
- Who it's for
- Anyone running a chatbot or AI agent, using AI images in advertising or in a shop, or publishing text written with AI.
- What you'll be able to do
- Know which of the four labelling duties applies to you, who in the company is responsible, and which notices the Commission considers insufficient.
- As of
- September 2026
Since 2 August 2026, people must be able to tell that they are talking to an AI or looking at something an AI produced. For most businesses that means the chatbot says at the start that it's an AI, and deceptively realistic AI images or videos carry a visible notice. A line in your terms and conditions won't do. Most advertising copy is not affected, and nor is text that a person has reviewed in substance and taken responsibility for.
What has applied since 2 August
Article 50 of the AI Act is the rule that affects almost every business using AI in front of customers. It has applied since 2 August 2026.1 Unlike the obligations for high-risk systems, which the amending Regulation (EU) 2026/1744 pushed back to 2 December 2027 (and, for AI in regulated products under Annex I, to 2 August 2028), it was not postponed — apart from one transitional period, covered below.2
The overall timetable is set out in the update at the top of the post on the AI inventory. This post is only about labelling.
Since 20 July 2026 there have been European Commission guidelines on the subject.3 They are not binding — as they say themselves, only the Court of Justice of the EU can give an authoritative interpretation.4 But they show how supervisors will read the rule, and they are full of examples. Most of what follows comes from there.
Four duties, two roles
Article 50 contains four duties aimed at two different parties: the provider, who develops an AI system or has it developed and places it on the market or puts it into service under its own name, and the deployer, who uses it under its own authority — unless purely for personal purposes.1
Your role depends on what you do, not on how big you are. The guidelines explicitly name as a provider a company that develops a chatbot in-house and puts it into service under its own name for its own use.4 Anyone who modifies an existing system, for example with new training data, and puts it into service under their own name also becomes the provider of the new system.4
By contrast, a company that simply commissions an advertising agency, without deciding whether or how the agency uses AI, is not a deployer under the guidelines.4
The chatbot: it has to say it's an AI
The duty in paragraph 1 is the one most often overlooked, precisely because it sounds so obvious. People interacting with an AI system must be told so — unless it is obvious from the circumstances to a reasonably well-informed, observant person.1
I wouldn't build on that exception. The guidelines say it "should be interpreted restrictively", and point out that general awareness that chatbots exist does not mean people recognise them in a conversation.4
The regulation doesn't prescribe what the notice looks like. The guidelines give examples: a chatbot that opens the conversation by saying it is based on AI; a voice assistant that says so at the start; an email from an AI agent with an AI label at the top.4 The notice has to come at the latest at the first interaction, be clearly recognisable and be accessible.1
The guidelines list notices that are not enough on their own:4
- a notice only in the terms and conditions, in a URL or in the documentation
- a machine-readable mark that the person doesn't perceive during the interaction
- vague labels such as just "assistant", or a human-looking representation
- a blanket line like "Services on this website use AI" on a site offering many services
- a purely technical statement like "this system uses LLMs" that doesn't explain what it means for the user
A single, clearly visible notice before the first interaction is enough in most cases. In riskier contexts — the guidelines name financial, insurance, legal and health advice, as well as complaints handling, among others — repeated notices are likely to be needed.4 And if someone asks the chatbot whether it is a person, it has to tell the truth.4
The same applies to AI agents, with one addition. Agents that book, correspond or negotiate on someone's behalf should, according to the guidelines, disclose both that they are artificial and on whose behalf they are acting.4 More on agents in the post on four questions before an agent gets access.
A notice doesn't make a wrong answer right, by the way. That a business is liable for what its chatbot says was decided by the Higher Regional Court of Hamm in May — details in When your chatbot gets it wrong, you said it.
AI images and video: when an image becomes a deepfake
Under the regulation, a deepfake is AI-generated or manipulated image, audio or video content that resembles existing persons, objects, places, entities or events and would falsely appear to a person to be authentic or truthful.1 Anyone using such content has to disclose that it was artificially generated.
The word suggests fake political speeches, but it covers product images too. The guidelines explicitly count machinery and consumer goods as "objects".4 And they give as an example of a deepfake an AI-generated image of a product in advertising or on packaging that can mislead as to the product's actual appearance, characteristics or use.4
The line doesn't run between real and artificial, but between harmless and misleading. The guidelines' examples show it:4
For evidently artistic, satirical or fictional works, a notice that doesn't spoil the work is enough.1 The EU has created a set of icons that deployers can use for labelling.6
AI text: usually not affected, with one exception
The text rule is narrower than many people think. Disclosure is only required for AI text published to inform the public on matters of public interest.1 The guidelines name topics such as politics, public administration, public health, environmental protection, consumer safety and economic developments that may be the subject of public debate.4
Explicitly outside the scope: AI-edited text in advertising and product descriptions, as long as it makes no claims about, for example, health, consumer safety or sustainability. Likewise internal texts on a corporate network and advice written for an individual client.4
And even within the scope, the duty falls away if two conditions are both met: a person has reviewed the text in substance, and someone holds editorial responsibility.1
The guidelines take "reviewed in substance" seriously. Fact-checking is the minimum; spell-checking, the mere existence of an editorial policy or a cursory sign-off don't count.4 And if you have the AI rework the text after sign-off, you lose the exception again.4
One example from the guidelines that concerns businesses: a sustainability report on a listed company's website that professionals, for instance from compliance, have reviewed falls under the exception.4 Without that review, the exception doesn't apply.
Machine-readable marking and the December deadline
Paragraph 2 requires AI output to be marked in a machine-readable format and detectable as artificially generated.1 That is the duty of the provider of the generating system. If you create images with an image model you've bought in, it usually isn't yours.
This is where the only transitional period applies. Providers whose systems were already on the market before 2 August 2026 have until 2 December 2026 to add the marking.2 The guidelines make clear that this only covers marking: a system that both generates content and talks to people has had to give the AI notice since 2 August.4
The deadline matters to you if you offer a generating system of your own — say, an image generator for customers. Then you are the provider, and 2 December is your deadline.
You don't have to label anything retroactively: content generated before 2 August 2026 doesn't need to be marked or labelled after the fact. Text on matters of public interest that was generated before but published after that date does.4
What happens if you don't
Breaches of Article 50 can be fined up to €15 million or up to 3% of worldwide annual turnover, whichever is higher. For small and medium-sized enterprises, the lower of the two applies.5
In Germany, the Federal Network Agency has been the central point of contact and complaints body for the AI Act since 29 July 2026.7 According to the guidelines, anyone with grounds to suspect a breach can lodge a complaint.4
Anyone who signs a code of practice that the Commission has assessed as adequate can rely on its measures. There is such a code for labelling AI content; the Commission and the AI Board have confirmed it as an adequate voluntary tool.6
What I would do now
Most of the work isn't the implementation, it's knowing where to look. If you know where in the business an AI talks to people or produces images, can add the labelling where it is needed. If you don't, start with the AI inventory.
- Every point listed where an AI talks to customers, applicants or suppliers — chatbot, phone, email agent
- For each one, clarified whether you are the provider (own development, own name) or a provider supplies the labelling
- A notice at the start of every conversation, not just in the terms or the privacy policy
- AI product images checked for whether they show the product differently from how it is
- For published text on public topics, decided who reviews it in substance and who signs off
- Agreed with your agency or service provider who labels AI content they deliver
If you have a chatbot, an agent or an image workflow and aren't sure the notice is in the right place: tell me what it does and where it runs. I'll tell you what's missing according to the guidelines and how much work it is to fix. It is no substitute for legal advice.
Sources
- 1Regulation (EU) 2024/1689 (AI Act), Articles 3, 50 and 113 — EUR-Lex · retrieved 23 September 2026
- 2Regulation (EU) 2026/1744 (Digital Omnibus on AI), recital 38 and new Article 111(4) — EUR-Lex · retrieved 23 September 2026
- 3European Commission: Guidelines on transparency obligations for providers and deployers of AI systems (20 July 2026) · retrieved 23 September 2026
- 4European Commission: Guidelines on Article 50, C(2026) 5054 final, annex (PDF) · retrieved 23 September 2026
- 5Regulation (EU) 2024/1689, Article 99(4) and (6) — EUR-Lex · retrieved 23 September 2026
- 6European Commission: Code of Practice on Transparency of AI-generated Content · retrieved 23 September 2026
- 7Bundesnetzagentur: takes on central role in implementing the AI Act (29 July 2026, in German) · retrieved 23 September 2026
