A single clause in the EU AI Act has quietly become one of the most operationally consequential provisions for any organization deploying generative AI in Europe. Article 50, which took effect on , mandates that AI-generated content be identifiable as such. The accompanying Code of Practice on Transparency of AI-Generated Content, finalized in June 2026, translates that legal obligation into a compliance pathway that organizations can actually implement.
The code is voluntary. The underlying legal requirement is not. That distinction matters for every marketing team, newsroom, and customer service operation now running generative AI in production.
The Mechanism: Who Carries the Obligation
Article 50 creates a two-tier structure. Providers, meaning the companies that build or supply generative AI systems, must ensure their outputs are machine-readable and detectable as artificially generated. Deployers, meaning the organizations that use those systems to produce content, carry the labeling obligation when that content reaches the public.
Legal analysis from Jones Day published during the drafting process noted that this structure mirrors the AI Act's broader approach: upstream technical requirements for providers, downstream disclosure duties for deployers. A company does not escape Article 50 simply because it licensed an external AI tool from a third party.
The practical implication: if a marketing team uses a generative AI system to produce a campaign image that resembles a real person or place, the team, not the AI vendor, is responsible for labeling that image before publication.
What Actually Requires Labeling
The code does not require labeling for every AI-assisted output. The scope is narrower than early commentary suggested.
The EU's official guidance on labeling icons specifies three categories:
Deepfakes. Any AI-generated or manipulated image, audio, or video that resembles existing persons, objects, places, or events and would falsely appear authentic to a viewer. The test is perceptual: would an average person mistake this for real? Content that is obviously synthetic, such as stylized illustrations, generally falls outside the requirement.
Chatbots and AI agents. Users must be informed when they are interacting with an AI system rather than a human. This applies to customer service bots, virtual assistants, and any interface where the distinction might not be obvious.
AI-generated text on matters of public interest. This applies only where the text has not undergone human review or editorial control, and where no natural or legal person has assumed editorial responsibility. The phrase "matters of public interest" covers health, safety, environment, economy, politics, science, and culture.
The third category contains a significant carve-out. As design commentator Vitaly Friedman noted, the disclosure obligation does not apply where AI-generated text has been reviewed and edited by a human who takes editorial responsibility for the publication. A journalist who uses AI to draft an article and then edits it before publication does not trigger the labeling requirement, provided the journalist or their publication assumes responsibility for the final text.
The Visual Test and the Compliance Pathway
Guidance from FELD M emphasizes that compliance does not depend on the specific tool used. It depends on whether the content looks photo-realistic and plausible to the average viewer. A stylized AI-generated illustration for a blog post likely falls outside the deepfake definition. A synthetic image of a recognizable public figure in a realistic setting almost certainly falls within it.
The EU has developed a set of standardized icons that deployers may use to label AI-generated content. The icons come in four variations: black, white, and two transparency levels. User testing informed the design, and performance improved across all measures when the basic icon was accompanied by a text label such as "modified" or "AI-generated."
Organizations that sign the code can rely on its measures to demonstrate compliance across all Member States. The Commission and the AI Board have confirmed that the code is an adequate voluntary tool for this purpose. Signatories will also participate in Signatory Taskforces to share practices and advance implementation.
Organizations that choose not to sign the code must still comply with Article 50. They will need to demonstrate that their alternative measures are adequate, assessed individually by different market surveillance authorities. In Germany, the Federal Network Agency (Bundesnetzagentur) serves as the relevant authority.
Extraterritorial Reach
SSL.com's compliance guide notes that Article 50 applies to any organization whose AI output reaches people in the EU, regardless of where the organization is headquartered. This follows the market-of-destination principle familiar from GDPR. A US-based company running a customer support chatbot that serves EU users carries the same disclosure obligations as an EU-based competitor.
The enforcement mechanism remains to be tested. But the legal exposure is clear: fines under the AI Act can reach €15 million or 3% of global annual turnover for transparency violations, whichever is higher.
Implementation: Where the Work Actually Sits
For most organizations, the operational challenge is not understanding the rule but embedding it into existing workflows. Pandectes' compliance analysis suggests a practical starting point: map every point at which AI-assisted output reaches customers, users, or the public. This includes images, videos, audio, written content, and chatbot interactions.
The goal is to make labeling a repeatable part of publishing and service processes rather than a decision left to an individual employee at the last minute. Organizations with mature content operations will likely integrate labeling into their content management systems. Those with less structured workflows face a steeper implementation curve.
The code also requires providers to implement technical marking, meaning machine-readable metadata that allows downstream systems to detect AI-generated content. This creates a dependency: deployers need their AI vendors to implement upstream marking before downstream labeling can be fully automated.
What the Code Does Not Resolve
Several ambiguities remain. The phrase "matters of public interest" is broad, and the boundary between covered and uncovered text will likely be tested through enforcement actions. The "human review" exception creates incentives for organizations to route AI-generated content through nominal editorial processes, but the code does not specify what level of review qualifies.
The code also does not address the interaction between Article 50 and other AI Act provisions, such as the high-risk system requirements or the general-purpose AI model rules. Organizations operating across multiple AI Act categories will need to coordinate compliance efforts.
Implications
The transparency framework creates a new operational layer for any organization deploying generative AI in Europe. The compliance pathway is clearer than it was six months ago, but implementation requires investment in workflow design, technical integration, and staff training.
For policymakers and governance scholars, the code offers an early test case for how voluntary instruments interact with binding legal obligations under the AI Act. For startup leaders and investors, it signals that AI deployment in Europe now carries disclosure costs that must be factored into product design and go-to-market strategy.
The broader question is whether transparency obligations will meaningfully reduce the risks of deception and manipulation that motivated Article 50, or whether they will become a compliance checkbox that sophisticated actors learn to game. That question will be answered not by the code itself, but by how enforcement authorities interpret and apply it over the coming years.
Frequently Asked Questions
Q: When did the EU AI Act's transparency obligations for AI-generated content take effect?
A: Article 50's transparency obligations became legally binding on 2 August 2026. The Code of Practice was finalized in June 2026 to provide implementation guidance ahead of that deadline.
Q: Does every piece of AI-generated content require labeling under Article 50?
A: No. Labeling requirements apply specifically to deepfakes, chatbots and AI agents interacting with users, and AI-generated text on matters of public interest that has not undergone human editorial review. Most AI-assisted work falls outside these categories.
Q: What happens if AI-generated text is reviewed and edited by a human before publication?
A: The disclosure obligation does not apply where AI-generated text has undergone human review or editorial control and where a natural or legal person has assumed editorial responsibility for the publication.
Q: Does Article 50 apply to companies outside the European Union?
A: Yes. Any organization whose AI output reaches people in the EU must comply, regardless of where the company is headquartered. This follows the market-of-destination principle.
Q: What are the penalties for non-compliance with Article 50?
A: Fines for transparency violations under the AI Act can reach €15 million or 3% of global annual turnover, whichever is higher.
Q: Is signing the Code of Practice mandatory for compliance?
A: No. The code is voluntary, but the underlying Article 50 obligations are legally binding. Organizations that do not sign must demonstrate that their alternative compliance measures are adequate, assessed individually by market surveillance authorities.