From 2 August 2026, Article 50 of the EU AI Act becomes applicable. It is the provision that deals with transparency toward the people who see, hear, or talk to AI output. Most coverage of the Act focuses on high-risk system rules. Article 50 is different. It applies far more broadly, to any provider or deployer whose system talks to a person or generates synthetic content, and it is the part most content, marketing, and AI-product teams will feel first.
Here is what the article actually requires, what the European Commission has published to help meet it, and where document and content provenance fits, and where it does not.
What Article 50 requires
The article sets out four separate obligations, each aimed at a different situation:
- Direct interaction disclosure. Providers of AI systems intended to interact directly with natural persons must ensure people are informed they are dealing with an AI system, unless this is obvious from the circumstances.
- Machine-readable and detectable marking. Providers of systems that generate synthetic audio, image, video, or text content must ensure the output is marked in a machine-readable format and detectable as artificially generated or manipulated. Both properties are required, a label a person can read is not sufficient on its own if the content cannot also be detected as synthetic by a downstream system.
- Public-interest disclosure for deepfakes and AI text. Deployers of systems generating deepfakes, and deployers of AI systems generating or manipulating text published to inform the public on matters of public interest, must disclose that the content has been artificially generated or manipulated.
- Emotion-recognition and biometric-categorization notice. Deployers of emotion-recognition or biometric-categorization systems must inform the natural persons exposed to them of the system's operation.
Each obligation carries its own exceptions and edge cases in the full article text, and the exact technical form the marking must take is still being worked out in practice rather than fixed by the regulation itself.
The Commission's Code of Practice
On 10 June 2026, the European Commission published a Code of Practice on Transparency of AI-Generated Content. It is a voluntary framework, not a binding standard, aimed at helping providers and deployers meet the marking and disclosure duties in Article 50(2), (4), and (5). Signing up to the code is one route to demonstrating good-faith compliance, but it is not the only route, and it does not replace the underlying legal obligation. Organisations can meet Article 50 through other technical and organisational measures as long as the outcome (informed users, detectable synthetic content, disclosed deepfakes) is achieved.
For the current text of the obligation itself, the AI Act Service Desk's Article 50 page is the Commission's own reference point and is worth checking directly rather than relying on secondary summaries, including this one.
Enforcement and penalties
Article 50 is enforced by national market surveillance authorities in each EU member state, not by a single central regulator. Non-compliance can result in fines of up to fifteen million euros or 3% of worldwide annual turnover, whichever is higher. That places transparency violations in the same penalty band as several other AI Act obligations, well above what most companies budget for a documentation gap.
Where provenance sealing fits, and where it does not
This is where we want to be precise rather than promotional. A qualified, timestamped seal on a document or media file establishes two things: that a specific file existed in a specific state at a specific time, and, at the QES tier under ZertES and eIDAS, who created or authorised it. That is a form of content provenance, and provenance is adjacent to what Article 50(2) is asking for: a way to tell, after the fact, whether a piece of content is what it claims to be.
It is not the same thing as the machine-readable, detectable AI-content marking Article 50(2) describes, and it should not be presented as such. The Act is asking for a marking mechanism embedded in or attached to the generated content itself, of the kind the Commission's Code of Practice and related technical standards work are still specifying. A Swiss Trust Layer seal proves what a document was and, at the qualified tier, who stands behind it. That is complementary evidence an organisation can point to when demonstrating good-faith provenance practices around AI-adjacent content such as training records, model documentation, or disclosure logs, not a substitute for whatever specific technical marking standard applies to the AI-generated output itself.
Teams building AI products who also generate or rely on datasets should also look at how training-data provenance is documented and defended, a related but separate obligation under the Act's data-governance provisions. Our AI dataset provenance page covers that side of the compliance picture in more detail.
What to do before 2 August
Three practical steps for teams with any AI-facing surface. First, map every system in your product that interacts directly with a user or generates audio, image, video, or text, and note which of the four obligations applies to each. Second, decide whether you are relying on the Commission's Code of Practice, your own technical measures, or a combination, and document that decision. Third, keep a dated record of what your disclosure and marking practices were at each point in time, since a dispute about compliance will turn on what was actually in place on a given date, not on a policy written after the fact.
Article 50 rewards organisations that can show their work. A clear, timestamped record of your compliance decisions is worth having regardless of which specific marking technology you end up standardising on.






