EU AI Act Article 50: A Practical Transparency Checklist for AI Startups.
The transparency duties in Article 50 of the EU AI Act have applied since 2 August 2026. They affect startups that provide systems which interact directly with people or generate synthetic content, and startups that deploy emotion recognition, biometric categorisation, deepfakes, or certain AI-generated public-interest text.
A generic “AI-powered” badge cannot address all these duties. Article 50 distinguishes provider duties from deployer duties, machine-readable marking from human-visible disclosure, and broad rules from narrow exceptions. A startup may occupy more than one role across different features, customers, and publications.
This checklist draws on the final legal text, the European Commission’s July 2026 guidelines, and the voluntary Code of Practice on Transparency of AI-generated Content to help you identify and prioritise compliance issues early. It is not a substitute for legal advice on a specific system, market, or exception.
WHAT CHANGED IN 2026
The consolidated EU AI Act applies Article 50 from 2 August 2026. The Commission published final Article 50 guidelines in July 2026 and the final Code of Practice on Transparency of AI-generated Content in June 2026. The rules are therefore in force and supported by implementation guidance.
One narrow transition remains. Providers of synthetic-content systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with the machine-readable marking duty in Article 50(2). The Commission’s Article 50 questions and answers state that the grace period does not extend the other Article 50 duties, and content generated before 2 August 2026 does not have to be labelled retroactively.
Check the live product against the duties that now apply. If the company relies on the December transition, document why the system qualifies and what will be completed by the deadline.
START WITH THE ROLE MAP
Article 50 assigns obligations according to what an organisation does. The organisation’s own description of its role does not determine its duties. A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its authority, except for personal non-professional activity.
A startup selling a branded support agent may be the provider of that AI system even when it uses a third-party general-purpose model. The customer operating the agent may be its deployer. The same startup can also be a deployer when its marketing team uses a generative tool to publish content. Record the role for each feature and use case rather than assigning one label to the whole company.
Check the territorial scope too. The Act can apply to providers outside the EU that place systems on the EU market and, in defined circumstances, where an AI system’s output is used in the EU. Do not treat company location as the scope test.
THE FOUR ARTICLE 50 TRIGGERS
1. Direct interaction with people: provider duty
If an AI system is intended to interact directly with natural persons, the provider must design it so people are informed that they are interacting with AI, unless that fact is obvious to a reasonably well-informed, observant, and circumspect person in the circumstances. Examples include chatbots, conversational agents, and avatars. Assess whether the interaction is obvious in its actual context before relying on that exception.
2. Synthetic audio, image, video, or text: provider duty
Providers of systems that generate synthetic content must make outputs machine-readable and detectable as artificially generated or manipulated. The technical solution must be effective, interoperable, robust, and reliable as far as technically feasible, considering the content type, cost, and state of the art. Standard assistive editing and changes that do not substantially alter the input or its semantics can fall outside this duty.
3. Emotion recognition or biometric categorisation: deployer duty
Deployers must inform natural persons exposed to an emotion-recognition or biometric-categorisation system that it is operating. Personal-data processing must also comply with applicable data-protection law. A notice cannot make an otherwise prohibited or unlawful use permissible, so include this check in the startup’s assessments of prohibited practices, privacy, and high-risk systems.
4. Deepfakes and some public-interest text: deployer duty
A deployer must disclose AI-generated or manipulated image, audio, or video that constitutes a deepfake. It must also disclose AI-generated or manipulated text published to inform the public on matters of public interest, unless the text has undergone substantive human review or editorial control and a natural or legal person holds editorial responsibility. Superficial grammar or formatting checks do not amount to that review.
Evidently artistic, creative, satirical, fictional, or analogous deepfake works receive a narrower disclosure treatment that should not hamper the display or enjoyment of the work. Record how the work meets the definition and why its context justifies this treatment. Calling it “creative” is not enough.
TWO DIFFERENT TRANSPARENCY LAYERS
Article 50 creates two complementary product requirements. Machine-readable provenance under Article 50(2) helps systems detect that content was generated or manipulated by AI. Human-visible disclosure under Articles 50(1), (3), and (4) helps the person interacting with or exposed to the system understand what is happening.
Meeting one requirement does not automatically satisfy the other. The Commission says a deployer cannot rely only on an embedded machine-readable mark when a clear deepfake disclosure is required. A visible label does not replace a provider’s output-marking obligation either. Preserve both layers through export, download, transformation, syndication, and re-sharing where the relevant duty requires it.
Article 50(5) sets the common delivery standard: information must be clear and distinguishable, provided by the first interaction or exposure at the latest, and conform to applicable accessibility requirements. The Commission’s optional EU icons for AI-generated content can support deployer labelling; an icon alone, however, does not establish compliance.
THE EIGHT-STEP CHECKLIST
1. Inventory EU-facing AI use cases
List every feature, model, workflow, channel, and content type that can reach a person in the EU or produce output used there. Include internal tools that publish externally, customer-configured features, beta paths, exports, APIs, and white-labelled deployments. Record the launch date and material version changes so you can assess whether the transition applies.
2. Assign roles and Article 50 triggers
For each use case, identify the provider, deployer, model provider, distributor, and customer. Then test Articles 50(1) to 50(4) separately. Record why a duty applies, why you rely on an exception, and who is responsible for the decision. Reassess these roles when a customer rebrands the system, the startup changes control over deployment, or a feature moves from assistance to autonomous generation.
3. Design the AI-interaction notice
Show the disclosure by the first interaction at the latest. Test the wording and placement in every supported language, channel, and modality, including voice and embedded widgets. Check that users still receive the notice if onboarding fails, they arrive through a deep link, or they return for another session. Do not bury the only disclosure in terms and conditions.
4. Implement and preserve machine-readable provenance
Determine which synthetic outputs require marking and what upstream models already provide. Specify how marks are created, detected, retained through processing, and tested after export. Measure robustness across compression, resizing, transcoding, copying, screenshots, and likely customer workflows. If an upstream service cannot support the obligation, address the risk in your supplier choice and system architecture. The requirement still applies.
5. Label deepfakes and public-interest text
Check image, audio, video, and text before publication. Ask whether the content resembles something real and may falsely appear authentic, or whether text is published to inform the public on a matter of public interest. Where disclosure is required, make it perceivable at first exposure and check that it remains so when people download or share the content. If you rely on the text exception, retain evidence of substantive human review, editorial control, and accountable editorial responsibility.
6. Handle emotion and biometric notices separately
Identify who is exposed, where the system operates, whether processing is live or retrospective, and how each person is informed. Review the notice alongside privacy, lawful basis, data-protection impact, prohibited practices, worker protections, and sector-specific requirements. Include the Article 50 disclosure in the overall assessment; it cannot determine the outcome on its own.
7. Test timing, clarity, and accessibility
Verify the disclosure with keyboard navigation, screen readers, captions, audio alternatives, contrast checks, zoom, mobile layouts, and supported languages. Test first exposure rather than only the settings page. Ask a person unfamiliar with the product what they believe is AI-generated, what the system is doing, and where further information can be found.
8. Retain evidence and monitor change
Keep the role map, legal rationale, interface copy, accessibility evidence, marking tests, supplier commitments, content-review records, release approvals, complaints, and corrective actions. Assign someone to maintain these records and specify when to reassess compliance. Replacing a model, adding a modality, rebranding, entering a new market, changing the audience, or altering the publishing workflow can affect which duties apply, even if the feature keeps the same name.
For Articles 50(2), (4), and (5), decide whether to sign the voluntary Code of Practice. The Commission and AI Board have assessed it as an adequate compliance tool. Signatories can rely on its measures; organisations using another route must be ready to demonstrate that their alternative is adequate. The code does not replace the Act or the guidelines.
A FAST FEATURE-LEVEL DECISION TEST
- Does the feature qualify as an AI system and fall within the Act’s scope? If no, record the basis and revisit after material changes.
- Are we the provider, deployer, or both for this use case? Name the other actors and confirm contracts reflect the operational split.
- Does it interact directly with people? If yes, design a first-interaction AI notice unless the interaction is demonstrably obvious.
- Does it generate synthetic audio, image, video, or text? If yes, test provider-side machine-readable marking and any narrow exemption.
- Does our use expose people to emotion recognition or biometric categorisation? If yes, add the deployer notice and complete the separate legality and privacy reviews.
- Are we publishing a deepfake or unreviewed public-interest text? If yes, add a clear human-visible disclosure at first exposure.
- Can we prove timing, accessibility, robustness, and ownership? If no, the product is not operationally ready.
COMMON STARTUP MISTAKES
- Avoid treating every AI use as equivalent. Article 50 targets defined systems, outputs, roles, and contexts.
- Using a third-party model does not necessarily make the startup only a deployer. A branded downstream system may create provider responsibilities.
- One generic website notice may not meet the product’s requirements for timing, modality, and first exposure.
- Do not confuse watermarking with disclosure. Machine detectability and human perception are separate controls.
- Check which rule applies before labelling AI-assisted text. The deployer rule targets published public-interest text and contains a substantive-review exception; assess provider marking separately.
- A human click does not amount to human review. The Commission expects knowledgeable, substantive examination and real editorial authority.
- Do not apply the December deadline to all of Article 50. The transition is limited to Article 50(2) for systems placed on the market before 2 August 2026.
- Continue the compliance assessment beyond disclosure. Article 50 applies alongside other AI Act, data-protection, consumer, accessibility, employment, and sector rules.
IN SUMMARY
Article 50 now applies to how you build and operate the product. Start by mapping the company’s role feature by feature. Separate provider duties from deployer duties, and machine-readable provenance from human-visible disclosure. Build notices into the first interaction or exposure, preserve marks through real content workflows, and retain evidence for every exception and review decision.
Adding more legal copy will not cover all these tasks. Use a repeatable process to coordinate product design, content publishing, accessibility checks, supplier management, release approvals, and audit evidence. Update that process as models, features, customers, and guidance change.
SOURCES AND FURTHER READING
- European Union: Regulation (EU) 2024/1689, consolidated text of 27 July 2026
- European Commission: Guidelines on transparency obligations for providers and deployers of AI systems
- European Commission: Transparency obligations under Article 50 of the AI Act: questions and answers
- European Commission: Code of Practice on Transparency of AI-generated Content
- European Commission: EU icons for labelling AI-generated content
- European Commission AI Act Service Desk: Timeline for the implementation of the EU AI Act
RELATED INSIGHTS AND RESOURCES
Continue exploring this topic with these related insights and practical resources.
INTRIGUED?
For more information on how our advisory services can help you accelerate your entrepreneurial journey, please contact us to arrange an introductory meeting or
Book a Discovery Session now!
Get to know us. Put us to the test.