Skip to content
C50 Clause50EU AI Act transparency — made auditable.EU AI Act evidence, made auditable
EU AI Act · Guide

The EU AI Act & Article 50, in plain English

The Act sorts every AI system into one of four risk classes and attaches different duties to each. This guide walks all four, shows which one you are probably in, and links down to the detail — starting with Article 50, the class most products in production today actually sit in.

Article 50 transparency obligations apply from 2 August 2026.

What the EU AI Act is

The EU AI Act is a risk-based framework: it sorts AI systems into unacceptable-risk (banned), high-risk, limited-transparency-risk, and minimal-risk tiers, and attaches different obligations to each. It applies to anyone placing a system on the EU market, or whose system’s output is used by people in the EU — regardless of where the provider or deployer is based.

Most AI products in production today — chatbots, AI-generated content, virtual assistants — sit in the transparency-risk tier. That’s Article 50’s home, and these are the obligations Clause50 evidences.

Two words do most of the work throughout. A provider develops an AI system, or places one on the market under its own name or trade mark. A deployer uses one under its own authority. The same organisation is very often both — if you build a chatbot and also run it, duties from both roles land on you at once.

The four risk classes

The class is decided by what the system is used for, not by what technology is inside it. One model can be minimal-risk in one product and high-risk in another.

The EU AI Act’s four risk classes, as a pyramidFour stacked bands, narrowest at top. Unacceptable risk: banned outright, Article 5. High risk: Annex III and Annex IV, heavy obligations. Limited transparency risk: Article 50, disclose to people. Minimal risk, the widest band: no specific obligations beyond the AI-literacy duty.UnacceptableBanned outright · Art. 5High riskAnnex III & IV · heavy dutiesLimited riskArticle 50 · tell peopleMinimal riskNo specific obligations

1. Unacceptable risk — prohibited outright (Article 5)

Banned outright since 2 February 2025 — social scoring, mass biometric scraping, workplace/school emotion inference, exploiting vulnerable groups, most real-time public biometric ID. There is no compliance route for a prohibited system — it may not be placed on the market at all.

2. High risk — the heavy end (Article 6, Annexes I and III)

A safety component under EU product law, or one of Annex III’s eight areas — biometrics, infrastructure, education, employment, essential services, law enforcement, migration, justice. Brings risk management, data governance, logging, human oversight, a technical file, conformity assessment. Annex III & Annex IV, in detail →

3. Limited transparency risk — Article 50

Talks to people, generates synthetic content, or produces deepfakes. The duty is to tell people, clearly, at first interaction — not to change the system. Where most products live today, set out in full below. Article 50 in depth →

4. Minimal risk — everything else

Spam filters, recommenders, forecasting, most internal tooling. No obligations beyond Article 4’s AI-literacy duty, which binds everyone regardless of class. Voluntary codes of conduct only (Article 95).

One more thing that is not a risk class, and is confused with one constantly: the obligations on general-purpose AI models (Articles 53 and 55) bind the organisations that build those models, not the people building products on top of them. Why GPAI is not Article 50 →

Does it apply to you?

Three things need to hold. If all three do, Article 50 applies to that system from 2 August 2026:

1. Reach

Your system is offered in the EU, or its output is used by people in the EU. This can reach organisations with no EU presence at all.

2. Role

You’re a provider (you develop or brand the system) or a deployer (you use it under your own authority) — the duties differ by role.

3. Situation

Your system falls into one of the four situations covered by the duties below.

The four Article 50 duties

50(1) — “You’re talking to an AI.”

Providers of AI that interacts directly with people must ensure users are informed it’s an AI system, unless that’s already obvious. (Exemption: certain law-enforcement uses.)

50(2) — “This was AI-generated.”

Providers of AI generating synthetic audio, image, video, or text must mark outputs, machine-readably, as artificially generated. (Exemption: minor or assistive editing that doesn’t substantially alter the input.)

50(3) — “This system reads emotions/biometrics.”

Deployers of emotion-recognition or biometric-categorisation systems must inform the people exposed to them, and process personal data under GDPR. (Exemption: certain law-enforcement uses.)

50(4) — “This is a deepfake / AI-written.”

Deployers who generate or manipulate deepfake image, audio, or video content must disclose it; AI-generated text published to inform the public on matters of public interest must also be disclosed. (Exemptions: clearly artistic or satirical work gets limited disclosure; content under human editorial responsibility; certain law-enforcement uses.)

Across all four duties, the information must be given clearly, at the first interaction or exposure, and in an accessible form (Art. 50(5)). The full treatment — exemptions, timing, and the evidence an auditor asks for →

EU AI Act Article 50 — provider vs deployer dutiesTwo columns. Provider (you build or brand the AI) owns Article 50(1) tell users it’s an AI, for chatbots and assistants, and 50(2) mark AI-generated output, for synthetic audio, image, video and text. Deployer (you use it under your authority) owns 50(3) inform the people exposed, for emotion and biometric systems, and 50(4) disclose it’s AI-made, for deepfakes and public-interest text. One organisation can be both. Information must be given clearly at first interaction, per 50(5).Article 50 — who must do whatThe duty depends on your role. One organisation can hold both.PROVIDERyou build or brand the AI systemDEPLOYERyou use it under your own authority50(1)Tell users it’s an AIChatbots & AI assistants50(2)Mark AI-generated outputSynthetic audio, image, video, text50(3)Inform the people exposedEmotion & biometric systems50(4)Disclose it’s AI-madeDeepfakes & public-interest textSame organisation can be both. If you build a chatbot and also run it, 50(1) and 50(3)/(4) can all apply.Across all four: tell people clearly, at first interaction or exposure, in an accessible way (Art. 50(5)).

When it applies — timeline

Source: European Commission; the two postponed high-risk dates reflect the Digital Omnibus on AI, below.

  • 1 Aug 2024Regulation enters into force — nothing applies yet.
  • 2 Feb 2025Prohibited practices + AI literacy obligations begin.
  • 2 Aug 2025GPAI obligations, governance, and penalties begin.
  • 27 Jul 2026The Digital Omnibus on AI (Regulation (EU) 2026/1744) enters into force, postponing the two high-risk dates below.
  • 2 Aug 2026Article 50 transparency duties (+ most of the Act) begin.
  • 2 Dec 2027High-risk systems under Article 6(2) and Annex III begin — postponed from the original 2026 date by the Digital Omnibus.
  • 2 Aug 2028High-risk systems under Article 6(1) and Annex I (embedded in already-regulated products) begin.

The Digital Omnibus citation above is not yet counsel-reviewed (see the notice at the foot of this page); verify against the consolidated regulation before relying on the exact dates.

What happens if you don’t comply

Article 99 sets three ceilings, and which one applies depends on what was breached. Article 99(3) is the highest and covers the prohibited practices of Article 5. Article 99(4) is the middle tier and covers operator obligations — including, expressly, the Article 50 transparency duties. Article 99(5) is the lowest and covers supplying incorrect or misleading information to authorities. Article 99(6) points the ceiling downwards for SMEs and start-ups.

An actual fine is not a ceiling: Article 99(7) lists ten criteria a national market surveillance authority must weigh, with no published weights or methodology. Our penalty estimator renders the statutory ceilings from Article 99 and keeps them visibly separate from any illustration, because they are not the same kind of number. See the full regulation text below for the exact figures and how they’re calculated.

Go deeper

How Clause50 helps

Clause50 turns these duties into versioned, hash-chained, auditor-ready evidence for every client site you manage. Start with a free check and a free scan to see where you stand.

Official & further reading

Not yet reviewed by counsel. This page explains our reading of Regulation (EU) 2024/1689 and is kept deliberately close to the regulation’s own wording, but it has not been through legal review. Clause50 produces compliance documentation; it is not legal advice and does not by itself make any system compliant — the obligations described here remain yours. Verify anything you rely on against the primary regulation or your own counsel. See our terms.