Art. 50 EU AI Act: AI Labeling Requirements Starting 2026
Last updated on August 10, 2026 at 14:23 PM.Article 50 of the EU AI Act is the central legal basis for the mandatory labelling of AI-generated content in the European Union. The provision obliges providers and deployers of AI systems to ensure transparency — for chatbots, deepfakes, synthetic audio, video and image content, as well as AI-generated text on matters of public interest. From 2 August 2026, the rule is binding and applies to every company that uses generative AI for content production or customer communication. This article explains the four categories defined in Article 50, provides a worked example of the implementation effort, and puts the relevant technical standards — from C2PA to the EU label — into context.

What does Article 50 of the EU AI Act regulate? — Definition and scope
Article 50 defines transparency obligations for providers and deployers of certain AI systems. The provision applies regardless of risk classification — meaning it covers not only high-risk systems but any generative AI that produces content or interacts with people. According to data from the AI Act Compliance Checker, around 33 % of all companies using AI fall under at least one of the four categories. The effective date is 2 August 2026; for generative AI systems already on the market before that date, the AI Omnibus Package of May 2026 grants a transitional period until 2 December 2026.
Wer generative KI im Unternehmen einsetzt, sollte wissen, wo die eigenen Daten landen und wer dafür geradesteht. Shadow AI ist kein Randthema, sondern ein Risiko, das sich mit Audits, Richtlinien und DSGVO-konformen Integrationen auf gesicherten Boden bringen lässt. Genau das entscheidet, ob aus einem Werkzeug ein Loch im Tank wird.
The decisive distinction in the legislative text lies between provider and deployer. Both carry obligations, but different ones.
| Role | Obligation | Example |
|---|---|---|
| Provider | Design the system so that AI use is discernible; label outputs in a machine-readable format | OpenAI, Midjourney, in-house AI tools |
| Deployer | Disclosure to end users for deepfakes and AI-generated text | Marketing department, publisher, agency |
The four categories of AI transparency obligations in detail
Article 50 distinguishes four situations in which transparency must be established. Each category addresses a different communication channel and distributes obligations differently between provider and deployer. The categories are cumulative — a company can fall under several at the same time.
Category 1 — Interactive AI systems and chatbot labelling
This covers chatbots, virtual assistants and automated phone systems. The obligation is clear: users must be informed before or at the start of the first interaction that they are communicating with an AI system. An exception applies only where the use of AI is "obvious" to a reasonably informed person — the Commission's draft guidelines provide a two-step test for this. In practice, chatbot labelling means: a visible notice in the chat interface or an announcement at the beginning of an automated phone call.
Category 2 — Machine-readable labelling of synthetic content
This category covers all AI-generated text, images, audio and video content. The provider must label its outputs in a machine-readable format and make them identifiable as AI-generated. The technical reference standard is C2PA (Coalition for Content Provenance and Authenticity) — an open standard for cryptographically signed provenance records. The EU label "AI" is in its final design phase under the Code of Practice. An exception applies to purely assistive functions such as grammar correction or spell-checking that do not substantially alter the content. Anyone producing AI-generated images, AI audio or synthetic video must integrate labelling into the production workflow.
Category 3 — Emotion recognition and biometric categorisation
Where a deployer uses AI systems for emotion recognition or biometric categorisation, it must inform the affected individuals in advance. The distinction from the prohibition under Article 5 is relevant: emotion recognition in the workplace and in educational institutions is generally banned. Where it remains permissible, deployment additionally requires GDPR compliance — in particular a legal basis for processing biometric data.
Category 4 — Deepfake labelling and AI-generated text of public interest
Deepfakes — defined in Article 3(60) as AI-generated or manipulated image, audio or video content that falsely appears authentic — must be disclosed by the deployer. Deepfake labelling is mandatory for every publisher or producer. An exception exists for obviously artistic, satirical or fictional works; in those cases, an "appropriate" label that does not disproportionately restrict creative freedom is sufficient.
For AI-generated text, the disclosure obligation applies when the purpose is to inform the public on matters of public interest. The most important exception: if the text has undergone human review and a natural or legal person bears editorial responsibility, the labelling obligation does not apply. This review must be substantive — a superficial sign-off is not enough.
How does technical labelling work? — C2PA, watermarks and the EU icon
The EU AI Act does not prescribe a single technology but requires "appropriate technical solutions". In practice, three methods are emerging that the Code of Practice of June 2026 references as standards. The distinction between "fully AI-generated" and "AI-assisted" determines the level of disclosure required.
- C2PA standard: Cryptographically signed metadata in the file container document provenance and every editing step. The standard is interoperable and supported by major platforms.
- Invisible watermark: Markings embedded in the pixel structure or audio signal survive compression and cropping but can be removed through targeted manipulation.
- Visible EU icon: A visual "AI" label placed directly on the content, immediately recognisable to humans but without technical protection against removal.
| Method | How it works | Strength | Weakness |
|---|---|---|---|
| C2PA metadata | Cryptographically signed provenance data in the file container | Richest authenticity signal; interoperable | Metadata can be stripped during platform upload |
| Invisible watermark | Marking embedded in pixel structure/audio signal | Survives compression and cropping | Can be removed through targeted manipulation |
| Visible EU icon | Visual "AI" label on the content | Immediately recognisable to humans | No technical protection against removal |
None of these methods is sufficient on its own. The Code of Practice recommends a combination of machine-readable labelling (C2PA or watermark) and a visible notice.
The EU Code of Practice of June 2026 — Voluntary, but authoritative
On 10 June 2026, the European Commission published the final Code of Practice on Marking and Labelling of AI-Generated Content. Signing is voluntary — but in practice the Code becomes the benchmark against which national market surveillance authorities assess compliance with Article 50. Companies that sign and implement the Code thereby document their compliance efforts.
The core elements of the Code include: standardised EU icons for labelling, a classification into "fully AI-generated" and "AI-assisted", media-specific labelling rules for text, image, audio and video, and an open signature process that companies can join at any time. The AI Act 2026 thus relies on a mix of binding obligation and voluntary specification — a model familiar from the GDPR world.
Worked example — Implementation effort for a mid-sized marketing team
Abstract obligations become tangible when applied to a concrete scenario. Assume: a mid-sized company operates across five channels (website, LinkedIn, newsletter, YouTube, podcast) and uses generative AI for content production. The affected touchpoints span three categories: the chatbot on the website (Category 1), AI-generated blog posts and press releases (Category 4), and AI images for social media (Category 2).
The estimated initial effort: an audit of existing AI workflows (8–16 person-hours), implementation of technical labelling depending on the tool landscape (2–5 person-days), and the definition of ongoing processes for human review and quality assurance.
| Category | Typical touchpoint | One-off effort | Ongoing effort/month |
|---|---|---|---|
| 1 — Chatbot | Website chat, phone bot | 4–8 h (implement notice) | < 1 h (monitoring) |
| 2 — Synthetic content | Social media images, videos | 2–5 days (tool integration) | 2–4 h (quality assurance) |
| 4 — Text/deepfakes | Blog, press releases | 4–8 h (define process) | 2–3 h (human review) |
In total, the one-off effort for a team of this size amounts to 4–7 person-days, with ongoing effort at 5–8 hours per month. This is not a transformation project — but it does require a deliberate decision about who on the team owns the responsibility.
Fines and enforcement — What non-compliance means
Violations of Article 50 can result in fines of up to €15 million or 3 % of global annual turnover — whichever is higher. Enforcement lies with the national market surveillance authorities of the EU member states. In Germany, this role is expected to be assumed by the Bundesnetzagentur.
Enforcement begins on 2 August 2026; for existing systems, the transitional period runs until 2 December 2026. EU AI regulation thus follows the GDPR pattern: high fine ceilings as a deterrent, selective enforcement focused on serious violations. Anyone who can demonstrate that processes exist and are actively followed will be in a stronger position than someone with nothing to show at all.
Trends and outlook — Where AI labelling is heading
AI transparency obligations are not a European outlier. California's CAITA (California AI Transparency Act) also takes effect on 2 August 2026 and imposes similar requirements. China has been regulating since 2023 through its Deep Synthesis Provisions. Anyone producing for international markets already needs to comply with multiple regimes simultaneously — EU labelling is becoming the lowest common denominator.
Three developments deserve particular attention:
- Platform integration: Meta, Google and Adobe are implementing C2PA natively. Metadata is preserved on upload rather than being silently stripped. This solves one of the biggest practical problems of machine-readable labelling.
- AI detection as a service: The market for detection tools is growing. Companies will increasingly need both labelling (for their own content) and verification (for third-party content).
- Editorial responsibility as a differentiator: Anyone who can demonstrate human review is exempt from the disclosure obligation for text. Quality processes become a competitive advantage — not only from a regulatory standpoint but also in how readers and search engines perceive the content.
"Documented processes are not bureaucratic overhead — they are proof that a piece of content is backed by a decision, not just a prompt. Anyone who audits their AI workflows before the regulator asks has understood that method is not an end in itself but a promise to the reader." — Gerrit Grunert, Founder and Managing Director of Crispy Content®
Embedding Article 50 in your content strategy
Am Ende zählt nicht der Kanal, sondern die Substanz dahinter. Von Landingpages über Whitepaper und E-Books bis zu Social-Media-Inhalten reicht ein redaktionelles Leistungsspektrum, das unterschiedliche Content-Bedürfnisse abdeckt – und zeigt, dass die Wahl des Formats immer der Frage folgt, was der Nutzer tatsächlich sucht.
Companies that document their AI workflows and establish human-review processes meet the requirements of Article 50 while simultaneously strengthening their brand credibility. The effort is manageable — 5–8 hours per month for a mid-sized team — but it must be planned deliberately. A documented content strategy makes transparency obligations predictable. Those who prefer not to build this capability in-house can develop it with a specialised content marketing agency like Crispy Content®.
Sources
European Commission (2026): Code of Practice on marking and labelling of AI-generated content. URL: https://digital-strategy.ec.europa.eu/en/news/commission-publishes-code-practice-marking-and-labelling-ai-generated-content (accessed 20 July 2026).
European Commission (2026): Code of Practice on transparency of AI-generated content — overview page. URL: https://digital-strategy.ec.europa.eu/de/policies/code-practice-ai-generated-content (accessed 20 July 2026).
Future of Life Institute (2026): The EU AI Act's transparency rules: A practical guide to Article 50. URL: https://artificialintelligenceact.eu/de/transparency-rules-article-50/ (accessed 20 July 2026).
AI Act Law (2026): Art. 50 AI Act — Transparency obligations for providers and deployers of certain AI systems. URL: https://ai-act-law.eu/de/artikel/50/ (accessed 20 July 2026).
Ecovis (2026): EU AI Act: Labelling obligation for AI-generated content. URL: https://de.ecovis.com/unternehmensberatung/eu-ai-act-kennzeichnungspflicht-unternehmen/ (accessed 20 July 2026).
HÄRTING Rechtsanwälte (2026): Transparency obligations in the AI Act (Art. 50). URL: https://haerting.de/wissen/transparenzpflichten-in-der-ki-verordnung/ (accessed 20 July 2026).
Haufe (2026): Labelling obligation for AI content applies from August 2026. URL: https://www.haufe.de/recht/kanzleimanagement/kennzeichnungspflicht-fuer-ki-inhalte-gilt-ab-august-2026_222_681220.html (accessed 20 July 2026).
C2PA — Coalition for Content Provenance and Authenticity (2026): Open technical standard for content provenance. URL: https://c2pa.org/ (accessed 20 July 2026).
Gerrit Grunert
Gerrit Grunert is the founder and CEO of Crispy Content®. In 2019, he published his book "Methodical Content Marketing" published by Springer Gabler, as well as the series of online courses "Making Content." In his free time, Gerrit is a passionate guitar collector, likes reading books by Stefan Zweig, and listening to music from the day before yesterday.