Forty Cases That Decide Whether You Label
Article 50 of the EU AI Act, read against the Commission's own worked examples — thirty scenarios anchored to the Guidelines, plus ten documented incidents run through the test.
Published on August 17, 2026
Forty Cases That Decide Whether You Label
Article 50 of the EU AI Act, Read Against the Commission’s Own Examples — and Against Ten Incidents That Already Happened
In brief. Article 50 has applied since 2 August 2026. It is not one labelling rule but four duties split across providers and deployers, with several narrowly framed exceptions that turn on factual assessments you have to make and record. The Commission’s Guidelines clarify many of the hard cases with worked examples — a flying sphinx, an in-car navigation voice, a witness-statement chatbot — and several of those examples cut against the popular understanding. Below: thirty of them, plus ten incidents that already happened.
Why this article exists
Article 50 of Regulation (EU) 2024/1689 became applicable on 2 August 2026.1 The European Commission adopted and published its interpretive Guidelines on 20 July 2026 (Communication C(2026) 5054) — a 51-page document that market surveillance authorities can be expected to treat as the reference point for how the provision is read.2
Nearly every explainer circulating on the topic paraphrases the Commission’s summary pages. Almost none of them read the Guidelines themselves — which is a problem, because the Guidelines resolve most of the questions the summaries leave open, and in several places they resolve them against the popular understanding.
This article does three things. It states the four obligations with paragraph-level anchoring. It works through thirty scenarios drawn from the Commission’s own worked examples. And it then runs ten documented real-world incidents — Arup, Slovakia, CNET, Coca-Cola and others — through the Article 50 test, as counterfactuals: none of them was governed by Article 50 at the time, and that is precisely what makes them useful.
One correction up front, because it is the clearest illustration of why source-level precision matters. It is widely assumed — and I assumed it myself — that running a public-interest text through AI translation triggers the marking obligation. It does not, provided the translation stays within standard editing assistance. Translation appears in the Commission’s standard-editing examples. Summarising does not. But note the second half of that correction, which is easy to miss: the translation exception belongs to the provider’s marking duty under Article 50(2). Whether the published text needs a visible label is a separate question under Article 50(4), with its own separate exception. Two different duties, two different actors, two different answers.
Part 1 — The architecture, with anchors
Article 50 contains four transparency duties plus one horizontal rule. The same system can trigger several at once, engaging providers and deployers at different points in the value chain (paragraph 8).2
| Paragraph | Duty | Who |
|---|---|---|
| 50(1) | Inform people they are interacting with an AI system | Provider (design duty) |
| 50(2) | Mark synthetic output machine-readably and make it detectable | Provider |
| 50(3) | Inform people exposed to emotion recognition / biometric categorisation | Deployer |
| 50(4) | Label deepfakes; label unreviewed public-interest text | Deployer |
| 50(5) | Clear, distinguishable, at first interaction or exposure, accessible | Both |
Three structural points that most summaries omit:
Transparency does not launder legality. Compliance with Article 50 neither replaces the Article 5 prohibitions, nor the high-risk requirements under Article 6, nor the AI-literacy duty under Article 4 (paragraph 25). Data protection, consumer, IP and DSA obligations run in parallel.2
Substantial modification creates a new provider. A company that retrains an existing generative system and places it on the market under its own name becomes the provider of a new system, with the full provider duty set (Section 2.3).2
Article 50 binds AI systems, not GPAI models. Model-level transparency is encouraged and helps downstream compliance, but the 50(2) obligation rests with the provider of the system that generates the content — not the upstream model provider. The system provider may rely on the model provider’s or a third party’s marking solution, but responsibility does not transfer: it must verify and be able to demonstrate that the solution is effective, interoperable, robust and reliable.3
The scope carve-outs
- Purely personal, non-professional use (Article 2(10)) exempts the deployer’s obligations only. The system remains in scope for the provider, who must still mark synthetic outputs under 50(2) (paragraphs 19–20).2
- Scientific research and development is excluded — but the obligations revive the moment the system is put into service or its outputs are used for other purposes (paragraphs 21–22).
- Free and open-source systems stay in scope where Article 50 applies. Standalone open-source components that are not themselves AI systems do not carry the duties (paragraphs 23–24).
Who is the deployer
- Employees, freelancers and contractors acting under a legal person’s authority — animators, journalists, web designers — are not separate deployers (paragraph 14).
- Hosting services and broadcasters are not deployers merely by disseminating third-party AI content, though they are strongly encouraged to preserve marks and labels and may face DSA duties (paragraphs 16–17).
- A company that builds a generative system in-house and uses it to produce deepfakes is both provider and deployer (paragraph 15).
- Third-country reach: providers are caught where the system is placed on the Union market or its output is used in the Union; deployers where established in the Union or where they foresee dissemination of the output in the Union. Purely incidental, unforeseeable downstream reach does not on its own trigger the obligations (paragraphs 10, 13).
Part 2 — Thirty worked cases from the Commission’s Guidelines
Each verdict below is anchored to the Commission’s paragraph numbering.
A. Interactive systems — Article 50(1), Section 3
Case 1 — A helpdesk chatbot on a company website whose replies a user could read as human. Disclose. The Commission lists helpdesk chatbots explicitly among the not obvious examples. The obviousness exception is measured against a reasonably well-informed, observant and circumspect member of the intended and foreseeable audience — the consumer-law “average consumer” standard — and general public awareness that AI exists does not mean a person recognises a specific interaction as AI. The exception is limited to cases where almost no doubt remains (paragraphs 42–45).
Case 2 — A code-review assistant available only to professional developers. No disclosure required. Listed by the Commission as obvious (paragraphs 42–45).
Case 3 — An internal AI tool used only by trained, AI-literate staff. No disclosure required. Also listed by the Commission as obvious. Note how narrow this is: it is the audience’s trained competence that carries the exception, not the tool’s sophistication.
Case 4 — AI-enabled non-playable characters in a single-player game. No disclosure required (paragraphs 42–45).
Case 5 — A lifelike robotic companion pet in an elderly-care setting. Disclose. Listed among not obvious. Physical embodiment plus lifelike behaviour is precisely the combination the Commission treats as capable of deceiving.
Case 6 — Realistic avatars in an immersive VR environment where children or older users are foreseeably present. Disclose. Listed among not obvious. The disclosure must also be adapted for vulnerable audiences, including children, where they are reasonably likely to be in the audience (paragraphs 32–37).
Case 7 — A police chatbot for reporting a crime; a bank’s fraud-reporting hotline assistant; a witness-statement assistant. Disclose. The law-enforcement exception under Section 3.2.2 covers systems authorised by law to detect, prevent, investigate or prosecute criminal offences — but the Commission states expressly that it does not apply where the system is available to the public to report an offence. These three examples are named (paragraphs 46–49). This is the single most counter-intuitive holding in Section 3, and it lands directly on public-sector deployments.
Case 8 — An AI agent that makes bookings, manages correspondence, negotiates or concludes contracts, or executes purchases. Disclose twice over. The agent must be designed to disclose both its artificial nature and the person on whose behalf it acts, at key steps and at every new interaction. Where the provider cannot know in advance whether the agent will meet a natural person, it must be built to disclose in every situation where interaction is reasonably likely (paragraph 31).23
Case 9 — A rule-based out-of-office auto-reply. Out of scope. Not an AI system within Article 3(1); the Commission names simple non-AI automation of exactly this kind (paragraph 30).
Case 10 — An AI drafts a reply; a human reviews it and sends it under their own name. Out of 50(1). The interaction is not direct where a human is the main interlocutor reviewing and sending the output (paragraph 30). Note carefully: this disposes of 50(1) only. If the resulting text is published on a public-interest matter, 50(4) has to be analysed separately.
Case 11 — Your current disclosure wording. The Commission lists five formulations that are insufficient on their own for the Article 50(1) interactive disclosure (paragraph 38):
- disclosure buried in terms and conditions or documentation;
- machine-readable marks not perceivable at the point of interaction;
- vague signals such as “assistant”;
- generic site-wide notices — “services on this website use AI”;
- technology descriptions — “this system uses LLMs” — that do not explain the artificial origin.
If your interactive disclosure is on that list, it is not a disclosure.
B. Marking and detection — Article 50(2), Section 4
Case 12 — An AI feature that translates an existing document. No marking required under 50(2). Translation sits among the Commission’s standard-editing examples, alongside grammar and spelling correction, formatting, noise reduction and minor cropping — preparing existing content for publication without generating new content (examples following paragraphs 90–92).
But do not stop there. This resolves the provider’s marking duty only. If the translated text is then published to inform the public on a matter of public interest, the deployer must run the separate Article 50(4) analysis, where the operative exception is human review and editorial responsibility (paragraphs 133–138) — not standard editing. A machine-translated public-interest article published without substantive human review is a 50(4) problem even though it was never a 50(2) problem.
Case 13 — An AI feature that summarises an existing document. Marking required. The Commission’s “no substantial alteration” analysis treats summarising — together with paraphrasing that changes meaning, object or face replacement, voice cloning and realistic event fabrication — as going beyond standard editing (paragraphs 91–92 and the examples following).
Cases 12 and 13 sit adjacent in the Guidelines and point in opposite directions. Any content pipeline that treats “AI text assistance” as a single category is mis-scoped.
Case 14 — Outputs consisting of single words, captions, alt-text or UI labels; source code and machine-readable configuration (SDKs, SQL, IaC, YAML, JSON, APIs). Out of scope (paragraphs 64–68). Very short strings and source code are expressly excluded.
Case 15 — A generated playlist; a recommender’s ranked output; sensor and telemetry recordings; a rendered frame produced by simple data processing. Out of scope. Pure reproduction, selection or arrangement of existing content, observations and recordings not AI-generated, and content from simple data processing all fall outside (paragraphs 64–68).
Case 16 — Previsualisation frames generated inside a closed studio pipeline. Not automatically out of scope. Being intermediate is not enough on its own. Intermediate outputs used only in closed industrial or product-development workflows can qualify for the narrow industrial and B2B relief, but only where every condition in paragraph 87 is met: the output is strictly technical, restricted to a limited predefined professional audience, and protected against external sharing. The final published output remains covered and must be marked and detectable (paragraphs 64–68, 87).
Case 17 — 3-D assets, VR/AR/MR environments, digital twins, and agent outputs. In scope where the output is human-perceivable. VR/AR/MR is treated as video; 3-D images, 3-D video, 3-D audio and qualifying digital twins are covered. Agent outputs are covered where the action produces content perceptible by people; intermediate reasoning and machine-only actions are not. Nor are the underlying technical artefacts used to generate the output — point clouds and 3-D meshes do not themselves have to be marked (paragraphs 60–63).
Case 18 — An in-car navigation voice; strictly technical B2B output consumed by a defined internal professional audience; real-time ephemeral content that is never stored or disseminated. Narrow relief in each case (paragraphs 86–88): less-robust metadata marking may suffice for closed, instructive embedded products such as the navigation voice; no marking is required for the strictly technical B2B output; and the ephemeral real-time content may be exempt where marking is not feasible and users are told the content is AI-generated. Note the conditionality — none of these is a blanket exemption, and each needs a written assessment.
C. Emotion recognition and biometric categorisation — Article 50(3), Section 5
Case 19 — Emotion recognition applied to employees at work, or to students in a classroom. Stop before you reach Article 50. All emotion-recognition systems are also high-risk unless they are prohibited outright in the workplace and education under Article 5(1)(f) — a prohibition that excepts medical and safety uses. Biometric categorisation is covered by 50(3) regardless of high-risk status, unless prohibited as sensitive-attribute inference under Article 5(1)(g) (paragraphs 101–104). Transparency notification does not make an otherwise prohibited use lawful (paragraph 110).
Case 20 — Ex-post sentiment analysis run over recorded customer calls. Notification still required — if it is an emotion-recognition system. Article 3(39) requires the system to infer emotions or intentions from biometric data: sentiment analysis run over a transcript, without inference from biometric voice data, does not by itself fall within it. Where it does, the obligation applies whether the system runs in real time or ex post (paragraphs 99–100). What must be said is only that the person is exposed to the operating system — the Regulation does not require stating the reasons; purposes and processing details are governed by data-protection law, and the two notices can be combined (paragraphs 105–110).
D. Deepfakes and public-interest text — Article 50(4), Section 6
Case 21 — A sphinx flying over the Eiffel Tower; cartoon mice debating the merits of cheese. Not deepfakes. The Article 3(60) definition is cumulative: AI-generated or manipulated image, audio or video that appreciably resembles an existing person, object, place, entity or event and would falsely appear to be authentic or truthful. Content that defies nature or physics and has no potential to mislead falls outside — and these two are the Commission’s own illustrations (paragraph 113).
A note on counting. The Commission’s Q&A page presents three cumulative criteria; the Guidelines at paragraph 113 set out four, splitting the resemblance element from the category of thing resembled.42 Same test, two presentations. For an internal classification checklist, use the four-element breakdown — separating “appreciably resembles” from “an existing person, object, place, entity or event” forces the two distinct factual questions you actually have to answer.
Case 22 — Colour correction, background clean-up, compression and aesthetic adjustment of a press photograph. Generally not a deepfake. But heavy editing of journalistic images beyond standard editorial practice can constitute one where the criteria are met (paragraph 116). Photorealism makes deepfake status more likely but is not determinative, and the false-appearance test is objective — it does not require any intent to deceive (paragraphs 114–115).
Case 23 — A politician’s face swapped into an authentic photograph; an authentic photograph of an empty apartment furnished by AI. Both will normally be deepfakes, and both are the Commission’s own published use cases for the Partially AI-Modified icon.5 The icon listing is not itself the legal test: the face swap qualifies where the result appreciably resembles the politician and would falsely appear authentic in its deployment context, and the furnished apartment where it is presented so as to mislead viewers about the property’s actual condition. The cumulative Article 3(60) criteria still have to be assessed. Disclosure must be perceivable without special tools, and the deployer cannot discharge it by relying on the provider’s machine-readable 50(2) mark (paragraph 117).
Case 24 — A satirical AI sketch inside a late-night comedy programme. Attenuated, not eliminated. Where a deepfake is evidently part of an artistic, creative, satirical, fictional or analogous work, disclosure is limited to a form that does not hamper enjoyment of the work — but it is still required. “Evidently” is read strictly; purely informative or commercial content is excluded from the attenuated regime; and where a work mixes informative and creative character, the informative character prevails (paragraphs 119–123). The attenuated regime does not excuse infringing third-party data-protection or IP rights (paragraph 124).
Case 25 — An AI-drafted memo circulated to staff on an intranet. Not “published.” Publication means accessible to an indeterminate, sizeable audience — not private or organisation-internal communication (paragraph 131).
Case 26 — An AI-drafted council press release, substantively reviewed and signed off by a named editor — and then run through an AI tool one more time for polish. The exemption is void. The editorial exception requires two cumulative conditions: genuine human review or editorial control (a deliberate substantive examination, with fact-checking as a minimum — not spell-checking, not an editorial policy that exists only on paper, not an automated review, not a cursory sign-off) and a natural or legal person holding editorial responsibility. And then the trap: any substantive AI intervention after editorial sign-off voids the exception (paragraphs 133–138). The Guidelines further recommend that the responsible person’s identity and contact details be publicly and easily findable, and align the concept with editorial responsibility under the European Media Freedom Act (paragraph 140).
Case 27 — An archived AI-generated article from 2025, re-published on your site in September 2026. Must be labelled. Content generated before 2 August 2026 need not be marked or labelled retroactively — but pre-existing text re-published on or after that date must be labelled (paragraphs 153–154). Every content migration, site relaunch and newsletter re-run now needs this check.
Case 28 — Your team’s plan to satisfy the deepfake label with the vendor’s embedded watermark. Fails. Provider marking is machine-readable; deployer disclosure must be human-perceivable. The Commission states the point at paragraph 117 and repeats it in its Q&A.4
Case 29 — An advertising agency’s freelance animator produces AI deepfake content for a client campaign. The agency is the deployer, not the animator, where it controls and takes responsibility for the animator’s use of the system on its behalf (paragraph 14). But if the freelancer uses the system in their own professional activity, under their own authority and control — separately engaged in a business, trade, occupation or freelance activity of their own, or deriving economic benefit on a regular basis — they may qualify as a deployer in their own right for that activity.4
Case 30 — Article 50(5), applied to a video that autoplays mid-scroll. The information must reach every natural person’s first interaction or exposure — not merely the first person overall. For interactive systems, at least once at the start of a session; for content, per output and per exposed person, with additional disclosure where people may not perceive the content from its start (paragraphs 141–143). On accessibility, Article 50(5) does not create a free-standing standard: it requires conformity with the accessibility requirements that already apply, such as Directive (EU) 2016/2102 and Directive (EU) 2019/882 where those are applicable (paragraph 144).
Part 3 — Ten documented incidents, run through Article 50
None of these was governed by Article 50 at the time. That is the point: each shows what the provision is aimed at, and each would now produce a determinate answer — though in several the answer is genuinely fact-sensitive rather than obvious.
Incident 1 — Arup, Hong Kong, January 2024. $25.6 million. A finance employee joined a video call on which the CFO and several recognisable colleagues appeared. All of them were AI-generated. Fifteen transfers to five bank accounts followed. Arup confirmed to CNN that fake voices and images were used and that no internal systems were compromised.6 Article 50 analysis: a textbook deepfake under the Article 3(60) criteria. And a textbook illustration of the limit of transparency law — criminals do not label. The provision’s value here is indirect: the 50(2) marking and detection duty is precisely the infrastructure that would let a verification tool flag such a stream. Transparency obligations protect the honest ecosystem; they do not deter fraud. Build your callback-verification control regardless.
Incident 2 — Slovakia, September 2023. Two days before the parliamentary election. A fabricated audio clip appeared to capture Progressive Slovakia leader Michal Šimečka and Denník N journalist Monika Tódová discussing vote-rigging. Both denounced it immediately; AFP’s fact-checking unit found signs of AI manipulation. It circulated during the 48-hour pre-election moratorium, which made rebuttal structurally difficult, and — because it was audio — it fell through a gap in the platform’s manipulated-media policy at the time.7 Article 50 analysis: a deepfake on the most acute matter of public interest there is. The audio-vs-video gap that let it spread is exactly what 50(2) closes by covering audio, image, video and text symmetrically. If a political party used an AI system under its own authority to generate or manipulate such audio, it would be the deployer and would carry the 50(4) labelling duty; a party or platform that merely disseminates someone else’s clip is not, for that reason alone, the deployer (paragraphs 14, 16–17). The generating system’s provider has a 50(2) marking duty.
Incident 3 — New Hampshire, January 2024. The Biden robocall. Voters received calls carrying a cloned Biden voice telling them not to vote in the primary. The FCC adopted a $6 million forfeiture against political consultant Steve Kramer in September 2024; the carrier, Lingo Telecom, settled separately for $1 million with a compliance plan mandating STIR/SHAKEN adherence and KYC obligations.8 Article 50 analysis: synthetic audio deepfake of an existing person on a matter of public interest. The US enforcement pattern reached both the originator and the carrier — but that was telecoms law, and it does not transpose directly. Under the EU stack, Article 50 places the labelling duty on the deployer and the marking duty on the provider; whether any intermediary carries additional obligations depends on what kind of service it operates, and a telecoms carrier is not automatically an online platform within the DSA.
Incident 4 — CNET, January 2023. 77 machine-generated stories. CNET published AI-generated explanatory articles on financial-services topics under the byline “CNET Money Staff”. Then-editor Connie Guglielmo confirmed 77 machine-generated stories; an internal review led to corrections on 41 of them. At first, readers had to click or hover over the author attribution to learn that automation was involved. The site later made AI involvement clearer.9 Article 50 analysis: the paradigm 50(4) text case. Published, informative, on financial matters of public interest. The disclosure mechanism — buried behind a byline click — is the kind of placement that struggles against the Article 50(5) requirement that the information be clear, distinguishable and reaching the reader at first exposure (paragraphs 141–143). Whether the editorial exception could have applied is answerable only on the facts: was there deliberate substantive examination with fact-checking, by a person with subject-matter competence, with editorial responsibility held? The correction rate on more than half the output does not by itself answer that question, but it raises a real one about the depth and effectiveness of the review.
Incident 5 — Sports Illustrated, November 2023. Authors who did not exist. Articles appeared under bylines whose headshots were traced to a site selling AI-generated portraits. The publisher disputed that the text was AI-written, attributing the pen names to a third-party contractor, and deleted the articles.10 Article 50 analysis: two distinct questions the Guidelines keep separate. On the synthetic portraits, do not assume that “this person is invented” ends the analysis. Paragraph 113 reaches subjects that could plausibly exist in reality, and a photorealistic AI persona presented as a real staff writer is capable of falsely appearing authentic — the test is contextual, and here the context was a claim of human authorship. On the text, 50(4) engages only if the text was AI-generated or manipulated. And on the contractor point, paragraph 14 answers only half the question: a third party operating on the publisher’s behalf and under its responsibility and control does not shift deployer status away from the publisher, but a contractor using the system under their own professional authority may be a deployer in their own right.
Incident 6 — Coca-Cola, November 2024 and again in 2025. Three AI-generated Christmas ads in 2024, produced by three AI studios using four generative models; a further AI-generated campaign followed in 2025 with the same lead studio.11 Article 50 analysis: commercial content is expressly excluded from the attenuated artistic regime (paragraphs 119–123) — an advertisement does not get the light-touch treatment a satirical sketch gets. But that exclusion decides which disclosure regime applies, not whether a label is owed in the first place. Whether each spot is a deepfake turns on whether it appreciably resembles existing persons, objects, places or events and would falsely appear authentic. AI-generated trucks recreating a 1995 campaign, in photorealistic style, is a genuinely arguable case that has to be assessed and documented — not assumed away in either direction.
Incident 7 — Toys “R” Us, June 2024. The founder. An AI-generated commercial depicted the company’s late founder in a bike shop alongside the brand mascot.11 Article 50 analysis: the clearest deepfake in this list. A recognisable, real, deceased individual, photorealistically synthesised. “Existing” under Article 3(60) reaches subjects that existed or could plausibly have existed in reality, and personality and post-mortem image rights run in parallel with the AI Act — the attenuated regime does not excuse infringing them (paragraph 124).
Incident 8 — McDonald’s, December 2025. The ad that was delisted. An AI-generated Christmas advertisement was widely criticised, comments were disabled, and the spot was ultimately delisted.12 Article 50 analysis: be precise about what would and would not be owed. The provider of the generating system owes machine-readable marking under 50(2). A visible label is owed by the deployer only if the content meets the deepfake criteria under 50(4) — being AI-generated is not by itself the trigger. The durable lesson here is reputational rather than legal: audiences detect synthetic commercial content and react to the absence of candour more sharply than to the technology.
Incident 9 — Microsoft Travel, August 2023. The Ottawa food bank. An AI-assisted travel guide recommended that tourists visit a local food bank. Microsoft removed the article after it was reported.13 Article 50 analysis: published and informative — but whether a travel guide is published to inform the public on a matter of public interest is itself arguable, and this belongs in the borderline column rather than the settled one. If it does so qualify, and the editorial exception is unavailable because no substantive review with assumed editorial responsibility occurred, disclosure would be required. Either way the case is instructive: a workflow with genuine substantive review would have caught the recommendation — and a label is a far cheaper failure mode than the story that followed.
Incident 10 — Gannett / USA Today, 2023. The garbled sports roundups. AI-generated high-school sports summaries containing errors and awkward stock phrases were published across Gannett titles. Gannett then paused the experiment.14 Article 50 analysis: local sports reporting sits at the boundary of “matters of public interest” — assess it, do not assume it out. The more durable lesson is procedural: an organisation that cannot say who reviewed which piece, what was substantively checked, and who assumed editorial responsibility will struggle to rely on the exception at all. Absence of documentation is not automatically absence of the exception, but it is a serious evidentiary weakness — and the exemption is evidentiary before it is substantive.
Part 4 — The 2 December cliff
The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July.15 It deferred the Annex III high-risk regime substantially. Inside Article 50 it changed exactly one thing.
Article 50 applies from 2 August 2026 to all in-scope systems regardless of when they were placed on the market. The Omnibus grandfathers only the Article 50(2) marking obligation, for generative systems placed on the market before that date, to 2 December 2026 (paragraphs 153–154).2 The wider misreading of that date is taken apart in The AI Act Delay Is Not a Reprieve.
Three consequences that are easy to miss:
- Systems that are partly interactive and partly generative benefit from the transition only for the marking obligation — the 50(1) interactive-disclosure duty is not extended.
- Two identical generative systems, one placed on the market before and one on or after 2 August 2026, are on different timelines for the 50(2) marking duty — the transition extends nothing else in Article 50. The placing-on-the-market date is now a compliance-critical record.
- Pre-existing text re-published on or after 2 August 2026 must be labelled, even though it need not have been labelled when first generated.
Part 5 — Demonstrating compliance
The Code of Practice
The Code of Practice on Transparency of AI-generated Content was published on 10 June 2026. The Commission concluded on 8 July 2026 that it adequately covers the obligations in Article 50(2), (4) and (5), and the AI Board adopted its adequacy assessment the following day. It has two sections — Section 1 for providers (marking and detection) and Section 2 for deployers (labelling of deepfakes and text).16
Signatories may rely on its measures to demonstrate compliance with 50(2), (4) and (5) regardless of which national authority supervises them, and join the Signatory Taskforces. Non-signatories must demonstrate compliance by other adequate means, assessed individually by each market surveillance authority, and can expect more detailed information requests; the Guidelines advise a gap analysis against an adequate code in any event (paragraphs 146–150). Where no code is deemed adequate, the Commission may set common rules by implementing act.
There is no code covering 50(1) or 50(3). For those, you determine adequate measures yourself against the Guidelines.
The EU icons
Three icons — Basic, Fully AI-Generated, Partially AI-Modified — each in four variants: black, white, black at 50% transparency and white at 50% transparency, in SVG and PNG, free to use without attribution.5 User testing found performance improved across all measures when the icon was accompanied by a text label, so pair them.
Placement commitments in Section 2 of the Code: perceivable and distinguishable at the latest at first exposure; placed where no intervening overlay elements exist; directly embedded in the content (except creative works) unless an equivalent alternative such as a UI overlay exists; and visible when the content is reshared or downloaded. Accessibility: clearly visible size, plain language, alt text or ARIA labels, and — where the disclosure is time-limited — displayed long enough for users with cognitive or processing difficulties to read it.
Using the icons does not by itself establish compliance.
Part 6 — Enforcement
Authorities (paragraph 151): Member State market surveillance authorities within the Regulation (EU) 2019/1020 system; the AI Office for systems built on a GPAI model from the same provider; the EDPS for EU institutions. Any affected person can lodge a complaint.
Penalties (paragraph 152): up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher; up to €750,000 for EU institutions, bodies and agencies. For SMEs and start-ups the applicable ceiling is whichever of the percentage or the fixed amount is lower, with small-mid-cap proportionality.
That last asymmetry is frequently reported incorrectly. For a large enterprise the ceiling is the higher of the two figures; for an SME it is the lower.
Part 7 — What to build
- Inventory every AI system you provide and every AI system you deploy, including embedded features in SaaS you already licence.
- Assign the role per system — provider, deployer, or both (paragraph 15). Check whether any retraining you have done made you a provider (Section 2.3).
- Map to paragraphs — 50(1), 50(2), 50(3), 50(4). Expect several per system.
- Screen Article 5 first for anything touching emotions or biometrics. Prohibition beats transparency.
- Record placing-on-the-market dates for every generative system.
- Audit your interactive disclosure wording against paragraph 38’s list of five insufficient formulations.
- Split your text pipeline twice: first at the standard-editing line for the provider’s 50(2) duty — translation and formatting on one side, summarisation and paraphrase on the other; then again at the editorial-responsibility line for the deployer’s 50(4) duty, which the first split does not answer.
- Formalise editorial control — named reviewers with subject-matter competence, substantive review including fact-checking, a person holding editorial responsibility whose contact details are publicly findable, an audit trail, and, as a conservative internal control, a hard rule that nothing goes back through an AI tool after sign-off — what matters legally is that no further substantive AI intervention occurs.
- Test label persistence — screenshot it, reshare it, download it. Persistence through resharing and download is a concrete commitment for Code signatories; for everyone else it is strong evidence that the disclosure genuinely reaches each person at first exposure, which is what Article 50(5) requires.
- Add a re-publication checkpoint so migrations and newsletter re-runs trigger the paragraph 153–154 analysis.
- Decide on the Code of Practice, and either sign or document your equivalently adequate alternative.
- Push it into procurement: marking method and interoperability, detectability tooling, placing-on-the-market date, 2 December readiness, Code signatory status, and a contractual commitment that visible-disclosure capability is exposed to you as deployer.
The operational, week-by-week version of this list — inventory, role, notice, publication check, supplier evidence, decision gate — is set out in Article 50 Implementation Strategy: A Seven-Step Guide.
Closing
The Guidelines are non-binding, and only the Court of Justice can give an authoritative interpretation — the Commission says so itself at paragraph 5. But they are the Commission’s official reading and the reference point market surveillance authorities are expected to work from, and they are unusually generous with worked examples: a flying sphinx, mice debating cheese, an in-car navigation voice, a robotic companion pet, a code-review assistant, a witness-statement chatbot.
Those examples exist because the Commission understood something that the summary carousels have not caught up with: Article 50 is not a rule about labelling. It is a classification exercise with a labelling consequence. The organisations that survive the first enforcement cycle will be the ones that can produce the classification — system by system, paragraph by paragraph, with the exception rationale written down and dated.
Forty cases will not cover your estate. But if you can answer all forty, you can answer yours.
Sources
Verification note
Paragraph references follow the Commission’s own numbering in the Guidelines. The substantive claims in Parts 1, 2 and 4–6 — including paragraphs 113, 116–124, 133–154, and the enforcement and penalty framework — were checked against the official Guidelines PDF in an independent second-source review before publication.
Two limitations remain, stated openly:
- Some pinpoints are ranges rather than single paragraphs. Where the Guidelines place worked examples in unnumbered lists following a numbered paragraph — as with the standard-editing examples after paragraphs 90–92 — this article cites the range. Before relying on a borderline classification, open the Guidelines at the range cited and read the example list itself.
- Footnote 3 rests on the publicly indexed portion of the Bird & Bird analysis, not on a full read of that article.
Part 3 describes documented incidents that pre-date the application of Article 50 and were not governed by it. The Article 50 analysis attached to each is counterfactual, illustrative and fact-sensitive — it is not an allegation that any named organisation breached the AI Act.
This article is not legal advice.
-
Regulation (EU) 2024/1689 (AI Act), Article 50; OJ L, 12 July 2024, CELEX 32024R1689. https://digital-strategy.ec.europa.eu/en/policies/guidelines-transparency-ai-generated-content ↩
-
European Commission, Guidelines on the implementation of the transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689, adopted and published 20 July 2026, Communication C(2026) 5054, 51 pages. Landing page: https://digital-strategy.ec.europa.eu/en/library/guidelines-transparency-obligations-providers-and-deployers-ai-systems — official PDF: https://ec.europa.eu/newsroom/dae/redirection/document/131215 ↩ ↩2 ↩3 ↩4 ↩5 ↩6 ↩7 ↩8
-
Bird & Bird, European Commission adopts final Guidelines on AI Act Article 50 transparency obligations — first impressions, July 2026, https://www.twobirds.com/en/insights/2026/european-commission-adopts-final-guidelines-on-ai-act-article-50-transparency-obligations-first-impr ↩ ↩2
-
European Commission, Questions & Answers — Transparency obligations under Article 50 of the AI Act, last updated 24 July 2026, https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act ↩ ↩2 ↩3
-
European Commission, EU Icons for labelling AI-generated content, last updated 20 July 2026, https://digital-strategy.ec.europa.eu/en/policies/eu-icons-labelling-ai-generated-content ↩ ↩2
-
CNN Business, Arup revealed as victim of $25 million deepfake scam involving Hong Kong employee, 16 May 2024, https://www.cnn.com/2024/05/16/tech/arup-deepfake-scam-loss-hong-kong-intl-hnk ; AI Incident Database, Incident 634, https://incidentdatabase.ai/cite/634/ ↩
-
Harvard Kennedy School Misinformation Review, Beyond the deepfake hype: AI, democracy, and “the Slovak case”, https://misinforeview.hks.harvard.edu/article/beyond-the-deepfake-hype-ai-democracy-and-the-slovak-case/ ; AI Incident Database, Incident 573, https://incidentdatabase.ai/cite/573/ ; Schneier on Security, Deepfake Election Interference in Slovakia, https://www.schneier.com/blog/archives/2023/10/deepfake-election-interference-in-slovakia.html ↩
-
Federal Communications Commission, FCC Fines Man Behind Election Interference Scheme $6 Million, 26 September 2024, https://docs.fcc.gov/public/attachments/DOC-405811A1.pdf ; NBC News, Telecom company agrees to $1M fine over Biden deepfake, https://www.nbcnews.com/politics/2024-election/telecom-company-agrees-1-million-fine-biden-deepfake-rcna167564 ↩
-
Engadget, CNET had to correct most of its AI-written articles, 25 January 2023, https://www.engadget.com/cnet-corrected-41-of-its-77-ai-written-articles-201519489.html ; The Washington Post, CNET used AI to write articles. It was a journalistic disaster, 17 January 2023, https://www.washingtonpost.com/media/2023/01/17/cnet-ai-articles-journalism-corrections/ ↩
-
CNN Business, Sports Illustrated deletes articles published under fake author names and AI-generated profile photos, 27 November 2023, https://www.cnn.com/2023/11/27/media/sports-illustrated-deletes-articles-fake-author-names-ai-profile-photos/index.html ; CBS News (publisher’s response), https://www.cbsnews.com/news/sports-illustrated-denies-using-ai-fake-writers-to-produce-stories/ ↩
-
NBC News, Coca-Cola causes controversy with AI-generated ad, 18 November 2024, https://www.nbcnews.com/tech/innovation/coca-cola-causes-controversy-ai-made-ad-rcna180665 (also reporting the Toys “R” Us spot); Forbes, Coca-Cola Sparks Backlash With AI-Generated Christmas Ad, Again, 4 November 2025, https://www.forbes.com/sites/danidiplacido/2025/11/04/coca-cola-sparks-backlash-with-ai-generated-christmas-ad-again/ ↩ ↩2
-
Yahoo News / The Cool Down, McDonald’s pulls controversial Christmas commercial within days of being uploaded, https://www.yahoo.com/news/articles/mcdonalds-pulls-controversial-christmas-commercial-044500195.html (single syndicated source; the incident is illustrative only and no legal proposition in this article rests on it) ↩
-
CBS News, Microsoft removes AI-generated travel guide recommending Ottawa food bank, 21 August 2023, https://www.cbsnews.com/news/microsoft-ai-travel-guide-ottawa-food-bank/ ↩
-
Axios Columbus, Dispatch pauses AI sports writing program, 28 August 2023, https://www.axios.com/local/columbus/2023/08/28/dispatch-gannett-ai-newsroom-tool ; The Washington Post, Gannett halts AI-written sports recaps after readers mocked the stories, 31 August 2023, https://www.washingtonpost.com/nation/2023/08/31/gannett-ai-written-stories-high-school-sports/ ↩
-
Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ 24 July 2026, in force 27 July 2026, https://eur-lex.europa.eu/eli/reg/2026/1744/oj ; Lewis Silkin, The Digital Omnibus on AI enters into force today, 27 July 2026, https://www.lewissilkin.com/insights/2026/07/27/the-digital-omnibus-on-ai-enters-into-force-102nedo ↩
-
European Commission, Code of Practice on Transparency of AI-generated Content, published 10 June 2026, https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content ; European Commission, Commission Opinion on the assessment of the Code of Practice on Transparency of AI-generated content, published 9 July 2026, https://digital-strategy.ec.europa.eu/en/library/commission-opinion-assessment-code-practice-transparency-ai-generated-content ↩