Short answer: Article 50 requires that people be told when they're interacting with an AI system, that emotion recognition and biometric categorisation be disclosed to those subject to them, that synthetic audio, image, video and text be marked in a machine-readable way, and that deepfakes and certain AI-generated public-interest text be labelled. It became enforceable on 2 August 2026. For most small businesses, compliance is a notice and a labelling habit.
General information, not legal advice.
The four disclosure duties
1. Interaction disclosure. If you operate an AI system that interacts with people — a chatbot, a voice agent, an AI-powered support widget — those people must be informed they're dealing with an AI system, unless it's obvious to a reasonably observant person in the circumstances.
2. Emotion recognition and biometric categorisation. If you deploy such a system, you must inform the people exposed to it. Note that emotion inference in workplaces and education is separately prohibited outright, not merely subject to disclosure.
3. Synthetic content marking. Providers of systems generating synthetic audio, image, video or text must mark outputs in a machine-readable format detectable as artificially generated. This duty sits primarily with providers, but it affects your tool selection — you want tools that do this.
4. Deepfakes and public-interest text. Deployers of systems producing deepfakes must disclose that the content is artificially generated or manipulated. AI-generated or manipulated text published to inform the public on matters of public interest must also be disclosed, unless it has been through human editorial review with someone holding editorial responsibility.
Who this actually catches
Far fewer businesses than the headlines imply, and more than many assume. You're likely in scope if you:
- Run a chatbot or AI assistant on your website.
- Use AI voice agents for calls.
- Publish AI-generated content on public-interest topics without editorial review.
- Produce synthetic media of people for marketing.
You're likely not in scope if AI is used internally for drafting, analysis or automation with no direct interaction with the public and no synthetic media output.
What compliance looks like in practice
For the common case — a website chatbot — a short, visible statement at the start of the interaction is sufficient. Something on the lines of "You're chatting with an AI assistant. Ask for a human at any time." Clear, present before the conversation begins, not buried in terms and conditions.
The requirements specify that the information be provided in a clear and distinguishable manner at the latest at the point of first interaction, and be accessible — which matters for screen reader users and for people with disabilities.
For AI-generated marketing content, an internal labelling practice and a public statement about your approach covers most of it. For anything published on public-interest matters, keep a record of human editorial review, which is the exemption route.
What it does not require
- Disclosing every internal use of AI. Your drafting process is your business.
- Labelling AI-assisted work where a human has editorial responsibility for the output.
- Detailed technical documentation. That's the high-risk regime.
- Disclosure where AI use is obvious from context.
Businesses routinely over-comply here, adding disclosure to everything and diluting the disclosures that matter.
What to do this quarter
- List every point where AI touches a customer or the public.
- Add interaction disclosure to any conversational AI.
- Check that your content tools mark synthetic output, and record your editorial review process for published material.
- Write your position into your AI usage policy so the practice survives staff changes.
- Record the date you made the changes.
Frequently asked questions
What are the penalties?
Transparency breaches fall in the tier attracting fines up to €15 million or 3% of global annual turnover, with SMEs subject to the lower of the two figures rather than the higher.
Does this apply to UK businesses?
Where output is used in the EU or the system is placed on the EU market, yes.
Do I need to label AI-assisted blog posts?
Not where a human has reviewed and taken editorial responsibility. Keep evidence of that review.
We check where Article 50 actually applies and fix the gaps with the lightest possible touch. See what's covered.
