
The Economics of Enterprise AI Systems
29 September 2026
A customer opens a support window and starts a conversation. A user asks an AI assistant to generate a product description. A platform creates images, summaries or personalised content on demand. From a product perspective, these are very different features, but under the EU AI Act they can all raise transparency questions.
Article 50 of the AI Act introduces specific transparency obligations for certain AI systems, including systems that interact directly with people and systems that generate or manipulate synthetic content. The rules have applied since 2 August 2026, so transparency is no longer just a UX or trust consideration but a compliance requirement. For companies building or operating chatbots, AI assistants and generative features, the question is therefore not simply whether “AI content needs a label”. The answer depends on what the system does, whether the company acts as a provider or a deployer, what kind of output is produced and how users encounter it.
This article explains how Article 50 works, which obligations matter for common commercial AI applications and what companies should review in systems already running in production.
What does Article 50 of the AI Act regulate?
Article 50 is part of Chapter IV of Regulation (EU) 2024/1689 and is titled “Transparency obligations for providers and deployers of certain AI systems”. It does not establish one universal disclosure rule for every use of artificial intelligence. Instead, it addresses several situations in which people should be able to understand that AI is involved:
- Article 50(1) – AI systems designed to interact directly with natural persons, such as chatbots and conversational assistants.
- Article 50(2) – systems that generate synthetic text, images, audio or video, where the focus is on machine-readable marking and detectability of the output.
- Article 50(3) – emotion recognition and biometric categorisation systems.
- Article 50(4) – disclosure of deepfakes and of certain AI-generated or manipulated texts published on matters of public interest.
- Article 50(5) – how and when the required information must be provided.
These obligations are not interchangeable. A chatbot disclosure shown to a customer is different from machine-readable provenance information embedded in generated media, and both differ from a visible disclosure attached to a deepfake. Identifying which part of Article 50 applies is the first step towards compliance.
Do chatbots have to tell users that they are interacting with AI?
For many businesses, Article 50(1) is the most immediately relevant requirement. Providers of AI systems intended to interact directly with natural persons must ensure that those systems are designed and developed so that people are informed that they are interacting with an AI system. The exception is where this is already obvious to a reasonably well-informed, observant and circumspect person, taking into account the circumstances and context of use.
In practice, this covers support chatbots, AI assistants, conversational agents and other interfaces in which a person communicates directly with an AI system. Under Article 50(5), the information must be provided in a clear and distinguishable manner, no later than the time of the first interaction or exposure, and in line with applicable accessibility requirements.
Transparency should therefore be considered when the interaction is designed, not added once the chatbot is already in production. The disclosure may form part of the opening message, the interface or another clearly visible element of the experience, provided that the implementation satisfies the legal requirement in the relevant context.
When can the disclosure be omitted because the use of AI is obvious?
Article 50 does not require a warning in every possible AI interface: the obligation does not apply where it is obvious that the person is interacting with an AI system. That exception should nevertheless be approached carefully, because a product team’s own understanding of how a feature works is not necessarily shared by an ordinary user.
Calling a feature an “assistant”, giving it a name or using an automated interface does not by itself settle whether the AI nature of the interaction is sufficiently obvious. The assessment should consider the entire user journey: how the feature is introduced, what claims are made about it, whether it could reasonably be mistaken for a human and what information the user receives before or during the first interaction.
The practical rule is simple: if a reasonable user could be uncertain whether they are communicating with a person or an AI system, the interface should make this clear.
Provider or deployer: who is responsible under Article 50?
Article 50 assigns different duties to providers and deployers, so the distinction is essential. Under the AI Act, a provider is not necessarily the company that developed the underlying large language model. A provider is an organisation that develops an AI system, or has one developed for it, and places that system on the market or puts it into service under its own name or trademark. A deployer is an organisation or person using an AI system under its authority in a professional context.
This matters for companies commissioning custom AI applications. Imagine that a business hires a software house to build an AI customer assistant based on a third-party foundation model. The fact that OpenAI, Anthropic, Google or another vendor supplies the underlying model does not determine who is the provider of the final AI system. Depending on how the system is developed, branded, supplied and put into service, different parties in the value chain may have different regulatory roles.
AI Act compliance should therefore not begin with a generic privacy notice or a label in the interface. It should begin by mapping the system and establishing who is the provider, who is the deployer and which party is responsible for each requirement.
What Article 50 means for companies building their own AI assistants
A company launching an AI assistant under its own brand should assess Article 50 at product level, not only at the level of the API or model used underneath. If the application communicates directly with customers, Article 50(1) may require the system to make clear that users are interacting with AI. If it also generates text, audio, images or video, Article 50(2) may add technical requirements concerning the output.
This is particularly important in systems combining several capabilities. A single assistant may answer customer questions, create personalised documents, generate images and produce content that is later published elsewhere. Each of these functions can trigger a different transparency analysis, so compliance cannot be handled only at the model-selection stage. The architecture, frontend, content pipeline and publication workflow all affect whether the final system meets the requirements.
Generative AI features: does every AI-generated output need a visible label?
No. This is one of the most important distinctions in Article 50. The Regulation does not require every piece of AI-created content to carry a visible “AI-generated” label.
Under Article 50(2), providers of AI systems, including general-purpose AI systems, that generate synthetic audio, images, video or text must ensure that outputs are marked in a machine-readable format and are detectable as artificially generated or manipulated. The technical solution must be effective, interoperable, robust and reliable as far as technically feasible, taking into account the type of content, implementation costs and the generally acknowledged state of the art.
The obligation does not apply to the extent that an AI system performs an assistive function for standard editing or does not substantially alter the input data provided by the deployer or its semantics. Using AI for minor editorial corrections is therefore not automatically equivalent to generating synthetic content that requires full Article 50(2) marking.
It is also worth separating two concepts often grouped together as “AI labelling”. Machine-readable marking under Article 50(2) is primarily a provider obligation and makes output technically detectable. Disclosure to people appears elsewhere in Article 50: users must be told they are dealing with AI, and deployers publishing certain deepfakes or public-interest texts must disclose their artificial origin. A product may require one, both or neither mechanism. A visible label does not replace technical marking, and machine-readable provenance does not inform a human user.
What are the rules for deepfakes and public-interest texts?
Article 50(4) requires deployers of AI systems that generate or manipulate image, audio or video content constituting a deepfake to disclose that the content has been artificially generated or manipulated. For evidently artistic, creative, satirical, fictional or similar works, the disclosure can be made in an appropriate manner that does not hamper the display or enjoyment of the work.
The same provision covers AI-generated or manipulated text published to inform the public on matters of public interest. In principle, deployers must disclose its artificial origin. An important exception applies where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication.
Whether disclosure is required therefore depends on the content, its purpose, the role of the organisation and the editorial process around publication – not on a blanket rule to “label AI content”.
Emotion recognition and biometric categorisation
Article 50 also reaches beyond chatbots and generative AI. Deployers of emotion recognition or biometric categorisation systems must inform the natural persons exposed to them, and personal data must be processed in accordance with EU data protection law.
Businesses considering automated emotional analysis should not treat it as an ordinary extension of conversational AI. Beyond Article 50, the AI Act prohibits emotion recognition in the workplace and in educational institutions, except for medical or safety reasons (Article 5(1)(f)), and other use cases may be classified as high-risk.
When did Article 50 start to apply?
Article 50 has applied since 2 August 2026. The Digital Omnibus on AI – Regulation (EU) 2026/1744, in force since 27 July 2026 – postponed several other AI Act requirements, but it did not postpone the Article 50 transparency obligations.
The changes concern mainly high-risk AI systems: obligations for stand-alone high-risk systems listed in Annex III now apply from 2 December 2027, and for high-risk AI embedded in products covered by Annex I from 2 August 2028. They should not be read as a general delay of AI Act compliance.
There is one specific transitional rule for generative AI. Providers of systems generating synthetic audio, images, video or text that were placed on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2). The grace period covers only this marking obligation. For new systems and for the other Article 50 obligations, including chatbot disclosure, no additional transition period applies.
What are the Code of Practice and the Commission guidelines?
The European Commission published the final Code of Practice on Transparency of AI-generated Content on 10 June 2026. The Code supports implementation of the rules on marking and labelling AI-generated or manipulated content – Article 50(2), Article 50(4) and the related requirements of Article 50(5). On 8 July 2026, the Commission confirmed in a formal opinion that the Code adequately covers these obligations. The Code also foresees interoperable detection solutions for marked content by 2 February 2027.
Signing the Code is voluntary. Adherence can help demonstrate compliance, but it does not create a safe harbour: whether a system meets Article 50 is still assessed on its own merits.
On 20 July 2026, the Commission also published final Guidelines on transparency obligations for providers and deployers of AI systems under Article 50. They cover all parts of Article 50, including direct human-AI interaction under Article 50(1), which the Code does not address. Both documents are implementation tools, not substitutes for analysing the Regulation itself.
What are the penalties for breaching Article 50?
Under Article 99 of the AI Act, infringements of the Article 50 transparency obligations can be subject to administrative fines of up to EUR 15 million or, for an undertaking, up to 3% of its total worldwide annual turnover for the preceding financial year, whichever is higher.
For SMEs, including start-ups, the maximum is the lower of the two amounts. The Digital Omnibus extends this rule to small mid-cap enterprises (Article 99(6a)), applicable from 2 December 2026 – companies that are not SMEs but employ fewer than 750 people and have an annual turnover not exceeding EUR 150 million or a balance sheet total not exceeding EUR 129 million.
These are statutory maximums, not an automatic penalty for every missing disclosure. Authorities must consider the circumstances of the individual case, including the nature, gravity and duration of the infringement. For most businesses, the more immediate risk is operational: a transparency gap identified after launch can require changes to the interface, content pipeline, contracts or already published materials.
How to prepare an AI chatbot or generative feature for Article 50
Article 50 is best treated as a product and system-design requirement rather than a legal documentation task. Some obligations have to exist inside the product itself: a policy page cannot fix a chatbot interface that fails to disclose the AI interaction, and contractual language between a client and a software house cannot replace technical output marking where Article 50(2) applies.
A practical review should cover:
- Inventory – every AI feature that interacts directly with users or generates synthetic text, images, audio or video.
- Roles – whether the organisation acts as provider, deployer or both for different parts of the system, and how responsibilities are split with the software supplier, model provider and other parties in the value chain.
- First interaction – whether required disclosures are clear, distinguishable and accessible at the first point of contact.
- Output pipeline – whether generated output carries machine-readable marking under Article 50(2), and whether the backend preserves it.
- Publication – whether workflows involving deepfakes or public-interest texts need separate disclosure under Article 50(4).
- Exceptions – documented reasoning for relying on obvious AI interaction, standard editing or human editorial review.
- Testing and change control – verification before release and re-review whenever the user experience, architecture or functionality materially changes.
This applies equally to companies adding AI to an existing product: even a small generative extension may require changes to the user journey, output pipeline and internal responsibilities. The aim is not to add as many warnings as possible, but to identify the relevant obligation and implement transparency where the user or downstream system actually needs it.
Key questions to ask early
- What exactly does the system do?
- Who is the provider, and who is the deployer?
- Does the user know that they are interacting with AI?
- Does generated output require machine-readable marking?
- Will that output later be published in a context requiring separate disclosure?
With Article 50 in application since 2 August 2026, these questions are no longer preparation for a distant deadline. They are part of designing, deploying and maintaining compliant AI systems in the European market.
Sources and further reading
- Regulation (EU) 2024/1689 (AI Act) – EUR-Lex
- Regulation (EU) 2026/1744 (Digital Omnibus on AI) – EUR-Lex
- Commission opinion on the assessment of the Code of Practice on Transparency of AI-generated Content
- European Commission, Guidelines on transparency obligations for providers and deployers of AI systems under Article 50 of the AI Act (20 July 2026)

