Does the EU AI Act apply to my business?

    Yes, if you develop, provide, or deploy AI systems (including chatbots, virtual assistants, or generative AI tools) that reach EU users, or if you use an AI system to deliver AI-enabled services to EU consumers or businesses. The same entity can be both a “provider” (an entity that builds and places an AI product on the market) and a “deployer” (an entity that uses an existing AI tool under its own authority in professional activities). The distinction matters because Article 50 allocates different obligations to each role.

    The four obligations

    Article 50 imposes four transparency obligations, split between providers and deployers. 

    1. Tell people they are talking to AI (Article 50(1)) 

      Providers of AI systems designed to interact directly with people must develop and design the AI system in such a way that users are informed they are interacting with AI. This covers chatbots, virtual assistants, automated phone systems, and AI agents. An exception applies where the AI nature is obvious to a reasonably well-informed, observant and circumspect person. On 8 May 2026, the European Commission published draft guidelines on the implementation of Article 50 (the Draft Guidelines), which indicate the “obvious AI” exception will not cover general-purpose chatbots or AI help-desk tools. 
    2. Mark AI-generated content so machines can read it (Article 50(2))

      Providers of generative AI systems (including large language models) that produce synthetic audio, images, video, or text must mark those outputs to show they have been generated or manipulated by an AI system. The providers of those systems must enable marking in a machine-readable format, so far as technically feasible. The marking must be effective, interoperable, robust, and reliable. Technical feasibility is assessed objectively. 

      The obligation does not apply where the AI performs only an assistive function for standard editing (such as grammar correction) or does not substantially alter the input data or its meaning. The Draft Guidelines construe this carve-out narrowly. For example, AI-generated summaries or translations of text, object removal from images, or colour and contrast adjustments do not qualify for the exemption. For generative AI systems already on the EU market before 2 August 2026, the AI Omnibus provisional agreement of May 2026 grants providers until 2 December 2026 to meet the machine-readable marking requirement.
    3. Disclose emotion recognition and biometric categorisation (Article 50(3))

      Deployers of AI systems that identify or infer emotions or that categorise individuals using their biometric data must inform every individual exposed to the system that it is in use. This covers, for example, systems that infer sentiment from facial expressions or voice tone, or that assign individuals to categories such as age, gender, or ethnicity. 
    4. Label deepfakes and AI-generated public interest text (Article 50(4))

      Deployers who produce deepfakes (which are AI-generated or manipulated content resembling existing persons, objects, places or events that would falsely appear authentic) must disclose the content has been artificially generated or manipulated. For deepfakes used in artistic, creative, satirical, fictional or analogous works, the obligation is limited to disclosure that does not hamper display or enjoyment of the work. 

      Deployers publishing AI-generated or AI-manipulated text to inform the public on matters of public interest must also disclose its AI origin. A carve-out applies where the text has been subject to genuine human editorial review, being substantive editorial oversight, not merely reading or approving the text, and a person or organisation assumes editorial responsibility for publication. The Draft Guidelines indicate that spell-checking or a superficial grammatical review before publication does not constitute genuine human review.

    In each case, disclosure must be clear, distinguishable, and provided at the latest at the time of first interaction or exposure. Disclosure buried in terms and conditions or footnotes does not comply. AI systems authorised by law to detect, prevent, investigate, or prosecute criminal offences are exempt from the transparency obligations described above.

    The Code of Practice: Your compliance benchmark

    On 10 June 2026, the European Commission (Commission) published its final Code of Practice on Transparency of AI-Generated Content (the Code). The Code does not create binding legal obligations beyond those in the AI Act itself. It explains how providers should mark AI-generated content, and how deployers should label deepfakes. The Code and the Draft Guidelines are complementary. The Draft Guidelines address the full scope of Article 50 and provide the Commission’s interpretive guidance on its scope and application, while the Code focuses specifically on the technical and organisational implementation of Articles 50(2) and 50(4).

    Signatories to the Code receive increased regulatory trust, and supervisory authorities will assess compliance against the Code’s standards. Non-signatories must independently demonstrate they meet Article 50, including through a gap analysis against the Code. So, in practice, the Code is the compliance benchmark for marking and labelling obligations.

    Share.

    Comments are closed.