Who's actually in scope — and why "we're not in the EU" doesn't help
The single most common mistake we're seeing this week is companies assuming Article 50 is a European-market-only concern. It isn't. Like the GDPR before it, the AI Act's territorial reach is defined by where the effects land, not where the company is incorporated: if your chatbot, content generator, or synthetic media tool is used by people in the EU, or your output reaches the EU market, Article 50 applies to you whether you're based in Austin, Bangalore, or São Paulo.
That matters more for Article 50 specifically than for most of the AI Act, because the obligations attach to consumer-facing behavior — a chatbot widget, a generated image, a synthetic voice — not to some internal risk classification your legal team can quietly manage. If your product has EU users, the disclosure has to exist for them, regardless of where your servers or your headquarters sit.
The five concrete obligations
1. Disclose that people are interacting with AI
Systems designed for direct interaction with people — chatbots, AI agents, conversational avatars — must make it clear to the person that they're talking to a machine, unless that's obvious from the context. The Commission's guidelines read that exception narrowly: you can't assume a user "should have known." The disclosure needs to appear from the very first interaction, in a way that's clear and accessible. Systems that only operate in the background, without direct interaction with a person, fall outside this specific obligation.
2. Technically mark synthetic content
Whoever builds a system capable of generating or manipulating audio, image, video, or text has to design it so its output carries a machine-readable marker identifying it as AI-generated. This obligation sits with the provider of the system, not the deployer using it, and it's distinct from the visible disclosure covered next. There are carve-outs for standard editing functions that don't substantially alter content, and for purely technical or machine-to-machine outputs.
3. Perceptibly disclose deepfakes
Here the obligated party shifts: whoever uses AI to generate or manipulate image, audio, or video that resembles reality has to inform people that the content is artificial when it qualifies as a deepfake — and that disclosure has to be perceptible to the person exposed to it. A machine-readable watermark buried in the file metadata isn't enough on its own. Clearly artistic, satirical, or fictional works get more flexibility in how the disclosure is presented, so it doesn't undermine the work itself.
4. Label AI-generated text on matters of public interest
When a company publishes AI-generated or AI-manipulated text on economic, political, health, scientific, environmental, or security topics, it must be labeled as AI-generated unless it went through genuine human review or editorial control. The Commission is explicit that a spell-check doesn't count as review: there has to be a person with real judgment over the substance, actual authority to approve, edit, or reject the text, verify facts, and assess source reliability — and someone who takes editorial responsibility for the piece.
5. Disclose emotion recognition and biometric categorization
Lawful use of emotion-recognition or biometric-categorization systems must be disclosed to the people exposed to them. This transparency duty doesn't make an otherwise-prohibited use legal: AI that infers emotions in the workplace or in schools remains banned since February 2025, except for narrow medical or safety exceptions. Check legality first, then layer transparency on top — not the other way around.
| Obligation | Who's responsible | When it applies |
|---|---|---|
| AI interaction disclosure | Provider / deployer of the chatbot or agent | From the start of the interaction, unless obvious from context |
| Technical marking of synthetic content | Provider of the generative system | Already in force; transition until Dec 2, 2026 for pre-August systems |
| Deepfake disclosure | Deployer | When publishing or distributing, unless artistic/satirical exception applies |
| Public-interest text labeling | Publisher | When there's been no genuine human review or editorial control |
| Emotion/biometric disclosure | Deployer | Whenever the underlying use is lawful |
What to check this week
- Inventory your AI tools across customer service, marketing, HR, and content — provider, function, and output type for each.
- Classify each tool by whether it interacts with people, generates published content, or uses biometrics/emotion recognition.
- Check the actual disclosure a user sees today in every chatbot or agent: does it exist, is it clear, does it show up from the first message?
- Review the editorial process for any AI-generated content on public-interest topics: is there a person with real authority, or just a spell-checker?
- Assign an internal owner for disclosures, traceability, and content approval if one doesn't already exist.
The fines aren't symbolic
Article 50 violations sit among the infringements punishable by fines of up to €15 million or 3% of worldwide annual turnover, with proportionality rules for SMEs that avoid an automatic maximum penalty but don't remove the obligation to comply. Beyond the fine, the more immediate risk is reputational: an undisclosed chatbot or an unlabeled deepfake is exactly the kind of thing that goes viral online long before any regulator gets involved.
The high-risk timeline moved. Article 50's didn't. If your company runs any AI facing the public — and most do — this week's task is simple to state and easy to postpone: inventory what you have, classify it, and confirm the disclosure your users actually see is real.