EU AI Act Article 50: AI Transparency and Labelling Rules Explained

  • Aug 29, 2026
  • 21 min read
EU AI Act Article 50, focusing on transparency and AI-content labelling.

EU AI Act Article 50 establishes targeted transparency obligations for certain AI systems. Providers must disclose direct AI interaction and make certain AI-generated or manipulated content machine-readable and detectable. Deployers must inform people about emotion recognition or biometric categorisation and disclose deepfakes and certain public-interest text.

 

The rules do not impose one universal visible label on every AI output. The applicable duty depends on the system, content, legal role, and use context.

 

Article 50 has applied since 2 August 2026. The legal baseline is the current consolidated text of Regulation (EU) 2024/1689, dated 27 July 2026. The European Commission's final Article 50 guidelines, FAQ, and final Code of Practice provide the main implementation materials.

 

Key takeaways

  • Article 50 creates specific transparency duties, not a rule that all AI content needs a visible label.

  • Providers carry the duties under Article 50(1) and 50(2); deployers carry those under Article 50(3) and 50(4).

  • Machine-readable marking under Article 50(2) is different from a human-facing disclosure under Article 50(4).

  • Deepfake disclosure covers qualifying AI-generated or manipulated image, audio, and video, not every AI-created visual or recording.

  • Certain public-interest text is exempt following substantive human review or editorial control plus editorial responsibility.

  • The Code of Practice is voluntary, but the underlying Article 50 obligations are mandatory.

What Is EU AI Act Article 50?

EU AI Act Article 50 addresses transparency risks from certain interactive, generative, biometric, and emotion-related AI systems. It helps people recognise AI interaction, artificial content, and systems analysing emotions or categorising people through biometric data.

 

It allocates defined responsibilities. A provider may need to make a chatbot identify itself or embed machine-readable marks. A deployer may need to announce emotion recognition or disclose a deepfake.

 

A provider develops a system, or has it developed, and markets or puts it into service under its own name or trademark. A deployer uses a system under its authority, excluding personal non-professional activity. One organisation can hold both roles. The consolidated EU AI Act contains the controlling definitions and all seven paragraphs.

When Does EU AI Act Article 50 Apply?

2 August 2026. Article 50's transparency obligations have been applicable and enforceable since that date.

 

There is one limited transition in the current consolidated law. Providers of generative AI systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with the machine-readable marking and detection obligation in Article 50(2). This transition does not generally postpone Article 50(1), 50(3), 50(4), or 50(5). The Commission also states that content generated before 2 August 2026 does not need to be labelled retroactively, although voluntary disclosure is encouraged where possible.

 

The Commission's Article 50 FAQ explains this transition. The AI Act enforcement framework confirms that national authorities, the AI Office within its competence, and the European Data Protection Supervisor now have enforcement roles.

Who Must Comply With Article 50?

AI providers

Providers are responsible for Article 50(1), 50(2), and the related Article 50(5) presentation rules. They must build transparency into an in-scope system before market placement or service.

AI deployers

Deployers are responsible for Article 50(3), 50(4), and related Article 50(5) rules. The deployer is normally the organisation controlling the use. Its employees are not separate deployers, and contractors do not displace its role where it retains responsibility and control.

Organisations using third-party AI

An organisation using third-party AI professionally is often the deployer, while the vendor is the provider. It should verify vendor notices, marking, and detection. A customer offering a system under its own name or trademark may become a provider. Classify roles system by system.

Companies outside the EU

Article 2 covers providers placing systems on the EU market and third-country providers or deployers where output is used in the Union. Applicability turns on market placement, deployment, and output use, not headquarters alone.

Role

Main Article 50 responsibilities

Example

Provider

Design direct-interaction disclosures; mark and enable detection of in-scope synthetic outputs

Company offering an AI chatbot or image generator under its brand

Deployer

Inform people about emotion or biometric systems; disclose deepfakes and certain public-interest text

Publisher using generative AI in professional publishing

Both

Meet provider and deployer duties that apply to each role

Organisation developing its own generative system and publishing its outputs

What Are the EU AI Act Article 50 Transparency Requirements?

Article provision

Requirement

Responsible party

Practical example

Article 50(1)

Inform people that they are interacting directly with AI, unless this is obvious or a specific exception applies

Provider

AI customer-service agent identifies itself as AI

Article 50(2)

Mark synthetic audio, image, video, and text outputs in a machine-readable format and make them detectable

Provider

Image generator embeds machine-readable provenance signals

Article 50(3)

Inform exposed people that emotion recognition or biometric categorisation is operating

Deployer

Venue gives notice before using an emotion recognition system

Article 50(4)

Disclose qualifying deepfakes and certain AI-generated or manipulated public-interest text

Deployer

Publisher labels a qualifying synthetic political video

Article 50(5)

Provide the information clearly, distinguishably, accessibly, and no later than first interaction or exposure

Provider or deployer responsible for paragraphs 1 to 4

Disclosure appears when a user first starts an AI chat

 

Article 50(6) makes these obligations cumulative. They do not displace high-risk AI requirements in Chapter III or other EU or national transparency laws. Article 50(7) directs the Commission to facilitate codes of practice, assess their adequacy for paragraphs 2 and 4, and, if necessary, adopt common implementing rules.

Article 50(1): When Must AI Systems Tell Users They Are Interacting With AI?

Article 50(1) applies when the technology is an AI system, supports a genuine two-way exchange, communicates directly without a human intermediary, and interacts with a natural person. Background and machine-to-machine systems fall outside this duty.

 

The provider must build in a clear disclosure available no later than first interaction. Notice is unnecessary only where AI interaction is obvious to a reasonably well-informed, observant, and circumspect person. The Commission interprets that exception restrictively.

 

There is also a law-enforcement exception, subject to safeguards. It does not cover public-facing systems used to report crime.

Does Article 50 Apply to AI Chatbots?

Yes, an AI chatbot designed for direct, two-way communication with people is a core Article 50(1) use case. The provider must ensure that users are informed they are interacting with AI unless that fact is already obvious in context.

Does Every Website Chatbot Need an AI Disclosure?

No. The tool must qualify as AI and support direct, genuine two-way interaction with a person. A fixed decision tree, contact form, static FAQ, or scripted response may fall outside scope. Obvious AI interaction may not need a notice, but that exception is narrow.

Article 50(2): How Must AI-Generated Content Be Marked?

Providers of AI systems, including general-purpose AI systems, that generate synthetic text, image, audio, or video must ensure that outputs are marked in a machine-readable format and detectable as artificially generated or manipulated.

 

The solution must be effective, interoperable, robust, and reliable as far as technically feasible, taking account of content limitations, cost, the state of the art, and standards. No single technology is declared sufficient for every use case.

 

The guidelines exclude short sequences of numbers, symbols, or letters, source code, solely machine-to-machine outputs never exposed to people, and non-final outputs confined to closed production environments. They also describe narrow treatment for qualifying B2B or industrial contexts, not a blanket exemption.

What Is Machine-Readable AI Marking?

Machine-readable marking is information or a signal that software can detect and interpret to determine that content was generated or manipulated by AI. It may be invisible to a person. Its function is different from a visible caption such as “AI-generated.”

 

The provider must place the mark in or with the output and enable detection. An uninterpretable marker does not meet the full objective.

What Technologies Can Be Used?

Potential methods include metadata, digitally signed or cryptographic provenance records, imperceptible watermarking, fingerprinting, logging, and combinations of techniques. The final Code of Practice uses digitally signed metadata and imperceptible watermarking as central measures for signatories, with fingerprinting or logging as optional supplementary approaches in suitable cases. The Code does not treat fingerprinting or logging alone as universally sufficient.

 

The combination should address removal, alteration, false positives, incompatibility, and metadata loss. The Commission's studies examine text, audio, image, and video marking, but the statutory quality test remains controlling.

Does the EU AI Act Require Every AI-Generated Image, Video, Audio or Text to Be Labelled?

No. Article 50 creates different marking and disclosure obligations depending on the AI system, content, role, and use case.

 

Article 50(2) generally requires the provider of an in-scope generative AI system to embed machine-readable marking in synthetic outputs. This is a provider-side technical obligation and does not necessarily produce a visible label.

 

Article 50(4) creates human-facing disclosure duties for deployers in two defined situations: image, audio, or video content that meets the legal definition of a deepfake; and AI-generated or manipulated text published to inform the public on a matter of public interest, unless the review and editorial conditions for the exception are met.

 

An ordinary AI product illustration may carry an Article 50(2) machine mark without needing a visible Article 50(4) label. If it does not misleadingly resemble an existing or plausibly existing subject, it is not a deepfake. Voluntary disclosure may still be useful.

What Is the Difference Between AI Marking, Labelling and Disclosure?

Concept

Meaning

Who is responsible?

Example

Machine-readable marking

A technical signal that software can read to identify artificial generation or manipulation

Provider under Article 50(2)

Signed metadata plus an imperceptible watermark

Human-facing labelling

A visible or audible notice a person can perceive

Deployer for in-scope Article 50(4) content

“AI-generated or manipulated” shown with a video

Disclosure

The broader act of informing a person about AI interaction, system operation, or artificial content

Provider or deployer, depending on the paragraph

Chatbot notice, emotion-recognition notice, or deepfake label

 

Machine-readable marking does not by itself satisfy a deployer's deepfake disclosure duty because a natural person should not need a specialist tool or extra action to understand the notice.

Article 50(2) Exceptions to AI Content Marking

The statutory marking obligation does not apply to the extent that:

  • the AI system performs an assistive function for standard editing;

  • the system does not substantially alter the deployer's input data or its semantics; or

  • the system is authorised by law to detect, prevent, investigate, or prosecute criminal offences.

 

“Standard editing” is not a blanket exemption for any workflow that includes a human. The relevant question is what the AI system does to the input and whether it materially changes content or meaning. Ordinary correction or assistance may qualify; substantial generation, replacement, or semantic alteration generally requires a fresh assessment. The Commission's guidelines include examples, while the legal wording in Article 50(2) remains controlling.

Article 50(3): Emotion Recognition and Biometric Categorisation

An emotion recognition system identifies or infers a person's emotions or intentions from biometric data. A biometric categorisation system assigns people to categories using biometric data, subject to the technical-service qualification in Article 3(40).

 

The deployer must inform exposed people whether analysis occurs in real time or later. Article 50 requires notice of operation, not by itself an explanation of purpose. Other laws may require more.

 

The Article 50(3) notice does not apply where the system is permitted by law to detect, prevent, or investigate criminal offences, subject to safeguards and Union law. Any personal-data processing must still comply with the GDPR, Regulation (EU) 2018/1725, or the Law Enforcement Directive, as applicable. Article 50 is a transparency rule, not a legal basis for biometric-data processing.

Article 50(4): What Are the EU AI Act Deepfake Labelling Requirements?

A deepfake is AI-generated or manipulated image, audio, or video that resembles existing persons, objects, places, entities, or events and would falsely appear to a person to be authentic or truthful. The Commission treats resemblance, an existing or plausibly existing subject, and a false appearance of authenticity or truthfulness as cumulative features. Context, audience expectations, the level of resemblance, and the content's message can affect the assessment.

 

A deployer using an AI system to generate or manipulate qualifying deepfake content must disclose that the content was artificially generated or manipulated. Under Article 50(5), the disclosure must be clear and distinguishable, accessible, and available no later than first exposure.

Does Every AI-Generated Image Count as a Deepfake?

No. A stylised abstract image, a clearly fantastical scene, or an image that does not resemble an existing or plausibly existing subject in a misleadingly authentic way may not meet the definition. Conversely, fully generated content can be a deepfake even without editing an original photograph if it convincingly depicts a real or plausibly real person, object, place, entity, or event and falsely appears authentic or truthful.

Deepfake Disclosure Exceptions

Article 50(4) contains a law-enforcement exception where the use is authorised by law to detect, prevent, investigate, or prosecute criminal offences.

 

For evidently artistic, creative, satirical, fictional, or analogous works or programmes, the duty is reduced rather than removed. The deployer must still disclose the existence of AI-generated or manipulated content, but may do so in an appropriate way that does not hamper the display or enjoyment of the work. A credits notice, programme-level notice, or other contextual method may be appropriate, but Article 50 does not prescribe one universal format. The organisation should document why its chosen disclosure remains effective in the context.

Article 50(4): AI-Generated Text About Matters of Public Interest

Article 50(4) also covers text generated or manipulated by an AI system and published for the purpose of informing the public on matters of public interest. The deployer must disclose the artificial generation or manipulation unless the law-enforcement exception applies or the human review or editorial control conditions are satisfied.

 

The duty requires three elements: the text is published, it is intended to inform the public, and its subject is a matter of public interest. Private notes, internal drafts never published, and text that does not inform the public do not meet all three elements, although other rules or internal policies may still apply.

What Counts as a Matter of Public Interest?

The Commission includes politics, public administration, justice, fundamental rights, security, health, environmental protection, consumer safety, and economic, financial, scientific, or cultural developments relevant to public debate. The list is contextual, not closed.

When Does Human Review Exempt AI-Generated Public-Interest Text From Disclosure?

The disclosure is not required where the text has undergone a process of human review or editorial control and a natural or legal person holds editorial responsibility for its publication.

 

Human review means deliberate examination of the substance by one or more people with relevant knowledge and professional judgement. Editorial control means that a responsible editorial entity has practical authority to approve, alter, or reject the substance on substantive grounds, including fact-checking and evaluating source trustworthiness. Editorial responsibility means ultimate legal responsibility for publication, including the review or control process.

 

Evidence may include reviewer assignments, qualifications, substantive edits, fact-check notes, source checks, approval history, and the responsible person or entity.

Is Proofreading Enough to Count as Human Review?

No. The Commission expressly states that superficial, formal, or procedural checks such as spell-checking or grammatical correction do not constitute human review or editorial control. The review must address the substance.

Article 50(5): How Must AI Transparency Information Be Presented?

Article 50(5) requires information under paragraphs 1 to 4 to be:

  • clear;

  • distinguishable;

  • provided no later than the first interaction or exposure; and

  • consistent with applicable accessibility requirements.

When Must the Disclosure Be Provided?

For direct AI interaction, it must be available from the start of the first interaction. For emotion recognition, biometric categorisation, deepfakes, and in-scope public-interest text, it must reach the person no later than first exposure. A notice hidden only in terms and conditions that a person sees later would not meet that timing.

What Does Clear and Distinguishable Mean?

The notice should be understandable and perceivable in its medium. Article 50 sets no universal font, colour, placement, or script. Avoid obscured, ambiguous notices and reliance on specialist tools. Detailed Code placement rules bind signatories as Code commitments, not as new statutory wording.

What Is the EU AI Act Code of Practice on Transparency of AI-Generated Content?

The Code of Practice on Transparency of AI-Generated Content is a voluntary implementation tool developed by independent experts through a process facilitated by the AI Office. It supports compliance with Article 50(2), 50(4), and 50(5).

 

Section 1 applies to providers. It addresses machine-readable marking, preservation of marks, detection mechanisms, the quality of marking and detection, and supporting information. Its technical measures include signed metadata and imperceptible watermarking, while permitting supplementary approaches such as fingerprinting or logging where appropriate.

 

Section 2 applies to deployers. It addresses human-facing labelling of deepfakes and public-interest text, label design and placement, artistic and similar works, and the human review, editorial control, and responsibility conditions for text.

 

The Commission and AI Board assessed the Code as adequate for facilitating compliance. The Commission's adequacy opinion says adherence is not conclusive proof. Non-signatories must demonstrate adequate alternatives.

Is the EU AI Act Transparency Code of Practice Mandatory?

The Code itself is voluntary, but Article 50's legal obligations are mandatory.

 

Non-signatories remain bound by Article 50 and must show adequate alternative measures. Signatories must implement the sections they sign. The Code does not replace the regulation, guidelines, or case-specific enforcement.

What Are the EU AI Act Icons for AI-Generated Content?

The EU icons for labelling AI-generated content are optional visual tools for deployers making Article 50(4) disclosures. They relate to deepfakes and in-scope public-interest text, not to every AI output.

 

There are three semantic choices: basic AI involvement, fully AI-generated, and partially AI-modified. Each has black, white, and semi-transparent black or white treatments. Use is free and optional, does not prove compliance, and does not remove the underlying duty.

How to Comply With EU AI Act Article 50

  1. Create an AI inventory. Record interactive systems, generators, biometric tools, emotion systems, vendors, owners, audiences, and deployment locations.

  2. Identify provider and deployer roles. Classify each organisation's role for each system and note where roles overlap.

  3. Map Article 50 applicability. Test paragraphs 1 to 5 separately instead of using one generic transparency status.

  4. Identify direct AI interactions. Review chatbots, agents, avatars, voice assistants, and conversational interfaces.

  5. Identify synthetic-content workflows. Map text, image, audio, and video generation or manipulation from output creation through publication.

  6. Assess machine-readable marking. Ask providers how marks are embedded, preserved, detected, tested, and documented.

  7. Review deepfake use cases. Assess resemblance, authenticity, context, audience expectations, and disclosure method.

  8. Review public-interest text. Identify publication workflows that inform the public on matters of public interest.

  9. Establish human review and editorial controls. Define substantive review standards, authority, qualifications, evidence, and editorial responsibility.

  10. Establish disclosure procedures. Set clear, accessible, timely notices for each modality and channel.

  11. Document decisions. Keep role assessments, exceptions, vendor evidence, tests, reviews, approvals, and corrective actions.

  12. Monitor regulatory updates. Track standards, Code updates, guidance, enforcement practice, and changes to systems or use cases.

 

Teams building this operating model may use structured learning in AI governance fundamentals to connect Article 50 controls with ownership, documentation, risk, and oversight.

EU AI Act Article 50 Compliance Checklist

  • The AI inventory identifies relevant systems and content workflows.

  • Provider, deployer, and overlapping roles are documented.

  • Direct interactions have been assessed under Article 50(1).

  • Required AI interaction notices are configured and tested.

  • Synthetic text, image, audio, and video outputs are mapped.

  • Provider-side marking and detection evidence is available.

  • Emotion recognition and biometric categorisation uses are identified.

  • Potential deepfakes are reviewed before publication.

  • Public-interest text is assessed against all scope elements.

  • Human review is substantive and performed by suitable reviewers.

  • Editorial control and responsibility are assigned and evidenced.

  • Disclosures are clear, distinguishable, timely, and accessible.

  • The organisation has decided whether to sign the Code or use adequate alternatives.

  • Vendor contracts, test results, decisions, and exceptions are documented.

  • Changes in systems, law, guidance, and enforcement are monitored.

 

Internal AI policy and acceptable use rules should define who may generate or publish synthetic content, when legal review is required, and who owns disclosure and recordkeeping.

What Are the Penalties for Article 50 Non-Compliance?

Article 99 places Article 50 infringements within the tier carrying administrative-fine ceilings of up to €15 million or, for an undertaking, up to 3% of total worldwide annual turnover for the preceding financial year, whichever ceiling is higher. For SMEs, including start-ups, the lower of the percentage or fixed amount applies. The current consolidated text also includes proportional treatment for small mid-cap companies.

 

These are ceilings, not automatic fines. Authorities consider gravity, duration, consequences, affected persons, cooperation, prior infringements, and other circumstances. Warnings, information requests, corrective action, withdrawal, or restrictions may also be available.

 

National market surveillance authorities mainly enforce Article 50. The AI Office covers specified systems, including certain GPAI-based systems and systems integrated into designated very large platforms or search engines. The EDPS handles EU institutions. Authority and penalty depend on the facts.

EU AI Act Article 50 vs GDPR

Article 50 concerns defined AI transparency duties. The GDPR governs personal-data processing, including legal basis, fairness, transparency, data minimisation, security, data-subject rights, and restrictions involving special-category data.

 

Both regimes can apply to the same use case. An employer using an emotion recognition system may have to inform exposed people under Article 50(3), while separately establishing whether biometric personal-data processing is lawful under the GDPR. Meeting the Article 50 notice requirement does not make the processing lawful and does not replace the information required by data-protection law. Article 2(7) of the consolidated AI Act expressly preserves EU data-protection law.

How Article 50 Fits Into an AI Governance Program

Article 50 compliance should sit within the organisation's AI inventory, role mapping, vendor management, risk assessment, human oversight, policy, documentation, training, monitoring, and incident processes. A labelling control will fail if teams do not know which content is synthetic, who owns publication, or whether a vendor's machine-readable mark survives download and redistribution.

 

Connect transparency with security, privacy, intellectual property, accessibility, records, marketing approval, and awareness. Article 50 is one part of Responsible AI, AI ethics and governance, not a stand-alone labelling project.

Article 50 Practical Examples

Example 1: AI customer-service chatbot

Scenario: A company offers a genuine two-way AI chatbot to customers.

 

Applicable Article 50 provision: Article 50(1), with Article 50(5).

 

Required action: The provider must inform customers at the start unless AI interaction is obvious. A deploying customer should verify the configured notice.

Example 2: AI image-generation platform

Scenario: A provider offers a system that generates synthetic images.

 

Applicable Article 50 provision: Article 50(2), with Article 50(5).

 

Required action: The provider must implement machine-readable marking and detection meeting the statutory quality criteria. This does not automatically require a visible label.

Example 3: AI-generated political deepfake

Scenario: A professional campaign team publishes a realistic synthetic video that depicts a political figure saying words the person did not say.

 

Applicable Article 50 provision: Article 50(4), with Article 50(5).

 

Required action: If it is a deepfake, the deployer must disclose the artificial origin no later than first exposure. Provider marking is separate.

Example 4: AI-generated public-interest article

Scenario: A publisher uses AI to draft an article informing the public about a public-health policy.

 

Applicable Article 50 provision: Article 50(4), with Article 50(5).

 

Required action: Disclose unless substantive review or editorial control occurs and a person holds editorial responsibility. Grammar correction is insufficient.

Example 5: Emotion recognition system

Scenario: An organisation uses AI to infer people's emotions from biometric data.

 

Applicable Article 50 provision: Article 50(3), with Article 50(5).

 

Required action: Inform exposed people by first exposure and comply separately with data-protection law.

What Should Businesses Do About Article 50 in 2026?

AI providers

Assess Articles 50(1) and 50(2). Test notices, marking persistence, detection, accessibility, interoperability, and failure modes. Prepare evidence and consider Code Section 1.

AI deployers

Map emotion, biometric, deepfake, and public-interest text uses. Establish pre-publication checks, channel-specific disclosures, and a decision on Code Section 2.

Marketing teams

Approve synthetic people, voices, places, products, and events before release. Creative or satirical context does not remove disclosure completely. Preserve labels during redistribution.

Publishers

Define substantive review, approval authority, and editorial responsibility. Preserve fact-check, source, and edit records. Proofreading is not the exemption.

Compliance teams

Own mapping, exceptions, testing, vendor assurance, records, training, and monitoring. Integrate Article 50 with AI security, governance and compliance controls.

HR and employee AI use

Set rules for publication, synthetic media, approved tools, escalation, and records. Employees must know when publishing creates a deployer duty the vendor cannot perform for them.

Conclusion: What Article 50 Means for AI Transparency in 2026

EU AI Act Article 50 establishes specific transparency obligations that have applied since 2 August 2026. Providers and deployers have different responsibilities. Providers must address direct AI interaction and machine-readable marking, while deployers must address emotion recognition, biometric categorisation, deepfakes, and certain public-interest text.

 

The central compliance distinction is that machine-readable marking is not the same as a visible label. Deepfakes and certain public-interest text require human-facing disclosure, while substantive human review or editorial control plus editorial responsibility can change the rule for public-interest text. The Commission's final guidelines clarify scope and exceptions, and the voluntary Code of Practice offers a recognised implementation route without replacing the law.

 

For professionals who want to place Article 50 within a wider system of ethics, risk, policy, and oversight, the Responsible AI: AI Ethics, Governance & Compliance course offers a structured next step in responsible AI education.

Frequently Asked Questions

It imposes transparency duties for AI interaction, synthetic-content marking, emotion and biometric systems, deepfakes, and certain public-interest text.

It has applied since 2 August 2026. Pre-existing generative systems have a limited Article 50(2) transition to 2 December 2026.

No. Provider-side machine-readable marking and deployer-side visible or audible disclosure are different duties with different scopes and exceptions.

Providers generally machine-mark in-scope images. Deployers add a human-facing disclosure when an image is a deepfake, subject to exceptions.

It applies to qualifying systems and roles, not product names. Conversational AI can trigger provider duties, while professional publication can create deployer duties.

It is a software-readable signal of AI generation or manipulation, potentially using metadata, provenance records, or watermarking.

It is AI-generated or manipulated image, audio, or video that resembles an existing or plausible subject and falsely appears authentic or truthful.

Yes. Providers machine-mark in-scope synthetic text. Deployers disclose covered public-interest text unless an exception applies.

It includes politics, administration, justice, rights, safety, health, the environment, and developments relevant to public debate. Context controls.

For covered text, substantive review or editorial control plus editorial responsibility can remove disclosure. Provider marking remains separate.

No. Spell-checking, grammar correction, and other superficial checks do not qualify as substantive human review or editorial control under the Commission's guidance.

No. The Code is voluntary. Article 50 is mandatory, and non-signatories must demonstrate compliance through alternative adequate measures.

Providers cover paragraphs 1 and 2; deployers cover 3 and 4. Paragraph 5 governs their respective notices.

Yes, potentially, where systems enter the EU market or third-country system output is used in the EU.

Ceilings reach €15 million or 3% of worldwide annual turnover for undertakings. Actual measures depend on the circumstances.

Inventory AI systems, classify provider and deployer roles, map each Article 50 paragraph, test marking and disclosures, formalise substantive review, document decisions, and monitor guidance. Training in AI governance fundamentals can help teams connect those steps to ownership and oversight.