This article clarifies which of the four transparency obligations actually apply to businesses, agencies and publishers, where the European Commission’s guidelines of 20 July 2026 provide clarity – and where the grey areas begin.
What exactly does Article 50 of the AI Regulation cover?
Article 50 of the AI Regulation covers four categories:
- AI systems that interact directly with humans (chatbots),
- AI systems that generate synthetic content,
AI systems for emotion recognition or biometric categorisation, - deepfakes, and
- AI-generated texts on topics of public interest.
Chatbots
In the case of an AI chatbot or agent that communicates directly with people, users must be able to recognise that they are speaking to an AI. According to the Commission’s guidelines, a note in the terms and conditions alone is not sufficient for this purpose. Even a vague term such as ‘assistant’ is not enough. A clear, highly visible notice at the start of the interaction is required.
Deepfakes
Deepfake’ sounds like criminal forgery. Legally, however, the term is broader. The AI Regulation covers any AI-generated or AI-manipulated image, audio or video content that resembles a real or plausibly existing person, object, place or event and which would falsely appear to a person to be genuine or truthful. Intent to deceive is irrelevant.
An example: an AI-generated model photograph on a product page shows a person who does not exist – but who could plausibly exist. This is likely to meet the criteria for a deepfake. The same applies to a product image generated entirely by AI that makes the product appear more attractive than it is in reality. An AI-generated dragon, on the other hand, would not – dragons do not exist. And a real product set against an AI-generated background would generally be unproblematic, provided the depiction does not mislead regarding the product’s actual characteristics.
Unlike with text, it is irrelevant for images, audio and video whether the content is promotional or informative. The obligation applies regardless of the intended use. An exemption applies only to recognisably artistic, satirical or fictional works – purely commercial product advertising is generally unlikely to benefit from this.
AI-generated texts
Stricter requirements apply to text. Three criteria must be met cumulatively:
- The text must be published – that is, publicly accessible, not merely a draft or an internal note.
- It serves to inform the public – not to sell or advertise anything. Traditional product descriptions and promotional social media posts are therefore generally unlikely to be covered – unless they contain statements on health, consumer safety or sustainability, which may be regarded as matters of public interest.
- The text concerns a subject of public interest – politics, health, the environment, consumer protection or similar socially relevant topics.
And even if all three conditions are met, there is an exception: if the content of the text has been substantially reviewed by an expert and a natural or legal person bears editorial responsibility for its publication, the labelling requirement does not apply. A mere spell-check, an automated review by another AI system or a purely formal rubber-stamping are not sufficient. The review process should be carefully documented – not only as evidence for the authorities, but also as proof that a personal intellectual creation within the meaning of Section 2(2) of the German Copyright Act (UrhG) exists. Without this proof, the basic prerequisite for copyright protection is also lacking.
The crucial question: provider or operator – or neither?
In practice, it is evident that many companies now reflexively label everything that has come into contact with AI in any way. Whilst this is understandable, it misses the point of the law.
Whether and to whom the labelling obligations apply depends on the role one is in.
The AI Regulation distinguishes between the provider – that is, the party who develops an AI system or commissions its development and places it on the market or puts it into operation under their own name – and the operator, that is, the party who uses an AI system professionally or commercially under their own responsibility . The chatbot disclosure requirement (Article 50(1)) and the technical labelling of synthetic content (Article 50(2)) apply to the provider. The duty to provide information regarding emotion recognition and biometric categorisation (Art. 50(3)), as well as the labelling of deepfakes and the labelling requirement for AI-generated texts on topics of public interest (Art. 50(4)), apply to the operator.
As most companies do not develop their own AI systems, the crucial question therefore regularly arises: Am I an operator?
Three scenarios illustrate just how different the outcome can be – even though each involves a similar situation with virtually the same end result:
- A company enters a prompt into an AI image-generation tool and has an AI-generated model photo (deepfake) created to advertise a product, as it wishes to avoid the expensive photo shoots involving real models and photographers. The AI image is then uploaded by the company to its own website and product page.
- For another product, the same company commissions a creative agency to ‘showcase the product’, without requesting the use of AI or being aware of it. The agency nevertheless uses an AI tool and delivers a fully AI-generated image of the product (deepfake), which the company then uploads to its own website.
- Now, the same company explicitly commissions an agency to use AI tools in content creation, and also provides further detailed specifications for this. The agency implements the specifications accordingly and creates an AI-generated product image (deepfake), which the company then uploads to its website.
These examples illustrate that the division of roles – and thus the question of whether the labelling obligation applies to an individual – is, in some cases, fluid:
Whilst in the first case the company selected, configured and operated the AI system itself – and is therefore quite clearly the operator within the meaning of Article 3(4) of the AI Regulation, and must accordingly label the image as AI-generated upon publication – in the second case precisely this control is lacking: The company neither initiated the use of AI nor was it aware of it – the decision on the ‘whether’ and ‘how’ of the AI’s use lay solely with the agency, which should therefore be regarded as the sole operator. The company is therefore not required to label the deepfake product image as AI-generated. In the third case, however, the company is likely to be regarded as a (co-)operator, because, through its detailed specifications, it exerted significant influence over the selection and configuration of the AI system and expressly ordered the use of AI. Here, too, the company is subject to the labelling obligation.
Operator status is always determined by law and cannot be altered by contract. What can, however, be regulated by contract – and, according to the Commission’s guidelines, should be regulated – is the operational assurance of labelling throughout the production and distribution chain: for example, the service provider’s obligation to disclose AI-generated content to the client, not to remove machine-readable labels and, where necessary, to establish a clear division of roles.
What you should check now
Do you operate a chatbot or AI agent yourself? If so, Article 50(1) applies – a visible notice at the start of every interaction.
Do you create and publish realistic AI-generated images, videos or audio recordings relating to people, places or events? If so, check the deepfake criteria – including for product photos.
Do you commission agencies to produce AI-supported content? If so, ensure that roles and responsibilities are clearly defined in the contract.
Do you publish AI-generated texts that provide information on a topic of public interest? If so, label them as such unless there is documented editorial review.
Fines
Breaches may be punishable by fines of up to 15 million euros or 3 per cent of global annual turnover. For the technical labelling requirement under Article 50(2), a transitional period until 2 December 2026 applies to generative systems already on the market before 2 August 2026. Chatbot disclosure and deepfake labelling apply without a transitional period.
Conclusion
Article 50 of the AI Regulation is not a marginal provision. Anyone publishing AI-generated images, videos or audio content that appears realistic must check whether it is a deepfake – regardless of whether the content is promotional or informative. In the case of text, the obligations apply only under more specific conditions, but can be avoided through a documented editorial process. And anyone who outsources the use of AI to agencies should be aware that the definition of ‘controller’ is not determined by the contract, but by who has control over the AI system. The Commission’s guidelines and the Code of Practice are available, but there is as yet no case law. Some issues will only become clear in practice. Those who set up their processes now will have a head start – and save themselves unpleasant questions later on. If you need support with this, please do not hesitate to contact us.
Key points in brief
- For most companies, Article 50(4) – the labelling of deepfakes and text – is of particular importance. The technical labelling of synthetic content (paragraph 2) is the responsibility of the tool provider.
- Deepfakes are defined more broadly than many people realise: the AI Regulation covers any realistic AI image, video or audio – regardless of its intended use and without there needing to be any intent to deceive. Product photos may also be affected.
- The ‘operator’ is whoever has control: the status of operator is determined by law, not by contract. Anyone outsourcing the use of AI to agencies should clearly define the roles and labelling obligations in the contract.








