Short answer. Article 50 of the EU AI Act starts to apply on 2 August 2026. It requires that people are told when they are talking to a chatbot, when media is a deepfake, and when text or images were generated by AI. Providers must mark synthetic outputs so machines can detect them. Breaches carry fines up to EUR 15 million or 3% of global annual turnover.
Article 50 sets four transparency duties. Each one attaches to a specific role, either the provider that builds the system or the deployer that puts it in front of people. The rules cover the AI outputs a customer actually sees and hears, not the model behind them.
The four duties break down as follows:
Disclosure has to be clear, distinguishable, and given no later than the first interaction or exposure. A buried line in a privacy policy does not meet the standard.
Banks and insurers already run the exact systems Article 50 names. Customer service chatbots handle account queries. Generative models draft marketing copy, claims letters, and onboarding messages. Voice bots answer the phone. Every one of these becomes a documented disclosure obligation on 2 August 2026.
The rule sits next to obligations these firms already carry. DORA has applied to financial entities since 17 January 2025 and governs the resilience of the ICT systems that run these models. The EU AI Act adds the transparency layer on top. A bank that deploys a customer-facing chatbot now needs an inventory of where AI speaks to customers, a disclosure at each of those points, and evidence it can show a supervisor. The compliance question is no longer whether AI is used, it is whether the firm can prove it told people.
Article 50 of the EU AI Act applies from 2 August 2026 and sets four AI transparency duties.
Article 50 splits duties by role, and financial firms usually sit on both sides. The provider that builds or brands a chatbot owns the duty to inform users they are talking to AI, and the provider of a generative model owns the duty to mark synthetic output. Those are paragraphs 50(1) and 50(2).
The deployer, the entity that uses an AI system under its own authority, owns paragraphs 50(3) and 50(4): telling people about emotion recognition or biometric categorisation, and disclosing deepfakes and AI-generated public-interest text. A bank that licenses a third-party model and points it at its customers is a deployer, and often a provider too when it fine-tunes or rebrands the system. Both roles need a named owner inside the organisation.
The Act defines a deepfake as AI-generated or manipulated image, audio, or video content that resembles real people, objects, places, or events and would falsely appear authentic. The test is realism plus a real referent, not the tool used to make it.
For a financial firm this reaches further than obvious fakes. A synthetic voice that mimics a named advisor, an AI-generated video of an executive, or a manipulated image used in a campaign all fall inside the definition. Purely artistic or satirical work gets a lighter disclosure that does not spoil the piece, but commercial and informational uses get the full clear-and-distinguishable label.
Article 50 applies from 2 August 2026, twenty-four months after the AI Act entered into force. There is no separate grace period built into the article itself. The European Commission has issued guidance and is finalising a Code of Practice on transparency and marking of AI-generated content to help providers meet the machine-readable marking duty, with a signatory window that closed in July 2026.
Watermarking and machine-readable marking remain technically immature, and the Commission has acknowledged the gap between the mandate and available tooling. That does not move the date. Firms that wait for perfect marking technology will still be inside scope on 2 August 2026.
Breaching Article 50 sits in the AI Act’s general penalty tier. National authorities can impose fines up to EUR 15 million or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. For a mid-market financial group with EUR 300 million in revenue, 3% is EUR 9 million per breach category.
Prohibited practices carry a higher ceiling of EUR 35 million or 7%, but transparency failures land in the 3% band alongside most other obligations. Supervisors weigh the size of the firm, the duration of the breach, and whether disclosure was absent or merely unclear. For regulated entities the reputational cost of an undisclosed chatbot or deepfake usually outruns the fine.
Start with an inventory. List every point where an AI system speaks to a customer or generates content a customer sees, then map each point to the responsible role and the specific paragraph of Article 50 that applies. This turns an abstract rule into a checklist a compliance team can sign off.
Then build the disclosure into the product, not the paperwork. A chatbot opens by stating it is an automated assistant. A generative content pipeline stamps a machine-readable mark on every output. A deepfake or synthetic-voice campaign carries a visible label. Each control needs an owner, a test, and a log, so the firm can show a supervisor what it did and when. Governance that is observable beats governance that is asserted.
Article 50 rewards firms that treat AI as production infrastructure with accountability built in, not as a set of loose experiments. That is the work Ableneo does. In 2025 Ableneo shipped 34 production AI projects across financial services, insurance, and other regulated sectors, and 94% of them use large language models, so the disclosure surfaces Article 50 governs are the same ones we help clients ship and observe. Our approach maps each customer-facing AI touchpoint to its owner and its control, then makes the disclosure part of the system rather than a policy note. See the Ableneo AI Transformation FAQ for related answers on EU AI Act and DORA obligations.
Key takeaways
Planning AI in a regulated business? Ableneo takes systems from classification to governed production.