Article 50 EU AI Act vs. Code of Practice: Key Differences
Last updated on August 10, 2026 at 14:23 PM.The transparency obligations under Article 50 of the EU AI Act become legally binding on 2 August 2026. The Code of Practice – a voluntary code of conduct published by the European Commission's AI Office on 10 June 2026 – is not. The Code of Practice is a document that proposes practical measures for providers and deployers of general-purpose AI systems to comply with the statutory transparency obligations: guidance, not law. This article clears up the confusion, classifies both instruments in legal terms, and sets out what specifically applies to marketing leaders in AI-assisted content production.

Why confusing the code with the law is risky
Transparency obligations under Article 50 are one thing – the internal handling of AI is another. Anyone deploying generative systems in content production collects data, processes inputs, and creates dependencies that are rarely documented. This is precisely where the risk arises: the problem is not official AI use, but unofficial use – Shadow AI that no one has approved and no one has audited. How to place AI deployment on a GDPR-compliant foundation through audits, binding policies, and secured integrations is outlined in the overview on AI governance and compliance.
The misunderstanding is structural: companies read "voluntary code" and translate it into "no obligation to act." Yet Article 50 of the AI Act is binding EU law with a sanctions framework of up to €15 million or 3% of global annual turnover. Ignoring the code does not eliminate the obligation – it forfeits the simplest route to demonstrating compliance. Think of it as the difference between a TÜV inspection seal and the road traffic regulations: the seal is voluntary, the rules of the road are not.
For marketing decision-makers, the relevance is immediate. Any company using generative AI for content production, chatbots, or image generation falls under Article 50. According to the AI Act Explorer, the transparency obligations affect approximately 33% of all assessed organisations – the second most frequent compliance trigger after the AI literacy requirement. Anyone publishing AI-assisted content today needs a documented process in 13 days.
What is Article 50 of the EU AI Act? – Definition and scope
Article 50 defines transparency obligations for providers and deployers of certain AI systems. These obligations apply regardless of the system's risk classification – including generative AI tools that are not classified as "high-risk." The threshold is low: anyone operating a system that generates synthetic content or interacts with humans is addressed.
The four transparency obligations at a glance
- Interaction with humans: Chatbots and virtual assistants must disclose that the interaction is taking place with an AI system. Disclosure must occur before or at the latest at the beginning of the interaction.
- Synthetic content: Generated audio, image, video, and text content must be labelled in a machine-readable manner – through metadata, watermarks, or comparable technical methods.
- Emotion recognition and biometric categorisation: Affected individuals must be informed when an AI system recognises their emotions or categorises them biometrically.
- Deepfakes and AI-generated text of public interest: Deployers must disclose that content is AI-generated or AI-manipulated – particularly for content concerning public affairs.
Effective dates and deadlines
| Date | What applies |
|---|---|
| 10 June 2026 | Publication of the final Code of Practice by the AI Office |
| 2 August 2026 | Transparency obligations under Article 50 become applicable (deployers) |
| 2 December 2026 | Transition period for providers ends (systems placed on the market before 2 August; extended by the Digital Omnibus Regulation) |
The staggered timeline is pragmatic: deployers – i.e. companies using AI tools – must label from August onward. Providers of the tools themselves receive four additional months to retrofit their technical labelling mechanisms.
What is the Code of Practice? – A voluntary instrument with practical effect
The Code of Practice is a voluntary code of conduct, developed in a multi-stakeholder process led by the European Commission's AI Office. Signatories can use their measures as compliance evidence for Article 50 – a pre-built proof that the statutory requirements are met. Non-signatories must demonstrate compliance individually to market surveillance authorities.
Transparency obligations under Article 50 are one thing – the internal handling of AI is another. Anyone deploying generative systems in content production collects data, processes inputs, and creates dependencies that are rarely documented. This is precisely where the risk arises: the problem is not official AI use, but unofficial use – Shadow AI that no one has approved and no one has audited. How to place AI deployment on a GDPR-compliant foundation through audits, binding policies, and secured integrations is outlined in the overview on AI governance and compliance.
Benefits for signatories
Signing the code delivers three concrete advantages: reduced administrative burden in demonstrating compliance, legal certainty through EU-wide recognised measures, and access to Signatory Taskforces where signatories exchange experiences and develop best practices. The code functions like a toolkit – those who use it don't have to invent the tools themselves.
Consequences for non-signatories
There is no sanction for non-signature itself. The consequence is subtler: non-signatories must demonstrate to different national authorities on an individual basis that the transparency obligations are met. In a single market with 27 member states and just as many supervisory structures, that is no trivial undertaking.
Obligation versus voluntariness – the key difference at a glance
The confusion arises because both instruments address the same subject: labelling and detection of AI-generated content. Their legal status is fundamentally different. One is an EU regulation with direct applicability in all member states; the other is a voluntary commitment with practical utility but no sanctions mechanism.
| Criterion | Article 50 (Transparency obligations) | Code of Practice (Code of conduct) |
|---|---|---|
| Legal character | Statutory obligation (EU regulation, directly applicable) | Voluntary self-commitment |
| Sanctions for non-compliance | Up to €15 million or 3% of global annual turnover | No direct sanctions |
| Scope | All providers and deployers in the four defined scenarios | Signatories only |
| Evidence of compliance | Individual demonstration to market surveillance authorities | Code measures serve as compliance evidence |
| Adaptation | Requires legislative amendment | Regular review by the AI Office |
What the code specifically regulates for marketing teams
The Code of Practice addresses two core areas: machine-readable labelling by providers (metadata, watermarks) and visible labelling by deployers (EU icons, labels, disclaimers). For marketing teams, the second area is operationally relevant – this is where the day-to-day action items arise.
Labelling by providers – metadata and watermarks
The code requires a multi-layer approach: at least two machine-readable labelling layers per piece of generated content. For free-form text, a watermarking threshold of 200 tokens applies – below this limit, labelling cannot be reliably implemented from a technical standpoint. By 2 February 2027, the detection mechanisms of different providers must be interoperable – meaning a watermark from Provider A must also be readable by Provider B.
Labelling by deployers – EU icons and labels
The AI Office has defined three EU icons: one for fully AI-generated content, one for AI-modified content, and a base icon with an interactive second information layer. Use of these specific icons is voluntary – however, anyone using custom labels must comply with design and placement requirements defined in the code. Labelling must be visible, comprehensible, and placed in immediate proximity to the content.
Worked example: 40 graphics and 10 blog articles per month
A company publishes 40 AI-generated social media graphics and 10 AI-assisted blog articles per month. For the graphics, Article 50(2) applies: the provider of the image generator must embed machine-readable labelling; the deployer must additionally label visibly where deepfake-like content is involved (para. 4). For the blog articles, para. 4 applies only under two conditions: the articles address topics of public interest and no editorial review takes place that establishes human responsibility for the content. A B2B technical article on product specifications that has been editorially reviewed does not fall under the disclosure obligation – an AI-generated commentary on political topics without editorial review does.
Sanctions and enforcement – what happens when Article 50 is breached
The AI Act provides for tiered fines. Violations of the transparency obligations under Article 50 can be sanctioned with fines of up to €15 million or 3% of global annual turnover – whichever amount is higher. Proportionally lower caps apply to SMEs and start-ups.
| Violation category | Maximum fine | Reference metric |
|---|---|---|
| Transparency obligations (Art. 50) | €15 million or 3% annual turnover | Global group turnover |
| Prohibited AI practices (Art. 5) | €35 million or 7% annual turnover | Global group turnover |
| Other violations | €7.5 million or 1.5% annual turnover | Global group turnover |
In Germany, the national market surveillance authority will be responsible. The specific authority structure is currently being determined. Until national structures are fully established, the AI Office monitors at EU level. Enforcement will not begin with penalty notices on day one – but the obligation applies from day one.
Impact on content strategy and brand management
For B2B companies with global reach, Article 50 means that AI-assisted content production must be set up in a documented and labelling-ready manner – regardless of whether the code of conduct is signed. The question is not whether, but how efficiently the process is designed.
Transparency obligations under Article 50 are one thing – the internal handling of AI is another. Anyone deploying generative systems in content production collects data, processes inputs, and creates dependencies that are rarely documented. This is precisely where the risk arises: the problem is not official AI use, but unofficial use – Shadow AI that no one has approved and no one has audited. How to place AI deployment on a GDPR-compliant foundation through audits, binding policies, and secured integrations is outlined in the overview on AI governance and compliance.
Process adjustments in content production
- Inventory of all AI-assisted workflows: Text, image, audio, video – every channel, every tool, every use case. What is not inventoried cannot be labelling-ready.
- Documentation of editorial review processes: Relevant for the exemption regarding texts of public interest. Anyone who can demonstrate that a human bears content responsibility may, under certain conditions, be exempt from the disclosure obligation.
- Contractual obligation of AI providers: The provider's labelling obligation (metadata, watermarks) must be contractually secured – otherwise the deployer is liable for a deficit it cannot technically control.
Strategic advantage through early compliance
Companies that proactively implement transparency strengthen brand trust in an environment where synthetic content is increasingly scrutinised. Consistent labelling becomes a quality marker in B2B communications – comparable to ISO certification in manufacturing: not a selling point in itself, but a disqualifier in its absence.
A documented content strategy that integrates AI transparency obligations from the outset saves rework and protects against fines. Those who prefer not to build this capability in-house can develop it with a specialised content marketing agency such as Crispy Content®.
Trends – how the regulatory framework is evolving
The Code of Practice is not a static document. The European Commission has announced regular reviews and updates in line with technological progress. Four developments are emerging:
- Digital Omnibus Regulation: The postponement of provider obligations to December 2026 signals a pragmatic approach – the EU wants to enable compliance, not prevent it.
- Interoperability requirement from February 2027: The requirement that watermark detection mechanisms must work across providers will force technical standards. For marketing teams, this means tool selection will also depend on labelling capability.
- Further codes of conduct: Separate codes are in preparation for GPAI models with systemic risk. The transparency code is the first, not the last.
- International signal effect: The EU approach is being discussed as a reference model for other jurisdictions – much as the GDPR became the global data protection standard.
| Milestone | Date | Significance for deployers |
|---|---|---|
| Provider transition period ends | 2 December 2026 | From this date, all tools must deliver machine-readable labelling |
| Watermark interoperability | 2 February 2027 | Cross-tool detection becomes mandatory |
| First code review (expected) | H1 2027 | Adaptation to current state of technology |
Article 50 and the Code of Practice – clarity, not uncertainty
The facts are unambiguous: Article 50 is binding law; the Code of Practice is a voluntary tool for implementation. Marketing leaders who correctly classify both instruments can set up their AI-assisted content production in a legally sound and efficient manner. The code is the tool, not the obligation – and those who choose not to use the tool still have to build. Just without the manual.
Sources
European Commission / AI Office (2026): Code of Practice on Transparency of AI-Generated Content. URL: https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content (accessed 20 July 2026).
Freshfields Bruckhaus Deringer (2026): EU AI Act Unpacked #33: The final Code of Practice on Transparency of AI-generated content. URL: https://www.freshfields.com/en/our-thinking/blogs/technology-quotient/eu-ai-act-unpacked-33-the-final-code-of-practice-on-transparency-of-ai-generate-102n4yx (accessed 20 July 2026).
Future of Life Institute (2026): The EU AI Act's Transparency Rules: A Practical Guide to Article 50. URL: https://artificialintelligenceact.eu/de/transparency-rules-article-50/ (accessed 20 July 2026).
Skill Sprinters (2026): KI-Transparenzpflicht nach dem EU AI Act: Wann muss der KI-Einsatz gekennzeichnet werden? URL: https://skill-sprinters.de/blog/compliance/ki-transparenzpflicht-eu-ai-act/ (accessed 20 July 2026).
Tiefenschärfe (2026): Neue EU-Kennzeichnung für KI-Inhalte: Was ab August 2026 gilt. URL: https://tiefenschaerfe.de/neue-eu-kennzeichnung-fuer-ki-inhalte-was-ab-august-2026-gilt/ (accessed 20 July 2026).
TÜV Akademie (2026): Kennzeichnungspflicht für KI-Inhalte? Was Art. 50 AI Act tatsächlich verlangt. URL: https://die-tuev-akademie.de/blog/kennzeichnungspflicht-fuer-ki-inhalte-was-art-50-ai-act-tatsaechlich-verlangt (accessed 20 July 2026).
Gerrit Grunert
Gerrit Grunert is the founder and CEO of Crispy Content®. In 2019, he published his book "Methodical Content Marketing" published by Springer Gabler, as well as the series of online courses "Making Content." In his free time, Gerrit is a passionate guitar collector, likes reading books by Stefan Zweig, and listening to music from the day before yesterday.