Labelling AI Content: What Article 50 Requires Now
The transparency rules of the EU AI Act have applied since 2 August 2026. Most coverage is written for large corporations. This one is about what a small website has to change, and what it does not.
The transparency obligations of the EU AI Act have been in force since 2 August 2026, per Article 113 of Regulation (EU) 2024/1689. The Digital Omnibus, Regulation (EU) 2026/1744 of 8 July 2026, pushed several high risk deadlines back, and Article 50 was left untouched.
Almost all of it is written for companies with a legal department. A small business has a different picture: a chat window in support, the odd generated header image, copy from an AI tool. What has to change on your site, and what can you leave alone.
This is a practical explanation and not legal advice; for a binding assessment you need a qualified lawyer. Article numbers and dates come from the regulation or the Commission FAQ on Article 50, retrieved 21 August 2026.
Settle the role first, then look for the paragraph
Article 50 splits its duties across two roles. A provider develops an AI system and places it on the market under its own name. A deployer uses such a system under its own authority in a professional capacity, the term Article 3(4) uses. Embed a chatbot widget or take copy from an AI service, and you are the deployer.
That takes two of the four paragraphs off your desk. Company size changes nothing: Article 50 contains no threshold based on turnover or headcount, and a sole trader using an AI system professionally is a deployer just as a large group is.
The four paragraphs, kept apart
Paragraph 1: the chat window says it is a machine
Paragraph 1 binds the provider. AI systems intended to interact directly with natural persons are designed so the person concerned is informed they are interacting with an AI system. The notice can be dropped where this is obvious to a reasonably well informed, observant and circumspect natural person in the circumstances and context of use.
The duty sits with the provider of your widget, the visible consequence on your page. If no notice appears, one line above the input field is quicker than settling who owes it.
Paragraph 2: machine readable marking is the provider's job
Paragraph 2 also binds the provider. Anyone offering an AI system that generates synthetic audio, image, video or text content ensures the outputs are marked in a machine readable format and detectable as artificially generated or manipulated, meaning watermarks and metadata.
This is where the exception most often quoted in the wrong place lives. In the wording, the duty does not apply to the extent the AI systems perform an assistive function for standard editing or do not substantially alter the input data provided by the deployer or the semantics thereof. It belongs to the provider duty in paragraph 2 and does not let a deployer skip disclosure under paragraph 4.
The Commission guidelines add further cases: short sequences of numbers, symbols or letters, source code, and pure machine to machine outputs. For generative systems placed on the market before 2 August 2026, machine readable marking only applies from 2 December 2026. That grace period covers paragraph 2 and legacy systems only, and sources disagree on which provision carries it. Deployer duties are not postponed.
Paragraph 3: emotion recognition and biometric categorisation
Paragraph 3 binds the deployer: anyone operating an emotion recognition or biometric categorisation system informs the people exposed to it and processes personal data under the GDPR. If you analyse neither faces nor voices, this paragraph is done with you.
Paragraph 4, first limb: deep fakes
Paragraph 4 carries two separate limbs. The first covers image, audio and video: anyone deploying an AI system that generates or manipulates such content constituting a deep fake discloses that the content has been artificially generated or manipulated.
Here, and only here, sits the carve out for art. Where the content forms part of an evidently artistic, creative, satirical, fictional or analogous work, the transparency obligation is limited to disclosing the existence of such content, in a manner that does not hamper the display or enjoyment of the work. It does not carry across to AI generated text.
Paragraph 4, second limb: published text on matters of public interest
The second limb covers text. Deployers of an AI system that generates or manipulates text published with the purpose of informing the public on matters of public interest disclose that the text has been artificially generated or manipulated.
The Commission FAQ requires three conditions cumulatively: the text is published, it serves to inform the public, and it concerns a matter of public interest. Miss one and the duty does not apply.
Published, in the Commission's reading, means accessible to an indeterminate and sufficiently large number of unconnected potential readers, simultaneously or in sequence, for payment or free of charge. An open blog clears that bar, a newsletter depending on the list.
As matters of public interest the Commission lists, by way of example, politics and democratic processes, public administration and services, justice and law enforcement, public safety, health, environmental protection, consumer safety, and economic, scientific and cultural developments. A product post sits outside it.
What editorial control means, and what falls short of it
Text comes with an exception, in practice the article's most important sentence. The disclosure duty falls away where the AI generated content has undergone human review or editorial control and where a natural or legal person holds editorial responsibility for the publication.
The Commission fills in all three terms. Human review means deliberate examination of the substance by one or more natural persons possessing relevant knowledge and professional judgement. Editorial control means a responsible editorial body can approve, amend or reject the content on substantive grounds, fact checking included. Editorial responsibility means one person carries the ultimate legal responsibility.
Now the line that decides most cases. Superficial, solely formal or procedural checks are expressly insufficient, the Commission's example being spell checking and grammatical correction. Skimming a draft, fixing two commas and hitting publish is not editorial control. Checking the claims, holding numbers against the source and putting your name to the result is.
Five cases from a small website
| Case on your site | Which paragraph | Who is bound | What to do |
|---|---|---|---|
| Chatbot in the support widget | Paragraph 1 | Provider of the chatbot | Check for yourself whether the notice shows up. If it does not, put a line above the input field. That is quicker than establishing who owes it. |
| AI generated header image on a blog post | Paragraph 2 for the provider, paragraph 4 only for a deep fake | Provider, and you only for a deep fake | An illustrative image with no recognisable real person is not a deep fake. A note in the caption is voluntary here and still worth adding. |
| Product copy from an AI tool, then substantively reworked | Paragraph 4, text | Deployer, so you | Usually no duty. Product copy does not inform the public on a matter of public interest, and a substantive rework additionally meets the editorial control exception. |
| Newsletter subject lines from a suggestion tool | Paragraph 4, text | Deployer, so you | No duty. The public interest condition is missing. Short character sequences are also excluded by the Commission from machine readable marking under paragraph 2. |
| A deep fake in an advertisement | Paragraph 4, deep fake | Deployer, so you | Disclose that the content is artificially generated or manipulated, at the latest at the time of first exposure. The carve out for evidently artistic works does not carry in advertising. |
What a label looks like without wrecking the page
Paragraph 5 covers timing and form: the information comes at the latest at the first interaction or exposure, in a clear and distinguishable manner, in line with accessibility requirements. Translated: on the content itself rather than in a privacy policy, readable as a notice, and as real text a screen reader can announce.
All of that can be done quietly. For a generated image, a caption plus alt text naming the origin. For a chat window, one line above the input field. For an article, one line by the byline. No modal needed.
The Code of Practice is voluntary, the duty is not
Article 50 has a Code of Practice on Transparency of AI-generated Content attached to it, final version published 10 June 2026, drafted by independent experts in a process facilitated by the AI Office. Around 190 companies and organisations had signed by the end of July 2026.
The Commission states plainly that adherence is voluntary while the transparency requirements under Article 50 are legal obligations. Signatories can use the code to demonstrate compliance with paragraphs 2, 4 and 5, everyone else by other appropriate means. The guidelines of 20 July 2026 sit alongside it, also not binding. Neither names a harmonised labelling standard listed in the Official Journal, because none exists so far.
What a breach costs, and who chases it
The penalties sit in Article 99. Paragraph 4, point (g) names the transparency obligations under Article 50 explicitly: up to 15,000,000 euros or, for undertakings, up to 3 percent of total worldwide annual turnover for the preceding financial year, whichever is higher.
For SMEs including start ups, Article 99(6) inverts that: for any fine under paragraphs 3, 4 and 5 the lower of the two figures applies. It affects the size of the fine, not the obligation.
Germany is a worked example. The KI-Marktüberwachungs- und Innovationsförderungsgesetz, KI-MIG for short, was promulgated in BGBl. 2026 I No. 233 of 28 July 2026 and entered into force on 29 July 2026, setting up a coordination and competence centre for the AI Act, KoKIVO, at the Bundesnetzagentur. The act takes a hybrid approach, and regional authorities keep part of the remit, media being one example. Which authority would pursue a blog operator over a missing label could not be established with confidence as of 21 August 2026.
The contrast with the Cyber Resilience Act is instructive: there the German implementing act is still in parliament while the reporting duty from 11 September 2026 applies regardless. Under the AI Act it landed first. Whether you count as a manufacturer under the CRA sits in the article on the CRA and open source.
The grey area this very article sits in
A specialist article about regulation is a borderline case. The Commission list names economic developments and consumer safety, which argues for treating such a text as a matter of public interest. There is no decision on the point and no statement from any authority about company blogs. That is an interpretation, not a quotation.
So we take the simple road: every article here is reviewed on substance by a human, figures are held against the source, and a named person answers for the publication. That triggers the editorial control exception however the public interest question falls.
What this means for the hafenstudios plugins
Checked rather than claimed: of the product pages that could qualify, exactly one names an AI feature. Wellenbrecher offers an AI second opinion in its Pro tier, running on your own access key, as an optional add on to the permanently free core. The Adjet and Kurato pages list none.
If an AI feature runs on your installation with your key, you are the deployer under Article 50, and the duties in paragraphs 3 and 4 land on you. What we cannot give you is a compliance promise, because we have no idea what you publish with it. The AI second opinion itself scores incoming submissions and produces no published content, which on our reading keeps it outside paragraph 4.
Newsletters and contact data inside your own WordPress
Kurato sends through your own provider account, with your own keys, and the contact data stays in your database. If you draft copy with an AI tool, the labelling stays under your control.
What the free tier covers and where Pro starts is listed on the pricing page.
Frequently asked questions
Does Article 50 apply to sole traders and small companies?
Yes. Article 50 contains no threshold based on turnover or headcount. Anyone using an AI system professionally is a deployer under the regulation, whatever the size of the business. The only size dependent relief concerns the level of the fine, through Article 99(6).
Do I have to label every text an AI helped write?
No. The disclosure duty in paragraph 4 only applies when three conditions are met together: the text is published, it serves to inform the public, and it concerns a matter of public interest. A product page or a release note will usually fail the third condition.
Is reading the AI draft through once enough?
That depends on what happens while you read. The Commission requires deliberate examination of the substance by a person with relevant knowledge and professional judgement, with the ability to amend or reject the content on substantive grounds. Superficial, solely formal or procedural checks are expressly insufficient, and the example the Commission gives is spell checking and grammatical correction.
Do I have to go back and label old posts?
No, there is no retroactive effect. Content generated before 2 August 2026 does not have to be labelled after the fact. One special case remains: if you publish a text generated before 2 August 2026 on or after that date, the Commission says it needs a label, provided the conditions of paragraph 4 are met.
Who enforces this at member state level?
It varies by member state. Germany is one worked example: the KI-MIG entered into force on 29 July 2026 and sets up a coordination and competence centre for the AI Act, KoKIVO, at the Bundesnetzagentur. The act takes a hybrid approach and regional authorities keep part of the remit, media being one example. Which authority would actually pursue a blog operator over a missing label could not be established with confidence as of 21 August 2026.