Article50.io
Guide · Providers & deployers

EU AI Act Transparency Obligations Under Article 50

Article 50 is the part of the EU AI Act dedicated to transparency: making sure people know when AI is talking to them or produced what they're seeing. Which obligations land on you depends on whether you're a provider or a deployer.

Provider or deployer?

01
Provider — Art. 3(3)
Develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark. Chatbot vendors and generative-AI tool makers are providers.
02
Deployer — Art. 3(4)
Uses an AI system under its own authority in a professional capacity. A business that embeds a vendor's chatbot or publishes AI-generated images on its website is a deployer.
03
Both
Build your own AI feature and ship it to visitors, and you're the provider of that system and its deployer. Many SaaS products with in-app AI assistants fall here.

Who owes what under Article 50

Providers carry the design-level obligations. Under Article 50(1), an AI system that interacts directly with people must be designed so they're informed they're dealing with an AI, unless it's obvious from context. Under Article 50(2), systems that generate synthetic audio, image, video or text must mark their outputs in a machine-readable, detectable way.

Deployers carry the publication-level obligations. Under Article 50(4), anyone deploying AI to create deep fakes must disclose that the content is artificially generated or manipulated, and anyone publishing AI-generated text to inform the public on matters of public interest must disclose that too, unless it has been through human editorial control.

In practice, the line blurs on a live website. If your vendor's chatbot doesn't announce itself, visitors still see your site with an undisclosed AI on it. The pragmatic move is to add the disclosure yourself rather than wait on the vendor.

What “transparency” means here

Article 50 transparency is about the person on the other end — the visitor, the reader, the viewer. It's not about explaining how a model works internally or publishing training data. The test is simple: would someone reasonably know that AI is involved in what they're interacting with or looking at?

That information has to be clear and distinguishable, and given at the latest at the time of the person's first interaction or exposure. For a chatbot that means a notice in or beside the chat window; for an image, a label or marker attached to the image itself.

How Article 50 differs from high-risk obligations

The AI Act is organised around risk. Some AI practices are prohibited outright; high-risk systems — in areas like hiring, credit scoring or critical infrastructure — face heavy requirements such as risk management, data governance, human oversight and conformity assessment.

Article 50 is a separate, lighter layer focused specifically on transparency. It doesn't require a conformity assessment or a risk management system; it requires telling people the truth about AI involvement. It applies to the AI systems it names regardless of their risk classification, so an ordinary customer service chatbot that is nowhere near high-risk still owes an Article 50(1) disclosure.

Lighter doesn't mean cheap to ignore: Article 50 breaches fall under fines of up to €15 million or 3% of worldwide annual turnover. See the full Article 50 explainer for the enforcement timeline, or the compliance checklist for what to fix first.

Frequently Asked Questions

Am I a provider or a deployer under the EU AI Act?

If you develop an AI system (or have one developed) and place it on the market or put it into service under your own name, you're a provider (Article 3(3)). If you use an AI system under your own authority in a professional capacity — for example, embedding a vendor's chatbot on your site — you're a deployer (Article 3(4)). One organisation can be both for different systems.

Do Article 50 transparency obligations only apply to high-risk AI?

No. Article 50 applies to the specific kinds of AI system it names — systems that interact with people, generate synthetic content, or produce deep fakes and public-interest text — whether or not they're classed as high-risk. A system can be subject to both sets of rules.

Does a privacy policy mention satisfy Article 50?

Unlikely. Article 50 requires the information to be given in a clear and distinguishable manner, at the latest at the time of first interaction or exposure. A line buried in a policy page most visitors never open doesn't meet that bar.

Check your site automatically

Article50.io is an automated Article 50 transparency assessment platform that scans websites for potential EU AI Act transparency obligations and provides remediation guidance, implementation instructions, and compliance-ready disclosure language.

The free scan shows your single most severe finding in about 30 seconds — no signup, public pages only.

Related Article 50 resources

Automated technical guidance, not legal advice. Citations refer to Regulation (EU) 2024/1689.