Short answer
Responsibility follows the role held towards a specific system, not the level of its risk. The provider is responsible for making the system disclose that a person is interacting with AI and for marking synthetic content in a machine-readable format. The deployer has two obligations of its own: it informs people about emotion recognition and biometric categorisation, and it discloses deepfakes and published text. These obligations have applied since 2 August 2026 and were not covered by the July postponement.
Why this question arises at all
In the summer of 2026 the market settled on one message: the AI Act has been postponed. The postponement, however, covered only the requirements and obligations concerning high-risk systems. The transparency provisions were left untouched and became applicable on the original schedule.
For an organisation that only uses AI, the difference is fundamental. High-risk requirements apply to a narrow group of use cases and still have more than a year to run. Transparency obligations do not ask about the risk category. They ask what the system does and who uses it in a given arrangement.
The second source of confusion is commercial. The vendor of a tool usually declares compliance with the AI Act, and the organisation reads that as the end of the subject. Yet two of the four transparency obligations are addressed directly to the deployer. The provider cannot perform them on the client’s behalf, because it does not know what the client will do with the system’s output.
The third source is terminological. “Transparency” in the AI Act does not mean documentation or a policy. It means specific information given to a specific person at a specific moment.
What to establish before deciding
Four obligations and two roles
Article 50 of the regulation contains four separate obligations. The first two are designed into the product; the other two are performed inside the organisation.
| Obligation | Who holds it | What it covers | From when |
|---|---|---|---|
| Informing people that they interact with an AI system (para. 1) | provider | systems intended to interact directly with natural persons | 2 August 2026 |
| Marking synthetic content in a machine-readable format (para. 2) | provider | audio, image, video and text that is generated or manipulated | 2 August 2026; systems placed on the market earlier — 2 December 2026 |
| Informing people about emotion recognition and biometric categorisation (para. 3) | deployer | the persons the system is applied to | 2 August 2026 |
| Disclosing deepfakes and published text (para. 4) | deployer | content passed on to recipients | 2 August 2026 |
The split has a practical consequence for procurement. The provider’s obligations can be moved into contractual terms and verified before deployment. The deployer’s obligations cannot be moved anywhere. They depend on how the organisation uses the system’s output, and the provider does not control that.
What the deployer has to disclose
The first obligation covers two kinds of systems. The organisation informs people that an emotion recognition system or a biometric categorisation system is being applied to them. The provision also requires personal data to be processed in line with the GDPR, so both layers run in parallel.
In the workplace, however, the question usually comes earlier. The regulation prohibits the use of AI systems to infer emotions of individuals in the workplace and in education institutions. The exception covers medical and safety reasons only. Before the organisation designs information for its staff, it therefore has to settle whether it may run such a tool at all.
The second obligation covers content. The regulation defines a deepfake as image, audio or video content resembling existing persons, objects or events. The decisive element is the second limb of the definition: a recipient could wrongly consider such content to be authentic. The deployer then discloses that the content has been artificially generated or manipulated.
The same paragraph covers text. Here the obligation is narrower and concerns text published in order to inform the public on matters of public interest. Ordinary marketing communication and internal correspondence fall outside its scope. The line gets thin in the communication of public institutions and in materials on safety, health and the environment.
When the editorial exemption applies
For text the provision sets out an exemption, and it is the exemption that is most often overused in practice. The duty to disclose falls away where the content has undergone human review or editorial control and a natural or legal person holds editorial responsibility for the publication.
It is worth reading that condition as having two limbs. Review alone is not enough — there has to be someone bearing editorial responsibility. In practical terms this means a named role in the publication process, rather than the customary “somebody read it before it went out”. An organisation that wants to rely on the exemption should be able to point to that role and show a trace of the review.
A separate relaxation applies to content that is evidently artistic, creative, satirical or fictional. The obligation is then limited to disclosing the existence of such content in a way that does not hamper the display or enjoyment of the work.
How and when to give the information
The regulation settles both the form and the moment. The information is given in a clear and distinguishable manner, at the latest at the time of the first interaction or exposure to the system. It must meet the applicable accessibility requirements.
Three practical design decisions follow from that. The information cannot be hidden in terms of service or in a privacy policy, because it does not reach the person at the moment of first contact. It cannot be available visually only, where digital accessibility requirements apply. And it cannot be delivered after the fact.
The provision also states that these transparency obligations are without prejudice to other information duties under Union and national law. Information under Article 50 therefore does not replace the information duty under the GDPR. They are two parallel messages with different subject matter.
What changes on 2 December 2026
The July 2026 omnibus added one date that concerns older tools. Providers of systems generating synthetic content that were placed on the market before 2 August 2026 have until 2 December 2026 to align with the marking obligation.
For the deploying organisation the conclusion runs the other way than it first seems. A tool bought before August 2026 may not mark its output in a machine-readable way until December. The duty to disclose deepfakes and published text, however, already rests with the deployer and applies regardless of what the tool does. In that period the disclosure has to be delivered by a process, not by a product feature.
What you can rely on
On 20 July 2026 the European Commission issued guidelines on the application of Article 50. They address, among other things, the division of responsibility between the provider and the deployer, the scope of the exemptions and the meaning of a deepfake. The guidelines are not a source of obligation, but they show how the authority will read the provision.
The second document is the Code of Practice on Transparency of AI-Generated Content. The Commission and the AI Board considered it an adequate voluntary instrument. Its second section is addressed directly to deployers and describes how content is marked and which internal processes support it. Signing up to the code is a way of demonstrating compliance, not compliance itself.
Most common mistakes
- Assuming the postponement covered the whole regulation. What moved were the requirements for high-risk systems. Transparency has applied since 2 August 2026.
- Assigning all four obligations to the provider. Paragraphs 3 and 4 of Article 50 are addressed to the deployer and cannot be shifted by contract.
- Treating machine-readable marking as disclosure to the recipient. The marking under paragraph 2 serves technical detectability. The disclosure under paragraph 4 is a message for a human being.
- Invoking the editorial exemption with no one holding editorial responsibility. The provision requires both elements at once, and the organisation has to be able to show both.
- Putting the information in the terms of service instead of at the moment of first contact. The provision fixes a moment, not a place in the documentation.
- Overlooking the prohibition on emotion recognition in the workplace. Informing staff does not cure a practice that is prohibited.
Conclusions and next steps
Transparency is the chapter of the AI Act that already concerns an organisation using off-the-shelf tools. What decides here is the role held towards a specific use case, not the risk category and not the provider’s declaration. Two obligations have to be performed by the organisation itself, so it needs a process rather than just a clause in a contract.
A sequence that works when putting this area in order:
- Collect the use cases in which AI interacts with people or produces content published externally.
- For each use case establish the organisation’s role and assign the obligations from the relevant paragraph of Article 50.
- Check whether tools bought before August 2026 mark their output in a machine-readable way, and plan a solution for the period until December.
- Design the wording and the moment of the information, and for published text settle who holds editorial responsibility.
- Keep a trace of those decisions, because that is what answers the question of a client, an auditor or an authority.
The last point is the one most often skipped. Transparency obligations are performed towards people, but they are demonstrated towards an authority — and that calls for different material than a notice on a website.
Related materials
- When does an organisation using AI become its provider? (material in preparation) — crossing the line between roles moves the obligations from the first two paragraphs of Article 50 onto the organisation.
- What does the AI literacy obligation require? (material in preparation) — the second obligation that applies without a transitional period.
- Is the AI tool we use a high-risk system? (material in preparation) — the classification that decides the postponed obligations.
Sources
- Regulation (EU) 2024/1689 of the European Parliament and of the Council (Artificial Intelligence Act), consolidated version of 27 July 2026, Article 3(60), Article 5(1)(f), Article 50 and Article 113 — eur-lex.europa.eu (accessed: August 20, 2026).
- Regulation (EU) 2026/1744 of the European Parliament and of the Council of 8 July 2026, Article 1(39) and (40) (amendments to Articles 111 and 113) — eur-lex.europa.eu (accessed: August 20, 2026).
- European Commission, guidelines on transparency obligations for certain AI systems under Article 50 of Regulation (EU) 2024/1689, C(2026) 5054 final of 20 July 2026 (accessed: August 20, 2026).
- Code of Practice on Transparency of AI-Generated Content, together with the Commission’s opinion on its adequacy, European Commission — digital-strategy.ec.europa.eu (accessed: August 20, 2026).
See where AI already speaks for your organisation
Transparency obligations concern use cases that usually appeared without a board decision. The review starts with a list of them and ends by assigning the obligations under Article 50 to specific people in the organisation.
This material is general and educational in nature. It is not an individual legal opinion or a recommendation for any specific organisation. The scope of the obligations should be assessed against the situation of the organisation concerned.
Legal status: August 2026.