AI labelling obligations since August 2026: what Article 50 actually requires

Editorial note: The information in this article was compiled to the best of our knowledge at the time of publication. Technical details, prices, versions, licensing terms, and external content may change. Please verify the information provided independently, particularly before making business-critical or security-related decisions. This article does not replace individual professional, legal, or tax advice.

Do you use AI that is visible to the outside? WZ-IT reviews AI use, settles the role question and runs models on your own infrastructure, see AI solutions. Discuss your setup
Article 50 of the AI Act has applied since 2 August 2026. Coverage of it reduces to a single sentence: companies must label their chatbots and mark AI content.
That sentence is right on substance and wrong on attribution. Article 50 distributes its four obligations across two different roles, and most companies carry only part of them. Anyone skipping the role question builds notices they do not owe and misses the obligation that actually applies to them.
This article assigns the four paragraphs to their addressees, sets out the 2 December 2026 deadline, and covers the case that shifts the roles: the self-hosted model.
All details from the regulation text, as of 31 August 2026.
Table of contents
- The role question comes first
- The four paragraphs and their addressees
- Paragraph 1: the notice that it is a machine
- Paragraph 2: machine-readable marking
- Paragraph 4: what the deployer must disclose
- The 2 December 2026 deadline
- Self-hosted models shift the role
- What Article 50 does not regulate
- How we approach this at WZ-IT
- Further guides
The role question comes first
The AI Act knows two roles, and almost every obligation hangs on them.
A provider develops an AI system or has it developed and places it on the market or puts it into service under their own name or trademark.
A deployer uses an AI system under their own authority.
A company that buys a chatbot from a vendor and embeds it on its website is a deployer. A company that runs a language model in house and builds an assistant from it that it provides under its own name is a provider.
This distinction is not a technicality. It decides which of the four obligations in Article 50 apply at all.
The four paragraphs and their addressees
| Paragraph | Subject | Addressee |
|---|---|---|
| 1 | Notice that the person is interacting with an AI system | provider |
| 2 | Machine-readable marking of synthetic content | provider |
| 3 | Notice for emotion recognition and biometric categorisation | deployer |
| 4 | Disclosure for deepfakes and informative AI text | deployer |
For a company that uses finished AI tools, paragraphs 3 and 4 are therefore the relevant ones. Paragraphs 1 and 2 are owed by the maker of the tool.
This is where the common summary "companies must label their chatbots" misleads. A purchased chatbot must arrive with the notice built in. Whoever deploys it should check that it does, but does not owe it themselves.
Paragraph 1: the notice that it is a machine
Paragraph 1 requires that AI systems intended to interact directly with natural persons are designed and developed so that the persons concerned are informed that they are interacting with an AI system.
Two points about this are regularly missed.
The notice must be built into the system. The wording targets design and development, not a line in the privacy policy.
The exemption is narrow. No notice is needed where this is obvious from the point of view of a reasonably well-informed, observant and circumspect person. For an assistant that answers in full sentences and follows up on questions, that exemption does not hold.
Under paragraph 5 the information must be provided at the latest at the time of the first interaction, in a clear and distinguishable manner, and must meet accessibility requirements. A notice that only appears after the third answer does not satisfy this.
The obligation applies regardless of whether the counterpart is a customer or an employee. An internal assistant falls under it.
Paragraph 2: machine-readable marking
Paragraph 2 requires providers of AI systems generating synthetic audio, image, video or text content to mark those outputs in a machine-readable format and make them detectable as artificially generated or manipulated. The obligation expressly includes general-purpose AI systems.
Exempt are assistive editing functions that do not substantially alter the input data. A spellchecker does not fall under this; a full rewrite does.
For image, audio and video the path is mapped out: embedded provenance data and watermarking are established methods.
For plain text there is no settled method. Watermarking text is a subject of research, but none of it is a standard an assessor could expect. That is an open point in the regulation, and it affects precisely the case that occurs most often in companies. Anyone wanting to be safe here documents traceably which content was machine-generated, rather than claiming a marking that does not technically hold.
Paragraph 4: what the deployer must disclose
Paragraph 4 addresses the deployer and has two parts.
Deepfakes. Anyone deploying an AI system that generates or manipulates image, audio or video content constituting a deepfake must disclose that the content has been artificially generated or manipulated.
Informative text. Anyone publishing AI-generated or manipulated text in order to inform the public on matters of public interest must disclose this.
The second part is often read too broadly. It targets content of public interest, not every text on a corporate website. A product description generally does not fall under it.
Two exemptions matter in practice:
- Artistic, creative, satirical or fictional works: here the obligation is limited to disclosing the existence of such content in an appropriate manner without hampering the display of the work.
- Editorial responsibility: content that has undergone human review or editorial control and for which a person holds editorial responsibility is exempt.
The second exemption is the workable route for most companies: review and take responsibility for AI drafts, rather than marking every paragraph.
The 2 December 2026 deadline
For systems already placed on the market or put into service before 2 August 2026, the machine-readable marking obligation under paragraph 2 applies only from 2 December 2026.
That grace period is not in the original regulation text. It came through the Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force since 27 July 2026. Anyone consulting the 2024 text will not find it, and Article 111 on pre-existing systems does not cover it either.
Three points for context:
- The grace period applies only to paragraph 2, not to the other obligations. The notice under paragraph 1 and the disclosure under paragraph 4 have applied since 2 August 2026 with no transition.
- It applies only to pre-existing systems. A system going live after 2 August 2026 must bring the marking from the start.
- The same Omnibus postponed the high-risk obligations: Annex III to 2 December 2027, embedded systems under Annex I to 2 August 2028. We covered that separately.
Self-hosted models shift the role
Here lies the point missing from most accounts.
Anyone running a language model on their own infrastructure, for instance with vLLM or Ollama behind their own interface, and providing an application from it under their own name, is no longer merely a deployer. They are putting an AI system into service under their own name and thereby become a provider.
The consequence: paragraphs 1 and 2 are added.
| purchased service | self-hosted model | |
|---|---|---|
| Role | deployer | provider and deployer |
| AI notice (para. 1) | owed by the vendor | owed by you |
| Machine-readable marking (para. 2) | owed by the vendor | owed by you |
| Deepfake disclosure (para. 4) | owed by you | owed by you |
This is not an argument against self-hosting. It is an argument for settling the role question before the architecture decision and building the paragraph 1 notice into the interface straight away, rather than retrofitting it later.
For environments where data must not leave the premises, the reasons for self-hosting outweigh this anyway. How that looks in practice we described for local AI in companies. What is added is traceable logging showing which model produced which output, see Langfuse.
What Article 50 does not regulate
Three boundaries that come up regularly in conversation:
Article 50 is not a permission. It governs transparency, not admissibility. Whether an AI deployment is lawful under data protection law is answered by the GDPR, not the AI Act.
Article 50 requires no certification. There is no notification, no registration and no conformity assessment for transparency obligations. Anyone claiming such an obligation is confusing it with the high-risk requirements.
Article 50 displaces nothing. Paragraph 6 makes clear that other transparency obligations under Union or national law continue to apply alongside.
How we approach this at WZ-IT
We start with an inventory rather than a measure: which AI systems run in house, which of them interact with people or generate content, and which role you hold for each.
That usually yields a short action plan. In the cases we have seen it comes down to a few places: a notice in the interface of a self-built assistant, documented editorial responsibility for AI-assisted text, and the question of which pre-existing systems need marking by 2 December.
Where models run on your own infrastructure, we set up logging so that it remains traceable later which model produced which output. Article 50 does not expressly require this, but it is the basis for any account you may have to give.
Further guides
- EU AI Act: high-risk obligations and what applies from August 2026 - the postponement through the Digital Omnibus
- Self-hosting Langfuse - logging for AI applications
- vLLM, Ollama or llama.cpp - inference servers for self-hosting
- Local AI or ChatGPT Business - cost and control compared
- AI solutions at WZ-IT - overview of the offering and approach
Unsure which role you hold? We review your AI use, assign each application to a role and set out what obligations follow. Book a call
Sources
Review your AI use against the labelling obligation
We review which AI systems you use, which role you hold for each, and what obligations follow from that.
Frequently Asked Questions
Answers to important questions about this topic
Article 50 of the AI Act has applied since 2 August 2026. For systems already placed on the market before that date, the machine-readable marking under paragraph 2 applies only from 2 December 2026. That grace period came through the Digital Omnibus on AI, which entered into force on 27 July 2026.
The obligation in Article 50(1) falls on the provider, meaning whoever develops the system and places it on the market. Anyone buying a finished chatbot is a deployer and not the addressee of that paragraph. Anyone building the chatbot themselves, for instance on a self-hosted model, becomes the provider and carries the obligation.
A provider develops an AI system or has it developed and places it on the market under their own name or trademark. A deployer uses an AI system under their own authority. Article 50 distributes its obligations differently: paragraphs 1 and 2 address the provider, paragraphs 3 and 4 the deployer.
Yes. Article 50 sets no threshold by company size or turnover. What matters is whether an AI system interacts directly with people or generates synthetic content, not how large the company behind it is.
No. Article 50(1) exempts cases where this is obvious from the point of view of a reasonably well-informed, observant and circumspect person. That exemption is narrow and does not hold as soon as the interaction resembles a conversation with a human.
Paragraph 2 requires that generated outputs are marked in a machine-readable format and detectable as artificially generated or manipulated. For image, audio and video, methods such as embedded provenance data and watermarking are established. For plain text there is no settled method, and that is exactly where implementation remains open.
Two separate obligations apply. The provider must mark machine-readably under paragraph 2. The deployer must disclose under paragraph 4 when publishing AI-generated text to inform the public on matters of public interest. A product description generally does not fall under this; an editorial piece on a societal topic more likely does.
Paragraph 4 exempts content that has undergone human review or editorial control and for which a natural or legal person holds editorial responsibility. Anyone who reviews and takes responsibility for AI drafts falls under that exemption.
The role. Anyone running a model in house and building an application from it that they provide under their own name is no longer merely a deployer but a provider. Paragraphs 1 and 2 then apply in addition, including machine-readable marking of generated content.
Paragraph 1 attaches to direct interaction with natural persons and does not distinguish between customers and employees. An internal assistant that staff chat with falls under it. The practical hurdle is low, because a notice in the interface is enough.
The AI Act provides for fines for breaches of the transparency obligations, imposed by the national market surveillance authorities. The larger practical consequence is usually not the fine but that an unlabelled chatbot looks like deception in a dispute.
No, these are separate regimes. The obligations for high-risk systems under Annex III were postponed to 2 December 2027 through the Digital Omnibus, and for embedded systems under Annex I to 2 August 2028. Article 50 has applied independently since August 2026.

Written by
Timo Wevelsiep
Co-Founder & CEO
Co-Founder of WZ-IT. Specialized in cloud infrastructure, open-source platforms and managed services for SMEs and enterprise clients worldwide.
LinkedInLet's Talk About Your Idea
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.





