EU AI Act Article 50

Label your AI content,
and prove you did

Article 50 applies from 2 August 2026. Here is what you have to label, why a label on its own leaves the burden with you, and how a sealed declaration turns that claim into evidence.

The transparency obligations sit in Article 50 of Regulation (EU) 2024/1689 . Providers must mark generative output as machine-readable. Deployers, meaning whoever publishes the result, must disclose it.

Sealed AI declaration

What a counterparty receives

Verified
File hashSHA-256, bound to one version
DeclarationAI assisted
Qualified timestampIssued by a QTSP
Verifiable byAnyone, without an account

The difference: a label lives on your site and is edited by you. This record is fixed by a third party at a moment you cannot move afterwards.

What Article 50 requires

Article 50 of the EU AI Act requires that people are told when content they see was generated or manipulated by an AI system. Synthetic audio, image, video and text must be marked in a machine-readable format, deep fakes must be disclosed, and AI-generated text published to inform the public on matters of public interest must be disclosed. It applies from 2 August 2026.

Providers must mark

Whoever puts the AI system on the market has to build the marking in. Output of a generative system must be machine-readable as artificially generated or manipulated.

Deployers must disclose

Whoever uses the system and publishes the result has to disclose. If you are a marketing team, an agency, a publisher or an in-house content function, this one is yours.

The content in scope is broader than most teams assume. It is not only the obvious synthetic image. It reaches audio, video and text, it names deep fakes specifically, and it reaches text published to inform the public on matters of public interest. Disclosure has to reach the person at the point they encounter the content, not buried where nobody looks.

The date is fixed. The AI Act entered into force in 2024 and its obligations phase in on a schedule. The transparency obligations in Article 50 are the ones that arrive on 2 August 2026.

The gap nobody mentions

A label is a claim. You are stating something about your own content, in your own words, on your own site. That is what the rule asks for. What it is not, is proof of itself.

A label

  • Written by you, on a surface you control
  • Can be edited after the fact
  • Says what you claim happened
  • Holds until somebody has a reason to test it

A sealed record

  • Bound to one exact file by a cryptographic hash
  • Timestamped by a third party you do not control
  • Shows what was made, by whom, and when
  • Checkable without an account and without contacting you

Three questions a label cannot answer

01

What exactly was published?

Not the current version on the page. The version that actually went out.

02

Who produced it, and what touched it?

Which parts were generated, which a model edited, which a person wrote.

03

When was that true?

A statement made today about work done in March is a memory, not a record.

Where teams think their evidence lives

File modified dates Email threads Project management history Cloud version history

Each of these is held by the party making the claim, and each can be edited by that party. They are useful internally. They are weak the moment their value depends on somebody else believing them.

The four AI declarations

Disclosure is about accuracy, not about having said something. Four statements cover nearly everything a publishing team produces, and picking the wrong one is a worse position than picking none.

AI generated

A model produced the content, with little or no human authorship in the result.

AI modified

A human made the work, then a model altered it enough to change what it shows.

AI assisted

A human authored the work and used a model as a tool along the way. This is what most teams actually are.

Human authored

No model involvement worth declaring, and now that is something you can record rather than simply assert.

Most content produced by a working team lands on AI assisted. A person wrote it, a model helped somewhere in the process, and the result is still the work of that person. Declaring that plainly is more defensible than declaring nothing and being asked about it later.

How the seal closes it

A sealed declaration turns the statement into a record that somebody outside your organisation can check. Four parts, in order.

Step 1

The file is hashed

A cryptographic hash is computed from the file itself. Change one pixel or one character and the hash no longer matches.

Step 2

The declaration is attached

Which of the four statements applies is recorded alongside the hash, so the claim and the artefact travel together.

Step 3

A qualified timestamp

A Qualified Trust Service Provider timestamps the hash and the declaration, fixing when the record existed.

Step 4

A certificate anyone can check

A third party verifies it without an account and without contacting you. The only part your counterparty sees.

Remove any one of the four and the record weakens in a specific way. Without the hash it is not tied to a version. Without the declaration it proves existence but says nothing about production. Without the timestamp the date is your word. Without third-party verification the recipient still has to trust you, which is the problem you were trying to solve. Verify a sealed document to see what the recipient sees.

Primary sources: EU AI Act · eIDAS · ZertES · Swiss Code of Obligations Art. 14 · Berne Convention

The trust basis

Three separate legal frameworks sit underneath a sealed declaration. They do different jobs and it is worth keeping them apart.

eIDAS, for the EU

Regulation (EU) No 910/2014 sets the framework for electronic signatures, seals and timestamps across the member states. A qualified electronic timestamp issued by a Qualified Trust Service Provider carries a legal presumption as to the date and time it indicates and the integrity of the data it is bound to.

eIDAS on EUR-Lex

ZertES and Art. 14 para. 2bis of the Swiss Code of Obligations

ZertES governs certification services for electronic signatures under Swiss federal law. Handwritten equivalence itself comes from Art. 14 para. 2bis of the Swiss Code of Obligations, which puts a qualified electronic signature with a qualified timestamp on the same footing as a signature by hand. The two are frequently collapsed into one citation. They are separate instruments and the equivalence rule lives in the Code of Obligations.

The Berne Convention, for the underlying rights

Copyright in the work exists on creation, without any registration formality, in over 180 countries. Berne gives you the right. It does not give you a record of when you had it, which is the job the timestamp does.

Berne Convention at WIPO

eIDAS

Legal presumption on qualified timestamps across the EU

ZertES with Swiss CO Art. 14 para. 2bis

Handwritten equivalence under Swiss federal law

Berne Convention

Copyright on creation in over 180 countries, no formality

Article 50 asks you to disclose. Copyright decides who owns the work. The qualified timestamp is what lets you answer both questions with the same record instead of two separate arguments.

Frequently asked questions

When does Article 50 apply?

From 2 August 2026. The AI Act entered into force in 2024 and its obligations phase in on a schedule set out in the regulation. Article 50 carries the transparency obligations and that is the date they start to apply.

Does it cover text?

Yes. Article 50 reaches synthetic audio, image, video and text. It also names deep fakes specifically, and AI-generated or manipulated text published to inform the public on matters of public interest.

Does it apply to a Swiss company publishing into the EU?

Switzerland is not an EU member state, so the regulation does not apply to a Swiss company by virtue of where it is registered. What matters is where the output lands. A Swiss company publishing AI-generated content into the EU market should treat itself as in scope and take advice on its specific position rather than assume the border helps.

Is a website notice enough?

A notice is a disclosure and disclosure is what the rule asks for. It is not a record. It states what you say happened. If the statement is ever tested, what is asked for is what was made, by whom and when, and a notice on your own site does not answer that.

What if AI only edited the work?

That is the AI modified case, and it is a real declaration rather than a lesser one. If a model altered the work enough to change what it shows, say so. If a model was used as a tool while a human authored the result, that is AI assisted. The distinction matters because accuracy is the obligation.

Who has to prove what?

The party making the statement is the party asked to support it. If you publish content and declare how it was produced, the evidence sits with you. That is why the practical question is not whether you labelled it, but whether you can produce something a third party can check.

Not sure whether any of this reaches your content?

A few questions about what you publish and where it goes will tell you whether Article 50 applies to you, and what evidence you would need if somebody asked.

Already sealing? Verify a document

快速解答

欧盟人工智能法案第 50 条从何时开始适用?

《条例(欧盟)2024/1689》第 50 条的透明度义务自 2026 年 8 月 2 日起适用。

第 50 条是否同时涵盖文本和图像?

是。第 50 条涵盖合成的音频、图像、视频和文本,并单独规定了深度伪造以及为向公众通报公共利益事项而发布的文本。

网站上的一则声明是否足以满足合规要求?

声明是一种披露,不是记录。它陈述的是你所说的情况,并未显示内容由谁在何时制作,而这正是该陈述受到检验时你需要拿出的东西。

谁需要证明什么?

作出陈述的一方就是被要求为其提供支持的一方。如果你发布内容并声明其制作方式,该声明的证据由你承担。