AI Labeling Obligation under Art. 50 EU AI Act: What Operators Must Do Now

Compliance & Data Protection

Image

Dominik Keller

Founder, Kontinent

The AI labeling requirement under Article 50 of the AI Act requires that people can recognize when they are interacting with an AI or are looking at AI-generated content. It has been directly applicable since August 2, 2026 – regardless of the risk class of the system and therefore for far more companies than the high-risk rules.

Key Takeaways

  • Article 50 has been applicable since August 2, 2026, and was not postponed by the Digital Omnibus – unlike the high-risk obligations.

  • It affects you regardless of the risk class: a simple support chatbot is enough.

  • Four cases are regulated: interaction, synthetic content, emotion recognition, deep fakes and AI text.

  • The fine framework is €15 million or 3% of worldwide annual turnover (Art. 99 para. 4) – not the often cited €35 million, which applies to prohibited practices.

  • In Germany, the Federal Network Agency (Bundesnetzagentur) has been responsible since July 29, 2026.

Table of Contents

  1. Who is affected by the obligation: Providers or Deployers?

  2. The Four Cases at a Glance

  3. Formulations You Can Adopt

  4. When You Do Not Need to Label

  5. What the Digital Omnibus Changed

  6. Who Checks Compliance in Germany

  7. What Violations Threaten

  8. Where a Gateway Facilitates Implementation

  9. Frequently Asked Questions

Who is affected by the obligation: Providers or Deployers?

Article 50 distributes the obligations between two roles, and this distinction determines what you concretely need to do. A provider is someone who develops an AI system and places it on the market under their own name. A deployer (operator) is someone who uses such a system under their own responsibility. Most companies that buy AI and integrate it into their products are deployers – and exactly this role is addressed in two of the four paragraphs.

The most common misconception in practice: "We only use the OpenAI API, so OpenAI is responsible." This is true for the machine-readable marking of synthetic content (paragraph 2, provider obligation). For the visible notice on the chatbot and for the disclosure of deep fakes, however, you are responsible as soon as you deploy the system.

Paragraph

Addressee

What needs to be done

Para. 1 – Interaction

Provider

Design the system so that the use of AI is recognizable

Para. 2 – Synthetic content

Provider

Mark outputs as AI-generated in a machine-readable format

Para. 3 – Emotion recognition, biometric categorization

Deployer

Inform affected persons about the use

Para. 4 – Deep fakes, AI texts on public affairs

Deployer

Disclose that the content has been artificially generated or manipulated

According to paragraph 5, the information must be provided at the latest at the time of the first interaction, clearly recognizable and accessible. A notice that is only found after scrolling or in the T&C does not meet the requirement. Paragraph 6 clarifies that Article 50 does not replace the high-risk requirements from Chapter III, but stands alongside them.

The Four Cases at a Glance

Case 1: Chatbots and AI Assistants

Every system intended for direct interaction with humans must make it recognizable that an AI is responding. This applies to support chatbots, voicebots in the telephone system, and AI assistants in the customer portal. The exception only applies if the use of AI is already obvious from the context for a reasonable user – you should not rely on this in case of doubt.

Case 2: Labeling Synthetic Content in a Machine-Readable Format

Providers of generative systems must label their outputs in a machine-readable format, for example via watermarks or metadata. For you as the deploying company, this is primarily a procurement question: clarify with the model provider whether and how labeling is done, and record the answer in writing. Not every provider delivers this today.

Case 3: Emotion Recognition and Biometric Categorization

Anyone who deploys a system for emotion recognition or biometric categorization must inform the affected persons. This obligation applies in addition to the GDPR, not instead of it – so you still need a legal basis for processing and usually a clean data processing agreement.

Case 4: Deep Fakes and AI Texts on Public Affairs

For image, audio, or video content that deceptively depicts real people or events, you must disclose that they have been artificially generated or manipulated. For text, the obligation is narrower: only for content that informs the public on matters of public interest and is published without real editorial control. An AI-written product text in an online shop does not fall under this, but an automatically generated post on a political topic does.

Formulations You Can Adopt

The regulation does not prescribe specific wording, but demands clarity. The following components meet the requirement of paragraph 5 and can be adopted directly:

Use Case

Proposed Formulation

Placement

Support Chatbot

"You are writing with an AI assistant here. For personal feedback, you can reach us at…"

first message in the dialog window, permanently visible in the header area

Voicebot

"You are speaking with an automated assistant. Say 'agent' at any time to be connected."

announcement before the first question

AI-generated Image

"AI-generated" or "AI-altered"

visible in the image or directly in the caption

Video with Real People

"This video contains AI-generated content."

overlay at the beginning, not just in the credits

AI Text on Public Topic

"This post was created with AI assistance and editorially reviewed."

directly below the headline

Two details deserve attention. First, the chatbot notice should include not only the fact that an AI is responding, but also a path to a human. Second, in German-speaking countries, the abbreviation "KI" (or "AI") is the safe choice; although the code of conduct mentions the English "AI", the notice must be understandable to your audience.

When You Do Not Need to Label

Article 50 contains four exceptions that carry different weight in practice:

  • Obviousness (Para. 1): When it is clear to a reasonable user from the circumstances that an AI is responding. A weak exception – when in doubt, label.

  • Editorial Control (Para. 4): When a human has checked the text content and assumed editorial responsibility. A mere plausibility check is not sufficient for this.

  • Art and Satire (Para. 4): For recognizably artistic, creative, satirical, or fictional works, the obligation is eased, not lifted – the notice may be placed in a way that does not disturb the presentation, such as in the opening or closing credits.

  • Law Enforcement: For legally authorized systems used for detecting and prosecuting crime.

  • Supportive Functions (Para. 2): When the AI does not significantly alter the input data, such as in pure spell checking.

What the Digital Omnibus Changed

The Digital Omnibus (Regulation (EU) 2026/1744, in force since July 27, 2026) has significantly postponed the high-risk obligations – Annex III to December 2, 2027, Annex I to August 2, 2028. Article 50 was not affected by this. The transparency obligations have applied unchanged since August 2, 2026.

This is the point where many companies are currently planning incorrectly: because the headlines reported a postponement, labeling was also postponed to 2027. For your gateway or chatbot decision, this means the opposite – the time pressure on high-risk has decreased, but not on transparency. A complete overview of deadlines is in our AI Act Checklist for Gateways.

There is, however, one single relief: for the machine-readable marking under paragraph 2, the grace period for systems placed on the market before August 2, 2026, has been extended to December 2, 2026.

Who Checks Compliance in Germany

The Federal Network Agency (Bundesnetzagentur) is responsible. The KI-MIG (Act on Market Surveillance and Innovation Promotion of Artificial Intelligence) was promulgated in the Federal Law Gazette on July 28, 2026, and has been in force since July 29, 2026. This makes the Federal Network Agency the central market surveillance authority, notifying authority, and complaints office for the AI Act – also for the transparency obligations.

Practically relevant is the complaints office: not only authorities will become active, but customers, competitors, and affected persons can also report violations. At the same time, the Federal Network Agency is setting up an AI Service Desk and AI regulatory sandboxes – contact points intended to support companies with implementation rather than just issuing sanctions.

What Violations Threaten

For violations of Article 50, the framework from Article 99 Paragraph 4 of Regulation (EU) 2024/1689 applies: up to 15 million euros or 3% of worldwide annual turnover, whichever is higher.

This figure deviates from what can currently be read in many places. The frequently mentioned 35 million euros or 7% refer to Article 99 Paragraph 3 and thus to prohibited practices under Article 5 – not to transparency violations. Anyone planning with the higher figure overestimates the risk; anyone who therefore considers the obligation subordinate underestimates it.

For small and medium-sized enterprises and start-ups, Article 99 provides for relief: in their case, the lower of the two values applies.

Where a Gateway Facilitates Implementation

The labeling itself happens in your application, not in the gateway – the notice in the chat window is frontend work. However, two requirements surrounding Article 50 can be fulfilled much more easily in a central location than distributed across every integration:

  • Proving which model responded when. If a supervisory authority or a customer asks which output came from which system, you need a continuous log of requests, model, provider, and timestamp.

  • Knowing which model actually responds. Paragraph 2 requires a machine-readable label from the provider. You can only judge whether your model delivers this if the model origin does not disappear behind an automatic replacement.

A gateway is the most cost-effective place to bundle both instead of building it individually in each application. What else such a layer does is described in our introduction What is an LLM Gateway?; which European providers are eligible for this is shown in the Comparison of GDPR-compliant LLM Routers.

Frequently Asked Questions

Does the labeling requirement also apply to internal AI applications?

Yes. Article 50 Paragraph 1 refers to interaction with natural persons, not to customers. An internal assistant in the intranet with which employees chat falls under this. The exception of obviousness is more likely to apply here if the system is clearly introduced and named as an AI tool.

Do I need to label AI-generated product texts in the online shop?

Usually not. The text obligation in paragraph 4 only applies to content that informs the public on matters of public interest. Product descriptions and marketing texts do not fall under this. It is different for automatically generated posts on political, social, or health topics.

Is a notice in the T&C or the privacy policy sufficient?

No. Paragraph 5 requires the information at the latest at the time of the first interaction, clearly recognizable and accessible. A reference that users only find by clicking on a legal page does not meet this requirement. The notice belongs where the interaction takes place.

What applies to content created before August 2, 2026?

There is no retroactive labeling requirement for already published content. For the machine-readable marking under paragraph 2, a grace period until December 2, 2026, applies to systems placed on the market before this date.

Who is liable if the model provider does not mark in a machine-readable format?

The obligation under paragraph 2 lies with the provider of the generative system. As the deployer, you remain responsible for your own obligations under paragraphs 1, 3, and 4. It makes sense to contractually query and document the marking capability – this is also proof of your diligence.

Was the labeling obligation postponed by the Digital Omnibus?

No. The Digital Omnibus only postponed the high-risk obligations. Article 50 has applied unchanged since August 2, 2026. Only the grace period for the machine-readable marking of older systems was extended until December 2, 2026.

How high is the fine really?

Up to 15 million euros or 3% of worldwide annual turnover, whichever is higher (Art. 99 para. 4). The often mentioned 35 million euros apply to prohibited practices under Article 5, not to transparency violations. For SMEs and start-ups, the lower value applies in each case.

Sources

Status: August 28, 2026 · kontinent.ai. Legal status checked against EUR-Lex and the Federal Law Gazette; no legal advice.

  • Border Shape
  • Border Shape