Article 50 of the EU AI Act went live on 2 August. Most teams had it filed under "we'll deal with it later."
Wrong file. The Digital Omnibus pushed the high-risk regime out to December 2027. It did not touch this one. What went live is the transparency regime: chatbots that have to tell you they're chatbots, deepfakes that have to be labelled, synthetic content that has to be detectable as synthetic.
It reads like the easy one: a notice, a watermark, a line of copy at the top of a chat window. That is precisely why it is the obligation most organisations are going to get wrong.
What is Article 50 of the EU AI Act?
Four things, in plain terms.
AI-interaction disclosure (50(1)). Put an AI system in front of a person, a chatbot, a voice assistant, an agent, even a form, and they have to know they're dealing with a machine, unless it's obvious from context.
Emotion recognition and biometric categorisation (50(3)). Deploy it, and you tell the people exposed to it.
Deepfake labelling (50(4)). Generate or manipulate a deepfake and you label it.
AI-generated public-interest text (50(4)) and synthetic-content marking (50(2)). Publish AI-generated text on a matter of public interest and you disclose it, unless a human takes genuine editorial responsibility. Build a system that generates synthetic audio, image, video or text and you mark that output in a machine-readable way so detection tools can spot it. Providers already on the market have until 2 December 2026 to finish that piece.
None of this is intellectually hard. A product team could be briefed on it in an afternoon. The catch: every one of these is a control that has to keep working 24/7/365, under load, under adversarial pressure, across every model update shipped after go-live.
Why a disclosure is not the same thing as a control
A disclosure you add once is a feature. A disclosure that is still present after a user has spent forty turns trying to talk your assistant into "roleplaying as a human agent," that's a control. Those are not the same thing, and Article 50 is written about the second one.
The Commission's guidelines and the final Code of Practice on transparency are explicit: this is expected to be designed in and maintained, not bolted on and forgotten. The obligation is not "display a notice." It is "the person must be informed," an outcome you have to hold to every chat, every engagement, not a checkbox ticked once.
I run an assurance company, so I'll admit my bias up front: sometimes LLMs don't. I see the world through what breaks in production. But you don't need to share the bias to see the failure mode:
A "this is an AI" banner that a prompt-injection attack strips out.
A deepfake watermark a downstream compression step quietly removes.
A bank with "we may use AI in this process" buried in a paragraph.
Every one of these organisations believes it is compliant. Every one of them isn't. Nobody tested whether the control holds. Nobody is watching whether it still does.
What is the fine for breaching Article 50?
Breaching Article 50 sits in the second tier of the Act's penalty regime. Three tiers, for context:
Prohibited practices: up to €35 million or 7% of global turnover.
Article 50 transparency breaches: up to €15 million or 3%, whichever is higher.
Supplying incorrect information to an authority: up to €7.5 million or 1%.
SMEs and start-ups get the lower of the fixed sum and the percentage, small comfort, but real. None of this is confined to companies with an EU address: the Act reaches any provider or deployer whose AI is placed on the EU market or whose outputs are used in the EU, wherever they're headquartered. A US or UK company serving European users is squarely in scope.
But the headline number is the least interesting part of the penalty regime, and it's the point worth a board sitting with. The fine is not binary. The Act tells regulators exactly what to weigh when setting an amount:
The nature and gravity of the breach.
Whether it was negligent or deliberate.
What was done to mitigate.
Critically, whether measures were in place at all.
Absence of demonstrable controls is an aggravating factor. Demonstrable, contemporaneous controls are a mitigating one.
Which means the real question Article 50 puts to you is not "did you comply?" It's "when a market surveillance authority sends the documentation request, the cheapest, most likely opening move an under-resourced regulator can make, can you show them your evidence?"
That reframes the whole exercise. Compliance here isn't a state you're in. It's evidence you can produce on the day someone asks for it. For the full picture of what the Digital Omnibus does and does not move, see our EU AI Act enforcement tracker. Article 50 is not one of the dates that shifted.
How do you keep an Article 50 control provably compliant?
Holding an Article 50 control operationally comes down to three disciplines, the same three whether the obligation is a chatbot disclosure, a deepfake label, or a form a customer fills in.
Test & Detect. Not whether the notice renders, but whether the disclosure survives the jailbreaks, prompt injections, and edge cases real users will throw at it. Assume someone is actively trying to make your AI pass as human, because on the public internet, someone is.
Protect & Enforce. Monitor the control at runtime. A disclosure that was working at launch and silently degraded three model versions later is worse than no control at all, because it manufactures false confidence. It has to be enforced and watched continuously, not validated once and trusted forever.
Prove & Comply. Keep a dated, audit-ready record that the control was designed in and is operating, the contemporaneous proof that moves you from aggravating to mitigating, and the answer to the documentation request before it lands.
It's the work we do at Disseqt, and I'd be lying if I said building the assurance layer for exactly this wasn't why we exist. But I'd make the same argument if we sold nothing.
Governance without enforcement is shelfware. A policy document that says "we disclose AI interactions" is not assurance. A tested, monitored, evidenced control that demonstrably does so, is.
Bottom Line
Article 50 looks easy. It isn't. The Omnibus bought most organisations sixteen months on high-risk. It bought them nothing on transparency.
That clock is already running. The fines are already live. The regulator's email will not ask whether you meant well. It will ask you to prove it.
A label won't answer that. A control will.
FAQs
What is Article 50 of the EU AI Act?
Article 50 is the EU AI Act's transparency regime. It requires disclosure when a person interacts with an AI system, labelling of deepfakes and AI-generated public-interest text, and machine-readable marking of synthetic audio, image, video and text. It became enforceable on 2 August 2026.
What is the fine for breaching Article 50?
Up to €15 million or 3% of total worldwide annual turnover, whichever is higher. The exact amount depends on the gravity and intent of the breach and, critically, whether the organisation had demonstrable, contemporaneous controls in place.
Who does Article 50 apply to?
Any provider or deployer whose AI system is placed on the EU market or whose output is used by people in the EU, regardless of where the company is headquartered.
What is the deadline for synthetic-content marking?
Providers with systems already on the market have until 2 December 2026 to implement machine-readable marking of AI-generated audio, image, video and text.
How do you turn an Article 50 disclosure into a compliant control?
By applying three disciplines: test the disclosure against adversarial conditions before it ships, monitor it continuously at runtime so drift is caught, and keep dated, audit-ready evidence that the control was designed in and is still operating.




