Article50.io
Checklist · SaaS · Art. 50

EU AI Act Article 50 Compliance Checklist for SaaS Companies

· 10 min read

For a SaaS company, Article 50 of the EU AI Act applies to specific product surfaces, not to the business as a whole. The main ones are your chat widget, your in-app assistant, any feature that generates content, and any feature that reads emotions or categorises people from biometric data. For most of these you are the provider, and the customers who use your AI features are often deployers with their own separate duties. This checklist goes through each surface in turn.

If you want the general, website-focused version, use the Article 50 compliance checklist. This page covers what is specific to SaaS products.

Key point: Article 50 sets four transparency duties. 50(1): providers must design AI systems that talk to people so users know it's an AI, unless that's obvious. 50(2): providers of generative AI must mark outputs in a machine-readable, detectable way. 50(3): deployers of emotion recognition or biometric categorisation must tell the people exposed to it. 50(4): deployers must disclose deep fakes and AI-generated text published to inform the public on matters of public interest.

Provider or deployer: settle this first

You are the provider of any AI system you develop, or have developed, and place on the market under your own name (Art. 3(3)). You are a deployer when you use an AI system under your own authority in a professional capacity (Art. 3(4)). A typical SaaS company is the provider of its own AI features and the deployer of vendor tools it embeds, such as a third-party support bot. The transparency obligations guide covers the distinction in more depth.

  • List every AI feature in your product and on your marketing site
  • For each one, record whether you are the provider, the deployer, or both
  • For each one, record which of 50(1)–50(4) it could trigger

Deadlines and fines

Article 50 applies from 2 August 2026. Regulation (EU) 2026/1744 (the "Digital Omnibus on AI") inserted a new Art. 111(4). Under it, providers of generative AI systems that were already on the market before 2 August 2026 have until 2 December 2026 to comply with Art. 50(2). That extension covers only the 50(2) marking duty for legacy systems. It does not delay 50(1), 50(3) or 50(4).

Breaches of Article 50 fall under Art. 99(4): fines of up to €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs, including start-ups, the cap is whichever of the two is lower (Art. 99(6)). Art. 99(6a), added by the Digital Omnibus, extends that lower cap to small mid-cap enterprises. See what happens if you ignore Article 50.

1. Marketing site chat widget · Art. 50(1)

This is the most visible gap, and it is the one an outside party is most likely to notice first.

  • Every chat widget with AI answers turned on tells visitors they are talking to an AI, including vendor widgets such as Intercom, Drift, Zendesk and Crisp
  • The notice appears in or beside the chat window at the latest when the conversation starts, not only in your terms or privacy policy
  • The notice is clear, distinguishable from the surrounding interface, and accessible (screen readers can read it, and it is not faint or tiny text), in line with Art. 50(5)
  • Human-sounding bot personas (a first name and an avatar) are still disclosed as AI, because a friendly persona makes it hard to argue the AI is "obvious from context"
  • The widget hands over to a human agent in a way that makes clear when the visitor is no longer talking to the AI

For wording, use the free AI chatbot disclaimer template. For whether a disclosure is needed at all, see does my chatbot need an AI disclosure?

2. In-app AI assistants and copilots · Art. 50(1)

When you build the assistant, you are its provider. The 50(1) duty is to design it so users are informed.

  • The assistant identifies itself as AI inside the product UI, not just in onboarding emails or help docs
  • This works on every surface where the assistant can talk to someone: web app, mobile app, Slack or Teams integrations, email replies and voice
  • Voice agents and AI phone features identify themselves as AI at the start of the call
  • If you rely on "obvious from context", you have written down why, for each interface. Treat it as a narrow exception rather than a default
  • Where your AI sends messages to third parties on a user's behalf, such as AI agents that email or chat with people outside your customer's organisation, you have decided how those recipients will be informed

Your customers may embed your assistant in their products under their brand. Section 6 covers what they need from you.

3. Generative features you provide · Art. 50(2)

If your product generates synthetic audio, images, video or text for customers, you as the provider must mark those outputs in a machine-readable format so they can be detected as artificially generated or manipulated. This applies whether the output is marketing copy, product images, voiceovers or avatar video.

  • Every generative output type (text, image, audio, video) has a marking approach that is machine-readable and detectable
  • Your marking approach is effective, interoperable, robust and reliable as far as technically feasible, and you have documented where it isn't feasible and why
  • If you build on a third-party model API, you have checked whether the upstream provider marks outputs and whether your own pipeline keeps or strips that marking (resizing, transcoding, format conversion)
  • Export and download paths keep the metadata or watermark, not just the in-app preview
  • Features that only assist with standard editing, or don't substantially alter the user's input, have been assessed against the 50(2) exceptions and the result recorded
  • If the feature was on the market before 2 August 2026, you have a plan to meet the 2 December 2026 deadline

The AI-generated content labelling guide covers what marking looks like in practice.

4. AI outputs your customers publish · Art. 50(4)

Article 50(4) applies to deployers. When your customer publishes a deep fake (Art. 3(60)) or AI-generated text meant to inform the public on matters of public interest, the duty to disclose it falls on the customer. You can't make that disclosure for them. What you can do is make it easy for them.

  • Your product lets customers add a visible "AI-generated" label to exports, or includes one by default where that makes sense
  • Features that can produce realistic people, voices, places or events (avatars, voice cloning, face swap, photoreal images) are flagged in your UI as likely to produce deep fakes
  • Customers who publish AI-drafted articles or reports know about the exemption for human review or editorial control, and that it only applies when someone holds editorial responsibility
  • Your own marketing team follows the same rules when it publishes AI-generated images, video or articles, because for that content you are the deployer

Background: deep fake disclosure, does Article 50 apply to AI-generated text?, do AI avatars require disclosure?. For label wording, see the AI content label template.

5. Emotion recognition and biometric categorisation · Art. 50(3)

Under Article 50(3), deployers of an emotion recognition system or a biometric categorisation system must inform the people exposed to it that the system is operating. They must also process the personal data in line with the GDPR, or with Regulation 2018/1725 or Directive 2016/680 where those apply. There is a narrow exception for systems permitted by law to detect, prevent or investigate criminal offences.

In SaaS, this is most likely to come up in call-centre tools that analyse voice tone, video-meeting or interview tools that read facial expressions, and retail or event analytics that categorise people from camera feeds.

  • You have checked whether any feature infers emotions or intentions, or assigns people to categories, from biometric data such as face, voice or body signals. Text-only sentiment analysis probably doesn't count, but get it reviewed
  • You have ruled out prohibited uses. Emotion recognition in workplaces and education institutions is generally banned under Article 5, apart from medical or safety reasons. That is a bigger problem than a missing disclosure
  • Customers deploying these features have a clear way to notify the people exposed, for example meeting participants or callers
  • There is a GDPR basis and a DPIA for the biometric processing, whether you act as processor or controller

The free scan does not detect emotion recognition or biometric categorisation. This section has to be reviewed by hand.

6. Contracts and docs for customers who deploy your AI

Article 50 doesn't spell out a provider-to-customer paperwork duty. Even so, your customers' own 50(3) and 50(4) compliance depends on what you tell them, and B2B procurement teams increasingly ask for it.

  • Product docs list each AI feature, say whether it interacts with people, generates content or processes biometric data, and name the Article 50 paragraph it relates to
  • Docs explain how your 50(2) marking works and which export paths keep it
  • Terms or an AI addendum assign responsibilities: you handle interaction disclosure and output marking, and the customer handles deployer-side disclosure of deep fakes, public-interest text and emotion recognition
  • White-label and embed agreements say who is the provider once the customer puts its own brand on your assistant, and they don't let customers switch off the AI disclosure
  • Sales and support teams have a one-page answer to "is your product Article 50 compliant?" that doesn't overclaim

For the official text, see the AI Act Service Desk's Article 50 page and the Commission's Article 50 transparency FAQ. The Commission's July 2026 Article 50 guidelines have been widely reported, including by Bird & Bird, Reed Smith and Davis+Gilbert. They are guidance, not binding law.

A quick check for the public-facing part

A free Article50.io scan loads one public URL. It flags two things: a known or custom chat widget with no visible AI-interaction disclosure, and machine-readable AI-generation markers on the page with no visible AI-content disclosure. That makes it a fast way to check the marketing-site items in section 1 and part of section 4.

It can't log in, so it doesn't see your in-app copilot. It doesn't inspect watermarks or C2PA metadata inside media files, and it doesn't detect emotion recognition. It doesn't judge whether something is "obvious from context", and it doesn't decide whether you are the provider or the deployer. A clean scan does not mean you are compliant. Sections 2, 3, 5 and 6 need a manual review.

Frequently asked questions

Is my SaaS company a provider or a deployer under Article 50?

Usually both. You are the provider (Art. 3(3)) of AI features you build and ship under your own name, so the design duties in Article 50(1) and 50(2) are yours. You are a deployer (Art. 3(4)) of third-party AI tools you use yourself, such as a vendor chatbot on your site, and of any AI-generated content your own team publishes. Your customers are typically deployers of your features, and they carry the Article 50(3) and 50(4) disclosure duties for how they use them.

When do SaaS companies have to comply with Article 50?

Article 50 has applied since 2 August 2026. There is one extension. Under Article 111(4), inserted by the Digital Omnibus on AI (Regulation (EU) 2026/1744), providers of generative AI systems already on the market before 2 August 2026 have until 2 December 2026 to meet the Article 50(2) machine-readable marking requirement. The chatbot disclosure, emotion recognition and deep fake duties are not extended.

What are the fines for a SaaS company that breaches Article 50?

Breaches fall under Article 99(4): up to €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. For SMEs and start-ups, Article 99(6) applies the lower of the two figures. Article 99(6a), added by the Digital Omnibus on AI, extends that lower cap to small mid-cap enterprises. These are maximums, and actual fines depend on the circumstances.

Does Article 50 apply to AI features inside a logged-in SaaS app?

Yes. Article 50 attaches to the AI system, not to whether it sits on a public page. An in-app copilot that talks to users needs an AI-interaction disclosure under Article 50(1) unless that's obvious from context, and generative features need machine-readable output marking under Article 50(2). Automated public-page scanners, including Article50.io's, can't see behind a login, so in-app features need a manual review.

Does text sentiment analysis count as emotion recognition under Article 50(3)?

Probably not, but get it reviewed. Article 50(3) covers emotion recognition and biometric categorisation systems, and the AI Act ties these to biometric data such as facial features or voice. Sentiment scoring of written text usually isn't based on biometric data. Voice-tone or facial-expression analysis in call, meeting or interview tools is much more likely to be caught, and in workplace or education settings it may be prohibited outright under Article 5.

This checklist is general information, not legal advice. Consult a qualified lawyer about your specific obligations.

Check your site automatically

Article50.io is an automated Article 50 transparency assessment platform that scans websites for potential EU AI Act transparency obligations and provides remediation guidance, implementation instructions, and compliance-ready disclosure language.

The free scan shows your single most severe finding in about 30 seconds — no signup, public pages only.

More from the blog

Automated technical guidance, not legal advice. Citations refer to Regulation (EU) 2024/1689.