AI Labeling Obligation under Art. 50 EU AI Act: What Operators Must Do Now
Compliance & Data Protection

Dominik Keller

The AI labeling obligation under Article 50 of the AI Act requires that people can recognize when they are talking to an AI or are looking at AI-generated content. It has been directly applicable since August 2, 2026 – regardless of the risk class of the system and therefore for far more companies than the high-risk rules.
The essentials in brief
Article 50 has been applicable since August 2, 2026 and was not postponed by the Digital Omnibus – unlike the high-risk obligations.
It affects you regardless of the risk class: a simple support chatbot is enough.
Four cases are regulated: interaction, synthetic content, emotion recognition, deepfakes and AI texts.
The fine framework is €15 million or 3% of the worldwide annual turnover (Art. 99 para. 4) – not the often cited €35 million that applies to prohibited practices.
In Germany, the Federal Network Agency (Bundesnetzagentur) has been responsible since July 29, 2026.
Table of contents
Who the obligation affects: provider or deployer?
Overview of the four cases
Phrasing you can adopt
When you do not have to label
What the Digital Omnibus changed
Who checks compliance in Germany
What the penalties are for violations
Where a gateway facilitates implementation
Frequently asked questions
Who the obligation affects: provider or deployer?
Article 50 distributes the obligations between two roles, and this distinction determines what you specifically need to do. A provider is someone who develops an AI system and places it on the market under their own name. A deployer is someone who uses such a system under their own responsibility. Most companies that buy AI and integrate it into their products are deployers – and this is precisely the role addressed in two of the four paragraphs.
The most common misconception in practice: "We only use the OpenAI API, so OpenAI is responsible." This applies to the machine-readable marking of synthetic content (paragraph 2, provider obligation). However, you are responsible for the visible notice on the chatbot and for the disclosure of deepfakes as soon as you deploy the system.
Paragraph | Addressee | What needs to be done |
|---|---|---|
Para. 1 – Interaction | Provider | Design the system so that the use of AI is recognizable |
Para. 2 – Synthetic content | Provider | Mark outputs as AI-generated in a machine-readable format |
Para. 3 – Emotion recognition, biometric categorization | Deployer | Inform affected individuals about the use |
Para. 4 – Deepfakes, AI texts on public matters | Deployer | Disclose that the content was artificially generated or manipulated |
According to paragraph 5, the information must be provided at the latest at the time of the first interaction, clearly recognizable and accessible. A notice that is only found after scrolling or in the T&Cs does not meet the requirement. Paragraph 6 clarifies that Article 50 does not replace the high-risk requirements from Chapter III, but stands alongside them.
Overview of the four cases
Case 1: Chatbots and AI assistants
Any system intended for direct interaction with humans must make it recognizable that an AI is responding. This applies to support chatbots, voicebots in phone systems, and AI assistants in customer portals. The exception only applies if the use of AI is obvious from the context to a reasonably well-informed user – you should not rely on this in case of doubt.
Case 2: Marking synthetic content in a machine-readable format
Providers of generative systems must mark their outputs in a machine-readable format, for example via watermarks or metadata. For you as a deploying company, this is primarily a procurement issue: clarify with the model provider whether and how it is marked, and keep the answer in writing. Not every provider delivers this today.
Case 3: Emotion recognition and biometric categorization
Anyone deploying a system for emotion recognition or biometric categorization must inform the affected individuals. This obligation applies in addition to the GDPR, not instead of it – so you still need a legal basis for processing and usually a clean data processing agreement.
Case 4: Deepfakes and AI texts on public matters
In the case of image, audio, or video content that deceptively resembles real people or events, you must disclose that they were artificially generated or manipulated. For texts, the obligation is narrower: only for content that informs the public on matters of public interest and is published without real editorial control. An AI-written product text in an online shop does not fall under this, but an automatically generated post on a political topic does.
Phrasing you can adopt
The regulation does not prescribe specific wording but demands clarity. The following building blocks meet the requirement of paragraph 5 and can be adopted directly:
Application | Suggested wording | Placement |
|---|---|---|
Support Chatbot | "You are chatting with an AI assistant here. For a personal response, you can reach us at ..." | First message in the dialog window, permanently visible in the header area |
Voicebot | "You are speaking with an automated assistant. Say 'representative' at any time to be connected." | Announcement before the first question |
AI-generated image | "AI-generated" or "AI-altered" | Visible in the image or directly in the caption |
Video with real people | "This video contains AI-generated content." | Overlay at the beginning, not just in the credits |
AI text on public topics | "This article was created with AI assistance and editorially reviewed." | Directly below the headline |
Two details are worth paying attention to. First, the chatbot notice includes not only the fact that an AI is responding, but also a path to a human. Second, in German-speaking areas, the abbreviation "KI" is the safe choice; although the code of conduct mentions the English "AI", the notice must be understandable to your audience.
When you do not have to label
Article 50 has four exceptions that have varying degrees of resilience in practice:
Obviousness (Para. 1): If it is clear to a reasonably well-informed user from the circumstances that an AI is responding. A weak exception – label when in doubt.
Editorial control (Para. 4): If a human has reviewed the content of the text and assumed editorial responsibility. A mere plausibility check is not sufficient for this.
Art and satire (Para. 4): For recognizably artistic, creative, satirical, or fictional works, the obligation is eased, not lifted – the notice may be placed in a way that does not disturb the presentation, such as in the intro or credits.
Law enforcement: For legally authorized systems for detecting and prosecuting criminal offenses.
Supporting functions (Para. 2): If the AI does not significantly alter the input data, such as for pure spellchecking.
What the Digital Omnibus changed
The Digital Omnibus (Regulation (EU) 2026/1744, in force since July 27, 2026) significantly postponed the high-risk obligations – Annex III to December 2, 2027, Annex I to August 2, 2028. Article 50 was not affected by this. The transparency obligations have applied unchanged since August 2, 2026.
This is the point where many companies are currently planning incorrectly: because the headlines reported a postponement, labeling was also deferred to 2027. For your gateway or chatbot decision, this means the opposite – the time pressure for high-risk systems has decreased, but not for transparency. A complete overview of deadlines is available in our AI Act Checklist for Gateways.
There is, however, one single relief: for the machine-readable marking according to paragraph 2, the grace period for systems placed on the market before August 2, 2026 was extended to December 2, 2026.
Who checks compliance in Germany
The Federal Network Agency (Bundesnetzagentur) is responsible. The KI-MIG (Act on Market Surveillance and Innovation Promotion of Artificial Intelligence) was promulgated in the Federal Law Gazette on July 28, 2026 and has been in force since July 29, 2026. This makes the Federal Network Agency the central market surveillance authority, notifying authority, and complaints office for the AI Act – also for the transparency obligations.
The complaints office is practically relevant: not only authorities will become active, but customers, competitors, and affected individuals can also report violations. At the same time, the Federal Network Agency is setting up an AI Service Desk and AI regulatory sandboxes – contact points intended to support companies with implementation rather than just penalizing them.
What the penalties are for violations
For violations of Article 50, the framework from Article 99 Paragraph 4 of Regulation (EU) 2024/1689 applies: up to 15 million euros or 3% of the worldwide annual turnover, whichever is higher.
This number differs from what can currently be read in many places. The frequently mentioned 35 million euros or 7% refer to Article 99 Paragraph 3 and thus to prohibited practices under Article 5 – not to transparency violations. Anyone planning with the higher figure overestimates the risk; anyone who therefore considers the obligation secondary underestimates it.
For small and medium-sized enterprises as well as start-ups, Article 99 provides for relief: for them, the lower of the two values applies.
Where a gateway facilitates implementation
The labeling itself happens in your application, not in the gateway – the notice in the chat window is frontend work. However, two requirements related to Article 50 are much easier to fulfill in a central location than distributed across every integration:
Proving which model responded when. If a supervisory authority or a customer asks which output came from which system, you need a continuous log of queries, model, provider, and timestamp.
Knowing which model actually responds. Paragraph 2 requires the provider to apply a machine-readable mark. You can only judge whether your model delivers this if the model origin does not disappear behind an automatic replacement.
A gateway is the most cost-effective place to bundle both instead of building them individually in each application. What else such a layer achieves is described in our introduction What is an LLM Gateway?; which European providers are suitable for this is shown in the Comparison of GDPR-compliant LLM Routers.
Frequently asked questions
Does the labeling obligation also apply to internal AI applications?
Yes. Article 50 Paragraph 1 refers to interaction with natural persons, not just customers. An internal assistant in the intranet that employees chat with falls under this. The exception of obviousness is more likely to apply here if the system is clearly introduced and named as an AI tool.
Do I need to label AI-generated product texts in my online shop?
Usually not. The text obligation in paragraph 4 only applies to content that informs the public on matters of public interest. Product descriptions and marketing texts do not fall under this. The situation is different for automatically generated articles on political, social, or health topics.
Is a notice in the T&Cs or privacy policy sufficient?
No. Paragraph 5 requires the information at the latest at the time of the first interaction, clearly recognizable and accessible. A reference that users only find by clicking on a legal page does not meet this requirement. The notice belongs where the interaction takes place.
What applies to content created before August 2, 2026?
There is no retroactive labeling obligation for content already published. For the machine-readable marking under paragraph 2, a grace period until December 2, 2026 applies to systems placed on the market before this date.
Who is liable if the model provider does not mark in a machine-readable format?
The obligation under paragraph 2 lies with the provider of the generative system. As a deployer, you remain responsible for your own obligations under paragraphs 1, 3, and 4. It makes sense to contractually query and document the marking capability – this is also proof of your diligence.
Was the labeling obligation postponed by the Digital Omnibus?
No. The Digital Omnibus only postponed the high-risk obligations. Article 50 has applied unchanged since August 2, 2026. Only the grace period for the machine-readable marking of older systems was extended to December 2, 2026.
How high is the fine really?
Up to 15 million euros or 3% of the worldwide annual turnover, whichever is higher (Art. 99 para. 4). The often mentioned 35 million euros apply to prohibited practices under Article 5, not to transparency violations. For SMEs and start-ups, the lower value applies.
Sources
Regulation (EU) 2024/1689 (AI Act) – especially Art. 50 and Art. 99 para. 4
Regulation (EU) 2026/1744 (Digital Omnibus on AI), in force since July 27, 2026
KI-MIG – Act on Market Surveillance and Innovation Promotion of Artificial Intelligence, promulgated July 28, 2026, effective from July 29, 2026
Federal Network Agency (Bundesnetzagentur) – Press release on the role as market surveillance authority
dejure.org, Art. 50 AI Act – Standard text
As of: August 28, 2026 · kontinent.ai. Legal status checked against EUR-Lex and the Federal Law Gazette; no legal advice.