The EU AI Act & Article 50, in plain English
The Act sorts every AI system into one of four risk classes and attaches different duties to each. This guide walks all four, shows which one you are probably in, and links down to the detail — starting with Article 50, the class most products in production today actually sit in.
Article 50 transparency obligations apply from 2 August 2026.
What the EU AI Act is
The EU AI Act is a risk-based framework: it sorts AI systems into unacceptable-risk (banned), high-risk, limited-transparency-risk, and minimal-risk tiers, and attaches different obligations to each. It applies to anyone placing a system on the EU market, or whose system’s output is used by people in the EU — regardless of where the provider or deployer is based.
Most AI products in production today — chatbots, AI-generated content, virtual assistants — sit in the transparency-risk tier. That’s Article 50’s home, and these are the obligations Clause50 evidences.
Two words do most of the work throughout. A provider develops an AI system, or places one on the market under its own name or trade mark. A deployer uses one under its own authority. The same organisation is very often both — if you build a chatbot and also run it, duties from both roles land on you at once.
The four risk classes
The class is decided by what the system is used for, not by what technology is inside it. One model can be minimal-risk in one product and high-risk in another.
1. Unacceptable risk — prohibited outright (Article 5)
Banned outright since 2 February 2025 — social scoring, mass biometric scraping, workplace/school emotion inference, exploiting vulnerable groups, most real-time public biometric ID. There is no compliance route for a prohibited system — it may not be placed on the market at all.
2. High risk — the heavy end (Article 6, Annexes I and III)
A safety component under EU product law, or one of Annex III’s eight areas — biometrics, infrastructure, education, employment, essential services, law enforcement, migration, justice. Brings risk management, data governance, logging, human oversight, a technical file, conformity assessment. Annex III & Annex IV, in detail →
3. Limited transparency risk — Article 50
Talks to people, generates synthetic content, or produces deepfakes. The duty is to tell people, clearly, at first interaction — not to change the system. Where most products live today, set out in full below. Article 50 in depth →
4. Minimal risk — everything else
Spam filters, recommenders, forecasting, most internal tooling. No obligations beyond Article 4’s AI-literacy duty, which binds everyone regardless of class. Voluntary codes of conduct only (Article 95).
One more thing that is not a risk class, and is confused with one constantly: the obligations on general-purpose AI models (Articles 53 and 55) bind the organisations that build those models, not the people building products on top of them. Why GPAI is not Article 50 →
Does it apply to you?
Three things need to hold. If all three do, Article 50 applies to that system from 2 August 2026:
1. Reach
Your system is offered in the EU, or its output is used by people in the EU. This can reach organisations with no EU presence at all.
2. Role
You’re a provider (you develop or brand the system) or a deployer (you use it under your own authority) — the duties differ by role.
3. Situation
Your system falls into one of the four situations covered by the duties below.
The four Article 50 duties
50(1) — “You’re talking to an AI.”
Providers of AI that interacts directly with people must ensure users are informed it’s an AI system, unless that’s already obvious. (Exemption: certain law-enforcement uses.)
50(2) — “This was AI-generated.”
Providers of AI generating synthetic audio, image, video, or text must mark outputs, machine-readably, as artificially generated. (Exemption: minor or assistive editing that doesn’t substantially alter the input.)
50(3) — “This system reads emotions/biometrics.”
Deployers of emotion-recognition or biometric-categorisation systems must inform the people exposed to them, and process personal data under GDPR. (Exemption: certain law-enforcement uses.)
50(4) — “This is a deepfake / AI-written.”
Deployers who generate or manipulate deepfake image, audio, or video content must disclose it; AI-generated text published to inform the public on matters of public interest must also be disclosed. (Exemptions: clearly artistic or satirical work gets limited disclosure; content under human editorial responsibility; certain law-enforcement uses.)
Across all four duties, the information must be given clearly, at the first interaction or exposure, and in an accessible form (Art. 50(5)). The full treatment — exemptions, timing, and the evidence an auditor asks for →
When it applies — timeline
Source: European Commission; the two postponed high-risk dates reflect the Digital Omnibus on AI, below.
- 1 Aug 2024Regulation enters into force — nothing applies yet.
- 2 Feb 2025Prohibited practices + AI literacy obligations begin.
- 2 Aug 2025GPAI obligations, governance, and penalties begin.
- 27 Jul 2026The Digital Omnibus on AI (Regulation (EU) 2026/1744) enters into force, postponing the two high-risk dates below.
- 2 Aug 2026Article 50 transparency duties (+ most of the Act) begin.
- 2 Dec 2027High-risk systems under Article 6(2) and Annex III begin — postponed from the original 2026 date by the Digital Omnibus.
- 2 Aug 2028High-risk systems under Article 6(1) and Annex I (embedded in already-regulated products) begin.
The Digital Omnibus citation above is not yet counsel-reviewed (see the notice at the foot of this page); verify against the consolidated regulation before relying on the exact dates.
What happens if you don’t comply
Article 99 sets three ceilings, and which one applies depends on what was breached. Article 99(3) is the highest and covers the prohibited practices of Article 5. Article 99(4) is the middle tier and covers operator obligations — including, expressly, the Article 50 transparency duties. Article 99(5) is the lowest and covers supplying incorrect or misleading information to authorities. Article 99(6) points the ceiling downwards for SMEs and start-ups.
An actual fine is not a ceiling: Article 99(7) lists ten criteria a national market surveillance authority must weigh, with no published weights or methodology. Our penalty estimator renders the statutory ceilings from Article 99 and keeps them visibly separate from any illustration, because they are not the same kind of number. See the full regulation text below for the exact figures and how they’re calculated.
Go deeper
- GuideArticle 50 in depthAll four duties written out, with the exemptions, the Article 50(5) timing rule, and what an auditor actually asks you to show.
- Which uses make a system high-risk, the nine points of the technical file, and why that evidence has to be recorded as it happens.
- The most common mix-up in the whole Act: model-provider duties mistaken for your own.
- Clause50What Clause50 covers todayRendered live from our rule pack, with a plain statement of where we stop.
How Clause50 helps
Clause50 turns these duties into versioned, hash-chained, auditor-ready evidence for every client site you manage. Start with a free check and a free scan to see where you stand.
Official & further reading
- The binding legal text; most authoritative source for Article 50.
- Source of truth for the application timeline.
artificialintelligenceact.eu is an independent resource maintained by the Future of Life Institute — not an official EU site. For the binding legal text, see EUR-Lex above.
Not yet reviewed by counsel. This page explains our reading of Regulation (EU) 2024/1689 and is kept deliberately close to the regulation’s own wording, but it has not been through legal review. Clause50 produces compliance documentation; it is not legal advice and does not by itself make any system compliant — the obligations described here remain yours. Verify anything you rely on against the primary regulation or your own counsel. See our terms.