Article 50 of the EU AI Act does not hand one department a job. It hands seven paragraphs to different actors, and the split between them decides whether your obligation is to redesign a product or to add a sentence to a page footer. Most companies reading Article 50 assume the heavy duties are theirs. For deployers, two of them are not.
This article is about that split. It is not a timeline piece. Article 50 has applied since 2 August 2026 and the Digital Omnibus did not move it, which we covered in the enforcement tracker, and the high-risk obligations that did move are a separate story. What follows is the question those pieces leave open: which paragraph is yours, and who in the building signs for it.
Who owes Article 50, and which paragraph?
Article 50 assigns each of its disclosure duties to either the provider or the deployer of a system, and never to both. The Commission's own guidelines, published 20 July 2026, set it out as a table. Here it is against the operative text:
| Provision | Who owes it | The duty |
|---|---|---|
| 50(1) | Provider | Build interactive systems so people are told they are dealing with an AI |
| 50(2) | Provider | Mark synthetic audio, image, video or text in a machine-readable format |
| 50(3) | Deployer | Tell people exposed to emotion recognition or biometric categorization |
| 50(4), first subparagraph | Deployer | Disclose deep fake image, audio or video |
| 50(4), second subparagraph | Deployer | Disclose AI-generated text published to inform the public on matters of public interest |
| 50(5) | Whoever owes 50(1) to 50(4) | Make it clear, distinguishable, accessible, and no later than first interaction |
| 50(6) | Nobody | A savings clause preserving Chapter III and other transparency law |
| 50(7) | The Commission | Encourage codes of practice and assess whether they are adequate |
Read the second column again if you run a company that buys AI rather than builds it. The two duties that cost real engineering effort, 50(1) and 50(2), are provider duties. A company using a vendor's chatbot or a vendor's image generator does not owe the marking obligation in 50(2). The vendor does.
That is the good news, and it lasts exactly as long as you stay a deployer.
How an in-house chatbot turns you into a provider
The provider label is not a description of what industry you are in. It is a description of what you did to a system. Guidelines paragraph 11 says that where a company takes a generative AI system another provider placed on the market, modifies it, and puts it into service under its own name or trade mark, that company becomes a provider of the new system, without prejudice to the responsibility of the original provider.
Two ordinary enterprise patterns cross that line.
The first is fine-tuning. You take a foundation model, train it on your own data, and ship the result to customers as your product. You are now a provider of that system, and 50(2) is yours. The second is quieter and catches more people: an in-house assistant, built on somebody else's model, put into service under your own brand. Your customers see your name on it. So does the regulator.
This is the single most expensive misreading available in Article 50, because a company that believes it is a deployer will budget for a disclosure banner and will not budget for provenance marking on every generated asset. The two sit several orders of magnitude apart in cost.
What exactly has to be disclosed?
Article 50(1) is narrower than its reputation. The text:
"Providers shall ensure that AI systems intended to interact directly with natural persons are designed and developed in such a way that the natural persons concerned are informed that they are interacting with an AI system, unless this is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use."
Note what it does not say. It does not prescribe wording, placement, font, or a standard phrase. It does not require a consent click. It requires that the person be informed, and 50(5) adds that the information must arrive in a clear and distinguishable manner at the latest at the time of the first interaction or exposure, and must conform to applicable accessibility requirements.
That last clause does real work and is widely skipped. A disclosure rendered as gray placeholder text at 11 pixels, or as an image with no alternative text, is a disclosure that fails an accessibility requirement and therefore fails 50(5).
When is AI obvious enough to skip the disclosure?
The exemption in 50(1) is written against a specific imaginary person: one who is reasonably well-informed, observant and circumspect. That standard is doing the opposite of what most teams hope. It does not ask whether your team knows the thing is a bot. It asks whether a reasonably attentive outsider would, in that context.
A widget that opens with a robot avatar and the words "AI Assistant" clears it comfortably. A voice agent that answers your support line with a human-sounding greeting does not, and voice is where this bites hardest, which is why it surfaces early in contact center and voice deployments.
The practical test we would apply: if a reasonable person could finish the entire interaction still believing they spoke to an employee, disclose. The sentence costs nothing. The argument with a regulator about what was obvious costs a great deal.
Do internal copilots and employee tools count?
Mostly they clear the exemption, and for a reason worth understanding rather than assuming.
An employee who has been trained on the tool, who opens it from an internal launcher, and who knows it is a copilot is a reasonably well-informed person for whom the AI nature is obvious. That is the exemption working as designed, not a carve-out for internal systems. There is no internal-use exemption in Article 50.
Guidelines paragraph 14 adds a point that resolves an argument we have watched companies have with themselves: individual employees acting under the instructions and control of the legal person, including content creators, designers and journalists, should not be considered separate deployers. The obligation sits with the organization. A marketing employee who generates a campaign image does not personally become a deployer with their own disclosure duty. Your company was already the deployer.
The place internal tools stop being simple is the moment their output leaves the building. An assistant used to draft a public policy statement has produced text that may fall under 50(4), and the person who used it knowing it was AI is not the person the disclosure protects.
Which duties can land on the same system at once
Guidelines paragraph 8 states that the transparency obligations may apply cumulatively to the output of a single AI system, possibly engaging the responsibility of different actors.
A customer-facing assistant that also generates images is the common case. It owes 50(1) because it interacts with people. Its provider owes 50(2) because it produces synthetic content. If your marketing team then publishes one of those images as a realistic depiction of something that did not happen, your company owes 50(4) as deployer. One system, three duties, two companies.
This is why the ownership question cannot be answered once and filed. It has to be answered per system and per output type, which is the form the checklist at the end of this article takes.
What evidence proves you complied?
Article 50 does not contain an evidence clause. No paragraph tells you to keep records of your disclosures. This is the gap that turns a solved compliance question into an unprovable one eighteen months later, when the person who configured the banner has changed jobs.
What a regulator can ask for, and what you should therefore be able to produce, falls into four groups:
| Evidence | What it proves |
|---|---|
| A system inventory naming, per AI system, whether you are provider or deployer | That you performed the classification at all |
| Dated screenshots or rendered captures of each disclosure as users see it | 50(5) clarity, placement and timing |
| An accessibility check on the disclosure element | The 50(5) accessibility requirement |
| A record of who approved the obvious-from-context call, and on what reasoning | That the exemption was a decision, not an oversight |
The fourth row is the one that matters most and exists least. Where a company decided no disclosure was needed, the file should say who decided, when, and why. An undocumented exemption and a missed obligation look identical from the outside.
If you want the mapping from these duties to the evidence a deployer keeps, alongside the rest of the regulation, we maintain a working map of the Act's obligations to evidence. The disclosure rule itself belongs in a written policy rather than in somebody's memory, and an acceptable use policy is where it lands in practice.
Who signs: legal, marketing, or product?
Article 50 fails in most companies for an organizational reason rather than a legal one. The duties are split across functions that do not share a backlog.
50(1) is a product duty, because the disclosure has to be designed into the interface. 50(2) is an engineering duty, because marking is a pipeline change. 50(4) is a marketing and communications duty, because it attaches to what gets published. The classification that decides which of these you owe is a legal and compliance judgment. No single one of those four functions can complete the work, and each can reasonably believe another owns it.
The fix is not a committee. It is a named owner per paragraph, recorded in the same place as the system inventory, which turns "who handles Article 50" into four smaller questions that each have an answer.
Penalties sit in the 3% tier. Article 99(4)(g) covers transparency obligations under Article 50, with administrative fines up to EUR 15 000 000 or 3% of total worldwide annual turnover, whichever is higher. Whether any national authority has yet used it against an Article 50 breach is a different question, and as of this writing the public record shows none.
The checklist
Per AI system in your estate, answer in this order. The first answer changes every answer after it.
| # | Question | If yes |
|---|---|---|
| 1 | Did you modify it and put it into service under your own name or trade mark? | You are the provider. 50(1) and 50(2) are yours. |
| 2 | Does it interact directly with people? | 50(1) applies unless the AI nature is obvious to a reasonably attentive user. |
| 3 | Does it generate audio, image, video or text? | Its provider owes 50(2) machine-readable marking. |
| 4 | Does it infer emotion or categorize people biometrically? | You owe 50(3) as deployer, plus a GDPR basis. |
| 5 | Do you publish realistic generated image, audio or video? | You owe 50(4) disclosure as deployer. |
| 6 | Do you publish AI-written text on matters of public interest? | You owe 50(4) unless a named person holds editorial responsibility. |
| 7 | For every yes above: is the disclosure clear, distinguishable, accessible, and present at first interaction? | That is 50(5), and it applies to all of them. |
| 8 | For every no: is the reasoning written down and dated? | That is your defense. |
Row 6 has an exemption worth reading closely, because it is the one that most publishing workflows already satisfy without knowing it. The duty does not apply where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication. An editor who reviews and signs off discharges it. An automated publishing pipeline with nobody named does not.