What are the limited-risk AI transparency obligations under the EU AI Act?
Updated 9 August 2026 for Regulation (EU) 2026/1744.
Article 50 sets four transparency duties: providers must disclose AI interaction (50(1)) and mark synthetic content (50(2)); deployers must disclose emotion recognition and biometric categorisation (50(3)) and label deep fakes and AI-written public-interest text (50(4)). All four have applied since 2 August 2026 — with one exception: providers of synthetic-content systems placed on the market before that date have until 2 December 2026 to comply with 50(2) (Article 111(4)).
Quick answer
- Four duties, split by role. Providers: 50(1) chatbot disclosure and 50(2) machine-readable content marking. Deployers: 50(3) emotion-recognition and biometric-categorisation notice and 50(4) deep-fake and public-interest-text disclosure.
- Live since 2 August 2026, and not moved by the amendment. Article 50 sits in Chapter IV, carved out nowhere in Article 113, third paragraph, so it took effect on the main application date under Article 113, second paragraph. Pre-2 August 2026 synthetic-content systems have until 2 December 2026 to meet 50(2) (new Article 111(4)).
- Not a safe harbour. Under Article 50(6) these duties do not affect Chapter III — a system can carry Article 50 duties and be high-risk.
- Timing is fixed. Article 50(5): clear and distinguishable disclosure, at the latest at the first interaction or exposure.
- The penalty: up to €15 million or 3% of total worldwide annual turnover, whichever is higher (Article 99(4), point (g)).
Which AI systems are "limited risk"?
The Regulation's operative text never uses the phrase. Chapter IV's actual title is "Transparency obligations for providers and deployers of certain AI systems" — "limited risk" is industry shorthand for systems that trigger one of the four Article 50 duties without landing in a higher tier. The trigger is function — interacting, generating, inferring, fabricating — not sector. In the classification sequence, Article 50 comes after the Article 5 prohibitions and both high-risk routes — the full method is in how to classify your AI system.
Do you have to tell users they are talking to an AI? (Article 50(1))
Providers must ensure systems "intended to interact directly with natural persons" are designed and developed so those persons are informed they are interacting with an AI system. It is a product-design duty — a disclosure buried in terms of service does not satisfy "designed and developed".
The qualifier: no duty where AI interaction is "obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use". A widget labelled "AI assistant" on a SaaS dashboard is a plausible "obvious" case; an outbound voice agent on a phone line is not. The carve-out: systems authorised by law to detect, prevent, investigate or prosecute criminal offences are exempt — unless the system is available for the public to report a criminal offence.
How must AI-generated content be marked? (Article 50(2))
Providers of systems generating synthetic audio, image, video or text — expressly including general-purpose AI systems — must ensure outputs "are marked in a machine-readable format and detectable as artificially generated or manipulated". The standard is qualified: technical solutions must be "effective, interoperable, robust and reliable as far as this is technically feasible", accounting for content-type limitations, implementation costs and the state of the art. If you build on a foundation model, check what marking ships upstream — the GPAI obligations run on their own track, but 50(2) attaches to the system you place on the market.
Two exceptions besides the law-enforcement one: an "assistive function for standard editing", and systems that "do not substantially alter the input data provided by the deployer or the semantics thereof" — a grammar checker is out; a text-to-image generator is in.
One catch-up deadline lands here. Article 111(4), inserted by Regulation (EU) 2026/1744, gives providers of systems "including general-purpose AI systems, generating synthetic audio, image, video or text content, that have been placed on the market before 2 August 2026" until 2 December 2026 to "take the necessary steps in order to comply with Article 50(2)". Three limbs: providers, not deployers; 50(2) only, not the 50(1) interaction disclosure; and placing on the market — the provision does not say "or put into service".
Article 50(7) was itself rewritten in 2026. It now tasks the Commission, not the AI Office, with facilitating codes of practice on the detection, marking and labelling of artificially generated content, and the implementing act that used to approve them is gone: the Commission, "taking utmost account of the opinion of the Board", assesses whether adherence to a code is adequate to ensure compliance with Article 50(2) and (4) under Article 56(6), and may displace an inadequate code with common rules under Article 98(2). Recital 41 of the amending regulation gives the reason — these codes have limited legal effect and in particular grant no presumption of conformity.
What must deployers of emotion recognition disclose? (Article 50(3))
Deployers of an emotion recognition system or a biometric categorisation system must inform exposed persons "of the operation of the system" and process personal data in accordance with the GDPR, Regulation (EU) 2018/1725 and Directive (EU) 2016/680, as applicable. The law-enforcement exception here is narrower than its 50(1) and 50(2) counterparts: it covers systems permitted by law to detect, prevent or investigate criminal offences — no "prosecute" limb, and "permitted", not "authorised".
The boundary matters more than the duty: 50(3) only governs contexts where emotion recognition is lawful at all. Inferring emotions in the workplace or education institutions is prohibited outright under Article 5(1), first subparagraph, point (f), except for medical or safety reasons — no disclosure fixes that. A retail customer-experience system can comply via 50(3); the same capability pointed at your own employees falls under the Article 5 prohibitions, in force since 2 February 2025.
When must deep fakes and AI-written text be disclosed? (Article 50(4))
Two subparagraphs, two different rules — do not blur them.
Deep fakes (first subparagraph): deployers of a system generating or manipulating image, audio or video content constituting a deep fake — defined in Article 3, point (60), as content that "resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful" — must disclose that the content is artificially generated or manipulated. Law-enforcement use authorised by law is excepted. For "evidently artistic, creative, satirical, fictional or analogous" work, the duty is not lifted but limited: disclosure "in an appropriate manner that does not hamper the display or enjoyment of the work".
Public-interest text (second subparagraph): deployers of a system generating or manipulating text "published with the purpose of informing the public on matters of public interest" must disclose it. Here the second exception is different: no duty where the content "has undergone a process of human review or editorial control" and a natural or legal person "holds editorial responsibility" for the publication. That editorial escape exists only for text — there is no equivalent for video or audio deep fakes.
Is limited risk a safe harbour?
No. Article 50(6) states that paragraphs 1 to 4 "shall not affect the requirements and obligations set out in Chapter III" and are without prejudice to other transparency obligations laid down in Union or national law for deployers of AI systems. Article 50 is a layer, not a ceiling: a recruitment chatbot that screens candidates falls under point 4(a) of Annex III, so under Article 6(2) it "shall be considered to be high-risk" — and it still owes the 50(1) disclosure. Both sets apply, on different dates now: Article 50 since 2 August 2026 — 2 December 2026 for 50(2) on a synthetic-content system that was already on the market (Article 111(4)) — the high-risk obligations from 2 December 2027 for Annex III systems (Article 113, third paragraph, point (c)(i), as amended).
What happens if you ignore Article 50?
Every date around Article 50 is in the full timeline.
Non-compliance with the "transparency obligations for providers and deployers pursuant to Article 50" carries fines up to €15 million or 3% of total worldwide annual turnover, whichever is higher (Article 99(4), point (g)); for SMEs and start-ups, Article 99(6) caps each fine at whichever of the percentage or amount is lower, and new Article 99(6a) does the same for small mid-cap enterprises (SMCs). Fines are not the only lever: Article 79(6), point (d) lists Article 50 non-compliance as a ground on which market surveillance authorities can restrict or withdraw a system.
The disclosure itself is the compliance artefact. Under Article 50(5) it must reach people "in a clear and distinguishable manner at the latest at the time of the first interaction or exposure" and conform to applicable accessibility requirements — so keep the actual wording, where it appears, and since when, on file. A regulator asking how you complied gets a dated record, not a memory.
What this means for you
If you're a provider: You own 50(1) and 50(2). Inventory every system that talks to users or generates content, decide the "obvious" question per interface with reasons recorded, and implement machine-readable marking against the current state of the art — rechecking as codes of practice under 50(7) appear. Anything you shipped before 2 August 2026 carries the Article 111(4) date: 2 December 2026. Complipath's requirements checklist lists each obligation a classification triggers with status, owner and an evidence link, and hints at what counts as proof — which for Article 50 is the disclosure wording itself.
If you're a deployer: You own 50(3) and 50(4). Before running emotion recognition or biometric categorisation, confirm the context is not prohibited under Article 5(1), first subparagraph, point (f) — then notify exposed persons and square the data processing with the GDPR. For generated media and text, decide per publication which subparagraph of 50(4) applies and whether the artistic or editorial-responsibility limits genuinely fit.
Must your system say what it is?
Classify your system now — 7 questions on the main line, plus follow-ups where they apply, no account, and the classification runs in your browser: answers stay there unless you choose to keep the result.
FAQ
When did the Article 50 transparency obligations start to apply? 2 August 2026. Article 50 sits in Chapter IV, which is not listed in any of the staggered exceptions of Article 113, third paragraph, so it follows the default application date in Article 113, second paragraph. The duties are live; the one catch-up is Article 111(4), giving pre-2 August 2026 synthetic-content systems until 2 December 2026 for 50(2).
Does every chatbot need an "I am an AI" disclosure? No. Article 50(1) waives the duty where AI interaction is obvious to a reasonably well-informed, observant and circumspect person in context. But "obvious" is judged from the user's side, not yours — document the reasoning per interface, and disclose whenever the call is close.
Is emotion recognition limited-risk or prohibited? Both, depending on context. In the workplace and education institutions it is prohibited under Article 5(1), first subparagraph, point (f), except for medical or safety reasons. Elsewhere it can be lawful, and Article 50(3) then requires deployers to inform exposed persons and to process personal data lawfully.
Can a high-risk system also have Article 50 duties? Yes. Article 50(6) says paragraphs 1 to 4 do not affect Chapter III requirements. A high-risk system with a conversational interface owes both the full high-risk obligations and the Article 50(1) disclosure. Article 50 never downgrades a classification — it stacks on top of one.
Sources: Regulation (EU) 2024/1689 (EUR-Lex), Articles 3, 5, 50, 79, 99 and 113, as amended by Regulation (EU) 2026/1744 (EUR-Lex), Article 1, points (20), (38) and (39)(b), with recital 41. Article 50 itself — paragraphs 1 to 6 — was not amended, and neither was its 2 August 2026 application date; Article 111(4), added by point (39)(b), gives one class of provider until 2 December 2026 for 50(2). The Article 50(7) codes of practice on detection, marking and labelling of artificially generated content remain a moving part: the Regulation provides the mechanism but this guide, written from the Regulation's text alone, cannot confirm which codes exist — verify the current status before finalising a marking approach.