Art 50: the four disclosure duties

Lesson 1 of 5 in Transparency and General-Purpose AI: Art 50 and the GPAI Chapter.

Between the heavy machinery of the high-risk chapter and the freedom of minimal risk sits the Act’s lightest-touch tier: transparency. Art 50 does not demand conformity assessments or risk management systems. It demands one thing, four ways: people must not be deceived about when they are dealing with AI or its outputs.

The four duties, and — crucially — who owes each:

  1. Art 50(1), providers of interactive systems. An AI system intended to interact directly with natural persons must be designed so those persons are informed they are dealing with AI — unless this is obvious to a reasonably well-informed, observant and circumspect person, given the context. A law-enforcement exception applies for systems authorised by law to detect or investigate crime.
  2. Art 50(2), providers of synthetic-content generators. Systems generating synthetic audio, image, video or text must mark their outputs in a machine-readable format, detectable as artificially generated or manipulated — the next lesson dissects this.
  3. Art 50(3), deployers of emotion-recognition and biometric-categorisation systems. They must inform the exposed persons about the system’s operation, and process personal data in line with the GDPR and the Law Enforcement Directive.
  4. Art 50(4), deployers of deepfakes and public-interest text. Deployers of systems generating or manipulating deepfakes must disclose the artificial origin — softened where the use is evidently artistic, creative, satirical or fictional, where disclosure only needs to avoid hampering the work. Deployers generating or manipulating text published to inform the public on matters of public interest must disclose too — unless a human performed editorial review and someone holds editorial responsibility for the publication.

Notice the pattern before the decision tree drills it: duties (1) and (2) sit on providers — they attach at design time, to the system itself. Duties (3) and (4) sit on deployers — they attach at use time, to the act of exposing people or publishing content. This is the value-chain logic in miniature: whoever controls the moment of potential deception owes the disclosure.

Delivery has its own standard (Art 50(5)): the information must be provided clearly and distinguishably at the latest at the first interaction or exposure, and meet accessibility requirements. A disclosure buried in clause 14.3 of the terms of service is a non-disclosure.

Two boundary lines matter. First, Art 50 duties stack on top of any high-risk duties — an emotion-recognition system in a call centre is both Annex III high-risk and Art 50(3)-disclosable; the tiers are cumulative, not exclusive. Second, Art 50(3) presumes the practice is lawful at all: emotion recognition in the workplace or education is prohibited outright by Art 5(1)(f) (save the medical/safety exception) — disclosure cannot launder a prohibited practice.

Which Art 50 duty — if any — do you owe?

Interactive decision tree — outcomes:

  • Art 50(1): design in the disclosure

    As provider, design the system so users are informed they are dealing with AI — clearly, distinguishably, at the latest at first interaction, accessibly (Art 50(5)). A law-enforcement exception exists for legally authorised crime-detection systems. And remember this is also high-risk-neutral: if the system is high-risk for other reasons, those duties stack on top.

  • Art 50(2): machine-readable marking

    Your outputs must be marked in a machine-readable format and detectable as artificially generated or manipulated — with solutions as effective, interoperable, robust and reliable as technically feasible. Exceptions: assistive/standard-editing functions that do not substantially alter the input, and legally authorised law-enforcement uses. Compliance deadline post-Omnibus: 2 December 2026.

  • Art 50(3): inform the exposed persons

    As deployer, inform the natural persons exposed to the system about its operation, and process their personal data in accordance with the GDPR or the Law Enforcement Directive. Note the classification stack: emotion recognition and biometric categorisation are also Annex III point 1 high-risk uses.

  • Art 50(4): disclose the deepfake

    Disclose that the content has been artificially generated or manipulated — clearly, at first exposure. Undisclosed authentic-seeming deepfakes are exactly what this paragraph exists to prevent.

  • Art 50(4): softened disclosure

    For evidently artistic, creative, satirical or fictional works, disclosure is limited to an appropriate form that does not hamper the display or enjoyment of the work — a credit line or content note rather than a banner across the frame.

  • Art 50(4): disclose the AI text

    Text informing the public on matters of public interest must be disclosed as artificially generated unless the human-editorial-review-and-responsibility exception applies. An automated news feed with no editor owes the label.

  • Exception applies — no Art 50(4) label required

    Human editorial review plus a person holding editorial responsibility takes the text outside Art 50(4)’s disclosure duty. The provider’s Art 50(2) machine-readable marking of the raw output still happened upstream — the exception is yours, not theirs.

  • Stop — Art 5 territory

    Emotion recognition in the workplace or education is prohibited by Art 5(1)(f), except for medical or safety reasons — the top penalty tier (€35M / 7% of worldwide turnover). No disclosure cures a prohibited practice. Re-scope the use or abandon it.

  • No deployer disclosure duty

    Content that is neither a deepfake nor public-interest text carries no Art 50(4) duty for the deployer. The provider’s Art 50(2) marking still applies to the generator itself — and voluntary labelling remains good practice.

  • No Art 50 duty in this situation

    Art 50 does not bite here. Keep checking the other tiers: the system may still be high-risk under Art 6, and the AI-literacy duty of Art 4 applies to providers and deployers across the board.

Key terms: deepfake, synthetic content, emotion recognition, biometric categorisation, transparency obligations

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.