27/07/26

The AI Act's Transparency Obligations: Rules, Scope and Timeline

AI & Transparency series – Part 1

On 20 July 2026, the European Commission adopted guidelines on the transparency obligations for certain AI systems under Article 50 of the AI Act. These obligations – which apply from 2 August 2026 – require providers and deployers of AI systems to be transparent about the use of AI in four key areas: i) direct interaction with individuals; ii) AI-generated content; iii) emotion recognition and biometric categorisation; and iv) deep fakes and AI-generated text on public-interest matters. Non-compliance can attract fines of up to EUR 15 million or 3% of worldwide annual turnover. This post, the first in a five-part series, introduces the broader context: what the guidelines cover, who is affected, and why these obligations matter for your organisation right now.

For years, stakeholders have called for clear labelling of AI so that individuals can recognise when they are interacting with an artificial intelligence system rather than a human being. The original proposal for the AI Act already included transparency obligations, which were subsequently expanded – notably in response to the emergence of large-scale generative AI tools such as ChatGPT in late 2022 – and largely maintained in the final text of the AI Act as adopted on 13 June 2024.

The AI Act's transparency obligations for providers and deployers of certain AI systems apply from 2 August 2026. These obligations are by far the most widely applicable section of the AI Act: they do not only apply to the providers of AI systems, but also to the deployers – i.e. the persons, companies, organisations or public authorities that (merely) use those systems.

On 20 July 2026, the European Commission approved the AI Office's draft guidelines, filling in the gaps left by the open-ended language of Article 50 of the AI Act. Although these guidelines are non-binding – and any authoritative interpretation may ultimately only be given by the courts – they are expected to serve as the primary reference for national authorities when interpreting the transparency obligations. Alongside the guidelines, the AI Office has also overseen the development of the Code of Practice on Transparency of AI-Generated Content. This voluntary instrument, open for signature by organisations across the EU, sets out specific technical and operational measures for marking, labelling and watermarking AI-generated content – focusing in particular on the category (2) obligations, as described below. Signing the Practice Code is increasingly seen as a practical way for organisations to demonstrate alignment with the Article 50(2) obligations, and the AI Office has indicated that signatories will benefit from a degree of presumption of conformity.

This is the first in a series of five blog posts on the transparency obligations for certain AI systems under Article 50 of the AI Act. This post introduces the series and sets out the broader context: what the guidelines are, who they are aimed at, and why they matter right now. Subsequent posts will examine each of the four specific obligations in Article 50 in turn.

Four categories

Article 50 of the AI Act captures four different situations where either the provider or the deployer should be transparent about the use of AI.

  • AI systems directly interacting with natural persons (e.g. chatbots, voice assistants, AI hotlines, bots on social media, coding agents, …)
  • AI systems generating or manipulating synthetic content (e.g. generative AI tools producing text, images, audio or video, AI-powered substantive editing tools, synthetic video or audio generators, etc.)
  • Emotion recognition or biometric categorisation AI systems (e.g. gaming experience measurement tools, wearable devices with mood monitors, patient or passenger categorisation systems, …)
  • AI systems generating or manipulating deep fakes, or AI-generated/manipulated text published to inform the public on matters of public interest (e.g. AI-generated or manipulated audio, video or images resembling existing persons, places or events; AI-generated or manipulated text in news articles or public-interest reports, etc.)

The general idea behind these obligations is that the use and development of AI should be transparent and traceable. Individuals must be able to recognise when they are interacting with an AI system, and to distinguish AI-generated or manipulated content from human-created content. The stated objectives include reducing the risks of impersonation, deception, misinformation and manipulation, while safeguarding democratic processes, societal trust and fundamental rights.

Each of these categories is subject to its own precise scope, exceptions and specific disclosure, labelling or transparency obligation. In the subsequent parts of this series, we will delve into each of the four categories, expanding on their scope, exceptions, practical obligations and interaction with other laws, using concrete examples.

Before examining each category in detail, it is useful to place the Article 50 transparency obligations in the broader context of the AI Act. The transparency-risk tier under article 50 is often presented as one of the four 'tiers' in the pyramid structure of the AI Act, alongside (i) prohibited practices, (ii) high-risk AI systems, and (iii) minimal-risk AI systems (not taking general-purpose AI into account). Overlaps can arise, both across the four tiers (e.g. a transparency-risk AI system that is also a high-risk AI system) and across the four transparency categories themselves. For instance, an AI chatbot that also generates images as part of a direct interaction will be captured by both categories (1) and (2) of Article 50 of the AI Act.

In addition, obligations under other instruments – including the General Data Protection Regulation (GDPR), the Digital Services Act (DSA), the Digital Markets Act (DMA), consumer protection laws and accessibility legislation – continue to apply in parallel and will need to be reconciled with the AI Act.

Who is responsible

Categories (1) and (2) of article 50 AI Act apply to providers of AI systems, while categories (3) and (4) apply to deployers. But who are these providers and deployers?

Providers are natural or legal persons, public authorities, agencies or other bodies that develop AI systems, or have them developed, and place them on the Union market or put them into service under their own name or trademark, whether for payment or free of charge. These are the companies behind the actual AI system – not to be confused with the developers of the underlying model (e.g. GPT, Claude, Gemini, Muse, etc.). Well-known examples include OpenAI (as the provider of the ChatGPT application) and Anthropic (as the provider of Claude), but also Canva (for their AI-powered editing functionalities), Grammarly (for their spellchecking plug-in) and Spotify (for AI-powered recommendations).

Deployers are the natural or legal persons, public authorities, agencies or other bodies using AI systems under their own authority. This is typically the company or person using the AI system for its own business operations – think of a bank deploying a third-party AI chatbot on its customer-service portal, a media company using a generative AI tool to produce news articles, or a recruitment firm using AI-powered CV-screening software. A legal person remains the deployer even if it involves third parties (e.g. contractors or freelancers) in operating the system on its behalf, provided these third parties act under its responsibility and control. By contrast, where a contractor has the freedom to decide whether and how to use AI for a given assignment, that contractor itself becomes the deployer and must ensure compliance with the applicable transparency obligations. This distinction is particularly relevant where companies engage creative or advertising agencies.

The transparency obligations will not apply where a natural or legal person uses an AI system for purely personal, non-professional activities (e.g. use within a household, a student generating text for a university assignment, publishing deep fakes on social media in a personal capacity, etc.). AI that was specifically developed and put into service for the sole purpose of scientific research and development is also excluded. Importantly, AI systems released under free and open-source licences are not exempted from the transparency obligations under Article 50 – providers and deployers of open-source AI systems falling within the scope of Article 50 must still comply. In addition to these general exclusions, the AI Act provides for specific exceptions for each of the four categories separately.

Enforcement

The transparency obligations apply from 2 August 2026, with fines of up to EUR 15 million or 3% of worldwide annual turnover, whichever is higher. Unlike most other provisions of the AI Act, these obligations are instantly applicable to all AI systems within scope, regardless of when the system was placed on the market or put into service. This means that existing AI systems must comply from day one. However, content (including deep fakes and AI-generated text) that was both generated and published before 2 August 2026 does not need to be retroactively marked or labelled. Conversely, if content was generated before that date but published on or after 2 August 2026, the labelling obligations do apply. The legislator has introduced a limited transitional period for the marking and detection obligations under Article 50(2) only: providers of generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to bring those systems into conformity with the marking requirements.

In summary, it is not just the companies developing AI systems that need to act – organisations that use these systems must equally ensure that the transparency obligations are integrated into their compliance and governance frameworks. Companies active on social media, deploying chatbots, using coding assistants, publishing AI-generated advertisements or generating content with AI tools will inevitably be confronted with these obligations. If you have any questions, or if you would like assistance in setting up the appropriate compliance structure, please do not hesitate to contact one of our experts.

Authors:

  • Thibau Duquin, Associate, Brussels at Stibbe
  • Frederiek Fernhout, Senior Associate, Amsterdam at Stibbe
dotted_texture