Skip to main content
← notes
AI · 7 Oct 2026 · 6 min read

AI Act Article 50: a checklist for the AI in your product

blurple studio

Since 2 August 2026, the AI Act's transparency rules apply. If your product has a chatbot, an assistant or an agent, or if it generates images, audio, video or text, Article 50 decides what you have to tell people, and when. The changes the EU agreed this year delayed the rules for high-risk AI, not these. This is the checklist we work from.

First, the short version of the law

  • Who it covers: the provider, who builds an AI system and offers it under their own name, and the deployer, who uses one in their own product or service. If you build an assistant on top of a model API and put it in your app under your brand, you are generally treated as the provider of that assistant, not only as a user of someone else's model.
  • Where it applies: to AI systems offered in the EU, and to systems whose output is used in the EU. Companies outside the EU, including in Türkiye, are covered when they serve people in the EU.
  • When: from 2 August 2026. The one exception is the machine-readable marking of generated content (point 2 below): generative systems already on the market before that date have until 2 December 2026.
  • Fines: up to €15 million or 3% of worldwide annual turnover, whichever is higher. For small and medium-sized companies and startups, whichever is lower.

What follows is what it means on the screen.

1. Say it's AI, before the conversation starts

Article 50(1): people who interact with an AI system must be told so, unless it is already obvious to a reasonably well-informed person in that context.

  • Chat and assistants: say it in the first message or right above the input field: "I'm an AI assistant." Not on a terms page, and not only after someone asks.
  • Voice: say it out loud at the start of the call.
  • Don't lean on "it's obvious". A human name, a friendly avatar and a natural tone make it less obvious, not more. If you've designed it to feel human, say it isn't.
  • Agents that act for your users: when your agent writes to or calls someone on a user's behalf, the person on the other side is interacting with an AI system too. Design the disclosure into those messages.

Our own example: Ask Blu, the assistant on this site, introduces itself as an AI assistant in its first message, and says so again in a line under the input.

2. Mark what it generates

Article 50(2), for providers: synthetic audio, images, video and text must be marked in a machine-readable way, so they can be detected as AI-generated or manipulated.

  • What counts: embedded metadata and watermarks; content credentials such as C2PA are one widely used approach.
  • What doesn't: assistive features that only edit lightly, such as spelling fixes or cropping, and don't substantially change what the user put in.
  • If you use a model provider's API: find out what marking the provider already applies, and make sure your own pipeline doesn't strip it. Image processing that re-encodes files and drops metadata is the usual culprit.

3. Label deepfakes and AI text on public matters

Article 50(4), for deployers:

  • Deepfakes: images, audio or video that resemble real people, places or events and would falsely appear authentic must be disclosed as AI-generated or manipulated. For clearly artistic, satirical or fictional work, the disclosure can be made in a way that doesn't spoil the work.
  • Text on matters of public interest: AI-generated text published to inform the public must be disclosed, unless a person has genuinely reviewed it and someone holds editorial responsibility for it. A quick glance before publishing is not editorial review.
  • In marketing: a campaign visual showing a real person or place in a scene that never happened counts. A stylised illustration usually doesn't.

4. Emotion recognition and biometric categorisation

Article 50(3): if your product infers emotions, or sorts people into categories from biometric data, tell the people it is used on, and process the data under the GDPR. Note that emotion recognition at work and in education is prohibited outright under Article 5, apart from medical and safety uses.

5. Make the notice usable

Article 50(5): the information must be clear and distinguishable, given at the latest at the first interaction or exposure, and it must meet accessibility requirements.

  • Text, not only an icon. A screen reader must read it, and its contrast must pass.
  • In the language of the product.
  • Visible on touch screens and with a keyboard, not only on hover.
  • The same pattern everywhere in the product, so people learn to recognise it.

If you are working on the European Accessibility Act too, the two meet here: our EAA checklist covers the accessibility side.

What doesn't count

  • A line in the terms of service. Nobody reads it at the moment that matters.
  • A tooltip that only appears on hover. It doesn't exist on a phone or for a keyboard user.
  • A model's logo in the footer. It names a technology; it doesn't tell people they're talking to an AI.

Where we come in

  • AI Readiness Sprint (€1,500, half a day): what AI should, and shouldn't, do in your product, the AI Act's transparency rules included, with a 90-day plan you own.
  • Agent Experience (AX) design: conversation design, failure states, trust and consent, and Article 50 transparency, designed into the product rather than added at the end.

We design and build products that meet these requirements and document how. For the legal reading, we work alongside your counsel.

Useful? Share it with your team.
Want us to look at your product?

A short call, and we'll tell you honestly where you stand and what the first step should be.