or manipulated. For text, the duty is narrower than the headlines suggest: it covers AI-generated text published with the purpose of informing the public on matters of public interest — and even then, it lifts where the content underwent human review and a natural or legal person holds editorial responsibility for it.

The delivery rule — Article 50(5). All of this information must be provided in a clear and distinguishable manner, at the latest at the first interaction or exposure, and in line with accessibility requirements. A paragraph buried in your terms of service fails every part of that sentence.

Duty Who owes it Triggered by What satisfies it
AI-interaction disclosure — 50(1) Provider A system that interacts directly with people Clear notice at first interaction, unless AI-ness is obvious in context
Synthetic-content marking — 50(2) Provider Generating audio, image, video, or text Machine-readable marks, as far as technically feasible
Emotion/biometric disclosure — 50(3) Deployer Operating emotion-recognition or biometric-categorisation systems Informing exposed persons
Deepfake and public-interest text disclosure — 50(4) Deployer Publishing deepfakes, or AI text informing the public — unless human editorial review Visible disclosure of AI generation

For interpretation questions beyond the text, the two official channels are the EU AI Act service desk’s FAQ and the Commission’s AI policy pages at digital-strategy.ec.europa.eu. Bookmark both; they’re where clarifications land first.

Who’s in scope: provider, deployer, and the EU nexus

Two roles carry the duties, and you can hold both at once. A provider develops an AI system (or has it developed) and places it on the market or puts it into service under its own name. A deployer uses an AI system under its authority in a professional context — personal, non-professional use is excluded. The distinction that surprises teams: wrap GPT-5.6 or Claude Fable 5 into a support bot you ship under your brand, and you are the provider of that AI system. The model vendor’s compliance doesn’t absorb yours.

Geographic reach is broad by design. The Act covers providers placing systems on the EU market regardless of where they’re established, and it covers providers and deployers in third countries where the output of the system is used in the EU. A US company with EU users should assume it’s in scope; “we have no EU entity” is not the exit it used to be.

Now the three scenarios every agent team actually asks about:

Your internal coding agent. Claude Code in your terminal, a fleet in an autonomous workspace, the tools from our best agentic AI tools roster: these interact with the operator who invoked them, and the obviousness carve-out plainly covers a developer who installed the tool and typed the prompt. On a plain reading, no disclosure banner is required for your own engineers using tools that announce themselves in every possible way. Write down that reasoning once, and move on.

Your customer-facing bot. Support chat, sales assistant, voice agent, onboarding concierge: squarely inside 50(1). Obviousness is judged from the user’s chair, in context — and a support widget that answers fluently at 3 a.m. is precisely the case the article was written for. Disclose at first interaction, clearly. One subtlety for agent builders: an agent that reaches out on your behalf — emailing vendors, negotiating in chat, operating the open web — is interacting with natural persons who never installed anything. On a plain reading, the disclosure duty follows the agent there too.

Your content pipeline. Agents drafting blog posts, marketing copy, images, video. Two layers apply. Marking under 50(2) binds the provider of the generating system — if the pipeline is your own system, that’s you; if you deploy a vendor’s tool, the machine-readable marking rides on them, but check what survives your pipeline, because a mark stripped in post-processing is a mess you own in practice. Disclosure under 50(4) is narrower than feared: ordinary marketing copy is not “informing the public on matters of public interest,” and text a human reviewed under someone’s editorial responsibility is carved out even when it is. Photorealistic image or video of real people doing things they didn’t do — disclose, full stop.

Decision tree: is your AI agent in scope of EU AI Act Article 50 — EU nexus, interaction, content generation, deployer duties The four questions that route you to a duty. More than one can apply to the same system.

Compliance patterns that hold up

The duties are clearer than most regulation ever gets, and the implementation patterns are already settling. Three areas cover nearly everyone.

Disclosure UX

The pattern that satisfies 50(1) and 50(5) together: a clear label at first interaction — “You’re chatting with an AI assistant” — plus a persistent affordance (a badge, a header line) so the fact stays visible in long sessions. Voice agents say it up front, before the small talk. Two anti-patterns to avoid: burying disclosure in terms of service (fails “clear and distinguishable at first interaction” on its face), and the disappearing toast that shows once for 800 milliseconds. Make the label accessible — it must survive screen readers — and when a human takes over the conversation, label that hand-off too. Users calibrate their trust on it, which is the entire point of the article.

Content marking

For images, audio, and video, the working stack is provenance metadata and watermarking — C2PA-style content credentials attached at generation, watermarks that survive re-encoding where the state of the art allows. Text is the honest hard case: durable text watermarking remains unsolved, which is exactly why 50(2) carries the “technically feasible” clause. The defensible pattern today is provenance at the publication layer plus records of generation, not claims of magic. The Commission has been developing guidelines and a code of practice on marking and labelling of AI-generated content; watch for them, because they will define what “state of the art” means in practice.

Whichever tools you use, audit the chain: if your CMS strips metadata or your CDN re-encodes images, you are quietly destroying the marks your generation layer applied. Verify end to end, once, and after every pipeline change.

Evidence and logging

Compliance you can’t demonstrate might as well not exist. Keep records of where and when disclosures appear (screenshots and config beat memories), your marking configuration per pipeline, and the human-review step you rely on for the editorial carve-out — named reviewer, dated approval. This is ordinary AgentOps discipline pointed at a legal requirement, and it overlaps almost entirely with the logging you should already run for agent security: the same trails answer “what did the agent do” whether the asker is your incident channel or a regulator.

Product note: Compliance is partly an evidence problem — when a question comes, you want to show what your agents did and when. Automater Lite consolidates sessions from 10+ AI CLIs into one local, full-text-searchable archive, with Vault redaction for scrubbing sensitive data before a transcript is shared. And it’s local-first: the record stays on your machine, which is exactly where audit material about your own systems belongs. Free on automater.ai.

What Article 50 does not require

Calm is a compliance strategy too. The panic-adjacent claims circulating since August 2, sorted:

  • No authorization, license, or filing. Article 50 is transparency, not permission. You do not register your chatbot with anyone before shipping it.
  • Not every AI feature. Systems that neither interact with people nor generate content — rankers, fraud scorers, routing models, spam filters — sit outside Article 50 entirely. Other parts of the Act have their own scopes; this article’s duties don’t touch them.
  • No AI popup on obviously-AI tools. The obviousness carve-out means your IDE’s agent, your terminal harness, and your internal dev tooling don’t need disclosure banners for the professionals driving them.
  • No watermarks in your git repo. The marking duty falls on providers of generating systems, and the text-disclosure duty covers public-interest publications — which a codebase is not. On a plain reading, nobody is watermarking commits.
  • No retroactive relabeling. The obligations bind systems and their output from applicability. Your 2024 blog archive did not become unlawful on August 2, 2026.
  • Not the high-risk regime. Chapter III — conformity assessments, quality management, registration — is a different part of the Act with its own scope: employment screening, credit scoring, critical infrastructure, and the rest of Annex III. A disclosure duty does not make your support bot “high-risk,” and the compliance programs are entirely different sizes.

If a claim you’ve heard isn’t in the duty table above, check it against the article text before budgeting for it. Most of the scary versions dissolve on contact with the primary source.

Enforcement outlook and the timeline beyond

Enforcement runs through national market surveillance authorities, and the ceiling is real: non-compliance with Article 50 can draw administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher. Member-state readiness is uneven — authorities are still staffing up, and guidance is still maturing.

The practical read for builders, without promising anything: transparency duties are the cheapest tier of the Act to comply with and the easiest to check from outside — a regulator, competitor, or journalist can test your bot’s disclosure in five minutes with a browser. That combination usually means early attention goes to visible, persistent, easily-documented failures. Being demonstrably diligent — labels shipped, marks configured, records kept — is both the compliance and the defense.

The calendar keeps moving after this. August 2, 2026 was the Act’s general-applicability milestone, Article 50 included. On August 2, 2027, high-risk obligations attach to AI systems that are safety components of regulated products (Annex I), and general-purpose models placed on the market before August 2025 must reach compliance. Parts of the high-risk timeline have been debated in Brussels through the simplification push around the digital omnibus — but Article 50 itself took effect on schedule and is in force as of this writing.

What to watch quarterly: the Commission’s guidelines and the code of practice on marking, the first enforcement actions, and the service desk FAQ, which is where interpretation questions get answered in public.

The EU AI Act Article 50 compliance checklist

The shareable version, suitable for pinning in your team channel:

EU AI Act Article 50 compliance checklist for agent builders, August 2026 Eight steps, one afternoon of honest work for most agent teams. Share freely.

  1. Inventory your systems. Everything you provide or deploy that talks to people, generates media or text, or infers emotion — including agents embedded inside products, not just the headline chatbot.
  2. Assign roles per system. Provider, deployer, or both. Shipping a wrapped model under your brand makes you a provider.
  3. Confirm the EU nexus. Users, customers, or system output in the EU — including output your agents send to third parties.
  4. Ship disclosure UX on every interactive system without a solid obviousness case: clear, at first interaction, accessible, persistent. Screenshot it for the record.
  5. Turn on marking for generated media — content credentials, watermarks, metadata — and verify the marks survive your pipeline end to end.
  6. Paper the carve-outs you rely on. The human editorial review behind unlabeled text, the obviousness reasoning behind undisclosed internal tools: written down, dated, findable.
  7. Keep the evidence. Logs of disclosures, marking configs, review records — retained somewhere you can search when asked.
  8. Set a review cadence. An owner, a quarterly check against new guidance and enforcement news, and a separate look at whether anything you build is drifting toward a high-risk category.

Most agent teams will read that list and realize they’re five items in already. That’s the accurate takeaway from August 2, 2026: the EU’s first enforceable word on AI agents is “say what you are” — and for builders who’ve been shipping honestly, the distance to compliant is short.

FAQ: EU AI Act Article 50

What is Article 50 of the EU AI Act?

Article 50 sets transparency obligations that became applicable on August 2, 2026: providers must ensure people know when they’re interacting with AI and that synthetic audio, image, video, and text is marked machine-readably, while deployers must disclose deepfakes, certain AI-written public-interest text, and emotion-recognition use.

Does the EU AI Act apply to companies outside the EU?

Yes, when there’s an EU nexus. The Act reaches providers placing AI systems on the EU market regardless of where they’re established, and providers and deployers in third countries when the system’s output is used in the EU. A US company with EU users should assume Article 50 applies to it.

Do internal AI tools need an “I am an AI” disclosure?

Generally no. Article 50(1) doesn’t require disclosure where AI interaction is obvious to a reasonably well-informed, observant person in context — a developer driving a coding agent they installed qualifies on any sensible reading. Document that reasoning, and spend the disclosure engineering on customer-facing systems instead.

Do I have to label all AI-generated content in the EU?

No. Machine-readable marking under Article 50(2) binds providers of generating systems, with exceptions for assistive editing. Deployer-side disclosure covers deepfakes and AI text published to inform the public on matters of public interest — and human editorial review with responsibility lifts the text duty. Ordinary human-edited marketing copy isn’t the target.

What are the penalties for violating Article 50?

Non-compliance with Article 50’s transparency obligations can draw administrative fines of up to €15 million or 3% of total worldwide annual turnover, whichever is higher, enforced by national market surveillance authorities. Early enforcement attention will most plausibly land on visible, persistent failures rather than good-faith edge cases.

Sources