AI Labeling Obligation under Art. 50 EU AI Act: What Operators Must Do Now

Compliance & Data Protection

Image

Dominik Keller

Image

The AI labeling obligation under Article 50 of the AI Act requires that people can recognize when they are talking to an AI or are looking at AI-generated content. It has been directly applicable since August 2, 2026 – regardless of the risk class of the system and therefore for far more companies than the high-risk rules.

The essentials in brief

  • Article 50 has been applicable since August 2, 2026 and was not postponed by the Digital Omnibus – unlike the high-risk obligations.

  • It affects you regardless of the risk class: a simple support chatbot is enough.

  • Four cases are regulated: interaction, synthetic content, emotion recognition, deepfakes and AI texts.

  • The fine framework is €15 million or 3% of the worldwide annual turnover (Art. 99 para. 4) – not the often cited €35 million that applies to prohibited practices.

  • In Germany, the Federal Network Agency (Bundesnetzagentur) has been responsible since July 29, 2026.

Table of contents

  1. Who the obligation affects: provider or deployer?

  2. Overview of the four cases

  3. Phrasing you can adopt

  4. When you do not have to label

  5. What the Digital Omnibus changed

  6. Who checks compliance in Germany

  7. What the penalties are for violations

  8. Where a gateway facilitates implementation

  9. Frequently asked questions

Who the obligation affects: provider or deployer?

Article 50 distributes the obligations between two roles, and this distinction determines what you specifically need to do. A provider is someone who develops an AI system and places it on the market under their own name. A deployer is someone who uses such a system under their own responsibility. Most companies that buy AI and integrate it into their products are deployers – and this is precisely the role addressed in two of the four paragraphs.

The most common misconception in practice: "We only use the OpenAI API, so OpenAI is responsible." This applies to the machine-readable marking of synthetic content (paragraph 2, provider obligation). However, you are responsible for the visible notice on the chatbot and for the disclosure of deepfakes as soon as you deploy the system.

Paragraph

Addressee

What needs to be done

Para. 1 – Interaction

Provider

Design the system so that the use of AI is recognizable

Para. 2 – Synthetic content

Provider

Mark outputs as AI-generated in a machine-readable format

Para. 3 – Emotion recognition, biometric categorization

Deployer

Inform affected individuals about the use

Para. 4 – Deepfakes, AI texts on public matters

Deployer

Disclose that the content was artificially generated or manipulated

According to paragraph 5, the information must be provided at the latest at the time of the first interaction, clearly recognizable and accessible. A notice that is only found after scrolling or in the T&Cs does not meet the requirement. Paragraph 6 clarifies that Article 50 does not replace the high-risk requirements from Chapter III, but stands alongside them.

Overview of the four cases

Case 1: Chatbots and AI assistants

Any system intended for direct interaction with humans must make it recognizable that an AI is responding. This applies to support chatbots, voicebots in phone systems, and AI assistants in customer portals. The exception only applies if the use of AI is obvious from the context to a reasonably well-informed user – you should not rely on this in case of doubt.

Case 2: Marking synthetic content in a machine-readable format

Providers of generative systems must mark their outputs in a machine-readable format, for example via watermarks or metadata. For you as a deploying company, this is primarily a procurement issue: clarify with the model provider whether and how it is marked, and keep the answer in writing. Not every provider delivers this today.

Case 3: Emotion recognition and biometric categorization

Anyone deploying a system for emotion recognition or biometric categorization must inform the affected individuals. This obligation applies in addition to the GDPR, not instead of it – so you still need a legal basis for processing and usually a clean data processing agreement.

Case 4: Deepfakes and AI texts on public matters

In the case of image, audio, or video content that deceptively resembles real people or events, you must disclose that they were artificially generated or manipulated. For texts, the obligation is narrower: only for content that informs the public on matters of public interest and is published without real editorial control. An AI-written product text in an online shop does not fall under this, but an automatically generated post on a political topic does.

Phrasing you can adopt

The regulation does not prescribe specific wording but demands clarity. The following building blocks meet the requirement of paragraph 5 and can be adopted directly:

Application

Suggested wording

Placement

Support Chatbot

"You are chatting with an AI assistant here. For a personal response, you can reach us at ..."

First message in the dialog window, permanently visible in the header area

Voicebot

"You are speaking with an automated assistant. Say 'representative' at any time to be connected."

Announcement before the first question

AI-generated image

"AI-generated" or "AI-altered"

Visible in the image or directly in the caption

Video with real people

"This video contains AI-generated content."

Overlay at the beginning, not just in the credits

AI text on public topics

"This article was created with AI assistance and editorially reviewed."

Directly below the headline

Two details are worth paying attention to. First, the chatbot notice includes not only the fact that an AI is responding, but also a path to a human. Second, in German-speaking areas, the abbreviation "KI" is the safe choice; although the code of conduct mentions the English "AI", the notice must be understandable to your audience.

When you do not have to label

Article 50 has four exceptions that have varying degrees of resilience in practice:

  • Obviousness (Para. 1): If it is clear to a reasonably well-informed user from the circumstances that an AI is responding. A weak exception – label when in doubt.

  • Editorial control (Para. 4): If a human has reviewed the content of the text and assumed editorial responsibility. A mere plausibility check is not sufficient for this.

  • Art and satire (Para. 4): For recognizably artistic, creative, satirical, or fictional works, the obligation is eased, not lifted – the notice may be placed in a way that does not disturb the presentation, such as in the intro or credits.

  • Law enforcement: For legally authorized systems for detecting and prosecuting criminal offenses.

  • Supporting functions (Para. 2): If the AI does not significantly alter the input data, such as for pure spellchecking.

What the Digital Omnibus changed

The Digital Omnibus (Regulation (EU) 2026/1744, in force since July 27, 2026) significantly postponed the high-risk obligations – Annex III to December 2, 2027, Annex I to August 2, 2028. Article 50 was not affected by this. The transparency obligations have applied unchanged since August 2, 2026.

This is the point where many companies are currently planning incorrectly: because the headlines reported a postponement, labeling was also deferred to 2027. For your gateway or chatbot decision, this means the opposite – the time pressure for high-risk systems has decreased, but not for transparency. A complete overview of deadlines is available in our AI Act Checklist for Gateways.

There is, however, one single relief: for the machine-readable marking according to paragraph 2, the grace period for systems placed on the market before August 2, 2026 was extended to December 2, 2026.

Who checks compliance in Germany

The Federal Network Agency (Bundesnetzagentur) is responsible. The KI-MIG (Act on Market Surveillance and Innovation Promotion of Artificial Intelligence) was promulgated in the Federal Law Gazette on July 28, 2026 and has been in force since July 29, 2026. This makes the Federal Network Agency the central market surveillance authority, notifying authority, and complaints office for the AI Act – also for the transparency obligations.

The complaints office is practically relevant: not only authorities will become active, but customers, competitors, and affected individuals can also report violations. At the same time, the Federal Network Agency is setting up an AI Service Desk and AI regulatory sandboxes – contact points intended to support companies with implementation rather than just penalizing them.

What the penalties are for violations

For violations of Article 50, the framework from Article 99 Paragraph 4 of Regulation (EU) 2024/1689 applies: up to 15 million euros or 3% of the worldwide annual turnover, whichever is higher.

This number differs from what can currently be read in many places. The frequently mentioned 35 million euros or 7% refer to Article 99 Paragraph 3 and thus to prohibited practices under Article 5 – not to transparency violations. Anyone planning with the higher figure overestimates the risk; anyone who therefore considers the obligation secondary underestimates it.

For small and medium-sized enterprises as well as start-ups, Article 99 provides for relief: for them, the lower of the two values applies.

Where a gateway facilitates implementation

The labeling itself happens in your application, not in the gateway – the notice in the chat window is frontend work. However, two requirements related to Article 50 are much easier to fulfill in a central location than distributed across every integration:

  • Proving which model responded when. If a supervisory authority or a customer asks which output came from which system, you need a continuous log of queries, model, provider, and timestamp.

  • Knowing which model actually responds. Paragraph 2 requires the provider to apply a machine-readable mark. You can only judge whether your model delivers this if the model origin does not disappear behind an automatic replacement.

A gateway is the most cost-effective place to bundle both instead of building them individually in each application. What else such a layer achieves is described in our introduction What is an LLM Gateway?; which European providers are suitable for this is shown in the Comparison of GDPR-compliant LLM Routers.

Frequently asked questions

Does the labeling obligation also apply to internal AI applications?

Yes. Article 50 Paragraph 1 refers to interaction with natural persons, not just customers. An internal assistant in the intranet that employees chat with falls under this. The exception of obviousness is more likely to apply here if the system is clearly introduced and named as an AI tool.

Do I need to label AI-generated product texts in my online shop?

Usually not. The text obligation in paragraph 4 only applies to content that informs the public on matters of public interest. Product descriptions and marketing texts do not fall under this. The situation is different for automatically generated articles on political, social, or health topics.

Is a notice in the T&Cs or privacy policy sufficient?

No. Paragraph 5 requires the information at the latest at the time of the first interaction, clearly recognizable and accessible. A reference that users only find by clicking on a legal page does not meet this requirement. The notice belongs where the interaction takes place.

What applies to content created before August 2, 2026?

There is no retroactive labeling obligation for content already published. For the machine-readable marking under paragraph 2, a grace period until December 2, 2026 applies to systems placed on the market before this date.

Who is liable if the model provider does not mark in a machine-readable format?

The obligation under paragraph 2 lies with the provider of the generative system. As a deployer, you remain responsible for your own obligations under paragraphs 1, 3, and 4. It makes sense to contractually query and document the marking capability – this is also proof of your diligence.

Was the labeling obligation postponed by the Digital Omnibus?

No. The Digital Omnibus only postponed the high-risk obligations. Article 50 has applied unchanged since August 2, 2026. Only the grace period for the machine-readable marking of older systems was extended to December 2, 2026.

How high is the fine really?

Up to 15 million euros or 3% of the worldwide annual turnover, whichever is higher (Art. 99 para. 4). The often mentioned 35 million euros apply to prohibited practices under Article 5, not to transparency violations. For SMEs and start-ups, the lower value applies.

Sources

As of: August 28, 2026 · kontinent.ai. Legal status checked against EUR-Lex and the Federal Law Gazette; no legal advice.